Keysigning Party @ LinuxTag 2005

Kultiges Zusammensitzen und gemeinsames Murmeln magischer Zahlen.
Gert Döring, FdI 95
At the LinuxTag 2005 in Karlsruhe there will be an OpenPGP (pgp/gpg) keysigning party.

The party will be on Saturday, June 25th, at 14:00.

What is/Why keysigning?

Please read section One of the GnuPG Keysigning Party HOWTO (note: we are doing the party slightly different, so the other chapters do not 100% apply).

How

The party will be conducted using Len Sassaman's Efficient Group Key Signing Method:

Downloads:

Summary: What to bring with you

If you have questions please ask Peter Palfrader <peter@palfrader.org>.

Relevant Information and Sources for More Information

Keyservers

The only keyserver rotation you should use is subkeys.pgp.net, or random.sks.keyserver.penguin.de if you insist. Any of the servers in this rotations is fine.

Please, please, pretty please with a cherry on top, do not use other rotations, like keyserver.net or wwwkeys.pgp.net: They all mangle keys in various ways, including but not limited to dropping subkeys, moving binding sigs around between subkeys, duplicating user ids, modifying signature subpackets (dropping non-hashed data), calculating KeyIDs wrong (for v4 RSA keys), rejecting keys with attribute UIDs (such as photo ids), or don't sync with the rest of the network.

Please use subkeys.pgp.net.

caff

CA Fire and Forget is a script that helps you in keysigning. It takes a list of keyids on the command line, fetches them from a keyserver and calls GnuPG so that you can sign it. It then mails each key to all its email addresses - only including the one UID that we send to in each mail, pruned from all but self sigs and sigs done by you.

Download it: caff.

Depends: gnupg (>= 1.3.92), perl, libgnupg-interface-perl, libmime-perl, libmailtools-perl (>= 1.62)

gpgsigs

Uli Martens wrote a small perl script that, given a key ID and ksp-lt2k5.txt tells you which keys (UIDs) you already signed by annotating the UID with (S).

153  [ ] Fingerprint OK        [ ] ID OK
(S)  pub  1024D/52698E9F 2001-11-07 Uli Martens <uli@youam.net>
     Key fingerprint = A48F 8894 37A0 FDE9 60D5  212A 2A58 CEAA 5269 8E9F
(S)  uid     Uli Martens <isax@gmx.de>
( )  uid     Uli Martens <u.martens@youam.com>
(S)  uid     Uli Martens <u.martens@scientific.de>

Download it: gpgsigs.

It requires perl, gnupg (>=1.2.x) and either Locale::Recode (in Debian Package libintl-perl, in testing and unstable) or recode (Debian Package recode).

A word on GnuPG versions

GnuPG 1.0.*, as shipped with Debian Woody has serious problems. Please consider upgrading to 1.2.*. It's a lot faster too, which you will appreciate I guess. Debian Sarge ships 1.4.1, which is needed for some of the utilities above.

There is a newer GnuPG package at backports.org:

deb http://www.backports.org/debian/ woody gnupg

Keyring analysis

Christoph Berg is running keyanalyze statistics for the keyring used at this KSP: http://www.df7cb.de/debian/ksp-lt2k5/
Last modified: Monday, 20-Jun-2005 01:54:45 CEST
Peter Palfrader <peter@palfrader.org>
This Page Is Valid HTML 4.0 Transitional!