PGP Keysigning

From What The Wiki?!

(Redirected from PGP keysigning)

Contents

Latest News

List frozen and available for download!

Since noone was attempting to take over the coordination I (Sebastian Krohn) will try to get it going. There is now the final list available for download. (Sorry for some messed up characters. Please blame the Perl script ;-))

What you - as a participant - should now do is:

  • print the above mentioned list on a piece of dead tree
  • compute the md5 and/or sh1 checksum of the file, e.g. with 'gpg --print-mds'. (Compute them on your own!) You should get something that starts like this:
 MD5 (list.html) = d7 43 4d fe 13 9a a6 5b e4 .. .. .. .. .. .. ..
 SHA1 (list.html) = f89b 3fa6 d980 39b6 d75d .... .... .... .... ....
  • Write the checksum(s) on top of the list and bring it together with your passport to WTH

When will all this take part?

It's scheduled for day 3, 18:00 in Tent 4. I think we should start with the Keysigning at about 18:15?


Help! I wasn't able to print the list before i travelled to WTH!

I will bring some extra printouts with me. Don't panic.

Help! I was too late putting my key on the list

The you still have a chance of getting signed and sign others' key:

  • Bring your key ID together with the fingerprint printed on many paper stripes so you can hand everyone a copy with your id/fingerprint.
  • Take a list of the participants from Seb (see above) and follow the whole event.

After that you can sign the keys on the list and others can sign yours if you handed them a paper stripe.

Sorry but we have to put a deadline if this should not end in chaos.

What and why?

The basic idea of this page is to organize a big PGP key signing party at WTH.

The main intentention of a keysigning is to improve your personal web of trust. When you create a PGP-key, nobody knows if it really belongs to you. (You can create keys for any name you want.) Therefore people meet at keysignings and compare the data on a persons key with its passport or any other official documents. If they believe, that key and person belong to each other, they will sign your key.

So you can improve the trustlevel of your key and you'll also got to know some interesting people.

The keysigning will be held together with other signings, see: the event mentioned in the program

What can I do to take part?

You should follow those steps:

  1. Create, if not already done, your key. If you'd like to know how to do that, take a look at GPG-Mini-Howto
  2. Load your public key to one of the usual keyservers:
    • subkeys.pgp.net
    • random.sks.keyserver.penguin.de
  3. Put your key ID in the list on this page
  4. Download the compiled list of all participants after the the now passed deadline and print it.
  5. Check your key(s) on the list.
  6. Calculate the MD5- or SHA1-hash of the list and enter these value into the correspondig field.
  7. Take the list and your passport to WTH and enjoy the keysigning :-)

How does the whole thing work?

We will meet at the above mentioned time and will compare the MD5-/SHA1-values that everyone has calculated for his own. If these values are all equal, everyone has the same version of the list. Hereafter we create a long line and everyone will check fingerprint and passport of its opposite.

When you arrive at home home and you recovered from the WTH-strains, sign all keys which you believe valid.

Suggestion: reading the fingerprints out loud is very tedious and error-prone. Being able to do this visually is much better. I (Iljitsch) once did this by printing a copy of the key info on a transparancy sheet so checking can be done by superimposing the transparant sheet over a user's copy. Another way to do this is to project the fingerprints on a screen.

Who takes part?

  1. Sebastian Krohn 0x82268497 (msd: 4.1001)
  2. Sebastian Roth 0x6E2B43DC (msd: 4.3734)
  3. Tobias Kirschstein 0xD6DED000 (msd: 4.1658)
  4. Nils Vogels 0xAD3A5AAD
  5. DWizzy 0x24C56D3B (msd: 4.814)
  6. BugBlue 0x033849C4 (msd: 4.1174)
  7. Stefan Schmidt 0xDDF51665 (msd:4.0167) Key statistic
  8. Thali 0x9287B2E0
  9. Philipp Drössler 0x198B4E4E
  10. Kai Münz 0x93E2AF93
  11. Jan Lübbe 0xD8480F2E
  12. Andreas Kupfer 0x1D738434
  13. Iljitsch van Beijnum 0x1B1FC4E6
  14. Harald Welte 0x30F48BFF
  15. FooBar (Mark Janssen) 0x357D2178
  16. pepe (Steffen Schulz) 0xA04D7875
  17. David Leder 0xE32CD143
  18. Tobias Lange 0x0043DFB3
  19. mike castleman 0x7E407AF9
  20. Vasil Kolev 0x5A798930
  21. Dapke (Pim van Pelt) 0x4dca7e5e
  22. tehmaze (Wijnand Modderman) 0x2EA206A6
  23. Antti Vähä-Sipilä 0x3DE9A7CA
  24. Enno Lenze 0x45C86402
  25. Jtb 0x41AD84C2 (msd: 4.4968)
  26. mc.fly 0x2ECE6D0F
  27. Miguel van de Laar 0x6FD503FA
  28. Andreas Müller 0x1AAAC2A4
  29. Ivana Belgers 0xA89D21A2
  30. DreckSoft 0xB2270BAD
  31. Nico Fritschi 0xADF08A7F
  32. Martien Remijn 0x003FB5A1
  33. Jeroen Dekkers 0xAC1E715E
  34. Michael Bramer 0x258d8781
  35. Hamster 0xAE620038 (msd: 5.0179)
  36. Nico Wieczorek 0x5B05D8A2
  37. Hendrik Scholz 0x3D883EA0 (msd:3.92809)
  38. Stew 0x365A1AD1
  39. Martin Heistermann 0xBAADDD9D
  40. Henryk Plötz 0x4D0E0368
  41. Mario Lipinski 0x56C516B2
  42. Udo van den Heuvel 0x8300CC02
  43. Cliff Albert 0x9A9B1C5A (msd: 5.0399)
  44. Folkert van Heusden 0x1F28D8AE
  45. Jeroen van Nieuwenhuizen 0xC6AAAF61
  46. Kurt Roeckx 0x7244970B
  47. Lewe Zipfel 0x7A9C29EB
  48. Thomas Kaschwig 0x3D68D63A (msd: 3.9796)
  49. Sven Schnelle 0x25DA21B1
  50. Zeno4ever 0x0FAB3351

List frozen here at Mon Jul 25 14:51:10 CEST 2005

Analyze of the current keyring

I've built a little graph to demonstrate the curent web Of trust in this group of people. I will update the graph every few days, if more people are joining the {list,keysigning}. You can find it at http://www.datenfreihafen.org/~stefan/GPG-PGP/KeySigning-WTH-2005/

I'va add an output from the original keyanalyze code, used by Jason Harris. You can find it in the keyanalyze directory. The individual reports are very useful to look, which keys you have already signed.

In the ranking directory you can yet find some files with ranking information for the current keys.

See also