BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] [BLU/Officers] update instructions for key signing
- Subject: [Discuss] [BLU/Officers] update instructions for key signing
- From: bill at horne.net (Bill Horne)
- Date: Mon, 17 Sep 2018 11:05:48 -0400
- In-reply-to: <CAAbKA3V_=5Hy=SwtZxM2JH1eZ7pTYzXPoX8LW--crkgpB6efQg@mail.gmail.com>
- References: <CAPOg-Py6+yYCcEKNYESd73Vp+CMgSyM8htPtte8ZAj1t-VTJSg@mail.gmail.com> <CAPOg-PwcihOuHn_vmpUz14ncXqvnikUftp-8COt3_rVadVWgNQ@mail.gmail.com> <CAPOg-PzP9iRU1bn=bQdMF=k3BOOsuyWyUBUJfqSmDi5aWM25_w@mail.gmail.com> <CAPOg-Py+j5d3z6X8mrYJ+BGSc7=97k-ddub=3wPiYsd==uJwpA@mail.gmail.com> <CAAbKA3V_=5Hy=SwtZxM2JH1eZ7pTYzXPoX8LW--crkgpB6efQg@mail.gmail.com>
Bill, I've got a question about GPG, or actually about PKI in general. Since my browser now flags non-https sites as "Unsecure," I'd like to know how to generate a key to put in my Apache setup which will swing the padlocks shut. I know that it won't be "valid" unless I import the key into my browser, but that's a one-time effort and will stop the "unsecure" messages when I ask people to visit my websites. Also, if possible, I'd like to be able to pass out keys for users to use in lieu of passwords to access secured areas. Please tell me how to go about that, and thanks in advance. Bill On 9/16/2018 11:41 PM, Bill Ricker wrote: > > * We will NO LONGER sign RSA or DSA 1024b keys (or shorter). Obsolete. > * We will NOT sign RSA 2048b keys without expiration dates orwith > expiration dates beyond 2020. > * Use RSA 4096 or ed25519 for gpg2 --gen-key > > Notes > * If concerned about well-capitalized massive factoring dictionaries, > subtract a small multiple of 8 bits to get a size that is not standard > and thus won't be dictionaried. > * Alas the one trustworthy ECC curve,? ed25519, is supported only in > GPG 2.1.7+ (gpg2), but if you have recent Ubuntu you you can use it now. > ? See https://nickhu.co.uk/posts/2016-09-03-curvy-gpg/ for instructions > GPG2 gives a warning that it's not yet standardized so i'm considering > it still somewhat expriemental ... i'm going to try a 10y expiring on > this > > > > > > > > > > > > > > > > > _______________________________________________ > Announce mailing list > Announce at blu.org <mailto:Announce at blu.org> > http://lists.blu.org/mailman/listinfo/announce > > > -- > Bill Ricker > bill.n1vux at gmail.com <mailto:bill.n1vux at gmail.com> > https://www.linkedin.com/in/n1vux > > > _______________________________________________ > Officers mailing list > Officers at blu.org > http://lists.blu.org/mailman/listinfo/officers -- Bill Horne 828-678-1548 (Cell)
- Follow-Ups:
- [Discuss] [BLU/Officers] update instructions for key signing
- From: dsr at randomstring.org (Dan Ritter)
- [Discuss] [BLU/Officers] update instructions for key signing
- Prev by Date: [Discuss] Geeqie problem with thumbnail checkboxes
- Next by Date: [Discuss] [BLU/Officers] update instructions for key signing
- Previous by thread: [Discuss] Geeqie problem with thumbnail checkboxes
- Next by thread: [Discuss] [BLU/Officers] update instructions for key signing
- Index(es):