Re: [Sks-devel] HKPS certificate

2015-05-17 Thread Benny Baumann
won't get domains outside your organization included in certificates. But this limitation could be resolved with a CPS change introducing support for HA server pools - which might be of interest outside the SKS pool. Christian Am 16.05.2015 um 23:36 schrieb Benny Baumann: Which lead

Re: [Sks-devel] HKPS certificate

2015-05-16 Thread Benny Baumann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, Am 14.05.2015 um 13:02 schrieb Christiaan de Die le Clercq: Hi! I am wondering if I can still get a certificate for keys.techwolf12.nl, my server has been stable for over 3 months now and I would like to add an extra layer of security.

[Sks-devel] HPKS Certificates and Revokation?

2014-05-08 Thread Benny Baumann
Hi folks, hi Kristian, I just had a review of my cert after I got hinted on a small, but essential problem with the HPKS certificates: They contain no revokation information. Neither CRL nor OCSP. Thus even IF Kristian was going to revoke them, nobody could ever notice (from the certificates

Re: [Sks-devel] old certificates

2014-04-29 Thread Benny Baumann
Hi, Am 29.04.2014 12:52, schrieb Kiss Gabor (Bitman): Dear all, A quick scan of certificates used by current HKPS pool members shows that the following servers have pre-heartbleed certificate: a.keyserver.pki.scientia.net Aug 4 15:32:48 2013 GMT key.adeti.org

Re: [Sks-devel] Problem solved - Looking for further peers for 78.47.150.61

2014-04-27 Thread Benny Baumann
Hi, do you happen to have a FQDN for your server? Also please provide the Long Key ID or the full fingerprint for your contact key if possible. Regards, BenBE. Am 27.04.2014 00:55, schrieb Matthias Schreiber: Hello everyone, finally I could manage to solve the DB problems I faced. It turned

Re: [Sks-devel] Heartbleed ans HKPS pool

2014-04-10 Thread Benny Baumann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi Folks, Am 09.04.2014 17:38, schrieb Kiss Gabor (Bitman): Folks, Do not forget that all hkps.pool.sks-keyservers.net certificates should be revoked and replaced after fixing openssl Heartbleed Bug on vulnerable key servers. (Including

Re: [Sks-devel] HKPS SSL Ciphers

2014-02-11 Thread Benny Baumann
Hi guys, Am 11.02.2014 14:16, schrieb Stephan Seitz: Hi guys, since I've recently checked (and understood :) ) the difference of SSL ciphers, I've build up a cypherlist which is currently used on keyserver.secretresearchfacility.com (part of hkps pool) The following syntax is for Apache,

Re: [Sks-devel] Tuning

2014-02-11 Thread Benny Baumann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, Am 11.02.2014 16:59, schrieb Kristian Fiskerstrand: On 02/11/2014 04:53 PM, Daniel Kahn Gillmor wrote: On 02/11/2014 10:48 AM, Kristian Fiskerstrand wrote: By default stats are updated once a day, for more than this you need to send a

Re: [Sks-devel] Tuning

2014-02-11 Thread Benny Baumann
Hi, Am 11.02.2014 20:19, schrieb Daniel Kahn Gillmor: On 02/11/2014 01:58 PM, Benny Baumann wrote: Am 11.02.2014 16:59, schrieb Kristian Fiskerstrand: Unless you run it in a clustered setup where the different members calculate it on different times and the frontend passes the request

[Sks-devel] Protocol Details for HKP\HKPS\Gossip

2014-02-09 Thread Benny Baumann
Hi folks, because I know this might get a bit complicated let's split this in 3 parts: 1. HKP: AFAIK this is based on HTTP/1.0, but is there any documentation on what possible calls could arrive at the server (in the logs I noticed /pks/lookup, /pks/hashquery and /pks/add, but it's somehow a bit