GnuPG Key Signing Party
Where?
O'Reilly & Associates
Sebastapol, Ca
Directions
When?
After the general meeting. Meetings usually run from about 7:30pm to 10:00pm.
Why?
A key signing party properly facilitates the signing of your GnuPG public key
by other GnuPG users. Having your public key signed increases the "web of trust"
for everyone, and brings more validity to your key, as it represents your identity.
What to bring?
- Your self (physical attendance is mandatory)
- Picture ID
- Your Key ID, Key type, HEX fingerprint, and Key size
(probably just make a print out from your keyring...unless you've got all this memorized ;) )
- Something to write with
- NO computer!
How does it work?
- Before the party generate a key pair, and either upload your public key to a public key server
such as www.keyserver.net, or be prepared to tell
people from where they can access your public key on the internet.
- Email your public key to the coordinator:
augie@nblug.org
- The coordinator prints a list with everyone's key ID, key type, fingerprint, and key size from the compiled
keys and distributes copies of the printout at the meeting.
- Bring along a paper copy of your key ID, key type, fingerprint, and key size that you obtained from
your own keyring. Also bring a photo ID.
- You will be making two marks on the listing, one for correct key information
(key ID, key type, fingerprint, and key size) and one if the ID check is ok.
- Now mingle. The point is to meet as many people, and get as many signatures as you can.
- When you meet someone read your key ID, key type, fingerprint, key size, and user ID
from your own printout, not from the distributed listing. This is because there could be an error,
intended or not, on the listing. This is also the time to confirm ID information. If the key
information matches your printout then place a check-mark by the key on your own distributed list,
and if the ID appears to be valid place another check-mark on your own distributed list.
- That's it! When you get home, take a look at your list, any keys on your list with TWO check-marks
are valid keys, and you may download that key from the keyserver or from another location that
the key owner has specified. Sign that key and upload it back to the server you got it from, or email
it back to its owner.
Links
http://www.nblug.org/augie/gpg
- shameless self promotion
http://www.mandrakesecure.net/en/docs/gpg.php
- good brief introduction into GnuPG
http://www.gnupg.org/gph/en/manual.html
- more indepth information
Resources:
http://www.cryptnet.net/fdp/crypto/gpg-party.html
- GnuPG Key Signing Party How-To
Author: August Schwer augie@nblug.org