[Sks-devel] sks should not allow id cert packets after a subkey

2012-07-30 Thread Daniel Kahn Gillmor
Clint Adams just reported: http://bugs.debian.org/683328 This key is buggy: http://keys.mayfirst.org/pks/lookup?op=getsearch=0xED34CEABE27BAABC Note the 0x10 and 0x13 signatures on the 4096-bit subkey; these should not be there. Please check the signature types and only

Re: [Sks-devel] sks should not allow id cert packets after a subkey

2012-07-30 Thread Kristian Fiskerstrand
On 2012-07-31 00:32, Daniel Kahn Gillmor wrote: I think his analysis is correct, although: 0) i don't have a patch to propose, and 1) i'm not sure how to deploy such a fix across the whole keyserver network, since it looks to me like it would effectively appear as a filter change.