[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debconf-discuss] Call for keys for keysigning in Edinburgh during DebConf7



>    I'm wondering how you are going to know that a given signature was
> made by someone who went to the two-hour party and that the signature is
> a result of these two persons attending the party.


My understanding is that Manoj gives little or even no credit to the
signatures of people who participate in such parties and wants to
discard them from his own web of trust.

Of course, I may be wrong in my interpretation of that giant thread
and I'd be happy to be proven wrong.

As a tentative help to Manoj's concern (getting the list of such
untrustable people), I add my own little brick by suggesting to use
the output of "gpg --list-sigs 0xC0143D2D" as a start. As far as I
remember, probably over 95% of the signatures here were done during
Debconf keysigning parties by those weak links in the web of trust.

Of course, adding the owner of 0xC0143D2D at the top of the list is
highly recommended.



Reply to: