Bug#931339: [pkg-gnupg-maint] Bug#931339: gnupg: Change default keyserver?

2021-07-04 Thread Paul Wise
On Sun, 2021-07-04 at 22:28 +0900, Roger Shimizu wrote:

> Is there any other bug involved?

In another mail, Harald Welte says lxc is now broken:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=931339#29

Hopefully he can re-check things and reply.

-- 
bye,
pabs

https://wiki.debian.org/PaulWise


signature.asc
Description: This is a digitally signed message part


Bug#931339: [pkg-gnupg-maint] Bug#931339: gnupg: Change default keyserver?

2021-07-04 Thread Roger Shimizu
On Sun, Jul 4, 2021 at 6:00 PM Paul Wise  wrote:
>
> On Tue, 2 Jul 2019 15:55:32 +0200 Guillem Jover wrote:
>
> > According to the dirmngr(8) man page, the default built-in server is
> > «hkps://hkps.pool.sks-keyservers.net». Given the recent attacks, and
> > the problems inherent in that network, could we just change the
> > default to be «hkps://keys.openpgp.org» instead?
>
> This is fixed in bullseye, but not buster. Now that sks-keyservers.net
> is no longer working, Debian users on bullseye are having issues, so it
> would be great if the default could be updated in buster/stretch too:

>From changelog, version in buster already [1] updated the default
server to keys.openpgp.org
Is there any other bug involved?

[1] 
https://tracker.debian.org/news/1060144/accepted-gnupg2-2212-1deb10u1-source-into-proposed-updates-stable-new-proposed-updates/

Cheers,
Roger



Bug#931339: [pkg-gnupg-maint] Bug#931339: gnupg: Change default keyserver?

2019-07-03 Thread Werner Koch
On Tue,  2 Jul 2019 15:55, guil...@debian.org said:

> According to the dirmngr(8) man page, the default built-in server is
> «hkps://hkps.pool.sks-keyservers.net». Given the recent attacks, and

Not from upstream.  We have a default keyserver because that is (or
better was) a pool of keyservers which allows to maintain a set of
responsive keyservers without chnages on the client side.
keys.openpgp.org may ask to be included into the pool but I doubt that
this makes sense because it is, like pgp.com, a standalone keyserver
which by design can't synchronize with others.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.


signature.asc
Description: PGP signature