[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c cont
From: |
John Clizbe |
Subject: |
Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing? |
Date: |
Wed, 30 May 2012 21:58:26 -0500 |
User-agent: |
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.20pre) Gecko/20110606 Mnenhy/0.8.5 SeaMonkey/2.0.15pre |
Jeffrey Johnson wrote:
>
> Its the expired robo-signatures on existing pubkeys, not
> the pubkeys, that need filtering. There is also a need to
> delete pubkeys
>
> Is there a solution that can filter out specific expired
> signatures on pub keys that can be gossip'd efficiently?
>
> AFAIK additional certification signatures are accumulated
> and the pubkeys are then re-distributed and re-merged.
>
> How should one block distributing a specific pubkey's expired signatures
> on all existing pubkeys efficiently?
<lots of top and bottom posting mix snipped>
I'm with Rob. The keyservers should always host full certificates. Once we
start expiring keys or modifying them by removing bits, we become the
Untrusted Keyserver Cabal. Many would abandon us, probably forking to create a
new keyserver network of unmodified keys. IMO, leaving SKS to become this
century's PKS.
Now, that doesn't mean we always have to serve full certificates to clients.
&options=clean -- much like GnuPG, remove unusable userIDs and sigs, remove
duplicate signatures keeping the most recent, remove expired
signatures
&options=minimal -- This removes all signatures except the most recent
self-signature on each user ID. Also alá GnuPG
&options=no-uat -- remove User photos and other BLOB data and accompanying
signatures
These have the unfortunate side-effect of requiring the addition of crypto to
handle the validation, but we'd only be doing it on lookup?op=get instead of
every time we processed the key. And HEY! the trunk is updated to the latest
cryptokit, 1.5.
-John
- Re: [Sks-devel] Keys over NNTP, (continued)
- Re: [Sks-devel] Keys over NNTP, Phil Pennock, 2012/05/28
- Re: [Sks-devel] Keys over NNTP, David Shaw, 2012/05/28
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/27
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, John Marshall, 2012/05/27
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, David Benfell, 2012/05/27
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/27
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/27
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Yaron Minsky, 2012/05/30
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Ari Trachtenberg, 2012/05/30
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/30
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?,
John Clizbe <=
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/30
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, John Clizbe, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Jeffrey Johnson, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Gabor Kiss, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Robert J. Hansen, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Gabor Kiss, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Robert J. Hansen, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Kiss Gabor (Bitman), 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Robert J. Hansen, 2012/05/31
- Re: [Sks-devel] 0xd5920e937cc1e39b shows signatures with 0xca57ad7c continuing?, Kiss Gabor (Bitman), 2012/05/31