Re: gpg trust paths



On Thu, May 15, 2008 at 12:17 AM, Richard Hector <richard@xxxxxxxxxxxxx>
wrote:

The wiki page for the recent OpenSSL vulnerability offers a perl script
for checking keys, and a gpg signature for that script, and a key id for
that signature (that of Florian Weimer)

I can import the key as shown, and show that the script was indeed
signed by that key.

However, gpg warns me that it can't tell that that key indeed belongs to
Florian Weimer.

How can I fill in that gap, to properly verify the file?

I have signed keys of several people who have been to keysigning parties
at several debconfs, so I feel I should have a trust path to anybody of
significance in the Debian community - though I could be proved wrong.

I've also added the debian keyserver to my ~/.gnupg/options, as well as
the keyring from the debian-keyring package.

Is there a step I'm missing?


AFAIU you'd need to have all keys of the entire path locally in your keyring
in order for GPG to see a trusted path. If you don't want to download all
the missing keys you could try a PGP pathfinder on the web (there are
several that are easily found).

/M


Relevant Pages

  • Re: FC4 Mplayer installation problem
    ... > I just wasn't in the mood to learn gpg. ... If it will help you with the keys use my little script in the attachment. ... will download and install to the correct directory. ...
    (Fedora)
  • Re: gpg signature & ssh keys
    ... can my gpg signature & ssh keys (public & private) be imported to ... SSH keys are stored to ~/.ssh and gpg keyrings and config file are ...
    (Debian-User)
  • Re: [SLE] A way to harvest gpg keys from kmail? Followup question
    ... >> fetchmail and gpg to automaticly give me the keys in a set of messages. ... > Then extract the GnuPG signature into a temporary file. ... And import into Gpg. ... 80's so i am a programming illiterate. ...
    (SuSE)
  • Re: Alternative to PGP solutions
    ... I pointed out that for commercial applications GNuPG ... My main gripe against GPG is ... | Windows and Linux. ... manage keys as well as upload public keys to some keyservers, ...
    (Security-Basics)
  • Re: backports
    ... You have to tell gpg which key's signatures it should check. ... These keys are not included in debian-backports-keyring.gpg ... I suppose that you can check that Joerg Jaspert is a Debian developer by ...
    (Debian-User)