Proposal: Let us run a keyserver
Bernhard Reiter
bernhard at intevation.de
Mon Mar 9 10:36:41 CET 2020
Hi Phil,
Am Sonntag 08 März 2020 00:38:36 schrieb Phil Pennock:
> On 2020-03-07 at 17:15 +0100, Bernhard Reiter wrote:
> > So what about rending a server and running a keyserver as e.V.?
> I ran a keyserver for about 8 years, I wrote most of the operational
> documentation and debugged a lot of problems for people.
thanks for your long termin contributions to the keyserver network! :)
[In my view our intern Verein mailinglist should only see limited discussions.
Many topics are worth to be discussed in a wider circle. This is why I answer
briefly and try refer to public mails. I'd appreciate other Verein members
short feedback on the proposal.]
> The keyserver network is a public append-only filesystem. This is not
> compatible with strong privacy law.
In my post
Preserving non-central and privacy with a "permission recording keyserver"
[Reiter 2019-07 a]
https://lists.gnupg.org/pipermail/gnupg-devel/2019-July/034399.html
there is a concept allowing for compatibility with strong privacy laws.
> I think that the public keyservers fulfilled a social need for a long
> time, but that their time has passed.
My case why public keyservers should be preserved is
Web of Trust's usefulness [Reiter 2019-07 c]
https://lists.gnupg.org/pipermail/gnupg-devel/2019-July/034412.html
| as additional source of trust and history.
| Abandoning the web of trust common infrastructure works against usage
| models where there is anonymous usage, several identities, non-email use
| and offline usage. All those maybe not the majority case, they may even be
| niche models, but I think they are important to add diversity and
| resiliance against manipulations of mainstream players.
(spelling improved)
A third post of mine showed how we could conceptually preserve third party
signature information on public servers:
Preserving third party signatures distribution [Reiter 2019-07 b]
https://lists.gnupg.org/pipermail/gnupg-devel/2019-July/034394.html
> I think that the Verein's resources are better spent pushing
> next-generation keyserving facilities. The WKD stuff is good, a better
> UI on it might help. Abuse resistant keystores would be good.
As Verein, we could do both to an extend.
[And in this proposal I focus on the public keyserver.]
> I assert that trying to resurrect the SKS network is a case
> of living in the past when we should be trying to build the future.
Preserving something important is a task that is well suited for a Verein,
because it can do long running and neutral things. Look like the the state of
the number of public keyservers and who were running was used as arguments in
the debate I've pointed to. Verein would be in a good position to at least be
one trusted operator of a public keyserver.
Regards,
Bernhard
--
www.intevation.de/~bernhard +49 541 33 508 3-3
Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: This is a digitally signed message part.
URL: <https://lists.gnupg.org/pipermail/verein/attachments/20200309/e558036f/attachment.sig>
More information about the Verein
mailing list