[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: [Debconf-discuss] DebConf15: Call for keys for keysigning in Heidelberg, Germany



Andreas Tille <andreas@an3as.eu> writes:

> On Mon, Jul 27, 2015 at 02:01:03PM +0200, Christoph Egger wrote:
>> 
>> % ls -lha .caff/gnupghome/gpg.conf 
>> lrwxrwxrwx 1 christoph christoph 31 Nov 15  2010 .caff/gnupghome/gpg.conf -> /home/christoph/.gnupg/gpg.conf
>> 
>> It does if you first ran caff in recent enough times. It just doesn't
>> iff your ~/.caff is "too old"
>
> Ahhh, finally!
>
> However, why not even
>
>    ln -s ~/.gnupg .caff/gnupghome
>
> or in other words, why is .caff using anything else than .gnupg
> pubring etc.

The caff keyring ends up with signed keys in it, does it not?  So that
would introduce the danger of pushing someone else's key, and so
publishing your signature on thier key, whereas the whole point of caff
is to make sure that the signature can only be published if the
recipient controls the matching email address and can decrypt you mail
to them.

Cheers, Phil.
-- 
|)|  Philip Hands  [+44 (0)20 8530 9560]  HANDS.COM Ltd.
|-|  http://www.hands.com/    http://ftp.uk.debian.org/
|(|  Hugo-Klemm-Strasse 34,   21075 Hamburg,    GERMANY

Attachment: signature.asc
Description: PGP signature


Reply to: