Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.project > #11956 > unrolled thread

Keysigning in times of COVID-19

Started byEnrico Zini <enrico@enricozini.org>
First post2020-08-06 18:10 +0200
Last post2020-08-13 14:20 +0200
Articles 13 on this page of 53 — 31 participants

Back to article view | Back to linux.debian.project


Contents

  Keysigning in times of COVID-19 Enrico Zini <enrico@enricozini.org> - 2020-08-06 18:10 +0200
    Re: Keysigning in times of COVID-19 Roberto C. Sánchez <roberto@debian.org> - 2020-08-06 18:50 +0200
      Re: Keysigning in times of COVID-19 Federico Ceratto <federico.ceratto@gmail.com> - 2020-08-17 20:30 +0200
        Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-17 21:10 +0200
          Re: Keysigning in times of COVID-19 Wouter Verhelst <wouter@debian.org> - 2020-08-19 16:20 +0200
            Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-19 18:10 +0200
              Re: Keysigning in times of COVID-19 Philip Hands <phil@hands.com> - 2020-08-20 10:20 +0200
                Re: Keysigning in times of COVID-19 Andrey Rahmatullin <wrar@debian.org> - 2020-08-20 10:50 +0200
                Re: Keysigning in times of COVID-19 Ansgar <ansgar@debian.org> - 2020-08-20 10:50 +0200
                Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-20 12:20 +0200
                  Re: Keysigning in times of COVID-19 Russ Allbery <rra@debian.org> - 2020-08-20 19:30 +0200
                Re: Keysigning in times of COVID-19 Florian Weimer <fw@deneb.enyo.de> - 2020-08-23 23:10 +0200
    Re: Keysigning in times of COVID-19 Felix Lechner <felix.lechner@lease-up.com> - 2020-08-06 19:10 +0200
    Re: Keysigning in times of COVID-19 Johannes Schauer <josch@debian.org> - 2020-08-06 19:30 +0200
      Re: Keysigning in times of COVID-19 Holger Levsen <holger@layer-acht.org> - 2020-08-07 11:40 +0200
    Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-06 19:40 +0200
    Re: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-06 23:40 +0200
    Re: Keysigning in times of COVID-19 Héctor Orón Martínez <hector.oron@gmail.com> - 2020-08-07 01:30 +0200
    Re: Keysigning in times of COVID-19 Alexandre Viau <aviau@debian.org> - 2020-08-07 09:30 +0200
      Re: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-07 12:00 +0200
    Re: Keysigning in times of COVID-19 Didier 'OdyX' Raboud <odyx@debian.org> - 2020-08-07 12:00 +0200
    Re: Keysigning in times of COVID-19 Alberto Garcia <berto@igalia.com> - 2020-08-07 12:10 +0200
    Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-07 16:10 +0200
      Re: Keysigning in times of COVID-19 Ulrike Uhlig <ulrike@debian.org> - 2020-08-07 18:50 +0200
      Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:50 +0200
        Re: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-10 20:00 +0200
    Re: Keysigning in times of COVID-19 Gunnar Wolf <gwolf@debian.org> - 2020-08-09 07:40 +0200
    Re: Keysigning in times of COVID-19 Jonathan McDowell <noodles@earth.li> - 2020-08-12 10:10 +0200
      Re: Expressing regrets for how I handled the transition to Identity Verification  in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:30 +0200
    Re: Potential Summary: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-12 14:10 +0200
      Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-12 14:30 +0200
      Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 08:20 +0200
        Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 19:30 +0200
          Re: Potential Summary: Keysigning in times of COVID-19 Pirate Praveen <praveen@onenetbeyond.org> - 2020-08-13 20:20 +0200
            Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-13 21:10 +0200
              Re: Potential Summary: Keysigning in times of COVID-19 Steve McIntyre <steve@einval.com> - 2020-08-13 23:10 +0200
                Re: Potential Summary: Keysigning in times of COVID-19 Adrian Bunk <bunk@debian.org> - 2020-08-14 18:50 +0200
                  Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-14 23:00 +0200
                    Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 23:10 +0200
                      Re: Potential Summary: Keysigning in times of COVID-19 Jonas Smedegaard <dr@jones.dk> - 2020-08-15 00:30 +0200
              Re: Potential Summary: Keysigning in times of COVID-19 Christian Kastner <ckk@debian.org> - 2020-08-13 23:10 +0200
                Re: Potential Summary: Keysigning in times of COVID-19 Adam Borowski <kilobyte@angband.pl> - 2020-08-14 00:40 +0200
          Re: Potential Summary: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-13 21:40 +0200
    Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-12 17:30 +0200
      Re: Keysigning in times of COVID-19 Paul Wise <pabs@debian.org> - 2020-08-13 08:20 +0200
        Re: Keysigning in times of COVID-19 Sam Hartman <hartmans@debian.org> - 2020-08-13 14:00 +0200
          Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200
            Re: Keysigning in times of COVID-19 Guilhem Moulin <guilhem@debian.org> - 2020-08-13 14:50 +0200
              Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 16:50 +0200
                Re: Keysigning in times of COVID-19 Ángel <debian-project@debian.16bits.net> - 2020-08-14 04:00 +0200
                  Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-16 15:40 +0200
        Re: Keysigning in times of COVID-19 rhkramer@gmail.com - 2020-08-13 14:00 +0200
        Re: Keysigning in times of COVID-19 Pierre-Elliott Bécue <peb@debian.org> - 2020-08-13 14:20 +0200

Page 3 of 3 — ← Prev page 1 2 [3]


#12009 — Re: Potential Summary: Keysigning in times of COVID-19

FromChristian Kastner <ckk@debian.org>
Date2020-08-13 23:10 +0200
SubjectRe: Potential Summary: Keysigning in times of COVID-19
Message-ID<ADsE1-1G0-13@gated-at.bofh.it>
In reply to#12006
On 2020-08-13 21:03, Adam Borowski wrote:
> I don't think someone could possibly be prosecuted for using a fake passport
> to obtain a gpg signature.

In many (if not most) jurisdictions, using a fake government ID for any
transaction whatsoever is a crime. It's not tied to monetary or any
other gain. The deterrent is meant to be absolute. Otherwise it wouldn't
be very effective.

But even if it weren't a crime: Once the person waving the fake ID is
caught, it's unlikely that we'd see that person ever again at future
Debian events, as that would probably result in a call to law enforcement.

You can't change your own face (within reason), and exposing that face
is a risk.

You can easily discard an online persona and create a new one, though.

[toc] | [prev] | [next] | [standalone]


#12010 — Re: Potential Summary: Keysigning in times of COVID-19

FromAdam Borowski <kilobyte@angband.pl>
Date2020-08-14 00:40 +0200
SubjectRe: Potential Summary: Keysigning in times of COVID-19
Message-ID<ADu38-2qf-9@gated-at.bofh.it>
In reply to#12009
On Thu, Aug 13, 2020 at 10:59:47PM +0200, Christian Kastner wrote:
> On 2020-08-13 21:03, Adam Borowski wrote:
> > I don't think someone could possibly be prosecuted for using a fake passport
> > to obtain a gpg signature.

> But even if it weren't a crime: Once the person waving the fake ID is
> caught, it's unlikely that we'd see that person ever again at future
> Debian events, as that would probably result in a call to law enforcement.

Someone planning mischief won't attend a big event.

> You can't change your own face (within reason), and exposing that face
> is a risk.
> 
> You can easily discard an online persona and create a new one, though.

With ~1000 DDs, you can get 500 pairs of signatures without ever meeting the
same person twice.


Meow!
-- 
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁
⢿⡄⠘⠷⠚⠋⠀ It's time to migrate your Imaginary Protocol from version 4i to 6i.
⠈⠳⣄⠀⠀⠀⠀

[toc] | [prev] | [next] | [standalone]


#12007 — Re: Potential Summary: Keysigning in times of COVID-19

FromÁngel <debian-project@debian.16bits.net>
Date2020-08-13 21:40 +0200
SubjectRe: Potential Summary: Keysigning in times of COVID-19
Message-ID<ADreW-FA-5@gated-at.bofh.it>
In reply to#12003

[Multipart message — attachments visible in raw view] — view raw

On 2020-08-13 at 17:57 +0200, Adam Borowski wrote:
> On Thu, Aug 13, 2020 at 02:59:59AM +0200, Ángel wrote:
> > as there would be an external motivation to do that which is financing
> > such activity. Please note that by 'company' I am not meaning just
> > business entities, but also three letter agencies, nation states,
> > malicious hacker groups, mafia...
> > Even ignoring the (likely) ability of such groups to get a passport
> > under a name different than the one given at birth to an individual,
> > it seems they would have little trouble to produce a new identity to
> > present to Debian. I assume they would probably only have a few people
> > on payroll with the required expertise tasked to infiltrate into the
> > project, *however* it would be very easy to let them assume online the
> > identity of any other employee (such as a non-technical receptionist),
> > which would be plenty if compared to the number of "ghosthacker
> > developers".
> 
> I don't get where people get the feeling that producing a passport would
> require a TLA/nation state/organized crime/etc.  You can get one for
> peanuts.
> 
> I've been offered one once, and I inquired about the details -- for just
> ~$25 (100PLN) the guy claimed it's done on original booklet, etc.  That's
> stuff for fooling actual government officials.  No need to sacrifice that
> whole $25 to get a fake for Debian purposes, though -- no one among us can
> tell apart one booklet/card with a badly-made photo from another.
> 
> Waving a passport or similar id offers laughable security.
> 
> 
> Meow.

Hi

Please note that my point was that any determined 'company' could get
multiple identities signed, without even involving crafting new
passports or identity cards, which of course would also be within their
reach.

Would a TLA/nation state/organized crime/etc. be interested in being
able to compromise Debian hosts? Sure. Amongst them, some would try hard
for plausible deniability, while others directly don't care.

If the keysigning is expected to protect (to a certain point) against
this, it's a scenario to take into account, uncomfortable as it is.

It might be possible that there is a better solution for that that could
be included, or that it is determined that the system is fallible yet we
don't have anything better so far to use.

It is thus important to define what is expected from this step of the
process.

Best regards

[toc] | [prev] | [next] | [standalone]


#11994

FromPierre-Elliott Bécue <peb@debian.org>
Date2020-08-12 17:30 +0200
Message-ID<AD0Rr-1ym-3@gated-at.bofh.it>
In reply to#11956

[Multipart message — attachments visible in raw view] — view raw

Le jeudi 06 août 2020 à 17:54:21+0200, Enrico Zini a écrit :
> Hello,
> 
> we have people approaching Debian with a lack of GPG signatures, and we
> generally cannot ask them to travel and meet other developers in person
> to get their key signed.
> 
> Technically, we are not requiring that people meet a DD in person, only
> that people have their key signed by a DD.
> 
> Technically, every DD has their own policies for signing keys, which
> could go from not requiring meeting in person at all, to requiring to
> meet in person multiple times. It might require to check a government
> issued photo ID, or it might not.
> 
> Practically, I feel like most of the time people's policies match what
> are the perceived expectations of the rest of the project. Meeting in
> person has always been a good safe bet, if only for the reson that it's
> been accepted without question for many years.
> 
> It's time to review those expectations.
> 
> For example, speaking of myself only, if my goal is to raise the cost of
> impersonation or sock puppet identities, then probably signing someone's
> key after having worked with them online for a significant time, would
> require a much higher cost than showing up at a keysigning party with a
> fake ID good enough to fool me.
> 
> Others may have other policies, and are likely to be acceptable.
> 
> As DAM, I would have a problem if someone automatically signed the keys
> of every stanger who asked them nicely in an email. At the same time, I
> am open to the idea of policies that do not require meeting people in
> person.
> 
> I think the world has changed enough in the last months that currently
> perceived project expectations about key signing are getting out of
> alignment with practical realities, and it might be time to explore
> other options.
> 
> I do not intend to ask people to break their sensible signing policies
> so that people can get into Debian. I'm interested instead in exploring
> what signing policies people may have, or may be considering, that have
> been staying out of our narrative because we've always been having a
> specific standard one that worked.
> 
> What do you think could be alternative key signing policies, that would
> be acceptable to you, that would not require traveling and meeting face
> to face?

IMHO, the issue with lowering keysigning policy is that these signatures
will be as valid as any other for later DD application, while we
probably don't want to lower our expectations for other status
applications than DM.

I'd rather try to solve the issue in a more sensible way : lower the
number of expected GPG signatures to 0 temporarily, and ask for two or
three advocacies from DDs.

We'd lose a bit of ID verification security for the DM status, but we
could regain this security when the DM applies to become a DD, as they'd
have to reach out to other developers and get their key signed.

This wouldn't solve the broader issue that can arise when one lives in a
place with no close DD and wants to become a DD themselves.

But it'd be a start.

-- 
Pierre-Elliott Bécue
GPG: 9AE0 4D98 6400 E3B6 7528  F493 0D44 2664 1949 74E2
It's far easier to fight for one's principles than to live up to them.

[toc] | [prev] | [next] | [standalone]


#11995

FromPaul Wise <pabs@debian.org>
Date2020-08-13 08:20 +0200
Message-ID<ADeKJ-1EM-1@gated-at.bofh.it>
In reply to#11994
On Wed, Aug 12, 2020 at 3:27 PM Pierre-Elliott Bécue wrote:

> I'd rather try to solve the issue in a more sensible way : lower the
> number of expected GPG signatures to 0 temporarily, and ask for two or
> three advocacies from DDs.

This seems like the most natural solution to the problem of COVID
mentioned thus far.

> We'd lose a bit of ID verification security for the DM status, but we
> could regain this security when the DM applies to become a DD, as they'd
> have to reach out to other developers and get their key signed.

We could also ask them to get signatures once the COVID situation in
their area allows them to do that.

> This wouldn't solve the broader issue that can arise when one lives in a
> place with no close DD and wants to become a DD themselves.

Given the "problems" that are being discussed on another thread in
another location, I think there is an obvious solution to solve both
issues at the same time, once the COVID situation allows it.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise

[toc] | [prev] | [next] | [standalone]


#11997

FromSam Hartman <hartmans@debian.org>
Date2020-08-13 14:00 +0200
Message-ID<ADk3M-4Gx-3@gated-at.bofh.it>
In reply to#11995
>>>>> "Paul" == Paul Wise <pabs@debian.org> writes:

    Paul> On Wed, Aug 12, 2020 at 3:27 PM Pierre-Elliott Bécue wrote:
    >> I'd rather try to solve the issue in a more sensible way : lower
    >> the number of expected GPG signatures to 0 temporarily, and ask
    >> for two or three advocacies from DDs.

    Paul> This seems like the most natural solution to the problem of
    Paul> COVID mentioned thus far.

How do you feel about the idea of short-term expirations on signatures
proposed in the previous message on the list?

[toc] | [prev] | [next] | [standalone]


#11999

FromPierre-Elliott Bécue <peb@debian.org>
Date2020-08-13 14:20 +0200
Message-ID<ADkn7-52C-3@gated-at.bofh.it>
In reply to#11997

[Multipart message — attachments visible in raw view] — view raw

Le jeudi 13 août 2020 à 07:42:29-0400, Sam Hartman a écrit :
> >>>>> "Paul" == Paul Wise <pabs@debian.org> writes:
> 
>     Paul> On Wed, Aug 12, 2020 at 3:27 PM Pierre-Elliott Bécue wrote:
>     >> I'd rather try to solve the issue in a more sensible way : lower
>     >> the number of expected GPG signatures to 0 temporarily, and ask
>     >> for two or three advocacies from DDs.
> 
>     Paul> This seems like the most natural solution to the problem of
>     Paul> COVID mentioned thus far.
> 
> How do you feel about the idea of short-term expirations on signatures
> proposed in the previous message on the list?

Unless I missed a GPG capability, this seems kinda technically hard to
do.

-- 
Pierre-Elliott Bécue
GPG: 9AE0 4D98 6400 E3B6 7528  F493 0D44 2664 1949 74E2
It's far easier to fight for one's principles than to live up to them.

[toc] | [prev] | [next] | [standalone]


#12001

FromGuilhem Moulin <guilhem@debian.org>
Date2020-08-13 14:50 +0200
Message-ID<ADkQ9-5cr-3@gated-at.bofh.it>
In reply to#11999

[Multipart message — attachments visible in raw view] — view raw

Hi,

On Thu, 13 Aug 2020 at 14:11:14 +0200, Pierre-Elliott Bécue wrote:
> Le jeudi 13 août 2020 à 07:42:29-0400, Sam Hartman a écrit :
>>>>>>> "Paul" == Paul Wise <pabs@debian.org> writes:
>> 
>>   Paul> On Wed, Aug 12, 2020 at 3:27 PM Pierre-Elliott Bécue wrote:
>>   >> I'd rather try to solve the issue in a more sensible way : lower
>>   >> the number of expected GPG signatures to 0 temporarily, and ask
>>   >> for two or three advocacies from DDs.
>> 
>>   Paul> This seems like the most natural solution to the problem of
>>   Paul> COVID mentioned thus far.
>> 
>> How do you feel about the idea of short-term expirations on signatures
>> proposed in the previous message on the list?
> 
> Unless I missed a GPG capability, this seems kinda technically hard to
> do.

gpg has a `--ask-cert-expire` flag and a `--default-cert-expire` option
in that effect.  Expired certification signatures will be ignored when
building the Web of Trust.

Cheers
-- 
Guilhem.

[toc] | [prev] | [next] | [standalone]


#12002

FromPierre-Elliott Bécue <peb@debian.org>
Date2020-08-13 16:50 +0200
Message-ID<ADmIh-6lf-1@gated-at.bofh.it>
In reply to#12001

[Multipart message — attachments visible in raw view] — view raw

Le jeudi 13 août 2020 à 14:29:35+0200, Guilhem Moulin a écrit :
> Hi,
> 
> On Thu, 13 Aug 2020 at 14:11:14 +0200, Pierre-Elliott Bécue wrote:
> > Le jeudi 13 août 2020 à 07:42:29-0400, Sam Hartman a écrit :
> >>>>>>> "Paul" == Paul Wise <pabs@debian.org> writes:
> >> 
> >>   Paul> On Wed, Aug 12, 2020 at 3:27 PM Pierre-Elliott Bécue wrote:
> >>   >> I'd rather try to solve the issue in a more sensible way : lower
> >>   >> the number of expected GPG signatures to 0 temporarily, and ask
> >>   >> for two or three advocacies from DDs.
> >> 
> >>   Paul> This seems like the most natural solution to the problem of
> >>   Paul> COVID mentioned thus far.
> >> 
> >> How do you feel about the idea of short-term expirations on signatures
> >> proposed in the previous message on the list?
> > 
> > Unless I missed a GPG capability, this seems kinda technically hard to
> > do.
> 
> gpg has a `--ask-cert-expire` flag and a `--default-cert-expire` option
> in that effect.  Expired certification signatures will be ignored when
> building the Web of Trust.
> 
> Cheers

This could work, but we'd have to handle the case when developers forget
to set a signature as time-limited/don't follow this thread and never
care to set it up.

I'd rather avoid relying on signatures, than making the meaning of
signature quite less tangible.

-- 
Pierre-Elliott Bécue
GPG: 9AE0 4D98 6400 E3B6 7528  F493 0D44 2664 1949 74E2
It's far easier to fight for one's principles than to live up to them.

[toc] | [prev] | [next] | [standalone]


#12011

FromÁngel <debian-project@debian.16bits.net>
Date2020-08-14 04:00 +0200
Message-ID<ADxaG-4cH-5@gated-at.bofh.it>
In reply to#12002

[Multipart message — attachments visible in raw view] — view raw

On 2020-08-13 at 16:43 +0200, Pierre-Elliott Bécue wrote:
> > gpg has a `--ask-cert-expire` flag and a `--default-cert-expire` 
> > option in that effect.  Expired certification signatures will be 
> > ignored when building the Web of Trust.
> > 
> > Cheers
> 
> This could work, but we'd have to handle the case when developers
> forget to set a signature as time-limited/don't follow this thread and
> never care to set it up.
> 
> I'd rather avoid relying on signatures, than making the meaning of
> signature quite less tangible.


I don't see your point. We have a general standard or what to require
for signing, and this thread started asking about weaking them due to
the pandemic.

Limiting the time the signature is valid is a time-limited way to do
that. And it is a cryptographic one, which is a very nice feature.
I would like to have some common notation so that the standard used
could be tracked, too.

If a developer is going to forget how to do a "weak value" signature, he
should probably stick to the standards he has generally used, but
anyway, if someone wanted to do a limited-time signature but forgot the
parameter, he should do exactly the same as if he signed Eve key while
intending to sing Alice's: revoke the wrong signature and create a new
one.


Regards

Ángel


[toc] | [prev] | [next] | [standalone]


#12024

FromPierre-Elliott Bécue <peb@debian.org>
Date2020-08-16 15:40 +0200
Message-ID<AEr3b-4Ko-1@gated-at.bofh.it>
In reply to#12011

[Multipart message — attachments visible in raw view] — view raw

Le vendredi 14 août 2020 à 01:10:02+0200, Ángel a écrit :
> On 2020-08-13 at 16:43 +0200, Pierre-Elliott Bécue wrote:
> > > gpg has a `--ask-cert-expire` flag and a `--default-cert-expire` 
> > > option in that effect.  Expired certification signatures will be 
> > > ignored when building the Web of Trust.
> > > 
> > > Cheers
> > 
> > This could work, but we'd have to handle the case when developers
> > forget to set a signature as time-limited/don't follow this thread and
> > never care to set it up.
> > 
> > I'd rather avoid relying on signatures, than making the meaning of
> > signature quite less tangible.
> 
> 
> I don't see your point. We have a general standard or what to require
> for signing, and this thread started asking about weaking them due to
> the pandemic.
> 
> Limiting the time the signature is valid is a time-limited way to do
> that. And it is a cryptographic one, which is a very nice feature.
> I would like to have some common notation so that the standard used
> could be tracked, too.
> 
> If a developer is going to forget how to do a "weak value" signature, he
> should probably stick to the standards he has generally used, but
> anyway, if someone wanted to do a limited-time signature but forgot the
> parameter, he should do exactly the same as if he signed Eve key while
> intending to sing Alice's: revoke the wrong signature and create a new
> one.

I fully agree on the principle, but there is a big hiatus between what
some do with their GPG key and what others do.

Without being judgmental, I think this spectre of ways to do things has
to be taken into account before giving any project-wide directives
regarding identity certification.

Cheers,

-- 
Pierre-Elliott Bécue
GPG: 9AE0 4D98 6400 E3B6 7528  F493 0D44 2664 1949 74E2
It's far easier to fight for one's principles than to live up to them.

[toc] | [prev] | [next] | [standalone]


#11998

Fromrhkramer@gmail.com
Date2020-08-13 14:00 +0200
Message-ID<ADk3L-4Gx-1@gated-at.bofh.it>
In reply to#11995
On Wednesday, August 12, 2020 11:36:11 PM Paul Wise wrote:
> Given the "problems" that are being discussed on another thread in
> another location, I think there is an obvious solution to solve both
> issues at the same time, once the COVID situation allows it.

??

[toc] | [prev] | [next] | [standalone]


#12000

FromPierre-Elliott Bécue <peb@debian.org>
Date2020-08-13 14:20 +0200
Message-ID<ADkn7-52C-5@gated-at.bofh.it>
In reply to#11995

[Multipart message — attachments visible in raw view] — view raw

Le jeudi 13 août 2020 à 03:36:11+0000, Paul Wise a écrit :
> > This wouldn't solve the broader issue that can arise when one lives in a
> > place with no close DD and wants to become a DD themselves.
> 
> Given the "problems" that are being discussed on another thread in
> another location, I think there is an obvious solution to solve both
> issues at the same time, once the COVID situation allows it.

Could you ellaborate a bit on this part, I feel that I have missed
something.

-- 
Pierre-Elliott Bécue
GPG: 9AE0 4D98 6400 E3B6 7528  F493 0D44 2664 1949 74E2
It's far easier to fight for one's principles than to live up to them.

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | linux.debian.project


csiph-web