Refreshing keyring via WKD

Ingo Klöcker kloecker at kde.org
Mon Mar 23 09:03:10 CET 2026


On Sonntag, 22. März 2026 20:21:18 Mitteleuropäische Normalzeit Ingo Klöcker 
wrote:
> On Sonntag, 22. März 2026 18:31:30 Mitteleuropäische Normalzeit Werner Koch
> 
> via Gnupg-users wrote:
> > On Sun, 22 Mar 2026 13:29, Seth McDonald said:
> > > To my understanding, GnuPG has been encouraging the use of WKD over
> > > keyservers for the distribution of public keys.  I personally use WKD as
> > 
> > Right, except for organizational-wide LDAP keyservers.
> > 
> > > Though when it comes to updating my keyring via --refresh-keys, GnuPG
> > > seems to only be able to use keyservers to obtain the up-to-date keys.
> > 
> > Yes, this is an open task.
> 
> Kleopatra already can update multiple keys in one go. Simply select the
> OpenPGP certificates you want to update and then select "Update
> Certificates". Kleopatra queries WKD and the configured OpenPGP keyserver.
> If you just want to update via WKD then temporarily remove the configured
> keyserver.

I forgot that one has to enable the option "Query certificate directories of 
providers for all user IDs" if all keys should be updated via WKD. Otherwise, 
only keys that were originally retrieved via WKD are updated via WKD.

Regards,
Ingo
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 265 bytes
Desc: This is a digitally signed message part.
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20260323/fca97960/attachment.sig>


More information about the Gnupg-users mailing list