Skip to content

Integrate PGP Key into keys.openpgp.org #5643

Description

@maltfield

Please verify your email address with keys.openpgp.org so that users can download your key.

Problem

It's great that your project signs your releases with pgp using key = [email protected].

Unfortunately, it's not well documented which key is used to sign your releases. This key should be available for download on many key servers and well-integrated into the Web-of-Trust.

It's great that I can find your key on Ubuntu's keyservers

However, it's trivial for an attacker to create another key with uid = [email protected]. As such, your documentation should specify the full fingerprint of the key, for which an attacker cannot create a conflicting key = 3B9191625F3B1F1BF5DD3B47673A02042F6B6B7F.

(See also related ticket wp-cli/handbook#584)

Unfortunately, certificate spamming attacks have made old sks keyservers vulnerable. It's recommended that you use a modern keyserver that strips signature data:

I see your key has been uploaded to this server, but the email address was never verified. Therefore, users cannot download your key from the above keyserver.

Error: Verifying your email address…

Solution

Please verify your email address with keys.openpgp.org

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions