Re: Keyserver for gpg.conf ?

Jeremy Stanley <[email protected]> Mon, 17 Nov 2025 15:05:01 +0000
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
--CbHkxOfPlO7uEue9
Content-Type: text/plain; charset=us-ascii; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On 2025-11-16 02:57:02 +0000 (+0000), debianmailinglists.hz5zm@simplelogin.=
com wrote:
> Do these other keyring servers leave the key intact? I stopped=20
> using the key servers for my small personal projects and just have=20
> my public key posted on my personal website because one of them (=20
> keys.openpgp.org I think ) lists my public key, but it seems to=20
> have stripped all the identifying information from it so it can't=20
> be searched for by email address and even if you download the copy=20
> they have apps like Kleopatra fail to import it, and when=20
> comparing it to my copy of the public key I manually exported the=20
> contents are MUCH shorter on their copy.
[...]

The main reason for this, as I understand it, is to avoid the=20
vulnerabilities which led to the fall of the SKS keyserver network.=20
In short, the traditional keyserver model of allowing anyone to=20
upload third-party signatures for keys they didn't control led=20
eventually to vandals and other malicious persons uploading unwanted=20
signatures with objectionable content or in volumes which overflowed=20
the ability of clients and servers to deal with them (denial of=20
service on the network and also on specific keys making them=20
irretrievable). They did this in the most severe way possible,=20
essentially filtering out all third-party signatures and even=20
self-signatures and UIDs if the uploader can't prove control of the=20
E-mail addresses associated with them (which implicitly means=20
discarding non-E-mail identities too such as photo images).

Discussions I followed some time ago indicated they were willing to=20
accept updates that enabled a caff-style approval process for=20
third-party signatures at least, but it sounded like the existing=20
team didn't have the resources to develop such a feature and that it=20
would require additional volunteers working on that.
--=20
Jeremy Stanley

--CbHkxOfPlO7uEue9
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQKTBAABCgB9FiEEl65Jb8At7J/DU7LnSPmWEUNJWCkFAmkbOZRfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDk3
QUU0OTZGQzAyREVDOUZDMzUzQjJFNzQ4Rjk5NjExNDM0OTU4MjkACgkQSPmWEUNJ
WCmz6g/8DMqD7GWly4qw2p1mUPfzU+pIxwXxfjY/XtJX/sEzAsLsiiHUN+OFuZa/
vqbD3NX7ICmf1ThEjgQI/EBYPnlEKVI7NnwTR3HFKTHRRg8XPxDMYSX8Y5/Gfb+j
PF6+R5WJ56naO8rSjZQ8T55x/UssQ1lF2tP84ZjVy+EyFbLqvU+/foFDmm8uIUS6
e438b1/XgXchs/iqO916smsRD0XR0LCI4fii8kxZ7cYe8G2gMwCO5NPcUCZrNpci
en9NC8T66i658WNmK+Q6JH0vzVgCd4XzeVMF23FcX2UdDRMnArKaUhW1Mb2zMWQl
o/2vdjl7V7u+1ioRuhi1tq9EMKrSKb1KVmthJdmwNdT3+V6ChTTbQqeijf57OC9k
3l9AsS09rMy+L/cr41HEjyGEDt6MgcomxuEtI7XO8g54XFiLXXA0d5JXBCOVTceg
uQXez8EOit66maxTpu4QGdCo3N/woLDqyIqKuumfxcIoUroNjVI1VjwIp5eTVUaf
44BmChuge7DjcxXcO4age492jhB0BnvispcVgMJTLQ2X6zscR3nUl/zAbG/EEfWa
4lQUmK5xe9b6Wo64Pb0eV9JVQJF1KM0tE34rxBpfbk1cvIsRYtT9tM9abnJLz1Ry
xDfL2RU/BMaahglUhJl03QAxZYK+5Dz62oLnGImSj/xYJavVWw8=
=rdKe
-----END PGP SIGNATURE-----

--CbHkxOfPlO7uEue9--