Keysigning: please submit your keys
The keysigning infrastructure seems to have held up well this year. I spent some time today preparing the infrastructure for FOSDEM 2011. Same procedure as last year: if you intend to participate in the keysigning event, please submit the keys you'd like to have signed to ksp.fosdem.org. If you're using GnuPG, that can be easily accomplished with: % gpg --keyserver ksp.fosdem.org --send-key <your-keyid> Please check that your key was correctly submitted by pointing a webbrowser at http://ksp.fosdem.org/. If your key is missing after you submitted it, send me an email and I'll try to find out what's up. Key submissions close Monday before FOSDEM to give me some time to try to remember how I generated the lists again. Get submitting. - Philip -- Philip Paeps Please don't Cc me, I am philip@fosdem.org subscribed to the list.
The keysigning infrastructure seems to have held up well this year. I spent some time today preparing the infrastructure for FOSDEM 2011. As you are now promoting the KSP here (and on twitter) allow me to suggest that the KSP organizers recommend
On 12/21/2010 09:17 AM, Philip Paeps wrote: that attendees consider generating stronger 4096 RSA keys [0] if they have not already and double check the GPG configuration for signature strength SHA-512 [1][2][3]. In preparing for the Debconf 10 KSP [4] several resources were assembled to help in this process [5][6]. I created a small program, kspsig, to help verify signature strength [7]. HTH, --Tom [0] https://we.riseup.net/riseuplabs+paow/openpgp-best-practices#primary-keys-sh... [1] https://lists.debian.org/debian-devel-announce/2009/05/msg00005.html [2] http://www.gnupg.org/faq/weak-digest-algos.html [3] http://csrc.nist.gov/groups/ST/hash/statement.html [4] http://people.debian.org/~anibal/ksp-dc10/ksp-dc10.html [5] http://keyring.debian.org/creating-key.html [6] http://www.debian-administration.org/users/dkg/weblog/48 [7] https://github.com/tmarble/kspsig
On 2010-12-23 07:41:01 (-0600), Tom Marble <tmarble@info9.net> wrote:
On 12/21/2010 09:17 AM, Philip Paeps wrote:
The keysigning infrastructure seems to have held up well this year. I spent some time today preparing the infrastructure for FOSDEM 2011.
As you are now promoting the KSP here (and on twitter)
Ehm, I'm not promoting anything on twitter. I don't believe in systems that are designed for more overhead than data. I hope whoever is sending stuff to twitter is not doing so in my name. When in doubt, only this mailing list is authoritative.
allow me to suggest that the KSP organizers recommend that attendees consider generating stronger 4096 RSA keys [0] if they have not already and double check the GPG configuration for signature strength SHA-512 [1][2][3].
In preparing for the Debconf 10 KSP [4] several resources were assembled to help in this process [5][6]. I created a small program, kspsig, to help verify signature strength [7].
The keyserver could probably be modified to reject weak keys. Alternatively, I could also run a cronjob over the submitted keys nightly and email the UIDs if the keys are weak. I'll take a look at your program. - Philip -- Philip Paeps Please don't Cc me, I am philip@fosdem.org subscribed to the list.
On 2010-12-21 16:17:25 (+0100), Philip Paeps <philip@fosdem.org> wrote:
The keysigning infrastructure seems to have held up well this year. I spent some time today preparing the infrastructure for FOSDEM 2011.
If you like graphs and statistics, you may find http://ksp.fosdem.org/graphs/ amusing. Last years graphs are at http://ksp.fosdem.org/2010/graphs/. The submissions.png graphs tracks key submissions per day. It is generated by a questionable perl script every night. Karlheinz Geyer generates the much prettier SVG graphs of the web of trust (thanks). I'll try to find something witty and interesting to say about the final graphs at FOSDEM before I send everybody out into the Big Blue Room to go sign each other's keys. ;-) In the mean time: don't forget to submit your keys! - Philip -- Philip Paeps Please don't Cc me, I am philip@fosdem.org subscribed to the list.
participants (2)
-
Philip Paeps -
Tom Marble