sks-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Sks-devel] "SKS is effectively running as end-of-life software at t


From: Andrew Gallagher
Subject: Re: [Sks-devel] "SKS is effectively running as end-of-life software at this point"?
Date: Wed, 6 Feb 2019 23:37:28 +0000

> On 6 Feb 2019, at 23:15, robots.txt fan <address@hidden> wrote:
> 
> To answer my first question, I guess that it is possible to implement a 
> keyserver with the same interface for GPG users that can still recon with 
> older servers. The older servers might try to send them keys that are on the 
> blacklist or are large, but the new server can reject those keys of course.

Easier said than done. There is plenty of discussion in the archives about how 
difficult this would be technically. Because you can reject a key, but then 
what happens is it just keeps trying to come back. Pretty soon there are so 
many rejected keys floating around that the network stops reconciling. Also, 
what happens if I reject certain keys and you don’t, but your only connection 
to the rest of the network is through me? Once nodes start implementing 
different policies you can go split-brain surprisingly easily. 

It’s not a simple matter of just coding it up.

A



reply via email to

[Prev in Thread] Current Thread [Next in Thread]