From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from lists.gentoo.org (pigeon.gentoo.org [208.92.234.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by finch.gentoo.org (Postfix) with ESMTPS id 2E43C138334 for ; Fri, 1 Feb 2019 12:47:15 +0000 (UTC) Received: from pigeon.gentoo.org (localhost [127.0.0.1]) by pigeon.gentoo.org (Postfix) with SMTP id 09EA4E085B; Fri, 1 Feb 2019 12:47:14 +0000 (UTC) Received: from mo6-p05-ob.smtp.rzone.de (mo6-p05-ob.smtp.rzone.de [IPv6:2a01:238:20a:202:5305::6]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by pigeon.gentoo.org (Postfix) with ESMTPS id A41D8E0833 for ; Fri, 1 Feb 2019 12:47:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; t=1549025232; s=strato-dkim-0002; d=akhuettel.de; h=References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From: X-RZG-CLASS-ID:X-RZG-AUTH:From:Subject:Sender; bh=QwCu8cm+yco9kgYFO4IMHvmUF4x50w355WsVJDqftvw=; b=XaN0sEGwhgxHvTLz0v/jVMWBKEeeL+hCpamaAo7B35X64EMUblmY5M4BnburVE8jEX +xfDu78yLthTOeXP8NwzbSyhuDc3cU2otMoYsXke//BTIeDHZ7+Q6oehrPjO8tOmnNzv lCg3c08drUq5GFExuh6FoTf8g7FA8Y7P8Qsmm32BX5ot3v+rQsDT9btjXYSJ/0IHNLZc IqPR26xmlChSuuMpx1IAtd0n4bqcpnCMqnpjKS10TX/TLRG/r8xtTVQSRLdYOiYn1vk3 DMF14Z2kuw/efl+z7CnZB3S1/7sNlVf+W4Sp9L1AAKn5Gx5nwvym0ZTZH63a4sIMOIFw 655Q== X-RZG-AUTH: ":IW0NeWCpcPchHrcnS4ebzBgQnKHTmkWA4CWORNSv8N53ayXN3oevcYUH1GZ/bxBHaw==" X-RZG-CLASS-ID: mo05 Received: from porto.localnet by smtp.strato.de (RZmta 44.9 DYNA|AUTH) with ESMTPSA id L0904av11Cl7nDx (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (curve secp521r1 with 521 ECDH bits, eq. 15360 bits RSA)) (Client did not present a certificate); Fri, 1 Feb 2019 13:47:07 +0100 (CET) From: "Andreas K. Huettel" To: gentoo-project@lists.gentoo.org Cc: Matthew Thode Subject: Re: [gentoo-project] pre-GLEP: Gentoo OpenPGP web of trust Date: Fri, 01 Feb 2019 13:47:04 +0100 Message-ID: <3018116.TxlsP8b7va@porto> Organization: Gentoo Linux In-Reply-To: <20190131153228.w2jb4txsm6d3iabh@gentoo.org> References: <1548943008.796.1.camel@gentoo.org> <20190131153228.w2jb4txsm6d3iabh@gentoo.org> Precedence: bulk List-Post: List-Help: List-Unsubscribe: List-Subscribe: List-Id: Gentoo Project discussion list X-BeenThere: gentoo-project@lists.gentoo.org Reply-To: gentoo-project@lists.gentoo.org X-Auto-Response-Suppress: DR, RN, NRN, OOF, AutoReply MIME-Version: 1.0 Content-Type: multipart/signed; boundary="nextPart9746746.MgcjD48a1j"; micalg="pgp-sha512"; protocol="application/pgp-signature" X-Archives-Salt: 878c8536-b3c5-42e4-95b1-2c9bec31f9d6 X-Archives-Hash: fe745c9265ae21ab82db54d5a3e5bcbc --nextPart9746746.MgcjD48a1j Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="iso-8859-1" >=20 > I don't see anything in glep 76 about requiring verification of the > signatures. It's my view (as trustee) that assertation by the signer > that 'this is my signature' is sufficient. ^ This.=20 It's not our business to check IDs, and it's not our business to stalk peop= le=20 on google or facebook. Now if someone says "Here's my name, and actually it is a fake name", then= =20 that is a reason to refuse commit rights or patch acceptance, and probably = ask=20 for some sort of verification when another name is then given.=20 (That behaviour is roughly as intelligent as walking up to the security guy= at=20 the airport and claiming loudly "I have a bomb in my luggage.") Apart from that, I dont think we should care. =2D-=20 Andreas K. H=FCttel dilfridge@gentoo.org Gentoo Linux developer=20 (council, toolchain, base-system, perl, libreoffice) --nextPart9746746.MgcjD48a1j Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part. Content-Transfer-Encoding: 7Bit -----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE2dlecvcVU8/ThuQ/jJJgxvbXoxAFAlxUP8gACgkQjJJgxvbX oxCCPRAA05KjpYajzjw23OoLL2yhxXc7QA38uU0hnYIGq3NI9+PHLQPQk6KSg08C X/Pn+sRTUiR6qPhvfUbDoVAp4g07ixvGmWqe3r09k1rkzJSR/vYUosjn9kwM2FQQ HDu+Lq9R29xNfpmTV4k/si8Rz+5sVl1D6jAv6ZvlLDMfsCnuxzEoBcmdCNwD4WcL jRQubK7hB1BgFT8GZIHVrrVUuMprLQYowfJZUgGdk9H0SpEdmc7CiRtapWKYD86F ukFqvIrSG5Q0HVCOC32H72wzOOgWqovx7k9xD507R1YIadxFc+GYalMv7Ypbq54P 5qOL3gig7cwhH9yYhAnyLhSE0uLbrdCIkCvVW1aCoOTNi72KmpK7oFvRxnsDCMMe bKiJm+uGFf8j+RI33AOxCVcjMFIDjBAs2hgRRDwO5bSDwixpTViXOBCZK51jmxmq CHfMTTej7c343ToGhQGKtFBbr35ReW4F0Fope+RiiuZpkBLdTuNazwWbZfxmTn/T 6gdx4e6ynb4JeFefYCkeqWcGNjeJZWNGAq1IHEooFZlyvB77r1PFT/K3wgQBkY1D pG9eExhkzxaU9Oy844YCXPa0/UsnRzZH9imPAtNKp+udyo+W048+W41Zqip5zv/d wUr6rcUt3QbcU7xmEO/vOwILrAzVL1WZlablcx7fht6c4QLRvp0= =pdUN -----END PGP SIGNATURE----- --nextPart9746746.MgcjD48a1j--