Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider WKD (Web Key Directory) for our keys #13

Open
lazka opened this issue Feb 16, 2022 · 6 comments
Open

Consider WKD (Web Key Directory) for our keys #13

lazka opened this issue Feb 16, 2022 · 6 comments

Comments

@lazka
Copy link
Member

lazka commented Feb 16, 2022

Instead of using the keyserver we would host the keys ourselves. https://wiki.gnupg.org/WKD

Background: https://bugs.archlinux.org/task/63171

@Biswa96
Copy link
Member

Biswa96 commented Feb 16, 2022

Thanks for sharing the details. The threads in that bug report are awesome. Just out of curiosity, I have some queries.

  • The discussion was started based on spamming the keyserver. Can the new msys2's own keyserver prevent that type of spamming?
  • How secure the new keyserver will be?
  • Will this transition be transparent to all users?
  • Does this require a email server also?

@lazka
Copy link
Member Author

lazka commented Feb 16, 2022

From what I understand it's just a static website with a certain structure. So yes, very(?), yes, no.

@lazka
Copy link
Member Author

lazka commented Feb 16, 2022

The main challenge would be to get Alexey to sign our keys again, I think.

@jeremyd2019
Copy link
Member

jeremyd2019 commented Feb 16, 2022

I've set WKD up a couple of times. It is a static website. Most of the spec actually deals with automated key submission/updates, and can be ignored if you don't care about that. The only bit that you need to do is that you MUST publish a policy file, but it can be empty if you don't support submission.

@lazka lazka changed the title Consider WKD for our keys Consider WKD (Web Key Directory) for our keys Mar 4, 2022
@lazka
Copy link
Member Author

lazka commented Mar 5, 2022

Had a short talk with David yesterday and he's OK if we try this.

Also had a very short exchange with Alexey, he's reachable, but very bussy as always :)

@jeremyd2019
Copy link
Member

If you decide to do this, I have some experience setting this up, over multiple revisions of the spec, if you want advice on how to do it in a way that complies with as many revisions as possible (or you can just conform to the latest revision, hosting files in https://openpgpkey.msys2.org/.well-known/openpgpkey/msys2.org/..., since it could be safely assumed that the consumer is a recent version of GnuPG),

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants