Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 1 Oct 2003 17:48:53 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Paul Murphy <pnmurphy@cogeco.ca>
Cc:        Kris Kennaway <kris@obsecurity.org>
Subject:   Re: Mail-list PGP Keys
Message-ID:  <20031002004853.GA15441@rot13.obsecurity.org>
In-Reply-To: <20031001185105.197701ef.pnmurphy@cogeco.ca>
References:  <XFMail.20031001140907.ah46@mlz.us> <200310011315.05004.ecrist@tech-con-inc.com> <20031001182729.GA14111@rot13.obsecurity.org> <20031001185105.197701ef.pnmurphy@cogeco.ca>

next in thread | previous in thread | raw e-mail | index | archive | help

--pf9I7BMVVzbSWLtt
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Oct 01, 2003 at 06:51:05PM -0400, Paul Murphy wrote:
> On Wed, 1 Oct 2003 11:27:29 -0700
> Kris Kennaway <kris@obsecurity.org> wrote:
>=20
> > On Wed, Oct 01, 2003 at 01:15:03PM -0500, Eric F Crist wrote:
> >=20
> > > How do I submit my keys?
> > >=20
> > > TIA
> >=20
> > 1) Don't middle-post
> >=20
> > 2) Read the URL provided.
> >=20
> > > > > Just a little pet peeve.
> > > >
> > > > AFAIK, most people use http://pgp.mit.edu to submit their keys.
> >=20
> > Kris
>=20
>  FWIW, have you checked _your_ pgp key lately, I always get:
>=20
> BAD signature from "Kris Kennaway <kris@citusc.usc.edu>"
>                 aka "Kris Kennaway <kris@FreeBSD.org>"
>                 aka "Kris Kennaway <kris@obsecurity.org>"

The copy in one of the PGP key networks is corrupted, and it's a
vulnerability in the keyserver system that there is no way provided to
correct this.  AFAICT you can corrupt any given key in the database by
uploading a mis-formatted signature to it, which the key servers do
not appear to adequately guard against (this is how mine became
corrupted).  Fetch the uncorrupted copy from the FreeBSD handbook or
my .plan on freebsd.org.

Kris

--pf9I7BMVVzbSWLtt
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)

iD8DBQE/e3X1Wry0BWjoQKURAsSfAKDwrDDYztL87q5MnGhpw3V/DfHoLgCgikIb
7IEraGI16W4/MHj6XYteYgk=
=xyfH
-----END PGP SIGNATURE-----

--pf9I7BMVVzbSWLtt--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20031002004853.GA15441>