Skip to content
This repository was archived by the owner on Mar 5, 2025. It is now read-only.

Improve GPG key handling#61

Open
stefanor wants to merge 2 commits into
rapid7:masterfrom
stefanor:full-fingerprint
Open

Improve GPG key handling#61
stefanor wants to merge 2 commits into
rapid7:masterfrom
stefanor:full-fingerprint

Conversation

@stefanor

Copy link
Copy Markdown
  1. Specify the full key fingerprint. (avoiding evil32)
  2. Use a HA keyserver pool.

stefanor added 2 commits June 15, 2018 08:36
8-byte key-ids are trivially brute-forceable these days. In fact most
keys in the strong set have had brute-force-copies uploaded to
keyservers.

See: https://evil32.com/
Currently the MIT keyserver is unavailable. I've had good results with
using this pool in Chef.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant