How to sign multiple PGP keys at once?
Hello all, I know this is pretty late, but I wanted to ask what the easiest way to sign multiple PGP keys and email them automatically is. I know there's a few different ways to do this, but oddly it's pretty tricky to find anything helpful on Google. I normally use Pius… https://www.phildev.net/pius/ …however, it's incompatible with newer versions of GPG and the upstream is slow to respond (I filed the bug in February). https://github.com/jaymzh/pius/issues/52 Instead of waiting around, I'd like to get my signatures sent out ASAP. I have all the keys on a key ring on my local system. What are you all using to do this and are there any good docs / how-tos you know of that you can link? Thanks in advance! -- Cheers, Justin W. Flory jflory7@gmail.com
On Wed, 21 Jun 2017 20:16:00 +0000, Justin W. Flory wrote:
I know this is pretty late, but I wanted to ask what the easiest way to sign multiple PGP keys and email them automatically is. I know there's a few different ways to do this, but oddly it's pretty tricky to find anything helpful on Google.
I'm still a happy user of caff. The last time I used it, with modern gnupg, I first had to stop the gpg-agent and/or dirmngr which where running on my system [0]; after that it worked as normal. Cheers, gregor [0] gpgconf --kill gpg-agent gpgconf --kill dirmngr -- .''`. https://info.comodo.priv.at/ - Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe `- NP: Tracy Chapman: Telling Stories
On 06/21/2017 05:32 PM, gregor herrmann wrote:
On Wed, 21 Jun 2017 20:16:00 +0000, Justin W. Flory wrote:
I know this is pretty late, but I wanted to ask what the easiest way to sign multiple PGP keys and email them automatically is. I know there's a few different ways to do this, but oddly it's pretty tricky to find anything helpful on Google.
I'm still a happy user of caff.
The last time I used it, with modern gnupg, I first had to stop the gpg-agent and/or dirmngr which where running on my system [0]; after that it worked as normal.
Thanks Gregor, caff was the tool I was trying to remember. I found it in Fedora packaged under `gpg-tools`. However, do you know of any way to get caff to use a GPG keyring to sign keys, or did you all hand-type 100+ key IDs when you all signed everyone else's keys? I'm curious if anyone has a faster way of using caff to sign this many keys, especially if they're already on a standalone keyring. Thanks! -- Cheers, Justin W. Flory jflory7@gmail.com
On Fri, 23 Jun 2017 21:46:00 +0000, Justin W. Flory wrote:
Thanks Gregor, caff was the tool I was trying to remember. I found it in Fedora packaged under `gpg-tools`. However, do you know of any way to get caff to use a GPG keyring to sign keys, or did you all hand-type 100+ key IDs when you all signed everyone else's keys?
caff can read the key IDs from KSP lists: caff [-eERS] [-m yes|ask-yes|ask-no|no] [-u yourkeyid] [keyid ..] </path/to/ksp-annotated.txt ^^^^^^^^^^^^^^^^^^^^^^^^^^ [..] The list of keys to sign can also be provided through caff's standard input, as gpgparticipants(1) formatted content. Only keys for which both the "Fingerprint OK" and "ID OK" boxes are ticked (i.e., marked with an "x") are considered for signing. Furthermore, the input header must include at least one checksum line, and all checksum boxes must be marked as verified (with an "x"). I'm not sure if it works with FOSDEM's key list but it might be worth a try.
I'm curious if anyone has a faster way of using caff to sign this many keys, especially if they're already on a standalone keyring.
The keyring contains more keys than what you are probably going to sign, so somehow you need to specify which ones to pick. Cheers, gregor -- .''`. https://info.comodo.priv.at/ - Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe `- NP: Beatles
I used caff last year to sign the keys from FOSDEM. I needed some sed-magic to convert the list to a format understood by caff. Apart from that, it worked flawlessly! On 24/06/17 00:25, gregor herrmann wrote:
On Fri, 23 Jun 2017 21:46:00 +0000, Justin W. Flory wrote:
Thanks Gregor, caff was the tool I was trying to remember. I found it in Fedora packaged under `gpg-tools`. However, do you know of any way to get caff to use a GPG keyring to sign keys, or did you all hand-type 100+ key IDs when you all signed everyone else's keys?
caff can read the key IDs from KSP lists:
caff [-eERS] [-m yes|ask-yes|ask-no|no] [-u yourkeyid] [keyid ..] </path/to/ksp-annotated.txt ^^^^^^^^^^^^^^^^^^^^^^^^^^ [..] The list of keys to sign can also be provided through caff's standard input, as gpgparticipants(1) formatted content. Only keys for which both the "Fingerprint OK" and "ID OK" boxes are ticked (i.e., marked with an "x") are considered for signing. Furthermore, the input header must include at least one checksum line, and all checksum boxes must be marked as verified (with an "x").
I'm not sure if it works with FOSDEM's key list but it might be worth a try.
I'm curious if anyone has a faster way of using caff to sign this many keys, especially if they're already on a standalone keyring.
The keyring contains more keys than what you are probably going to sign, so somehow you need to specify which ones to pick.
Cheers, gregor
_______________________________________________ FOSDEM mailing list FOSDEM@lists.fosdem.org https://lists.fosdem.org/listinfo/fosdem
On 06/23/2017 05:32 PM, Andreas Gnau wrote:
I used caff last year to sign the keys from FOSDEM. I needed some sed-magic to convert the list to a format understood by caff.
Apart from that, it worked flawlessly!
Do you have this a script for that sed-magic lying around somewhere? Sadly, I seem to have misplaced my papers from the event, but I put all of the keys that I verified in person onto this specific keyring file some months ago. I could start with the original list, but it feels like it might just be easier to sign and send the keys manually then to go through this. Alternatively, I might keep waiting for pius to push a fix or open a CentOS VM and share my public/private key there, but that also seems a little tedious too. Thanks anyways for all of this feedback! -- Cheers, Justin W. Flory jflory7@gmail.com
On Sat, 24 Jun 2017 02:33:00 +0000, Justin W. Flory wrote:
Sadly, I seem to have misplaced my papers from the event, but I put all of the keys that I verified in person onto this specific keyring file some months ago.
In that case I'd probably just try to extract the key IDs from the keyring, like: % gpg --no-default-keyring --keyring=$KEYRING --list-keys --list-options no-show-photos 2>/dev/null | egrep "^pub" | awk '{print $2}' | cut -f2 -d Cheers, gregor -- .''`. https://info.comodo.priv.at/ - Debian Developer https://www.debian.org : :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06 `. `' Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe `- NP: Status Quo: In The Army Now
On 06/23/2017 10:14 PM, gregor herrmann wrote:
On Sat, 24 Jun 2017 02:33:00 +0000, Justin W. Flory wrote:
Sadly, I seem to have misplaced my papers from the event, but I put all of the keys that I verified in person onto this specific keyring file some months ago.
In that case I'd probably just try to extract the key IDs from the keyring, like:
% gpg --no-default-keyring --keyring=$KEYRING --list-keys --list-options no-show-photos 2>/dev/null | egrep "^pub" | awk '{print $2}' | cut -f2 -d
Cheers, gregor
Thanks for the help, all. As it turns out, I found a fix for using pius… https://github.com/jaymzh/pius/issues/52 I just sent out all of my signatures, albeit a bit late. Also, some people may have received double emails from me, the process interrupted the first time around and some of the first keys in the keyring probably were emailed twice. Sorry for any extra noise. -- Cheers, Justin W. Flory jflory7@gmail.com
participants (3)
-
Andreas Gnau -
gregor herrmann -
Justin W. Flory