* Update AB5FEB886DBB99C2 @ 2024-11-27 15:37 Vincent Mailhol 2024-11-27 16:02 ` Konstantin Ryabitsev 0 siblings, 1 reply; 6+ messages in thread From: Vincent Mailhol @ 2024-11-27 15:37 UTC (permalink / raw) To: keys; +Cc: Vincent Mailhol [-- Attachment #1: Type: text/plain, Size: 728 bytes --] Hi, I collected a few more cross signatures. Could you update my public key with the one attached? Thank you. Actually, I also wanted to confirm one thing. I uploaded my keys and all its cross signature on keyserver.ubuntu.com: https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index and so, I was expecting those cross signs to be automatically synchronized during the periodic update. But it did not happen. So let me ask: what type of data are actually synchronized? Is it only the sub-keys and the expiration dates? Or is there a way to upload the cross signatures somewhere to have them automatically synchronized in kernel/pgpkeys.git during the periodic updates? Yours sincerely, Vincent Mailhol [-- Attachment #2: AB5FEB886DBB99C2.asc --] [-- Type: text/plain, Size: 5267 bytes --] -----BEGIN PGP PUBLIC KEY BLOCK----- mDMEZluomRYJKwYBBAHaRw8BAQdAf+/PnQvy9LCWNSJLbhc+AOUsR2cNVonvxhDk /KcW7Fu0LFZpbmNlbnQgTWFpbGhvbCA8bWFpbGhvbC52aW5jZW50QHdhbmFkb28u ZnI+iLIEExYKAFoCGwMFCQp/CJcFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AW IQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx41XhgYaGtwczovL2tleXMub3BlbnBn cC5vcmcACgkQq1/riG27mcIYiwEAkgKKBJ+ANKwhTAAvL1XeApQ+2NNNEwFWzipV AGvTRigA+wUeyB3UQwZrwb7jsQuBXxhk3lL45HF58+y4bQCUCqYGiQIzBBABCgAd FiEEPZKym/RZuOCGeA/kCwJExA0NQxwFAmcqrpoACgkQCwJExA0NQxzMBg/+KemC j6xu8qpZlB4GJMJIcq4+/vWElvAqHCUZBRZciMalWbBUVbBMXsp1EpTpvalQREJa /CPt69XjR8eeW8zPI6z6oq3CWBj8rXXyqUsONyjn6oJAml4JXAJmz1QaDaYkrHH/ ULxmGWMXtpQuaiPJu+N3FljkftPKzzUS5cThuumNFen2nUgohsl+yMJfhXEJDWKF alaW1XehgoY22qk5x9UsEV8JhUxGAZx3GdILIDD2bJsm0XGw3XIDWBMoFeH7PwUv 6XBlJDFc88wHQFOIgmcaVjV2KZr3eI8GZqVa+553pOYFRXGVycHbFfpjYW1QJLf0 j2hAXnGIEUxZ2gtVgrglApEJ7km8RWR3Ieb2kgk4NNw6zDEwf84aSw6HHH/9bY+X kQc3r6YJZVKMCfd8Yv3fPtyKF/FxOZSQf8Hllh5KifZMSA28UdbGKgmgcPcw5d54 et5kpD5t03Hvy6FuX2vryNMjVg1aMlC2APA8ULaePY3R+1V6uk37t53UV4LeBUW0 lUUzU1hrb8Gb/H2l8BAJt5upDmkOiwqlXp2wMBjg2H+sTfuIuAZLYfwAPDYcTkqi OVTuCjcPOaLDMXV4738aB/VmAPczoccff3t5JpXdQ0wMUxaKQ4G5KX26Eagjwe1x nkRbGZf8ADKSlZUcedavXB7/TL5c+7gR9c5TXWCJAjMEEAEKAB0WIQRe2aSPxUwK ItHQgEzrwmzbWlbecwUCZykH/QAKCRDrwmzbWlbec2aHD/0fk1F4ai6Xh8O3nSzd oM6KmBtXfcj7/q27/iICpOjqoTxK7vc2+/C4Iwc7Xdv+Po4cia4DgmawhhwvuUdf w+WXBdzefZvH0/GEQOLNN0ood2BjHjfEnSCz+anc5fIqFYbwogSGTeK9feKthgzf 2yrqz40FXL0inBoppBgJY6pkFnaZ0y1TS05rje2aj8Z4EeX6L4gLLNkJBVvX5UkW e5EuH4YkBToGveNea2CABLHx85MQq2kQVeeeqEi6ZH2h87D+OTvgApF+oxKNXN6B 9TGtGSQV0nM0/V+RWBrpV4KdRHmh4Axit6BY6KUTfEFtjQ5CZcdt6kx2/tRcJVYI B78rnXkx2DD9COcxcn6G+P7H1ahwdqLV2m1Fnr32Hmu1Wd94MS8Y9OxBHBASEbNg 2+ZgvJ2pk5quQgfdR/6OouPdo1X1rzBhRc4xY4X+2zaV27ls/sXMYDxdOVgQQXKW vcbVyd26qf1TwHw7T25h5H1fWf/WZnRZr9wQ9fv8/+HPftvLudtSgpBse0IqYHaj sAgPE4hmN1olCPWxnSCufwzu4mYMDfgd3lPHu++WnZfdodo96o5tOkK7sE561FFw 7pv+vONB4vSj3LPKopr+hNM3OcfyAeRFIjFUXm3dg0UosjquPAsYqjSIs19cR1yR 4M9CPnOyI9IYBe1ZG4xO4UJbLIkCMwQQAQgAHRYhBFDr7Ughai8WP+6cd43ONVYw IuV6BQJnK9poAAoJEI3ONVYwIuV6WkkQAJh8KlfnJkJzPTLI5vYxze4HQnekUUtw C2RtdzPrqm4KKTNr30CmumOzCIJpQl2rlLGsLDhR4VFBsXeOWG1IvfT1SFz01L8h lSDAOZ+m4z5NYW5IX5o2QNJFGpCXXMHHnGwfbqmVkCYLAHryHQa8OOKg02rkwXE5 X9ms4/Nfo1GYyOOJCYf8urZgerIEaj661cDTbqqBC+qu0OqBkauGfO0vuF6ejLhV BJPA/BTuPE8f4I+rdy1C1h3zI5pw7gggR/VXMt4UB5801FBaOOMImNTOQUKfzcxm 1ZL5a7HO1bOI32lueFuuyHLv2B/tN48o9RTQObftaYF/KPbKO/ZfoMDp142k3LHd s1OSKekdwG1vIG80w/u32KrtmPVIe+eJdv1iVS8drjrI7Tdayxf1YLZvbh0SUdQk /TpYZpjLX/Rzt8iCASK0u/P3KA4U/5VLzjH85dKjxzGnUnOhkxGzW0pr4sHCinsS aJd+d8h8gFU7nOYSxrtc1OKQkNhVI1scUnKk8I+r/03NMHjAx0W3K9PsnEFLBE5u MuNSBkMYz7AkKelrirDd0Tq1AFzI1h41tYSHSKBdbtwowgWPeaV/hYXeFQe/fJCa A8CVPZEMWs5OySISHIptkh+xxsZkrCHNJGqToBlQxaT61T5SqKYFQyvCOCoOqhhX 6FDOmnYQ+G+XiQIzBBABCAAdFiEEZH8oZUiU471FcZm+ONu9yGCSaT4FAmcwVIsA CgkQONu9yGCSaT7Ctw//d9EjpTm+kktdabxuLihGk0wIGaSpFYtl3f77Sw9nQ5xy 0a7E4Un3gl/C9hcFtOzkP8Cv9j5PObnGonjR/zRbBQgC7qvrKKhMQu9/k6ZrQgPg E87iMvG4Y1c/vwQEAOlOcaOEAnq759/HPmlcri6B3wsoxjMCHSfI62LJj1xgRQ73 kepbM5EqH0f8GRCrL8WXsVfGp5ZBjR/lx2WZgUtIMnOdHJGk1ER/MRb7yGh2YmTo nknAmzhxsK461I5GUXyykL1cxw0KYQPT4+Daxlu2pDswrwTMRnfLTE04E3BCHPmC mbL3lE30iormEDzEPi/ONUAFFT4hnl6zfvrI3/A5uLX8sQ++7u44vv27qKTEb71f JrkGJChlv1CBS+JqHh/BTENOEZcX8RbhbP+s67EjTEcRjw04Ztkz0+sFURvdAjb9 b3mZV34apz5Se5Y0yvfVLj7qk1d9LmtH8asbJfLV393RS2+TtUmdXEMszu84Fg5r HJVnNbcSRC8UERpKtGkUGkOM3vSdhK10qZdnMrRqbnC+U2uHMccrWTaTnXSSGWue e0BW0CigxnGusyQ36BSb1A04ww+sMllPs3IVXgrnD0iQGHVV9lr+vZkevlFkhJ4N yIMAOdJBQfSCTa+NIQBseneiSbEBsle6pQNwg9HtxcpiB1Cbb/JUtA08KUFfML+J ATMEEAEKAB0WIQQhB1r6r/K+DGCfEVtzWqL0YTbZVgUCZzIdwwAKCRBzWqL0YTbZ ViMhB/95kn48R8U+Ahj6bVHZcPGaw/+7iDdQnb+/s+F5+jCDVmtQPZbWmuLzTAP4 45z241O2E4ooRgqTEJCA7J8YRC36rCuW4ZXw5Srgf/Z4eyu2Ga3m/C9Qe80TdylG 6SlXIYJPC/6vElda3+WMrjdiM97+y4HkupCdjqwTnxXECRlAbwMUBICCt/8Riu5e EcAqxSc3+Z4pzC/aQfWrTxnObvWNYXhCrpBDf8eNEc0Agta30p/3b2bfV9oRME+p R9KYf2rXexw27YEOap7XzIHZv4UzF0oQlluKUwt38wVQoxcUr/ndPR1vfhm7ee97 q7XbsGA22/kcb8Birf7o9ryYDsT3iQEzBBABCAAdFiEE1WBuc8i0YnG+rZrfgUrk fCFIVNYFAmcsxDwACgkQgUrkfCFIVNaPWggAud85ZlGcsCycnBMr8GUO6LADxzq8 8ifnaR3JWMBaZoDhXnXNTw6UNQZAaYNbY6Rh0vaSnFCG7pYvYYfcQWbjkvX8qCbC h410nXZiLhBn5A+MiZwtcgk8RRA38iS18igmBqoCVplmLI/PEYMt8QcQ0s6y+Q/T RB+DiapshtUS5WPv/vMOUIvjdxws1lKHmyPsySGkDn/kkqIZLV7AaQBJ/JB3Yk54 HkyeAPyrOk0QsLUOdkudKZbHXzerMADyrol5ERa3ME1BnK3o3DHh/9lrpIMH2o98 RrFcygA8lliUE6mkN0Yx22o8j7w101RMxQRiLyjRrtf7nRixZ5XriRyb+bgzBGce MuEWCSsGAQQB2kcPAQEHQB2i2kHWm26u0qHFeMCNRCbqVTLiRKIMKbXDNkY7/3C1 iPUEGBYKACYWIQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx4y4QIbAgUJA8JnAACB CRCrX+uIbbuZwnYgBBkWCgAdFiEEpncJCyCIcUtWwv050WQ+QNd/fbMFAmceMuEA CgkQ0WQ+QNd/fbOEFQD/ZaAI+8HbY27teJ7OINpoX3xYBZBo0RgGplyuGsFEVlcB AIssq3J4v4pOQG6B0PP/ayjCTZ1hp9bdpaHynnaWoQ0HorkA+gKMyo+MlHuFGP6R heHBUjktfvu1Ko4VTC2AAIlhdcM+AP4ucmvm1J5vmSbjTFsloIfFgC6QUYP6u0Vz 4an8Ne8RD7g4BGceMvMSCisGAQQBl1UBBQEBB0Ca22Gc7tCRucPIMROhLUHui5sS jKj+hMkd97APgUfaSwMBCAeIfgQYFgoAJhYhBO2PcAV05n8g5XTo4qtf64htu5nC BQJnHjLzAhsMBQkDwmcAAAoJEKtf64htu5nCVO0BAPi5qRYX0NWoo/y/Fc7GcK/0 uOBws3M+fo5MZ1VUOS2eAQDTgqWBGPgmK5XeV2bzPIdhJ7TZ88Rx7oY3wzkNzAJB CrgzBGceRW4WCSsGAQQB2kcPAQEHQEj9HSaebUdimo77xdWjsdVZrMYfCY0GkKaJ y0QINxJfiH4EGBYKACYWIQTtj3AFdOZ/IOV06OKrX+uIbbuZwgUCZx5FbgIbIAUJ A8JnAAAKCRCrX+uIbbuZwt4GAP9xXdBwLLNUox3phQMU8rM4GrUFWDovNoIoN1lp KUzflAEAnNnWVMPQrLXc4Y4RSVVPBWQkFxXJXtpZcC5hKIMiOwU= =lpJ8 -----END PGP PUBLIC KEY BLOCK----- ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2 2024-11-27 15:37 Update AB5FEB886DBB99C2 Vincent Mailhol @ 2024-11-27 16:02 ` Konstantin Ryabitsev 2024-11-28 5:34 ` Vincent Mailhol 2025-02-10 12:43 ` Uwe Kleine-König 0 siblings, 2 replies; 6+ messages in thread From: Konstantin Ryabitsev @ 2024-11-27 16:02 UTC (permalink / raw) To: Vincent Mailhol; +Cc: keys On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote: > Hi, > > I collected a few more cross signatures. Could you update my public key > with the one attached? Thank you. Updated, thanks. > Actually, I also wanted to confirm one thing. I uploaded my keys and all > its cross signature on keyserver.ubuntu.com: > > https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index > > and so, I was expecting those cross signs to be automatically > synchronized during the periodic update. But it did not happen. Indeed, looks like they don't give us the third-party signature data when we ask for key updates: $ gpg --list-sigs AB5FEB886DBB99C2 pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31] ED8F700574E67F20E574E8E2AB5FEB886DBB99C2 uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr> sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature] sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org> sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org> [...] $ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2 gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed gpg: Total number processed: 1 gpg: unchanged: 1 I only get your latest signatures when I import what you sent in: $ gpg --import keys/AB5FEB886DBB99C2.asc gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures gpg: Total number processed: 1 gpg: new signatures: 3 This is normal, though -- very few keyservers still provide third-party signature data after the attacks on that functionality a few years ago. > So let me ask: what type of data are actually synchronized? Is it only > the sub-keys and the expiration dates? Or is there a way to upload the > cross signatures somewhere to have them automatically synchronized in > kernel/pgpkeys.git during the periodic updates? The keyservers can really only be relied for publishing things like: - new subkeys - new uids - updated expiry dates For third-party signature data it's best to send an export to this list. -K ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2 2024-11-27 16:02 ` Konstantin Ryabitsev @ 2024-11-28 5:34 ` Vincent Mailhol 2025-02-10 12:43 ` Uwe Kleine-König 1 sibling, 0 replies; 6+ messages in thread From: Vincent Mailhol @ 2024-11-28 5:34 UTC (permalink / raw) To: Konstantin Ryabitsev; +Cc: keys On Thu. 28 Nov. 2024 at 01:02, Konstantin Ryabitsev <konstantin@linuxfoundation.org> wrote: > On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote: > > Hi, > > > > I collected a few more cross signatures. Could you update my public key > > with the one attached? Thank you. > > Updated, thanks. Great. I am all set now. > > Actually, I also wanted to confirm one thing. I uploaded my keys and all > > its cross signature on keyserver.ubuntu.com: > > > > https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index > > > > and so, I was expecting those cross signs to be automatically > > synchronized during the periodic update. But it did not happen. > > Indeed, looks like they don't give us the third-party signature data when we > ask for key updates: > > $ gpg --list-sigs AB5FEB886DBB99C2 > pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31] > ED8F700574E67F20E574E8E2AB5FEB886DBB99C2 > uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr> > sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature] > sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org> > sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org> > [...] > > $ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2 > gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed > gpg: Total number processed: 1 > gpg: unchanged: 1 > > I only get your latest signatures when I import what you sent in: > > $ gpg --import keys/AB5FEB886DBB99C2.asc > gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures > gpg: Total number processed: 1 > gpg: new signatures: 3 > > This is normal, though -- very few keyservers still provide third-party > signature data after the attacks on that functionality a few years ago. The reality is a bit more nuanced. If I add the --verbose option, I get: $ gpg --verbose --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2 gpg: data source: http://185.125.188.26:11371 gpg: armor header: Comment: Hostname: gpg: armor header: Version: Hockeypuck 2.2 gpg: key AB5FEB886DBB99C2: number of dropped non-self-signatures: 6 gpg: pub ed25519/AB5FEB886DBB99C2 2024-06-01 Vincent Mailhol <mailhol.vincent@wanadoo.fr> gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed gpg: Total number processed: 1 gpg: unchanged: 1 So, the client received six non-self-signatures, but decided to drop them. Which is consistent with what the documentation has to say: The default list of options is: "*self-sigs-only*, import-clean, repair-keys, repair-pks-subkey-bug, export-attributes". Link: https://www.gnupg.org/documentation/manuals/gnupg/GPG-Configuration-Options.html It is true that many servers do not provide third party signatures anymore, but keyserver.ubuntu.com still does. The attack you are referring to is, I guess, the third party signature spamming in which the attacker would upload thousands of dummy cross signatures to cause a denial of service. But this attack does not apply to kernel/pgpkeys.git because we operate in a closed circle. This makes it easy to filter out any third party signatures which originate from someone which is not part of the kernel network of trust. This is easily controlled by passing the --keyserver-options no-self-sigs-only and --keyserver-options import-clean options. For example, if doing think from my old key: $ gpg --keyserver keyserver.ubuntu.com --keyserver-options no-self-sigs-only --keyserver-options import-clean --recv-key AB5FEB886DBB99C2 gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures gpg: marginals needed: 3 completes needed: 1 trust model: pgp gpg: depth: 0 valid: 1 signed: 0 trust: 0-, 0q, 0n, 0m, 0f, 1u gpg: next trustdb check due at 2026-11-06 gpg: Total number processed: 1 gpg: new signatures: 3 The signatures which do not match a valid identity are silently removed. --verbose is needed to get the message, e.g.: gpg: removing signature from key 735AA2F46136D956 on user ID "Vincent Mailhol <mailhol.vincent@wanadoo.fr>": key unavailable > > So let me ask: what type of data are actually synchronized? Is it only > > the sub-keys and the expiration dates? Or is there a way to upload the > > cross signatures somewhere to have them automatically synchronized in > > kernel/pgpkeys.git during the periodic updates? > > The keyservers can really only be relied for publishing things like: > > - new subkeys > - new uids > - updated expiry dates > > For third-party signature data it's best to send an export to this list. Please note that I have no issue with this approach. I just think that downloading the third party signatures as part of the periodic update is better because: 1. it is less work for you 2. I do not see how an attacker would be able to abuse this But I do not mind manually submitting changes. Whatever approach is used, I would like to suggest updating the documentation to clearly specify what has to be sent manually and what will be automatically synchronized. Yours sincerely, Vincent Mailhol ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2 2024-11-27 16:02 ` Konstantin Ryabitsev 2024-11-28 5:34 ` Vincent Mailhol @ 2025-02-10 12:43 ` Uwe Kleine-König 2025-02-10 16:22 ` Konstantin Ryabitsev 1 sibling, 1 reply; 6+ messages in thread From: Uwe Kleine-König @ 2025-02-10 12:43 UTC (permalink / raw) To: Konstantin Ryabitsev; +Cc: Vincent Mailhol, keys [-- Attachment #1: Type: text/plain, Size: 2768 bytes --] Hello Konstantin, On Wed, Nov 27, 2024 at 11:02:10AM -0500, Konstantin Ryabitsev wrote: > On Thu, Nov 28, 2024 at 12:37:32AM +0900, Vincent Mailhol wrote: > > Hi, > > > > I collected a few more cross signatures. Could you update my public key > > with the one attached? Thank you. > > Updated, thanks. > > > Actually, I also wanted to confirm one thing. I uploaded my keys and all > > its cross signature on keyserver.ubuntu.com: > > > > https://keyserver.ubuntu.com/pks/lookup?search=AB5FEB886DBB99C2&op=index > > > > and so, I was expecting those cross signs to be automatically > > synchronized during the periodic update. But it did not happen. > > Indeed, looks like they don't give us the third-party signature data when we > ask for key updates: > > $ gpg --list-sigs AB5FEB886DBB99C2 > pub ed25519/AB5FEB886DBB99C2 2024-06-01 [SC] [expires: 2029-12-31] > ED8F700574E67F20E574E8E2AB5FEB886DBB99C2 > uid [ unknown] Vincent Mailhol <mailhol.vincent@wanadoo.fr> > sig 3 AB5FEB886DBB99C2 2024-10-27 [self-signature] > sig 0B0244C40D0D431C 2024-11-05 Shuah Khan <shuah@gonehiking.org> > sig EBC26CDB5A56DE73 2024-11-04 Steven Rostedt (Der Hacker) <rostedt@goodmis.org> > [...] > > $ gpg --keyserver keyserver.ubuntu.com --recv-key AB5FEB886DBB99C2 > gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" not changed > gpg: Total number processed: 1 > gpg: unchanged: 1 > > I only get your latest signatures when I import what you sent in: > > $ gpg --import keys/AB5FEB886DBB99C2.asc > gpg: key AB5FEB886DBB99C2: "Vincent Mailhol <mailhol.vincent@wanadoo.fr>" 3 new signatures > gpg: Total number processed: 1 > gpg: new signatures: 3 > > This is normal, though -- very few keyservers still provide third-party > signature data after the attacks on that functionality a few years ago. > > > So let me ask: what type of data are actually synchronized? Is it only > > the sub-keys and the expiration dates? Or is there a way to upload the > > cross signatures somewhere to have them automatically synchronized in > > kernel/pgpkeys.git during the periodic updates? > > The keyservers can really only be relied for publishing things like: > > - new subkeys > - new uids > - updated expiry dates > > For third-party signature data it's best to send an export to this list. Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just gpg doesn't import them by default. If you really want all that stuff, use: gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com Best regards Uwe [-- Attachment #2: signature.asc --] [-- Type: application/pgp-signature, Size: 488 bytes --] ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2 2025-02-10 12:43 ` Uwe Kleine-König @ 2025-02-10 16:22 ` Konstantin Ryabitsev 2025-02-10 17:04 ` Uwe Kleine-König 0 siblings, 1 reply; 6+ messages in thread From: Konstantin Ryabitsev @ 2025-02-10 16:22 UTC (permalink / raw) To: Uwe Kleine-König; +Cc: Vincent Mailhol, keys On Mon, Feb 10, 2025 at 01:43:41PM +0100, Uwe Kleine-König wrote: > > > So let me ask: what type of data are actually synchronized? Is it only > > > the sub-keys and the expiration dates? Or is there a way to upload the > > > cross signatures somewhere to have them automatically synchronized in > > > kernel/pgpkeys.git during the periodic updates? > > > > The keyservers can really only be relied for publishing things like: > > > > - new subkeys > > - new uids > > - updated expiry dates > > > > For third-party signature data it's best to send an export to this list. > > Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just > gpg doesn't import them by default. > > If you really want all that stuff, use: > > gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com Thank you for the hint! I didn't know that was needed. However, we'll still probably only use keyservers for key updates, since if a key is in our keyring, that means we already have sufficient signatures and we just want updates to things like uids, subkeys and expiration dates. -K ^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: Update AB5FEB886DBB99C2 2025-02-10 16:22 ` Konstantin Ryabitsev @ 2025-02-10 17:04 ` Uwe Kleine-König 0 siblings, 0 replies; 6+ messages in thread From: Uwe Kleine-König @ 2025-02-10 17:04 UTC (permalink / raw) To: Konstantin Ryabitsev; +Cc: Vincent Mailhol, keys [-- Attachment #1: Type: text/plain, Size: 1587 bytes --] Hello Konstantin, On Mon, Feb 10, 2025 at 11:22:36AM -0500, Konstantin Ryabitsev wrote: > On Mon, Feb 10, 2025 at 01:43:41PM +0100, Uwe Kleine-König wrote: > > > > So let me ask: what type of data are actually synchronized? Is it only > > > > the sub-keys and the expiration dates? Or is there a way to upload the > > > > cross signatures somewhere to have them automatically synchronized in > > > > kernel/pgpkeys.git during the periodic updates? > > > > > > The keyservers can really only be relied for publishing things like: > > > > > > - new subkeys > > > - new uids > > > - updated expiry dates > > > > > > For third-party signature data it's best to send an export to this list. > > > > Note that keyserver.ubuntu.com still provides 3rd-Party signatures, just > > gpg doesn't import them by default. > > > > If you really want all that stuff, use: > > > > gpg --refresh --keyserver-options no-self-sigs-only --keyserver keyserver.ubuntu.com > > Thank you for the hint! I didn't know that was needed. > > However, we'll still probably only use keyservers for key updates, since if a > key is in our keyring, that means we already have sufficient signatures and we > just want updates to things like uids, subkeys and expiration dates. That's true until you start to consider removing keys (because they are expired or their crypto is week) or you also take into account revokations. Also new signatures are good because a key that is today at distance 3 from Linus might get nearer and so qualify to sign new keys. Best regards Uwe [-- Attachment #2: signature.asc --] [-- Type: application/pgp-signature, Size: 488 bytes --] ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2025-02-10 17:04 UTC | newest] Thread overview: 6+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2024-11-27 15:37 Update AB5FEB886DBB99C2 Vincent Mailhol 2024-11-27 16:02 ` Konstantin Ryabitsev 2024-11-28 5:34 ` Vincent Mailhol 2025-02-10 12:43 ` Uwe Kleine-König 2025-02-10 16:22 ` Konstantin Ryabitsev 2025-02-10 17:04 ` Uwe Kleine-König
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.