[vox] Let's have a key signing party this Monday!

Ken Bloom kbloom at gmail.com
Sun Nov 20 17:46:15 PST 2005


Scott Ritchie wrote:
> Hey folks, I need some trustworthy folk to sign my GPG key so I can work
> my way into the Debian and Ubuntu webs of trust in order to properly
> upload packages.
> 
> So, let's sign some keys this Monday.  Heck, we can even have a party!
> There's a howto for it here:
> http://www.cryptnet.net/fdp/crypto/gpg-party.html
> 
> I think the best way to do this is to select a hapless coordinator, who
> comes with a printed list of all the keyids and fingerprints using the
> handy pearl script there, which we then take a copy of so we can sign
> keys in bulk.
> 
> So, here is my keyid: 387EE263
> My fingerprint is: 0CDE E38B C356 1EF8 BD46 82BE 5840 3026 387E E263
> Name is: Scott Ritchie
> Email is: scott at open-vote.org
> 
> Now, if I am understanding this right, I go to the meeting with the key
> and fingerprint, and you verify that it matches and I am me, and then
> you go home and download my key off of a keyserver, verify that it's
> fingerprint is the same, sign it and then upload it or send it to me
> (and then I upload it).
> 
> So, who else is in?

To be in the Debian web of trust, you need to have a Debian developer
sign your key. (I would imagine this should also suffice for the ubuntu
web of trust since they use debian packages).

http://www.debian.org/devel/join/nm-step2 describes the process

https://nm.debian.org/gpg_offer.php Lists Debian developers who sign
keys, by locality.

I met a few developers, including Branden Robinson, Joshua Kwan, and Don
Armstrong at LinuxWorld a few years ago and got my key signed then.

Don't try to become a Debian Developer yet. Instead, file an ITP[0] bug
against WNPP[1], indicating that you plan to package your software,
indicate in the ITP that you're not a DD[2] and you'll need a sponsor,
and also head over to debain-mentors at lists.debian.org and post an RFS[3]
there.

When you've got some experience behind you, then apply to become a DD at
http://nm.debian.org.

Godwilling, my first package, link-grammar[4] will be uploaded soon.

--Ken Bloom

[0] Intent to Package. The bug should have ITP at the beginning of the
    title.
[1] http://www.us.debian.org/devel/wnpp/
[2] Debian Developer
[3] Request for Sponsor
[4] http://lists.debian.org/debian-wnpp/2005/11/msg00082.html

-- 
I usually have a GPG digital signature included as an attachment.
See http://www.gnupg.org/ for info about these digital signatures.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 256 bytes
Desc: OpenPGP digital signature
Url : http://ns1.livepenguin.com/pipermail/vox/attachments/20051120/7e742116/signature.pgp


More information about the vox mailing list