Re: Replacement GPG key for Sasha Levin

Uwe Kleine-König <[email protected]> Wed, 25 Mar 2026 07:28:40 +0100
Newsgroups org.kernel.linux.keys
Message-ID <acN9F9hCGUliPkQh@monoceros>
--jqljjwrfb5222lkl
Content-Type: text/plain; protected-headers=v1; charset=us-ascii
Content-Disposition: inline
Subject: Re: Replacement GPG key for Sasha Levin
MIME-Version: 1.0

Hello Sasha,

On Tue, Mar 24, 2026 at 08:49:53PM -0400, Sasha Levin wrote:
> Please add my new ed25519 GPG key to the keyring, replacing my old RSA-4096 key
> (E27E5D8A3403A2EF66873BBCDEA66FF797772CDC).

In contrast to the old certificate the new one makes `sq cert lint`
happy, so that's a good step. (The old one resulted in
	Certificate DEA66FF797772CDC contains a User ID (Sasha Levin <[email protected]>) protected by SHA-1
	Certificate DEA66FF797772CDC contains a User ID (Sasha Levin <[email protected]>) protected by SHA-1
	Certificate DEA66FF797772CDC, key D0065D755EB09DBB uses a SHA-1-protected binding signature.
.)

> The new key is cross-signed by the old one.

The old cert only has a single trust path (see
https://git.kernel.org/pub/scm/docs/kernel/pgpkeys.git/plain/graphs/DEA66FF797772CDC.svg),
as the new cert is only signed by the old, it also only has a single path
through the old one. It would be great to improve that, still because
that single path goes away when the old cert is removed.

Best regards
Uwe

--jqljjwrfb5222lkl
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmnDgJYACgkQj4D7WH0S
/k75Jwf/ZC80FRdslxRL2ppr8QJowXkQMuno10VvXuMT6PMDkarVedoVlzO22Jnt
WQ4cL9U7RdKuj+yba2z2pJVC/Zdyj6Us/BKbycpierlGXJLy4raa6IVbbpOwWHYq
JKt+iY941YvzE9yppYQcHgiqaE1ccgTp1Z8d64RjZqAzxPLLny7neqQabeFa0KU9
PZSUFX4NWdKtsZ6aIgMzpWeRSblWZqbuUDT5XmbEpiilEQGN7JVdmOzBExBwdnQU
IT9Zvr1Zb6xM+cuG8qAN41cruWjRhv9wtUKJ+TLzbDiweUXzwJ+67a8sSOLOtCmv
IkEMi+MfI3owFS6gRoS9VyHwyL5R+Q==
=rtNT
-----END PGP SIGNATURE-----

--jqljjwrfb5222lkl--