WLUG
By thread
wlug@lists.wlug.org
By month
Messages by month
- ----- 2026 -----
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2008 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2007 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2006 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2005 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2004 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2003 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2002 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2001 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2000 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
September 2013
- 6 participants
- 12 messages
Announce: WLUG Meeting Wed 10/9 7PM Jim Gettys on Internet buffer bloat
by Chuck Anderson
Hi folks,
The next Worcester Linux Users' Group (WLUG) meeting will be held at
its regularly scheduled time: the 2nd Wednesday of the month, which is
Wednesday, October 9, at 7PM. The location will be the WPI Campus
Center, Mid-Centry Room 331.
This month we will have Jim Gettys from Bell Labs talk about Internet
buffer bloat. This is the talk that has been rescheduled from April.
"Internet buffer bloat, by Jim Gettys (Bell Labs)
VOIP and teleconferencing often perform much more poorly on today's
Internet than the Internet of a decade ago, despite great gains in
bandwidth. Lots of fiber, cheap memory, smart hardware, variability of
wireless goodput, changes in web browser behaviour, changes in TCP
implementations, and a focus on benchmarking Internet performance
solely by bandwidth, and engineer's natural reluctance to drop packets
have conspired to encourage papering over problems by adding buffers;
each of which may introduce latency when filled.
The mistaken quest to never drop packets has destroyed interactivity
under load, and often results in actual higher packet loss, as TCP's
congestion avoidance algorithms have been defeated by these
buffers. The lessons of the "RED manifesto" of 1997 have been
forgotten or never learned by a new generation of engineers."
Wednesday, October 9, 7:00 - 9:00 PM
WPI Campus Center, Mid-Centry Room 331
Afterwards, we will go out for pizza.
See you there,
Chuck
President, Worcester Linux Users' Group
http://www.wlug.org/
Sept. 23, 2013
Keysigning Party -- what to do AFTER
by Chuck Anderson
So you've attended a keysigning party and diligently checked people's
key fingerprints & IDs. Now what should you do?
Here is an overview of the process you should follow:
1. Sign: Look at the checklist you made at the Keysigning Party. For
each user where you checked off that you verified their key
information & ID, you need to import their key, verify the imported
key's fingerprint matches the printout/notes that you verified at
the party, sign their key(s), and send them back to them,
preferrably signed+encrypted to their key.
2. Import: As you receive your signed key(s) from other people, import
them to your keyring and then upload them to a keyserver.
3. Refresh: Periodically refresh your keyring from a keyserver so you
get local copies of other people's keys with any additional
signatures that were added since you last refreshed.
Detailed instructions for each step:
1. Sign: Configure GPG to always ask for the certification level.
Before signing keys, it is a good idea to set your GnuPG
configuration to always ask you what certification level to assign
to each key you sign. This indicates to others how carefully you
verified the person's identity before you signed their key. If you
don't do this, GnuPG will default to 0 which means you make no
particular claim as to how careful you were.
Edit $HOME/.gnupg/gpg.conf and add the following to the end:
ask-cert-level
You can also optionally change the default (in case you don't want
to be asked every time):
default-cert-level 2
1a. Sign: The CAFF Method.
The easiest way to do this is to use CAFF (CA Fire & Forget) from
the pgp-tools package on Fedora, or the signing-party package on
Debian/Ubuntu.
After installing the pgp-tools or signing-party package, you need
to configure CAFF. In order to create your initial .caffrc, just
run "caff" once.
caff
Then edit the .caffrc file in your home directory. The minimum
settings you should set are:
$CONFIG{'owner'} = 'YOUR FULL NAME';
$CONFIG{'email'} = 'YOUREMAIL@FOO';
$CONFIG{'bcc'} = 'YOUREMAIL@FOO';
$CONFIG{'keyid'} = [ qw{YOUR-KEY-ID YOUR-OTHER-KEY-ID-IF-YOU-HAVE-ANY} ];
$CONFIG{'local-user'} = [ qw{YOUR-KEY-ID YOUR-OTHER-KEY-ID-IF-YOU-HAVE-ANY} ];
$CONFIG{'also-encrypt-to'} = [ qw{YOUR-KEY-ID YOUR-OTHER-KEY-ID-IF-YOU-HAVE-ANY} ];
$CONFIG{'default-cert-level'} = '2'; # as above, but for CAFF specifically
Note that the KEY-IDs CAFF wants are 8-byte ones rather than the
usual 4-byte. Just use the last 16 digits of the fingerprint. You
can also customize the email message body that CAFF will send out
with each signed key.
Then you just run CAFF like this:
caff 0xKEY-ID1 0xKEY-ID2 0xKEY-ID3 ...
... etc to sign all those KEY-IDs. You can run it once for each
person/key, or list every person's KEY-ID on a single run.
CAFF will prompt you to sign people's keys one by one (which you
should only do after you verify the fingerprint against your paper
copy from the Keysigning Party), then it will email the signatures
for each uid (email address) separately to that email address,
signed+encrypted to that user. That proves that the user who can
receive email at that email address, and who can decrypt the
message, is the only user who can get the signature for that
user/uid/email, and that is the only way they can get the signature
for that uid/email (as long as you don't send your signed copy of
their key to a keyserver or anywhere else--leave that to the
recipient).
1b. Sign: The Manual Method.
It is tricky to do the above manually without CAFF, but if you
don't want to run CAFF or can't for some reason, you can sign the
key and then export the signed key with gpg --export. Ideally, you
should then encrypt that and send it to at least one of the email
addresses listed in the uid(s) if not all of them. This is not as
good as the CAFF method, because it only proves that at least ONE
of the uids/email addresses is controlled by the user who has that
key, and the person who controls that ONE email address can get
your signature on ALL of the uids/email addresses.
These commands should work for the manual method. First verify
that the fingerprint matches your printout or notes from the
Keysigning Party:
gpg --fingerprint 0xRECIPIENT-KEY-ID
Now sign the key:
gpg --sign-key 0xRECIPIENT-KEY-ID
Now export their key, signed+encrypted to both them and you. Store
the result, ascii armoured, into a file:
gpg --export 0xRECIPIENT-KEY-ID | gpg --encrypt --sign --armour --recipient 0xRECIPIENT-KEY-ID --recipient 0xYOUR-KEY-ID - > 0xRECIPIENT-KEY-ID-signed-key.asc
You can verify that this came out right before emailing (since you
signed/encrypted it ALSO to your own KEY-ID above) with the
following:
cat 0xRECIPIENT-KEY-ID-signed-key.asc | gpg -d | gpg --list-packets
And you can import it to a test keyring to see the signatures like
this:
cat 0xRECIPIENT-KEY-ID-signed-key.asc | gpg --decrypt | gpg --import --keyring=testring.gpg --no-default-keyring
gpg --list-sigs --fingerprint --keyring=testring.gpg --no-default-keyring
Now that you've verified it is all correct, just attach the .asc
file to an email and send it to the user's email address(es).
2. Import signed keys other people send you and then upload them.
When you receive emails from other people with your signed key(s)
(hopefully signed+encrypted in the email) you should import them as
follows.
If the sender used the CAFF Method, the entire email will be
signed+encrypted and you can import the key like this:
cat encrypted-email.asc | gpg --decrypt | gpg --import
If the sender used the Manual Method, you will have a
signed+encrypted attachment that you can import like so:
cat 0xYOUR-KEY-ID-signed-key.asc | gpg --decrypt | gpg --import
Now you should send your key back to a keyserver with the new
signature(s) you just added:
gpg --keyserver=subkeys.pgp.net --send-key 0xYOUR-KEY-ID
3. Refresh: Periodically refresh your keyring from a keyserver.
In order to reap the benefits of the Web of Trust, you need to
download other people's public keys so you can take advantage of
the signatures on those keys to verify other people further out in
the Web. As people upload their keys with additional signatures on
them, your local copies become out of date so you need to refresh
them to gain the additional signatures, any revocations, etc.
To refresh a single key, just download that key from a keyserver:
gpg --keyserver=subkeys.pgp.net --recv-key 0xKEY-ID
To refresh your entire keyring (do this sparingly as it does place
quite a load on the keyserver):
gpg --keyserver=subkeys.pgp.net --refresh-keys
That's it!
Sept. 19, 2013
Follow up from key signing
by Eric Martin
Hi WLUG and BLU,
I have signed all of the keys I have access to. If you haven't received
an email from me, it's because either a) I can't get your key, or b) the
email with your signed key was lost. Please email me directly if you're
expecting a signed key from me.
A few people expressed interest in the suite of tools I'm using to make
signing easier, and also some visualization tools I'm playing with.
They're all based on Debian's pgp-tools which can be called
keysigning-party on your distribution. Hands down, the most useful tool
is CA Fire and Forget or caff. It's in most distributions, and if it's
not in your distro (or you're on a Mac) it's pretty easy to build. Just
checkout it out from svn://svn.debian.org/svn/pgp-tools/trunk, and do a
make all && make install clean
Now that you have caff installed on your machine, it's time for some
tweaks. Go ahead and run caff by typing caff at the command prompt.
This will setup the folders and files you need that we'll be tweaking.
1) I *highly* suggest making a symlink from ~/.gnupg/gpg.conf ->
~/.caff/gnupghome/ via
ln -s ~/.gnupg/gpg.conf ~/.caff/gnupghome
This will have caff use your preferences in gpg.conf and it makes it
easier to configure / use the way you want to.
2) edit ~/.gnupg/gpg.conf and set your default key, default keyserver
(most of them sync with each other so it's not a big deal, but I prefer
pool.sks-keyservers.net since it handles subkeys very well.) Also to
note, keys can prefer certain servers so don't worry if gpg is asking a
few different servers where things are. Also, if you haven't already,
set your preferences for algorithms, hashes, and compression. *NOTE*
this only applies to making new keys. You should still set the proper
preferences on your key via gpg --edit-key <KEYID>. Lastly, I like to add
ask-cert-level
so gpg (and therefore caff) ask me what certification level to give to
each signature
3) edit your ~/.caffrc file to customize your name, email address, and
email template / procedure for signing keys. Caff looks for 16 digit
keyids, not 8 so punch in the last 16 of your fingerprint for you key.
Also, I like to bcc myself on the emails in case a message gets bounced
so I can resend it easily via Thunderbird
4) Once those are edited and saved, you're all set! Grab your trusted
list, and feed caff one or more keyids to handle via
caff <KEYID> <KEYID> <KEYID...>
Don't forget to verify the fingerprint caff / gpg show you with your
trusted list.
I'm attaching my gpg.conf and .caffrc files for those of you who are
interested. I should probably put this up as a wiki / blog post at some
point in time to I can go back and update / clarify it.
Also, check out:
sig2dot (included in pgp-tools / keysigning-party) which is a visualizer
for the Web of Trust
http://pgp.cs.uu.nl/ for PGP trust paths
Cheers!
Sept. 19, 2013
Re: [Wlug] Ubuntu usb/bluetooth/android
by Jason Couture
You'd need an android app that provides OBEX because android doesn't
support it out of the box. But it should work.
Not sure how it'd do on performance though.
On Sep 15, 2013 1:16 PM, "Bill Mills-Curran" <bill(a)mills-curran.net> wrote:
> I've had my shiny new HTC One for a while, and I've found that the
> USB-connected file mount/transfer/etc speed with my Ubuntu (Precious)
> is atrocious. I've tried both the nautilus (automount) interface and
> the mtp-mount: both are bad.
>
> I'm wondering whether a usb-bluetooth adapter (my laptop does not have
> bluetooth) would allow me to mount the smartphone filesystem and get
> decent performance.
>
> TIA,
> Bill
> _______________________________________________
> Wlug mailing list
> Wlug(a)mail.wlug.org
> http://mail.wlug.org/mailman/listinfo/wlug
>
Sept. 15, 2013
Ubuntu usb/bluetooth/android
by Bill Mills-Curran
I've had my shiny new HTC One for a while, and I've found that the
USB-connected file mount/transfer/etc speed with my Ubuntu (Precious)
is atrocious. I've tried both the nautilus (automount) interface and
the mtp-mount: both are bad.
I'm wondering whether a usb-bluetooth adapter (my laptop does not have
bluetooth) would allow me to mount the smartphone filesystem and get
decent performance.
TIA,
Bill
Sept. 15, 2013
Re: [Wlug] Next WLUG Meeting: Keysigning Party 9/11/2013
by Chuck Anderson
Those of you who created your keys and didn't upload them yet, you
should upload them to:
http://biglumber.com/x/web?keyring=4480
and/or preferrably send them to a public keyserver:
gpg --keyserver=subkeys.pgp.net --send-keys <your-key-id(s)>
so that we can sign them! After you have received signatures from
people encrypted to your email address(es), import all of them, one at
a time to your keyring:
gpg --import <decrypted-email-with-your-signed-key>
(In Mutt this is really easy--just view the attachement and hit
"| gpg --import" to pipe the attachment through gpg)
and then send them back to a public keyserver again so other people
can see/use those signatures by refreshing their own keyring:
gpg --keyserver=subkeys.pgp.net --send-keys <your-key-id(s)>
gpg --keyserver=subkeys.pgp.net --refresh-keys
On Wed, Sep 11, 2013 at 04:55:15PM -0400, Eric Martin wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> Hi All, I forgot to mention that you should print out your fingerprint
> and bring it to the meeting, to make sure that the one I have on file
> for you is the correct one. If you aren't able to pre-register, print
> out 15 copies or so to hand out to people at the meeting. You can get
> the fingerprint by typing
>
> gpg --list-secret-keys | grep ^sec
> For me, this is 146797fa. Yours will be different.
>
> gpg --fingerprint KEYID
>
> I'm looking forward to seeing everybody there. We'll have a short talk
> on the how and why of PGP, then we'll adjourn to Tech Pizza for dinner.
>
> On 9/11/13 10:37 AM, Chuck Anderson wrote:
> > Now is a good time to check if your key is expired and/or is using a
> > weak algorithm or key size, and generate a new key if necessary.
> >
> > I followed the steps here to start a transition from an ancient 1024D
> > (DSA 1024-bit) key to a modern 4096R (RSA 4096-bit) key:
> >
> > http://www.apache.org/dev/key-transition.html
> >
> > See you all tonight!
> >
> > On Sun, Sep 08, 2013 at 10:48:00PM -0400, Eric Martin wrote:
> >> Just a reminder that this week I'll be giving a talk on PGP and running a
> >> key signing. Please upload your public key to the keyring before the
> >> meeting to register for the key signing. It is possible to participate
> >> without registering but it's a lot easier if you register.
> >>
> >> Please don't hesitate to ask if you have any questions.
> >>
> >>
> >> On Thu, Aug 29, 2013 at 11:53 PM, Eric Martin
> >> <eric.joshua.martin(a)gmail.com>wrote:
> >>
> >>>
> > On Wednesday, September 11th 2013 I'll be running a PGP Key Signing
> > party. PGP stands for Pretty Good Privacy and was developed by Phil
> > Zimmerman in 1991 for secure communications. Signing keys allows you to
> > say that you trust somebody's key, and extends the Web of Trust which
> > helps everybody.
> >
> > To participate, please bring your public key's fingerprint, and at least
> > (2) forms of ID (Government issued photo ID is the best way to go). If
> > you don't yet have a public key, follow the directions for 'Preparing
> > for the Party' from this [1] Key Signing Party HOWTO.
> >
> > Additionally, please upload your public key to our keyring for this
> > event here [2]. I'll give a brief talk on PGP, and then we'll go
> > through everybody's keys.
> >
> > What not to bring: A computer. Keys are signed at home, we just verify
> > them at the Key Signing.
> >
> > [1]
> >
> >
> http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.htm…
> > [2] http://biglumber.com/x/web?keyring=4480
Sept. 12, 2013
Re: [Wlug] Next WLUG Meeting: Keysigning Party 9/11/2013
by Eric Martin
I'm leaving work now so I might be a few minutes late.
On Sep 11, 2013 4:55 PM, "Eric Martin" <eric.joshua.martin(a)gmail.com> wrote:
>
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA256
>
> Hi All, I forgot to mention that you should print out your fingerprint and
> bring it to the meeting, to make sure that the one I have on file for you
> is the correct one. If you aren't able to pre-register, print out 15
> copies or so to hand out to people at the meeting. You can get the
> fingerprint by typing
>
> gpg --list-secret-keys | grep ^sec
> For me, this is 146797fa. Yours will be different.
>
> gpg --fingerprint KEYID
>
> I'm looking forward to seeing everybody there. We'll have a short talk on
> the how and why of PGP, then we'll adjourn to Tech Pizza for dinner.
>
> On 9/11/13 10:37 AM, Chuck Anderson wrote:
> > Now is a good time to check if your key is expired and/or is using a
> > weak algorithm or key size, and generate a new key if necessary.
> >
> > I followed the steps here to start a transition from an ancient 1024D
> > (DSA 1024-bit) key to a modern 4096R (RSA 4096-bit) key:
> >
> > http://www.apache.org/dev/key-transition.html
> >
> > See you all tonight!
> >
> > On Sun, Sep 08, 2013 at 10:48:00PM -0400, Eric Martin wrote:
> >> Just a reminder that this week I'll be giving a talk on PGP and running
> a
> >> key signing. Please upload your public key to the keyring before the
> >> meeting to register for the key signing. It is possible to participate
> >> without registering but it's a lot easier if you register.
> >>
> >> Please don't hesitate to ask if you have any questions.
> >>
> >>
> >> On Thu, Aug 29, 2013 at 11:53 PM, Eric Martin
> >> <eric.joshua.martin(a)gmail.com> <eric.joshua.martin(a)gmail.com>wrote:
> >>
> >>>
> > On Wednesday, September 11th 2013 I'll be running a PGP Key Signing
> > party. PGP stands for Pretty Good Privacy and was developed by Phil
> > Zimmerman in 1991 for secure communications. Signing keys allows you to
> > say that you trust somebody's key, and extends the Web of Trust which
> > helps everybody.
> >
> > To participate, please bring your public key's fingerprint, and at least
> > (2) forms of ID (Government issued photo ID is the best way to go). If
> > you don't yet have a public key, follow the directions for 'Preparing
> > for the Party' from this [1] Key Signing Party HOWTO.
> >
> > Additionally, please upload your public key to our keyring for this
> > event here [2]. I'll give a brief talk on PGP, and then we'll go
> > through everybody's keys.
> >
> > What not to bring: A computer. Keys are signed at home, we just verify
> > them at the Key Signing.
> >
> > [1]
> >
> >
> http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.htm…
> > [2] http://biglumber.com/x/web?keyring=4480
> >
> >>>
> >>>
> >>> _______________________________________________
> >>> Wlug mailing list
> >>> Wlug(a)mail.wlug.org
> >>> http://mail.wlug.org/mailman/listinfo/wlug
>
> - --
> Eric Martin
> Key Fingerprint = C74F 1EBF 2E80 7984 8CB5 064E BF17 D34C C704 B30F
> -----BEGIN PGP SIGNATURE-----
> Version: GnuPG v1.4.13 (Darwin)
> Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
>
> iQIcBAEBCAAGBQJSMNizAAoJEL8X00zHBLMPCk4QAKLjQJSh4giYnOsCUGsuJuV9
> /NzBkG701IJACLFBNeehMB/6jFYk6sNKCYRPSFVMOh2aHogndr+OhHPujAR7mGOv
> yShdjDvSNGGNfI4gXcxBvz3+0Hol20DEMQbOaN6WcrLiUG8j5ma5a//V/3+CVCEk
> SgYhCg6r1v71Zq+CfpcDoByX8SRHmfp2/48zEUlDv9JCpuE/X9x33L0mhN1wYlGY
> zp/jZT3tXVdgkAz/pCLyScq4cMLagj8IkrzlCMT9vd313WVQ/lRm05QKFVlR67XM
> 9mn0poXP7E04Tl3Z4q8fgO6wM8wdVG4r6cYCUuICysNjhU773JoY7PyxOLmgXggB
> BEWlJD6TD/hPFmFVM6T+JoCyDSsh3bEnpefehbW12PXKxPuArLZ5xXF1JHHe3hFb
> YcH/9aT+xWWyIUxRfEj1GBbIGDESo9KRmmSiuo0EBFYVSNYtyaEFqoAUsqFS7BmS
> acQ/x3Tn7uidOT1IwXJqX9BBSpFJlzqMleLIDjcPezuzr04f3OVqGsZdjJ8iS3M5
> cV2P6fdJroJRp9WpaCBkrK2U3rLpqSwTZzn/RylCR9BWSP2nNrEButp62+uwAc3I
> 69HQAcrpu/DqjP9yVrADe1dnnRKD4s1+lusr23QXETqXEJ0mJHQ4LlJGc/yH/DPu
> WePyoSrB+xHgsKj8i/Lv
> =n+42
> -----END PGP SIGNATURE-----
>
>
Sept. 11, 2013
Re: [Wlug] Next WLUG Meeting: Keysigning Party 9/11/2013
by Eric Martin
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hi All, I forgot to mention that you should print out your fingerprint
and bring it to the meeting, to make sure that the one I have on file
for you is the correct one. If you aren't able to pre-register, print
out 15 copies or so to hand out to people at the meeting. You can get
the fingerprint by typing
gpg --list-secret-keys | grep ^sec
For me, this is 146797fa. Yours will be different.
gpg --fingerprint KEYID
I'm looking forward to seeing everybody there. We'll have a short talk
on the how and why of PGP, then we'll adjourn to Tech Pizza for dinner.
On 9/11/13 10:37 AM, Chuck Anderson wrote:
> Now is a good time to check if your key is expired and/or is using a
> weak algorithm or key size, and generate a new key if necessary.
>
> I followed the steps here to start a transition from an ancient 1024D
> (DSA 1024-bit) key to a modern 4096R (RSA 4096-bit) key:
>
> http://www.apache.org/dev/key-transition.html
>
> See you all tonight!
>
> On Sun, Sep 08, 2013 at 10:48:00PM -0400, Eric Martin wrote:
>> Just a reminder that this week I'll be giving a talk on PGP and running a
>> key signing. Please upload your public key to the keyring before the
>> meeting to register for the key signing. It is possible to participate
>> without registering but it's a lot easier if you register.
>>
>> Please don't hesitate to ask if you have any questions.
>>
>>
>> On Thu, Aug 29, 2013 at 11:53 PM, Eric Martin
>> <eric.joshua.martin(a)gmail.com>wrote:
>>
>>>
> On Wednesday, September 11th 2013 I'll be running a PGP Key Signing
> party. PGP stands for Pretty Good Privacy and was developed by Phil
> Zimmerman in 1991 for secure communications. Signing keys allows you to
> say that you trust somebody's key, and extends the Web of Trust which
> helps everybody.
>
> To participate, please bring your public key's fingerprint, and at least
> (2) forms of ID (Government issued photo ID is the best way to go). If
> you don't yet have a public key, follow the directions for 'Preparing
> for the Party' from this [1] Key Signing Party HOWTO.
>
> Additionally, please upload your public key to our keyring for this
> event here [2]. I'll give a brief talk on PGP, and then we'll go
> through everybody's keys.
>
> What not to bring: A computer. Keys are signed at home, we just verify
> them at the Key Signing.
>
> [1]
>
>
http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.htm…
> [2] http://biglumber.com/x/web?keyring=4480
>
>>>
>>>
>>> _______________________________________________
>>> Wlug mailing list
>>> Wlug(a)mail.wlug.org
>>> http://mail.wlug.org/mailman/listinfo/wlug
- --
Eric Martin
Key Fingerprint = C74F 1EBF 2E80 7984 8CB5 064E BF17 D34C C704 B30F
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (Darwin)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
iQIcBAEBCAAGBQJSMNizAAoJEL8X00zHBLMPCk4QAKLjQJSh4giYnOsCUGsuJuV9
/NzBkG701IJACLFBNeehMB/6jFYk6sNKCYRPSFVMOh2aHogndr+OhHPujAR7mGOv
yShdjDvSNGGNfI4gXcxBvz3+0Hol20DEMQbOaN6WcrLiUG8j5ma5a//V/3+CVCEk
SgYhCg6r1v71Zq+CfpcDoByX8SRHmfp2/48zEUlDv9JCpuE/X9x33L0mhN1wYlGY
zp/jZT3tXVdgkAz/pCLyScq4cMLagj8IkrzlCMT9vd313WVQ/lRm05QKFVlR67XM
9mn0poXP7E04Tl3Z4q8fgO6wM8wdVG4r6cYCUuICysNjhU773JoY7PyxOLmgXggB
BEWlJD6TD/hPFmFVM6T+JoCyDSsh3bEnpefehbW12PXKxPuArLZ5xXF1JHHe3hFb
YcH/9aT+xWWyIUxRfEj1GBbIGDESo9KRmmSiuo0EBFYVSNYtyaEFqoAUsqFS7BmS
acQ/x3Tn7uidOT1IwXJqX9BBSpFJlzqMleLIDjcPezuzr04f3OVqGsZdjJ8iS3M5
cV2P6fdJroJRp9WpaCBkrK2U3rLpqSwTZzn/RylCR9BWSP2nNrEButp62+uwAc3I
69HQAcrpu/DqjP9yVrADe1dnnRKD4s1+lusr23QXETqXEJ0mJHQ4LlJGc/yH/DPu
WePyoSrB+xHgsKj8i/Lv
=n+42
-----END PGP SIGNATURE-----
Sept. 11, 2013
Re: [Wlug] Next WLUG Meeting: Keysigning Party 9/11/2013
by Chuck Anderson
Now is a good time to check if your key is expired and/or is using a
weak algorithm or key size, and generate a new key if necessary.
I followed the steps here to start a transition from an ancient 1024D
(DSA 1024-bit) key to a modern 4096R (RSA 4096-bit) key:
http://www.apache.org/dev/key-transition.html
See you all tonight!
On Sun, Sep 08, 2013 at 10:48:00PM -0400, Eric Martin wrote:
> Just a reminder that this week I'll be giving a talk on PGP and running a
> key signing. Please upload your public key to the keyring before the
> meeting to register for the key signing. It is possible to participate
> without registering but it's a lot easier if you register.
>
> Please don't hesitate to ask if you have any questions.
>
>
> On Thu, Aug 29, 2013 at 11:53 PM, Eric Martin
> <eric.joshua.martin(a)gmail.com>wrote:
>
> >
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA256
> >
> > On Wednesday, September 11th 2013 I'll be running a PGP Key Signing
> > party. PGP stands for Pretty Good Privacy and was developed by Phil
> > Zimmerman in 1991 for secure communications. Signing keys allows you to
> > say that you trust somebody's key, and extends the Web of Trust which
> > helps everybody.
> >
> > To participate, please bring your public key's fingerprint, and at least
> > (2) forms of ID (Government issued photo ID is the best way to go). If
> > you don't yet have a public key, follow the directions for 'Preparing
> > for the Party' from this [1] Key Signing Party HOWTO.
> >
> > Additionally, please upload your public key to our keyring for this
> > event here [2]. I'll give a brief talk on PGP, and then we'll go
> > through everybody's keys.
> >
> > What not to bring: A computer. Keys are signed at home, we just verify
> > them at the Key Signing.
> >
> > [1]
> >
> > http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.htm…
> > [2] http://biglumber.com/x/web?keyring=4480
> >
> > - --
> > Eric Martin
> > Key Fingerprint = C74F 1EBF 2E80 7984 8CB5 064E BF17 D34C C704 B30F
> > -----BEGIN PGP SIGNATURE-----
> > Version: GnuPG v1.4.13 (Darwin)
> > Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
> >
> > iQIcBAEBCAAGBQJSIBdBAAoJEL8X00zHBLMPIP8P/AmMZiaHpVo3Mq72yOXONUbX
> > bUUFKtK2qCFw0g8uAJ63D5hL7kDTbWXlTWsm+73jvkaofsKyTP8hNR0ulr5ni7dw
> > X7EEQYSpK0MufQzEqUpfEoIa6I8Pjfa5qIWNOAuJDJpAwR8+0S2urGcQML0YarFG
> > fys0HHWW69kYG8CTGZw/0ATmBdVZFiZEjXFk6R5wIB33SvXtzuPTLltoded5bpwK
> > svtZf4Fa3QlaEBlg25AKWFpa6OOTt3eUBQU/KNGjhfIrLkhpsbuhcbAD6C6DPtzk
> > 25P/9TWCSaRAcyT29amGG5qLrFEHklAic6UcOjIJtlN6ywcHSbVtHOcxIA4OmBLy
> > e0HeskGlqu/qhqgZxDQMWbvMUdzIRqCa+pMzxGI40+w6tHnlTGPW1MZbZJxhfStW
> > AC720w6U+q/b9iCiZHF634gbvIL6Da3G2G20Vhr4h6s1rOX53sfgIqmoB66A6SPC
> > P6MUkO42oPdEQ7WE+69f7VHGyXgkEnJUaEXGYoBdILV3qyHyNJNKF/X7o0Vtf+xn
> > rJTokOgCEyg5xRtzQFlYpdiIoR/BMHTteKsyki6px2hn4bCsNItOJNhG8IutVo/o
> > qofPVIyJaiA5o7G7z8QNeppy4NBq0h752T0lU/gSs9ojhBzQ9kVuhR4PNL6QcZ98
> > +rLxS3s1fEsTmakIpo2G
> > =lNN3
> > -----END PGP SIGNATURE-----
Sept. 11, 2013
Re: [Wlug] [SPF:Probably_Forged] Re: Next WLUG Meeting: Keysigning Party 9/11/2013
by The Hammer
..I won't be able to get there either. Too much on my plate.
On Tue, Sep 10, 2013 at 5:46 PM, Bob <Robert.Athol.Mass(a)gmail.com> wrote:
> Darn..... Three meetings on Wed. evening; one in Rhode Island; one in
> Worcester; and one in Athol. And, I'm supposed to be retired! Going to
> have to get my key signed another day.
>
> Bob
>
> On 8/29/2013 11:53 PM, Eric Martin wrote:
> > -----BEGIN PGP SIGNED MESSAGE-----
> > Hash: SHA256
> >
> > On Wednesday, September 11th 2013 I'll be running a PGP Key Signing
> > party. PGP stands for Pretty Good Privacy and was developed by Phil
> > Zimmerman in 1991 for secure communications. Signing keys allows you to
> > say that you trust somebody's key, and extends the Web of Trust which
> > helps everybody.
> >
> > To participate, please bring your public key's fingerprint, and at least
> > (2) forms of ID (Government issued photo ID is the best way to go). If
> > you don't yet have a public key, follow the directions for 'Preparing
> > for the Party' from this [1] Key Signing Party HOWTO.
> >
> > Additionally, please upload your public key to our keyring for this
> > event here [2]. I'll give a brief talk on PGP, and then we'll go
> > through everybody's keys.
> >
> > What not to bring: A computer. Keys are signed at home, we just verify
> > them at the Key Signing.
> >
> > [1]
> >
> http://www.cryptnet.net/fdp/crypto/keysigning_party/en/keysigning_party.htm…
> > [2] http://biglumber.com/x/web?keyring=4480
> >
> > - --
> > Eric Martin
> > Key Fingerprint = C74F 1EBF 2E80 7984 8CB5 064E BF17 D34C C704 B30F
> > -----BEGIN PGP SIGNATURE-----
> > Version: GnuPG v1.4.13 (Darwin)
> > Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/
> >
> > iQIcBAEBCAAGBQJSIBdBAAoJEL8X00zHBLMPIP8P/AmMZiaHpVo3Mq72yOXONUbX
> > bUUFKtK2qCFw0g8uAJ63D5hL7kDTbWXlTWsm+73jvkaofsKyTP8hNR0ulr5ni7dw
> > X7EEQYSpK0MufQzEqUpfEoIa6I8Pjfa5qIWNOAuJDJpAwR8+0S2urGcQML0YarFG
> > fys0HHWW69kYG8CTGZw/0ATmBdVZFiZEjXFk6R5wIB33SvXtzuPTLltoded5bpwK
> > svtZf4Fa3QlaEBlg25AKWFpa6OOTt3eUBQU/KNGjhfIrLkhpsbuhcbAD6C6DPtzk
> > 25P/9TWCSaRAcyT29amGG5qLrFEHklAic6UcOjIJtlN6ywcHSbVtHOcxIA4OmBLy
> > e0HeskGlqu/qhqgZxDQMWbvMUdzIRqCa+pMzxGI40+w6tHnlTGPW1MZbZJxhfStW
> > AC720w6U+q/b9iCiZHF634gbvIL6Da3G2G20Vhr4h6s1rOX53sfgIqmoB66A6SPC
> > P6MUkO42oPdEQ7WE+69f7VHGyXgkEnJUaEXGYoBdILV3qyHyNJNKF/X7o0Vtf+xn
> > rJTokOgCEyg5xRtzQFlYpdiIoR/BMHTteKsyki6px2hn4bCsNItOJNhG8IutVo/o
> > qofPVIyJaiA5o7G7z8QNeppy4NBq0h752T0lU/gSs9ojhBzQ9kVuhR4PNL6QcZ98
> > +rLxS3s1fEsTmakIpo2G
> > =lNN3
> > -----END PGP SIGNATURE-----
> >
> > _______________________________________________
> > Wlug mailing list
> > Wlug(a)mail.wlug.org
> > http://mail.wlug.org/mailman/listinfo/wlug
> >
>
> _______________________________________________
> Wlug mailing list
> Wlug(a)mail.wlug.org
> http://mail.wlug.org/mailman/listinfo/wlug
>
Sept. 11, 2013