[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debconf-discuss] Follow-up: additional checks you can do



Manoj Srivastava wrote: 
> On 27 May 2006, Moritz Muehlenhoff stated:
> 
> > I'm more in favour of the trouble-maker part. I had a printed copy
> > from Anibal because I was on the road in Mexico prior to DebConf and
> > couldn't make a printout in time.  If you would have asked, I would
> > have confirmed you that I had checked the file by the checksum read
> > aloud by Martin. In fact, my paper did even have checkmarks on it.
> 
>         How do you know the piece pf paper you got came from the file
>  whose fingerprint was read?
<snip>

It's not necessary to know that at the time of the KSP, because it only
serves as a list of names (and maybe some other identifiers such as DoB)
to be checked.  Of course it is essential to compare those details
between paper and file before selecting the keys to sign from the file.

Ben.

-- 
Ben Hutchings
Anthony's Law of Force: Don't force it, get a larger hammer.

Attachment: signature.asc
Description: This is a digitally signed message part


Reply to: