X-Git-Url: https://git.decadent.org.uk/gitweb/?a=blobdiff_plain;f=web%2Fkeys.html;h=55036e9d13cd42810507bb594429920bb7324964;hb=b612f3da207fa0d75a5d3b204ac8f02bb244231a;hp=2fbb8ecede48a48b97dd1ede7b8901f22533ff7d;hpb=a387558a9634102f7b5624f397c48609748c48c7;p=dak.git diff --git a/web/keys.html b/web/keys.html index 2fbb8ece..55036e9d 100644 --- a/web/keys.html +++ b/web/keys.html @@ -67,23 +67,25 @@

Archive Keys

Active Signing Keys

-

The current (2007/etch) key can be downloaded here

- -

Upcoming Signing Keys

-

The new key, which will be used after the 4.0 key expires or - after Lenny r1 is released, can be downloaded here. (The debian-devel announcement - regarding this key can be read at +

The current (2009/lenny) key can be downloaded here
+ The fingerprint of this key is 150C 8614 919D 8446 E01E 83AF 9AA3 8DCD 55BE 302B.
+ The announcements regarding this key can be read at - http://lists.debian.org/debian-devel-announce/2009/01/msg00008.html)

+ http://lists.debian.org/debian-devel-announce/2009/01/msg00008.html + and http://www.debian.org/News/2009/20090523. +

+ +

The soon-to-be-retired (2007/etch) key can be downloaded here.
+ The fingerprint of this key is A999 51DA F9BB 569B DB50 AD90 A70D AF53 6070 D3A1

Stable Keys

etch

-

Details of the etch key from the release team

+

The fingerprint of the etch stable release key is 7EA3 91D7 2477 203B 58C0 4FBC B5D0 C804 ADB1 1277

lenny

-

Details of the lenny key from the release team

+

The fingerprint of the lenny stable release key is 7F5A 4445 4C72 4A65 CBCD 4FB1 4D27 0D06 F425 84E6

Retired Signing Keys

The following retired and in most cases expired keys are @@ -115,16 +117,67 @@

-

Key Revokation Procedure

+

Key Revocation Procedure

A revokation certificate for the archive key is produced at the time of the creation - of an archive key. The program ssss (a Shamir's secret sharing scheme implementation) - is then used to produce 20 shares of which 10 are needed to recover the revokation cert. + of an archive key. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is then used to produce 12 shares of + which 7 are needed to recover the revokation cert. This procedure is for use in emergencies only (such as losing ftp-master.debian.org and all of the backups, a hopefully unlikely event) as the key can normally be used to produce its own revokation certificate.

+
+

Key Backup / Restore Procedure

+

After the creation of the archive key, the secret part of it will be backed up in one additional + way. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is used to produce 14 shares of which 9 are needed + to recover the secret key.

+ +
+

SSSS holders

+

The following people each hold one of the shares of the revocation certificate / private key.

+

Revocation shares

+

7 of those shares are needed to reproduce the revocation certificate

+ + + + + + + + + + + + + + +
Debian uidName
shoSamuel Hocevar
donDon Armstrong
neilmNeil McGovern
djpigFrank Lichtenheld
jimmyJimmy Kaplowitz
killerKalle Kivimaa
noodlesJonathan McDowell
rraRuss Allbery
margaMargarita Manterola
thijsThijs Kinkhorst
meikeMeike Reichle
miriamMiriam Ruiz
+ +

Key shares

+

9 of those shares are needed to reproduce the secret key

+ + + + + + + + + + + + + + + + +
Debian uidName
lukLuk Claes
maxxMartin Wuertele
adeodatoAdeodato Simó
myonChristoph Berg
93samSteve McIntyre
bdaleBdale Garbee
sgranStephen Gran
dannfDann Frazier
weaselPeter Palfrader
enricoEnrico Zini
wouterWouter Verhelst
mhyMark Hymers
bzedBernd Zeimetz
stewMike O'Connor
+

Debian FTP team