Re: Update of James Bottemley's key in the kernel PGP keyring

James Bottomley <[email protected]> Wed, 28 Jan 2026 07:37:09 -0500
Newsgroups org.kernel.linux.keys
Message-ID <702051e34bb06831594e4a438182335691563ef1.camel@HansenPartnership.com>
On Wed, 2026-01-28 at 11:56 +0100, Uwe Kleine-König wrote:
> Hello,
> 
> recently (2026-01-16) the subkeys (as tracked in the kernel pgpkeys
> repo) of James Bottomley's key expired. He updated the expiry date,
> however adding the updated key to the keyring brings some trouble to
> the WoT as an update drops SHA1 protected signatures which (among
> others) loses the direct signature from Linus to James.

I don't think we care about historical signatures or the web of trust
any more.  The signatures are mostly from the original key signing in
2011 so they'll all be sha1.  All we actually care about is people
already in the keyring signing the keys of people who aren't but want
to be.  That's a current not historical function.

Regards,

James
signature.asc (application/pgp-signature, 265 B)
-----BEGIN PGP SIGNATURE-----

iJEEABMIADkWIQTnYEDbdso9F2cI+arnQslM7pishQUCaXoC9RsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDIACgkQ50LJTO6YrIUyCAEAiZ8qkwJL/KlPa+ZO6JuL
6xuFHmoA0RdriAv25lX7/vsBALp+sAMn9odr33SBZ1/9tPdbilkdpl3TlXk08e08
zx2e
=aWuH
-----END PGP SIGNATURE-----