The list of participants for this weekend's keysigning event is now available. If you're taking part in the keysigning event, you should now: o Download the list: http://ksp.fosdem.org/files/ksp-fosdem2014.txt o Optionally, if there's a trust path between your PGP key and mine, verify the integrity of the file using the detached signature: http://ksp.fosdem.org/files/ksp-fosdem2014.txt.sig e.g. using: % gpg --verify ksp-fosdem2014.txt.sig ksp-fosdem2014.txt o Verify that your fingerprint as shown on the list is correct. o Print this list of keys with fingerprints on paper. o Calculate the checksums of the file holding the list of keys. e.g. using: % gpg --print-md RIPEMD160 ksp-fosdem2014.txt % gpg --print-md SHA256 ksp-fosdem2014.txt o Write the checksums you calculated in the designated blanks. o Don't lose the list, and bring it with you on Sunday, along with a pen and appropriate means of identification. See you Sunday!
On 01/28/2014 03:29 AM, Niels Laukens wrote:
This says "2013" but please do not change it now :) This is how I print the KSP sheet (in case this is helpful): # only crazy USA folks want '--paper letter' (instead of A4) $ paps --header --landscape --columns=2 --font="Courier 7" --paper letter --top-margin=18 --bottom-margin=18 ksp-fosdem2014.txt > ksp-fosdem2014.ps $ ps2pdf ksp-fosdem2014.ps Please use caff(1) from the package signing-party (after the KSP) to sign the keys at home. But BEWARE the default caff configuration is NOT the same as for GPG. Please make sure you are using the configuration settings you intend (esp. strong signature strength). For more information please see: https://github.com/tmarble/kspsig Here is how you can get a sense for who has already signed your key (NOTE: does NOT take into account that a given e-mail may be used with different key ID's): MYEMAIL=tmarble@info9.net MYID=0x40BFEE868B055D9A Unique list of who's on the FOSDEM KSP list $ awk '/<.*@.*>/ { print substr($NF,2,length($NF)-2); }' ksp-fosdem2014.txt | sort -u > ksp-emails.txt Unique list of who has signed my key: $ gpg --list-sigs $MYID | awk '/<.*@.*>/ { print substr($NF,2,length($NF)-2); }' | sort -u > signed-myid.txt Who has previously signed my key that's on the FOSDEM KSP list? $ comm -12 signed-myid.txt ksp-emails.txt | grep -v $MYEMAIL > already-signed.txt Regards, --Tom
On Tue, Jan 28, 2014 at 08:53:17AM -0600, Tom Marble wrote:
On 01/28/2014 03:29 AM, Niels Laukens wrote:
This says "2013" but please do not change it now :)
This is how I print the KSP sheet (in case this is helpful):
# only crazy USA folks want '--paper letter' (instead of A4) $ paps --header --landscape --columns=2 --font="Courier 7" --paper letter --top-margin=18 --bottom-margin=18 ksp-fosdem2014.txt > ksp-fosdem2014.ps $ ps2pdf ksp-fosdem2014.ps
Please use caff(1) from the package signing-party (after the KSP) to sign the keys at home. But BEWARE the default caff configuration is NOT the same as for GPG. Please make sure you are using the configuration settings you intend (esp. strong signature strength). For more information please see: https://github.com/tmarble/kspsig
Here is how you can get a sense for who has already signed your key (NOTE: does NOT take into account that a given e-mail may be used with different key ID's):
MYEMAIL=tmarble@info9.net MYID=0x40BFEE868B055D9A
Unique list of who's on the FOSDEM KSP list $ awk '/<.*@.*>/ { print substr($NF,2,length($NF)-2); }' ksp-fosdem2014.txt | sort -u > ksp-emails.txt
Unique list of who has signed my key: $ gpg --list-sigs $MYID | awk '/<.*@.*>/ { print substr($NF,2,length($NF)-2); }' | sort -u > signed-myid.txt
Who has previously signed my key that's on the FOSDEM KSP list? $ comm -12 signed-myid.txt ksp-emails.txt | grep -v $MYEMAIL > already-signed.txt
You might want to use gpgsigs which annotates the ksp-fosdem2014.txt file with those signatures. You might also want to consider using it's latex output which shows the pictures if there are any. I first downloaded an imported the keyring, refreshed my keyring, and then used: $ gpgsigs -f utf8 --latex 2064C53641C25E5D,41DC1C907244970B ksp-fosdem2014.txt > ksp-fosdem2014.tex $ pdflatex ksp-fosdem2014.tex Run this in a temporary directory so you can clean up all the files. Kurt
On Tue, 28 Jan 2014 08:53:17 -0600, Tom Marble wrote:
Please use caff(1) from the package signing-party (after the KSP) to sign the keys at home. But BEWARE the default caff configuration is NOT the same as for GPG. Please make sure you are using the configuration settings you intend (esp. strong signature strength). For more information please see: https://github.com/tmarble/kspsig
Please be aware of http://bugs.debian.org/735536 when using caff. Cheers, gregor -- .''`. Homepage: http://info.comodo.priv.at/ - OpenPGP key 0xBB3A68018649AA06 : :' : Debian GNU/Linux user, admin, and developer - http://www.debian.org/ `. `' Member of VIBE!AT & SPI, fellow of the Free Software Foundation Europe `- NP: Flying Pickets: Looking For Love
On 29 Jan 2014, at 22:19, gregor herrmann <gregor+fosdem@comodo.priv.at> wrote:
On Tue, 28 Jan 2014 08:53:17 -0600, Tom Marble wrote:
Please use caff(1) from the package signing-party (after the KSP) to sign the keys at home. But BEWARE the default caff configuration is NOT the same as for GPG. Please make sure you are using the configuration settings you intend (esp. strong signature strength). For more information please see: https://github.com/tmarble/kspsig
Please be aware of http://bugs.debian.org/735536 when using caff.
This patch against gnupg-1.4.16 fixes it. When importing keys with --trust-model=always and no existing trustdb, gpg would exit with a fatal error about the missing trustdb despite successfully having imported the key. We should not exit with a fatal error when an operation completes successfully! Signed-off-by: Philip Paeps <philip@paeps.cx> --- g10/trustdb.c | 1 + 1 file changed, 1 insertion(+) diff --git a/g10/trustdb.c b/g10/trustdb.c index 0bf92e4..f0c0ab8 100644 --- a/g10/trustdb.c +++ b/g10/trustdb.c @@ -927,6 +927,7 @@ clear_ownertrusts (PKT_public_key *pk) TRUSTREC rec; int rc; + init_trustdb(); if (trustdb_args.no_trustdb && opt.trust_model == TM_ALWAYS) return 0; -- 1.8.3.4 (Apple Git-47) Philip -- Philip Paeps Senior Reality Engineer Ministry of Information
On 2014-01-28 10:29, Niels Laukens wrote:
The list of participants for this weekend's keysigning event is now available.
But it contains a minor bug, for which I sincerely apologize. The header still mentions last edition's year. Unfortunately, fixing this will result in two lists in circulation, and the associated sets of hashes, making things much more complicated than they need to be. Therefore, this will NOT be fixed. I've made sure that this won't happen again, though [1]. See you next Sunday (in the year 2014), Niels [1]: https://github.com/FOSDEM/keysigning/commit/750ee80a64ae50868f71b36ab59226a6...
As I type this, the keysigning should be almost done. My apologies for the confusion about the year on the list, it won't happen again. If you didn't catch the hashes as they flew past, you can verify them against the list of hashes on https://ksp.fosdem.org/files/. If you don't trust that, try to run into me somewhere during the remainder of FOSDEM, and you can read them off paper. Please try to complete your signing homework before Sunday 8 June 2014. You may find "caff" a helpful tool. Note: don't sign keys whose owners you haven't actually met at the keysigning event this afternoon. Thanks all for attending. -- Niels
participants (6)
-
gregor herrmann -
Kurt Roeckx -
Niels Laukens -
Philip Paeps -
Tom Marble -
Vipul Agarwal