[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Removing < 2048 bit keys from the Debian keyrings



On Tue, Sep 02 2014, Manoj Srivastava wrote:

> On Tue, Sep 02 2014, Jeremy T. Bouse wrote:
>
>
>> 	I don't know how the *-cert-level options in gpg/gpg2 match up with
>> that section RFC480. Actually reading the sections in the man pages it
>> reads very differently.
>
>         I stand corrected. Now I just need to figure out how to resign
>  the keys with the new options.

        I figured out how to do the signatures; I am now torn between
 whether I should resign just to get the cert-level data in the
 signature, and effectively obscuring when the signature was actually
 made (well, or replacing the date when I had checked the ID with the
 current one). I'll re-sign the keys from the current debconf in a
 month, if they make their way to the keyservers, but i'll leave the
 historical signatures alone.

        I learned something today :-)

        manoj
-- 
If I have not seen so far it is because I stood in giant's footsteps.
Manoj Srivastava <srivasta@debian.org> <http://www.debian.org/~srivasta/>  
4096R/C5779A1C E37E 5EC5 2A01 DA25 AD20  05B6 CF48 9438 C577 9A1C

Attachment: signature.asc
Description: PGP signature


Reply to: