Project

General

Profile

Actions

Feature #1935

closed

Document and/or decide on the Replicant project signing and encryption key usage and policies

Added by Denis 'GNUtoo' Carikli almost 6 years ago. Updated over 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
Website and wiki content
Target version:
Start date:
05/13/2019
Due date:
% Done:

100%

Estimated time:
Resolution:
fixed
Device:
Grant:
Type of work:

Related issues

Blocks Replicant - Issue #1960: Build release candidate image for 6.0 0004Closed10/09/2019

Actions
Actions #1

Updated by Denis 'GNUtoo' Carikli almost 6 years ago

  • Subject changed from Document and/or decide on the Replicant project gpg key usage and policies to Document and/or decide on the Replicant project signing and encryption key usage and policies

Replicant mainly uses gpg for signing the releases.

The gpg key is also setup for the contact address, but it's use is highly discouraged as not everyone has access to that key.

Some people already used that gpg (public) key to send encrypted logs with potentially privacy sensitive information in bugreports, but as not everyone has access to that key currently only developers not participating anymore in Replicant can read such logs.

See the following for some examples of gpg usage:
https://tails.boum.org/doc/about/openpgp_keys/index.en.html

Building Replicant also generates some TLS signing keys to sign the images:
  • Keys are used by the recovery to verify the installation zip.
  • Keys are also used to sign apk within the Replicant image.
  • Keys might also be used for generating OTA upgrades, but that is currently unused by Replicant.
Actions #2

Updated by Denis 'GNUtoo' Carikli almost 6 years ago

  • Category set to Website and wiki content
Actions #3

Updated by Kurtis Hanna over 5 years ago

  • Blocked by Issue #1960: Build release candidate image for 6.0 0004 added
Actions #4

Updated by Kurtis Hanna over 5 years ago

  • Blocked by deleted (Issue #1960: Build release candidate image for 6.0 0004)
Actions #5

Updated by Kurtis Hanna over 5 years ago

  • Blocks Issue #1960: Build release candidate image for 6.0 0004 added
Actions #8

Updated by Kurtis Hanna over 5 years ago

  • % Done changed from 0 to 100

We should create a new issue, if it isn't created already, related to using a keyring with the public key of several Replicant developers, like it is done in Parabola with the parabola-keyring package, as is discussed at the link GNUtoo provided above.

Actions

Also available in: Atom PDF