Keyserver thoughts (was Re: How to update a self-signature?)

David Shaw <dshaw@akamai.com> Tue, 28 August 2001 13:57 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id JAA10506 for <openpgp-archive@odin.ietf.org>; Tue, 28 Aug 2001 09:57:22 -0400 (EDT)
Received: by above.proper.com (8.11.6/8.11.3) id f7SDdHP22031 for ietf-openpgp-bks; Tue, 28 Aug 2001 06:39:17 -0700 (PDT)
Received: from claude.kendall.akamai.com (walrus.ne.mediaone.net [65.96.217.45]) by above.proper.com (8.11.6/8.11.3) with ESMTP id f7SDdFD22027 for <ietf-openpgp@imc.org>; Tue, 28 Aug 2001 06:39:16 -0700 (PDT)
Received: (from dshaw@localhost) by claude.kendall.akamai.com (8.9.3/8.9.3) id JAA09723 for ietf-openpgp@imc.org; Tue, 28 Aug 2001 09:38:49 -0400
Date: Tue, 28 Aug 2001 09:38:49 -0400
From: David Shaw <dshaw@akamai.com>
To: ietf-openpgp@imc.org
Subject: Keyserver thoughts (was Re: How to update a self-signature?)
Message-ID: <20010828093848.A9190@akamai.com>
Mail-Followup-To: ietf-openpgp@imc.org
References: <p05100303b7aaf65aff68@[192.168.1.180]> <008601c12c52$1b6181c0$c23fa8c0@transarc.ibm.com> <p0510031fb7ab945664e5@[192.168.1.180]> <002b01c12d74$b105fb20$c23fa8c0@transarc.ibm.com> <20010827094849.A26895@akamai.com> <87y9o5imcn.fsf@alberti.gnupg.de> <20010827123540.A834@akamai.com> <87y9o5gwzj.fsf@alberti.gnupg.de> <20010827165900.D834@akamai.com> <87d75ghbhv.fsf@alberti.gnupg.de>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <87d75ghbhv.fsf@alberti.gnupg.de>; from wk@gnupg.org on Tue, Aug 28, 2001 at 09:47:24AM +0200
X-PGP-Key: 2048R/3CB3B415/4D 96 83 18 2B AF BE 45 D0 07 C4 07 51 37 B3 18
X-URL: http://www.jabberwocky.com/
X-Phase-Of-Moon: The Moon is Waxing Gibbous (76% of Full)
X-Pointless-Random-Number: 198
X-Silly-Header: It sure is.
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

On Tue, Aug 28, 2001 at 09:47:24AM +0200, Werner Koch wrote:
> 
> On Mon, 27 Aug 2001 16:59:00 -0400, David Shaw said:
> 
> > sort of sanity checking there.  Either way, I think it's safe to say
> > that incorrect clocks are out of the scope of 2440!
> 
> Keyserver may want to discard signature which are timestamped more
> than a few days in the future.  This should greatly help not to spread
> erroneous signatures.

Yes, indeed.

I've often thought it would be good if keyservers could trim keys on
the way out - leaving off invalid signatures, expired subkeys, expired
signatures, etc.

It would be optional and allow someone to request the complete key if
they want it.  Computer programs that try to be "smart" often raise
unforseen problems.

David

-- 
David Shaw          |  Technical Lead
<dshaw@akamai.com>  |  Enterprise Content Delivery
617-250-3028        |  Akamai Technologies