New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider self-hosting team PGP keys #1903

Closed
andrewdavidwong opened this Issue Apr 13, 2016 · 10 comments

Comments

Projects
None yet
3 participants
@andrewdavidwong
Member

andrewdavidwong commented Apr 13, 2016

We already have keys.qubes-os.org, which is used to host some PGP keys. However, the Team page currently links to people's PGP keys on pgp.mit.edu. It might be a minor UX improvement to simply host all Qubes-related keys on keys.qubes-os.org.

@andrewdavidwong andrewdavidwong added this to the Documentation/website milestone Apr 18, 2016

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 15, 2016

Member

@marmarek: Any chance of this happening soon?

Member

andrewdavidwong commented Oct 15, 2016

@marmarek: Any chance of this happening soon?

@woju

This comment has been minimized.

Show comment
Hide comment
@woju

woju Oct 18, 2016

Member

On Sat, Oct 15, 2016 at 03:19:51PM -0700, Andrew David Wong wrote:

@marmarek: Any chance of this happening soon?

@andrewdavidwonv Is it really a priority? I can do it of course (I manage
keys.q-o.o), but I won't remember to update those keys when needed.

If so, what should I put there? Just snapshots of whatever pgp.mit.edu says?

pozdrawiam / best regards .-.
Wojtek Porczyk .-^' '^-.
Invisible Things Lab |'-.-^-.-'|
| | | |
I do not fear computers, | '-.-' |
I fear lack of them. '-._ : ,-'
-- Isaac Asimov `^-^-_>

Member

woju commented Oct 18, 2016

On Sat, Oct 15, 2016 at 03:19:51PM -0700, Andrew David Wong wrote:

@marmarek: Any chance of this happening soon?

@andrewdavidwonv Is it really a priority? I can do it of course (I manage
keys.q-o.o), but I won't remember to update those keys when needed.

If so, what should I put there? Just snapshots of whatever pgp.mit.edu says?

pozdrawiam / best regards .-.
Wojtek Porczyk .-^' '^-.
Invisible Things Lab |'-.-^-.-'|
| | | |
I do not fear computers, | '-.-' |
I fear lack of them. '-._ : ,-'
-- Isaac Asimov `^-^-_>

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 18, 2016

Member

Is it really a priority?

Not a priority at all, which is why I haven't mentioned it for six months. 😄

I can do it of course (I manage keys.q-o.o), but I won't remember to update those keys when needed.

I don't think it should be your responsibility to update them. Rather, I think people should just get their their key to you whenever they want them updated.

If so, what should I put there? Just snapshots of whatever pgp.mit.edu says?

Whatever is currently linked on the Team page, IMHO.

Member

andrewdavidwong commented Oct 18, 2016

Is it really a priority?

Not a priority at all, which is why I haven't mentioned it for six months. 😄

I can do it of course (I manage keys.q-o.o), but I won't remember to update those keys when needed.

I don't think it should be your responsibility to update them. Rather, I think people should just get their their key to you whenever they want them updated.

If so, what should I put there? Just snapshots of whatever pgp.mit.edu says?

Whatever is currently linked on the Team page, IMHO.

@woju

This comment has been minimized.

Show comment
Hide comment
@woju

woju Oct 18, 2016

Member

OK, so let's get it done.

https://keys.qubes-os.org/team/, just pulled from pgp.mit.edu. Joanna's keys are "joanna-email-itl.asc" from her page, though we may leave her link as is.

Didn't check them.

Member

woju commented Oct 18, 2016

OK, so let's get it done.

https://keys.qubes-os.org/team/, just pulled from pgp.mit.edu. Joanna's keys are "joanna-email-itl.asc" from her page, though we may leave her link as is.

Didn't check them.

@adrelanos

This comment has been minimized.

Show comment
Hide comment
@adrelanos

adrelanos Oct 18, 2016

Member

Perhaps just link to https://www.whonix.org/patrick.asc ? Or copy the
file. That is supposed to always host my most recent key.

Or from here?
https://github.com/marmarek/qubes-builder-debian/blob/master/keys/whonix-developer-patrick.asc

(I am trying to avoid too many locations of my key to update in future.)

Member

adrelanos commented Oct 18, 2016

Perhaps just link to https://www.whonix.org/patrick.asc ? Or copy the
file. That is supposed to always host my most recent key.

Or from here?
https://github.com/marmarek/qubes-builder-debian/blob/master/keys/whonix-developer-patrick.asc

(I am trying to avoid too many locations of my key to update in future.)

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 19, 2016

Member

Is it too much trouble for everyone to have an additional place to have their keys updated? If so, we can just scrap this idea. (The only motivation for it was that we already have keys.qubes-os.org, and we already use it to host Qubes-related keys, so it seems like a natural step to host and link there instead of pgp.mit.edu, but pgp.mit.edu has the advantage of automatically syncing with other public keyservers, while keys.qubes-os.org does not.)

Member

andrewdavidwong commented Oct 19, 2016

Is it too much trouble for everyone to have an additional place to have their keys updated? If so, we can just scrap this idea. (The only motivation for it was that we already have keys.qubes-os.org, and we already use it to host Qubes-related keys, so it seems like a natural step to host and link there instead of pgp.mit.edu, but pgp.mit.edu has the advantage of automatically syncing with other public keyservers, while keys.qubes-os.org does not.)

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 19, 2016

Member

To add: It probably makes more sense to host things that are truly Qubes-specific, like Qubes release signing keys, on keys.qubes-os.org. People are not Qubes-specific, so it doesn't really make sense to duplicate our keys there. So perhaps this is a bad idea after all.

Member

andrewdavidwong commented Oct 19, 2016

To add: It probably makes more sense to host things that are truly Qubes-specific, like Qubes release signing keys, on keys.qubes-os.org. People are not Qubes-specific, so it doesn't really make sense to duplicate our keys there. So perhaps this is a bad idea after all.

@woju

This comment has been minimized.

Show comment
Hide comment
@woju

woju Oct 19, 2016

Member

@andrewdavidwong, your decision :)

Member

woju commented Oct 19, 2016

@andrewdavidwong, your decision :)

@andrewdavidwong

This comment has been minimized.

Show comment
Hide comment
@andrewdavidwong

andrewdavidwong Oct 19, 2016

Member

@woju: Ok, closing. Sorry for the trouble!

Member

andrewdavidwong commented Oct 19, 2016

@woju: Ok, closing. Sorry for the trouble!

@woju

This comment has been minimized.

Show comment
Hide comment
@woju

woju Oct 20, 2016

Member

No problem. 😄 I removed that directory from keys.qubes-os.org, not to confuse anyone.

Member

woju commented Oct 20, 2016

No problem. 😄 I removed that directory from keys.qubes-os.org, not to confuse anyone.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment