Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #205759 > unrolled thread

dirmngr, can't live with it, can't live without it

Started byJim Popovitch <jim@k4vqc.com>
First post2019-02-26 13:00 +0100
Last post2019-02-28 18:50 +0100
Articles 12 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-26 13:00 +0100
    Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-26 20:40 +0100
      Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-26 21:30 +0100
        Re: dirmngr, can't live with it, can't live without it Tixy <tixy@yxit.co.uk> - 2019-02-26 22:10 +0100
          Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-27 01:50 +0100
        Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-27 00:50 +0100
          Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-27 01:40 +0100
            Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-27 08:10 +0100
              Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 12:20 +0100
                Re: dirmngr, can't live with it, can't live without it Curt <curty@free.fr> - 2019-02-28 14:00 +0100
                  Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 15:20 +0100
                    Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 18:50 +0100

#205759 — dirmngr, can't live with it, can't live without it

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-26 13:00 +0100
Subjectdirmngr, can't live with it, can't live without it
Message-ID<xvJyV-7av-5@gated-at.bofh.it>
OK d-u+AEA-l.d.o,

What's up with dirmngr?  If dirmngr is installed Evolution often takes
ages to open signed emails.  If dirmngr is not installed then (according
to p.d.o/buster/dirmngr) +ACI-the parts of the GnuPG suite that try to
interact with the network will fail+ACI

How can dirmngr be so tightly integrated but work so poorly querying
services?  /r

-Jim P. 

[toc] | [next] | [standalone]


#205764

Fromdeloptes <deloptes@gmail.com>
Date2019-02-26 20:40 +0100
Message-ID<xvQK6-3jG-7@gated-at.bofh.it>
In reply to#205759
Jim Popovitch wrote:

> What's up with dirmngr?  If dirmngr is installed Evolution often takes
> ages to open signed emails.  If dirmngr is not installed then (according
> to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to
> interact with the network will fail"
> 
> How can dirmngr be so tightly integrated but work so poorly querying
> services?  /r

why should it be dirmngrs fault? perhaps it is a kind of buster or other
issue.

Try to find out where the waiting is coming from and post back. For example
waiting for keyserver to respond or similar or waiting for something to
time out.

regards

[toc] | [prev] | [next] | [standalone]


#205765

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-26 21:30 +0100
Message-ID<xvRwt-3R7-11@gated-at.bofh.it>
In reply to#205764
On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote:
> Jim Popovitch wrote:
> 
> > What's up with dirmngr?  If dirmngr is installed Evolution often
> > takes
> > ages to open signed emails.  If dirmngr is not installed then
> > (according
> > to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to
> > interact with the network will fail"
> > 
> > How can dirmngr be so tightly integrated but work so poorly
> > querying
> > services?  /r
> 
> why should it be dirmngrs fault? perhaps it is a kind of buster or
> other issue.
> 
> Try to find out where the waiting is coming from and post back. For
> example waiting for keyserver to respond or similar or waiting for
> something to time out.

Glad you asked!

dirmngr uses sks-keyservers.net which has at least one NS with issues:
https://ednscomp.isc.org/ednscomp/0f65feeaa7

But more to the point, It's not an easy program to debug....

Following man page, I created ~/.gnupg/dirmngr.conf and populated it
with:
  verbose
  debug-level expert
  keyserver na.pool.sks-keyservers.net
  disable-ipv6
  disable-ldap
  log-file ~/dirmngr.log
  allow-ocsp

and then I fired up Evolution and opened emails with gpg sigs, but
still no data in the file ~/dirmngr.log.  :-(

What I suspect the problem to be, and what is alluded to on the sks-keyservers status page, is that there is a big inconsistency/availability with their servers (they have more off-pool servers listed than in-pool).  Obviously it's a freebie so complaints seem childish, but it is an important service.. just like pool.ntp.org (which ironically Debian has taken responsibility for at least sanitizing that with debian.pool.ntp.org)

-Jim P.

[toc] | [prev] | [next] | [standalone]


#205766

FromTixy <tixy@yxit.co.uk>
Date2019-02-26 22:10 +0100
Message-ID<xvS9b-4lO-11@gated-at.bofh.it>
In reply to#205765
On Tue, 2019-02-26 at 15:21 -0500, Jim Popovitch wrote:
> But more to the point, It's not an easy program to debug....
> 
> Following man page, I created ~/.gnupg/dirmngr.conf and populated it
> with:
>   verbose
>   debug-level expert
>   keyserver na.pool.sks-keyservers.net
>   disable-ipv6
>   disable-ldap
>   log-file ~/dirmngr.log
>   allow-ocsp
> 
> and then I fired up Evolution and opened emails with gpg sigs, but
> still no data in the file ~/dirmngr.log.  :-(

I've no idea what dirmngr is, but have you tried specifying a proper
path for 'log-file' rather than using a tilde (~)? Perhaps whatever
parses dirmngr.conf doesn't treat a tilde as special like shells do.

-- 
Tixy

[toc] | [prev] | [next] | [standalone]


#205770

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-27 01:50 +0100
Message-ID<xvVA5-6m1-3@gated-at.bofh.it>
In reply to#205766
On Tue, 2019-02-26 at 21:01 +0000, Tixy wrote:
> On Tue, 2019-02-26 at 15:21 -0500, Jim Popovitch wrote:
> > But more to the point, It's not an easy program to debug....
> > 
> > Following man page, I created ~/.gnupg/dirmngr.conf and populated
> > it
> > with:
> >   verbose
> >   debug-level expert
> >   keyserver na.pool.sks-keyservers.net
> >   disable-ipv6
> >   disable-ldap
> >   log-file ~/dirmngr.log
> >   allow-ocsp
> > 
> > and then I fired up Evolution and opened emails with gpg sigs, but
> > still no data in the file ~/dirmngr.log.  :-(
> 
> I've no idea what dirmngr is, but have you tried specifying a proper
> path for 'log-file' rather than using a tilde (~)? Perhaps whatever
> parses dirmngr.conf doesn't treat a tilde as special like shells do.

dirmngr (Directory Manager?) is an agent produced by the GnuPGP folks
who also have something called gpg-agent.  Why one is called an agent
and the other a mngr (manager) is unknown to me.

The log file eventually started dumping some stuff.  Here it is for
those interested:  http://paste.debian.net/plainh/16c494c3

-Jim P.

[toc] | [prev] | [next] | [standalone]


#205768

Fromdeloptes <deloptes@gmail.com>
Date2019-02-27 00:50 +0100
Message-ID<xvUE2-5LG-1@gated-at.bofh.it>
In reply to#205765
Jim Popovitch wrote:

> On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote:
>> Jim Popovitch wrote:
>> 
>> > What's up with dirmngr?  If dirmngr is installed Evolution often
>> > takes
>> > ages to open signed emails.  If dirmngr is not installed then
>> > (according
>> > to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to
>> > interact with the network will fail"
>> > 
>> > How can dirmngr be so tightly integrated but work so poorly
>> > querying
>> > services?  /r
>> 
>> why should it be dirmngrs fault? perhaps it is a kind of buster or
>> other issue.
>> 
>> Try to find out where the waiting is coming from and post back. For
>> example waiting for keyserver to respond or similar or waiting for
>> something to time out.
> 
> Glad you asked!
> 
> dirmngr uses sks-keyservers.net which has at least one NS with issues:
> https://ednscomp.isc.org/ednscomp/0f65feeaa7
> 

Hmm, I just wonder why you would need to run dirmngr all the time, or each
time you have to read encrypted mail. you should have imported the keys
locally.
I even do not see any evidence that it is dirmngr that is blocking.
When I start the gpg client and search for a key I see dirmngr is started

$ while true; do ps -A | grep dir; sleep 1; done

> But more to the point, It's not an easy program to debug....
> 
> Following man page, I created ~/.gnupg/dirmngr.conf and populated it
> with:
>   verbose
>   debug-level expert
>   keyserver na.pool.sks-keyservers.net
>   disable-ipv6
>   disable-ldap
>   log-file ~/dirmngr.log
>   allow-ocsp
> 

interesting but on my end I use pool.sks-keyservers.net and there were no
issues - well how often you download or upload a key to the server?
If I search for a key it takes like 3sec - and yes I think it goes via
dirmngr - but sorry no time to bother setting up a config.

The config I find here is the default
cat ~/.gnupg/dirmngr.conf

###+++--- GPGConf ---+++###
disable-ldap
debug-level basic
log-file socket:///home/pizza/.gnupg/log-socket
###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET
# GPGConf edited this configuration file.
# It will disable options before this marked block, but it will
# never change anything below these lines.

> and then I fired up Evolution and opened emails with gpg sigs, but
> still no data in the file ~/dirmngr.log.  :-(
> 
> What I suspect the problem to be, and what is alluded to on the
> sks-keyservers status page, is that there is a big
> inconsistency/availability with their servers (they have more off-pool
> servers listed than in-pool).  Obviously it's a freebie so complaints seem
> childish, but it is an important service.. just like pool.ntp.org (which
> ironically Debian has taken responsibility for at least sanitizing that
> with debian.pool.ntp.org)
> 
> -Jim P.

Some time ago keyservers got consolidated - so now we have
pool.sks-keyservers.net. I am not sure if you are taking this with
prejudices - might be only your setup.

I know dirmngr is somehow coupled with gpg, but never bothered to look into
that as it was always working properly.
The keyserver is not configured in ~/.gnupg/dirmngr.conf but in
~/.gnupg/gpg.conf

Show your ~/.gnupg/gpg.conf (or at least the relevant parts)

regards

[toc] | [prev] | [next] | [standalone]


#205769

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-27 01:40 +0100
Message-ID<xvVqq-6i9-17@gated-at.bofh.it>
In reply to#205768
On Wed, 2019-02-27 at 00:45 +0100, deloptes wrote:
> Jim Popovitch wrote:
> 
> > On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote:
> > > Jim Popovitch wrote:
> > > 
> > > > What's up with dirmngr?  If dirmngr is installed Evolution
> > > > often takes ages to open signed emails.  If dirmngr is not
> > > > installed then (according to p.d.o/buster/dirmngr) "the parts
> > > > of the GnuPG suite that try to interact with the network will
> > > > fail"
> > > > 
> > > > How can dirmngr be so tightly integrated but work so poorly
> > > > querying services?  /r
> > > 
> > > why should it be dirmngrs fault? perhaps it is a kind of buster
> > > or other issue.
> > > 
> > > Try to find out where the waiting is coming from and post back.
> > > For example waiting for keyserver to respond or similar or
> > > waiting for something to time out.
> > 
> > Glad you asked!
> > 
> > dirmngr uses sks-keyservers.net which has at least one NS with
> > issues:
> > https://ednscomp.isc.org/ednscomp/0f65feeaa7
> > 
> 
> Hmm, I just wonder why you would need to run dirmngr all the time, or
> each time you have to read encrypted mail. you should have imported
> the keys locally.

I don't choose to run dirmngr all the time, something within Evolution
or gpg-agent makes that choice, and there's no way for me to know who
on the d-u@l.d.o is going to sign their emails therefore I can't pre-
import their keys.

> I even do not see any evidence that it is dirmngr that is blocking.
> When I start the gpg client and search for a key I see dirmngr is
> started
>
> $ while true; do ps -A | grep dir; sleep 1; done
> 
> > But more to the point, It's not an easy program to debug....
> > 
> > Following man page, I created ~/.gnupg/dirmngr.conf and populated
> > it
> > with:
> >   verbose
> >   debug-level expert
> >   keyserver na.pool.sks-keyservers.net
> >   disable-ipv6
> >   disable-ldap
> >   log-file ~/dirmngr.log
> >   allow-ocsp
> > 
> 
> interesting but on my end I use pool.sks-keyservers.net and there
> were no issues - well how often you download or upload a key to the
> server?

I hardly ever upload, but reading this list results in 2 or 3 key
downloads every few hours.

> If I search for a key it takes like 3sec - and yes I think it goes
> via dirmngr - but sorry no time to bother setting up a config.
> 
> The config I find here is the default
> cat ~/.gnupg/dirmngr.conf
> 
> ###+++--- GPGConf ---+++###
> disable-ldap
> debug-level basic
> log-file socket:///home/pizza/.gnupg/log-socket
> ###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET
> # GPGConf edited this configuration file.
> # It will disable options before this marked block, but it will
> # never change anything below these lines.

Interesting.  My 2 Stretch systems did not have that file by default, I
had to create it.

> > and then I fired up Evolution and opened emails with gpg sigs, but
> > still no data in the file ~/dirmngr.log.  :-(
> > 
> > What I suspect the problem to be, and what is alluded to on the
> > sks-keyservers status page, is that there is a big
> > inconsistency/availability with their servers (they have more off-
> > pool servers listed than in-pool).  Obviously it's a freebie so
> > complaints seem childish, but it is an important service.. just
> > like pool.ntp.org (which ironically Debian has taken responsibility
> > for at least sanitizing that with debian.pool.ntp.org)
> > 
> > -Jim P.
> 
> Some time ago keyservers got consolidated - so now we have
> pool.sks-keyservers.net. I am not sure if you are taking this with
> prejudices - might be only your setup.

:-) I do run a clean, simple, tighten-down, secure setup.  One of those
things is a DNSSEC validating recursor.... which I now see that dnsviz
reports DNSSEC errors in... wait for it... sks-keyservers.net  <sigh>

http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/

Now, imagine if pool.ntp.org had those DNSSEC problems and the impact
it would have on the world.

> I know dirmngr is somehow coupled with gpg, but never bothered to
> look into that as it was always working properly.
> The keyserver is not configured in ~/.gnupg/dirmngr.conf but in
> ~/.gnupg/gpg.conf
> 
> Show your ~/.gnupg/gpg.conf (or at least the relevant parts)

~$ cat .gnupg/gpa.conf 
default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705
keyserver hkp://na.pool.sks-keyservers.net
advanced-ui


-Jim P.

[toc] | [prev] | [next] | [standalone]


#205773

Fromdeloptes <deloptes@gmail.com>
Date2019-02-27 08:10 +0100
Message-ID<xw1vQ-1Un-9@gated-at.bofh.it>
In reply to#205769
Jim Popovitch wrote:

> On Wed, 2019-02-27 at 00:45 +0100, deloptes wrote:
>> Jim Popovitch wrote:
>> 
>> > On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote:
>> > > Jim Popovitch wrote:
>> > > 
>> > > > What's up with dirmngr?  If dirmngr is installed Evolution
>> > > > often takes ages to open signed emails.  If dirmngr is not
>> > > > installed then (according to p.d.o/buster/dirmngr) "the parts
>> > > > of the GnuPG suite that try to interact with the network will
>> > > > fail"
>> > > > 
>> > > > How can dirmngr be so tightly integrated but work so poorly
>> > > > querying services?  /r
>> > > 
>> > > why should it be dirmngrs fault? perhaps it is a kind of buster
>> > > or other issue.
>> > > 
>> > > Try to find out where the waiting is coming from and post back.
>> > > For example waiting for keyserver to respond or similar or
>> > > waiting for something to time out.
>> > 
>> > Glad you asked!
>> > 
>> > dirmngr uses sks-keyservers.net which has at least one NS with
>> > issues:
>> > https://ednscomp.isc.org/ednscomp/0f65feeaa7
>> > 
>> 
>> Hmm, I just wonder why you would need to run dirmngr all the time, or
>> each time you have to read encrypted mail. you should have imported
>> the keys locally.
> 
> I don't choose to run dirmngr all the time, something within Evolution
> or gpg-agent makes that choice, and there's no way for me to know who
> on the d-u@l.d.o is going to sign their emails therefore I can't pre-
> import their keys.
> 

by all the time I mean each time Evolution opens a signed mail. I use
Trinity Desktop and there - I only see that signature could not be
verified.
BTW if you are advanced Linux user as it seems to be ... you may try
Trinity - saves a lot of troubles - but depends what you expect from it.

>> I even do not see any evidence that it is dirmngr that is blocking.
>> When I start the gpg client and search for a key I see dirmngr is
>> started
>>
>> $ while true; do ps -A | grep dir; sleep 1; done
>> 
>> > But more to the point, It's not an easy program to debug....
>> > 
>> > Following man page, I created ~/.gnupg/dirmngr.conf and populated
>> > it
>> > with:
>> > verbose
>> > debug-level expert
>> > keyserver na.pool.sks-keyservers.net
>> > disable-ipv6
>> > disable-ldap
>> > log-file ~/dirmngr.log
>> > allow-ocsp
>> > 
>> 
>> interesting but on my end I use pool.sks-keyservers.net and there
>> were no issues - well how often you download or upload a key to the
>> server?
> 
> I hardly ever upload, but reading this list results in 2 or 3 key
> downloads every few hours.
> 

So it might be a configuration to automatically search and download keys not
present - what if you configure to manually do so (this might be in
Evolution or at system level for the user)

>> If I search for a key it takes like 3sec - and yes I think it goes
>> via dirmngr - but sorry no time to bother setting up a config.
>> 
>> The config I find here is the default
>> cat ~/.gnupg/dirmngr.conf
>> 
>> ###+++--- GPGConf ---+++###
>> disable-ldap
>> debug-level basic
>> log-file socket:///home/pizza/.gnupg/log-socket
>> ###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET
>> # GPGConf edited this configuration file.
>> # It will disable options before this marked block, but it will
>> # never change anything below these lines.
> 
> Interesting.  My 2 Stretch systems did not have that file by default, I
> had to create it.
> 

Yes it is created by the Trinity Kgpg app AFAIR.

>> > and then I fired up Evolution and opened emails with gpg sigs, but
>> > still no data in the file ~/dirmngr.log.  :-(
>> > 
>> > What I suspect the problem to be, and what is alluded to on the
>> > sks-keyservers status page, is that there is a big
>> > inconsistency/availability with their servers (they have more off-
>> > pool servers listed than in-pool).  Obviously it's a freebie so
>> > complaints seem childish, but it is an important service.. just
>> > like pool.ntp.org (which ironically Debian has taken responsibility
>> > for at least sanitizing that with debian.pool.ntp.org)
>> > 
>> > -Jim P.
>> 
>> Some time ago keyservers got consolidated - so now we have
>> pool.sks-keyservers.net. I am not sure if you are taking this with
>> prejudices - might be only your setup.
> 
> :-) I do run a clean, simple, tighten-down, secure setup.  One of those
> things is a DNSSEC validating recursor.... which I now see that dnsviz
> reports DNSSEC errors in... wait for it... sks-keyservers.net  <sigh>
> 
> http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/
> 
> Now, imagine if pool.ntp.org had those DNSSEC problems and the impact
> it would have on the world.
> 

I am sure not only sks-keyservers.net reports back, but I agree this might
be part of the issue you report.

>> I know dirmngr is somehow coupled with gpg, but never bothered to
>> look into that as it was always working properly.
>> The keyserver is not configured in ~/.gnupg/dirmngr.conf but in
>> ~/.gnupg/gpg.conf
>> 
>> Show your ~/.gnupg/gpg.conf (or at least the relevant parts)
> 
> ~$ cat .gnupg/gpa.conf
> default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705
> keyserver hkp://na.pool.sks-keyservers.net
> advanced-ui
> 

I don't have the protocol (hkp) - but the point was to remove the keyserver
from dirmngr.conf - not sure if it is right for your DE though.

regards

[toc] | [prev] | [next] | [standalone]


#205810

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-28 12:20 +0100
Message-ID<xwrTj-3Az-1@gated-at.bofh.it>
In reply to#205773
On Wed, 2019-02-27 at 08:03 +-0100, deloptes wrote:
+AD4 by all the time I mean each time Evolution opens a signed mail. I use
+AD4 Trinity Desktop and there - I only see that signature could not be
+AD4 verified.

Ah, i see.  For me (Stretch/Cinnamon) dirmngr is started when Evolution
encounters the first sig, and dirmngr remains running until system
shutdown.

+AD4 BTW if you are advanced Linux user as it seems to be ... you may try
+AD4 Trinity - saves a lot of troubles - but depends what you expect from it.

Thanks, I'll certainly look into that more.  On a related note I highly
recommend Cinnamon for it's clean looks and ease of use. :-)

+AD4 +AD4 +AD4 I even do not see any evidence that it is dirmngr that is blocking.
+AD4 +AD4 +AD4 When I start the gpg client and search for a key I see dirmngr is
+AD4 +AD4 +AD4 started
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +ACQ while true+ADs do ps -A +AHw grep dir+ADs sleep 1+ADs done
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +AD4 But more to the point, It's not an easy program to debug....
+AD4 +AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +AD4 Following man page, I created +AH4-/.gnupg/dirmngr.conf and populated
+AD4 +AD4 +AD4 +AD4 it
+AD4 +AD4 +AD4 +AD4 with:
+AD4 +AD4 +AD4 +AD4 verbose
+AD4 +AD4 +AD4 +AD4 debug-level expert
+AD4 +AD4 +AD4 +AD4 keyserver na.pool.sks-keyservers.net
+AD4 +AD4 +AD4 +AD4 disable-ipv6
+AD4 +AD4 +AD4 +AD4 disable-ldap
+AD4 +AD4 +AD4 +AD4 log-file +AH4-/dirmngr.log
+AD4 +AD4 +AD4 +AD4 allow-ocsp
+AD4 +AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 interesting but on my end I use pool.sks-keyservers.net and there
+AD4 +AD4 +AD4 were no issues - well how often you download or upload a key to the
+AD4 +AD4 +AD4 server?
+AD4 +AD4 
+AD4 +AD4 I hardly ever upload, but reading this list results in 2 or 3 key
+AD4 +AD4 downloads every few hours.
+AD4 +AD4 
+AD4 
+AD4 So it might be a configuration to automatically search and download keys not
+AD4 present - what if you configure to manually do so (this might be in
+AD4 Evolution or at system level for the user)

I can't find anywhere in .gnupg/+ACo or Evolution config where that would
be setup. :-(

+AD4 +AD4 +AD4 If I search for a key it takes like 3sec - and yes I think it goes
+AD4 +AD4 +AD4 via dirmngr - but sorry no time to bother setting up a config.
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 The config I find here is the default
+AD4 +AD4 +AD4 cat +AH4-/.gnupg/dirmngr.conf
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +ACMAIwAjACsAKwAr---- GPGConf ---+-+-+-+ACMAIwAj
+AD4 +AD4 +AD4 disable-ldap
+AD4 +AD4 +AD4 debug-level basic
+AD4 +AD4 +AD4 log-file socket:///home/pizza/.gnupg/log-socket
+AD4 +AD4 +AD4 +ACMAIwAjACsAKwAr---- GPGConf ---+-+-+-+ACMAIwAj Thu 06 Dec 2018 01:45:13 AM CET
+AD4 +AD4 +AD4 +ACM GPGConf edited this configuration file.
+AD4 +AD4 +AD4 +ACM It will disable options before this marked block, but it will
+AD4 +AD4 +AD4 +ACM never change anything below these lines.
+AD4 +AD4 
+AD4 +AD4 Interesting.  My 2 Stretch systems did not have that file by default, I
+AD4 +AD4 had to create it.
+AD4 +AD4 
+AD4 
+AD4 Yes it is created by the Trinity Kgpg app AFAIR.
+AD4 
+AD4 +AD4 +AD4 +AD4 and then I fired up Evolution and opened emails with gpg sigs, but
+AD4 +AD4 +AD4 +AD4 still no data in the file +AH4-/dirmngr.log.+AKAAoA:-(
+AD4 +AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +AD4 What I suspect the problem to be, and what is alluded to on the
+AD4 +AD4 +AD4 +AD4 sks-keyservers status page, is that there is a big
+AD4 +AD4 +AD4 +AD4 inconsistency/availability with their servers (they have more off-
+AD4 +AD4 +AD4 +AD4 pool servers listed than in-pool).+AKAAoA-Obviously it's a freebie so
+AD4 +AD4 +AD4 +AD4 complaints seem childish, but it is an important service.. just
+AD4 +AD4 +AD4 +AD4 like pool.ntp.org (which ironically Debian has taken responsibility
+AD4 +AD4 +AD4 +AD4 for at least sanitizing that with debian.pool.ntp.org)
+AD4 +AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 +AD4 -Jim P.
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 Some time ago keyservers got consolidated - so now we have
+AD4 +AD4 +AD4 pool.sks-keyservers.net. I am not sure if you are taking this with
+AD4 +AD4 +AD4 prejudices - might be only your setup.
+AD4 +AD4 
+AD4 +AD4 :-) I do run a clean, simple, tighten-down, secure setup.  One of those
+AD4 +AD4 things is a DNSSEC validating recursor.... which I now see that dnsviz
+AD4 +AD4 reports DNSSEC errors in... wait for it...+AKA-sks-keyservers.net  +ADw-sigh+AD4
+AD4 +AD4 
+AD4 +AD4 http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/
+AD4 +AD4 
+AD4 +AD4 Now, imagine if pool.ntp.org had those DNSSEC problems and the impact
+AD4 +AD4 it would have on the world.
+AD4 +AD4 
+AD4 
+AD4 I am sure not only sks-keyservers.net reports back, but I agree this might
+AD4 be part of the issue you report.
+AD4 
+AD4 +AD4 +AD4 I know dirmngr is somehow coupled with gpg, but never bothered to
+AD4 +AD4 +AD4 look into that as it was always working properly.
+AD4 +AD4 +AD4 The keyserver is not configured in +AH4-/.gnupg/dirmngr.conf but in
+AD4 +AD4 +AD4 +AH4-/.gnupg/gpg.conf
+AD4 +AD4 +AD4 
+AD4 +AD4 +AD4 Show your +AH4-/.gnupg/gpg.conf (or at least the relevant parts)
+AD4 +AD4 
+AD4 +AD4 +AH4AJA cat .gnupg/gpa.conf
+AD4 +AD4 default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705
+AD4 +AD4 keyserver hkp://na.pool.sks-keyservers.net
+AD4 +AD4 advanced-ui
+AD4 +AD4 
+AD4 
+AD4 I don't have the protocol (hkp) - but the point was to remove the keyserver
+AD4 from dirmngr.conf - not sure if it is right for your DE though.

Thanks for that, testing that now+ACE

-Jim P.

[toc] | [prev] | [next] | [standalone]


#205817

FromCurt <curty@free.fr>
Date2019-02-28 14:00 +0100
Message-ID<xwts5-4v3-9@gated-at.bofh.it>
In reply to#205810
On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote:
>> 
>> I don't have the protocol (hkp) - but the point was to remove the keyserver
>> from dirmngr.conf - not sure if it is right for your DE though.
>
> Thanks for that, testing that now!

Perhaps unrelated to your plight, but have you tried another pool? ping
times to the North American pool from here (outside Lutèce) are
significantly higher (if that even means anything) than those to the
other pools I tried (primary, European, Oceania). 

https://sks-keyservers.net/overview-of-pools.php

> -Jim P.
>
>


-- 
When you have fever you are heavy and light, you are small and swollen, you
climb endlessly a ladder which turns like a wheel. 
Jean Rhys, Voyage in the Dark

[toc] | [prev] | [next] | [standalone]


#205819

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-28 15:20 +0100
Message-ID<xwuHv-5uc-9@gated-at.bofh.it>
In reply to#205817
On Thu, 2019-02-28 at 12:56 +0000, Curt wrote:
> On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote:
> > > 
> > > I don't have the protocol (hkp) - but the point was to remove the
> > > keyserver
> > > from dirmngr.conf - not sure if it is right for your DE though.
> > 
> > Thanks for that, testing that now!
> 
> Perhaps unrelated to your plight, but have you tried another pool?
> ping times to the North American pool from here (outside Lutèce) are
> significantly higher (if that even means anything) than those to the
> other pools I tried (primary, European, Oceania). 
> 
> https://sks-keyservers.net/overview-of-pools.php

I originally switched from the default SKS pool to the NA pool (I live
in Atlanta, GA, USA) because I thought that the NA pool might
reduce/eliminate any latency issues for me.  I do plan to test further
with  with a custom pool of just 1 or 2 well-known key servers in the
closest proximity (net'wise) to me.

-Jim P.

[toc] | [prev] | [next] | [standalone]


#205832

FromJim Popovitch <jim@k4vqc.com>
Date2019-02-28 18:50 +0100
Message-ID<xwxYJ-7lM-7@gated-at.bofh.it>
In reply to#205819
On Thu, 2019-02-28 at 09:12 -0500, Jim Popovitch wrote:
> On Thu, 2019-02-28 at 12:56 +0000, Curt wrote:
> > On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote:
> > > > 
> > > > I don't have the protocol (hkp) - but the point was to remove
> > > > the
> > > > keyserver
> > > > from dirmngr.conf - not sure if it is right for your DE though.
> > > 
> > > Thanks for that, testing that now!
> > 
> > Perhaps unrelated to your plight, but have you tried another pool?
> > ping times to the North American pool from here (outside Lutèce)
> > are
> > significantly higher (if that even means anything) than those to
> > the
> > other pools I tried (primary, European, Oceania). 
> > 
> > https://sks-keyservers.net/overview-of-pools.php
> 
> I originally switched from the default SKS pool to the NA pool (I
> live in Atlanta, GA, USA) because I thought that the NA pool might
> reduce/eliminate any latency issues for me.  I do plan to test
> further with  with a custom pool of just 1 or 2 well-known key
> servers in the closest proximity (net'wise) to me.

ha! it turns out that at least half of na.pool.sks-keyservers.net are
IPs in Europe.  /sigh

-Jim P.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web