public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Konstantin Ryabitsev <mricon@kernel.org>
To: ksummit-2013-discuss@lists.linux-foundation.org,
	linux-kernel <linux-kernel@vger.kernel.org>
Subject: Pubring and instructions for the KS 2013 keysigning
Date: Thu, 17 Oct 2013 17:22:11 -0400	[thread overview]
Message-ID: <20131017212211.GA15197@gmail.com> (raw)


[-- Attachment #1.1: Type: text/plain, Size: 3719 bytes --]

Hello, all:

I collected 36 keys from people interested in keysigning at the
Kernel Summit. I have uploaded the fingerprints and the keyring to the
following locations:

https://www.kernel.org/doc/ks/ks2013-fingerprints.txt
https://www.kernel.org/doc/ks/ks2013-keyring.gpg

This is the sha1sum of the keyring:
d9bb4f0519a5453fb445dbdc9e2bfee5b721332b

You can import the keyring using "gpg --import" command.

WARNING: just in case someone jumps the gun -- these fingerprints were
taken at "face value". I DID NO VERIFICATION WHATSOEVER whether these
keys belong to the actual people. DO NOT sign any of these keys
without the verification procedure at the Kernel Summit. My GPG
signature on this email is in no way an endorsement of these keys.

Here's how the procedure will play out:

1. Some time on Thursday during plenary meetings, I will take 5 minutes
   of your time to introduce myself and to recite the sha1sum of the
   keyring available for download from the link above. People with laptops
   capable of downloading the keyring and running "sha1sum" (should be
   about 95% of the audience, I think) can validate whether the hash
   verifies. Someone from those present who can identify me will state
   that I am indeed who I am.
2. I will also make available printed worksheets with people's names
   and key fingerprints (or print your own -- see attached).
3. If you are willing to sign people's keys, please obtain from me a
   copy of the worksheet, a short pencil, and a spider sticker (because
   it's Hallowe'en and they were on sale, plus because it clearly
   means "Web of Trust").
   a. Affix the spider sicker to your KS badge to indicate that
      you're willing to sign keys.
   b. Fold the worksheet and keep it in your KS badge.
   c. Keep the brass lantern^W^W short pencil in your badge, too.
4. During lunch and later during the day, if someone approaches you
   and asks to sign their key:
   a. Keep calm and carry on.
   b. Locate their name on the worksheet.
   c. Ask to see some government-issued ID to verify their identity.
   d. Alternatively, ask personal/kernel-related questions which only
      that person would be able to answer (see Harry Potter books 6 and 7).
5. If you are comfortable in asserting that the person asking your
   signature is who they say they are, put an "X" next to their name on
   the worksheet using the pencil provided (or an alternative writing
   utensil should there be a dearth of pencils).
6. When you get back to your laptop, run "gpg --sign-key [keyid]" for
   all the people marked "X" on your worksheet (assuming you ran "gpg
   --import ks2013-keyring.gpg" already). If a person has multiple keys,
   sign all of them.
7. Lastly, do "gpg --send-keys [keyid]" to upload the newly signed key
   to the keyservers.

If you're attending the Kernel Summit but have not submitted your key in
time -- or, alternatively, if you are attending LCE/CloudOpen but have
not been invited to the KS... do not despair!

Use the following procedure instead:

1. Write out your key on your business card, or
2. Make a QR code of the fingerprint and put it on your phone so
   others can scan it (e.g. like this http://goo.gl/xrdHz9, using
   this: http://www.unitaglive.com/qrcode).
3. Locate people sporting stylish spider stickers on their badges and ask them to
   sign your key. People with stylish spider stickers are likely in the
   kernel.org web of trust and have volunteered to participate in
   keysigning.


If you have any questions, please let me know.

Best,
-- 
Konstantin Ryabitsev
Systems Administrator
Linux Foundation, kernel.org
Montréal, Québec

[-- Attachment #1.2: ks2013-worksheet-2x.pdf --]
[-- Type: application/pdf, Size: 231664 bytes --]

[-- Attachment #2: Type: application/pgp-signature, Size: 665 bytes --]

                 reply	other threads:[~2013-10-17 21:22 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20131017212211.GA15197@gmail.com \
    --to=mricon@kernel.org \
    --cc=ksummit-2013-discuss@lists.linux-foundation.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox