-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1,SHA512 Sat, 15 Aug 2009 22:19:23 -0400 In order to reduce my dependence on the SHA-1 hash, I've recently set up a new OpenPGP key, and will be transitioning away from my old one. The old key will continue to be valid at least through the end of 2009, but I prefer all future correspondence to come to the new one. I would also like this new key to be re-integrated into the web of trust and the Debian, DebConf, OFTC, and SPI keyrings. This message is signed by both keys to certify the transition. the old key was: pub 1024D/F0D7D44A 2001-12-09 Key fingerprint = 0D4C 40C1 84AF A56A F548 DE1C EAE3 DC35 F0D7 D44A And the new key is: pub 4096R/A79679CC 2009-05-09 [expires: 2014-05-08] Key fingerprint = 46B6 5063 C267 884B 1282 170F 751A B5DD A796 79CC To fetch my new key from a public key server, you can simply do: gpg --keyserver pool.sks-keyservers.net --recv-key A79679CC If you already know my old key, you can now verify that the new key is signed by the old one: gpg --check-sigs A79679CC If you don't already know my old key, or you just want to be double extra paranoid, you can check the fingerprint against the one above: gpg --fingerprint A79679CC If you are satisfied that you've got the right key, and the UIDs match what you expect, I'd appreciate it if you would sign my key: gpg --sign-key A79679CC Lastly, if you could send me these signatures, I would appreciate it. Ideally this would be done using caff for optimal security; this program can be found at http://pgp-tools.alioth.debian.org/ or in the signing-party package in Debian and Ubuntu. Or you can either send me an e-mail with the new signatures, such as by doing: gpg --armor --export A79679CC | mail -s 'OpenPGP Signatures' jimmy@kaplowitz.org As a less preferred option, you can just upload the signatures to a public keyserver directly: gpg --keyserver pool.sks-keyservers.net --send-key A79679CC Please let me know if there is any trouble, and sorry for the inconvenience. - - Jimmy Kaplowitz jimmy@kaplowitz.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iEYEARECAAYFAkqHbXsACgkQ6uPcNfDX1EopmQCfaa51EpwWMiRNKQ1rtwBGwXoP WGsAnRVcxdGP2ZCzQN9GWi3ZiPtoz/3uiQIcBAEBCgAGBQJKh217AAoJEGT+wHBU dj6b25sQAKuZuw+tVa6paTRTjnwX9XUx2vp3X3FQcXCFpPpfBOfx/QDke985+Sjq 2+65YGsOiI5Dow8rEcZQAFL8UUShZAQT1CHQ+xSdGM6dWPHGhvl+jpZRlNGT9292 pSGCrtCdTcYxM90Bo0iT2RlXprK1TdOvtwLobPYfFdBxbjBrHzI9taT6wNKurkCB v5geKG/h79ieJgJTLFaepSDobNURMB5mrSglXz94+gC6z6GS9cmjERMWNaMzSM/y /RSc3f8K76cAgVfk+Sn/453/NVioOtLFiMElcLx51FB8QZmo8SXr5B6NeF30lYyN v7sBougW0c8o9WrTNA94bHv9AAvPmxrfIcXjHjeH0n9DmR3tuNzsb4mCttdPKCKg stLiL2KiCKsve7n4d/w8tkEjfG0Z9mpSSFLr3OJuMmtnb4A1RXeLMeCZdJ38pLEm c0AUw4jSgDe3qqXdNWAF0fLRwztrEOPQ3ZL2/K5TYkNUyBmxeh/IHN0MWSFH2whg EFIVAm4lpcKh41TnPO/U6rwWhHaap9XQKREHcpGa8ZqjaDQPw2yUrIB1vlCUaw6I jo9q2E7JQe2iEirk1HfDYi6x9OxK/70cbWG5y6KZXBS91X+xI8VSwpAvPgRSA4ZP TdHODLl/pOHSd7GV2WYhUKTcpXt2rUz6HD3Qq/TcFBFtFM43R9B0 =CadK -----END PGP SIGNATURE-----