[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: OpenPGP keys at GNU
From: |
Bruno Haible |
Subject: |
Re: OpenPGP keys at GNU |
Date: |
Wed, 11 Dec 2024 18:39:49 +0100 |
Simon Josefsson wrote:
> > This is consistent with the following observation: When I download your
> > PGP key from https://savannah.gnu.org/users/jas, I see that it has only
> > self-signatures.
>
> Savannah admins made a decision to "minimize" uploaded keys, removing
> all signatures. I think that is a bad idea, but some people suggest
> GDPR make people do this.
They not only removed all signatures. They also set an expire date of
2022-05-17, which is earlier than the original expire dates of your keys.
(I did not understand that it was possible for the same key to have
different expire dates, depending on where one gets it from. I thought
it was a gpg2 bug, and it confused me a lot.) See:
$ gpg2 --delete-keys 9AA9BDB11BB1B99A21285A330664A76954265E8C
$ gpg2 --delete-keys B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
$ gpg2 --keyserver keys.openpgp.org --search-keys simon@josefsson.org
$ gpg2 -k
pub rsa3744 2014-06-22 [SC] [expired: 2023-09-19]
9AA9BDB11BB1B99A21285A330664A76954265E8C
uid [ expired] Simon Josefsson <simon@josefsson.org>
$ gpg2 --list-signatures
pub rsa3744 2014-06-22 [SC] [expired: 2023-09-19]
9AA9BDB11BB1B99A21285A330664A76954265E8C
uid [ expired] Simon Josefsson <simon@josefsson.org>
sig 3 0664A76954265E8C 2014-06-22 [self-signature]
sig 3 0664A76954265E8C 2014-06-22 [self-signature]
sig 3 0664A76954265E8C 2014-08-26 [self-signature]
sig 3 0664A76954265E8C 2015-01-15 [self-signature]
sig 3 0664A76954265E8C 2015-08-13 [self-signature]
sig 3 0664A76954265E8C 2016-04-12 [self-signature]
sig 3 0664A76954265E8C 2016-08-11 [self-signature]
sig 3 0664A76954265E8C 2017-01-25 [self-signature]
sig 3 0664A76954265E8C 2017-08-28 [self-signature]
sig 3 0664A76954265E8C 2018-02-26 [self-signature]
sig 3 0664A76954265E8C 2018-08-02 [self-signature]
sig 3 0664A76954265E8C 2019-03-07 [self-signature]
sig 3 0664A76954265E8C 2020-01-01 [self-signature]
sig 3 0664A76954265E8C 2020-01-25 [self-signature]
sig 3 0664A76954265E8C 2020-12-22 [self-signature]
sig 3 0664A76954265E8C 2021-07-21 [self-signature]
sig 3 0664A76954265E8C 2022-03-21 [self-signature]
sig 3 0664A76954265E8C 2022-10-04 [self-signature]
$ gpg2 --delete-keys 9AA9BDB11BB1B99A21285A330664A76954265E8C
$ gpg2 --delete-keys B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
$ gpg2 --keyserver keyserver.ubuntu.com --search-keys simon@josefsson.org
4
$ gpg2 -k
pub ed25519 2019-03-20 [SC] [expires: 2025-04-26]
B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
uid [ unknown] Simon Josefsson <simon@josefsson.org>
sub cv25519 2019-03-20 [E] [expires: 2025-04-26]
sub ed25519 2019-03-20 [S] [expires: 2025-04-26]
sub ed25519 2019-03-20 [A] [expires: 2025-04-26]
$ gpg2 --list-signatures
pub ed25519 2019-03-20 [SC] [expires: 2025-04-26]
B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
uid [ unknown] Simon Josefsson <simon@josefsson.org>
sig 3 D73CF638C53C06BE 2019-03-20 [self-signature]
sig 3 D73CF638C53C06BE 2019-10-23 [self-signature]
sig 3 D73CF638C53C06BE 2020-05-27 [self-signature]
sig 3 D73CF638C53C06BE 2020-12-22 [self-signature]
sig 3 D73CF638C53C06BE 2021-07-21 [self-signature]
sig 3 D73CF638C53C06BE 2022-03-21 [self-signature]
sig 3 D73CF638C53C06BE 2022-10-04 [self-signature]
sig 3 D73CF638C53C06BE 2023-09-01 [self-signature]
sig 3 D73CF638C53C06BE 2024-03-22 [self-signature]
sub cv25519 2019-03-20 [E] [expires: 2025-04-26]
sig D73CF638C53C06BE 2024-03-22 [self-signature]
sub ed25519 2019-03-20 [S] [expires: 2025-04-26]
sig D73CF638C53C06BE 2024-03-22 [self-signature]
sub ed25519 2019-03-20 [A] [expires: 2025-04-26]
sig D73CF638C53C06BE 2024-03-22 [self-signature]
$ gpg2 --delete-keys 9AA9BDB11BB1B99A21285A330664A76954265E8C
$ gpg2 --delete-keys B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
$ gpg2 --import jas-key.gpg
$ gpg2 -k
pub rsa3744 2014-06-22 [SC] [expired: 2022-05-17]
9AA9BDB11BB1B99A21285A330664A76954265E8C
uid [ expired] Simon Josefsson <simon@josefsson.org>
uid [ expired] Simon Josefsson <simon@yubico.com>
pub ed25519 2019-03-20 [SC] [expired: 2022-05-17]
B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
uid [ expired] Simon Josefsson <simon@josefsson.org>
$ gpg2 --list-signatures
pub rsa3744 2014-06-22 [SC] [expired: 2022-05-17]
9AA9BDB11BB1B99A21285A330664A76954265E8C
uid [ expired] Simon Josefsson <simon@josefsson.org>
sig 3 0664A76954265E8C 2021-07-21 [self-signature]
uid [ expired] Simon Josefsson <simon@yubico.com>
sig 3 0664A76954265E8C 2021-07-21 [self-signature]
pub ed25519 2019-03-20 [SC] [expired: 2022-05-17]
B1D2BD1375BECB784CF4F8C4D73CF638C53C06BE
uid [ expired] Simon Josefsson <simon@josefsson.org>
sig 3 D73CF638C53C06BE 2021-07-21 [self-signature]
(Interestingly Ubuntu uses the keyserver keys.openpgp.org by default,
whereas Fedora 41 uses keyserver.ubuntu.com by default. Funny.)
Bruno
- Re: publish PGP-signed git bundles of gnulib?, (continued)
- Re: publish PGP-signed git bundles of gnulib?, Bruno Haible, 2024/12/10
- Re: publish PGP-signed git bundles of gnulib?, Simon Josefsson, 2024/12/10
- Re: publish PGP-signed git bundles of gnulib?, Bruno Haible, 2024/12/10
- Re: publish PGP-signed git bundles of gnulib?, Simon Josefsson, 2024/12/10
- Re: publish PGP-signed git bundles of gnulib?, Bruno Haible, 2024/12/11
- Re: publish PGP-signed git bundles of gnulib?, Simon Josefsson, 2024/12/12
- Re: publish PGP-signed git bundles of gnulib?, Bruno Haible, 2024/12/12
- Re: publish PGP-signed git bundles of gnulib?, Simon Josefsson, 2024/12/12
- Re: OpenPGP keys, Bruno Haible, 2024/12/10
- Re: OpenPGP keys, Simon Josefsson, 2024/12/11
- Re: OpenPGP keys at GNU,
Bruno Haible <=
- Re: OpenPGP keys at GNU, Simon Josefsson, 2024/12/12
- Re: OpenPGP keys, Bruno Haible, 2024/12/11
- Re: OpenPGP keys, Jeffrey Walton, 2024/12/11
- Re: OpenPGP keys, Simon Josefsson, 2024/12/12
- Re: OpenPGP keys, Bruno Haible, 2024/12/12
- Re: OpenPGP keys, Simon Josefsson, 2024/12/12