[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#259078: marked as done (http://www.debian.org/events/keysigning: 132s/key/fingerprint/)



* Pierre Machard <pmachard@debian.org> [2004-07-16 15:58]:
> On Fri, Jul 16, 2004 at 03:47:32PM +0200, Gerfried Fuchs wrote:
>>  This is only true for special keys....  In fact its the last eight hex
>> digits of the *key ID*.  That they match the fingerprint for gnupg keys
>> is a nice benefit, but not the rule for all keys.
> 
> Do you example of keys where this is not the case ?

pub  2048R/3BB8C931 1998-08-31 Andrew Martin Adrian Cater <amacater@debian.org>
  Schl.-Fingerabdruck = E9 20 DF 31 A4 83 91 88  C6 59 58 06 C7 D8 D0 12

pub   768R/A1ADE7C9 1997-04-22 Michael Bramer <grisu@debian.org>
  Schl.-Fingerabdruck = A4 15 08 9D 7B 96 47 EE  0C BC 37 8C AE 4D 82 E6

pub  1024R/3D97C149 1995-11-04 Michael Stone <mstone@debian.org>
  Schl.-Fingerabdruck = 95 93 B5 9F DF CF E9 EF  22 0A CD F5 A0 23 94 B4

 Those doesn't match. And there are some others in the Debian keyring
that don't match neither. And there are good reasons to not ignore such
keys, especially when it comes to the web of trust, which we want to
improve, not weaken, right?

>>  The whole texting though is quite GnuPG centric, so I am not sure if
>> this distinction is really needed here. Just wanted to raise the
>> concern and that sometimes the last eight hex digits of the fingerprint
>> doesn't help at all.
> 
> Probably, but I suppose that nearly everybody is using gnupg. A very few
> people are using pgp those days.

 It is not gnupg vs. pgp, it's RSA keys vs. DSA keys, if I understood it
correctly. It's just that gnupg doesn't like to create RSA keys.

>>  Pierre, are you sure about this change that it is really better?
> 
> Yes it is. Because, it is sure that the last 8 digits are not those of
> the key. In most cases these digits are the last 8 digits of the
> fingerprint. Do not forget that in the beginning we were speaking of the
> 8 lastest digit of the key.

 Yes.  I propose to change it again from fingerprint to key ID, because
that is what it *is* in fact originally and precisely.

 So long,
Alfie
-- 
Jetzt ist Sommer, egal ob man schwitzt oder friert,
Sommer ist, was in deinem Kopf passiert.
Es ist Sommer, ich hab das klar gemacht:
Sommer ist, wenn man trotzdem lacht.   -- Wise Guys, "Es ist Sommer"

Attachment: signature.asc
Description: Digital signature


Reply to: