亿万精品邮址低价大出售,详情请看网站内容。

2002-12-04 Thread 邮址网
꿅᣼http://emving.126.com   Email:[EMAIL PROTECTED]


ÍøÂçʱ´ú£¬²»ÂÛÊDzúÆ·ÓªÏú»¹Êǹã¸æÐû´«£¬ÓµÓдóÁ¿µÄ¿Í»§ÓʼþµØÖ·½«Êdzɹ¦µÄ¹Ø¼ü£¬
ÎÒÃÇÄ¿Ç°ÊÕ¼¯¸÷ÀàE-mailµØÖ·½üÒ»ÒÚ¾ÅǧÎå°ÙÍò¸ö£¬ÏÖ¹«¿ª³öÊÛ£¬Æä×÷ΪһÖÖ°²È«¡¢¿ì
ËÙ¡¢Á®¼Û¡¢·½±ãµÄ¹ã¸æýÌ壬¼«ÊʺϷ¢²¼É̼ҴÙÏúÐÅÏ¢¼°¸÷Àà¿ìѶ¡¢·¢Ë͸÷ÖÖ²úÆ·¼°·þ
ÎñµÄ¹ã¸æ¡¢¶ÌÆÚÄڵĹã¶ø¸æÖªÓ빩ÇóÐÅÏ¢µÈ£¬·½±ãÄúÊ÷Á¢ÆóҵƷÅÆ£¬ÍƹãÆóÒµÐÎÏ󣬽¨
Á¢ÖØÒªµÄÆóÒµ¿Í»§Èº,ÐγÉÆóÒµÓªÏúÎÄ»¯µÄÁíÒ»¸öÖØÒªºËÐÄ¡£¡£¡£¡£¡£




ÒÚÍò¾«Æ·ÓÊÖ·µÍ¼Û´ó³öÊÛ,ÏêÇéÇë¿´ÍøÕ¾ÄÚÈÝ¡£»ØÐÅÇëдȫEMAILµØÖ·£¬²»È»½«ÎÞ·¨»ØÐÅ¡£


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



亿万精品邮址低价大出售,详情请看网站内容。

2002-12-04 Thread 邮网
꿅᣼http://emving.126.com   Email:[EMAIL PROTECTED]


ÍøÂçʱ´ú£¬²»ÂÛÊDzúÆ·ÓªÏú»¹Êǹã¸æÐû´«£¬ÓµÓдóÁ¿µÄ¿Í»§ÓʼþµØÖ·½«Êdzɹ¦µÄ¹Ø¼ü£¬
ÎÒÃÇÄ¿Ç°ÊÕ¼¯¸÷ÀàE-mailµØÖ·½üÒ»ÒÚ¾ÅǧÎå°ÙÍò¸ö£¬ÏÖ¹«¿ª³öÊÛ£¬Æä×÷ΪһÖÖ°²È«¡¢¿ì
ËÙ¡¢Á®¼Û¡¢·½±ãµÄ¹ã¸æýÌ壬¼«ÊʺϷ¢²¼É̼ҴÙÏúÐÅÏ¢¼°¸÷Àà¿ìѶ¡¢·¢Ë͸÷ÖÖ²úÆ·¼°·þ
ÎñµÄ¹ã¸æ¡¢¶ÌÆÚÄڵĹã¶ø¸æÖªÓ빩ÇóÐÅÏ¢µÈ£¬·½±ãÄúÊ÷Á¢ÆóҵƷÅÆ£¬ÍƹãÆóÒµÐÎÏ󣬽¨
Á¢ÖØÒªµÄÆóÒµ¿Í»§Èº,ÐγÉÆóÒµÓªÏúÎÄ»¯µÄÁíÒ»¸öÖØÒªºËÐÄ¡£¡£¡£¡£¡£




ÒÚÍò¾«Æ·ÓÊÖ·µÍ¼Û´ó³öÊÛ,ÏêÇéÇë¿´ÍøÕ¾ÄÚÈÝ¡£»ØÐÅÇëдȫEMAILµØÖ·£¬²»È»½«ÎÞ·¨»ØÐÅ¡£


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Looking for tester/sponsor for koch-suite and magnetic

2002-12-04 Thread Michael Bussmann
Hi there,

I have packaged

Package name: koch-suite
Version : 0.7.1
Upstream Author : Michael Lestinsky <[EMAIL PROTECTED]>
URL : http://koch-suite.berlios.de/
Licence : BSD
Description : A PHP based recipe management system
 The Koch-Suite is a PHP-based recipe management system for Unix-like
 OS.  It uses MySQL or PostgreSQL as database-backend.

and

Package name: magnetic
Version : 2.1
Upstream Author : Niclas Karlsson <[EMAIL PROTECTED]>
  David Kinder <[EMAIL PROTECTED]>
  Stefan Meier <[EMAIL PROTECTED]>
  Paul D. Doherty <[EMAIL PROTECTED]>
  Torbjörn Andersson <[EMAIL PROTECTED]>
URL : http://www.if-legends.org/~msmemorial/magnetic.htm
Licence : GPL
Description: An interpreter for Magnetic Scrolls adventures
 Magnetic is an interpreter for the games written between 1985 and
 1991 by Magnetic Scrolls, a text adventure producer based in London,
 England.  Although they only produced seven games they have acquired
 legendary status for text adventures of as good quality as Infocom
 accompanied by exceptional graphics.

The packages can be downloaded from
http://www.fgan.de/~bus/Debian/src/magnetic/
and
http://www.fgan.de/~bus/Debian/src/koch-suite/

(or via apt: http://www.fgan.de/~bus/Debian testing main)

As these are my first packages I'd be thankful for any suggestions and
critics.

Best regards,
MB

-- 
Michael Bussmann <[EMAIL PROTECTED]>
When the men on the chessboard get up and tell you where to go,
And you've just had some kind of mushroom and your mind is moving low.
Go ask Alice; I think she'll know.
-- Jefferson Airplane, "White Rabbit"


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




RFS: gkrellmitime - Internet time plugin for gkrellm

2002-12-04 Thread Juan Manuel García Molina
Hi all.

I'm looking for a sponsor to upload to Debian's repository gkrellmitime 
package.

This is a new package containing an Internet plugin for gkrellm (I posted an 
ITP bug few months ago).

The files can be obtained at:
http://www.superiodico.net/debian/upload/

Thank you very much for your help.

Thanks and regards.

-- 
Juan Manuel  García Molina
   [EMAIL PROTECTED]


--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: signing a GPG key with multiple uids

2002-12-04 Thread John H. Robinson, IV
Osamu Aoki wrote:
> On Wed, Dec 04, 2002 at 03:05:57AM +0100, Rene Engelhard wrote:
> > > which have that address in it.
> > 
> > I sign a uid when these uid's address is not bouncing and the person who
> > claims to belong to this key answers a message encrypted to him sent
> > to the specific uid. If the person answers to all the mails sent to
> > him, I can sign all uid's.
> 
> This sounds like good practice but burden of proof for the "activeness"
> of e-mail account is on signer side.  A bit unfiar, IMHO.

this is as it should be. a signer needs to take Due Diligence when
saying ``Yes. I know that this key matches this Name and EMail address.''
failure to do that renders that signature, and potentially all other
signatures made by that signer. the whole Web-of-Trust thing.

some people do take more care than others when signing, and that is
okay. but the onus is always on the signer to verify that the facts as
she understands them are true.

-john


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Best practices of GPG signing

2002-12-04 Thread Osamu Aoki
I am wondering what is the best practice for me to gather and exchange
GPG signature.

  (I now have 2 e-mail accounts associated to my GPG key.  
   One e-mail address before I joined Debian and one with @debian.org.)

1) Should I gather signature for all active e-mail addresses?
   (Is signature only for [EMAIL PROTECTED] enough?  Is the act of asking
   signer to sign alternative address considered useless request? Or is
   it worthy cause?)

2) Should I print these alternative e-mail addresses on my Debian
   business card for the convenience of signer.  (I never see that in my
   experience but people tends to have multiple uids.)

3) Is it a good practice to ask people who signed only old uid to sign
   new uid?  (I do this with GPG signed mail.)

4) If someone who used only his ex-work address in GPG key, is it OK to
   sign his new uid by exchanging mail through different mail address
   but with properly signed mails?

5) How important is the uid field?  After all e-mail address can easily
   be spoofed. (For me, it looks totally secondary.  Important thing is
   possession of the secret key.)

-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: signing a GPG key with multiple uids

2002-12-04 Thread Osamu Aoki
Hi,

On Wed, Dec 04, 2002 at 10:04:21AM -0800, John H. Robinson, IV wrote:
> Osamu Aoki wrote:
> > On Wed, Dec 04, 2002 at 03:05:57AM +0100, Rene Engelhard wrote:
> > > > which have that address in it.
> > > 
> > > I sign a uid when these uid's address is not bouncing and the person who
> > > claims to belong to this key answers a message encrypted to him sent
> > > to the specific uid. If the person answers to all the mails sent to
> > > him, I can sign all uid's.
> > 
> > This sounds like good practice but burden of proof for the "activeness"
> > of e-mail account is on signer side.  A bit unfiar, IMHO.
> 
> this is as it should be. a signer needs to take Due Diligence when
> saying ``Yes. I know that this key matches this Name and EMail address.''
> failure to do that renders that signature, and potentially all other
> signatures made by that signer. the whole Web-of-Trust thing.
> 
> some people do take more care than others when signing, and that is
> okay. but the onus is always on the signer to verify that the facts as
> she understands them are true.

Sure I agree in your point of due dilligence.  (I said "a bit".)  

I do not want to make life any harder for the people signing my GPG key
either.

I think question was not well formed and discussion is drifting away.  I
started different thread to address my real question.

Thanks.

Osamu
-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: signing a GPG key with multiple uids

2002-12-04 Thread Michael Banck
On Wed, Dec 04, 2002 at 11:09:09AM -0800, Osamu Aoki wrote:
> I do not want to make life any harder for the people signing my GPG key
> either.

It's a reasonable thing to check whether an email-address is valid
before signing it IMHO.

Michael

-- 
 we should propose to rename the FSG to DFSG as our first action


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: signing a GPG key with multiple uids

2002-12-04 Thread Osamu Aoki
On Wed, Dec 04, 2002 at 08:12:37PM +0100, Michael Banck wrote:
> On Wed, Dec 04, 2002 at 11:09:09AM -0800, Osamu Aoki wrote:
> > I do not want to make life any harder for the people signing my GPG key
> > either.
> 
> It's a reasonable thing to check whether an email-address is valid
> before signing it IMHO.

You guys are misunderstanding situation. I have no intention to
circumvent GPG security.

I have 2 valid e-mail addresses and I want both to be signed.  I just
did not wanted signer to skip checking alternative address.

As far as "due diligence" is conceded, skipping "unsure" address was OK.
But that is something I wanted to avoid.

Thanks.

Osamu
-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: Best practices of GPG signing

2002-12-04 Thread Simon Richter
Hi,

On Wed, Dec 04, 2002 at 10:59:06AM -0800, Osamu Aoki wrote:
> 1) Should I gather signature for all active e-mail addresses?
>(Is signature only for [EMAIL PROTECTED] enough?  Is the act of asking
>signer to sign alternative address considered useless request? Or is
>it worthy cause?)

Of course more signatures are better, as the web of trust is also useful
outside of Debian.

> 2) Should I print these alternative e-mail addresses on my Debian
>business card for the convenience of signer.  (I never see that in my
>experience but people tends to have multiple uids.)

Well, I have separate cards with all my uids and subkeys on them, which
I use for signing purposes. Business cards are something different, I
have different cards for different "personalities" of mine -- i.e. one
with my private address, one for Debian, one for the uni, one for work,
... But I think this is sort of the German mentality to keep everything
apart.

> 3) Is it a good practice to ask people who signed only old uid to sign
>new uid?  (I do this with GPG signed mail.)

I'd say it depends. It makes sense if you're going to make heavy use of
the new uid, so people can easily validate it.

> 4) If someone who used only his ex-work address in GPG key, is it OK to
>sign his new uid by exchanging mail through different mail address
>but with properly signed mails?

I think yes, because that should still be the same person, and if the
key was stolen and someone is trying to get mails diverted, there should
be a revocation around soon.

> 5) How important is the uid field?  After all e-mail address can easily
>be spoofed. (For me, it looks totally secondary.  Important thing is
>possession of the secret key.)

Generally that's what the different levels of how you checked the uids
mean. If you have seen the ID card, use level 2, if you've checked the
mail address, use level 3. Where some years of correspondence replace
pinging the account, at least for me. :-)

   Simon

-- 
GPG Fingerprint: 040E B5F7 84F1 4FBC CEAD  ADC6 18A0 CC8D 5706 A4B4



msg08050/pgp0.pgp
Description: PGP signature


亿万精品邮址低价大出售,详情请看网站内容。

2002-12-04 Thread 邮址网
网址:http://emving.126.com   Email:[EMAIL PROTECTED]


网络时代,不论是产品营销还是广告宣传,拥有大量的客户邮件地址将是成功的关键,
我们目前收集各类E-mail地址近一亿九千五百万个,现公开出售,其作为一种安全、快
速、廉价、方便的广告媒体,极适合发布商家促销信息及各类快讯、发送各种产品及服
务的广告、短期内的广而告知与供求信息等,方便您树立企业品牌,推广企业形象,建
立重要的企业客户群,形成企业营销文化的另一个重要核心。




亿万精品邮址低价大出售,详情请看网站内容。回信请写全EMAIL地址,不然将无法回信。



亿万精品邮址低价大出售,详情请看网站内容。

2002-12-04 Thread 邮网
网址:http://emving.126.com   Email:[EMAIL PROTECTED]


网络时代,不论是产品营销还是广告宣传,拥有大量的客户邮件地址将是成功的关键,
我们目前收集各类E-mail地址近一亿九千五百万个,现公开出售,其作为一种安全、快
速、廉价、方便的广告媒体,极适合发布商家促销信息及各类快讯、发送各种产品及服
务的广告、短期内的广而告知与供求信息等,方便您树立企业品牌,推广企业形象,建
立重要的企业客户群,形成企业营销文化的另一个重要核心。




亿万精品邮址低价大出售,详情请看网站内容。回信请写全EMAIL地址,不然将无法回信。



Looking for tester/sponsor for koch-suite and magnetic

2002-12-04 Thread Michael Bussmann
Hi there,

I have packaged

Package name: koch-suite
Version : 0.7.1
Upstream Author : Michael Lestinsky <[EMAIL PROTECTED]>
URL : http://koch-suite.berlios.de/
Licence : BSD
Description : A PHP based recipe management system
 The Koch-Suite is a PHP-based recipe management system for Unix-like
 OS.  It uses MySQL or PostgreSQL as database-backend.

and

Package name: magnetic
Version : 2.1
Upstream Author : Niclas Karlsson <[EMAIL PROTECTED]>
  David Kinder <[EMAIL PROTECTED]>
  Stefan Meier <[EMAIL PROTECTED]>
  Paul D. Doherty <[EMAIL PROTECTED]>
  Torbjörn Andersson <[EMAIL PROTECTED]>
URL : http://www.if-legends.org/~msmemorial/magnetic.htm
Licence : GPL
Description: An interpreter for Magnetic Scrolls adventures
 Magnetic is an interpreter for the games written between 1985 and
 1991 by Magnetic Scrolls, a text adventure producer based in London,
 England.  Although they only produced seven games they have acquired
 legendary status for text adventures of as good quality as Infocom
 accompanied by exceptional graphics.

The packages can be downloaded from
http://www.fgan.de/~bus/Debian/src/magnetic/
and
http://www.fgan.de/~bus/Debian/src/koch-suite/

(or via apt: http://www.fgan.de/~bus/Debian testing main)

As these are my first packages I'd be thankful for any suggestions and
critics.

Best regards,
MB

-- 
Michael Bussmann <[EMAIL PROTECTED]>
When the men on the chessboard get up and tell you where to go,
And you've just had some kind of mushroom and your mind is moving low.
Go ask Alice; I think she'll know.
-- Jefferson Airplane, "White Rabbit"



RFS: gkrellmitime - Internet time plugin for gkrellm

2002-12-04 Thread Juan Manuel García Molina
Hi all.

I'm looking for a sponsor to upload to Debian's repository gkrellmitime 
package.

This is a new package containing an Internet plugin for gkrellm (I posted an 
ITP bug few months ago).

The files can be obtained at:
http://www.superiodico.net/debian/upload/

Thank you very much for your help.

Thanks and regards.

-- 
Juan Manuel  García Molina
   [EMAIL PROTECTED]



Re: signing a GPG key with multiple uids

2002-12-04 Thread John H. Robinson, IV
Osamu Aoki wrote:
> On Wed, Dec 04, 2002 at 03:05:57AM +0100, Rene Engelhard wrote:
> > > which have that address in it.
> > 
> > I sign a uid when these uid's address is not bouncing and the person who
> > claims to belong to this key answers a message encrypted to him sent
> > to the specific uid. If the person answers to all the mails sent to
> > him, I can sign all uid's.
> 
> This sounds like good practice but burden of proof for the "activeness"
> of e-mail account is on signer side.  A bit unfiar, IMHO.

this is as it should be. a signer needs to take Due Diligence when
saying ``Yes. I know that this key matches this Name and EMail address.''
failure to do that renders that signature, and potentially all other
signatures made by that signer. the whole Web-of-Trust thing.

some people do take more care than others when signing, and that is
okay. but the onus is always on the signer to verify that the facts as
she understands them are true.

-john



Best practices of GPG signing

2002-12-04 Thread Osamu Aoki
I am wondering what is the best practice for me to gather and exchange
GPG signature.

  (I now have 2 e-mail accounts associated to my GPG key.  
   One e-mail address before I joined Debian and one with @debian.org.)

1) Should I gather signature for all active e-mail addresses?
   (Is signature only for [EMAIL PROTECTED] enough?  Is the act of asking
   signer to sign alternative address considered useless request? Or is
   it worthy cause?)

2) Should I print these alternative e-mail addresses on my Debian
   business card for the convenience of signer.  (I never see that in my
   experience but people tends to have multiple uids.)

3) Is it a good practice to ask people who signed only old uid to sign
   new uid?  (I do this with GPG signed mail.)

4) If someone who used only his ex-work address in GPG key, is it OK to
   sign his new uid by exchanging mail through different mail address
   but with properly signed mails?

5) How important is the uid field?  After all e-mail address can easily
   be spoofed. (For me, it looks totally secondary.  Important thing is
   possession of the secret key.)

-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract



Re: signing a GPG key with multiple uids

2002-12-04 Thread Osamu Aoki
Hi,

On Wed, Dec 04, 2002 at 10:04:21AM -0800, John H. Robinson, IV wrote:
> Osamu Aoki wrote:
> > On Wed, Dec 04, 2002 at 03:05:57AM +0100, Rene Engelhard wrote:
> > > > which have that address in it.
> > > 
> > > I sign a uid when these uid's address is not bouncing and the person who
> > > claims to belong to this key answers a message encrypted to him sent
> > > to the specific uid. If the person answers to all the mails sent to
> > > him, I can sign all uid's.
> > 
> > This sounds like good practice but burden of proof for the "activeness"
> > of e-mail account is on signer side.  A bit unfiar, IMHO.
> 
> this is as it should be. a signer needs to take Due Diligence when
> saying ``Yes. I know that this key matches this Name and EMail address.''
> failure to do that renders that signature, and potentially all other
> signatures made by that signer. the whole Web-of-Trust thing.
> 
> some people do take more care than others when signing, and that is
> okay. but the onus is always on the signer to verify that the facts as
> she understands them are true.

Sure I agree in your point of due dilligence.  (I said "a bit".)  

I do not want to make life any harder for the people signing my GPG key
either.

I think question was not well formed and discussion is drifting away.  I
started different thread to address my real question.

Thanks.

Osamu
-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract



Re: signing a GPG key with multiple uids

2002-12-04 Thread Michael Banck
On Wed, Dec 04, 2002 at 11:09:09AM -0800, Osamu Aoki wrote:
> I do not want to make life any harder for the people signing my GPG key
> either.

It's a reasonable thing to check whether an email-address is valid
before signing it IMHO.

Michael

-- 
 we should propose to rename the FSG to DFSG as our first action



Re: signing a GPG key with multiple uids

2002-12-04 Thread Osamu Aoki
On Wed, Dec 04, 2002 at 08:12:37PM +0100, Michael Banck wrote:
> On Wed, Dec 04, 2002 at 11:09:09AM -0800, Osamu Aoki wrote:
> > I do not want to make life any harder for the people signing my GPG key
> > either.
> 
> It's a reasonable thing to check whether an email-address is valid
> before signing it IMHO.

You guys are misunderstanding situation. I have no intention to
circumvent GPG security.

I have 2 valid e-mail addresses and I want both to be signed.  I just
did not wanted signer to skip checking alternative address.

As far as "due diligence" is conceded, skipping "unsure" address was OK.
But that is something I wanted to avoid.

Thanks.

Osamu
-- 
~\^o^/~~~ ~\^.^/~~~ ~\^*^/~~~ ~\^_^/~~~ ~\^+^/~~~ ~\^:^/~~~ ~\^v^/~~~ +
Osamu Aoki <[EMAIL PROTECTED]>   Cupertino CA USA, GPG-key: A8061F32
 .''`.  Debian Reference: post-installation user's guide for non-developers
 : :' : http://qref.sf.net and http://people.debian.org/~osamu
 `. `'  "Our Priorities are Our Users and Free Software" --- Social Contract



Re: Best practices of GPG signing

2002-12-04 Thread Simon Richter
Hi,

On Wed, Dec 04, 2002 at 10:59:06AM -0800, Osamu Aoki wrote:
> 1) Should I gather signature for all active e-mail addresses?
>(Is signature only for [EMAIL PROTECTED] enough?  Is the act of asking
>signer to sign alternative address considered useless request? Or is
>it worthy cause?)

Of course more signatures are better, as the web of trust is also useful
outside of Debian.

> 2) Should I print these alternative e-mail addresses on my Debian
>business card for the convenience of signer.  (I never see that in my
>experience but people tends to have multiple uids.)

Well, I have separate cards with all my uids and subkeys on them, which
I use for signing purposes. Business cards are something different, I
have different cards for different "personalities" of mine -- i.e. one
with my private address, one for Debian, one for the uni, one for work,
... But I think this is sort of the German mentality to keep everything
apart.

> 3) Is it a good practice to ask people who signed only old uid to sign
>new uid?  (I do this with GPG signed mail.)

I'd say it depends. It makes sense if you're going to make heavy use of
the new uid, so people can easily validate it.

> 4) If someone who used only his ex-work address in GPG key, is it OK to
>sign his new uid by exchanging mail through different mail address
>but with properly signed mails?

I think yes, because that should still be the same person, and if the
key was stolen and someone is trying to get mails diverted, there should
be a revocation around soon.

> 5) How important is the uid field?  After all e-mail address can easily
>be spoofed. (For me, it looks totally secondary.  Important thing is
>possession of the secret key.)

Generally that's what the different levels of how you checked the uids
mean. If you have seen the ID card, use level 2, if you've checked the
mail address, use level 3. Where some years of correspondence replace
pinging the account, at least for me. :-)

   Simon

-- 
GPG Fingerprint: 040E B5F7 84F1 4FBC CEAD  ADC6 18A0 CC8D 5706 A4B4


pgp3uy0R9nO3a.pgp
Description: PGP signature