[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Bits from keyring-maint: Pushing keyring updates. Let us bury your old 1024D key!



Jonathan McDowell dijo [Tue, Mar 04, 2014 at 05:38:11AM +0000]:
> > Surely this is well within keyring-maint purview and a GR is thus
> > unnessecary? Running the plan by debian-project seems a reasonable
> > level of consultation.
> 
> We didn't need one for removing PGPv3 keys so I don't see why we'd need
> one for 1024D v4 keys.

I was thinking that we might need it just because of the amount of
keys. We will end up locking out *many* DDs.

> I have already suggested a timescale to -project but haven't seen any
> comments on it other than "you should script this" and "should we relax
> the requirement for 2 signatures".

Right. And that basically gives us green light - But, yes, some will
argue it's only involving people actively following said list.


Reply to: