Re: Update of James Bottemley's key in the kernel PGP keyring
James Bottomley <[email protected]> Wed, 28 Jan 2026 08:30:31 -0500
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <13517c3f2e61c898f22f8092df7da7930ee146b8.camel@HansenPartnership.com> |
On Wed, 2026-01-28 at 14:23 +0100, Uwe Kleine-König wrote: > Hello James, > > On Wed, Jan 28, 2026 at 07:37:09AM -0500, James Bottomley wrote: > > On Wed, 2026-01-28 at 11:56 +0100, Uwe Kleine-König wrote: > > > recently (2026-01-16) the subkeys (as tracked in the kernel > > > pgpkeys repo) of James Bottomley's key expired. He updated the > > > expiry date, however adding the updated key to the keyring brings > > > some trouble to the WoT as an update drops SHA1 protected > > > signatures which (among others) loses the direct signature from > > > Linus to James. > > > > I don't think we care about historical signatures or the web of > > trust any more. The signatures are mostly from the original key > > signing in 2011 so they'll all be sha1. All we actually care about > > is people already in the keyring signing the keys of people who > > aren't but want to be. That's a current not historical function. > > Note however that for the model that is actually implemented it's > Linus' signatures that matter. Actually, it's not just Linus. We have about five trust anchors in the kernel.org keyring (also not reflected in the web of trust). > So currently the criteria to get your key added to the keyring is > that there is at least one signature path from Linus to you within > the current keyring of length at most 5 (with counting both Linus and > you). See e.g. > https://git.kernel.org/pub/scm/docs/kernel/pgpkeys.git/plain/graphs/E4B71D5EEC39C284.svg > . A key that is only signed by Karel Zak doesn't qualify to be added. Well isn't that why this whole web of trust signature deprecation thing is wrong. The question, as Linus put it in that email, is *not* does it work now, but did it work then. And since we have the date of the signature we can know it was signed before sha1 was deemed compromised and thus can't be a forgery of Linus' indication of trust in me. And since it's already embedded in a transparency log (git in this case) that date can be proven. Regards, James
signature.asc
(application/pgp-signature, 265 B)
-----BEGIN PGP SIGNATURE----- iJEEABMIADkWIQTnYEDbdso9F2cI+arnQslM7pishQUCaXoPeBsUgAAAAAAEAA5t YW51MiwyLjUrMS4xMSwyLDIACgkQ50LJTO6YrIWzIgEA7PG9gZsLt/KCxgdCxABS 26vCuTxEJH3kBlKpopNtsUEBAMJ7QgCj7JZ6Yp/LprbxbG4yzrrODaoVMRvolq7Q ALuj =7WYa -----END PGP SIGNATURE-----