-
-
Notifications
You must be signed in to change notification settings - Fork 1
Create release signing key policy #1905
Copy link
Copy link
Open
Description
Gpg signature is a crucial component of our release artifacts but we don't have any policy for release signing key where would described who can access it, what the format is, rotation period, what should be in case of leaking.
Acceptance criteria
- policy is published on https://github.com/openssl/general-policies
- policy describes:
- who can own release signing key
- where it's stored
- release signing key format
- rotation period
- actions in case of leaking
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels
Type
Projects
Status
To do
Status
Pre-Refinement