Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-13 Thread John Clizbe
Phil Pennock wrote: On 2013-09-12 at 19:40 -0400, Daniel Kahn Gillmor wrote: While this seems like it is probably a fixable bug for someone who knows their way around the codebase, I forsee problems with synchronizing the pool, if some SKS keyservers start following the spec and others remain

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-13 Thread Robert J. Hansen
On 9/13/2013 5:48 PM, Daniel Kahn Gillmor wrote: RFC 4880 is explicit: Some implementations do not represent the interest of a single user (for example, a key server). Such implementations always trim local certifications from any key they handle. I don't see a MUST in there. The

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-13 Thread John Clizbe
Daniel Kahn Gillmor wrote: Someoneā„¢ (0x75D292D353ADACCD) made a non-exportable certification on your user ID John P. Clizbe jpcli...@keyservers.net (2048R/0x2313315C435BD034). Someone else uploaded that key to a keyserver (ok, i admit it was me :P). The keyserver network is currently

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-13 Thread Christoph Anton Mitterer
On Fri, 2013-09-13 at 18:09 -0400, Daniel Kahn Gillmor wrote: Did anyone on this list expect the keyserver network to propagate non-exportable certifications? Nah,... not really, IMHO it should be considered a bug, and ideally such existing signatures should be removed if possible. And I guess