rdoeffinger / iec16022

DataMatrix 2D barcode generator

Home Page:http://rdoeffinger.github.io/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Publish mail address of signing public key of iec16022 at keys.openpgp.org?

robert-scheck opened this issue · comments

Do you see a chance to publish the mail adress of the public key of key C61D16E59E2CD10C895838A40899A2B906D4D9C7, being used for signing iec16022 release tarballs, at keys.openpgp.org? This would allow Fedora to switch from the current binary GnuPG output blob (manually created) to the ASCII format provided there. Unfortunately keys.openpgp.org strips all user IDs unless the owner of the corresponding email address has allowed them to be published, thus keys.openpgp.org can't be used for the ASCII format right now.

What an annoyance, given for how long this key has been around. Anyway, done.
However not sure how long this will be useful/accept by Fedora's mechanisms, I will have to switch to a more modern key because this one is not particularly secure anymore.
I've been hoping for a proper key migration approach to maybe be implemented, but seems that's not going to happen...

Closing as done, but if anyone knows of a trick to "update" a key to newer crypto as seamlessly as possible, I'd be very interested.

Thank you very much. GnuPG unfortunately refuses the import of keys without user IDs - and GnuPG upstream is reluctant to change this behaviour. But using the ASCII armored variant is better to handle in version control systems.

I don't think there is a real "migration" or "update" process when looking to Simon Josefsson's OpenPGP 2019 Key Transition Statement; according to his description the setup is one of the most extended ones that I'm personally aware of.