Re: How can I have my GPG public key signed by a CA?
Akkana Peck <[email protected]> Wed, 17 Apr 2019 10:06:06 -0600
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Message-ID | <[email protected]> |
Rick Moen writes: > Web searching for someone having done the heavy lifting, which finds me > pages like https://wiki.gnupg.org/WebOfTrust . Ah, interesting. From that page it sounds like there never was any automagical web of trust following -- you have to connect the dots manually, emailing all your friends to ask "Does anyone know Bob?" and then, when you find out Alice does, getting her as your "trusted introducer" to email you Bob's key that she vouches for. Which would be worthwhile if you need to exchange some super-secret data (indeed, I did this once when exchanging server passwords for a project), or for a project like Debian where there's a well-known set of Debian Developers. But it's not useful for things like verifying random signed messages on mailing lists, since for each new person you see, you'd have to do a lot of asking around among all your friends to figure out which intermediary knows the other person and would be willing to mail you a key they vouch for. Rick Moen writes: > Oh, BTW: > > Quoting Kevin Dankwardt ([email protected]): > > > Rick Moen, Akkana Peck, Robert Freiberger willing to participate? > > Anyone else interested in participating? > > Unless she happens to be visiting the Bay Area, Akkana would be unlikely > as she is no longer local, as, last I heard, she was in New Mexico. Alas, yes. I stay on the SVLUG list (and a few other Bay Area lists) because of the good information and good people, but I escaped the Bay Area for New Mexico five years ago. Otherwise I would have been very interested in a key signing/GPG discussion get-together. ...Akkana