From bernhard at intevation.de Fri Jun 7 09:15:21 2024 From: bernhard at intevation.de (Bernhard Reiter) Date: Fri, 7 Jun 2024 09:15:21 +0200 Subject: keyserver.gnupg.org funded by GnuPG e. Verein In-Reply-To: <202301311636.21685.bernhard@intevation.de> References: <202301311636.21685.bernhard@intevation.de> Message-ID: <202406070915.30126.bernhard@intevation.de> Hello Friends of GnuPG and pragmatically standardised end-to-end crypto! Am Dienstag 31 Januar 2023 16:36:21 schrieb Bernhard Reiter: > over the course of last year our association ("Verein" in German) > has funded the setup and running of a server for public OpenPGP keys. > > It is running since a few months now at: > > https://keyserver2.gnupg.org/ > > (It's in beta, there will be some adjustments to the texts.) unfortunatly the server is down now. The two admins silently dropped out (for reasons outside of GnuPG). So I am not sure how long the server is down, I've just noticed two weeks ago or so. Got in contact with one of the previous admins. The question is now: Is there an interest to run another modern keyserver for public keys as part of the GnuPG association? When the old keyserver network broke down, some demand for a new network was visible. There is one now https://spider.pgpkeys.eu/ and the server from GnuPG e.V. was a part of it. The software https://hockeypuck.io is maintained and more resistant against attacks, but does not carry third party signatures (IIRC). From the conceptual side I think there is still a gap that decentralized pubkeyservers fill. What do you think? Best Regards Bernhard > How it came to be: > Werner suggested two young admins, and I handled the details. > The server is operated independently from the Verein: > e.g. the board does not have any access to the machines. > I estimate the costs for the verein between 1000 and 2000?, > maybe a little bit more, once we get more load on the system. > Technically the admin told me, they can scale the system up, if needed. -- https://intevation.de/~bernhard ? +49 541 33 508 3-3 Intevation GmbH, Osnabr?ck, DE; Amtsgericht Osnabr?ck, HRB 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 659 bytes Desc: This is a digitally signed message part. URL: From wk at gnupg.org Fri Jun 7 16:20:38 2024 From: wk at gnupg.org (Werner Koch) Date: Fri, 07 Jun 2024 16:20:38 +0200 Subject: keyserver.gnupg.org funded by GnuPG e. Verein In-Reply-To: <202406070915.30126.bernhard@intevation.de> (Bernhard Reiter's message of "Fri, 7 Jun 2024 09:15:21 +0200") References: <202301311636.21685.bernhard@intevation.de> <202406070915.30126.bernhard@intevation.de> Message-ID: <87ed98u955.fsf@jacob.g10code.de> On Fri, 7 Jun 2024 09:15, Bernhard Reiter said: > From the conceptual side I think there is still a gap that decentralized > pubkeyservers fill. Yes, for distributing revocations. But that should be a done using a simpler and better distributable system. I doubt that the currently used keyserver software is helpful. Searching by mail address or, worse, by name too often returns keys not actually hold by the expected holder. As long as there is a mail address there are simpler and more direct ways to get hold of a key. - Asking for a key using the inital contact (mail) - Sending the key along with the initial response. - Using the Web Key Directory Revocations are different because they are also needed after a mail address stopped working. Shalom-Salam, Werner -- The pioneers of a warless world are the youth that refuse military service. - A. Einstein -------------- next part -------------- A non-text attachment was scrubbed... Name: openpgp-digital-signature.asc Type: application/pgp-signature Size: 247 bytes Desc: not available URL: From bernhard at intevation.de Mon Jun 10 17:39:53 2024 From: bernhard at intevation.de (Bernhard Reiter) Date: Mon, 10 Jun 2024 17:39:53 +0200 Subject: keyserver.gnupg.org funded by GnuPG e. Verein In-Reply-To: <87ed98u955.fsf@jacob.g10code.de> References: <202301311636.21685.bernhard@intevation.de> <202406070915.30126.bernhard@intevation.de> <87ed98u955.fsf@jacob.g10code.de> Message-ID: <202406101739.53459.bernhard@intevation.de> Am Freitag 07 Juni 2024 16:20:38 schrieb Werner Koch: > As long as there is a mail > address there are simpler and more direct ways to get hold of a key. > > - Asking for a key using the inital contact (mail) > - Sending the key along with the initial response. > - Using the Web Key Directory For some use cases I think it makes sense to support usage without email addresses. And then just searching a pubkey id. Any yes, pubkeyserver will be much more useful if they start carrying third party signature again. (Which is conceptually possible.) In this case they contribute to distributing trust information. > Revocations are different because they are also needed after a mail > address stopped working. ACK -- https://intevation.de/~bernhard ? +49 541 33 508 3-3 Intevation GmbH, Osnabr?ck, DE; Amtsgericht Osnabr?ck, HRB 18998 Gesch?ftsf?hrer: Frank Koormann, Bernhard Reiter -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 659 bytes Desc: This is a digitally signed message part. URL: