Re: Tor and keyservers

Jason Harris <[email protected]> Fri, 4 Mar 2005 14:09:07 -0500
Newsgroups gmane.comp.encryption.pgp.keyserver-folk
Message-ID <[email protected]>
On Thu, Mar 03, 2005 at 03:04:02PM +0100, Thomas Sjögren wrote:
> On Thu, Mar 03, 2005 at 08:55:48AM -0500, Jason Harris wrote:

> > That is, does "gpg --keyserver x-hkp://yod73zr3y6wnm2sw.onion --refresh"
> > currently work?
> 
> You need to have 
> keyserver-options honor-http-proxy broken-http-proxy
> in your gpg.conf
> and export http_proxy=http://127.0.0.1:8118/

With gpg 1.4.0 on FreeBSD 4.x, this doesn't work.  It prints:

  ?: yod73zr3y6wnm2sw.onion: Host not found

although I can visit http://yod73zr3y6wnm2sw.onion/ and
http://yod73zr3y6wnm2sw.onion:11371/ in two different browsers.

(In advance,) the resulting /tmp/gpg-.../tempin.txt file has:

  # This is a GnuPG 1.4.0 keyserver communications file
  VERSION 1
  PROGRAM 1.4.0
  SCHEME hkp
  HOST yod73zr3y6wnm2sw.onion
  PATH /
  OPTION include-revoked
  OPTION include-subkeys
  OPTION try-dns-srv
  OPTION broken-http-proxy
  OPTION honor-http-proxy
  COMMAND GET

  0xD39DA0E3

Also, using "--keyserver keyserver.kjsl.com," still with broken-http-proxy
and honor-http-proxy set, GPG connects directly without going through
privoxy.

-- 
Jason Harris           |  NIC:  JH329, PGP:  This _is_ PGP-signed, isn't it?
[email protected] _|_ web:  http://keyserver.kjsl.com/~jharris/
          Got photons?   (TM), (C) 2004

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk
signature.asc (application/pgp-signature, 309 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iJoEARECAFoFAkIoslJTGGh0dHA6Ly9rZXlzZXJ2ZXIua2pzbC5jb206ODAvcGtz
L2xvb2t1cD9vcD1nZXQmc2VhcmNoPTB4RDM5REEwRTMmd2VoYXZleW91bm93PXRy
dWUACgkQSypIl9OdoON6ngCgwZFXxu04ZRKB7FffsHagUB/9scUAoJptxk9wPLha
W2L8XkGFgSGCbPg6
=Dav2
-----END PGP SIGNATURE-----