-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1,SHA512 Sun Feb 7 18:39:22 CET 2010, For a number of reasons, I've recently set up a new OpenPGP key, and will be transitioning away from my old one. The main reason is that my old key uses the Digital Signature Algorithm (DSA) which mandates the use of SHA-1 as a hash algorithm. SHA-1 is now widely believed to be broken, see for example http://www.schneier.com/blog/archives/2005/02/sha1_broken.html I encourage everybody using OpenPGP to transition away from SHA-1. See for example http://www.debian-administration.org/users/dkg/weblog/48 The old key will continue to be valid for some time, but I prefer all future correspondence to come to the new one. I would also like this new key to be re-integrated into the web of trust. This message is signed by both keys to certify the transition. The old key was: pub 1024D/EA323E66 2007-07-20 Key fingerprint: 442C 8E54 BF50 81F9 41F9 6058 D3C2 DF37 EA32 3E66 And the new key is: pub 4096R/4D5ADB32 2010-02-07 Key fingerprint: C88F 230E 4053 D94A 64C8 2D53 FB58 40DD 4D5A DB32 To fetch the full key, you can get it with: gpg --recv-key 4D5ADB32 If you already know my old key, you can now verify that the new key is signed by the old one: gpg --check-sigs 4D5ADB32 If you don't already know my old key, or you just want to be double extra paranoid, you can check the fingerprint against the one above: gpg --fingerprint 4D5ADB32 Please check that the signatures on this text are valid before going on: gpg --verify key-transition.txt If you are satisfied that you've got the right key, and the UIDs match what you expect, I'd appreciate it if you would sign my key: gpg --sign-key 4D5ADB32 Lastly, if you could upload these signatures, I would appreciate it. gpg --send-key 4D5ADB32 Please let me know if there is any trouble, and sorry for the inconvenience. Regards, Sebastien Vasey This text has been inspired by: http://fifthhorseman.net/key-transition-2007-06-15.txt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iEYEARECAAYFAktvAwEACgkQ08LfN+oyPmbk8wCdF+sZ3CUKxu/Ba4qfhpfIrFWV PxQAoJ1UkfZC3PwgCSW22/UKVJ49gehciQIcBAEBCgAGBQJLbwMBAAoJEPtYQN1N WtsyBdMP/RehXajiOuqrOHd+OD5VO7Yy1406AtKo+Vn2sITDT3LBd6/TOM8MxxTN R3FauJYPszoYIGdgHSpjry1HbbrDfIXIVUDIesS0e+ENlyOweFwdMPLmxTduVL7w 2u0grATUG3p9uprE1sNyv5k5+nXTQExCPpXMgp+3IB6TtSk7UAH2f5pHqNpiYU1n qzLfCB3tO94VqwOBGMQCq4F9NHfqXF78yfDDzmZQs+OKelwDmt0KQyWzW/b9knn5 Mt9Ly6OQ/iGTYUCNA3+6Q/oJkjsLVbk4ptRNooxm8D4x0dkqxc+ru79HQJtg1C7r 8nSwSiY5NrIgpVmpiHWfrd+emDwP2pKOEn6aTTFUeqNHKVeTSrYxfdXFuTr6DpoU rNNqT2UNW5jHA8hzY0uV7B9dhpe4dvkYWoCJb8isUHjUdz9+lRRpKSH6du6iNzjj Y+eTQJZIP5u/jzWIw5lp9eBl9mp06f11IStW3LO+4ZjKDsy40uVxV9N8Qd/nNx8u 1+NJarlmo77DNK1IUQ+DdOfdf8ijbxRZrzGs6NB5xPdkcHNYgoTG+3urPQSV11gb Eqt0fRUsBnUlYPf70UDr7C1AtAhRLUwKWJMcim8C8+Nb/M96elq2tZTj1WFm/SZU bU56lKWFyOG7CcFpa9Iyiczb7eQ+fQO/tWVvKmP8hQ61t2NFUQAs =HOqN -----END PGP SIGNATURE-----