Re: Add [email protected] to 1ED2916A667D8802.asc
Dan Williams <[email protected]> Fri, 10 Apr 2026 13:48:37 -0700
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <[email protected]> |
Uwe Kleine-K=C3=B6nig wrote: > Hallo Dan, > = > On Wed, Apr 08, 2026 at 06:49:33PM -0700, Dan Williams wrote: > > -----BEGIN PGP PUBLIC KEY BLOCK----- > > = > > mQINBE6TN1IBEADBi0Ztes1AmBXGUHh4zp7z8YMykXtF2o+Vd5uscmp0Z+CNoXMu > > waEOmxQjwjC6khh7gl/1i0YNMHtwTaNFgXJKVluH5uMXpeo5GXrCHmI14YNhJmRn > > 3AHzmM8wh9H0lCy96F71Wv13itJINy9AKYarQJcIUmpMxxO/f5VoE1UYeoouy19+ > > ... > > -----END PGP PUBLIC KEY BLOCK----- > = > The two UIDs that are already tracked in the pgpkeys repo are only > protected by SHA1, and also the key binding is affected. GnuPG has no > issues with that, but other tools (e.g. Sequioa) take this more serious= . > (See e.g. https://www.schneier.com/tag/sha-1/ for more details. And > https://lore.kernel.org/keys/fxotnlhsyl2frp54xtguy7ryrucuwselanazixeax3= motyyoo3@7vf7ip6gxyvx/ > for how to fix that.) > = > While you can address this yourself, your key has several signatures > protected by SHA1, which is somewhat the same issue, but you'd need the= > cooperation of the guys who signed your key before, to fix that. The > easiest way to do that is to ask them to resign your certificate. > In return you can offer to resign their certs as there are several > SHA1-protected signatures by you on other keys. See > https://www.kleine-koenig.org/~uwe/resign-sha1/?certid=3D1ED2916A667D88= 02 > for the "todo list". > = > Don't hesitate to ask if questions arise. Certainly the sq instructions look more approachable than doing this with gpg. Given my old intel.com address is now disabled I assume I should just delete that uid and then only need to fixup the gmail one? For using an offline backup gpg directory to redo the signatures looks like I can ask sq to use a different PGP_CERT_D directory. If you have a ready example for that case that would save some fumbling time. > From my side this doesn't need to stop adding your updated cert to the > pgpkeys repo, as it doesn't make things worse than they already are. Thanks for the heads up!=