Re: status: establishing a PGP web of trust

From: Ted Ts'o
Date: Wed Oct 05 2011 - 14:23:31 EST

On Wed, Oct 05, 2011 at 10:54:39AM +0300, Adrian Bunk wrote:
> What policy is now used at now is exactly the question
> I asked in [1], and where I'm still waiting for an answer from hpa.
> Other organizations like Debian have a clear and public policy on
> what is required for the user identification part for uploading to
> the archive [2], and I expect the same for

Peter has already said "are you prepared to swear in court".
Government issued ID is one way (although any US high school student
knows how easy it is to get fake ID); personal knowledge of someone's
speach patterns plus common history generated by years of talking to
that person at conferences and/or concalls, is another way.

When I bootstrapped Linus's key, he and I talked on the phone, and I
knew him well enough by our conversation my recognizing his speach
patterns that I was prepared to certify his key even though I've never
seen his government ID. That being said, I also know and trust Jim
Zemlin well enough to know trust that the person employed by the Linux
Foundation had his ID and right to work checked per US employment law,
and and that the person I talked to was the same person who is
employed by the Linux Foundation. Realistically, I'm far more sure of
Linus's identity than I would be of some random Debian developer who
got his key signed after some quick impromptu verification of what
appeared to be a governement-issued ID at some conference. :-)

- Ted
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at
Please read the FAQ at