keys and keysigning questions
I have a few questions about the key signing event on Sunday. CACert Signing On the keysigning page, here is a recommendation to print 20-40 copies of the WoT form. As far as I can see at the CACert Wiki (http://wiki.cacert.org/wiki/FAQ/AssuranceDetails#head- ca7832ef2e3dec5ccec2deff91d7b6c04bf425a6) assurers with 100 points (the minimum to be able to assure others) can issue 10 points. So with only 100-point assurers, 15 would suffice to issue the maximum of 150 points to the assuree. 1) Why do we need to print 20-40 copies when 15 copies would suffice, or even as few as 5 (assuming 150-point assurers granting 35 points each)? What about the trees? What about the toner forests? What about the empty inkjet cartridges crying in the night? GPG/PGP Keysigning 2) How many copies of the (16 page) document do I need to print and fill in the checksums? 3) If I add another email address to my identity (I only have one on it now), is the key as signed at the keysigning automatically valid for that address (or is my question already showing my lack of understanding)? 4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works? Thanks, John John Seifarth Words & Wires SPRL Computer Consulting & Language Services rue Valduc 266 1160 Brussels, Belgium Voice: + 32-2-660-3943 GSM: +32 478 42 45 20 Fax: + 32-2-675-3922 john@waw.be
On Fri, 23 Feb 2007, John Seifarth wrote:
GPG/PGP Keysigning
2) How many copies of the (16 page) document do I need to print and fill in the checksums?
1.
3) If I add another email address to my identity (I only have one on it now), is the key as signed at the keysigning automatically valid for that address (or is my question already showing my lack of understanding)?
When signing a key, GPG will ask whether you want to sign all email adresses. Some people won't say `Y' if your new email address is not on the list.
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
gpg --recv-key --keyserver pgp.mit.edu <id> gpg --send-key --keyserver pgp.mit.edu <id> You can also put the keyserver in your ~/.gnupg/options. Gr{oetje,eeting}s, Geert -- Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org In personal conversations with technical people, I call myself a hacker. But when I'm talking to journalists I just say "programmer" or something like that. -- Linus Torvalds
On Fri, Feb 23, 2007 at 05:44:02PM +0100, John Seifarth wrote:
I have a few questions about the key signing event on Sunday. [...] GPG/PGP Keysigning
2) How many copies of the (16 page) document do I need to print and fill in the checksums?
Just one.
3) If I add another email address to my identity (I only have one on it now), is the key as signed at the keysigning automatically valid for that address (or is my question already showing my lack of understanding)?
That will depend on the participants; some people will sign your new UID, others won't. It may help if you communicate that you have a new UID on your key at the signing party.
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
Make sure the following line is found in your ~/.gnupg/gpg.conf: keyserver hkp://subkeys.pgp.net Then, you can search for keys with gpg --recv-key <data> where you replace <data> with either the mail address or the key ID of your correspondent. After signing the key, please do not randomly upload them; you should also attempt to verify that the email address of the key you signed is valid. An easy way to do that is to encrypt and mail the key to the key owner; the 'caff' script can help you with this. You can find caff in the Debian package 'signing-party'; it's a perl script. I'll be sure to repeat this at the beginning of the signing party on sunday. -- <Lo-lan-do> Home is where you have to wash the dishes. -- #debian-devel, Freenode, 2004-09-22
* Wouter Verhelst <wouter@debian.org> wrote:
3) If I add another email address to my identity (I only have one on it now), is the key as signed at the keysigning automatically valid for that address (or is my question already showing my lack of understanding)?
That will depend on the participants; some people will sign your new UID, others won't. It may help if you communicate that you have a new UID on your key at the signing party.
I guess I would sign the new UID... however, it would be a good idea to also prepare additional paper slips with key fingerprints, just in case. -- left blank, right bald
John Seifarth wrote:
I have a few questions about the key signing event on Sunday.
CACert Signing
On the keysigning page, here is a recommendation to print 20-40 copies of the WoT form. As far as I can see at the CACert Wiki (http://wiki.cacert.org/wiki/FAQ/AssuranceDetails#head-ca7832ef2e3dec5ccec2de...) assurers with 100 points (the minimum to be able to assure others) can issue 10 points. So with only 100-point assurers, 15 would suffice to issue the maximum of 150 points to the assuree.
1) Why do we need to print 20-40 copies when 15 copies would suffice, or even as few as 5 (assuming 150-point assurers granting 35 points each)? What about the trees? What about the toner forests? What about the empty inkjet cartridges crying in the night?
You're right, 5 should be plenty. BTW, what CAcert assurers will be there? I would be happy to do some assuring but I have to give a talk at 12:30 so I can't be there for the entire hour. Peter -- Peter Saint-Andre XMPP Standards Foundation http://www.xmpp.org/xsf/people/stpeter.shtml
Hi, Op vr 23 feb 2007 om 05:44:02 +0100 schreef John Seifarth: <snip>
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
If you happen to speak dutch, you might like to check out http://mdcc.cx/gnupg/gpg_5_min.html . HTH, Bye, Joost
On 23 Feb 2007, at 19:40, Joost van Baal wrote:
Hi,
Op vr 23 feb 2007 om 05:44:02 +0100 schreef John Seifarth: <snip>
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
If you happen to speak dutch, you might like to check out http://mdcc.cx/gnupg/gpg_5_min.html .
HTH, Bye,
Joost
Since I'm American-born, I have an excuse for being language-challenged. I can only read English and French (although I understand enough spoken Italian to better appreciate the lovely women presenting the news on the RAI). If you have a pointer toward info on general GPG key management, beyond man pages for the commands to create or use them, in the two first languages above, I'd be most appreciative. Thanks, John John Seifarth Words & Wires SPRL Computer Consulting & Language Services rue Valduc 266 1160 Brussels, Belgium Voice: + 32-2-660-3943 GSM: +32 478 42 45 20 Fax: + 32-2-675-3922 john@waw.be
Hi, Op vr 23 feb 2007 om 09:36:13 +0100 schreef John Seifarth:
On 23 Feb 2007, at 19:40, Joost van Baal wrote:
Op vr 23 feb 2007 om 05:44:02 +0100 schreef John Seifarth: <snip>
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
If you happen to speak dutch, you might like to check out http://mdcc.cx/gnupg/gpg_5_min.html .
Since I'm American-born, I have an excuse for being language-challenged.
I can only read English and French (although I understand enough spoken Italian to better appreciate the lovely women presenting the news on the RAI).
If you have a pointer toward info on general GPG key management, beyond man pages for the commands to create or use them, in the two first languages above, I'd be most appreciative.
2 big manuals: http://www.gnupg.org/gph/en/manual.html http://cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.html 1 small one about keysigning parties: http://people.debian.org/~stevenk/keysigning.html NB: that one describes a simpler setup of the party than what's gonna happen at fosdem. Bye, Joost
On Fri, 23 Feb 2007, John Seifarth wrote:
On 23 Feb 2007, at 19:40, Joost van Baal wrote:
Op vr 23 feb 2007 om 05:44:02 +0100 schreef John Seifarth: <snip>
4) What is the best way to disseminate my public key, and to get the public keys of my correspondants? I understand there are key servers somewhere, can someone explain how this works?
If you happen to speak dutch, you might like to check out http://mdcc.cx/gnupg/gpg_5_min.html .
HTH, Bye,
Joost
Since I'm American-born, I have an excuse for being language-challenged.
I can only read English and French (although I understand enough spoken Italian to better appreciate the lovely women presenting the news on the RAI).
If you have a pointer toward info on general GPG key management, beyond man pages for the commands to create or use them, in the two first languages above, I'd be most appreciative.
The info for the FOSDEM keysigning party a few years ago may help: http://www.ael.be/action/gnupg/fosdem/ Gr{oetje,eeting}s, Geert -- Geert Uytterhoeven -- There's lots of Linux beyond ia32 -- geert@linux-m68k.org In personal conversations with technical people, I call myself a hacker. But when I'm talking to journalists I just say "programmer" or something like that. -- Linus Torvalds
participants (6)
-
Geert Uytterhoeven -
John Seifarth -
Joost van Baal -
markus reichelt -
Peter Saint-Andre -
Wouter Verhelst