msys2 / MSYS2-keyring

Master and packager keys for MSYS2 official Pacman repositories
23 stars 9 forks source link

Consider WKD (Web Key Directory) for our keys #13

Open lazka opened 2 years ago

lazka commented 2 years ago

Instead of using the keyserver we would host the keys ourselves. https://wiki.gnupg.org/WKD

Background: https://bugs.archlinux.org/task/63171

Biswa96 commented 2 years ago

Thanks for sharing the details. The threads in that bug report are awesome. Just out of curiosity, I have some queries.

lazka commented 2 years ago

From what I understand it's just a static website with a certain structure. So yes, very(?), yes, no.

lazka commented 2 years ago

The main challenge would be to get Alexey to sign our keys again, I think.

jeremyd2019 commented 2 years ago

I've set WKD up a couple of times. It is a static website. Most of the spec actually deals with automated key submission/updates, and can be ignored if you don't care about that. The only bit that you need to do is that you MUST publish a policy file, but it can be empty if you don't support submission.

lazka commented 2 years ago

Had a short talk with David yesterday and he's OK if we try this.

Also had a very short exchange with Alexey, he's reachable, but very bussy as always :)

jeremyd2019 commented 2 years ago

If you decide to do this, I have some experience setting this up, over multiple revisions of the spec, if you want advice on how to do it in a way that complies with as many revisions as possible (or you can just conform to the latest revision, hosting files in https://openpgpkey.msys2.org/.well-known/openpgpkey/msys2.org/..., since it could be safely assumed that the consumer is a recent version of GnuPG),