Re: Web of Trust work [Was: kernel.org tooling update]
James Bottomley <[email protected]> Mon, 26 Jan 2026 18:23:08 -0500
| Newsgroups | dev.linux.lists.ksummit |
|---|---|
| Message-ID | <2ef60fa3afe287cec92020b8b77a37c0b70cefaa.camel@HansenPartnership.com> |
On Mon, 2026-01-26 at 18:32 +0100, Uwe Kleine-König wrote: > Actually I'd like to see you/us add still more burden and asking > developers to only hand in keys with an expiry date <= (say) 3 years. > Something similar to what > https://www.gentoo.org/glep/glep-0063.html#bare-minimum-requirements > requests. You have seen Linus' views on gpg key expiry, right? https://lore.kernel.org/linux-scsi/CAHk-=wi03SZ4Yn9FRRsxnMv1ED5Qw25Bk9-+ofZVMYEDarHtHQ@mail.gmail.com/ As a result of that I've taken to using much longer expiry periods. Regards, James
signature.asc
(application/pgp-signature, 265 B)
-----BEGIN PGP SIGNATURE----- iJEEABMIADkWIQTnYEDbdso9F2cI+arnQslM7pishQUCaXf3XRsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMSwyLDIACgkQ50LJTO6YrIU12wEAkVYJjl8sBHm9CIPyY/W4 3uI7jz+xIC4iREnibrs48/wBAKENAJ1K3ochYTIfp32zcVWi2IB2bQw2/AEfooqs SE3i =b8eA -----END PGP SIGNATURE-----