From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6DBAC432BE8; Thu, 6 Aug 2026 10:11:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786011075; cv=none; b=eE5KwI6SjAau+vBULc0VjA/wK3XbYA19pPJ1e6qtNlSx3cqT6/SMCh8T/Z9ahOMds5nXo1bwAkM9SL7wGj4XDceYpDC/71gJVDMqpItJ3/o5fiN8rlgyNgJF4ENsPrJKvtJkiRM4oDWfjaeebH+wI1B/cc5x9FScA15fPMQSU9A= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786011075; c=relaxed/simple; bh=VsUGXyqW6+AXFVWNfcv1Rr9JCpv1q6E7+lTKL7eKqsE=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=BsO3kWh4vdV6vMzJ6WbX2lhKKV+jnKaP4e5C/GWT0w2OlkpVcVYd3785UnUkgtXFvvXUv4/S/5C5+IlGej2lPcPIYbmWuRLVNUAKpUo5grxaUFcY3fmG3lIR5Wx9g94OSbDdQda23dl7aDLVI8zDxV9IcftfvsLpopsGqq+upbk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=Q1x4rbwX; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="Q1x4rbwX" Received: by smtp.kernel.org (Postfix) with ESMTPSA id BE7F31F000E9; Thu, 6 Aug 2026 10:11:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786011071; bh=SkL4EpQi/fepasXArq9hBmEad+QBCiFTLehp/QrZ7H8=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=Q1x4rbwX9VGau0wOQDXnx9Oh7A59ri6FIrAnP+GypekfEwrE9eoySb5Ls3e2m+AHR XFD0jBF/VH1OlsmiJ0klJMitvijP7+a3rtgal8+pFA9ibW0ek6iv8/eYa90FvE3ag/ Pi8FpRXABHPpDH8mMdkkzEyxtQk4xzPNN5fP9y+p50UkJNjHRz7nQutELXMF5diUAf q6OFq8feRNzvhZQR5zXvUaZ/FMyzgJCHMk2EHvb1JDMJHFqo0UN+9ns6xay0jc/B/m SS0oxV4MRS+PQbDn2D1UGxZlfCS2+wNJ1lx4SmKKmIUalGOpcnzUALeYK+tvGITvvv pley8dLmxyWwA== Message-ID: Date: Thu, 6 Aug 2026 12:11:06 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: PGP keysigning at LPC/OSSE 2026 To: =?UTF-8?Q?Uwe_Kleine-K=C3=B6nig?= Cc: lpcosse-keysigning@baylibre.com, users@linux.kernel.org, linux-kernel@vger.kernel.org, Konstantin Ryabitsev References: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> From: Krzysztof Kozlowski Content-Language: en-US Autocrypt: addr=krzk@kernel.org; keydata= xsFNBFVDQq4BEAC6KeLOfFsAvFMBsrCrJ2bCalhPv5+KQF2PS2+iwZI8BpRZoV+Bd5kWvN79 cFgcqTTuNHjAvxtUG8pQgGTHAObYs6xeYJtjUH0ZX6ndJ33FJYf5V3yXqqjcZ30FgHzJCFUu JMp7PSyMPzpUXfU12yfcRYVEMQrmplNZssmYhiTeVicuOOypWugZKVLGNm0IweVCaZ/DJDIH gNbpvVwjcKYrx85m9cBVEBUGaQP6AT7qlVCkrf50v8bofSIyVa2xmubbAwwFA1oxoOusjPIE J3iadrwpFvsZjF5uHAKS+7wHLoW9hVzOnLbX6ajk5Hf8Pb1m+VH/E8bPBNNYKkfTtypTDUCj NYcd27tjnXfG+SDs/EXNUAIRefCyvaRG7oRYF3Ec+2RgQDRnmmjCjoQNbFrJvJkFHlPeHaeS BosGY+XWKydnmsfY7SSnjAzLUGAFhLd/XDVpb1Een2XucPpKvt9ORF+48gy12FA5GduRLhQU vK4tU7ojoem/G23PcowM1CwPurC8sAVsQb9KmwTGh7rVz3ks3w/zfGBy3+WmLg++C2Wct6nM Pd8/6CBVjEWqD06/RjI2AnjIq5fSEH/BIfXXfC68nMp9BZoy3So4ZsbOlBmtAPvMYX6U8VwD TNeBxJu5Ex0Izf1NV9CzC3nNaFUYOY8KfN01X5SExAoVTr09ewARAQABzSVLcnp5c3p0b2Yg S296bG93c2tpIDxrcnprQGtlcm5lbC5vcmc+wsGPBBMBCgA5AhsDBgsJCAcDAgYVCAIJCgsE FgIDAQIeAQIXgBYhBJvQfg4MUfjVlne3VBuTQ307QWKbBQJp2mE8AAoJEBuTQ307QWKbeaIP /ihHTkTW4KsN/DQ945JJbyu5tI0J80Wue7QyyLPglyKfhgb5cLLNPpOC8cCIJsc7+W3i2P38 s2c1cOH6CYGE7E9ur3Vfme8NW2S2I/Z8VC7bZnzyS23wT17LrsdS/qCpx4o8U+pt/xdXDKph EGRYrIEmMpUWvyYzyYKGIe25FtaayIIKpq8eZYyFcp2f/sG5IkOW5uZzHPMPdcm87jU7fyuQ rAU2vx9r+ulUfQ/q9Z2roC/ode3l7t2pN7BCBCsUDp6JCrUyZrtT1e7EbA0ZRP3aOBNk2P2E DQOgJGjGdO5Yx2Y9LFtltu6JbsBJHi1syGRX3AtQYOMc4Y1WGoeZJmMlvKj2ZqqXNkcWi2DS IQEWB0uW6CqFsBBIMGDa+6OzdaVO/uAVXWDWml02Men3CILdI1MbVjoh8ECqYUY7OQ+JJvNN vnliuq5WM3Ghd3jg/LZZrxXjdIginRHFQCjIJYLKpLZWm1/iDFedcfzqRNYmTtqscdCNHW41 oT3Z7BmO9xwdjuwBS6nmS6JJwkbf5Ot2QR4pB/DRU7ZwjT1qHe+9r9gF32wXVQatHNGK/VVu sfwOnkdxCWkp/qb2gdQRmZh+SedStWshigH6sNfuHBloF/q+hjMRc8b2m326OZdrbSHwY1Sz vti8Hn7n8NjdHO9LKB7BIdjkA9DA5WsqOuVCzsFNBFVDXDQBEADNkrQYSREUL4D3Gws46JEo Z9HEQOKtkrwjrzlw/tCmqVzERRPvz2Xg8n7+HRCrgqnodIYoUh5WsU84N03KlLueMNsWLJBv BaubYN4JuJIdRr4dS4oyF1/fQAQPHh8Thpiz0SAZFx6iWKB7Qrz3OrGCjTPcW6eiOMheesVS 5hxietSmlin+SilmIAPZHx7n242u6kdHOh+/SyLImKn/dh9RzatVpUKbv34eP1wAGldWsRxb f3WP9pFNObSzI/Bo3kA89Xx2rO2roC+Gq4LeHvo7ptzcLcrqaHUAcZ3CgFG88CnA6z6lBZn0 WyewEcPOPdcUB2Q7D/NiUY+HDiV99rAYPJztjeTrBSTnHeSBPb+qn5ZZGQwIdUW9YegxWKvX XHTwB5eMzo/RB6vffwqcnHDoe0q7VgzRRZJwpi6aMIXLfeWZ5Wrwaw2zldFuO4Dt91pFzBSO IpeMtfgb/Pfe/a1WJ/GgaIRIBE+NUqckM+3zJHGmVPqJP/h2Iwv6nw8U+7Yyl6gUBLHFTg2h YnLFJI4Xjg+AX1hHFVKmvl3VBHIsBv0oDcsQWXqY+NaFahT0lRPjYtrTa1v3tem/JoFzZ4B0 p27K+qQCF2R96hVvuEyjzBmdq2esyE6zIqftdo4MOJho8uctOiWbwNNq2U9pPWmu4vXVFBYI GmpyNPYzRm0QPwARAQABwsF2BBgBCgAgAhsMFiEEm9B+DgxR+NWWd7dUG5NDfTtBYpsFAmna YUkACgkQG5NDfTtBYptX+BAApg32CkxwNucNEi8WfWA8oKkW0y8YDuY6ORMo9FWNGiT/OTy0 vyJrLocrpn86zwfjVp+eCrssPYh8eqJfnWqmYv6ACQtHPYzPZQ3mSo8H97Z01oUxITzCxpXm ZkLgPIqtDPcC2E3dPM/fVxcyowM8XsaMA9wcsaUYrta8toOq2b9tKcjleKMfMrm0gQ9u7wUc QbLkwj6TCLOwucb07GXzLTNF9PZmaDUpKAZjMjmrW+le+SFvQbhamx0rxLWPR0NWntXpbCn+ +ACch03p/JyTBVktxFsFyCt7pTPE1kEaeuXBTe/a2D9iQvRxRW19LvuO2e59/u1wYUiH/orz wbIC2S4dBsPAPihL3ztOU1yE86GPyQtSE0kU+/7snnLt4QGi6PChf3t5gnNjAzjUUovO8rgI c+5yN5heq5loYHgK6OQ9OlHzsPHO9e9MOQcKlFycs1pyijFGzDwdNUm/SchK8iWT2QApTx4A K9bCVaboTA2T77QYkRcRJYSsO1alGX0ome/hMLD1daXlkrNUp1HWa3K4iytLRXjCSIorWiGs n+q3krnpXu3TFkA8qtOFZMdnIiFuiq1yLT8hptsV5xh1TA2nsVvSYiaCr3q4s4BKjS/KrLDb qoxzw8ISjdUp4pA85vb6YLCmb39NgidD+7PmAr65lBNveIFynTgsja1rRQ4= In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On 05/08/2026 12:29, Uwe Kleine-König wrote: > Hello Krzysztof, > > On Wed, Aug 05, 2026 at 08:32:22AM +0200, Krzysztof Kozlowski wrote: >> While as much as I like key signing, I do not believe in >> Zimmermann–Sassaman protocol to work, because of people's negligence. It >> requires the participants to check if THEIR key is correct, but based on >> my recent practice (people generated new key and week later they lost >> password to it; people received my signed keys and could not decrypt the >> message because they never used encrypted email, people sent me emails >> asking to send their keys) I think it has significant risk of this not >> happening. People just do not understand the security principles here >> thus they do not think certain steps are an absolute requirement. > > I see your point. However if Bob confirms his fingerprint on the > Zimmermann–Sassaman list is right while he didn't actually checked and > as an effect a forged certificate is signed, that's mostly Bob's > problem. > > Also if Bob doesn't check his own fingerprint, he probably also doesn't > check the certificates he signs carefully and thus his signatures > shouldn't be trusted. > > That's why a keysigning is about a *web* of trust where the (little?) > trust in each individual path between me and a given other person sums > up. I am rather thinking of someone planting their key in place of the person's one, thus of course Bob will have a problem, but bigger problem is that I would sign malicious actor's key. > >> IOW, I do not believe people will check their key fingerprints and email >> IDs, they will gladly accept what you prepared on the server and that >> could have been modified by an attacker or mischievous actor wanting to >> prank us. >> >> That's why I require that the keys to be given to me must be prepared by >> that owner, not by a third party. I have some proofs that at least that >> key was in the possession of the owner, when he was preparing it. I will >> be happy to sign keys of developers given to me that way. > > Last time I talked to Greg about these paper slips, he had trouble > finding gpg-key2ps on Arch and I prepared the postscript file for him :-D 1. gpg --fingerprint your-name 2. Paste it to a TXT file without the "sub" parts 3. Copy+paste to fill up the page 4. Print and cut No need for gpg-key2ps. > >> I know that you want to speed it up, but honestly korg keysigning should >> not have that many participants, so exchanging key slips should be fine >> as I was doing in the past. > > I think even if we're only 10 in the end, the speedup is noticeable. And > it also simplifies the actual signing process for everyone, as I will > provide a keyring of all the handed in certificates. And now I have one more doubt because Bob, who I did not trust that he understands security principles of key signing (see my previous email why), might not verify that keys in above keyring are the ones from the paper. IOW, Bob will happily sign whatever you send him, to speed things up. Otherwise there is no speed up comparing to: $ gpg --recv-key > > If you still want a paper slip from each participant before being ok to > sign their certificate, that's fine. I'm still convinced that preparing > the Zimmermann–Sassaman list is a net win. And you're welcome to > participate no matter if your cert is on the list or not. Best regards, Krzysztof