[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[Debconf-discuss] preventing direct keyserver uploads (was: Please don't upload GPG keys to keyserver when signing them)



also sprach Andreas Tille <andreas@fam-tille.de> [2009.08.06.0915 +0200]:
> IMHO this thread leads directly to a new meta-information on the
> KSP list:
> 
>    Do you prefer direct upload to keyservers?: yes / no

I suggest you patch gpg to honour the keyserver-no-modify preference
on keys and simply refuse to --send-keys if that preference is set
and the private key isn't available.

http://tools.ietf.org/html/rfc4880#section-5.2.3.17
http://www.imc.org/ietf-openpgp/mail-archive/msg34217.html

Even better: get the SKS software to outright refuse such keys
unless the upload is self-signed.

-- 
 .''`.   martin f. krafft <madduck@debconf.org>
: :'  :  DebConf orga team; press officer
`. `'`
  `-  DebConf10: New York, USA: http://debconf10.debconf.org
 
"to every complex problem, there is a solution
 which is short, simple, and wrong."
                                                          -- mencken

Attachment: digital_signature_gpg.asc
Description: Digital signature (see http://martin-krafft.net/gpg/)


Reply to: