OpenPGP

Public key for ant@shorenet.co.uk

Use this key to send encrypted mail, or to check a signature that claims to come from us. The fingerprint below is the only part worth trusting: verify it against a second channel before you rely on the key.

Fingerprint

4AFD 597C 2E05 2847 02A0 EE8B 8D60 11A1 587A A31F

The same 40 characters unspaced, for pasting: 4AFD597C2E05284702A0EE8B8D6011A1587AA31F

A fingerprint read off this page is only as trustworthy as this page. If the key matters to you, confirm those characters over a channel that does not run through this website — in person, by phone, or against a copy you already hold.

Key details

Fetching the key

This domain publishes the key through Web Key Directory, so most mail clients will find it on their own. No keyserver is involved, and nothing needs to be uploaded anywhere: the key is served from this domain, by us.

To fetch it by hand, and print the fingerprint so you can compare it with the one above:

gpg --locate-external-keys ant@shorenet.co.uk

(--locate-external-keys rather than --locate-keys: the latter answers from your local keyring first, so it can succeed without ever fetching anything, which defeats the point of checking.)

Or download the key directly: ant-at-shorenet.asc (ASCII-armoured). Import it with gpg --import ant-at-shorenet.asc, then check the fingerprint with gpg --fingerprint ant@shorenet.co.uk.

What this key does and does not establish

This key signs and encrypts mail. It is unrelated to the signing chain that seals Shorenet evidence bundles — those are signed by device and Pilot keys under a separate hierarchy, and are checked by the verifier, not by OpenPGP. A message signed with this key establishes that the message came from the holder of this key; it says nothing about the integrity of any capture.