Crypto

OpenPGP Key Signing Policy

GnuPG / PGP

All keys are also available via subkeys.pgp.net keyservers, such as keyserver.mine.nu.
You are strongly advised to use subkeys.pgp.net, as many other keyservers are broken and mangle keys in various ways.

Main key

All software released on elho.net is signed with my GnuPG key:

pub   1024D/D98502C5 2005-02-17
uid                  Elmar Hoffmann <elho@elho.net>
uid                  Elmar Hoffmann <elmar.hoffmann@credativ.de>
      Key fingerprint = EAD6 5896 4BEE B99D 0B62  89ED 3F10 1691 D985 02C5

Master signing key

This key is used to sign other keys, it is never used on a system with network connectivity.

pub   4096R/CF3401A9 2005-02-17
uid                  Elmar Hoffmann <elho@elho.net>
      Key fingerprint = 8736 FE21 A2DF DDC9 8E5A  AD73 9579 52D7 CF34 01A9

Trust paths

There are trust paths to the keys from the Debian keyring and from both the DFN-PCA of the German reseach network DFN via the CA of the Aachen University of Technology and the CA of the German c't magazine.

Revoked keys

pub   2048R/2AD5D135 1998-04-13 [revoked: 2005-01-31]
uid                            Elmar Hoffmann <elho@elho.net>
uid                            Elmar Hoffmann <elho@gmx.net>
     Key fingerprint = 91 08 82 04 C5 53 89 AB  12 7D 3B 55 48 0F 25 29
pub   1024D/5413E94F 2002-01-28 [revoked: 2005-01-31]
uid                            Elmar Hoffmann <elho@elho.net>
uid                            Elmar Hoffmann <elho@gmx.net>
uid                            Elmar Hoffmann <elmar.hoffmann@credativ.de>
     Key fingerprint = 7F08 AE70 078A 042B 0F52  5F91 3ABA 7F90 5413 E94F

Links

OpenPGP Charter
OpenPGP Message Format (RFC 4880)

GNU Privacy Guard

PGP Tools including caff

OpenPGP SDK

PGP pathfinder and key statistics (0xCF3401A9, 0xD98502C5, Top 1000)

Wotsap - Web of trust statistics and pathfinder (0xCF3401A9, 0xD98502C5)

keyanalyze - Analysis of a large OpenPGP ring (0xCF3401A9, 0xD98502C5, Top 1000)

The Footsie Web of Trust analysis

Biglumber - key signing coordination (0xD98502C5)

Robot CA at toehold.com
Signed Timestamp.org Robot CA
ImperialViolet Email Verifier

PGP Digital Timestamping Service

SKS Keyservers from the endusers view

Using multiple subkeys in GPG
Moving keys and subkeys
Using multiple passwords with a single key

nasty GnuPG private key passphrase brute force tool
GPG symcrack GnuPG symmetric encryption passphrase brute force tool

SSL

All certificates of SSL enabled elho.net servers are signed with the following CA Certificate:

elho.net X.509 CA Certificate (PEM encoded) (GnuPG signature)
elho.net X.509 CA Certificate (DER encoded) (GnuPG signature)

SSH

If you need to give me access to an account, use my SSH public key:

Public SSH version 2 RSA key (GnuPG signature)