You can then use your PGP key to sign or encrypt emails or sign your git commits or other stuff you can do with PGP keys. Others who trust this signing service then known that this key really belongs to someone with your name.
Yeah, but who are these others?
I mean I know how PGP key signing is supposed to work. But that all is entirely hypothetical.
It would be meaningful if e.g. there would be a requirement for gov agencies to accept communication with such keys with the same value as written communication. But "some fictional people may care about this signature" is meaningless.
Government agencies are required to accept de-mail, which is a proprietary email-like service. However, rollout has been nonexistent even among government agencies such that you cannot practically use it anywhere, they are a decade behind their rollout plan. The system itself is design-by-committee fugly, insecure and plain weird. You have to get an account with a commercial provider, all of which have closed down by now. PGP/GPG cannot be used with de-mail (except if you copy&paste the ascii-armored ciphertext into the software), and de-mail encryption is intentionally breakable anyways (officially "to scan for viruses").
The eID/ePA "elektronischer Personalausweis" electronic RFID passport which you need to use is another such weird proprietary waste of taxpayer money, accepted nowhere because it doesn't follow any standards and using the RFID function (e.g. as a bank for opening an account) costs tens of thousands per year just for the certificate you need. So nobody uses it and nobody enables the RFID functionality. Therefore the govt got the brilliant idea (among other, far less pleasant ideas such as requiring it for certain payouts) to offer free signatures on GPG/PGP keys using the ePA.
That is rather slim picking considering all other government interactions and especially private business interactions I did where it could’ve been useful but I’m glad I could do all least some stuff online.
Have PGP, have a web of trust with...people you actually trust.
Let's state instead a fictional scenario: you got an email from John Doe, is really from him? Well, if it's signed with a GPG key signed by a government authority probably yes (at least, if it's not him he have successfully steal card&credentials to sign his key or something even more complex). Did you know the small "key-icon" GMail offer in it's WebUI for "trusted messages" from some well-known vendors? Well, with this you can replicate the same with anybody in Germany, trusted not by a private company but by a government authority.
It's still marginal since most would not use such system, but potentially it's a pretty logic idea and a very good news.
This should allow you to actually send legal save communication to the government.
Actual electronic signatures recognized by law are not based on GPG.
Using your eID?
Do you know this or do you assume this?
GPG signatures convey no special legal status above regular email even if the key is signed by a government-owned company that verified your eID.
But let's see how it is currently reading this can become the defacto standard.
And technically it's a good workflow/choice
This would even allow companies to offer this for you because the only interface necessary is the key
I can envision a _lot_ of use cases for having your name publicly recognized by a trusted party.
Signing message contents I understand. But email headers can be faked in various ways.