On Thu, Aug 25, 2011 at 07:35:09PM +0100, MFPA wrote in <531058786.20110825193509@my_localhost>:
HiOn Thursday 25 August 2011 at 7:02:52 PM, in <mid:[email protected]>, Aaron Toponce wrote:If I have a public keyring of all the attendees of the party, then I will want to sign every key in that keyring.You could have a keyring that purported to be all the public keys from the signing party. Unless you checked the fingerprint of each key before signing it, how would you spot any extra or substituted keys for which you had not verified the ID?
The party I was at last weekend (and the first one I ever attended) [1] had all the keys with the signatures on a textfile and requested participants to compute hashes for that document up front and write that down on the print of that file. At the start of the party the hashes were read out aloud so we all knew we were working from the same list of keys.
Then everyone present announced their listed fingerprint was correct for their key.
After that, we checked ID's and verified each others keys. Remco [1] http://ksp.froscon.org/
signature.asc
Description: Digital signature
_______________________________________________ Gnupg-users mailing list [email protected] http://lists.gnupg.org/mailman/listinfo/gnupg-users
