X-Git-Url: https://git.decadent.org.uk/gitweb/?a=blobdiff_plain;f=web%2Fkeys.html;h=55036e9d13cd42810507bb594429920bb7324964;hb=3a541681a420745b36e6b6d025ef6b649c03e7c8;hp=7fd38e85af70d2c7efde2d6e87372f9f716ab424;hpb=0fbf46fb7da5309d9fca4761178c1375cb8916ee;p=dak.git diff --git a/web/keys.html b/web/keys.html index 7fd38e85..55036e9d 100644 --- a/web/keys.html +++ b/web/keys.html @@ -67,16 +67,18 @@

Archive Keys

Active Signing Keys

-

The current (2007/etch) key can be downloaded here

- -

Upcoming Signing Keys

-

The new key, which will be used after the 4.0 key expires or - after Lenny r1 is released, can be downloaded here. (The debian-devel announcement - regarding this key can be read at +

The current (2009/lenny) key can be downloaded here
+ The fingerprint of this key is 150C 8614 919D 8446 E01E 83AF 9AA3 8DCD 55BE 302B.
+ The announcements regarding this key can be read at - http://lists.debian.org/debian-devel-announce/2009/01/msg00008.html)

+ http://lists.debian.org/debian-devel-announce/2009/01/msg00008.html + and http://www.debian.org/News/2009/20090523. +

+ +

The soon-to-be-retired (2007/etch) key can be downloaded here.
+ The fingerprint of this key is A999 51DA F9BB 569B DB50 AD90 A70D AF53 6070 D3A1

Stable Keys

etch

@@ -115,16 +117,67 @@
-

Key Revokation Procedure

+

Key Revocation Procedure

A revokation certificate for the archive key is produced at the time of the creation - of an archive key. The program ssss (a Shamir's secret sharing scheme implementation) - is then used to produce 20 shares of which 10 are needed to recover the revokation cert. + of an archive key. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is then used to produce 12 shares of + which 7 are needed to recover the revokation cert. This procedure is for use in emergencies only (such as losing ftp-master.debian.org and all of the backups, a hopefully unlikely event) as the key can normally be used to produce its own revokation certificate.

+
+

Key Backup / Restore Procedure

+

After the creation of the archive key, the secret part of it will be backed up in one additional + way. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is used to produce 14 shares of which 9 are needed + to recover the secret key.

+ +
+

SSSS holders

+

The following people each hold one of the shares of the revocation certificate / private key.

+

Revocation shares

+

7 of those shares are needed to reproduce the revocation certificate

+ + + + + + + + + + + + + + +
Debian uidName
shoSamuel Hocevar
donDon Armstrong
neilmNeil McGovern
djpigFrank Lichtenheld
jimmyJimmy Kaplowitz
killerKalle Kivimaa
noodlesJonathan McDowell
rraRuss Allbery
margaMargarita Manterola
thijsThijs Kinkhorst
meikeMeike Reichle
miriamMiriam Ruiz
+ +

Key shares

+

9 of those shares are needed to reproduce the secret key

+ + + + + + + + + + + + + + + + +
Debian uidName
lukLuk Claes
maxxMartin Wuertele
adeodatoAdeodato Simó
myonChristoph Berg
93samSteve McIntyre
bdaleBdale Garbee
sgranStephen Gran
dannfDann Frazier
weaselPeter Palfrader
enricoEnrico Zini
wouterWouter Verhelst
mhyMark Hymers
bzedBernd Zeimetz
stewMike O'Connor
+

Debian FTP team