Feature #11747

Update our OpenPGP keys in 2017

Added by intrigeri 2016-08-30 03:25:05 . Updated 2017-09-28 18:42:29 .

Status:
Resolved
Priority:
Normal
Assignee:
Category:
Target version:
Start date:
2016-08-30
Due date:
% Done:

100%

Feature Branch:
feature/14483-new-signing-subkeys
Type of work:
Code
Blueprint:

Starter:
Affected tool:
Deliverable for:

Description

What we’re supposed to do each year:

  • Bump the signing key’s expiration date by 1 year.
  • Generate a new signing subkey for each RM, and move it onto new smartcards (the old ones are still needed to keep the previous subkey during the transition period).
  • If needed, generate and split a revocation certificate for our signing key. See internal.git for details.
  • Create a ticket about updating our OpenPGP keys next year.

To be done at the summit during northern hemisphere summer.


Subtasks

Feature #11749: Get more OpenPGP smartcard hardware Resolved

100

Feature #14483: Include the new signing subkeys & publish them on keyservers Resolved

100

Feature #14485: Distribute shares of our updated signing key Resolved anonym

100


Related issues

Related to Tails - Feature #11572: Update our OpenPGP keys in 2016 Resolved 2016-07-16
Related to Tails - Feature #14484: Update our OpenPGP keys in 2018 Resolved 2017-09-01
Blocks Tails - Feature #13234: Core work 2017Q3: Foundations Team Resolved 2017-06-29

History

#1 Updated by intrigeri 2016-08-30 03:27:11

#2 Updated by intrigeri 2016-08-30 03:28:05

  • Description updated

#3 Updated by intrigeri 2016-08-30 05:22:37

  • Description updated

#4 Updated by intrigeri 2017-06-05 13:53:35

  • Target version changed from 2017 to Tails_3.2

#5 Updated by intrigeri 2017-08-28 17:10:05

#6 Updated by intrigeri 2017-08-28 18:49:45

#7 Updated by intrigeri 2017-09-04 09:59:21

  • Status changed from Confirmed to In Progress

#8 Updated by intrigeri 2017-09-07 12:58:26

  • Type of work changed from Sysadmin to Code

#9 Updated by intrigeri 2017-09-18 14:40:31

  • Assignee changed from intrigeri to anonym
  • QA Check set to Ready for QA
  • Feature Branch set to feature/14483-new-signing-subkeys

#10 Updated by anonym 2017-09-21 22:49:47

  • Status changed from In Progress to Fix committed
  • Assignee deleted (anonym)
  • QA Check changed from Ready for QA to Pass

#11 Updated by anonym 2017-09-28 18:42:29

  • Status changed from Fix committed to Resolved