Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-12 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Roy T. Fielding wrote: On Aug 11, 2009, at 8:24 AM, Robert Burrell Donkin wrote: 1024 bit keys and SHA-1 links are currently considered safe so there's no reason to believe that apache keys have been compromised. transition statements [1] in a

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-12 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Henri Yandell wrote: Need to update http://www.apache.org/dev/release-signing.html to say 4096 asap I suspect :) Stop new people being lured into this problem. yes but... key size isn't the direct cause of the problem: SHA-1 is AIUI the OpenPGP

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-12 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 William A. Rowe, Jr. wrote: Jukka Zitting wrote: Hi, On Tue, Aug 11, 2009 at 4:09 PM, Rich Bowenrbo...@rcbowen.com wrote: Is it possible to regenerate my gpg key without losing all the signatures on my existing key? To bootstrap the new key,

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-12 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Robert Burrell Donkin wrote: Henri Yandell wrote: Need to update http://www.apache.org/dev/release-signing.html to say 4096 asap I suspect :) Stop new people being lured into this problem. i've committed something (as a stopgap measure) yes

[OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 with ApacheConUS only three months away, we really need to start planning how apache can move away from short keys (DSA and RSA 2048) and weak WOT links (SHA-1)[1]. the consensus on infra was that this is the best list for this discussion. if it

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Rich Bowen
Is it possible to regenerate my gpg key without losing all the signatures on my existing key? I presume not, but perhaps there's something I'm missing. I have a 1024 bit key, and would like to be like the cook kids, but not lose ten years of signatures. On Aug 11, 2009, at 08:39, Robert

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Tony Stevenson
You cannot retrospectively 'upgrade' your key, AIUI, at least. So you will sadly lose all your signatures as you will need a new key. Thankfully I created mine with a 4096 key length so I'm ok, but I get impression many folks wont be. Get your key created now, and at Apachecon we will have

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Rich Bowen
On Aug 11, 2009, at 10:13, Tony Stevenson wrote: You cannot retrospectively 'upgrade' your key, AIUI, at least. So you will sadly lose all your signatures as you will need a new key. Thankfully I created mine with a 4096 key length so I'm ok, but I get impression many folks wont be. Get

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Jukka Zitting
Hi, On Tue, Aug 11, 2009 at 4:09 PM, Rich Bowenrbo...@rcbowen.com wrote: Is it possible to regenerate my gpg key without losing all the signatures on my existing key? To bootstrap the new key, you could sign it with your old key. Not sure if that should be enough for others to trust that it

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Robert Burrell Donkin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Rich Bowen wrote: On Aug 11, 2009, at 10:13, Tony Stevenson wrote: You cannot retrospectively 'upgrade' your key, AIUI, at least. So you will sadly lose all your signatures as you will need a new key. it should be possible to use a script

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread William A. Rowe, Jr.
Jukka Zitting wrote: Hi, On Tue, Aug 11, 2009 at 4:09 PM, Rich Bowenrbo...@rcbowen.com wrote: Is it possible to regenerate my gpg key without losing all the signatures on my existing key? To bootstrap the new key, you could sign it with your old key. Not sure if that should be enough

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Henri Yandell
Need to update http://www.apache.org/dev/release-signing.html to say 4096 asap I suspect :) Stop new people being lured into this problem. Hen On Tue, Aug 11, 2009 at 5:39 AM, Robert Burrell Donkinrdon...@apache.org wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 with ApacheConUS only

Re: [OpenPGP] Moving Away From DSA and SHA-1

2009-08-11 Thread Roy T. Fielding
On Aug 11, 2009, at 8:24 AM, Robert Burrell Donkin wrote: 1024 bit keys and SHA-1 links are currently considered safe so there's no reason to believe that apache keys have been compromised. transition statements [1] in a trusted location will probably be good enough to convince most people to