[Sks-devel] New wiki page: TLS Configuration

2018-03-24 Thread Phil Pennock
Folks, https://bitbucket.org/skskeyserver/sks-keyserver/wiki/TLS%20Configuration New wiki page. Explains the issues with TLS configuration, says what should be done, and has a section for walk-throughs on a per-frontend-server basis. That section has been populated with one initial

Re: [Sks-devel] SKS apocalypse mitigation

2018-03-24 Thread Phil Pennock
On 2018-03-24 at 19:01 +0100, Kristian Fiskerstrand wrote: > I agree with this as well, UAT generally have very limited value, so if > we introduce a filter to skip all UATs I'm all fine with making that a > requirement across severs in sks-keyservers.net pools. That isn't > something that

Re: [Sks-devel] SKS apocalypse mitigation

2018-03-24 Thread Kristian Fiskerstrand
[I previously responded to a specific message not related to this thread but none the less... ] On 03/23/2018 03:02 PM, Daniel Kahn Gillmor wrote: > On Fri 2018-03-23 11:10:49 +, Andrew Gallagher wrote: >> Updating the sets on each side is outside the scope of the recon >> algorithm, and in

Re: [Sks-devel] SKS apocalypse mitigation

2018-03-24 Thread Alin Anton
Hello, Horrible topic, but base64 images or something could also work for regular bank transfers. One could use the image property to store blacklist data, regular expressions, etc. That key would be a regular one but with a noisy picture. Maybe a web of DIStrust is also a good idea to vote