From: "Uwe Kleine-König" <u.kleine-koenig@baylibre.com>
To: Krzysztof Kozlowski <krzk@kernel.org>
Cc: lpcosse-keysigning@baylibre.com, users@linux.kernel.org,
linux-kernel@vger.kernel.org,
Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Subject: Re: PGP keysigning at LPC/OSSE 2026
Date: Wed, 5 Aug 2026 12:29:58 +0200 [thread overview]
Message-ID: <anLhczVlFnnFsH8H@monoceros> (raw)
In-Reply-To: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org>
[-- Attachment #1: Type: text/plain, Size: 2633 bytes --]
Hello Krzysztof,
On Wed, Aug 05, 2026 at 08:32:22AM +0200, Krzysztof Kozlowski wrote:
> While as much as I like key signing, I do not believe in
> Zimmermann–Sassaman protocol to work, because of people's negligence. It
> requires the participants to check if THEIR key is correct, but based on
> my recent practice (people generated new key and week later they lost
> password to it; people received my signed keys and could not decrypt the
> message because they never used encrypted email, people sent me emails
> asking to send their keys) I think it has significant risk of this not
> happening. People just do not understand the security principles here
> thus they do not think certain steps are an absolute requirement.
I see your point. However if Bob confirms his fingerprint on the
Zimmermann–Sassaman list is right while he didn't actually checked and
as an effect a forged certificate is signed, that's mostly Bob's
problem.
Also if Bob doesn't check his own fingerprint, he probably also doesn't
check the certificates he signs carefully and thus his signatures
shouldn't be trusted.
That's why a keysigning is about a *web* of trust where the (little?)
trust in each individual path between me and a given other person sums
up.
> IOW, I do not believe people will check their key fingerprints and email
> IDs, they will gladly accept what you prepared on the server and that
> could have been modified by an attacker or mischievous actor wanting to
> prank us.
>
> That's why I require that the keys to be given to me must be prepared by
> that owner, not by a third party. I have some proofs that at least that
> key was in the possession of the owner, when he was preparing it. I will
> be happy to sign keys of developers given to me that way.
Last time I talked to Greg about these paper slips, he had trouble
finding gpg-key2ps on Arch and I prepared the postscript file for him :-D
> I know that you want to speed it up, but honestly korg keysigning should
> not have that many participants, so exchanging key slips should be fine
> as I was doing in the past.
I think even if we're only 10 in the end, the speedup is noticeable. And
it also simplifies the actual signing process for everyone, as I will
provide a keyring of all the handed in certificates.
If you still want a paper slip from each participant before being ok to
sign their certificate, that's fine. I'm still convinced that preparing
the Zimmermann–Sassaman list is a net win. And you're welcome to
participate no matter if your cert is on the list or not.
Best regards
Uwe
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
next prev parent reply other threads:[~2026-08-05 10:30 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 15:43 PGP keysigning at LPC/OSSE 2026 Uwe Kleine-König
2026-08-04 21:28 ` Uwe Kleine-König
2026-08-05 6:32 ` Krzysztof Kozlowski
2026-08-05 10:29 ` Uwe Kleine-König [this message]
2026-08-06 10:11 ` Krzysztof Kozlowski
2026-08-06 15:59 ` Uwe Kleine-König
2026-08-06 16:57 ` [workflows]PGP " Steven Rostedt
2026-08-06 22:15 ` Uwe Kleine-König
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anLhczVlFnnFsH8H@monoceros \
--to=u.kleine-koenig@baylibre.com \
--cc=konstantin@linuxfoundation.org \
--cc=krzk@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lpcosse-keysigning@baylibre.com \
--cc=users@linux.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.