Re: Please tackle the Right Thing

2021-01-27 Thread André Colomb
ting point to attract comments on the approach. By the way, is there something like a repository to send and discuss pull requests against the WKD draft document? Or is it just hand-crafted text edited by the submitter based on suggestions? Kind regards André -- Gree

Re: Please tackle the Right Thing

2021-01-22 Thread André Colomb
tions. IIUC, he is the main (and only?) draft author, so before IETF gets formally involved, the draft proposal can be iterated easily. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Fundraising

2021-01-22 Thread André Colomb
eetings... From: André Colomb ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Please tackle the Right Thing

2021-01-20 Thread André Colomb
hink that this logic still holds just in case SRV records are to be used again. So what do you think? I'm not subscribed to any IETF mailing lists, but feel free to propose this in the relevant circles. I hereby renounce my rights on the modified text :-) Kind regards André -- Greetings..

Re: WKD Checker

2021-01-18 Thread André Colomb
rue, while the rest of this thread was only applicable to a specific context :-) Good night. André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org h

Re: WKD proper behavior on fetch error

2021-01-18 Thread André Colomb
etter than no encryption at all, e.g. to set up an out-of-band key verification. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http:/

Re: WKD proper behavior on fetch error

2021-01-17 Thread André Colomb
, hence the > late reply. Sorry, I don't quite understand. Would you like a reply to be addressed directly in addition to the mailing list? Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature _

Re: WKD proper behavior on fetch error

2021-01-17 Thread André Colomb
will not revoke their wildcard certificate just for you. Hijacking a GitHub Pages user name seems more likely than taking over a well secured domain hosting account. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP di

Re: WKD proper behavior on fetch error

2021-01-17 Thread André Colomb
te you. Please try to keep the discussion productive. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD proper behavior on fetch error

2021-01-14 Thread André Colomb
n web server. For that to work, you must set up the advanced method for WKD on your domain's DNS. That method is perfectly fine and in some scenarios even easier to use. Kind regards André Hi raf, thanks for your perspective on the matter. -- Greetings... From: André Colomb

Re: WKD & Sequoia

2021-01-14 Thread André Colomb
I offer to help with any problems coming up. You should not rule out the advanced method yet. Depending on your setup, it might actually be the easier route if wildcard domains are involved. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital sign

Re: WKD proper behavior on fetch error

2021-01-14 Thread André Colomb
. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD proper behavior on fetch error

2021-01-14 Thread André Colomb
ve avoided this long > thread. :-) I couldn't resist trying to help Stefan understand where the error lies, so apologies for my share of the message flood :-) Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature _

Re: WKD & Sequoia

2021-01-13 Thread André Colomb
c even explicitly mentions one possible pitfall including a solution. Reactions to that kind of misconfiguration should also be standardized in the spec. That's all there is to criticize, IMHO. Kind regards André -- Greetings... From: André Colomb ___

Re: WKD & Sequoia

2021-01-13 Thread André Colomb
needs to "noodle around with domain settings". It points you to the right spice to add just in case your domain settings are already a noodle soup. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___

Re: WKD & Sequoia

2021-01-13 Thread André Colomb
Hi Stefan, On 13/01/2021 17.07, Stefan Claas wrote: > On Wed, Jan 13, 2021 at 10:22 AM André Colomb wrote: > >> So the core problem, as with Stefan's case, is the lack of control over >> the domain's DNS settings. Which the WKD mechanism relies upon to >> delegate trust

Re: WKD & Sequoia

2021-01-13 Thread André Colomb
ent WKD Internet Draft. At least a clarification and maybe some adjustments to the advised fall-back behavior would be in order. Let's see what Werner has to say about it and if there are yet unclear reasons for the currently specified way. Kind regards André -- Greetings... From: André Colomb

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
sac001.github.io, the certificate is *valid*. Nobody ever questioned that. But it doesn't mean the above is untrue. Stay safe. André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-user

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
ind that scheme :-) So, only anonymous in theory. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
rd domains and invalid TLS certificates as github.io. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
ey have every right to not care about OpenPGP at all and let WKD requests fail ungracefully. Even the right to serve an invalid wildcard certificate for sub-subdomains (which is still bad though). Sorry for the long read, but I hope it clarifies the situation. Regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
eing with your proposal. I don't mind to be proven wrong if it was in fact my misunderstanding. Kind regards André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: WKD for GitHub pages

2021-01-12 Thread André Colomb
erver side, compared to the two DNS queries you need to make either way. Hope that helps. André -- Greetings... From: André Colomb signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.g

Re: WKD for GitHub pages

2021-01-08 Thread André Colomb
hings on the domain. In your setup, the valid TLS certificate for sac001.github.io is the only one you'll get, so the "Direct" method fits perfectly. Nice idea actually, but you'd have to check if GitHub actually allows such use for "arbitrary" data distribution. Good

Re: WKD for GitHub pages

2021-01-08 Thread André Colomb
here: https://metacode.biz/openpgp/web-key-directory It reports that the policy file is missing, which I think is a hard requirement, no? Also make sure that the MIME content type and Access-Control-Allow-Origin headers are set correctly. Kind regards, André -- Greetings... From:

Re: Future OpenPGP Support in Thunderbird

2019-10-09 Thread André Colomb
Hi Patrick, >The Thunderbird developers and I have therefore agreed that it's much >better to implement OpenPGP support directly in Thunderbird. The set of >functionalities will be different than what Enigmail offers, and at >least initially likely be less feature-rich. But in my eyes, this is

Re: Why exactly does pinentry fails with gpg-agent and ssh support?

2018-01-24 Thread André Colomb
On 2018-01-22 18:06, André Colomb wrote: >> the systemd user service takes care of automatically launching the >> gpg-agent when the user connects to it via the ssh-agent protocol, so >> this isn't required when using systemd. > > I can't see how it does that in my package

Re: Why exactly does pinentry fails with gpg-agent and ssh support?

2018-01-22 Thread André Colomb
nt.socket unit file anywhere? Any other ideas on how to debug this? What logging should I enable for gpg-agent and how? Btw. it affects both my Yubikey as well as file-based authentication subkeys, so not specific to scdaemon apparently. Regards André -- Greeting

Re: Why exactly does pinentry fails with gpg-agent and ssh support?

2018-01-22 Thread André Colomb
s far, but today I found out that updatestartuptty suffices. Strange thing is, I could use the GPG part of gpg-agent already before issuing that command. Why does that behave differently? Can something be done to the systemd user unit file so the process gets told the correct $DISPLAY at leas

Re: Local-signing without (offline) private master key

2016-09-15 Thread André Colomb
ast gives some indication, but is not easy data to interpret. Did I miss some option here, or are any such additions planned? Regards André -- Greetings... From: André Colomb <an...@colomb.de> signature.asc Description: OpenPGP digital signature ___ Gnupg

Local-signing without (offline) private master key

2016-09-12 Thread André Colomb
- Greetings... From: André Colomb <an...@colomb.de> 0x9F45D0FB.asc Description: application/pgp-keys signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users