Return-Path: X-Original-To: apmail-incubator-general-archive@www.apache.org Delivered-To: apmail-incubator-general-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 38F51DD3C for ; Mon, 8 Oct 2012 16:47:46 +0000 (UTC) Received: (qmail 28886 invoked by uid 500); 8 Oct 2012 16:47:45 -0000 Delivered-To: apmail-incubator-general-archive@incubator.apache.org Received: (qmail 28634 invoked by uid 500); 8 Oct 2012 16:47:45 -0000 Mailing-List: contact general-help@incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: general@incubator.apache.org Delivered-To: mailing list general@incubator.apache.org Received: (qmail 28626 invoked by uid 99); 8 Oct 2012 16:47:45 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 08 Oct 2012 16:47:45 +0000 X-ASF-Spam-Status: No, hits=0.7 required=5.0 tests=SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (athena.apache.org: local policy) Received: from [216.119.133.2] (HELO a2s42.a2hosting.com) (216.119.133.2) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 08 Oct 2012 16:47:37 +0000 Received: from 71-217-73-181.tukw.qwest.net ([71.217.73.181]:33228 helo=Astraendo) by a2s42.a2hosting.com with esmtpa (Exim 4.77) (envelope-from ) id 1TLGU7-003V1w-7U for general@incubator.apache.org; Mon, 08 Oct 2012 12:47:16 -0400 Reply-To: From: "Dennis E. Hamilton" To: References: <20121005131523.GE3033@lp-shahaf.local> <2E45169E9A237B4DA78078A68962F9EF06BEF55D@IMCMBX01.MITRE.ORG> <5072E4EC.8060001@apache.org> In-Reply-To: Subject: RE: key signing Date: Mon, 8 Oct 2012 09:47:13 -0700 Message-ID: <00c501cda574$9224b140$b66e13c0$@apache.org> MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Mailer: Microsoft Outlook 14.0 Thread-Index: AQG2VGgRTYEyxooaYPD8V1D+NVOSCQIiBojkAWgd61QCHaLQ2gIZVq/LAxh9yL8BUZqWcwIlspSVl2u4ehA= Content-Language: en-us X-AntiAbuse: This header was added to track abuse, please include it with any abuse report X-AntiAbuse: Primary Hostname - a2s42.a2hosting.com X-AntiAbuse: Original Domain - incubator.apache.org X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12] X-AntiAbuse: Sender Address Domain - apache.org X-Virus-Checked: Checked by ClamAV on apache.org I don't understand what "keys from LDAP" are? Are these the same as keys whose fingerprints a ASF committer registers = in their account or something else? - Dennis -----Original Message----- From: Benson Margulies [mailto:bimargulies@gmail.com]=20 Sent: Monday, October 08, 2012 08:54 To: general@incubator.apache.org Subject: Re: key signing [ ... ] In my opinion, that's vanishingly unlikely, and so the best we can do is to allow users to verify that the signature was, in fact, made by the 'Apache hat' that it claimed to be made by. Using the keys in KEYS, or the fingerprints from LDAP, seems the best they can do. [ ... ] --------------------------------------------------------------------- To unsubscribe, e-mail: general-unsubscribe@incubator.apache.org For additional commands, e-mail: general-help@incubator.apache.org