Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Re: PGP key question
- X-seq: zsh-users 23694
- From: Clark Dunson <cdunson@xxxxxxxxxxxxxxx>
- To: "zsh-users@xxxxxxx" <zsh-users@xxxxxxx>
- Subject: Re: PGP key question
- Date: Tue, 2 Oct 2018 15:17:11 +0000
- Accept-language: en-US
- Authentication-results: spf=none (sender IP is ) smtp.mailfrom=cdunson@xxxxxxxxxxxxxxx;
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sstinc.onmicrosoft.com; s=selector1-shotspotter-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=VEWUXWNR5x03KPHyvTfPwDLgaDcBCd8nPAUSf5JbdWs=; b=JpgxfQ9cYXi/fyJKkiRARyUMLiMImTFZ+HkVjJZT8lTZCOwQXqwG+bJOfb9mPPfxWe1lTxSeO60LAGqBnXwGpGl8rb0A2deGzBA4G/mKyJuKEd5dRKYeVtI/C2l83/RKfshJ7mRzA+cOWRWHdap/pONPDtupCZqkkksp6Efhl6w=
- In-reply-to: <1538489720.837058.1527925520.5B526C32@webmail.messagingengine.com>
- List-help: <mailto:zsh-users-help@zsh.org>
- List-id: Zsh Users List <zsh-users.zsh.org>
- List-post: <mailto:zsh-users@zsh.org>
- List-unsubscribe: <mailto:zsh-users-unsubscribe@zsh.org>
- Mailing-list: contact zsh-users-help@xxxxxxx; run by ezmlm
- References: <BAC9B7B8-2F94-4B54-ACC0-38AF2E8706C4@contoso.com> <CGME20181002075914epcas5p426151406b599d2f9553ce3294da88016@epcas5p4.samsung.com> <20181002075117.GA7637@neptune.home.b999.me> <20181002082357eucas1p15daa8f2c0502c104b7ffe966c528571e~ZvRMqKvXa1039810398eucas1p1o@eucas1p1.samsung.com> <1538489720.837058.1527925520.5B526C32@webmail.messagingengine.com>
- Spamdiagnosticmetadata: NSPM
- Spamdiagnosticoutput: 1:99
- Thread-index: AQHUWe4vbVTNAZH+F0avmV7V6SlAnKULlYmAgAAJIACAAGIuAP//m+4A
- Thread-topic: PGP key question
Great you guys, thank you so much. Glad to hear that source forge hasn't swooped so low as cnet.
My coworker Thibault was showing me around zsh yesterday. I think I actually drooled.
Cheers
Clark
On 10/2/18, 7:16 AM, "Daniel Shahaf" <d.s@xxxxxxxxxxxxxxxxxx> wrote:
Peter Stephenson wrote on Tue, 02 Oct 2018 09:23 +0100:
> On Tue, 2 Oct 2018 08:51:17 +0100
> Ben Oliver <ben@xxxxxxxxxxxx> wrote:
> > On 18-10-02 01:21:03, Clark Dunson wrote:
> > >gpg: WARNING: This key is not certified with a trusted signature!
> > >
> > >gpg: There is no indication that the signature belongs to the owner.
> > >
> > >Primary key fingerprint: E966 46BE 08C0 AF0A A0F9 0788 A5FE EE3A C793 7444
> > >
> > > Subkey fingerprint: 6EB6 0B63 7CE5 ACBF 2449 A2DA DB27 E997 429A F20C
> > >
> > >Is there a concern here?
> >
> > This is just a warning that you have not personally signed the key, ie
> > verified that you know this person.
> >
> > gpg just knows that key X was used to sign the package, it doesn't know
> > if the key truly belongs to the owner - that's on you to find out. If
> > you are 100% sure (usually after meeting the owner) you can sign the key
> > to avoid the warning.
In gpg(1), you can use 'lsign' to mark the key as known without
accidentally publishing the signature. This is useful even without
verifying my identity, since it'll allow you to be sure that the 5.7
artifacts (when that version is released) will have been signed by the
same key who signed the 5.6.2 artifacts.
> To fill in the obvious: we're quite sure the releases were actually
> signed either by Daniel or me.
Messages sorted by:
Reverse Date,
Date,
Thread,
Author