Re: Moving away from SHA-1

2014-02-12 Thread Per Tunedal
Hi Peter, Yes, I've searched the archives. Conclusion: There's not any immediate danger to GnuPG. But, all the same: I cannot find any information on what's the plans for the future. Sooner or later a transition to some other hash has to take place, hasn't it? Yours, Per Tunedal On Tue, Feb 11, 2

Re: Moving away from SHA-1

2014-02-12 Thread Kristian Fiskerstrand
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Per, On 02/12/2014 09:31 AM, Per Tunedal wrote: > Hi Peter, Yes, I've searched the archives. Conclusion: There's not > any immediate danger to GnuPG. > > But, all the same: I cannot find any information on what's the > plans for the future. Soon

Re: Moving away from SHA-1

2014-02-12 Thread Stephane Bortzmeyer
On Tue, Feb 11, 2014 at 09:10:32AM +0100, Per Tunedal wrote a message of 17 lines which said: > When SHA-1 falls, GnuPG will otherwise be completely broken as > internal key signatures, as well signatures of public keys from > others and the fingerprint rely on SHA-1 hashes. Isn't three diffe

Trying to understand the bond between master and subordinate key pairs

2014-02-12 Thread Faru Guredo
I’ve read GNU Privacy Handbook, the FAQ and thought I understood the purpose of all four keys initially generated with --gen-keys. But then I found this https://wiki.debian.org/subkeys and lost it. tl;dr: There is suggested backup of ~/.gnupg, creation of a new pair of subkeys for signing, then al

Re: Trying to understand the bond between master and subordinate key pairs

2014-02-12 Thread Pete Stephenson
On Wed, Feb 12, 2014 at 4:02 AM, Faru Guredo wrote: > I’ve read GNU Privacy Handbook, the FAQ and thought I understood the purpose > of all four keys initially generated with --gen-keys. > But then I found this https://wiki.debian.org/subkeys and lost it. > > tl;dr: There is suggested backup of ~/

Re: Trying to understand the bond between master and subordinate key pairs

2014-02-12 Thread Hauke Laging
Am Mi 12.02.2014, 07:02:51 schrieb Faru Guredo: > This is suggested — as far as I understand — in order to keep > the original master key for signing in a secret place, because master > signing key = my genuine identity. But. Signing (data) is not the relevant aspect of a mainkey. Certification

Trying to understand the bond between master and subordinal key pairs

2014-02-12 Thread Michael Anders
On Wed, 2014-02-12 at 11:38 +0100, gnupg-users-requ...@gnupg.org wrote: > Am Mi 12.02.2014, 07:02:51 schrieb Faru Guredo: > > > This is suggested???as far as I understand???in order to keep > > the original master key for signing in a secret place, because > master > > signing key = my genuine ide

Organizing a GPG key signing party in London

2014-02-12 Thread Ludovic Hirlimann
Hi, I'm organizing a pgp key signing party in London on March the 25th at 6:30 PM BST in the mozilla space of the mozilla office in London. I've been trying to reach out to Londoners and Uk users of pgp using twitter ( https://twitter.com/lhirlimann/status/432867811002564608 ), I've tried to cont

Re: Trying to understand the bond between master and subordinal key pairs

2014-02-12 Thread Daniel Kahn Gillmor
On 02/12/2014 06:40 AM, Michael Anders wrote: > I am still puzzled, however. Can anyone explain the logical reason as to > why we need this jungle in OpenPGP, which thankworthily is usually more > or less hidden from the user anyways? > A good reason would help the complicated workings to stick w

Re: Could not extend expiration date

2014-02-12 Thread Pericle Unico
Johannes Zarl zarl.at> writes: > It looks like you use an offline master key and use subkeys for signing and > decryption. Thanks Johannes, you are right I forget I put the master key offline, now I've resolved. ___ Gnupg-users mailing list Gnupg-us

Re: Moving away from SHA-1

2014-02-12 Thread Per Tunedal
Hi Kristian, Thanks for the link. I've studied some interesting threads. Anyhow, I'm surprised that apparently there isn't any decision on how to move to the next OpenPGP standard, or what it would look like. Or has something been decided? I just want to be updated as I haven't followed the discu

Re: Organizing a GPG key signing party in London

2014-02-12 Thread MFPA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi On Wednesday 12 February 2014 at 11:40:23 AM, in , Ludovic Hirlimann wrote: > Hi, > I'm organizing a pgp key signing party in London on > March the 25th at 6:30 PM BST in the mozilla space of > the mozilla office in London. > I've been tryin

Re: Organizing a GPG key signing party in London

2014-02-12 Thread Ludovic Hirlimann
On 12/02/2014 23:49, MFPA wrote: > Hi > > It may also be worthwhile listing it on Biglumber.com. > When I see the state of the entries on big lumber (I've contacted everyone whose in London , and 75% of the email addresses didn't work) - I'm pretty sure it won't help. Ludo -- [:Usul] SRE Team a