Re: Thank you for your trust

2025-04-25 Thread Olaf Dreßler
;Hi, > >I'd like to thank the Debian community for the trust you've placed in me >by re-electing me as DPL. The greatest moments in my last term were >receiving so many signals of support from friends in the project once >things became difficult - that encouragement was a hu

Bug#1011388: ITP: sequoia-wot -- Authenticate OpenPGP certificates using the "Web of Trust"

2022-05-21 Thread Daniel Kahn Gillmor
: LGPL 2.0 or later Programming Lang: Rust Description : Authenticate OpenPGP certificates using the "Web of Trust" The "Web of Trust" describes a network of identity assertions ("OpenPGP certifications") and signing delegations ("OpenPGP trust

Re: Use files created during CI to seed trust and attract new users?

2021-08-18 Thread Paul Wise
On Wed, Aug 18, 2021 at 10:36 AM Steffen Möller wrote: > When CI fails, I get an email and can chase things up with a look at the > output files. This is something I like a lot. As a user, though, > especially for scientific packages I would want to see the files that > have been created. These a

Use files created during CI to seed trust and attract new users?

2021-08-18 Thread Steffen Möller
Hello, When CI fails, I get an email and can chase things up with a look at the output files. This is something I like a lot. As a user, though, especially for scientific packages I would want to see the files that have been created. This way I could confirm that, e.g., the generated PDFs have us

Bug#921309: ITP: node-trust-json-document -- JSON Document manipulation library

2019-02-03 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: node-trust-json-document Version : 0.1.4 Upstream Author : Anvil Research, Inc. * URL : https://github.com/anvilresearch/json-document * License

Bug#921307: ITP: node-trust-jwa -- JSON Web Algorithm

2019-02-03 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: node-trust-jwa Version : 0.4.6 Upstream Author : MIT Connection Science * URL : https://github.com/anvilresearch/jwa * License : Expat

Bug#921303: ITP: node-trust-webcrypto -- WebCrypto API for Node.js

2019-02-03 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: node-trust-webcrypto Version : 0.9.2 Upstream Author : 2016, Anvil Research, Inc. * URL : https://github.com/anvilresearch/webcrypto * License

Bug#921283: ITP: node-trust-keyto -- utility for translating cryptographic keys between representations

2019-02-03 Thread Jonas Smedegaard
Package: wnpp Severity: wishlist Owner: Jonas Smedegaard -BEGIN PGP SIGNED MESSAGE- Hash: SHA512 * Package name: node-trust-keyto Version : 0.3.4 Upstream Author : Greg Linklater * URL : https://eternaldeiwos.github.io/keyto * License : Expat

Re: Maybe helpful - tool to check for chains of trust and collisions in GPG signatures

2016-08-11 Thread Jakub Wilk
, and resulted in making a small tool which can discover and check trust paths within the PGP web of trust. It uses the "PGP pathfinder" service to discover signature chains. It also warns about collisions. The thing is still somewhat experimental (probably not suited for general us

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Holger Levsen
On Fri, Jul 08, 2016 at 02:54:20PM +0200, Enrico Zini wrote: > What if you received a message signed with key 9F6C6333? > > That is, what do you do (please list the practical steps) to validate a > signature that is a few steps away from your key in the WoT? trust in the real worl

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Guilhem Moulin
Hi Enrico, On Fri, 08 Jul 2016 at 11:21:27 +0200, Enrico Zini wrote: > gpg --verify tells me of a short key ID: In fact the issuer subpacket is 8-bytes long [0], hence contains the long key ID of the signer, as seen using ‘--list-packets’: ~$ gpg --list-packets " imported gpg: no ultima

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Jakub Wilk
* Simon Richter , 2016-07-08, 14:33: given that it is now possible to generate arbitrary short key ID collisions[1], and that it's now computationally feasible to at least generate a pair of keys with colliding long key IDs, I'd like to rethink practices and tools. With the web of

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Enrico Zini
ike to rethink > > practices and tools. > > With the web of trust, in principle there shouldn't be a problem. > > I have a valid trust path to Piotr's correct key. I don' have any to the > fake key, because no one I trust has signed a key from the evil32 set. W

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Simon Richter
tices and tools. With the web of trust, in principle there shouldn't be a problem. I have a valid trust path to Piotr's correct key. I don' have any to the fake key, because no one I trust has signed a key from the evil32 set. What could be improved would be detection of new signatur

Re: So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Jakub Wilk
* Enrico Zini , 2016-07-08, 11:21: $ mkdir /tmp/keyring $ chmod 0700 /tmp/keyring This way of creating a directory inaccessible to other is racy. Between mkdir and chmod calls, the directory could be opened by an attacker (and then kept open forever). A non-racy way looks like this: $ mkd

So I received a gpg-signed email, can I trust it?

2016-07-08 Thread Enrico Zini
cument it, then automate it", I'd like to begin with a simple use case: So I received a gpg-signed email, can I trust it? I'll write here my take on it and request your comments on it, to see if there are any gaps. Take for example this file, and an empty keyring: $ mkdir /t

Bug#759398: ITP: trust-router - Dynamically configure Trust Between RADIUS Realms

2014-08-26 Thread Sam Hartman
package: wnpp severity: wishlist owner: hartm...@debian.org URL: git://git.project-moonshot.org/trust_router.git http://www.project-moonshot.org/ license: bsd-3-clause Description: The trust router establishes a DH key between two RADIUS servers to protect a RADIUS over TLS session. GSS-API

Re: Trust and systemd (was Re: Bug#727708, et cetera)

2014-02-13 Thread Olav Vitters
gt; those principles are.) Just highlight them as you come across it (don't have to do that upstream, debian-devel is enough). If I agree and it is an issue I'll at least talk to systemd maintainers. I do trust them, in my opinion they cannot be aware of everything. Further, they might no

Trust and systemd (was Re: Bug#727708, et cetera)

2014-02-12 Thread The Wanderer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 02/11/2014 10:15 AM, Olav Vitters wrote: > On Tue, Feb 11, 2014 at 09:05:48AM -0500, The Wanderer wrote: >> I do not trust the systemd project to not do things I consider bad >> or even insane, because they've already done s

Bug#675829: ITP: libmodule-install-trustmetayml-perl -- trust META.yml list of dependencies

2012-06-03 Thread Jonas Smedegaard
+ Programming Lang: Perl Description : trust META.yml list of dependencies CPAN doesn't trust "META.yml"'s list of dependencies for a module. Instead it expects "Makefile.PL" run on the computer the package is being installed upon to generate its own list of depende

Bug#505806: ITP: monkeysphere -- use the OpenPGP web of trust to verify ssh connections

2008-11-15 Thread Jameson Graef Rollins
ysphere.info * License : GPLv3 Programming Lang: Bash, C Description : use the OpenPGP web of trust to verify ssh connections SSH key-based authentication is tried-and-true, but it lacks a true Public Key Infrastructure for key certification, revocation and expiration. Monke

Can i Trust You? Call me if yes +226 78 03 96 12

2008-09-20 Thread Ahmed Diallo
I have a new email address!You can now email me at: [EMAIL PROTECTED] I am Ahmed DIALLO, a staf of Bank Of Africa I want to transfer US$14 Million to your account. - Ahmed Diallo

Bug#434395: ITP: wotsap -- OpenPGP Web of Trust analyzer and pathfinder

2007-07-23 Thread Giovanni Mascellani
Web of Trust analyzer and pathfinder Wotsap is a tool that analyzes a OpenPGP Web of Trust description and reports to the user stastistics about the single keys and the whole network, or searches for paths from one key to another. OpenPGP is the most widely used email encryption standard, used by encr

Bug#421814: ITP: gnunet-tools -- Secure, trust-based peer-to-peer framework

2007-05-01 Thread Arnaud Kyheng
Description : Secure, trust-based peer-to-peer framework This is part of the gnunet package split into gnunet-daemon, gnunet-client, gnunet-tools, gnunet-common, and gnunet-dev. -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing') Ar

Bug#421812: ITP: gnunet-dev -- Secure, trust-based peer-to-peer framework

2007-05-01 Thread Arnaud Kyheng
Description : Secure, trust-based peer-to-peer framework This is part of the gnunet package split into gnunet-daemon, gnunet-client, gnunet-tools, gnunet-common, and gnunet-dev. -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing') Ar

Bug#421813: ITP: gnunet-daemon -- Secure, trust-based peer-to-peer framework

2007-05-01 Thread Arnaud Kyheng
Description : Secure, trust-based peer-to-peer framework This is part of the gnunet package split into gnunet-daemon, gnunet-client, gnunet-tools, gnunet-common, and gnunet-dev. -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing') Ar

Bug#421808: ITP: gnunet-common -- Secure, trust-based peer-to-peer framework

2007-05-01 Thread Arnaud Kyheng
Description : Secure, trust-based peer-to-peer framework This is part of the gnunet package split into gnunet-daemon, gnunet-client, gnunet-tools, gnunet-common, and gnunet-dev. -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing') Ar

Prices You Can Afford - Quality You Can Trust

2005-07-03 Thread Bobby
We have been helping thousands of men with male enhancement http://qudk.roukvs92oj9hda9.carucatedlf.info Everybody winds up kissing the wrong person good night. Practice, the master of all things. University politics are vicious precisely because the stakes are so small. -- To

trust

2003-10-13 Thread Kolapo Omidire
I am Mr. Kolapo Omidire,company secretary/Manager, internal and external services of COMMERCIAL BANK OF AFRICA.I was the accounts officer of late Mr. Alan a national of your country, who used to work with The Nigerian Mining Corporation(NMC) here in Nigeria who was banking with our bank. On