Keyserver doesn't honour signature removal

John W. Moore III jmoore3rd at bellsouth.net
Sun Apr 12 14:01:22 CEST 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Dominik George wrote:

> Is it even possible to remove signatures from a key and distribute this
> change? Or am I doing something wrong?

What lands on the Keyservers stays on the Keyservers, forever.  :(

This is due to the sharing/gossip nature of most Keyservers.  There are
2 Keyservers I am aware of which do not share/gossip; Big Lumber & PGP
Global Directory.  Of these 2 _only_ BL prevents anyone but the
Key/Account Owner from 'changing' the listed Key.

Listing Your Key at www.biglumber.com will allow You to display Your Key
exactly as You desire it to appear and folks may be directed to retrieve
it from there via a Comment line or a signature tagline.  I am not aware
of the ability to specify the Big Lumber listing in a 'Preferred
Keyserver' flag.

IMO, the benefits of having One's Key available via auto-retrieval
outweighs the hassle of undesired Signatures and the 'baggage' of
old/revoked UID's.  YMMV

JOHN ;)
Timestamp: Sunday 12 Apr 2009, 08:00  --400 (Eastern Daylight Time)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10-svn4979: (MingW32)
Comment: Public Key at:  http://tinyurl.com/8cpho
Comment: Gossamer Spider Web of Trust: https://www.gswot.org
Comment: Homepage:  http://tinyurl.com/yzhbhx

iQEcBAEBCgAGBQJJ4dgNAAoJEBCGy9eAtCsPzH4H/3Xnt6nJw60DBZB0TU2L85s5
dBP5mjLYaUzLL0CXj4dtoWgHdfUcJRTuGyeQKNHuXEnjA9ksMjGGwozSLEk1cZTd
+zxzLEK8RYEB6M0Fk8h4RrDpXTIDHLZen33JDfVIfDeWNTbHXcwaS6YAHSb7YACR
/nAwYPyYryYoaTuuBz0zB+SZHpu3N71tnGciIzbBh5CvlutHOwxTQcv55Yg3daDa
Yf/OCnzSWjN8H6VFBMKtRIBsBt89uzBe2V3RjKH1kh/CSkba3tVB0JBwoXc32eo3
VHeqPLoijghAz9PBXX36dJ9JKmsILKJzQ7aILAtePagFwE8k2uauG48/YRFQnYA=
=KhC/
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list