Re: [Sks-devel] stripping GD sigs (was: Re: clean sigs)

Jason Harris <[email protected]> Fri, 9 Sep 2005 00:22:00 -0400
Newsgroups gmane.comp.encryption.pgp.keyserver-folk,gmane.comp.gnu.gnupg.users,gmane.comp.encryption.pgp.sks
Message-ID <[email protected]>
--===============0535773332==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="6Nae48J/T25AfBN4"
Content-Disposition: inline


--6Nae48J/T25AfBN4
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Thu, Sep 08, 2005 at 11:23:08PM -0400, David Shaw wrote:
> On Thu, Sep 08, 2005 at 11:10:23PM -0400, Jason Harris wrote:

> > Not at all.  Anyone who wants sigs from the GD should use that
> > keyserver.  They're still available from it, and, remember,
> > expired sigs don't affect the WoT, so what's the point of the
> > well-synchronized keyservers keeping GD sigs?
>=20
> You're not dropping expired signatures.  You're dropping all
> signatures from a particular key - expired or not.  Those signatures
> are part of the web of trust.  The web of trust now has a different
> view from your keyserver than from the rest of the world.

Indeed, all keyservers (except the GD) should drop GD sigs.

> If I ran a keyserver, would it be appropriate for me to drop all
> signatures from your key D39DA0E3 simply because they're available
> somewhere else?

keyserver.pgp.com doesn't synchronize with other keyservers, by design,
which they maintain to be a GoodThing(TM).  Are you currently insinuating
that the GD sigs should spam the well-synchronized keyservers?

> Personal opinions as to the usefulness of signatures should not be a
> factor in what a keyserver stores.  It's a very dangerous path to go
> down: do you also strip signatures from someone "known" to be a bad
> signer?  What's the criteria for inclusion in your keyserver?  Is it
> stated somewhere so users can read it?

Right now, TTBOMK, only the GD is, indeed, ""known" to be a bad signer."

--=20
Jason Harris           |  NIC:  JH329, PGP:  This _is_ PGP-signed, isn't it?
[email protected] _|_ web:  http://keyserver.kjsl.com/~jharris/
          Got photons?   (TM), (C) 2004

--6Nae48J/T25AfBN4
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (FreeBSD)

iJ0EARECAF0FAkMhDehWGGh0dHA6Ly9rZXlzZXJ2ZXIua2pzbC5jb206MTEzNzEv
cGtzL2xvb2t1cD9vcD1nZXQmc2VhcmNoPTB4RDM5REEwRTMmd2VoYXZleW91bm93
PXRydWUACgkQSypIl9OdoOPVWQCgkK3wIgumvwFhm2fbb6edgKb0PfMAoKBF+aiB
H0k8AKUsZq3ClHv8XY0F
=UA+t
-----END PGP SIGNATURE-----

--6Nae48J/T25AfBN4--

--===============0535773332==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
pgp-keyserver-folk mailing list
[email protected]
http://lists.kjsl.com/mailman/listinfo/pgp-keyserver-folk

--===============0535773332==--