NowpPublishing fedora developer PGP keys in DNSSEC

Björn Persson Bjorn at xn--rombobjrn-67a.se
Sun Feb 1 19:34:51 UTC 2015


Paul Wouters wrote:
>paul at bofh:~$ openpgpkey --fetch pwouters at fedoraproject.org

openpgpkey: /var/lib/unbound/root.anchor is not a file. Unable to use
it as rootanchor

Huh?

>2) most people don't have their fedoraproject.org as uid on their key

Perhaps they are like me in that they want to be known by their actual
address rather than the fedoraproject.org alias. When people want to
reach me I want them to send their email directly to Bjorn at Rombobjörn.se
(or to Bjorn at Rombobeorn.se if their email client doesn't understand
IDNA), not to an alias in another domain. It doesn't hurt that an alias
exists, and it may be useful to automated stuff in the Fedora
infrastructure, but I prefer not to advertise it outside of Fedora.

Perhaps you should publish only those keys that have a
fedoraproject.org address?

> 	openpgpkey --create paul at nohats.ca

It seems to assume that everything is ASCII:

$ openpgpkey --create Bjorn at Rombobjörn.se
Traceback (most recent call last):
  File "/usr/bin/openpgpkey", line 189, in <module>
    if "<%s>"%args.email in uid:
UnicodeDecodeError: 'ascii' codec can't decode byte 0xc3 in position
14: ordinal not in range(128)

-- 
Björn Persson
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 819 bytes
Desc: OpenPGP digital signatur
URL: <http://lists.fedoraproject.org/pipermail/devel/attachments/20150201/ea995590/attachment.sig>


More information about the devel mailing list