Re: 20140407 keyring report

2014-04-22 Thread Paul Wise
On Tue, Apr 22, 2014 at 4:06 PM, Thijs Kinkhorst wrote:

> I think it has been suggested earlier in related discussions that a
> cleanup of long time inactive DD's may make a rather significant dent in
> the number of 1024 bits keys. Is this something you're considering?

That would be something for DAM's WaT activities, CCing them.

https://lists.debian.org/debian-devel-announce/2007/07/msg4.html
http://blog.ganneff.de/blog/2007/07/wat-where-are-they.html

-- 
bye,
pabs

http://wiki.debian.org/PaulWise


-- 
To UNSUBSCRIBE, email to debian-project-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/CAKTje6HJVg8p6ryMmma1giYCQcWzGL=hakdknfenaxhobba...@mail.gmail.com



Re: 20140407 keyring report

2014-04-22 Thread Thijs Kinkhorst
On Sun, April 20, 2014 06:12, Gunnar Wolf wrote:
> Kurt Roeckx dijo [Sun, Apr 20, 2014 at 12:51:45AM +0200]:
>> On Sat, Apr 19, 2014 at 09:41:40PM +, Clint Adams wrote:
>> > Upon request.  Made with an unpackaged set of keyrings[0].
>>
>> Thanks for the update.
>> (...)
>> So we seem to making some progress, and I hope the rest will
>> follow soon.
>
> Yes. March and April were happy and busy months for
> keyring-maint. Late-April has lost quite a bit of speed. I hope we can
> get traction again! IIRC, we have ~6 pending requests right now (I
> haven't done any keyring work this past week).

I think it has been suggested earlier in related discussions that a
cleanup of long time inactive DD's may make a rather significant dent in
the number of 1024 bits keys. Is this something you're considering?


Cheers,
Thijs


-- 
To UNSUBSCRIBE, email to debian-project-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
https://lists.debian.org/c26d795a0305d3631fdf5e89621a1a5a.squir...@aphrodite.kinkhorst.nl



Re: 20140407 keyring report

2014-04-19 Thread Gunnar Wolf
Kurt Roeckx dijo [Sun, Apr 20, 2014 at 12:51:45AM +0200]:
> On Sat, Apr 19, 2014 at 09:41:40PM +, Clint Adams wrote:
> > Upon request.  Made with an unpackaged set of keyrings[0].
> 
> Thanks for the update.
> (...)
> So we seem to making some progress, and I hope the rest will
> follow soon.

Yes. March and April were happy and busy months for
keyring-maint. Late-April has lost quite a bit of speed. I hope we can
get traction again! IIRC, we have ~6 pending requests right now (I
haven't done any keyring work this past week).

> Specially the DMs don't seem to make any progress.

Yes, sadly. And given that DMs are typically much least connected to
Debian than DDs, it seems it's up to us (keyring-maint) to reach out
and contact them individually.


-- 
To UNSUBSCRIBE, email to debian-project-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/20140420041244.ga6...@gwolf.org



Re: 20140407 keyring report

2014-04-19 Thread Kurt Roeckx
On Sat, Apr 19, 2014 at 09:41:40PM +, Clint Adams wrote:
> Upon request.  Made with an unpackaged set of keyrings[0].

Thanks for the update.

So we had in january:
DDs:
623 "DSA"
624 1024
DMs:
 54 "DSA"
 54 1024
non-upload:
  0 "DSA"
  0 1024


In february:
DDs:
611 "DSA"
612 1024
DMs:
 54 "DSA"
 54 1024
non-upload:
  0 "DSA"
  0 1024

And now in April:
DDs:
 550 "DSA"
 551 1024
DMs:
 52 "DSA"
 52 1024
non-upload:
  0 "DSA"
  0 1024

So we seem to making some progress, and I hope the rest will
follow soon.  Specially the DMs don't seem to make any progress.


Kurt


-- 
To UNSUBSCRIBE, email to debian-project-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/20140419225145.ga11...@roeckx.be



20140407 keyring report

2014-04-19 Thread Clint Adams
Upon request.  Made with an unpackaged set of keyrings[0].

(/tmp/keyrings/debian-keyring.gpg)
Total primary keys: 994
Key versions: 
994 4
Primary key pubkey algorithms: 
550 "DSA"
444 "RSA"
Primary key pubkey sizes: 
551 1024
 28 2048
  3 3072
409 4096
  2 8192
  1 10240
Judgment on preferred hash algorithms of "best" uid/uat: 
575 null
418 "weak hash with higher preference"
Judgment on expiration times of "best" uid/uat: 
  9 "expiration passed"
 30 "expiration too far in future"
873 "no expiration set"
 81 null
Total number of UIDs + UAts: 4267
Hash algorithm used for most recent self-sig: 
  1 "RIPEMD160"
   2856 "SHA1"
   1224 "SHA256"
  5 "SHA384"
181 "SHA512"
Judgment on preferred hash algorithms: 
   1411 null
   2856 "weak hash algorithm"
Judgment on expiration times: 
 59 "expiration passed"
107 "expiration too far in future"
   3773 "no expiration set"
328 null
==
(/tmp/keyrings/debian-maintainers.gpg)
Total primary keys: 215
Key versions: 
215 4
Primary key pubkey algorithms: 
 52 "DSA"
163 "RSA"
Primary key pubkey sizes: 
 52 1024
  1 1280
 17 2048
  1 3072
143 4096
  1 8192
Judgment on preferred hash algorithms of "best" uid/uat: 
181 null
 34 "weak hash with higher preference"
Judgment on expiration times of "best" uid/uat: 
  2 "expiration passed"
  7 "expiration too far in future"
168 "no expiration set"
 38 null
Total number of UIDs + UAts: 646
Hash algorithm used for most recent self-sig: 
327 "SHA1"
234 "SHA256"
 85 "SHA512"
Judgment on preferred hash algorithms: 
319 null
327 "weak hash algorithm"
Judgment on expiration times: 
  6 "expiration passed"
 20 "expiration too far in future"
523 "no expiration set"
 97 null
==
(/tmp/keyrings/debian-nonupload.gpg)
Total primary keys: 9
Key versions: 
  9 4
Primary key pubkey algorithms: 
  9 "RSA"
Primary key pubkey sizes: 
  1 2048
  8 4096
Judgment on preferred hash algorithms of "best" uid/uat: 
  9 null
Judgment on expiration times of "best" uid/uat: 
  6 "no expiration set"
  3 null
Total number of UIDs + UAts: 26
Hash algorithm used for most recent self-sig: 
  7 "SHA1"
 17 "SHA256"
  2 "SHA512"
Judgment on preferred hash algorithms: 
 19 null
  7 "weak hash algorithm"
Judgment on expiration times: 
 15 "no expiration set"
 11 null
==

[0] rsync -a keyring.debian.org::keyrings/keyrings /tmp; for i in 
/tmp/keyrings/{debian-keyring,debian-maintainers,debian-nonupload}.gpg; do 
print "($i)"; /tmp/keystats.zsh $i; done


-- 
To UNSUBSCRIBE, email to debian-project-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/20140419214140.ga...@scru.org