NODE 34602500pgp key distribution
shawnb <shawnb@ecst.csuchico.edu>Sat, 24 Oct 92 20:33:12 PDT
I'm pretty new to this mailing list, so something along these lines may
have already been proposed, but I was considering the possibility of
putting together a list of pgp public keys for distribution through this
list. My own collection of keys is pretty small, and I would pernally
like to expand this, but I think this would provide a great service to the
group as well. Let me know what you all think.
Shawn
NODE 8848ce13Re: pgp key distribution
Peter Shipley <shipley@tfs.COM>Sat, 24 Oct 92 20:54:34 PDT
jyanowitz@hamp.hampshire.edu is already creating a list
(you can find it posted to alt.security.pgp). As for me
I maintain two public rings one is a collection I have collected via
direct contact (friends mostly) the other is jyanowitz's list plus
random other rings).
-Pete
Ps: I do not know jyanowitz (etc etc, but while we are on the subject)
but I guess I should relay his request for people to email him your
keys and public rings
my casual key:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: 2.0
mQA9AirUzbUAAAEBfjC3p5COEUMJ3xzrq4sJCTaU5MgvzC94tp8yxxBJeKUGo7xx
gMShBCnIZp+xlFiyxQAFE7QYUGV0ZXIgTSBTaGlwbGV5IChjYXN1YWwptAZjYXN1
YWy0JlBldGVyIE0gU2hpcGxleSA8c2hpcGxleUBiZXJrZWxleS5lZHU+
=OR9u
-----END PGP PUBLIC KEY BLOCK-----
NODE 4137e49fpgp key distribution
pmetzger@shearson.com (Perry E. Metzger)Sat, 24 Oct 92 22:03:00 PDT
>From: shawnb <shawnb@ecst.csuchico.edu>
>I'm pretty new to this mailing list, so something along these lines may
>have already been proposed, but I was considering the possibility of
>putting together a list of pgp public keys for distribution through this
>list. My own collection of keys is pretty small, and I would pernally
>like to expand this, but I think this would provide a great service to the
>group as well. Let me know what you all think.
I keep seeing people propose things like this, and I can't for the
life of me understand why. The only way to know for sure that
someone's key is theirs is a signature from a trusted introducer
anyway, so people can just ask each other in clear for public keys and
it doesn't do a lick of harm -- if they have a trusted signature, you
can use their key for communication and if they don't, you have to
find another way to verify the key. People making lists of keys and
distributing them seems fairly useless to me. Can anyone tell me if I
am being really really thick here?
Perry