SKS Keyserver, HKPS, and GnuPG 2.1

Samir Nassar samir at samirnassar.com
Wed Mar 18 23:03:11 CET 2015


On Wednesday, March 18, 2015 10:40:57 PM Kristian Fiskerstrand wrote:
> try renaming  /home/snassar/.gnupg/myriapolis.net.crt to
> /home/snassar/.gnupg/myriapolis.net.pem

Done.

> if that doesn't help , can you increase debug verbosity in
> dirmngr.conf and set the logfile?
> $ cat dirmngr.conf
> verbose
> debug 4096
> debug-level 4096
> debug-all
> log-file /tmp/dirmngr.log

Results:

2015-03-18 22:57:20 dirmngr[23026.0] listening on socket 
'/home/snassar/.gnupg/S.dirmngr'
2015-03-18 22:57:20 dirmngr[23027.0] permanently loaded certificates: 0
2015-03-18 22:57:20 dirmngr[23027.0]     runtime cached certificates: 0
2015-03-18 22:57:21 dirmngr[23027.0] handler for fd 0 started
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 -> # Home: 
/home/snassar/.gnupg
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 -> # Config: 
/home/snassar/.gnupg/dirmngr.conf
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 -> OK Dirmngr 2.1.2 at your 
service
2015-03-18 22:57:21 dirmngr[23027.0] connection from process 23024 (1000:1000)
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 <- KEYSERVER --clear 
hkps://keyserver.myriapolis.net
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 -> OK
2015-03-18 22:57:21 dirmngr[23027.0] DBG: chan_0 <- KS_SEARCH -- 
samir at samirnassar.com
2015-03-18 22:57:21 dirmngr[23027.0] getnameinfo returned for 
'keyserver.myriapolis.net': 'keyserver.myriapolis.net' [already known]
2015-03-18 22:57:22 dirmngr[23027.0] TLS verification of peer failed: 
status=0x0042
2015-03-18 22:57:22 dirmngr[23027.0] TLS verification of peer failed: The 
certificate is NOT trusted. The certificate issuer is unknown. 
2015-03-18 22:57:22 dirmngr[23027.0] DBG: expected hostname: 
keyserver.myriapolis.net
2015-03-18 22:57:22 dirmngr[23027.0] DBG: BEGIN Certificate 'server[0]':
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      serial: 
4BC6878D433B6F5CA74E0142C8C2CA6B
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   notBefore: 2013-12-11 00:00:00
2015-03-18 22:57:22 dirmngr[23027.0] DBG:    notAfter: 2015-12-11 23:59:59
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      issuer: CN=COMODO RSA Domain 
Validation Secure Server CA,O=COMODO CA Limited,L=Salford,ST=Greater 
Manchester,C=GB
2015-03-18 22:57:22 dirmngr[23027.0] DBG:     subject: 
CN=*.myriapolis.net,OU=EssentialSSL Wildcard,OU=Domain Control Validated
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   hash algo: 1.2.840.113549.1.1.11
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   SHA1 fingerprint: 
47D0B4CAA99B5D3F9EA9C2E2F26B380CD60129C7
2015-03-18 22:57:22 dirmngr[23027.0] DBG: END Certificate
2015-03-18 22:57:22 dirmngr[23027.0] DBG: BEGIN Certificate 'server[1]':
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      serial: 
2B2E6EEAD975366C148A6EDBA37C8C07
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   notBefore: 2014-02-12 00:00:00
2015-03-18 22:57:22 dirmngr[23027.0] DBG:    notAfter: 2029-02-11 23:59:59
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      issuer: CN=COMODO RSA 
Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater 
Manchester,C=GB
2015-03-18 22:57:22 dirmngr[23027.0] DBG:     subject: CN=COMODO RSA Domain 
Validation Secure Server CA,O=COMODO CA Limited,L=Salford,ST=Greater 
Manchester,C=GB
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   hash algo: 1.2.840.113549.1.1.12
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   SHA1 fingerprint: 
339CDD57CFD5B141169B615FF31428782D1DA639
2015-03-18 22:57:22 dirmngr[23027.0] DBG: END Certificate
2015-03-18 22:57:22 dirmngr[23027.0] DBG: BEGIN Certificate 'server[2]':
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      serial: 
2766EE56EB49F38EABD770A2FC84DE22
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   notBefore: 2000-05-30 10:48:38
2015-03-18 22:57:22 dirmngr[23027.0] DBG:    notAfter: 2020-05-30 10:48:38
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      issuer: CN=AddTrust External CA 
Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
2015-03-18 22:57:22 dirmngr[23027.0] DBG:     subject: CN=COMODO RSA 
Certification Authority,O=COMODO CA Limited,L=Salford,ST=Greater 
Manchester,C=GB
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   hash algo: 1.2.840.113549.1.1.12
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   SHA1 fingerprint: 
F5AD0BCC1AD56CD150725B1C866C30AD92EF21B0
2015-03-18 22:57:22 dirmngr[23027.0] DBG: END Certificate
2015-03-18 22:57:22 dirmngr[23027.0] DBG: BEGIN Certificate 'server[3]':
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      serial: 01
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   notBefore: 2000-05-30 10:48:38
2015-03-18 22:57:22 dirmngr[23027.0] DBG:    notAfter: 2020-05-30 10:48:38
2015-03-18 22:57:22 dirmngr[23027.0] DBG:      issuer: CN=AddTrust External CA 
Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
2015-03-18 22:57:22 dirmngr[23027.0] DBG:     subject: CN=AddTrust External CA 
Root,OU=AddTrust External TTP Network,O=AddTrust AB,C=SE
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   hash algo: 1.2.840.113549.1.1.5
2015-03-18 22:57:22 dirmngr[23027.0] DBG:   SHA1 fingerprint: 
02FAF3E291435468607857694DF5E45B68851868
2015-03-18 22:57:22 dirmngr[23027.0] DBG: END Certificate
2015-03-18 22:57:22 dirmngr[23027.0] TLS connection authentication failed: 
General error
2015-03-18 22:57:22 dirmngr[23027.0] error connecting to 
'https://keyserver.myriapolis.net:443': General error
2015-03-18 22:57:22 dirmngr[23027.0] command 'KS_SEARCH' failed: General error 
<Unspecified source>
2015-03-18 22:57:22 dirmngr[23027.0] command 'KS_SEARCH' failed: General error 
<Unspecified source>
2015-03-18 22:57:22 dirmngr[23027.0] DBG: chan_0 -> ERR 1 General error 
<Unspecified source>
2015-03-18 22:57:22 dirmngr[23027.0] DBG: chan_0 <- BYE
2015-03-18 22:57:22 dirmngr[23027.0] DBG: chan_0 -> OK closing connection
2015-03-18 22:57:22 dirmngr[23027.0] handler for fd 0 terminated

Samir
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: This is a digitally signed message part.
URL: </pipermail/attachments/20150318/94edae96/attachment.sig>


More information about the Gnupg-users mailing list