{"thread":{"id":"40894","subject":"Signed tags and git repository","startedAt":"2015-11-25T23:19:07Z","lastAt":"2015-11-26T05:07:36Z","messageCount":3,"participants":["Stephen & Linda Smith","Johannes Löthberg"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"273773","messageId":"3816223.3lD8Al3iuQ@thunderbird","threadId":"40894","inReplyTo":null,"subject":"Signed tags and git repository","fromName":"Stephen & Linda Smith","fromEmail":"ischis2@cox.net","sentAt":"2015-11-25T23:19:07Z","receivedAt":"2015-11-25T23:19:07Z","isPatch":false,"sender":{"key":"ishchis2@gmail.com","avatar":null},"body":"I've been following commits to the linux and git repostitories for some time.   I used signed tags for\nprojects that I'm working on.   \n\nI know that the linux and git repositories have signed tags, but I'm not able to verify \nthem because my key isn't signed by anyone that leads back to one of the git or linux \nmaintainers. Of course I live in a technical desert since there seems to be no one that I\ncan find who lives in Phoenix, AZ that has a relationship to one of those two \ngit repositories.\n\nWhat have others done when they want their keys signed so they can be part of the \nweb of trust? Does either of those two projects have a formal way of establishing these\nrelationships?\n\nsps\n"},{"id":"273776","messageId":"20151126035600.GA11556@zorg.kyriasis.com","threadId":"40894","inReplyTo":"3816223.3lD8Al3iuQ@thunderbird","subject":"Re: Signed tags and git repository","fromName":"Johannes Löthberg","fromEmail":"johannes@kyriasis.com","sentAt":"2015-11-26T03:56:00Z","receivedAt":"2015-11-26T03:56:00Z","isPatch":false,"sender":{"key":"johannes@kyriasis.com","avatar":"https://gravatar.com/avatar/af2dea1b1759403329a1b7eaa28a07b5c5d1901e9f55723103d6324ffb7737ae?d=mp&s=160"},"body":"On 25/11, Stephen & Linda Smith wrote:\n>I know that the linux and git repositories have signed tags, but I'm not able to verify\n>them because my key isn't signed by anyone that leads back to one of the git or linux\n>maintainers.\n\nYour key would only have to be signed for others to be able to verify \n/your/ signatures through the Web of Trust.\n\nYou don't even need the Web of Trust though, you can just verify the \nsignature and then check that the key used to make the signature is the \ncorrect one, then you could either sign the key if you know that the key \nbelongs to the right person and want to make the signature public, or \nmake a local signature which is local to your keyring and won't be sent \nto eg keyservers. Or just mark the key as trusted overall.\n\n-- \nSincerely,\n  Johannes Löthberg\n  PGP Key ID: 0x50FB9B273A9D0BB5\n  https://theos.kyriasis.com/~kyrias/\n"},{"id":"273778","messageId":"3912454.5IyPOB72Zu@thunderbird","threadId":"40894","inReplyTo":"3816223.3lD8Al3iuQ@thunderbird","subject":"Re: Signed tags and git repository","fromName":"Stephen & Linda Smith","fromEmail":"ischis2@cox.net","sentAt":"2015-11-26T05:07:36Z","receivedAt":"2015-11-26T05:07:36Z","isPatch":false,"sender":{"key":"ishchis2@gmail.com","avatar":null},"body":"On Thursday, November 26, 2015 04:56:00 AM Johannes Löthberg wrote:\n\n> You don't even need the Web of Trust though, you can just verify the \n> signature and then check that the key used to make the signature is the \n> correct one, \n\nOk, but if I don't have a link to the Web or Trust, how do I know that \"the\nkey used to make sure the signature is the correct one\" (i.e. trusted).\n\nsps\n"}]}