Mailing List Archive

GPG in production. :)
There is currently a move afoot to convert the Usenet NoCeM protocol
(http://www.cm.org/) from PGP2->PGP5 (and RSA->DH/DSS) for legal reasons
and the eventual abolishment of unauthenticated cancels.

Andrew Gierth, Annihilator's master and FAQ-maintainer for
comp.unix.programmer amongst other things, posted the following today,
which is good news for GPG and the OpenPGP standard. :)

| From: Andrew Gierth <andrew@erlenstar.demon.co.uk>
| Newsgroups: news.admin.nocem
| Subject: Annihilator changes
| Date: 24 Nov 1998 05:29:52 +0000
|
| Annihilator is now signing some (not all) of its NoCeMs using the
| GNU Privacy Guard (GPG) in place of PGP.
|
| The exact same signature algorithm and keys are being used, so this
| change should *not* affect users of the Annihilator nocems. I have
| verified that the notices still verify correctly using PGP v2.6.3i
| (other 2.6.x versions of PGP should work too).
|
| This is primarily an operational experiment, testing GPG under
| production conditions with a view to migrating all my NoCeM-signing to
| use GPG in the short term, and in the longer term possibly moving away
| from RSA keys to other algorithms to allow users to avoid PGP and its
| licensing restrictions.
|
| I will revert to using PGP if anyone finds they have a problem
| verifying the new signatures.
|
| (GPG does not support RSA keys in its standard configuration; it
| requires the use of an add-on module. Use of RSA within the United
| States is subject to patents which still have a couple of years to
| run; outside the US it may be possible to use GPG+RSA without
| licensing problems.)


--
Brian Moore | "The Zen nature of a spammer resembles
Sysadmin, C/Perl Hacker | a cockroach, except that the cockroach
Usenet Vandal | is higher up on the evolutionary chain."
Netscum, Bane of Elves. Peter Olson, Delphi Postmaster
Re: GPG in production. :) [ In reply to ]
On Tue, 24 Nov 1998, brian moore wrote:
> There is currently a move afoot to convert the Usenet NoCeM protocol
> (http://www.cm.org/) from PGP2->PGP5 (and RSA->DH/DSS) for legal reasons
> and the eventual abolishment of unauthenticated cancels.

THANK YOU (and Andrew)! And my news server thanks you. Next task is to
start contacting hierarchy maintainers and getting them to switch to
either PGP5 or GPG, and use DH/DSS keys.

Now, if CERT would only get back to me about using a DH/DSS key to sign
their advisories... :-)

--
Edward S. Marshall <emarshal@logic.net> /> Who would have thought that we -o)
http://www.logic.net/~emarshal/ // would be freed from the Gates of /\\
Linux Weenie, Open-Source Advocate </ hell by a penguin named "Tux"? _\_v
Re: GPG in production. :) [ In reply to ]
On Wed, Nov 25, 1998 at 09:57:10AM -0600, Edward S. Marshall wrote:
> Now, if CERT would only get back to me about using a DH/DSS key to sign
> their advisories... :-)

Well, I just got back an ACK from the Internic (after waiting forever)
for a couple changes. PGP-verify with them works with GPG. :)

[.Idiots took almost a week to ack them. They're really quick when it's
something they bill for, but take forever when they don't bill for it.]

--
Brian Moore | "The Zen nature of a spammer resembles
Sysadmin, C/Perl Hacker | a cockroach, except that the cockroach
Usenet Vandal | is higher up on the evolutionary chain."
Netscum, Bane of Elves. Peter Olson, Delphi Postmaster