Pre-Registration Questions

Karl Kornel <kornel.1-ZbGKxL/[email protected]> Thu, 12 Aug 2004 23:23:16 -0400
Newsgroups gmane.comp.security.web-of-trust
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear all,

   I am a Thawte Notary, and I am planning on submitting a registration
request with the Web of Introducers soon.  However, before I do I would
like to make sure that I have the procedure correct.  I'm using PGP
8.1.  Are the following steps correct?

NOTARY REGISTRATION
- ----------------------
 1) Download the GSWoT key and each of the notaries keys.
 2) Add a new User ID to the soon-to-be-registered key.  Leave the
comment and e-mail address fields blank.  Set the name to the GSWoT ID.
 Self-sign it.  Upload the new key to various keyservers (I use the
wwwkeys servers, among others).
 3) Join the GSWoT Yahoo! Canada group.
 4) Send in the registration request using the template provided on the
web site.  Include the Yahoo! ID used to join the GSWoT group.  Do not
continue until the registration is confirmed.
 5) Get the newly-registered key from the keyservers to retrieve the
GSWoT signature, and forward it to other keyservers as necessary.  If
the signed key is e-mailed to me on registration, then skip the first
step and just send out the newly-signed key.
 6) Using the newly-registered key, sign the GSWoT key with a
non-exportable meta-introducer signature.  Set the maximum trust depth
to at least 2.
 7) Post notification here that a new introducer has been registered
and ask that currently-registered users sign the newly-registered key
with exportable meta-introducer signatures (or the equivalent in GPG)
with a trust depth of at least 1 and send the newly-signed key out to
whatever keyserver they normally use.
 8) Sign each introducers key with an exportable meta-introducer
signature with a trust depth of at least 1 and send the newly-signed
key out to the keyservers.
 9) Regularly check various keyservers and perform and synchronizations
(get from one, put to another) that are not handled automatically by
the keyservers.


   From everything that I have read, I am guessing that the above steps
ought to be correct.  Is this true?  Is there something that I missed,
or is one of the steps incorrect.  Thanks in advance for the info!

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQA/AwUBQRwz/p+lVwuP8ZcvEQK6egCg0XucVPeaS/mcQ33x0WldlE8sS1QAoNRM
0pAA8jr8VOZVMm9oOn8OFeQ3
=ZXnj
-----END PGP SIGNATURE-----




To unsubscribe from this group, send an email to:
GSWoT-unsubscribe-hHKSG33TihgD7/[email protected]

Visit us on Gmane - Mail To News
news://news.gmane.org/gmane.comp.security.web-of-trust
http://news.gmane.org/thread.php?group=gmane.comp.security.web-of-trust
 
Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://ca.groups.yahoo.com/group/GSWoT/

<*> To unsubscribe from this group, send an email to:
    GSWoT-unsubscribe-hHKSG33TihgD7/[email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://ca.yahoo.com/docs/info/tos.html