From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E729E3D9665; Wed, 5 Aug 2026 06:32:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785911548; cv=none; b=SczJLajtY+UAF/+ZtbweYH5jbnVptqHnDVCTHSY1hk2VJgotiXGpCE38xWmaEiIhLdPeu9xuNc/30R9IaqT2EEkhOQytO2KucxntXo9uL3iW/DQJV277DcW5lSHxd4p51hTnECw22BzRlSVKjRsr95kdXB30HJdS9YLRZqOAP8w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785911548; c=relaxed/simple; bh=CRDa3jzYS9NvuM8xubIY0h+emVbWvs4x5yNWGgGgBYU=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=W2y6QVBgAdW2rnC226PD+Xrsb3OX4+WwORiXQV6c0JwWdw2N34oYDstw/VmhqnbmFLXyJ/YvRcb+bGpao4aIpku40IbTPPF4p36iyAlLK3DVoRwkwSTCodRRnkYmLUAj7gH2RJM29xCSnh0Z/X+8aM6iEdrYmB2Zl0A04AmRtTA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=C8emeRsL; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="C8emeRsL" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E88861F000E9; Wed, 5 Aug 2026 06:32:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785911546; bh=9POgGx1xX6HXboTZD2kEFYX04U+i1qDc6EDODd85Xm8=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=C8emeRsLY1jyZetoSKqhdqyYKn1Pes0kWVvwz2zfmDh+Ct0kLe9YTfILzA3uX0XVS 9fzHkvPTpeJWbQEHDxAt4x1WQLKGMdv0MKh4fUpFvKreg7C3xColy+jvBBKiuNFYJF WO39aJ+cP6N7ccZDQTlreksP9Z0jKb3SZXcREXarOCP3Ty7mV7OqXscF5+pQdqaRMw c8r0p6skUlz/bMqXuXPjb91m8oPup3aLLF+/g8XmOt92/9E3fgdc2LMgAsI5OfXxtb QvESEfwRE8/j4EVxP/6MakAspcIBxo4duLxGr4MFlnUJIsP8+NTLKw1qiI8tcopXN2 QCcSj5RQdp21Q== Message-ID: <31bcf7e3-171b-45fe-86a6-69731c95412e@kernel.org> Date: Wed, 5 Aug 2026 08:32:22 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: PGP keysigning at LPC/OSSE 2026 To: lpcosse-keysigning@baylibre.com, users@linux.kernel.org Cc: linux-kernel@vger.kernel.org, Konstantin Ryabitsev References: From: Krzysztof Kozlowski Content-Language: en-US Autocrypt: addr=krzk@kernel.org; keydata= xsFNBFVDQq4BEAC6KeLOfFsAvFMBsrCrJ2bCalhPv5+KQF2PS2+iwZI8BpRZoV+Bd5kWvN79 cFgcqTTuNHjAvxtUG8pQgGTHAObYs6xeYJtjUH0ZX6ndJ33FJYf5V3yXqqjcZ30FgHzJCFUu JMp7PSyMPzpUXfU12yfcRYVEMQrmplNZssmYhiTeVicuOOypWugZKVLGNm0IweVCaZ/DJDIH gNbpvVwjcKYrx85m9cBVEBUGaQP6AT7qlVCkrf50v8bofSIyVa2xmubbAwwFA1oxoOusjPIE J3iadrwpFvsZjF5uHAKS+7wHLoW9hVzOnLbX6ajk5Hf8Pb1m+VH/E8bPBNNYKkfTtypTDUCj NYcd27tjnXfG+SDs/EXNUAIRefCyvaRG7oRYF3Ec+2RgQDRnmmjCjoQNbFrJvJkFHlPeHaeS BosGY+XWKydnmsfY7SSnjAzLUGAFhLd/XDVpb1Een2XucPpKvt9ORF+48gy12FA5GduRLhQU vK4tU7ojoem/G23PcowM1CwPurC8sAVsQb9KmwTGh7rVz3ks3w/zfGBy3+WmLg++C2Wct6nM Pd8/6CBVjEWqD06/RjI2AnjIq5fSEH/BIfXXfC68nMp9BZoy3So4ZsbOlBmtAPvMYX6U8VwD TNeBxJu5Ex0Izf1NV9CzC3nNaFUYOY8KfN01X5SExAoVTr09ewARAQABzSVLcnp5c3p0b2Yg S296bG93c2tpIDxrcnprQGtlcm5lbC5vcmc+wsGPBBMBCgA5AhsDBgsJCAcDAgYVCAIJCgsE FgIDAQIeAQIXgBYhBJvQfg4MUfjVlne3VBuTQ307QWKbBQJp2mE8AAoJEBuTQ307QWKbeaIP /ihHTkTW4KsN/DQ945JJbyu5tI0J80Wue7QyyLPglyKfhgb5cLLNPpOC8cCIJsc7+W3i2P38 s2c1cOH6CYGE7E9ur3Vfme8NW2S2I/Z8VC7bZnzyS23wT17LrsdS/qCpx4o8U+pt/xdXDKph EGRYrIEmMpUWvyYzyYKGIe25FtaayIIKpq8eZYyFcp2f/sG5IkOW5uZzHPMPdcm87jU7fyuQ rAU2vx9r+ulUfQ/q9Z2roC/ode3l7t2pN7BCBCsUDp6JCrUyZrtT1e7EbA0ZRP3aOBNk2P2E DQOgJGjGdO5Yx2Y9LFtltu6JbsBJHi1syGRX3AtQYOMc4Y1WGoeZJmMlvKj2ZqqXNkcWi2DS IQEWB0uW6CqFsBBIMGDa+6OzdaVO/uAVXWDWml02Men3CILdI1MbVjoh8ECqYUY7OQ+JJvNN vnliuq5WM3Ghd3jg/LZZrxXjdIginRHFQCjIJYLKpLZWm1/iDFedcfzqRNYmTtqscdCNHW41 oT3Z7BmO9xwdjuwBS6nmS6JJwkbf5Ot2QR4pB/DRU7ZwjT1qHe+9r9gF32wXVQatHNGK/VVu sfwOnkdxCWkp/qb2gdQRmZh+SedStWshigH6sNfuHBloF/q+hjMRc8b2m326OZdrbSHwY1Sz vti8Hn7n8NjdHO9LKB7BIdjkA9DA5WsqOuVCzsFNBFVDXDQBEADNkrQYSREUL4D3Gws46JEo Z9HEQOKtkrwjrzlw/tCmqVzERRPvz2Xg8n7+HRCrgqnodIYoUh5WsU84N03KlLueMNsWLJBv BaubYN4JuJIdRr4dS4oyF1/fQAQPHh8Thpiz0SAZFx6iWKB7Qrz3OrGCjTPcW6eiOMheesVS 5hxietSmlin+SilmIAPZHx7n242u6kdHOh+/SyLImKn/dh9RzatVpUKbv34eP1wAGldWsRxb f3WP9pFNObSzI/Bo3kA89Xx2rO2roC+Gq4LeHvo7ptzcLcrqaHUAcZ3CgFG88CnA6z6lBZn0 WyewEcPOPdcUB2Q7D/NiUY+HDiV99rAYPJztjeTrBSTnHeSBPb+qn5ZZGQwIdUW9YegxWKvX XHTwB5eMzo/RB6vffwqcnHDoe0q7VgzRRZJwpi6aMIXLfeWZ5Wrwaw2zldFuO4Dt91pFzBSO IpeMtfgb/Pfe/a1WJ/GgaIRIBE+NUqckM+3zJHGmVPqJP/h2Iwv6nw8U+7Yyl6gUBLHFTg2h YnLFJI4Xjg+AX1hHFVKmvl3VBHIsBv0oDcsQWXqY+NaFahT0lRPjYtrTa1v3tem/JoFzZ4B0 p27K+qQCF2R96hVvuEyjzBmdq2esyE6zIqftdo4MOJho8uctOiWbwNNq2U9pPWmu4vXVFBYI GmpyNPYzRm0QPwARAQABwsF2BBgBCgAgAhsMFiEEm9B+DgxR+NWWd7dUG5NDfTtBYpsFAmna YUkACgkQG5NDfTtBYptX+BAApg32CkxwNucNEi8WfWA8oKkW0y8YDuY6ORMo9FWNGiT/OTy0 vyJrLocrpn86zwfjVp+eCrssPYh8eqJfnWqmYv6ACQtHPYzPZQ3mSo8H97Z01oUxITzCxpXm ZkLgPIqtDPcC2E3dPM/fVxcyowM8XsaMA9wcsaUYrta8toOq2b9tKcjleKMfMrm0gQ9u7wUc QbLkwj6TCLOwucb07GXzLTNF9PZmaDUpKAZjMjmrW+le+SFvQbhamx0rxLWPR0NWntXpbCn+ +ACch03p/JyTBVktxFsFyCt7pTPE1kEaeuXBTe/a2D9iQvRxRW19LvuO2e59/u1wYUiH/orz wbIC2S4dBsPAPihL3ztOU1yE86GPyQtSE0kU+/7snnLt4QGi6PChf3t5gnNjAzjUUovO8rgI c+5yN5heq5loYHgK6OQ9OlHzsPHO9e9MOQcKlFycs1pyijFGzDwdNUm/SchK8iWT2QApTx4A K9bCVaboTA2T77QYkRcRJYSsO1alGX0ome/hMLD1daXlkrNUp1HWa3K4iytLRXjCSIorWiGs n+q3krnpXu3TFkA8qtOFZMdnIiFuiq1yLT8hptsV5xh1TA2nsVvSYiaCr3q4s4BKjS/KrLDb qoxzw8ISjdUp4pA85vb6YLCmb39NgidD+7PmAr65lBNveIFynTgsja1rRQ4= In-Reply-To: Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On 04/08/2026 17:43, Uwe Kleine-König wrote: > Hello, > > I will organize a PGP keysigning event for the participants of Linux > Plumbers and Open Source Summit Europe in Prague this October. > > The idea is to meet during the two conferences and exchange/verify PGP > fingerprints and (depending on how you practise keysigning) ID checking. > Then each participant back at home can sign the verified certificates to > improve the web of trust. (Current state of the web of trust (as of > commit f8c2189fb65f in the kernel's pgpkeys repo): > > - 654 certificates, among them 12 invalid > - 8088 signatures, 3613 of them invalid > - 9 certificates are not reachable from Greg's stable key > (38DBBDC86092693E). > - 317 certificates are not reachable from Linus's cert > (79BE3E4300411886). (That's why Greg is used as trust root since some > time.) > - strong set size: 289 > - average distance in the strong set: 4.85 > - maximal distance in the strong set: 13 > - Best connected certificate is Daniel Wagner's 587C5ECA5D0A306C which > can reach the other strong set certs with an average of 3.89 steps. > ) > > The gatherings will be on Tue 2026-10-06 and Thu 2026-10-08 (that is on > the second day of each conference) after the official program. > > I don't know the conference location and also don't have any idea yet > how many people will participate, so I will communicate the location and > exact time later. (If you have insights about the possibilities there, > please reach out.) > > While it's not mandatory, please register by sending your PGP > certificate ("public key") to lpcosse-keysigning@baylibre.com until > 2026-09-27 08:00 UTC. Your certificate doesn't need to be in the kernel > pgpkeys repo for that. I will prepare a text file with all the > registered certificates to speed up the event using the > Zimmermann–Sassaman key-signing protocol[1]. You can join without > sending your certificate, but then you have to care yourself about how > to share your fingerprint. (Probably use gpg-key2ps to prepare paper > slips with your certificate data. Having some of these even if you're on > the list might be a good idea.) While as much as I like key signing, I do not believe in Zimmermann–Sassaman protocol to work, because of people's negligence. It requires the participants to check if THEIR key is correct, but based on my recent practice (people generated new key and week later they lost password to it; people received my signed keys and could not decrypt the message because they never used encrypted email, people sent me emails asking to send their keys) I think it has significant risk of this not happening. People just do not understand the security principles here thus they do not think certain steps are an absolute requirement. IOW, I do not believe people will check their key fingerprints and email IDs, they will gladly accept what you prepared on the server and that could have been modified by an attacker or mischievous actor wanting to prank us. That's why I require that the keys to be given to me must be prepared by that owner, not by a third party. I have some proofs that at least that key was in the possession of the owner, when he was preparing it. I will be happy to sign keys of developers given to me that way. I know that you want to speed it up, but honestly korg keysigning should not have that many participants, so exchanging key slips should be fine as I was doing in the past. Best regards, Krzysztof