The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Krzysztof Kozlowski <krzk@kernel.org>
To: lpcosse-keysigning@baylibre.com, users@linux.kernel.org
Cc: linux-kernel@vger.kernel.org,
	Konstantin Ryabitsev <konstantin@linuxfoundation.org>
Subject: Re: PGP keysigning at LPC/OSSE 2026
Date: Wed, 5 Aug 2026 08:32:22 +0200	[thread overview]
Message-ID: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> (raw)
In-Reply-To: <lpcosse2026-keysigning@baylibre.com>

On 04/08/2026 17:43, Uwe Kleine-König wrote:
> Hello,
> 
> I will organize a PGP keysigning event for the participants of Linux
> Plumbers and Open Source Summit Europe in Prague this October.
> 
> The idea is to meet during the two conferences and exchange/verify PGP
> fingerprints and (depending on how you practise keysigning) ID checking. 
> Then each participant back at home can sign the verified certificates to
> improve the web of trust. (Current state of the web of trust (as of
> commit f8c2189fb65f in the kernel's pgpkeys repo):
> 
>  - 654 certificates, among them 12 invalid
>  - 8088 signatures, 3613 of them invalid
>  - 9 certificates are not reachable from Greg's stable key
>    (38DBBDC86092693E).
>  - 317 certificates are not reachable from Linus's cert
>    (79BE3E4300411886). (That's why Greg is used as trust root since some
>    time.)
>  - strong set size: 289
>  - average distance in the strong set: 4.85
>  - maximal distance in the strong set: 13
>  - Best connected certificate is Daniel Wagner's 587C5ECA5D0A306C which
>    can reach the other strong set certs with an average of 3.89 steps.
> )
> 
> The gatherings will be on Tue 2026-10-06 and Thu 2026-10-08 (that is on
> the second day of each conference) after the official program.
> 
> I don't know the conference location and also don't have any idea yet
> how many people will participate, so I will communicate the location and
> exact time later. (If you have insights about the possibilities there,
> please reach out.)
> 
> While it's not mandatory, please register by sending your PGP
> certificate ("public key") to lpcosse-keysigning@baylibre.com until
> 2026-09-27 08:00 UTC. Your certificate doesn't need to be in the kernel
> pgpkeys repo for that. I will prepare a text file with all the
> registered certificates to speed up the event using the
> Zimmermann–Sassaman key-signing protocol[1]. You can join without
> sending your certificate, but then you have to care yourself about how
> to share your fingerprint. (Probably use gpg-key2ps to prepare paper
> slips with your certificate data. Having some of these even if you're on
> the list might be a good idea.)

While as much as I like key signing, I do not believe in
Zimmermann–Sassaman protocol to work, because of people's negligence. It
requires the participants to check if THEIR key is correct, but based on
my recent practice (people generated new key and week later they lost
password to it; people received my signed keys and could not decrypt the
message because they never used encrypted email, people sent me emails
asking to send their keys) I think it has significant risk of this not
happening. People just do not understand the security principles here
thus they do not think certain steps are an absolute requirement.

IOW, I do not believe people will check their key fingerprints and email
IDs, they will gladly accept what you prepared on the server and that
could have been modified by an attacker or mischievous actor wanting to
prank us.

That's why I require that the keys to be given to me must be prepared by
that owner, not by a third party. I have some proofs that at least that
key was in the possession of the owner, when he was preparing it. I will
be happy to sign keys of developers given to me that way.

I know that you want to speed it up, but honestly korg keysigning should
not have that many participants, so exchanging key slips should be fine
as I was doing in the past.

Best regards,
Krzysztof

  parent reply	other threads:[~2026-08-05  6:32 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-04 15:43 PGP keysigning at LPC/OSSE 2026 Uwe Kleine-König
2026-08-04 21:28 ` Uwe Kleine-König
2026-08-05  6:32 ` Krzysztof Kozlowski [this message]
2026-08-05 10:29   ` Uwe Kleine-König
2026-08-06 10:11     ` Krzysztof Kozlowski
2026-08-06 15:59       ` Uwe Kleine-König
2026-08-06 16:57 ` [workflows]PGP " Steven Rostedt
2026-08-06 22:15   ` Uwe Kleine-König

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org \
    --to=krzk@kernel.org \
    --cc=konstantin@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lpcosse-keysigning@baylibre.com \
    --cc=users@linux.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox