sks-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Sks-devel] Inconsistency on vindex page with machine-readable flag set


From: Paul M Furley
Subject: [Sks-devel] Inconsistency on vindex page with machine-readable flag set or unset?
Date: Wed, 9 May 2018 19:11:09 +0100
User-agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0

Hi folks, I'd appreciate your input, I'm not sure if this is a bug in
SKS or a fault in my understanding.

(Example URLs used with permission of the Matthias)

Have a look at the output of this keyserver `vindex` page with the
"machine readable" flag set[1] — note `&options=mr`:

```
info:1:1
pub:042C7F2A344DA4C499F10AC76E3A6C3BC75C6BE0:1:4096:1462783933:1525855933:
uid:Matthias Lang <address@hidden>:1523297701::

```

See the last number on the first line, which indicates the key's expiry
date. The timestamp translates to 05/09/2018 @ 8:52am (UTC).

I believce that URL is what `gpg --search` uses, and as you can see, GPG
confirms the (incorrect) expiry:

```
gpg --keyserver keyserver.paulfurley.com --search 0x6E3A6C3BC75C6BE0
gpg: data source: http://keyserver.paulfurley.com:11371
(1)     Matthias Lang <address@hidden>
          4096 bit RSA key 0x6E3A6C3BC75C6BE0, created: 2016-05-09, expires:
2018-05-09
```

Now looking at the same vindex page without machine-readable set[2]:


```
pub  4096R/C75C6BE0 2016-05-09

uid Matthias Lang <address@hidden>
sig  sig3  C75C6BE0 2016-05-09 __________ 2018-05-09 [selfsig]
sig  sig3  C75C6BE0 2018-04-09 __________ __________ [selfsig]

sub  4096R/3C483678 2016-05-09
sig sbind  C75C6BE0 2016-05-09 __________ 2018-05-09 []
sig sbind  C75C6BE0 2018-04-09 __________ 2019-04-09 []

sub  4096R/90804041 2016-05-09
sig sbind  C75C6BE0 2016-05-09 __________ 2018-05-09 []
sig sbind  C75C6BE0 2018-04-09 __________ 2019-04-09 []
```

It seems there used to be an expiry (the one referenced above) but the
most recent selfsig removed the expiry date.

From my reading of this vindex page, the key is not expiring on
2018-05-09, as the previous URL suggests.

So what am I missing? Why is the machine-readable page giving that
2018-05-09 expiry timestamp?

Kind regards,

Paul

[1]
https://keyserver.paulfurley.com/pks/lookup?search=0x042C7F2A344DA4C499F10AC76E3A6C3BC75C6BE0&op=vindex&options=mr

[2]
https://keyserver.paulfurley.com/pks/lookup?search=0x042C7F2A344DA4C499F10AC76E3A6C3BC75C6BE0&op=vindex

Attachment: signature.asc
Description: OpenPGP digital signature


reply via email to

[Prev in Thread] Current Thread [Next in Thread]