[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sks-devel] unwanted tolerance of buggy keys
From: |
Jeffrey Johnson |
Subject: |
Re: [Sks-devel] unwanted tolerance of buggy keys |
Date: |
Mon, 30 Jul 2012 22:18:39 -0400 |
On Jul 30, 2012, at 10:10 PM, Jeffrey Johnson <address@hidden> wrote:
>
> I'm not sure SKS is the Right Place to enforce conformance
> (much like discussions about OpenPGP binding signatures).
>
Sorry for imprecision:
Not OpenPGP but rather
"PGP Global Directory Verification signatures."
with expiry of 2 weeks as described here
http://www.kfwebs.net/articles/article/17/GPG-mass-cleaning-and-the-PGP-Corp.-Global-Directory
Once you start filtering/rejecting pubkey materiel: whether
its blocking signature types on sub keys or filtering
revoked/expired signatures, the policies all become rather
a sticky wicket.
Personally, I think that reducing the bloat/load with narrower
and more predictable enforcement is wise in each case.
73 de Jeff