-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256,SHA1 Time-stamp: <2009-05-16 11:57:18 ruhl> Due to the recent weaknesses found in SHA-1 (c.f. MHP1), I am migrating away from my previous DSA key using SHA-1 to a newer RSA key using better digest algorithms. The old key will continue to be valid until 16 Aug 2009, after which I intend to submit a revocation certificate to pgp.mit.edu. This message is signed by both old and new keys in order to certify this transition. The old key was: pub 1024D/47740A63 2001-06-26 Key fingerprint = 347A 5D07 607B 6D88 6882 5F64 4361 EBDA 4774 0A63 The new key is: pub 4096R/A65E2454 2009-05-16 Key fingerprint = 0113 A3F5 598B 51C2 4D24 950B EC98 693D A65E 2454 To fetch the full key (including a photo uid when it's available), simply run: gpg --fetch-keys http://www.octopodial-chrome.com/~ruhl/A65E2454.asc Or, to fetch it from a public key server (which will probably strip the photo uid out): gpg --keyserver pgp.mit.edu --recv-key A65E2454 If you already know my old key, you can verify that the new key is signed by the old one: gpg --check-sigs A65E2454 If you don't already know my old key, you can check the fingerprint against the one above: gpg --fingerprint A65E2454 If you're satisfied that you have the correct key, I would appreciate it if you'd sign my key: gpg --sign-key A65E2454 If you _do_ choose to sign my key, it would be very useful if you would upload them, either by emailing to me: gpg --armour --export A65E2454 | mail -s 'OpenPGP signatures for A65E2454' eadmund42@gmail.com Or by sending them to a key server: gpg --keyserver pgp.mit.edu --send-key A65E2454 Please feel free to contact me if you have any questions. Sorry for the inconvenience, but it's the price we must pay in order to have security. Bob Uhl References: MHP1: http://eurocrypt2009rump.cr.yp.to/837a0a8086fa6ca714249409ddfae43d.pdf -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iQIcBAEBCAAGBQJKDw6xAAoJEOyYaT2mXiRUmM8P/3COop0CQpc1hVXk7gv2o04d u4SmSbxTXHIOwUDOT7apkTEF2amaBVzoyEUcljFJIlePedyi9siL2Q1Z3NFQAS+/ q5k94icWtXFBonGbE4wPqBxEZHAVgteA+0Y5KfiznxN4tJlNKtQajvExPPGXSKVn ZbkeUsGLWpCMx7H4dexjwIENstY49o7pBE114I56y3xifQctQYzKjliJ2asq50FF XAsvstylsK7Mp4+IRbAEdPsdCsifkOm10cP0YT/7RDyvmZtmk3Gi4iA0/K8n2g4r L2Bmq1C300U3aWM8YDsUwA3xdqMwQug1FyyysG3a3J7Teg89llXdmjwj3CFbR4MU aUR8RESAp9JNwAwfftfdCtduXsk2X145JZx4lBFvMeiL+FHYSCxbfIj8su2cgm3J IP2ztTH+/s9OT1asUwwahJiRhUcUkKB8aaDlnG5w4bP+Qxtm5TPkRpCwdRGZygnD VXc3EsB5COcUIzl3FW7D4XfIxIg/06hiMfLo+LE7gnW35/GtzPPgExTULf+DF8aT M11cArRzVKudXtgDHcqYYrVjcbyImV95kHVS4AU5GAsc4JALFSZAKS/vn0l+lTJl wYqBXHyhGbDJXpeE+RbuYkROHqT/LcffNkx/btyihnhIl0eNdSsc6AQP/Nvcwh2i yrNUy0x7snxzWJIEwVoZiEYEARECAAYFAkoPDrEACgkQQ2Hr2kd0CmPLYwCfXV7o /ek5zoFvUjZawVjKsjk7fMYAoKbO+6XIgsQidS/ax883Yron4Gwt =x9fR -----END PGP SIGNATURE-----