Re: How can I have my GPG public key signed by a CA?
Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> Wed, 17 Apr 2019 12:36:58 -0700
| Newsgroups | gmane.org.user-groups.linux.svlug |
|---|---|
| Organization | If you lived here, you'd be $HOME already. |
| Message-ID | <[email protected]> |
Quoting Akkana Peck ([email protected]): > Rick Moen writes: > > Web searching for someone having done the heavy lifting, which finds me > > pages like https://wiki.gnupg.org/WebOfTrust . > > Ah, interesting. From that page it sounds like there never was any > automagical web of trust following -- you have to connect the dots > manually, emailing all your friends to ask "Does anyone know Bob?" > and then, when you find out Alice does, getting her as your "trusted > introducer" to email you Bob's key that she vouches for. It's often more like this, IIRC: At some time in the past, you've attended a keysigning party with Alice, and entered into your local trustDB that you have confidence in her signatures of other people's keys. As it happens, when you acquire a copy of Bob's key, either from (the person who claims to be) Bob or from a public keyserver, it arrives bundled with a signature by Alice (among other people's signatures of his key), because Alice also at some other point had been in a position to attest to Bob's key (at a keysigning party or otherwise). The gpg docs include a broader example (https://www.gnupg.org/gph/en/manual/x334.html), where Alice has set gpg to permit reliance on the web of trust only a distance of three keys away or less, and to require signature of any key by either one fully trusted signer or by two marginally trusted signers: In one of the variations shown: Alice has full trust in Blake and Dharma's keys because she signed them both personally. Alice has marginal trust in either of their reliabilty and caution in signing other people's keys, and has set a software rule in gpg that two marginally trustworthy people having vouched for a key is good enough for for her. As it happens, at times in the past, Blake and Dharma had signed Chloe's key, with the result that Alice's copy of gpg considers Chloe's key fully valid. And Chloe's signature of Elena's key can be used by Alice to validate Elena's key, but that's a three-signature path, as long a web of trust as Alice is willing to rely on, hence Elena's signature of Geoff is a link too far from Alice's perspective, until other links emerge. That'll make more sense, I hope, when you look at the connection graph and read that page's explanation. Anyway, no, there isn't a lot of asking around required -- but the more you and others are able to confidently sign each other's keys, the more likely that a valid trust path will have already been created when you need to know whether Ted T'so's key is trustworthy. I haven't been to all -that- many keysignings, but: $ gpg --list-sigs rick-IyCrq+X4Fdq2oZ/[email protected] pub 1024D/6E03C0E3 2000-08-10 uid Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig 3 6E03C0E3 2000-08-10 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig 104B7390 2001-07-12 Eric Cain <[email protected]> sig 0722021E 2001-07-13 Tim Potter <[email protected]> sig A0B3E88B 2001-07-12 Martin Pool <[email protected]> sig 0167CA38 2001-07-12 Seth David Schoen <[email protected]> sig 66FBC18C 2001-07-12 M. Drew Streib <[email protected]> sig 700A0551 2001-07-12 Evan Prodromou (Securant Technologies, Inc.) <eprodromou-7ow2LzbJouxWk0Htik3J/[email protected]> sig D6D549AA 2001-07-13 David Schleef <[email protected]> sig 763BE901 2001-07-17 Marc MERLIN (Linux BOFH / Mail Goon) <[email protected]> sig 65242AC1 2001-08-07 Eric Lewis <[email protected]> sig 372FBD57 2001-08-07 Dale Harris (work address) <[email protected]> sig CF157338 2001-08-07 Patrick Wong <[email protected]> sig FD7E4A1A 2001-08-07 Aaron Peterson (work address) <[email protected]> sig 6ABE9DC3 2001-08-07 Daniel Brees <[email protected]> sig 3 DFB8625B 2004-09-01 Les Kopari (DBA /Dev) <les_kopari-/[email protected]> sig 3 BBC029CE 2004-08-27 Bill Crooke (Adding new address for attbi to comcast transition) <[email protected]> sig 3 A2848E99 2004-08-27 Arun K Viswanathan <[email protected]> sig 3 5E469CA3 2003-01-12 Stefano Maffulli <[email protected]> sig DDC5AD42 2002-09-15 Jonathan Adams (VA system administrator) <[email protected]> sig 55F2B9B0 2001-08-27 Karsten M. Self <[email protected]> sig 5BE3DCFD 2001-08-26 [User ID not found] sig D130D86E 2001-08-26 [User ID not found] sig AE895899 2001-08-26 [User ID not found] sig B209E8C5 2001-08-26 [User ID not found] sig 5E26741E 2001-08-26 Don Marti <[email protected]> sig 2664B9BA 2001-08-07 Rob Lemley <rjlemley-noJAvShuekUnaqmwTs//[email protected]> sig 144F16A9 2004-09-02 Peter Knaggs <[email protected]> sig 31A6FBD7 2004-09-25 William R. Ward <[email protected]> sig 3 6757003D 2004-09-24 David H. Wolfskill (no comment) <[email protected]> sig 3 282709C9 2004-09-24 Akkana Peck <[email protected]> sig BA73D04F 2004-11-11 Parag Mehta <[email protected]> sig E65CF0EE 2004-11-11 Parag Mehta <[email protected]> sig 1BFF2FBD 2004-11-11 Parag Mehta <[email protected]> sig FFECBF34 2004-11-11 Parag Mehta <[email protected]> sig 072DA99A 2004-11-11 Parag Mehta <[email protected]> sig 57B68612 2004-11-11 "[email protected]" <[email protected]> sig 3 BD2CA251 2004-11-10 Holt Sorenson (http://www.nosneros.net/hso/crypto_keys/) <[email protected]> sig 3 66D40E50 2005-02-17 [User ID not found] sig 3 A1E732BB 2012-01-26 Phil Dibowitz <[email protected]> sig 0722021E 2001-07-13 Tim Potter <[email protected]> sig EAB6AA5B 2005-09-14 [User ID not found] sig 3 88DBFD17 2012-01-26 Richard Kelly <[email protected]> sig 3 B477B687 2012-01-26 Antony T Curtis <[email protected]> sig 3 93755E08 2012-01-26 Robert William Wall <[email protected]> sig 3 ADCF551F 2012-01-26 Matthew Badin <[email protected]> sig 3 35EA205E 2012-01-26 Corey Quinn <[email protected]> sig 3 2E45568D 2012-01-27 Mark Loeser <[email protected]> sig 3 FF78DF62 2012-01-27 Trevor Sharpe (GPG Key) <tsharpe-aS9lmoZGLiVWk0Htik3J/[email protected]> sig 3 25716A2D 2012-01-27 Dan Rich <[email protected]> sig 3 53284DEA 2012-01-27 Joachim Feise <[email protected]> sig 3 4D4D5123 2012-01-27 Brian Stinson (Go Cats!) <bstinson-OYTqUY/[email protected]> sig 2 C21A3ED1 2012-01-27 Tony Pelaez (HarryGuerilla) <[email protected]> sig 3 B95703F8 2012-01-27 J. Joe Feise <[email protected]> sig 3 720E900A 2012-01-27 Carlos Macasaet <[email protected]> sig 3 17B9F494 2012-01-27 Seth Aaronson (ubuntu) <[email protected]> sig 3 83842826 2012-01-28 Phil Dibowitz <[email protected]> sig 3 BCD8CAEB 2012-01-30 Eric Ray Freeman <eric-C8BhZ69FdQxWk0Htik3J/[email protected]> sig 2 1EECC332 2012-02-01 Steven Pease <[email protected]> sig 3 B3001437 2012-02-04 Robert Reedy <[email protected]> sig 3 792E6EA7 2012-02-07 Jill Rouleau (Bespoke Software Solutions) <[email protected]> sig 3 E53E5107 2012-03-22 Rajiv M Ranganath <[email protected]> sig 82F8DEDD 2014-10-28 [User ID not found] sig 3 DD228FBB 2013-03-24 [User ID not found] sub 1024g/FC2DDC3B 2000-08-10 sig 6E03C0E3 2000-08-10 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> pub 2048R/4A3DA709 2018-10-08 uid Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig 3 4A3DA709 2018-10-08 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig 6E03C0E3 2018-10-08 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> pub 1024R/6E03C0E3 2014-06-16 [revoked: 2016-08-16] rev 6E03C0E3 2016-08-16 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> uid Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig A0B3E88B 2014-08-05 [User ID not found] sig 104B7390 2014-08-05 [User ID not found] sig D6D549AA 2014-08-05 [User ID not found] sig 66FBC18C 2014-08-05 [User ID not found] sig 0722021E 2014-08-05 [User ID not found] sig 65242AC1 2014-08-05 [User ID not found] sig 700A0551 2014-08-05 [User ID not found] sig 2664B9BA 2014-08-05 [User ID not found] sig 5E469CA3 2014-08-05 [User ID not found] sig DDC5AD42 2014-08-05 [User ID not found] sig 31A6FBD7 2014-08-05 [User ID not found] sig 5E26741E 2014-08-05 [User ID not found] sig FFECBF34 2014-08-05 [User ID not found] sig 072DA99A 2014-08-05 [User ID not found] sig CF157338 2014-08-05 [User ID not found] sig FD7E4A1A 2014-08-05 [User ID not found] sig 6ABE9DC3 2014-08-05 [User ID not found] sig BA73D04F 2014-08-05 [User ID not found] sig 1BFF2FBD 2014-08-05 [User ID not found] sig 57B68612 2014-08-05 [User ID not found] sig 372FBD57 2014-08-05 [User ID not found] sig B209E8C5 2014-08-05 [User ID not found] sig E65CF0EE 2014-08-05 [User ID not found] sig 282709C9 2014-08-05 [User ID not found] sig BBC029CE 2014-08-05 [User ID not found] sig A1E732BB 2014-08-05 [User ID not found] sig DFB8625B 2014-08-05 [User ID not found] sig 3 6E03C0E3 2014-08-05 Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> sig 144F16A9 2014-08-05 [User ID not found] $ I'm not the only person who considers the command interface of gpg to be pretty dreadful. I need to consult docs or do a Web search to figure out how to do pretty nearly everything it can do.