Re: How can I have my GPG public key signed by a CA?

Marc MERLIN <[email protected]> Mon, 15 Apr 2019 11:53:20 -0700
Newsgroups gmane.org.user-groups.linux.svlug
Message-ID <[email protected]>
On Mon, Apr 15, 2019 at 11:33:25AM -0700, Robert Freiberger wrote:
> Hello friends,
> 
> I have been using GPG encryption with work for exchanging attachments via
> email with our partners. While I am trusting that he is sending me the
> correct GPG key and it's signed, I can't really validate this signature as
> it's self-signed. Is there any sort of the third party GPG certificate
> authority that would sign these, or provide another level of verification?

The problem is "how would you trust that they did a good job?"
Should I trust your key because verisign signed it?
Did they check your ID in person (making sure it's not fake) and/or can
vouch as a person? (likely not)

And should I even trust a CA?
https://nakedsecurity.sophos.com/2012/02/02/verisign-hacked/
https://www.insuretrust.com/who-can-you-trust-certificate-authorities-hacked/

PGP is mostly for people who don't trust others (likely for good reason),
and therefore would also not trust a CA signed key much at all.

Marc
-- 
"A mouse is a device used to point at the xterm you want to type in" - A.S.R.
Microsoft is to operating systems ....
                                      .... what McDonalds is to gourmet cooking
Home page: http://marc.merlins.org/