PGP keysigning policy

The PGP/OpenPGP/GnuPG keysigning policy of Ewald Tienkamp

Contents

0.0 Preamble

Signing policy version: 1.0 (For changelog, see section 6.0)

This OpenPGP/GnuPG key signing policy is applicable to key signing done with the following OpenPGP/GnuPG key:

pub 4096R/C641F38C 2010-01-10 - Key fingerprint = D80A 2F08 A32C 6329 6F5C 9C44 F430 C145 C641 F38C

This key can be found on ewald.tienkamp.info/ewald.tienkamp.pgp.publickey.(0xC641F38C).asc, though the most up to date will be my public key on keyservers pgp.mit.edu and pgp.surfnet.nl.

This policy is to be found at ewald.tienkamp.info/keysigningpolicy.php.

0.1 Definitions

I, me, my: any references to 'I', 'me' or 'my' refer to Ewald Tienkamp.
keys: in this document, when not explicitly stated otherwise, key or keys refers to PGP/OpenPGP/GnuPG keys.
signee: the person requesting their key to be signed by me, Ewald Tienkamp, using my personal key C641F38C.

1.0 Key signing conditions

I only sign keys when I have personally met the person who claims to be the owner of said key. Thus, arranging a meet or attending a keysigning party where I'm present, is a requirement for the signee to get their key signed by me.

2.0 Signing levels

GnuPG supports four different signing levels. Below, all of the different levels are listed, and the requirements for the signee to obtain each level is provided.


2.1 Keysigning party modifiers

While keysigning parties are a great way to obtain a lot of signatures, the quality of the signature will be valued less by me. Usually the setting is not optimal, it is cold and/or really busy and the sheer amount of people attending pressures everyone to quickly continue down the line. Therefore, a sig 2 will be the highest signature given by me. Furthermore, any uid's not listed on the keysigning party sheet, will not be signed at all. I will obtain your key from one of the major keyservers, verify names, email, fingerprint and sign accordingly. Any additional uid's that are non-email (and contain anything else than just the name of signee) and/or picture uid's will not be signed and sent.

2.2 Signing of photo uid's

Photo uid's will only be signed for signees I have known for over a year or signees who can provide at least three photo ID's of which one is goverment issued and bear a strong resemblance to both real life and photo uid.

2.2 Signing of non-email uid's

Non-email uid's are not signed by me by default. However, there are some exceptions. First of all, just as with all email uid's, they have to be present on paper during the meeting. Second, if the uid consists of merely the full name, which is identical to the full name of one or more email uid's, I will sign. For things such as birth date and location, I will have to have verified those during the meeting. During a keysigning party there is hardly opportunity to do so, unfortunately, therefore, I will not sign non-email uid's which I were unable to verify during a keysigning party.

3.0 Meeting in person

Aside from meeting in person during a keysigning party, we can arrange a meeting for one on one mutual keysigning. If you happen to be in Utrecht, or better yet, the University complex Uithof, let me know in advance (see ewald.tienkamp.info for ways to contact me) and we'll see if we can meet up. If you like, I can also assure you for CAcert purposes.

3.1 One on one meetings

When meeting one on one, you will want to bring the following:

4.0 Signing procedure

After meeting in person, I will sign the key which was verified during said meeting, when home. The signing will be done using caff, which extracts the key from one of the major keyservers. Therefore, you will want to make sure that the key is present on keyservers and is up to date.

After signing, caff will email your signed public key to each of the uid's encrypted, if possible. Photo uid's and non-email uid's, if signed, will be attached to each email as well.

I reserve the right to not sign a key at my own discretion.

6.0 Changelog

16 February 2010 - Version 1.0, first version, all major sections present

Supplement: attended keysigning parties

I have attended the following parties:

7 February 2010, FOSDEM 2010.
Software used making this website: Gentoo Linux, KDE, Mozilla Firefox, KWrite, GIMP.
This page is valid XHTML 1.0 Strict
This page uses a valid CSS version 3