git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Signed tags and git repository

From
Johannes Löthberg <johannes@kyriasis.com>
Date
Nov 26, 2015, 03:56 UTC
Message-ID
<20151126035600.GA11556@zorg.kyriasis.com>
In-Reply-To
<3816223.3lD8Al3iuQ@thunderbird>
On 25/11, Stephen & Linda Smith wrote:
>I know that the linux and git repositories have signed tags, but I'm not able to verify
>them because my key isn't signed by anyone that leads back to one of the git or linux
>maintainers.

Your key would only have to be signed for others to be able to verify /your/ signatures through the Web of Trust.

You don't even need the Web of Trust though, you can just verify the signature and then check that the key used to make the signature is the correct one, then you could either sign the key if you know that the key belongs to the right person and want to make the signature public, or make a local signature which is local to your keyring and won't be sent to eg keyservers. Or just mark the key as trusted overall.

-- 
Sincerely,
  Johannes Löthberg
  PGP Key ID: 0x50FB9B273A9D0BB5
  https://theos.kyriasis.com/~kyrias/
Previous: Stephen & Linda SmithNext: Stephen & Linda Smith
Message 2 of 3 in “Signed tags and git repository”
  1. Stephen & Linda SmithNov 25, 2015
  2. Johannes LöthbergNov 26, 2015
  3. Stephen & Linda SmithNov 26, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.