Re: Keyserver for gpg.conf ?
Jeremy Stanley <[email protected]> Mon, 17 Nov 2025 15:05:01 +0000
| Newsgroups | gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
--CbHkxOfPlO7uEue9 Content-Type: text/plain; charset=us-ascii; format=flowed Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2025-11-16 02:57:02 +0000 (+0000), debianmailinglists.hz5zm@simplelogin.= com wrote: > Do these other keyring servers leave the key intact? I stopped=20 > using the key servers for my small personal projects and just have=20 > my public key posted on my personal website because one of them (=20 > keys.openpgp.org I think ) lists my public key, but it seems to=20 > have stripped all the identifying information from it so it can't=20 > be searched for by email address and even if you download the copy=20 > they have apps like Kleopatra fail to import it, and when=20 > comparing it to my copy of the public key I manually exported the=20 > contents are MUCH shorter on their copy. [...] The main reason for this, as I understand it, is to avoid the=20 vulnerabilities which led to the fall of the SKS keyserver network.=20 In short, the traditional keyserver model of allowing anyone to=20 upload third-party signatures for keys they didn't control led=20 eventually to vandals and other malicious persons uploading unwanted=20 signatures with objectionable content or in volumes which overflowed=20 the ability of clients and servers to deal with them (denial of=20 service on the network and also on specific keys making them=20 irretrievable). They did this in the most severe way possible,=20 essentially filtering out all third-party signatures and even=20 self-signatures and UIDs if the uploader can't prove control of the=20 E-mail addresses associated with them (which implicitly means=20 discarding non-E-mail identities too such as photo images). Discussions I followed some time ago indicated they were willing to=20 accept updates that enabled a caff-style approval process for=20 third-party signatures at least, but it sounded like the existing=20 team didn't have the resources to develop such a feature and that it=20 would require additional volunteers working on that. --=20 Jeremy Stanley --CbHkxOfPlO7uEue9 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmkbOZRfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3 QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ WCmz6g/8DMqD7GWly4qw2p1mUPfzU+pIxwXxfjY/XtJX/sEzAsLsiiHUN+OFuZa/ vqbD3NX7ICmf1ThEjgQI/EBYPnlEKVI7NnwTR3HFKTHRRg8XPxDMYSX8Y5/Gfb+j PF6+R5WJ56naO8rSjZQ8T55x/UssQ1lF2tP84ZjVy+EyFbLqvU+/foFDmm8uIUS6 e438b1/XgXchs/iqO916smsRD0XR0LCI4fii8kxZ7cYe8G2gMwCO5NPcUCZrNpci en9NC8T66i658WNmK+Q6JH0vzVgCd4XzeVMF23FcX2UdDRMnArKaUhW1Mb2zMWQl o/2vdjl7V7u+1ioRuhi1tq9EMKrSKb1KVmthJdmwNdT3+V6ChTTbQqeijf57OC9k 3l9AsS09rMy+L/cr41HEjyGEDt6MgcomxuEtI7XO8g54XFiLXXA0d5JXBCOVTceg uQXez8EOit66maxTpu4QGdCo3N/woLDqyIqKuumfxcIoUroNjVI1VjwIp5eTVUaf 44BmChuge7DjcxXcO4age492jhB0BnvispcVgMJTLQ2X6zscR3nUl/zAbG/EEfWa 4lQUmK5xe9b6Wo64Pb0eV9JVQJF1KM0tE34rxBpfbk1cvIsRYtT9tM9abnJLz1Ry xDfL2RU/BMaahglUhJl03QAxZYK+5Dz62oLnGImSj/xYJavVWw8= =rdKe -----END PGP SIGNATURE----- --CbHkxOfPlO7uEue9--