[Sks-devel] Question re: GDPR

2018-05-25 Thread Eric Germann
Good evening colleagues, Has anyone explored the implications of GDPR as it relates to keys stored on servers in the EU? Wondering how that all fits in, or how you would even get them out of the servers, short of getting the servers out of the EU. Thx EKG signature.asc Description:

[Sks-devel] Causes of "Vulnerable to CVE-2014-3207" flag in https://sks-keyservers.net/status/ks-status.php?server= page

2018-06-30 Thread Eric Germann
Greetings, Can anyone shed some light on what causes the "Vulnerable to CVE-2014-3207” flag to be set in the status page (https://sks-keyservers.net/status/ks-status.php?server= ) for a server? Build configuration is

Re: [Sks-devel] Causes of "Vulnerable to CVE-2014-3207" flag in https://sks-keyservers.net/status/ks-status.php?server= page

2018-06-30 Thread Eric Germann
t; > Kind regards, > > Christiaan de Die le Clercq > > Op 30-6-2018 om 3:20 PM schreef Eric Germann: >> Greetings, >> >> Can anyone shed some light on what causes the "Vulnerable to >> CVE-2014-3207” flag to be set in the status page >> (ht

Re: [Sks-devel] Causes of "Vulnerable to CVE-2014-3207" flag in https://sks-keyservers.net/status/ks-status.php?server= page

2018-06-30 Thread Eric Germann
iPt%3Eprompt(972363)%3C/ScRiPt%3E > > More info on here: > https://bitbucket.org/skskeyserver/sks-keyserver/issues/26/cve-2014-3207-unfiltered-xss > and on here https://nvd.nist.gov/vuln/detail/CVE-2014-3207 > > > Kind regards, > > Christiaan de Die le Clercq >

[Sks-devel] Inclusion in membership file to peer

2018-01-09 Thread Eric Germann
. I see 4825666 keys loaded. For operational issues, please contact me directly. sks-cmh.semperen.com 11370 # ekgermann@semperen.com0x89ED36B3515A211B639060A9E30D9B9B3EBFF1A1 Thank you! Eric Germann signature.asc Description: Message signed with OpenPGP

[Sks-devel] Underserved areas?

2018-01-10 Thread Eric Germann
Colleagues, As you may have noticed, I’ve spun up several SKS servers over the last several days. These are hosted in AWS regions. So far, they’re up in: Ohio,US Mumbai,IN Other available regions include: Northern Virginia, US Oregon, US Northern California, US Montreal, CA Sao Paulo, BR

[Sks-devel] Krisitian?

2018-01-17 Thread Eric Germann
Good morning, Does anyone know if Kristian still maintains his site and the signing service for CSR’s for four sites? Also, updating the Tor and bandwidth data for each of the respective servers. I’ve sent several emails to several addresses listed in the key and heard nothing back nor seen

[Sks-devel] Peers for two additional SKS servers (Tokyo and London)

2018-01-11 Thread Eric Germann
@semperen.com0x89ED36B3515A211B639060A9E30D9B9B3EBFF1A1 Thank you! Eric Germann signature.asc Description: Message signed with OpenPGP ___ Sks-devel mailing list Sks-devel@nongnu.org https://lists.nongnu.org/mailman/listinfo/sks-devel

[Sks-devel] Peering availability for sks-*.semperen.com

2018-02-04 Thread Eric Germann
We have finished the deployment of a fleet of SKS servers located in AWS datacenters globally. Some you have seen before, but the complete list is below. If you are interested in peering with any or all of the fleet, please drop me a note with you info and which of the server(s) you’d like to

[Sks-devel] Machine readable version of SKS key server stats

2018-02-14 Thread Eric Germann
Good evening all, Are there any docs anywhere regarding the HTTP request that can be made on port 11371? Specifically, wondering if /pks/lookup?op=stats can return a machine readable format (JSON, XML, etc) for server stats, etc. Thanks for any pointers. EKG signature.asc Description:

Re: [Sks-devel] New Keyservers and Dumps

2018-08-23 Thread Eric Germann
ian Fiskerstrand > wrote: > > On 08/20/2018 03:26 PM, Eric Germann wrote: >> I’ve reworked the keyserver fleet we’d previously deployed and made a blog >> post [1] about it. > > Are the servers clustered in any way? In my experience each site needs > at least 3 nodes t

[Sks-devel] New Keyservers and Dumps

2018-08-20 Thread Eric Germann
I’ve reworked the keyserver fleet we’d previously deployed and made a blog post [1] about it. If you’d peered with me before, those have most likely been cleaned out as I diversified the fleet across different cities and rebuilt them. They are TLS enabled, but just with a standard cert, not