Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-09-05 Thread Tobias Geerinckx-Rice
Ludovic Courtès 写道: I’m busy these days so I’d rather not commit to starting a discussion on this, but I’d suggest testing waters on #savannah on IRC. They weren't wild about it. We'd be asking for a lot from their perspective. I haven't given up on convincing them otherwise, but an altern

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-09-05 Thread Ludovic Courtès
Hi, Andrew Tropin skribis: >> Setting a pre-push hook that invokes ‘guix git authenticate’, as >> recommended in the manual (info "(guix) Commit Access"), should be >> enough: ‘git push’ would just fail in that situation. > > For some reason I thought it does git verify-commit, which I used > ma

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-09-05 Thread Andrew Tropin
On 2022-09-02 15:23, Ludovic Courtès wrote: > Hello! > > I’m late to the party, but thanks a lot for sending this analysis! > > Andrew Tropin skribis: > >> * What could be done better? >> - guix pull could be done from local checkout, before pushing. > > Setting a pre-push hook that invokes ‘guix

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-09-02 Thread Ludovic Courtès
Hello! I’m late to the party, but thanks a lot for sending this analysis! Andrew Tropin skribis: > * What could be done better? > - guix pull could be done from local checkout, before pushing. Setting a pre-push hook that invokes ‘guix git authenticate’, as recommended in the manual (info "(gu

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-08-11 Thread John Kehayias
Hi everyone, Thanks for this write-up and discussion Andrew. I'm also following along in [0] but I'll just chime in here for now. When I saw this I was worried since I also "just" use subkeys, meaning for all signing etc. only my subkey is used. These are set to expire each year and then I ren

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-08-11 Thread Maxime Devos
On 11-08-2022 16:26, Andrew Tropin wrote: * What to do after? - Accept subkey on guix pull if master key is in .guix-authorizations. As I've now written on 57091, this would cause security problems with old or revoked keys. Greetings, Maxime. OpenPGP_0x49E3EE22191725EE.asc Description: O

Re: [POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-08-11 Thread Development of GNU Guix and the GNU System distribution.
Hi, On Thu, Aug 11, 2022 at 7:27 AM Andrew Tropin wrote: > > Re: [POSTMORTEM] I have likewise used those words to describe concluding reports or to communicate lessons learned, but upon reflection I now prefer "incident summary" or "debrief". [1] Since both of my suggested replacements are assoc

[POSTMORTEM] Subkey is not authorized by .guix-authorizations

2022-08-11 Thread Andrew Tropin
* Summary On 2022-08-06 the commit 3946540[fn:1] was pushed and lead to failing guix pull: --8<---cut here---start->8--- guix pull: error: commit 39465409f0481f27d252ce25d2b02d3f5cbc6723 not signed by an authorized key: 2841 9AC6 5038 7440 C7E9 2FFA 2208 D209 5