Re: How can I have my GPG public key signed by a CA?

Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]> Wed, 17 Apr 2019 12:36:58 -0700
Newsgroups gmane.org.user-groups.linux.svlug
Organization If you lived here, you'd be $HOME already.
Message-ID <[email protected]>
Quoting Akkana Peck ([email protected]):

> Rick Moen writes:
> > Web searching for someone having done the heavy lifting, which finds me
> > pages like https://wiki.gnupg.org/WebOfTrust .
> 
> Ah, interesting. From that page it sounds like there never was any
> automagical web of trust following -- you have to connect the dots
> manually, emailing all your friends to ask "Does anyone know Bob?"
> and then, when you find out Alice does, getting her as your "trusted
> introducer" to email you Bob's key that she vouches for.

It's often more like this, IIRC:  At some time in the past, you've
attended a keysigning party with Alice, and entered into your local
trustDB that you have confidence in her signatures of other people's
keys.  As it happens, when you acquire a copy of Bob's key, either from
(the person who claims to be) Bob or from a public keyserver, it arrives
bundled with a signature by Alice (among other people's signatures of
his key), because Alice also at some other point had been in a position
to attest to Bob's key (at a keysigning party or otherwise).

The gpg docs include a broader example
(https://www.gnupg.org/gph/en/manual/x334.html), where Alice has set gpg
to permit reliance on the web of trust only a distance of three keys
away or less, and to require signature of any key by either one fully
trusted signer or by two marginally trusted signers:

In one of the variations shown:  Alice has full trust in Blake and
Dharma's keys because she signed them both personally.  Alice has
marginal trust in either of their reliabilty and caution in signing
other people's keys, and has set a software rule in gpg that two
marginally trustworthy people having vouched for a key is good enough
for for her.  As it happens, at times in the past, Blake and Dharma had
signed Chloe's key, with the result that Alice's copy of gpg considers
Chloe's key fully valid.  And Chloe's signature of Elena's key can be
used by Alice to validate Elena's key, but that's a three-signature
path, as long a web of trust as Alice is willing to rely on, hence
Elena's signature of Geoff is a link too far from Alice's perspective,
until other links emerge.

That'll make more sense, I hope, when you look at the connection graph
and read that page's explanation.

Anyway, no, there isn't a lot of asking around required -- but the more
you and others are able to confidently sign each other's keys, the more
likely that a valid trust path will have already been created when you
need to know whether Ted T'so's key is trustworthy.


I haven't been to all -that- many keysignings, but:

$ gpg --list-sigs rick-IyCrq+X4Fdq2oZ/[email protected]
pub   1024D/6E03C0E3 2000-08-10
uid                  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig 3        6E03C0E3 2000-08-10  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig          104B7390 2001-07-12  Eric Cain <[email protected]>
sig          0722021E 2001-07-13  Tim Potter <[email protected]>
sig          A0B3E88B 2001-07-12  Martin Pool <[email protected]>
sig          0167CA38 2001-07-12  Seth David Schoen <[email protected]>
sig          66FBC18C 2001-07-12  M. Drew Streib <[email protected]>
sig          700A0551 2001-07-12  Evan Prodromou (Securant Technologies, Inc.) <eprodromou-7ow2LzbJouxWk0Htik3J/[email protected]>
sig          D6D549AA 2001-07-13  David Schleef <[email protected]>
sig          763BE901 2001-07-17  Marc MERLIN (Linux BOFH / Mail Goon) <[email protected]>
sig          65242AC1 2001-08-07  Eric Lewis <[email protected]>
sig          372FBD57 2001-08-07  Dale Harris (work address) <[email protected]>
sig          CF157338 2001-08-07  Patrick Wong <[email protected]>
sig          FD7E4A1A 2001-08-07  Aaron Peterson (work address) <[email protected]>
sig          6ABE9DC3 2001-08-07  Daniel Brees <[email protected]>
sig 3        DFB8625B 2004-09-01  Les Kopari (DBA /Dev) <les_kopari-/[email protected]>
sig 3        BBC029CE 2004-08-27  Bill Crooke (Adding new address for attbi to comcast transition) <[email protected]>
sig 3        A2848E99 2004-08-27  Arun K Viswanathan <[email protected]>
sig 3        5E469CA3 2003-01-12  Stefano Maffulli <[email protected]>
sig          DDC5AD42 2002-09-15  Jonathan Adams (VA system administrator) <[email protected]>
sig          55F2B9B0 2001-08-27  Karsten M. Self <[email protected]>
sig          5BE3DCFD 2001-08-26  [User ID not found]
sig          D130D86E 2001-08-26  [User ID not found]
sig          AE895899 2001-08-26  [User ID not found]
sig          B209E8C5 2001-08-26  [User ID not found]
sig          5E26741E 2001-08-26  Don Marti <[email protected]>
sig          2664B9BA 2001-08-07  Rob Lemley <rjlemley-noJAvShuekUnaqmwTs//[email protected]>
sig          144F16A9 2004-09-02  Peter Knaggs <[email protected]>
sig          31A6FBD7 2004-09-25  William R. Ward <[email protected]>
sig 3        6757003D 2004-09-24  David H. Wolfskill (no comment) <[email protected]>
sig 3        282709C9 2004-09-24  Akkana Peck <[email protected]>
sig          BA73D04F 2004-11-11  Parag Mehta <[email protected]>
sig          E65CF0EE 2004-11-11  Parag Mehta <[email protected]>
sig          1BFF2FBD 2004-11-11  Parag Mehta <[email protected]>
sig          FFECBF34 2004-11-11  Parag Mehta <[email protected]>
sig          072DA99A 2004-11-11  Parag Mehta <[email protected]>
sig          57B68612 2004-11-11  "[email protected]" <[email protected]>
sig 3        BD2CA251 2004-11-10  Holt Sorenson (http://www.nosneros.net/hso/crypto_keys/) <[email protected]>
sig 3        66D40E50 2005-02-17  [User ID not found]
sig 3        A1E732BB 2012-01-26  Phil Dibowitz <[email protected]>
sig          0722021E 2001-07-13  Tim Potter <[email protected]>
sig          EAB6AA5B 2005-09-14  [User ID not found]
sig 3        88DBFD17 2012-01-26  Richard Kelly <[email protected]>
sig 3        B477B687 2012-01-26  Antony T Curtis <[email protected]>
sig 3        93755E08 2012-01-26  Robert William Wall <[email protected]>
sig 3        ADCF551F 2012-01-26  Matthew Badin <[email protected]>
sig 3        35EA205E 2012-01-26  Corey Quinn <[email protected]>
sig 3        2E45568D 2012-01-27  Mark Loeser <[email protected]>
sig 3        FF78DF62 2012-01-27  Trevor Sharpe (GPG Key) <tsharpe-aS9lmoZGLiVWk0Htik3J/[email protected]>
sig 3        25716A2D 2012-01-27  Dan Rich <[email protected]>
sig 3        53284DEA 2012-01-27  Joachim Feise <[email protected]>
sig 3        4D4D5123 2012-01-27  Brian Stinson (Go Cats!) <bstinson-OYTqUY/[email protected]>
sig 2        C21A3ED1 2012-01-27  Tony Pelaez (HarryGuerilla) <[email protected]>
sig 3        B95703F8 2012-01-27  J. Joe Feise <[email protected]>
sig 3        720E900A 2012-01-27  Carlos Macasaet <[email protected]>
sig 3        17B9F494 2012-01-27  Seth Aaronson (ubuntu) <[email protected]>
sig 3        83842826 2012-01-28  Phil Dibowitz <[email protected]>
sig 3        BCD8CAEB 2012-01-30  Eric Ray Freeman <eric-C8BhZ69FdQxWk0Htik3J/[email protected]>
sig 2        1EECC332 2012-02-01  Steven Pease <[email protected]>
sig 3        B3001437 2012-02-04  Robert Reedy <[email protected]>
sig 3        792E6EA7 2012-02-07  Jill Rouleau (Bespoke Software Solutions) <[email protected]>
sig 3        E53E5107 2012-03-22  Rajiv M Ranganath <[email protected]>
sig          82F8DEDD 2014-10-28  [User ID not found]
sig 3        DD228FBB 2013-03-24  [User ID not found]
sub   1024g/FC2DDC3B 2000-08-10
sig          6E03C0E3 2000-08-10  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>

pub   2048R/4A3DA709 2018-10-08
uid                  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig 3        4A3DA709 2018-10-08  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig          6E03C0E3 2018-10-08  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>

pub   1024R/6E03C0E3 2014-06-16 [revoked: 2016-08-16]
rev          6E03C0E3 2016-08-16  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
uid                  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig          A0B3E88B 2014-08-05  [User ID not found]
sig          104B7390 2014-08-05  [User ID not found]
sig          D6D549AA 2014-08-05  [User ID not found]
sig          66FBC18C 2014-08-05  [User ID not found]
sig          0722021E 2014-08-05  [User ID not found]
sig          65242AC1 2014-08-05  [User ID not found]
sig          700A0551 2014-08-05  [User ID not found]
sig          2664B9BA 2014-08-05  [User ID not found]
sig          5E469CA3 2014-08-05  [User ID not found]
sig          DDC5AD42 2014-08-05  [User ID not found]
sig          31A6FBD7 2014-08-05  [User ID not found]
sig          5E26741E 2014-08-05  [User ID not found]
sig          FFECBF34 2014-08-05  [User ID not found]
sig          072DA99A 2014-08-05  [User ID not found]
sig          CF157338 2014-08-05  [User ID not found]
sig          FD7E4A1A 2014-08-05  [User ID not found]
sig          6ABE9DC3 2014-08-05  [User ID not found]
sig          BA73D04F 2014-08-05  [User ID not found]
sig          1BFF2FBD 2014-08-05  [User ID not found]
sig          57B68612 2014-08-05  [User ID not found]
sig          372FBD57 2014-08-05  [User ID not found]
sig          B209E8C5 2014-08-05  [User ID not found]
sig          E65CF0EE 2014-08-05  [User ID not found]
sig          282709C9 2014-08-05  [User ID not found]
sig          BBC029CE 2014-08-05  [User ID not found]
sig          A1E732BB 2014-08-05  [User ID not found]
sig          DFB8625B 2014-08-05  [User ID not found]
sig 3        6E03C0E3 2014-08-05  Rick Moen <rick-IyCrq+X4Fdq2oZ/[email protected]>
sig          144F16A9 2014-08-05  [User ID not found]
$


I'm not the only person who considers the command interface of gpg to be 
pretty dreadful.  I need to consult docs or do a Web search to figure
out how to do pretty nearly everything it can do.