I¹m busily signing keys, but when I¹ve attempted to either upload to or download from hkp://ksp.mdcc.cx, I get the error gpgkeys: HTTP post error 7: couldn't connect to host I was able to pull most people¹s keys from wwwkeys.at.pgp.net, and I¹ve been uploading signed ones to there for the moment. There are, however, a fair number of keys which I¹ve been unable to find on that server or other accessible ones. Can anyone see whether ksp.mdcc.cx needs to be kicked or something...? Thanks to all who braved the cold to turn out this afternoon!
On Sun, Feb 08, 2009 at 11:03:27AM -0800, David Lefty Schlesinger wrote:
I¹m busily signing keys, but when I¹ve attempted to either upload to or download from hkp://ksp.mdcc.cx, I get the error
gpgkeys: HTTP post error 7: couldn't connect to host
I was able to pull most people¹s keys from wwwkeys.at.pgp.net, and I¹ve been uploading signed ones to there for the moment. There are, however, a fair number of keys which I¹ve been unable to find on that server or other accessible ones. Can anyone see whether ksp.mdcc.cx needs to be kicked or something...?
You can just usre the keyring which is at: http://ksp.mdcc.cx/files/ksp-fosdem2009.keyring.asc.bz2 Kurt
Kurt Roeckx ha scritto:
You can just usre the keyring which is at: http://ksp.mdcc.cx/files/ksp-fosdem2009.keyring.asc.bz2
Actually, I'm triing to figure out how to use caff to sign the keys. Which command should I give so caff ask for every key in the asc file if I want to sign it or not and make it send the key via e-mail to the key owner automatically (for the last one, I think I have to add "-m yes" to the command, but I can't imagine which smtp server caff will use...)? What about the person who decided not to upload the key to the keyserver and gave me his fingerprint on paper? Sorry for these stupid questions, but I'm new to gpg and keys in general. bye, Iacopo
* Iacopo Benesperi <iacopo.benesperi@mozillaitalia.org> wrote:
Kurt Roeckx ha scritto:
You can just usre the keyring which is at: http://ksp.mdcc.cx/files/ksp-fosdem2009.keyring.asc.bz2
Actually, I'm triing to figure out how to use caff to sign the keys. Which command should I give so caff ask for every key in the asc file if I want to sign it or not and make it send the key via e-mail to the key owner automatically (for the last one, I think I have to add "-m yes" to the command, but I can't imagine which smtp server caff will use...)?
Read the manpage :-) I've successfully been using the follwing approach: (edit the list of participants and get rid of the no-shows) cat ksp-lt2k6.txt | grep pub | awk -F '/' '{ print $2; }' | \ awk '{print $1; }' > ~/tmp.keyprints.txt caff -m -u mykeyid1,mykeyid2,mykeyid3 ` cat ~/tmp.keyprints.txt` I adapted .caffrc to my needs, it's commented & self-explanatory As for the smtp caff is using ... well, if you use postfix you need to have canonicals enabled via /etc/postfix/canonical user@your.local.setup valid@emailaddress.com f.e. like listed in your key id; and dont forget to include sender_canonical_maps = hash:/etc/postfix/canonical in /etc/postfix/main.cf
What about the person who decided not to upload the key to the keyserver and gave me his fingerprint on paper?
you can either add the fingerprint(s) to the edited list of participants and then fire up caff or do it all manually. Generally speaking, many people prefer to have their signatures mailed to them; that's what caff does. The uploading of signed keys to public keyservers is widely regarded as bad netiquette. If you have further questions regarding keys, feel free to contact me off list. Please contact your distribution community for setting up a mailserver, f.e. (I offer assistance with postfix on slackware though). HTH -- left blank, right bald
markus reichelt ha scritto:
Read the manpage :-)
Yeah, you're right. So, I edited my .caffrc adding (in addition to the default created one): $CONFIG{'local-user'} = [ qw{mykey} ]; $CONFIG{'mailer-send'} = [ 'smtp', Server => 'uit.telenet.be' ]; $CONFIG{'keyserver'} = 'ksp.mdcc.cx'; then I gave this command (after preparing the file the way you told me): caff -m yes --key-file ksp-fosdem2009.keyring.asc ` cat keyprints.txt` But it says that the import failed for some keys (not all keys, I checked), and asks me if I want to continue anyway. Why it can't import some keys? What should I do with these? Iacopo
I've signed keys for all the folks I met today, and uploaded them to wwwkeys.at.pgp.net... Please refresh your key from there if we met this afternoon. Also, I've received signed keys in the mail from a couple of folks, but when I try to import them using gpg --import {{filename}} I'm receiving the error gpg: no valid OpenPGP data found. gpg: Total number processed: 0 Anyone have any clues as to what the issue might be...?
* David Lefty Schlesinger <lefty@access-company.com> wrote:
Also, I've received signed keys in the mail from a couple of folks, but when I try to import them using
gpg --import {{filename}}
I'm receiving the error
gpg: no valid OpenPGP data found. gpg: Total number processed: 0
Anyone have any clues as to what the issue might be...?
Are you by any chance using the encrypted file? Usually the signed key is sent encrypted and needs to be decrypted, showing the key sig as attachement. That's what you want. -- left blank, right bald
Is it possible for me to use seahorse in Ubuntu to sign the keys and upload them to ksp.mdcc.cx? //Matthias Andersson
On Sun, 2009-02-08 at 11:03 -0800, David "Lefty" Schlesinger wrote:
I was able to pull most people’s keys from wwwkeys.at.pgp.net, and I’ve been uploading signed ones to there for the moment.
I should note that it's not generally considered good form to upload signatures. It's better to email the signed key to the owner of the key and let them decide what to do with it. Dan
Guys, Thanks very much for this thread -- it helped me setting up my own home signing event :) I think I was successful signing and emailing the keys. Unfortunately I have not redirected the output from caff to a file so I am unable to check if everything was o.k. The public IDs were reported to have a problem (see last line): [NOTICE] got unknown reply from gpg: [GNUPG:] KEYEXPIRED 1196525878 [NOTICE] got unknown reply from gpg: [GNUPG:] SIGEXPIRED deprecated-use-keyexpired-instead [NOTICE] Imported key D273757CD89E21A1610909D3618374FF is a version 3 key. Version 3 keys are obsolete, should not be used, and are not and will not be properly supported. [NOTICE] Imported key AE5A47405AA0D6158E5444AA8DDD6EBD is a version 3 key. Version 3 keys are obsolete, should not be used, and are not and will not be properly supported. [NOTICE] got unknown reply from gpg: [GNUPG:] KEYEXPIRED 1223736272 [NOTICE] got unknown reply from gpg: [GNUPG:] SIGEXPIRED deprecated-use-keyexpired-instead [NOTICE] Import failed for: 08782930 92EF5425 FA18A639. (Or maybe it's one of those ugly v3 keys?) These are numbers 4, 183 and 184. Not sure what the problem might be. Apart from that according to the exim log it sent out emails, I've seen occassional errors for some email address. Some of the also bounced back as they were non-existent. To cut the long story short let me know if I need to do anything for you :) I have uploaded my public key to http://wwwkeys.eu.pgp.net/ but you should be able to find it in the keyring downloaded from ksp.mdcc.cx. Cheers, Gabor On Mon, Feb 9, 2009 at 4:08 PM, Daniel Watkins <daniel@daniel-watkins.co.uk> wrote:
On Sun, 2009-02-08 at 11:03 -0800, David "Lefty" Schlesinger wrote:
I was able to pull most people's keys from wwwkeys.at.pgp.net, and I've been uploading signed ones to there for the moment.
I should note that it's not generally considered good form to upload signatures. It's better to email the signed key to the owner of the key and let them decide what to do with it.
Dan
_______________________________________________ FOSDEM mailing list FOSDEM@lists.fosdem.org http://lists.fosdem.org/mailman/listinfo/fosdem
http://policy.pdd.de/ "The v3 key with ID 0xb02d3a75 is only used for correspondence with people unable to use the current v4 keys (i.e. users of PGP 2.6.x); generally this key does not need to be signed unless you are using a v3 key, since signatures on v3 keys made with v4 keys are not useful to PGP 2.6.x users." It seems to be true for two of them (183 and 184), not sure about the third one. The order of the messages seems to be mixed up for me.. Gabor On Tue, Feb 10, 2009 at 11:21 PM, Matthias Andersson <matthias.andersson@gmail.com> wrote:
I get the same errors with those exact keys... Any solutions? _______________________________________________ FOSDEM mailing list FOSDEM@lists.fosdem.org http://lists.fosdem.org/mailman/listinfo/fosdem
Back to the keyserver issues, I decided to sign and send keys by hand. I imported the key from the asc file, but these: DA1406A6 07041A1F 83566359 702407F7 21D7DDA4 1B9CC2EA were not present. So I tried to download them from the keyserver, but I get the same error of David: $ gpg --keyserver ksp.mdcc.cx --recv-key 1B9CC2EA gpg: requesting key 1B9CC2EA from hkp server ksp.mdcc.cx ?: ksp.mdcc.cx: Connection refused gpgkeys: HTTP fetch error 7: couldn't connect: Connection refused How can I do to import these key? Using or not caff, you must have the keys to sign them. bye, Iacopo
Hi Iacopo, * Iacopo Benesperi <iacopo.benesperi@mozillaitalia.org> [13.02.2009 17.45.15 +0100]:
DA1406A6 07041A1F 83566359 702407F7 21D7DDA4 1B9CC2EA
$ gpg --keyserver ksp.mdcc.cx --recv-key 1B9CC2EA
This server _only_ supports the post-methode which is useful for collecting keys. Try gpg --keyserver subkeys.pgp.net --recv-key KEY-ID instead. On the other hand you can bunzip2 ksp-fosdem2009.keyring.asc.bz2 and import the bunch of keys with: gpg --import ksp-fosdem2009.keyring.asc afterwards. Thats all :)
How can I do to import these key? Using or not caff, you must have the keys to sign them.
bye, Iacopo
Happy signing! Viele Grüße, Karlheinz Geyer -- ------------------------------------------------------------------------ /~ Q///~ pub 1024D/AAE6022E 2004-12-07 (;#) FPR 7A39 2F67 8CAE 262E 64FD 8A10 2F95 1508 AAE6 022E /_\ uid Karlheinz Geyer (TUD) <geyerk.fv.tu@nds.tu-darmstadt.de> I I uid Karlheinz Geyer (RBOS) <karlheinz.geyer@lhsystems.com> ------------------------------------------------------------------------
It's me again ...
How can I do to import these key? Using or not caff, you must have the keys to sign them.
Point your browser to http://ksp.mdcc.cx/ and get the keyring ksp-fosdem2009.keyring.asc.bz2 from there. Section "When you're back home" Viele Grüße, Karlheinz -- ------------------------------------------------------------------------ /~ Q///~ pub 1024D/AAE6022E 2004-12-07 (;#) FPR 7A39 2F67 8CAE 262E 64FD 8A10 2F95 1508 AAE6 022E /_\ uid Karlheinz Geyer (TUD) <geyerk.fv.tu@nds.tu-darmstadt.de> I I uid Karlheinz Geyer (RBOS) <karlheinz.geyer@lhsystems.com> ------------------------------------------------------------------------
participants (8)
-
Daniel Watkins -
David "Lefty" Schlesinger -
Gabor Kuti -
Iacopo Benesperi -
Karlheinz Geyer -
Kurt Roeckx -
markus reichelt -
Matthias Andersson