[H-GEN] Key-signing at Humbug: Saturday, 1st March 2003

Anthony Towns aj at azure.humbug.org.au
Mon Feb 24 23:55:15 EST 2003


On Tue, Feb 25, 2003 at 02:21:08PM +1000, Robert Brockway wrote:
> > Robert Brockway <robert at timetraveller.org> writes:
> > > On Mon, 24 Feb 2003, Raymond Smith wrote:
> > > > [3] Of course, Mark Suter himself requires no authentication as he is
> > > >     inimitable. :-)
> > > Does this mean Mark is self signed? :)
> > Of course, everyone's key should be self-signed.  Right?
> In my experience that term usually refers only to a Root certificate.  So
> if you self sign you are setting yourself up as a root CA.

From gpg(1):

]  --allow-non-selfsigned-uid
]            Allow  the import and use of keys with user IDs which are not
]            self-signed.  This is not recommended, as a  non  self-signed
]            user ID is trivial to forge.

The security implications are probably different wrt cryptosystems other
than PGP.

Cheers,
aj

-- 
Anthony Towns <aj at humbug.org.au> <http://azure.humbug.org.au/~aj/>
I don't speak for anyone save myself. GPG signed mail preferred.

  ``Dear Anthony Towns: [...] Congratulations -- 
        you are now certified as a Red Hat Certified Engineer!''
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 350 bytes
Desc: not available
URL: <http://lists.humbug.org.au/pipermail/general/attachments/20030225/63884414/attachment.sig>


More information about the General mailing list