X-Git-Url: https://git.decadent.org.uk/gitweb/?a=blobdiff_plain;f=web%2Fkeys.html;h=78e35474bae44e73e1c2a7569a7fc56cb0f0477e;hb=44345b75a64b07c5b7255b782db57427478c4882;hp=7fd38e85af70d2c7efde2d6e87372f9f716ab424;hpb=c8317a2f52faed3832df6aee238cf9e04e7f49e6;p=dak.git diff --git a/web/keys.html b/web/keys.html index 7fd38e85..78e35474 100644 --- a/web/keys.html +++ b/web/keys.html @@ -115,16 +115,67 @@
-

Key Revokation Procedure

+

Key Revocation Procedure

A revokation certificate for the archive key is produced at the time of the creation - of an archive key. The program ssss (a Shamir's secret sharing scheme implementation) - is then used to produce 20 shares of which 10 are needed to recover the revokation cert. + of an archive key. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is then used to produce 12 shares of + which 7 are needed to recover the revokation cert. This procedure is for use in emergencies only (such as losing ftp-master.debian.org and all of the backups, a hopefully unlikely event) as the key can normally be used to produce its own revokation certificate.

+
+

Key Backup / Restore Procedure

+

After the creation of the archive key, the secret part of it will be backed up in one additional + way. The program gfshare (package + libgfshare-bin) + (a Shamir's secret sharing scheme implementation) is used to produce 14 shares of which 9 are needed + to recover the secret key.

+ +
+

SSSS holders

+

The following people each hold one of the shares of the revocation certificate / private key.

+

Revocation shares

+

7 of those shares are needed to reproduce the revocation certificate

+ + + + + + + + + + + + + + +
Debian uidName
shoSamuel Hocevar
donDon Armstrong
neilmNeil McGovern
djpigFrank Lichtenheld
jimmyJimmy Kaplowitz
killerKalle Kivimaa
noodlesJonathan McDowell
rraRuss Allbery
margaMargarita Manterola
thijsThijs Kinkhorst
meikeMeike Reichle
miriamMiriam Ruiz
+ +

Key shares

+

9 of those shares are needed to reproduce the secret key

+ + + + + + + + + + + + + + + + +
Debian uidName
lukLuk Claes
maxxMartin Wuertele
adeodatoAdeodato Simó
myonChristoph Berg
93samSteve McIntyre
bdaleBdale Garbee
sgranStephen Gran
dannfDann Frazier
weaselPeter Palfrader
enricoEnrico Zini
wouterWouter Verhelst
mhyMark Hymers
bzedBernd Zeimetz
stewMike O'Connor
+

Debian FTP team