Re: Web of Trust work [Was: kernel.org tooling update]

Mauro Carvalho Chehab <[email protected]> Fri, 23 Jan 2026 23:55:49 +0100
Newsgroups dev.linux.lists.ksummit
Message-ID <[email protected]>
On Fri, 23 Jan 2026 13:23:58 -0500
Konstantin Ryabitsev <[email protected]> wrote:

> - I said: sure, come up with some code and let's see, as long as the following
>   is assured:
> 
>   - It's opt-in; anyone who is happy using GnuPG can continue without any
>     change

This insurance is enough for me, provided that I can still revoke my
current keys and create new ones whenever needed. For this to keep
working for the ones that don't opt-in, it should still be possible
to update the existing GPG keychain and having gpg key parties from
time to time.

However, it actually means more work for the ones maintaining the
infra, as you'll still need to maintain the current web of trust - at 
least for the current users on it - and then maintain the new solution.

-

From my side, I don't intend to opt-in to a new solution until I trust
it enough - and even after opting in - I'll continue using my GPG key
as a backup plan.


Thanks,
Mauro