Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-14 Thread Robert J. Hansen
On 9/14/2013 3:08 PM, Daniel Kahn Gillmor wrote: Let me also be clearer about why i find this bug serious... I am still not seeing why this bug is serious. It still seems to be a case of mountains and molehills. I have told numerous people that the keyserver network will not propagate

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-14 Thread Daniel Kahn Gillmor
On 09/14/2013 05:00 PM, Robert J. Hansen wrote: [dkg wrote]: I have told numerous people that the keyserver network will not propagate local signatures. This is true. No, unfortunately, it is not true in any way for SKS 1.1.4 (and probably earlier versions, though i have not tested). In

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-14 Thread Christoph Anton Mitterer
On Fri, 2013-09-13 at 20:33 -0400, Robert J. Hansen wrote: In what bizarro universe is SKS an implementation of RFC4880? Well it uses/processes OpenPGP message formats (i.e. by storing/publishing them). ___ Sks-devel mailing list Sks-devel@nongnu.org

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-14 Thread John Clizbe
Daniel Kahn Gillmor wrote: On 09/14/2013 05:00 PM, Robert J. Hansen wrote: [dkg wrote]: I have told numerous people that the keyserver network will not propagate local signatures. This is true. No, unfortunately, it is not true in any way for SKS 1.1.4 (and probably earlier versions,

Re: [Sks-devel] SKS should not accept or replay non-exportable certifications

2013-09-14 Thread Jason Harris
On Sat, Sep 14, 2013 at 08:46:05PM -0500, John Clizbe wrote: As I see it, we have two related problems here, both involving the no-export signature flag: 2) JimBob lsigns his own key, creating a non-exportable selfsig then delsigs all of the exportable selfsigs. This is shooting oneself in