home.social

#keyservers — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #keyservers, aggregated by home.social.

  1. First steps towards more robust sync!

    #Hockeypuck’s dataset normalisation rules (or “filters”) were updated between v2.1 and v2.2, meaning that #SKS recon did not work between #openpgp #keyservers running the older and newer versions. The keyservers could not all be updated simultaneously, and a few keyservers still run v2.1 today for compatibility reasons, so we had to find a way to prevent the network from split-braining.

    The quick and dirty solution was a small script that runs on each side of the filter discontinuity, polls for local changes, and submits them to the other side over HKP (the protocol your #PGP client uses). But this is effectively the same idea as the old PKS sync model, just over HTTP(S) instead of email. And sks-keyserver used to support PKS-over-email, so shouldn’t hockeypuck be able to do PKS-over-HTTP natively?

    The short answer is, it can! It was long intended for hockeypuck to support PKS email, but only a fraction of the necessary code was written, and there were no tests. Today, the pgpkeys test swarm has just performed its first sync using the completed PKS code, which supports *both* HTTP and email transport.

    It’s not ready for production yet though. Further testing is required, and then the second part of the PKS code can be written: automatic failover from SKS to PKS when filter mismatch is detected (and just as importantly, automatic fail*back*).

    This will mean that keyserver operators will be able in the future to upgrade across filter discontinuities without risking a split brain scenario. It should also mean that key updates submitted to the hockeypuck network could be automatically synced to @keys_openpgp_org … watch this space! 😎

    (Hockeypuck v2.3 development is kindly supported by @NGIZero Core)

  2. @DrPen
    Yes, #Tor is good but in some ways #I2P is better.

    We would like #universities to not only run Tor and I2P relays but they should also provide #keyservers, code repositories, mid-scale #internetArchives, jump services (a sort of DNS for I2P).

    We need to return to a world where universities don't just pander to the corporate world for #funding also.

    Maybe we cannot get there.

  3. @vidak
    New idea for a #song.

    "I wanna talk to you,
    I had to write something,
    But its that time again,
    When all the #keyservers are dowwwn

    (Down Down Down Oouu Oouu Oouu)"

    #techSong #skit #funny #GPG #pgp #fediLyrics