)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"e8fd4cd7ce8bbcf809021c8477d52fa296d9db45","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":7,"id":"83898661_55cd9cd5","updated":"2023-01-25 00:58:58.000000000","message":"recheck","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"}],"inventory/service/group_vars/bastion.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"7596a4e28b0758b7714b6a8e85346d1f146c3096","unresolved":true,"context_lines":[{"line_number":332,"context_line":"      - openstackci-security"},{"line_number":333,"context_line":""},{"line_number":334,"context_line":"make_tarball_encrypt_public_key: |"},{"line_number":335,"context_line":"  -----BEGIN PGP PUBLIC KEY BLOCK-----"},{"line_number":336,"context_line":""},{"line_number":337,"context_line":"  mQGNBGOJRksBDADH6TlSTOJQWiCjvtXmEYIUEPDHhHuCqY1u3Tqjr6Guv5h90BbF"},{"line_number":338,"context_line":"  OgdxmoqJd70/ShLGUSsxv2860K0H7iei0ShLxrH4Oxw8rMXRsfimA7tF08Hs3Qsd"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"e66c5a57_6eaeb46c","line":335,"updated":"2023-02-15 00:04:17.000000000","message":"Was this key generated with the intention that we would share the split password? If so I think I missed out on that? Or maybe we\u0027ll generate a new key and update this change when ready?","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"83a32404e14b3d3a18e49fa19a354d12385dfec5","unresolved":false,"context_lines":[{"line_number":332,"context_line":"      - openstackci-security"},{"line_number":333,"context_line":""},{"line_number":334,"context_line":"make_tarball_encrypt_public_key: |"},{"line_number":335,"context_line":"  -----BEGIN PGP PUBLIC KEY BLOCK-----"},{"line_number":336,"context_line":""},{"line_number":337,"context_line":"  mQGNBGOJRksBDADH6TlSTOJQWiCjvtXmEYIUEPDHhHuCqY1u3Tqjr6Guv5h90BbF"},{"line_number":338,"context_line":"  OgdxmoqJd70/ShLGUSsxv2860K0H7iei0ShLxrH4Oxw8rMXRsfimA7tF08Hs3Qsd"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"9b8b63a7_13d4d95e","line":335,"in_reply_to":"e66c5a57_6eaeb46c","updated":"2023-02-15 00:09:01.000000000","message":"Yes, this is considered the production key","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"}],"playbooks/roles/import-gpg-key/tasks/main.yaml":[{"author":{"_account_id":4146,"name":"Clark Boylan","email":"cboylan@sapwetik.org","username":"cboylan"},"change_message_id":"7596a4e28b0758b7714b6a8e85346d1f146c3096","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    # wants to communicate with a tty if you do something obvious like"},{"line_number":36,"context_line":"    # \"gpg --edit-key \u003cid\u003e ...\".  And what is menu option number \"5\""},{"line_number":37,"context_line":"    # is actually \"6\" in the ownertrust db!"},{"line_number":38,"context_line":"    - name: Trust key"},{"line_number":39,"context_line":"      shell: |"},{"line_number":40,"context_line":"          echo $(gpg --fingerprint {{ gpg_key_id }} | sed -n  \"s/ //g;2 p\"):6: | gpg --import-ownertrust"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"fbf45ca5_0c425b71","line":38,"updated":"2023-02-15 00:04:17.000000000","message":"Why do we need to trust the key if we are using it to encrypt something? Trust is for signing not encryption right? Mostly I don\u0027t want to trust something unless we need to.","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"0fb45dd1ca3584ba65a53f722f5044cb8649bbf1","unresolved":false,"context_lines":[{"line_number":35,"context_line":"    # wants to communicate with a tty if you do something obvious like"},{"line_number":36,"context_line":"    # \"gpg --edit-key \u003cid\u003e ...\".  And what is menu option number \"5\""},{"line_number":37,"context_line":"    # is actually \"6\" in the ownertrust db!"},{"line_number":38,"context_line":"    - name: Trust key"},{"line_number":39,"context_line":"      shell: |"},{"line_number":40,"context_line":"          echo $(gpg --fingerprint {{ gpg_key_id }} | sed -n  \"s/ //g;2 p\"):6: | gpg --import-ownertrust"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"5220cfbd_e73fbfcd","line":38,"in_reply_to":"45303299_d1345678","updated":"2023-02-15 08:35:10.000000000","message":"we can actually use this from a file.  i\u0027ve reworked this into https://review.opendev.org/c/opendev/system-config/+/865784\n\nthanks for the comments!","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"},{"author":{"_account_id":7118,"name":"Ian Wienand","email":"iwienand@redhat.com","username":"iwienand"},"change_message_id":"83a32404e14b3d3a18e49fa19a354d12385dfec5","unresolved":true,"context_lines":[{"line_number":35,"context_line":"    # wants to communicate with a tty if you do something obvious like"},{"line_number":36,"context_line":"    # \"gpg --edit-key \u003cid\u003e ...\".  And what is menu option number \"5\""},{"line_number":37,"context_line":"    # is actually \"6\" in the ownertrust db!"},{"line_number":38,"context_line":"    - name: Trust key"},{"line_number":39,"context_line":"      shell: |"},{"line_number":40,"context_line":"          echo $(gpg --fingerprint {{ gpg_key_id }} | sed -n  \"s/ //g;2 p\"):6: | gpg --import-ownertrust"}],"source_content_type":"text/x-yaml","patch_set":7,"id":"45303299_d1345678","line":38,"in_reply_to":"fbf45ca5_0c425b71","updated":"2023-02-15 00:09:01.000000000","message":"You do have to trust things to sign with gpg -- I guess GPG wants to verify that you have thought about the trust of the key you\u0027re encrypting to (avoiding something like a man-in-the-middle where they say \"here use this to encrypt\" and you don\u0027t verify the fingerprint with the real person or something?)","commit_id":"e575afc612b94fdc4136d586c1b05db64328fde2"}]}
