Clint Adams just reported:

http://bugs.debian.org/683328

----------------
This key is buggy:

http://keys.mayfirst.org/pks/lookup?op=get&search=0xED34CEABE27BAABC


Note the 0x10 and 0x13 signatures on the 4096-bit subkey; these
should not be there.

Please check the signature types and only allow signature types 0x18
and 0x28 on subkeys.  (At the very least, 0x10 through 0x13 should
be discarded).
----------------

I think his analysis is correct, although:

 0) i don't have a patch to propose, and

 1) i'm not sure how to deploy such a fix across the whole keyserver
network, since it looks to me like it would effectively appear as a
"filter" change.

any thoughts on how to address this?

        --dkg

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Sks-devel mailing list
Sks-devel@nongnu.org
https://lists.nongnu.org/mailman/listinfo/sks-devel

Reply via email to