[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: GPG and Signing



On Sun, Apr 01, 2007 at 11:26:54AM +0300, Andrei Popescu wrote:
> Ron Johnson <ron.l.johnson@cox.net> wrote:
> 
> > > What are the advantages to having it?
> > 
> > Using a web of trust, you can validate whether the entity that
> > claims to have sent the email actually sent the email.
> 
> Which makes me wonder, how is anyone to establish such a web of trust
> in this community?
> 
I recall some concept called in-band and out-of-band. So if you want to
have a web-of-trust using pgp/gpg keys for email, you need to have an
out-of-band way of verifying those keys--this is ususally done by
meeting someone in person and examining their ID. This is done for folks
joining the Debian developement community. After you meet them and
verify that its ok, you them add their key to your set of trusted keys.

-- 
|  .''`.  == Debian GNU/Linux == |       my web site:           |
| : :' :      The  Universal     |mysite.verizon.net/kevin.mark/|
| `. `'      Operating System    | go to counter.li.org and     |
|   `-    http://www.debian.org/ |    be counted! #238656       |
|  my keyserver: subkeys.pgp.net |     my NPO: cfsg.org         |
|join the new debian-community.org to help Debian!              |
|_______  Unless I ask to be CCd, assume I am subscribed _______|

Attachment: signature.asc
Description: Digital signature


Reply to: