Skip to content
This repository was archived by the owner on Nov 12, 2022. It is now read-only.

Conversation

@maflcko
Copy link

@maflcko maflcko commented Dec 15, 2017

No description provided.

@maflcko
Copy link
Author

maflcko commented Dec 16, 2017

Since commits to this repo are not signed and it is less monitored than the main repo, an attacker would have an easier job to compromise it. They consequently compromise all users that only rely on the signatures and don't Gitian-build for themselves or take part in the web of trust.

Closing.

@maflcko maflcko closed this Dec 16, 2017
@maflcko maflcko deleted the keys branch December 16, 2017 00:42
laanwj added a commit to bitcoin/bitcoin that referenced this pull request Feb 6, 2018
…prints

fabb72b contrib: Remove xpired 522739F6 key (MarcoFalke)
faeab66 contrib: Replace developer keys with list of pgp fingerprints (MarcoFalke)

Pull request description:

  Having to host a copy of the keys in this repo was a common source of discussion and distraction, caused by problems such as:

  * Outdated keys. Unclear whether and when to replace by fresh copies.
  * Unclear when to add a key of a new developer or Gitian builder.

  The problems are solved by
  * Having no keys but only the fingerprints
  * Adding a rule of thumb, when to add a new key

  <strike>Moving the keys to a different repo solves none of these issues, but since the keys are not bound to releases or git branches of Bitcoin Core, they should live somewhere else.

  Obviously, all keys are hosted and distributed on key servers, but were added to the repo solely for convenience and redundancy.

  Moving the mirror of those keys to a different repo makes it less distracting to update them -- let's say -- prior to every major release.

  I updated our `doc/release-process.md` to reflect the new location.

  DEPENDS_ON bitcoin-core/gitian.sigs#621
  </strike>

Tree-SHA512: c00795a07603190e26dc4526f6ce11e492fb048dc7ef54b38f859b77dcde25f58ec4449f5cf3f85a5e9c2dd2743bde53f7ff03c8eccf0d75d51784a6b164e47d
@bitcoin-core bitcoin-core locked and limited conversation to collaborators Nov 12, 2022
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant