Re: Update of James Bottemley's key in the kernel PGP keyring
James Bottomley <[email protected]> Wed, 28 Jan 2026 07:37:09 -0500
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <702051e34bb06831594e4a438182335691563ef1.camel@HansenPartnership.com> |
On Wed, 2026-01-28 at 11:56 +0100, Uwe Kleine-König wrote: > Hello, > > recently (2026-01-16) the subkeys (as tracked in the kernel pgpkeys > repo) of James Bottomley's key expired. He updated the expiry date, > however adding the updated key to the keyring brings some trouble to > the WoT as an update drops SHA1 protected signatures which (among > others) loses the direct signature from Linus to James. I don't think we care about historical signatures or the web of trust any more. The signatures are mostly from the original key signing in 2011 so they'll all be sha1. All we actually care about is people already in the keyring signing the keys of people who aren't but want to be. That's a current not historical function. Regards, James
signature.asc
(application/pgp-signature, 265 B)
-----BEGIN PGP SIGNATURE----- iJEEABMIADkWIQTnYEDbdso9F2cI+arnQslM7pishQUCaXoC9RsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMSwyLDIACgkQ50LJTO6YrIUyCAEAiZ8qkwJL/KlPa+ZO6JuL 6xuFHmoA0RdriAv25lX7/vsBALp+sAMn9odr33SBZ1/9tPdbilkdpl3TlXk08e08 zx2e =aWuH -----END PGP SIGNATURE-----