* Update AB5FEB886DBB99C2
@ 2024-11-27 15:37 Vincent Mailhol
2024-11-27 16:02 ` Konstantin Ryabitsev
0 siblings, 1 reply; 6+ messages in thread
From: Vincent Mailhol @ 2024-11-27 15:37 UTC (permalink / raw)
To: keys; +Cc: Vincent Mailhol
[-- Attachment #1: Type: text/plain, Size: 728 bytes --]
Hi,
I collected a few more cross signatures. Could you update my public key
with the one attached? Thank you.
Actually, I also wanted to confirm one thing. I uploaded my keys and all
its cross signature on keyserver.ubuntu.com:
https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index
and so, I was expecting those cross signs to be automatically
synchronized during the periodic update. But it did not happen.
So let me ask: what type of data are actually synchronized? Is it only
the sub-keys and the expiration dates? Or is there a way to upload the
cross signatures somewhere to have them automatically synchronized in
kernel/pgpkeys.git during the periodic updates?
Yours sincerely,
Vincent Mailhol
[-- Attachment #2: AB5FEB886DBB99C2.asc --]
[-- Type: text/plain, Size: 5267 bytes --]
-----BEGIN PGP PUBLIC KEY BLOCK-----
mDMEZluomRYJKwYBBAHaRw8BAQdAf+/PnQvy9LCWNSJLbhc+AOUsR2cNVonvxhDk
/KcW7Fu0LFZpbmNlbnQgTWFpbGhvbCA8bWFpbGhvbC52aW5jZW50QHdhbmFkb28u
ZnI+iLIEExYKAFoCGwMFCQp/CJcFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AW
IQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx41XhgYaGtwczovL2tleXMub3BlbnBn
cC5vcmcACgkQq1/riG27mcIYiwEAkgKKBJ+ANKwhTAAvL1XeApQ+2NNNEwFWzipV
AGvTRigA+wUeyB3UQwZrwb7jsQuBXxhk3lL45HF58+y4bQCUCqYGiQIzBBABCgAd
FiEEPZKym/RZuOCGeA/kCwJExA0NQxwFAmcqrpoACgkQCwJExA0NQxzMBg/+KemC
j6xu8qpZlB4GJMJIcq4+/vWElvAqHCUZBRZciMalWbBUVbBMXsp1EpTpvalQREJa
/CPt69XjR8eeW8zPI6z6oq3CWBj8rXXyqUsONyjn6oJAml4JXAJmz1QaDaYkrHH/
ULxmGWMXtpQuaiPJu+N3FljkftPKzzUS5cThuumNFen2nUgohsl+yMJfhXEJDWKF
alaW1XehgoY22qk5x9UsEV8JhUxGAZx3GdILIDD2bJsm0XGw3XIDWBMoFeH7PwUv
6XBlJDFc88wHQFOIgmcaVjV2KZr3eI8GZqVa+553pOYFRXGVycHbFfpjYW1QJLf0
j2hAXnGIEUxZ2gtVgrglApEJ7km8RWR3Ieb2kgk4NNw6zDEwf84aSw6HHH/9bY+X
kQc3r6YJZVKMCfd8Yv3fPtyKF/FxOZSQf8Hllh5KifZMSA28UdbGKgmgcPcw5d54
et5kpD5t03Hvy6FuX2vryNMjVg1aMlC2APA8ULaePY3R+1V6uk37t53UV4LeBUW0
lUUzU1hrb8Gb/H2l8BAJt5upDmkOiwqlXp2wMBjg2H+sTfuIuAZLYfwAPDYcTkqi
OVTuCjcPOaLDMXV4738aB/VmAPczoccff3t5JpXdQ0wMUxaKQ4G5KX26Eagjwe1x
nkRbGZf8ADKSlZUcedavXB7/TL5c+7gR9c5TXWCJAjMEEAEKAB0WIQRe2aSPxUwK
ItHQgEzrwmzbWlbecwUCZykH/QAKCRDrwmzbWlbec2aHD/0fk1F4ai6Xh8O3nSzd
oM6KmBtXfcj7/q27/iICpOjqoTxK7vc2+/C4Iwc7Xdv+Po4cia4DgmawhhwvuUdf
w+WXBdzefZvH0/GEQOLNN0ood2BjHjfEnSCz+anc5fIqFYbwogSGTeK9feKthgzf
2yrqz40FXL0inBoppBgJY6pkFnaZ0y1TS05rje2aj8Z4EeX6L4gLLNkJBVvX5UkW
e5EuH4YkBToGveNea2CABLHx85MQq2kQVeeeqEi6ZH2h87D+OTvgApF+oxKNXN6B
9TGtGSQV0nM0/V+RWBrpV4KdRHmh4Axit6BY6KUTfEFtjQ5CZcdt6kx2/tRcJVYI
B78rnXkx2DD9COcxcn6G+P7H1ahwdqLV2m1Fnr32Hmu1Wd94MS8Y9OxBHBASEbNg
2+ZgvJ2pk5quQgfdR/6OouPdo1X1rzBhRc4xY4X+2zaV27ls/sXMYDxdOVgQQXKW
vcbVyd26qf1TwHw7T25h5H1fWf/WZnRZr9wQ9fv8/+HPftvLudtSgpBse0IqYHaj
sAgPE4hmN1olCPWxnSCufwzu4mYMDfgd3lPHu++WnZfdodo96o5tOkK7sE561FFw
7pv+vONB4vSj3LPKopr+hNM3OcfyAeRFIjFUXm3dg0UosjquPAsYqjSIs19cR1yR
4M9CPnOyI9IYBe1ZG4xO4UJbLIkCMwQQAQgAHRYhBFDr7Ughai8WP+6cd43ONVYw
IuV6BQJnK9poAAoJEI3ONVYwIuV6WkkQAJh8KlfnJkJzPTLI5vYxze4HQnekUUtw
C2RtdzPrqm4KKTNr30CmumOzCIJpQl2rlLGsLDhR4VFBsXeOWG1IvfT1SFz01L8h
lSDAOZ+m4z5NYW5IX5o2QNJFGpCXXMHHnGwfbqmVkCYLAHryHQa8OOKg02rkwXE5
X9ms4/Nfo1GYyOOJCYf8urZgerIEaj661cDTbqqBC+qu0OqBkauGfO0vuF6ejLhV
BJPA/BTuPE8f4I+rdy1C1h3zI5pw7gggR/VXMt4UB5801FBaOOMImNTOQUKfzcxm
1ZL5a7HO1bOI32lueFuuyHLv2B/tN48o9RTQObftaYF/KPbKO/ZfoMDp142k3LHd
s1OSKekdwG1vIG80w/u32KrtmPVIe+eJdv1iVS8drjrI7Tdayxf1YLZvbh0SUdQk
/TpYZpjLX/Rzt8iCASK0u/P3KA4U/5VLzjH85dKjxzGnUnOhkxGzW0pr4sHCinsS
aJd+d8h8gFU7nOYSxrtc1OKQkNhVI1scUnKk8I+r/03NMHjAx0W3K9PsnEFLBE5u
MuNSBkMYz7AkKelrirDd0Tq1AFzI1h41tYSHSKBdbtwowgWPeaV/hYXeFQe/fJCa
A8CVPZEMWs5OySISHIptkh+xxsZkrCHNJGqToBlQxaT61T5SqKYFQyvCOCoOqhhX
6FDOmnYQ+G+XiQIzBBABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmcwVIsA
CgkQONu9yGCSaT7Ctw//d9EjpTm+kktdabxuLihGk0wIGaSpFYtl3f77Sw9nQ5xy
0a7E4Un3gl/C9hcFtOzkP8Cv9j5PObnGonjR/zRbBQgC7qvrKKhMQu9/k6ZrQgPg
E87iMvG4Y1c/vwQEAOlOcaOEAnq759/HPmlcri6B3wsoxjMCHSfI62LJj1xgRQ73
kepbM5EqH0f8GRCrL8WXsVfGp5ZBjR/lx2WZgUtIMnOdHJGk1ER/MRb7yGh2YmTo
nknAmzhxsK461I5GUXyykL1cxw0KYQPT4+Daxlu2pDswrwTMRnfLTE04E3BCHPmC
mbL3lE30iormEDzEPi/ONUAFFT4hnl6zfvrI3/A5uLX8sQ++7u44vv27qKTEb71f
JrkGJChlv1CBS+JqHh/BTENOEZcX8RbhbP+s67EjTEcRjw04Ztkz0+sFURvdAjb9
b3mZV34apz5Se5Y0yvfVLj7qk1d9LmtH8asbJfLV393RS2+TtUmdXEMszu84Fg5r
HJVnNbcSRC8UERpKtGkUGkOM3vSdhK10qZdnMrRqbnC+U2uHMccrWTaTnXSSGWue
e0BW0CigxnGusyQ36BSb1A04ww+sMllPs3IVXgrnD0iQGHVV9lr+vZkevlFkhJ4N
yIMAOdJBQfSCTa+NIQBseneiSbEBsle6pQNwg9HtxcpiB1Cbb/JUtA08KUFfML+J
ATMEEAEKAB0WIQQhB1r6r/K+DGCfEVtzWqL0YTbZVgUCZzIdwwAKCRBzWqL0YTbZ
ViMhB/95kn48R8U+Ahj6bVHZcPGaw/+7iDdQnb+/s+F5+jCDVmtQPZbWmuLzTAP4
45z241O2E4ooRgqTEJCA7J8YRC36rCuW4ZXw5Srgf/Z4eyu2Ga3m/C9Qe80TdylG
6SlXIYJPC/6vElda3+WMrjdiM97+y4HkupCdjqwTnxXECRlAbwMUBICCt/8Riu5e
EcAqxSc3+Z4pzC/aQfWrTxnObvWNYXhCrpBDf8eNEc0Agta30p/3b2bfV9oRME+p
R9KYf2rXexw27YEOap7XzIHZv4UzF0oQlluKUwt38wVQoxcUr/ndPR1vfhm7ee97
q7XbsGA22/kcb8Birf7o9ryYDsT3iQEzBBABCAAdFiEE1WBuc8i0YnG+rZrfgUrk
fCFIVNYFAmcsxDwACgkQgUrkfCFIVNaPWggAud85ZlGcsCycnBMr8GUO6LADxzq8
8ifnaR3JWMBaZoDhXnXNTw6UNQZAaYNbY6Rh0vaSnFCG7pYvYYfcQWbjkvX8qCbC
h410nXZiLhBn5A+MiZwtcgk8RRA38iS18igmBqoCVplmLI/PEYMt8QcQ0s6y+Q/T
RB+DiapshtUS5WPv/vMOUIvjdxws1lKHmyPsySGkDn/kkqIZLV7AaQBJ/JB3Yk54
HkyeAPyrOk0QsLUOdkudKZbHXzerMADyrol5ERa3ME1BnK3o3DHh/9lrpIMH2o98
RrFcygA8lliUE6mkN0Yx22o8j7w101RMxQRiLyjRrtf7nRixZ5XriRyb+bgzBGce
MuEWCSsGAQQB2kcPAQEHQB2i2kHWm26u0qHFeMCNRCbqVTLiRKIMKbXDNkY7/3C1
iPUEGBYKACYWIQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx4y4QIbAgUJA8JnAACB
CRCrX+uIbbuZwnYgBBkWCgAdFiEEpncJCyCIcUtWwv050WQ+QNd/fbMFAmceMuEA
CgkQ0WQ+QNd/fbOEFQD/ZaAI+8HbY27teJ7OINpoX3xYBZBo0RgGplyuGsFEVlcB
AIssq3J4v4pOQG6B0PP/ayjCTZ1hp9bdpaHynnaWoQ0HorkA+gKMyo+MlHuFGP6R
heHBUjktfvu1Ko4VTC2AAIlhdcM+AP4ucmvm1J5vmSbjTFsloIfFgC6QUYP6u0Vz
4an8Ne8RD7g4BGceMvMSCisGAQQBl1UBBQEBB0Ca22Gc7tCRucPIMROhLUHui5sS
jKj+hMkd97APgUfaSwMBCAeIfgQYFgoAJhYhBO2PcAV05n8g5XTo4qtf64htu5nC
BQJnHjLzAhsMBQkDwmcAAAoJEKtf64htu5nCVO0BAPi5qRYX0NWoo/y/Fc7GcK/0
uOBws3M+fo5MZ1VUOS2eAQDTgqWBGPgmK5XeV2bzPIdhJ7TZ88Rx7oY3wzkNzAJB
CrgzBGceRW4WCSsGAQQB2kcPAQEHQEj9HSaebUdimo77xdWjsdVZrMYfCY0GkKaJ
y0QINxJfiH4EGBYKACYWIQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx5FbgIbIAUJ
A8JnAAAKCRCrX+uIbbuZwt4GAP9xXdBwLLNUox3phQMU8rM4GrUFWDovNoIoN1lp
KUzflAEAnNnWVMPQrLXc4Y4RSVVPBWQkFxXJXtpZcC5hKIMiOwU=
=lpJ8
-----END PGP PUBLIC KEY BLOCK-----
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2
2024-11-27 15:37 Update AB5FEB886DBB99C2 Vincent Mailhol
@ 2024-11-27 16:02 ` Konstantin Ryabitsev
2024-11-28 5:34 ` Vincent Mailhol
2025-02-10 12:43 ` Uwe Kleine-König
0 siblings, 2 replies; 6+ messages in thread
From: Konstantin Ryabitsev @ 2024-11-27 16:02 UTC (permalink / raw)
To: Vincent Mailhol; +Cc: keys
On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote:
> Hi,
>
> I collected a few more cross signatures. Could you update my public key
> with the one attached? Thank you.
Updated, thanks.
> Actually, I also wanted to confirm one thing. I uploaded my keys and all
> its cross signature on keyserver.ubuntu.com:
>
> https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index
>
> and so, I was expecting those cross signs to be automatically
> synchronized during the periodic update. But it did not happen.
Indeed, looks like they don't give us the third-party signature data when we
ask for key updates:
$ gpg --list-sigs AB5FEB886DBB99C2
pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31]
ED8F700574E67F20E574E8E2AB5FEB886DBB99C2
uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr>
sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature]
sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org>
sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org>
[...]
$ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2
gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed
gpg: Total number processed: 1
gpg: unchanged: 1
I only get your latest signatures when I import what you sent in:
$ gpg --import keys/AB5FEB886DBB99C2.asc
gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures
gpg: Total number processed: 1
gpg: new signatures: 3
This is normal, though -- very few keyservers still provide third-party
signature data after the attacks on that functionality a few years ago.
> So let me ask: what type of data are actually synchronized? Is it only
> the sub-keys and the expiration dates? Or is there a way to upload the
> cross signatures somewhere to have them automatically synchronized in
> kernel/pgpkeys.git during the periodic updates?
The keyservers can really only be relied for publishing things like:
- new subkeys
- new uids
- updated expiry dates
For third-party signature data it's best to send an export to this list.
-K
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2
2024-11-27 16:02 ` Konstantin Ryabitsev
@ 2024-11-28 5:34 ` Vincent Mailhol
2025-02-10 12:43 ` Uwe Kleine-König
1 sibling, 0 replies; 6+ messages in thread
From: Vincent Mailhol @ 2024-11-28 5:34 UTC (permalink / raw)
To: Konstantin Ryabitsev; +Cc: keys
On Thu. 28 Nov. 2024 at 01:02, Konstantin Ryabitsev
<konstantin@linuxfoundation.org> wrote:
> On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote:
> > Hi,
> >
> > I collected a few more cross signatures. Could you update my public key
> > with the one attached? Thank you.
>
> Updated, thanks.
Great. I am all set now.
> > Actually, I also wanted to confirm one thing. I uploaded my keys and all
> > its cross signature on keyserver.ubuntu.com:
> >
> > https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index
> >
> > and so, I was expecting those cross signs to be automatically
> > synchronized during the periodic update. But it did not happen.
>
> Indeed, looks like they don't give us the third-party signature data when we
> ask for key updates:
>
> $ gpg --list-sigs AB5FEB886DBB99C2
> pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31]
> ED8F700574E67F20E574E8E2AB5FEB886DBB99C2
> uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr>
> sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature]
> sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org>
> sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org>
> [...]
>
> $ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2
> gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed
> gpg: Total number processed: 1
> gpg: unchanged: 1
>
> I only get your latest signatures when I import what you sent in:
>
> $ gpg --import keys/AB5FEB886DBB99C2.asc
> gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures
> gpg: Total number processed: 1
> gpg: new signatures: 3
>
> This is normal, though -- very few keyservers still provide third-party
> signature data after the attacks on that functionality a few years ago.
The reality is a bit more nuanced. If I add the --verbose option, I get:
$ gpg --verbose --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2
gpg: data source: http://185.125.188.26:11371
gpg: armor header: Comment: Hostname:
gpg: armor header: Version: Hockeypuck 2.2
gpg: key AB5FEB886DBB99C2: number of dropped non-self-signatures: 6
gpg: pub ed25519/AB5FEB886DBB99C2 2024-06-01 Vincent Mailhol
<mailhol.vincent@wanadoo.fr>
gpg: key AB5FEB886DBB99C2: "Vincent Mailhol
<mailhol.vincent@wanadoo.fr>" not changed
gpg: Total number processed: 1
gpg: unchanged: 1
So, the client received six non-self-signatures, but decided to
drop them. Which is consistent with what the documentation has
to say:
The default list of options is: "*self-sigs-only*,
import-clean, repair-keys, repair-pks-subkey-bug,
export-attributes".
Link: https://www.gnupg.org/documentation/manuals/gnupg/GPG-Configuration-Options.html
It is true that many servers do not provide third party signatures
anymore, but keyserver.ubuntu.com still does. The attack you are
referring to is, I guess, the third party signature spamming in which
the attacker would upload thousands of dummy cross signatures to cause
a denial of service.
But this attack does not apply to kernel/pgpkeys.git because we
operate in a closed circle. This makes it easy to filter out any third
party signatures which originate from someone which is not part of the
kernel network of trust. This is easily controlled by passing the
--keyserver-options no-self-sigs-only and --keyserver-options
import-clean options. For example, if doing think from my old key:
$ gpg --keyserver keyserver.ubuntu.com --keyserver-options
no-self-sigs-only --keyserver-options import-clean --recv-key
AB5FEB886DBB99C2
gpg: key AB5FEB886DBB99C2: "Vincent Mailhol
<mailhol.vincent@wanadoo.fr>" 3 new signatures
gpg: marginals needed: 3 completes needed: 1 trust model: pgp
gpg: depth: 0 valid: 1 signed: 0 trust: 0-, 0q, 0n, 0m, 0f, 1u
gpg: next trustdb check due at 2026-11-06
gpg: Total number processed: 1
gpg: new signatures: 3
The signatures which do not match a valid identity are silently
removed. --verbose is needed to get the message, e.g.:
gpg: removing signature from key 735AA2F46136D956 on user ID
"Vincent Mailhol <mailhol.vincent@wanadoo.fr>": key unavailable
> > So let me ask: what type of data are actually synchronized? Is it only
> > the sub-keys and the expiration dates? Or is there a way to upload the
> > cross signatures somewhere to have them automatically synchronized in
> > kernel/pgpkeys.git during the periodic updates?
>
> The keyservers can really only be relied for publishing things like:
>
> - new subkeys
> - new uids
> - updated expiry dates
>
> For third-party signature data it's best to send an export to this list.
Please note that I have no issue with this approach. I just think that
downloading the third party signatures as part of the periodic update
is better because:
1. it is less work for you
2. I do not see how an attacker would be able to abuse this
But I do not mind manually submitting changes. Whatever approach is
used, I would like to suggest updating the documentation to clearly
specify what has to be sent manually and what will be automatically
synchronized.
Yours sincerely,
Vincent Mailhol
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2
2024-11-27 16:02 ` Konstantin Ryabitsev
2024-11-28 5:34 ` Vincent Mailhol
@ 2025-02-10 12:43 ` Uwe Kleine-König
2025-02-10 16:22 ` Konstantin Ryabitsev
1 sibling, 1 reply; 6+ messages in thread
From: Uwe Kleine-König @ 2025-02-10 12:43 UTC (permalink / raw)
To: Konstantin Ryabitsev; +Cc: Vincent Mailhol, keys
[-- Attachment #1: Type: text/plain, Size: 2768 bytes --]
Hello Konstantin,
On Wed, Nov 27, 2024 at 11:02:10AM -0500, Konstantin Ryabitsev wrote:
> On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote:
> > Hi,
> >
> > I collected a few more cross signatures. Could you update my public key
> > with the one attached? Thank you.
>
> Updated, thanks.
>
> > Actually, I also wanted to confirm one thing. I uploaded my keys and all
> > its cross signature on keyserver.ubuntu.com:
> >
> > https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index
> >
> > and so, I was expecting those cross signs to be automatically
> > synchronized during the periodic update. But it did not happen.
>
> Indeed, looks like they don't give us the third-party signature data when we
> ask for key updates:
>
> $ gpg --list-sigs AB5FEB886DBB99C2
> pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31]
> ED8F700574E67F20E574E8E2AB5FEB886DBB99C2
> uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr>
> sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature]
> sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org>
> sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org>
> [...]
>
> $ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2
> gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed
> gpg: Total number processed: 1
> gpg: unchanged: 1
>
> I only get your latest signatures when I import what you sent in:
>
> $ gpg --import keys/AB5FEB886DBB99C2.asc
> gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures
> gpg: Total number processed: 1
> gpg: new signatures: 3
>
> This is normal, though -- very few keyservers still provide third-party
> signature data after the attacks on that functionality a few years ago.
>
> > So let me ask: what type of data are actually synchronized? Is it only
> > the sub-keys and the expiration dates? Or is there a way to upload the
> > cross signatures somewhere to have them automatically synchronized in
> > kernel/pgpkeys.git during the periodic updates?
>
> The keyservers can really only be relied for publishing things like:
>
> - new subkeys
> - new uids
> - updated expiry dates
>
> For third-party signature data it's best to send an export to this list.
Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just
gpg doesn't import them by default.
If you really want all that stuff, use:
gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com
Best regards
Uwe
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2
2025-02-10 12:43 ` Uwe Kleine-König
@ 2025-02-10 16:22 ` Konstantin Ryabitsev
2025-02-10 17:04 ` Uwe Kleine-König
0 siblings, 1 reply; 6+ messages in thread
From: Konstantin Ryabitsev @ 2025-02-10 16:22 UTC (permalink / raw)
To: Uwe Kleine-König; +Cc: Vincent Mailhol, keys
On Mon, Feb 10, 2025 at 01:43:41PM +0100, Uwe Kleine-König wrote:
> > > So let me ask: what type of data are actually synchronized? Is it only
> > > the sub-keys and the expiration dates? Or is there a way to upload the
> > > cross signatures somewhere to have them automatically synchronized in
> > > kernel/pgpkeys.git during the periodic updates?
> >
> > The keyservers can really only be relied for publishing things like:
> >
> > - new subkeys
> > - new uids
> > - updated expiry dates
> >
> > For third-party signature data it's best to send an export to this list.
>
> Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just
> gpg doesn't import them by default.
>
> If you really want all that stuff, use:
>
> gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com
Thank you for the hint! I didn't know that was needed.
However, we'll still probably only use keyservers for key updates, since if a
key is in our keyring, that means we already have sufficient signatures and we
just want updates to things like uids, subkeys and expiration dates.
-K
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2
2025-02-10 16:22 ` Konstantin Ryabitsev
@ 2025-02-10 17:04 ` Uwe Kleine-König
0 siblings, 0 replies; 6+ messages in thread
From: Uwe Kleine-König @ 2025-02-10 17:04 UTC (permalink / raw)
To: Konstantin Ryabitsev; +Cc: Vincent Mailhol, keys
[-- Attachment #1: Type: text/plain, Size: 1587 bytes --]
Hello Konstantin,
On Mon, Feb 10, 2025 at 11:22:36AM -0500, Konstantin Ryabitsev wrote:
> On Mon, Feb 10, 2025 at 01:43:41PM +0100, Uwe Kleine-König wrote:
> > > > So let me ask: what type of data are actually synchronized? Is it only
> > > > the sub-keys and the expiration dates? Or is there a way to upload the
> > > > cross signatures somewhere to have them automatically synchronized in
> > > > kernel/pgpkeys.git during the periodic updates?
> > >
> > > The keyservers can really only be relied for publishing things like:
> > >
> > > - new subkeys
> > > - new uids
> > > - updated expiry dates
> > >
> > > For third-party signature data it's best to send an export to this list.
> >
> > Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just
> > gpg doesn't import them by default.
> >
> > If you really want all that stuff, use:
> >
> > gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com
>
> Thank you for the hint! I didn't know that was needed.
>
> However, we'll still probably only use keyservers for key updates, since if a
> key is in our keyring, that means we already have sufficient signatures and we
> just want updates to things like uids, subkeys and expiration dates.
That's true until you start to consider removing keys (because they are
expired or their crypto is week) or you also take into account
revokations. Also new signatures are good because a key that is today at
distance 3 from Linus might get nearer and so qualify to sign new keys.
Best regards
Uwe
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2025-02-10 17:04 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-11-27 15:37 Update AB5FEB886DBB99C2 Vincent Mailhol
2024-11-27 16:02 ` Konstantin Ryabitsev
2024-11-28 5:34 ` Vincent Mailhol
2025-02-10 12:43 ` Uwe Kleine-König
2025-02-10 16:22 ` Konstantin Ryabitsev
2025-02-10 17:04 ` Uwe Kleine-König
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.