<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN"
            "http://www.w3.org/TR/html4/strict.dtd">
<HTML lang="en-us">
<head profile="http://dublincore.org/documents/dcq-html/">
<TITLE>alt.security.keydist Frequently Asked Questions</TITLE>
<base href="http://www.alt-security-keydist.info/FAQ">

<META NAME="Description" CONTENT="This article explains how to distribute
public encryption keys through the newsgroup alt.security.keydist">
<meta name="keywords" content="alt.security.keydist, FAQ">

<meta name="DCTERMS.created" scheme="DCTERMS.W3CDTF" content="1997-02-22">
<meta name="DC.identifier" scheme="DCTERMS.URI" content="hdl:1030.65/keys-faq">
<meta name="DC.subject" scheme="DCTERMS.URI" content="news:alt.security.keydist">
<meta name="DCTERMS.isFormatOf" scheme="DCTERMS.URI" content="http://www.alt-security-keydist.info/FAQ.txt">

<link rel="Top" href="/">
<link rel="Search" href="/search">
<link rel="Author" rev="made" href="mailto:michael@bauser.com" title="Michael Bauser">
<link rel="Alternate" href="FAQ.txt" type="text/plain" title="plain text">
<link rel="Alternate" href="FAQ.xml" type="text/xml" title="QAML (XML)">
<link rel="meta" type="application/rdf+xml" href="/rdfscrape?path=%2FFAQ">
<link rel="styleSheet" type="text/javascript" href="yellow.jss">
<link rel="styleSheet" type="text/css" href="yellow.css" media="screen">
<link rel="schema.DC" href="http://purl.org/dc/elements/1.1/">
<link rel="schema.DCTERMS" href="http://purl.org/dc/terms/">
</HEAD>
<BODY>
<p id="logo"><a href="/">alt.security.keydist Resources</a></p>
<div id="entries">
<div id="intro">
<H1>alt.security.keydist Frequently Asked Questions</H1>

<H2 ID="one">Subject: Introduction</H2>

<P> This is a list of Frequently Asked Questions (and answers) for <A
HREF="news:alt.security.keydist">the unmoderated newsgroup
alt.security.keydist</A>. It explains the purpose of the newsgroup and how
to efficiently distribute public encryption keys using
alt.security.keydist. It is a very short <acronym title="Frequently Asked
Questions">FAQ</acronym>.</p>

<P>This <acronym title="Frequently Asked Questions">FAQ</acronym> assumes
you have a basic working knowledge of your chosen encryption software. If
you need more information about particular software, please try the
resources listed at the end of this <acronym title="Frequently Asked
Questions">FAQ</acronym>.</p>

</div>
<div class="section">

<H2 ID="two">Subject: Contents of this <acronym title="Frequently Asked
Questions">FAQ</acronym>.</H2>

<OL>
  <LI><A HREF="#intro">Introduction</A>
  <LI> Contents of this <acronym title="Frequently Asked Questions">FAQ</acronym>.
  <LI><A HREF="#newsgroup">What is this newsgroup for?</A>
  <LI><A HREF="#keyserver">Why not just use a keyserver?</A>
  <LI><A HREF="#posting">How do I post my key to alt.security.keydist?</A>
  <LI><A HREF="#other">Should I post my key to other newsgroups?</A>
  <LI><A HREF="#software">Further information about specific <acronym title="public key encryption">PKE</acronym> software.</A>

</OL>
</div>
<div class="section" id="newsgroup">

<H2 ID="three">Subject: What is this newsgroup for?</H2>

<P>This is the charter from Jonathan S. Haas's original newgroup message, posted
27 February 1993:

<BLOCKQUOTE cite="news:1993Feb27.212655.15966@zip.eecs.umich.edu"> 
For your newsgroups file:<BR>
alt.security.keydist     Exchange of keys for public key encryption systems<BR>
<br>
This group is for people who use public key encryption systems such as<br>
<acronym title="Pretty Good Privacy">PGP</acronym> or <acronym title="Riordan's Internet Privacy Enhanced Mail">RIPEM</acronym> to have a place to exchange public keys.
</BLOCKQUOTE>

<P>Jonathan's entire control message is archived at <A
HREF="ftp://ftp.uu.net/usenet/control/alt/alt.security.keydist"
>ftp://ftp.uu.net/usenet/control/alt/alt.security.keydist</A>.

</div>
<div class="section" id="keyserver">

<H2 ID="four">Subject: Why not just use a keyserver?</H2>

<P>
Although I'm sure many people have many different reasons for using this
newsgroup, there are two major ones:

<P> First, there are several public key encryption (<acronym>PKE</acronym>)
systems (such as InvisiMail, Puffer, <acronym title="Riordan's Internet
Privacy Enhanced Mail">RIPEM</acronym>, Vouch, and Sifr) that do not have
keyservers networks. A newsgroup can serve as a <span lang="la">de
facto</span> keyserver for users of those systems. 

<P> Second, even for <acronym title="public key encryption">PKE</acronym>
systems with established keyservers (i.e. OpenPGP), alt.security.keydist
provides "another channel of distribution". Many <acronym title="Pretty
Good Privacy">PGP</acronym> users attempt to distribute their public keys
through as many protocols as possible. Such users often have their keys
available in such diverse locations as keyservers (distribution by e-mail
and <acronym title="hypertext transfer protocol">http</acronym>), in .plan
files (distribution by finger), on web pages (distribution by <acronym
title="hypertext transfer protocol">http</acronym>), and in <acronym
title="file transfer protocol">ftp</acronym> archives. <A
HREF="news://alt.security.keydist">alt.security.keydist</A> is another
protocol for redundant key distribution, distribution by netnews.</p>

<P>(This <acronym title="Frequently Asked Questions">FAQ</acronym>'s author
has, at various times, distributed his key by finger, by web, by keyserver,
by newsgroup, by <a href="http://fidonet.fidonet.org/">Fidonet</a> echomail
and by <a href="http://www.compuserve.com/">CompuServe</a> file library.
This <acronym title="Frequently Asked Questions">FAQ</acronym>'s author is
prone to overkill.)</p>

</div>
<div class="section" id="posting">

<H2 Id="five">Subject: How do I post my key to alt.security.keydist?</H2>

<p>Whatever <acronym title="public key encryption">PKE</acronym> software
you're using must be able to extract your public key to a '7-bit', 'flat
ascii', or 'plaintext' file. (Most <acronym title="public key
encryption">PKE</acronym> programs now export keys in text format by
default.) Once you've extracted your key, just start an article to
alt.security.keydist, cut-and-paste the keyfile into your article, and post
it.</p>

<P>Your subject line should state what software you're posting a key
for, and the e-mail address that key is for. I also recommend
redirecting followups to e-mail with a "Followup-To: poster" header,
because alt.security.keydist really isn't a discussion group.</p>

<P>You should repost your public key whenever it changes (i.e., you change
your e-mail address, add a certification, or revoke the key).  Given the
ephemeral nature of netnews articles, periodically reposting unchanged keys
is acceptable.  Users who expect to repost keys often should consider
adding "Expires:" and/or "Supersedes:" headers to their posts.  The
documentation for your newsreading software should explain these
headers.</p>

<P><acronym title="Multipart Internet Mail
Extensions">MIME</acronym>-educated <acronym title="Pretty Good
Privacy">PGP</acronym>-users (and <acronym title="GNU Privacy
Guard">GPG</acronym>-users) may want to use "Content-Type:
application/pgp-keys" for posting public keys. (This will make it easier
for many <acronym title="Pretty Good Privacy">PGP</acronym> users to import
your key, but it may prevent <a href="http://groups.google.com/">Google
Groups</a> from archiving the post containing the key.) See <a
href="http://www.ietf.org/rfc/rfc3156.txt">RFC 3156 at
http://www.ietf.org/rfc/rfc3156.txt</a> for a description of the PGP media
types.</p>

<P>By the way, don't clear-sign the message containing your public key! That
just makes it harder for people to add your key to their keyrings (Think
about it: How do people verify the signature if they don't yet have the key
on their keyring?) and does not verify the integrity of your key.</p>

</div>
<div class="section" id="other">

<H2 ID="six">Subject: Should I post my key to other newsgroups?</H2>

<P>If you mean "Should I post my key to other alt.security.* or
comp.security.* newsgroups?", the answer is a definite "No". Those groups
are discussion and/or announcement groups, and public keys don't count,
unless they're very important keys (such as keys belonging to a timestamp
server or certficate authority).</p>

<P>There are, however, at least 11 other key-distribution newsgroups located in
smaller news hierarchies.  You might want to crosspost your public keys to
one of these newsgroups, or monitor them for new keys:</p>

<P>The newsgroup <A HREF="news:demon.security.keys" hreflang="en-gb"
lang="en-gb">demon.security.keys</A> is part of the internal hierarchy for
<A HREF="http://www.demon.net/" hreflang="en-gb">Demon Internet</A> (an
internet service provider in the United Kingdom), but has much wider
distribution. Recommended for <acronym title="public key
encryption">PKE</acronym>-users in the <acronym title="United
Kingdom">UK</acronym>.</p>

<P>The newsgroups <a href="news:fidonet.pkey_drop">fidonet.pkey_drop</a>
and <a href="news:fido7.lv.pgpkeys" hreflang="ru"
lang="ru">fido7.lv.pgpkeys</a> are (defunct?) gated versions of
(defunct?) Fidonet echomail channels. You cannot post to these groups from
from the netnews side of the gateway.</p>

<P>The newsgroups <a
href="news:aktiv-darkness.pgp-keys" lang="de"
hreflang="de">aktiv-darkness.pgp-keys</a>, <A
HREF="news:city-net.diverses.pgp-keys" lang="de"
hreflang="de">city-net.diverses.pgp-keys</A>, <A
HREF="news:domino.pgp.schluessel" lang="de"
hreflang="de">domino.pgp.schluessel</A>, <A
HREF="news:hothouse.lokal.pgp-keys" lang="de"
hreflang="de">hothouse.lokal.pgp-keys</A>, <A
HREF="news:t-netz.pgp.schluessel" lang="de"
hreflang="de">t-netz.pgp.schluessel</A>, <A
HREF="news://real-net.computer.pgp.public" lang="de"
hreflang="de">real-net.computer.pgp.
public_key</A>, <A HREF="news:waros.pgp.schluessel" lang="de"
hreflang="de">waros.pgp.schluessel</A>, and <A
HREF="news:z-netz.alt.pgp.schluessel" lang="de"
hreflang="de">z-netz.alt.pgp.schluessel</A>, are for distributing <acronym
title="Pretty Good Privacy">PGP</acronym> keys only, and are part of
German-language news hierarchies (<span lang="de">"schluessel"</span> means
"keys"). Many of these groups are defunct and/or <acronym title="internet
service provider">ISP</acronym>-local groups.</p>

</div>
<div class="section" id="software">

<H2 ID="seven">Subject:  Further information about software mentioned in this <acronym title="Frequently Asked
Questions">FAQ</acronym>.</H2>

<p id="GPG"><acronym title="GNU Privacy Guard">GPG</acronym> is
available at <a href="http://www.gnupg.org/">http://www.gnupg.org/</a></p>

<p id="InvisiMail"><a href="http://www.invisimail.com/">InvisiMail RPK</a>
is apparently out of business but the demo version of InvisiMail Lite is
still available at <a
href="http://www.infoweek.ch/library/Internet/IM40lite.exe"
>http://www.infoweek.ch/library/Internet/IM40lite.exe</a></p>

<P id="PGP"><acronym title="Pretty Good Privacy">PGP</acronym> is available
at <a href="http://www.pgp.com/">http://www.pgp.com/</a> and <a
href="http://www.pgp.com/">http://www.pgpi.org/</a></p>

<p>Puffer is available from <a
href="http://www.briggsoft.com/">http://www.briggsoft.com/</a></p>

<P id="RIPEM"><acronym title="Riordan's Internet Privacy Enhanced
Mail">RIPEM</acronym>'s source code is available at <a
href="http://www.funet.fi/pub/crypt/cryptography/rpem/"
>http://www.funet.fi/pub/crypt/cryptography/rpem/</a></p>

<p id="Sifr">Sifr &amp; Vouch are available at 
<a href="http://www.funet.fi/pub/crypt/msdos/bin-only/" 
>http://www.funet.fi/pub/crypt/msdos/bin-only/</a></p>

</div>
</div>

<div id="sidebar">
<div id="ads">
<iframe marginwidth="0" marginheight="0" width="160" height="600"
scrolling="no" frameborder="0"
src="http://rcm.amazon.com/e/cm?t=michaelbausercom&amp;l=st1&amp;search=encryption&amp;mode=books&amp;p=14&amp;o=1&amp;f=ifr">
<MAP NAME="boxmap-p14"><AREA SHAPE="RECT" COORDS="37, 588, 126, 600"
HREF="http://rcm.amazon.com/e/cm/privacy-policy.html?o=1" alt="Shop"><AREA
COORDS="0,0,10000,10000"
HREF="http://www.amazon.com/exec/obidos/redirect-home/michaelbausercom"
alt=" alt "></map><img src="http://rcm-images.amazon.com/images/G/01/rcm/160x600.gif"
width="160" height="600" border="0" usemap="#boxmap-p14" alt="Amazon.com">
</iframe>
</div>
<div id="icons">

<a href="http://www.cdt.org/crypto/"><img src="bin/keyescrowsmaller.gif"
alt="No mandatory key escrow!" height="125" width="150" border="0"
longdesc="longdesc#keyescrowsmaller.gif"></a>

<A HREF="http://www.aclu.org/privacy"><IMG SRC="bin/dataicon.gif"
ALT="[ACLU Defend Your Data Collection]" HEIGHT="60" WIDTH="120" BORDER="0"
longdesc="longdesc#keyescrowsmaller.gif"></a>

<A href="http://www.efc.ca/pages/crypto/golden-key.html"
hreflang="en-ca"><IMG height="54" alt="[EFC Golden Key - Strong Crypto]"
src="bin/efccrypt.gif" width="144" border="0" lang="en-ca"
longdesc="longdesc#efccrypt.gif"></A>

<A href="http://www.privacy.org/ipc/"><IMG height="98" alt="Golden Key
Campaign" src="bin/gk2.gif" width="159" border="0"
longdesc="longdesc#gk2.gif"></A>

<a href="http://vip.hotwired.com/crn/"><img src="bin/cyberrights.gif"
alt="Cyber Rights Now!" height="90" width="95" border="0"
longdesc="longdesc#cyberrights.gif"></a>

</div></div>
<address>http://www.alt-security-keydist.info/FAQ Copyright &copy; 1997-2004 <a
href="mailto:michael@bauser.com">michael&#64;bauser.com</a></address></BODY>
</HTML>

