[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: PGP use (was Re: uploaded package handling)



-----BEGIN PGP SIGNED MESSAGE-----

A "debian key server" by itself probably isn't that useful -- from a
security perspective anyway; having additional signatures might be
useful, except that you can't revoke a signature in pgp 2.6 (supposed
to be a 3.x feature.)

An easy step would be for one of the web pages to have direct pointers
to the pgp.ai.mit.edu keyserver (perhaps with duplicate pages that
send the links through the other mirror'ed servers in Europe and
elsewhere.) The MIT keyserver recently got about 100 times faster due
to some engineering work done as a thesis project - so it's probably
in better shape than any resources we've got to throw at it :-)

(and of course, MailCrypt will automatically check an mit-style
keyserver for a key it doesn't know about.)


-----BEGIN PGP SIGNATURE-----
Version: 2.6.2
Comment: Processed by Mailcrypt 3.4, an Emacs/PGP interface

iQCVAwUBMWqzfly/7Dlmzom3AQG/cwP+KZzvmGb84Qnq6T6H6o/nrX4hvo7GpSCU
IYRs0AaHEYTlmdBugW9MNedOH+F2BdUc6YKLg6sDXVXdSVSxiQHIcJDg/m1A6wr3
f9CGI4aO58K61yoKuxO0aSvcq100Of2deBQvJpmEIY6XpOt7MAOiSFXY5Dxv+JcY
q0bF2hX1Z0Y=
=zPT9
-----END PGP SIGNATURE-----



Reply to: