Possible bug in using 'recv-key' facility via a HTTP proxy

Steven Murdoch sjmurdoch at bigfoot.com
Sun Apr 29 00:07:02 CEST 2001


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

At 13:48 23/04/01 +0200, you wrote:
>On Mon, 23 Apr 2001, Matthias Urlichs wrote:
>
>> > is or add an option to not do the shutdown?
>> > 
>> The latter.
>
>Done, well not a option but a kludge:
>
>Use
>
>--keyserver=x-broken-hkp://my.keyserver.net:11371
>
>and if you have a keyserver running on a different port you can now
>also do a
>
>--keyserver=x-hkp://my.keyserver.net:4242

I wrote a very simple TCP client to confirm what was happening and
indeed when the shutdown was inserted the connection to the proxy
server failed, and when it was ommited the connection succeeded. When
I tried connecting to Apache on my local machine both methods worked
fine.

I haven't had a chance to look at the CVS code but from my
understanding of the mail the x-broken-hkp prefix is disables the
shutdown instruction. I'm not sure whether this is the best
option. The reason I was thinking this was all the http programs I've
tested let the server send the FIN packet first (i.e. ommit the
shutdown), so I would assume that more servers have trouble with the
shutdown, compared to those that require it. If this is the case then
maybe ommiting the shutdown should be the default. 

This is mainly a semantic issue since a server that requires either
option is broken, but I would guess that more people would have
problems with including the shutdown than if it were
ommitted. Therefore if the shutdown instruction was ommitted unless
broken-hkp was specified then this should reduce the number of people
that have problems.

Thank you,

Steven Murdoch.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE66zAKy7aeQyigOIYRAo+7AKCQFTjQ1jftIzdlUZF7a38Zrq0vfwCgorPc
oBKO7TYa8WAbHeUqhfLvCW4=
=JW0r
-----END PGP SIGNATURE-----

-- 
email: sjmurdoch at bigfoot.com
web: http://www.dcs.gla.ac.uk/~murdocsj/
PGP/GnuPG keys: http://www.bigfoot.com/~sjmurdoch/keys.html





More information about the Gnupg-devel mailing list