public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: David Brown <davidb@codeaurora.org>
To: Konstantin Ryabitsev <mricon@kernel.org>
Cc: ksummit-2012-discuss@lists.linux-foundation.org,
	linux-kernel <linux-kernel@vger.kernel.org>
Subject: Re: [Ksummit-2012-discuss] Pubring and instructions for the KS 2012 keysigning
Date: Sun, 26 Aug 2012 00:48:02 -0700	[thread overview]
Message-ID: <20120826074802.GB23985@codeaurora.org> (raw)
In-Reply-To: <50387307.9070001@kernel.org>

On Fri, Aug 24, 2012 at 11:39:03PM -0700, Konstantin Ryabitsev wrote:

> 6. When you get back to your laptop, run "gpg --sign-key [keyid]" for
> all the people marked "X" on your worksheet. The key id is the last 8
> chars of the fingerprint smushed together. [***] If a person has
> multiple fingerprints, sign all their keys.

Well, this can be made to work, but it's a bit clumsy.  People will be
verifying their fingerprint against the sha of the keyring.  The pdf
file isn't trusted (although each person could verify it, if desired).

This means that each person I want to sign, I have to assure that
their signature matches the one in the signed keyring, and to make the
worksheet useful, I have to also verify that the fingerprint on the
worksheet matches.

Some may find it useful to print out the worksheet themselves along
with its hash, and we can verify the sha256 hash of the pdf file.

David

-- 
Sent by an employee of the Qualcomm Innovation Center, Inc.
The Qualcomm Innovation Center, Inc. is a member of the Code Aurora Forum.

  reply	other threads:[~2012-08-26  7:48 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2012-08-25  6:39 Pubring and instructions for the KS 2012 keysigning Konstantin Ryabitsev
2012-08-26  7:48 ` David Brown [this message]
2012-08-26 16:42 ` [Ksummit-2012-discuss] " Ben Hutchings
2012-08-26 20:16   ` Konstantin Ryabitsev

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20120826074802.GB23985@codeaurora.org \
    --to=davidb@codeaurora.org \
    --cc=ksummit-2012-discuss@lists.linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mricon@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox