Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #205759 > unrolled thread
| Started by | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| First post | 2019-02-26 13:00 +0100 |
| Last post | 2019-02-28 18:50 +0100 |
| Articles | 12 — 4 participants |
Back to article view | Back to linux.debian.user
dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-26 13:00 +0100
Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-26 20:40 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-26 21:30 +0100
Re: dirmngr, can't live with it, can't live without it Tixy <tixy@yxit.co.uk> - 2019-02-26 22:10 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-27 01:50 +0100
Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-27 00:50 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-27 01:40 +0100
Re: dirmngr, can't live with it, can't live without it deloptes <deloptes@gmail.com> - 2019-02-27 08:10 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 12:20 +0100
Re: dirmngr, can't live with it, can't live without it Curt <curty@free.fr> - 2019-02-28 14:00 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 15:20 +0100
Re: dirmngr, can't live with it, can't live without it Jim Popovitch <jim@k4vqc.com> - 2019-02-28 18:50 +0100
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-26 13:00 +0100 |
| Subject | dirmngr, can't live with it, can't live without it |
| Message-ID | <xvJyV-7av-5@gated-at.bofh.it> |
OK d-u+AEA-l.d.o, What's up with dirmngr? If dirmngr is installed Evolution often takes ages to open signed emails. If dirmngr is not installed then (according to p.d.o/buster/dirmngr) +ACI-the parts of the GnuPG suite that try to interact with the network will fail+ACI How can dirmngr be so tightly integrated but work so poorly querying services? /r -Jim P.
[toc] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-02-26 20:40 +0100 |
| Message-ID | <xvQK6-3jG-7@gated-at.bofh.it> |
| In reply to | #205759 |
Jim Popovitch wrote: > What's up with dirmngr? If dirmngr is installed Evolution often takes > ages to open signed emails. If dirmngr is not installed then (according > to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to > interact with the network will fail" > > How can dirmngr be so tightly integrated but work so poorly querying > services? /r why should it be dirmngrs fault? perhaps it is a kind of buster or other issue. Try to find out where the waiting is coming from and post back. For example waiting for keyserver to respond or similar or waiting for something to time out. regards
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-26 21:30 +0100 |
| Message-ID | <xvRwt-3R7-11@gated-at.bofh.it> |
| In reply to | #205764 |
On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote: > Jim Popovitch wrote: > > > What's up with dirmngr? If dirmngr is installed Evolution often > > takes > > ages to open signed emails. If dirmngr is not installed then > > (according > > to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to > > interact with the network will fail" > > > > How can dirmngr be so tightly integrated but work so poorly > > querying > > services? /r > > why should it be dirmngrs fault? perhaps it is a kind of buster or > other issue. > > Try to find out where the waiting is coming from and post back. For > example waiting for keyserver to respond or similar or waiting for > something to time out. Glad you asked! dirmngr uses sks-keyservers.net which has at least one NS with issues: https://ednscomp.isc.org/ednscomp/0f65feeaa7 But more to the point, It's not an easy program to debug.... Following man page, I created ~/.gnupg/dirmngr.conf and populated it with: verbose debug-level expert keyserver na.pool.sks-keyservers.net disable-ipv6 disable-ldap log-file ~/dirmngr.log allow-ocsp and then I fired up Evolution and opened emails with gpg sigs, but still no data in the file ~/dirmngr.log. :-( What I suspect the problem to be, and what is alluded to on the sks-keyservers status page, is that there is a big inconsistency/availability with their servers (they have more off-pool servers listed than in-pool). Obviously it's a freebie so complaints seem childish, but it is an important service.. just like pool.ntp.org (which ironically Debian has taken responsibility for at least sanitizing that with debian.pool.ntp.org) -Jim P.
[toc] | [prev] | [next] | [standalone]
| From | Tixy <tixy@yxit.co.uk> |
|---|---|
| Date | 2019-02-26 22:10 +0100 |
| Message-ID | <xvS9b-4lO-11@gated-at.bofh.it> |
| In reply to | #205765 |
On Tue, 2019-02-26 at 15:21 -0500, Jim Popovitch wrote: > But more to the point, It's not an easy program to debug.... > > Following man page, I created ~/.gnupg/dirmngr.conf and populated it > with: > verbose > debug-level expert > keyserver na.pool.sks-keyservers.net > disable-ipv6 > disable-ldap > log-file ~/dirmngr.log > allow-ocsp > > and then I fired up Evolution and opened emails with gpg sigs, but > still no data in the file ~/dirmngr.log. :-( I've no idea what dirmngr is, but have you tried specifying a proper path for 'log-file' rather than using a tilde (~)? Perhaps whatever parses dirmngr.conf doesn't treat a tilde as special like shells do. -- Tixy
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-27 01:50 +0100 |
| Message-ID | <xvVA5-6m1-3@gated-at.bofh.it> |
| In reply to | #205766 |
On Tue, 2019-02-26 at 21:01 +0000, Tixy wrote: > On Tue, 2019-02-26 at 15:21 -0500, Jim Popovitch wrote: > > But more to the point, It's not an easy program to debug.... > > > > Following man page, I created ~/.gnupg/dirmngr.conf and populated > > it > > with: > > verbose > > debug-level expert > > keyserver na.pool.sks-keyservers.net > > disable-ipv6 > > disable-ldap > > log-file ~/dirmngr.log > > allow-ocsp > > > > and then I fired up Evolution and opened emails with gpg sigs, but > > still no data in the file ~/dirmngr.log. :-( > > I've no idea what dirmngr is, but have you tried specifying a proper > path for 'log-file' rather than using a tilde (~)? Perhaps whatever > parses dirmngr.conf doesn't treat a tilde as special like shells do. dirmngr (Directory Manager?) is an agent produced by the GnuPGP folks who also have something called gpg-agent. Why one is called an agent and the other a mngr (manager) is unknown to me. The log file eventually started dumping some stuff. Here it is for those interested: http://paste.debian.net/plainh/16c494c3 -Jim P.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-02-27 00:50 +0100 |
| Message-ID | <xvUE2-5LG-1@gated-at.bofh.it> |
| In reply to | #205765 |
Jim Popovitch wrote: > On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote: >> Jim Popovitch wrote: >> >> > What's up with dirmngr? If dirmngr is installed Evolution often >> > takes >> > ages to open signed emails. If dirmngr is not installed then >> > (according >> > to p.d.o/buster/dirmngr) "the parts of the GnuPG suite that try to >> > interact with the network will fail" >> > >> > How can dirmngr be so tightly integrated but work so poorly >> > querying >> > services? /r >> >> why should it be dirmngrs fault? perhaps it is a kind of buster or >> other issue. >> >> Try to find out where the waiting is coming from and post back. For >> example waiting for keyserver to respond or similar or waiting for >> something to time out. > > Glad you asked! > > dirmngr uses sks-keyservers.net which has at least one NS with issues: > https://ednscomp.isc.org/ednscomp/0f65feeaa7 > Hmm, I just wonder why you would need to run dirmngr all the time, or each time you have to read encrypted mail. you should have imported the keys locally. I even do not see any evidence that it is dirmngr that is blocking. When I start the gpg client and search for a key I see dirmngr is started $ while true; do ps -A | grep dir; sleep 1; done > But more to the point, It's not an easy program to debug.... > > Following man page, I created ~/.gnupg/dirmngr.conf and populated it > with: > verbose > debug-level expert > keyserver na.pool.sks-keyservers.net > disable-ipv6 > disable-ldap > log-file ~/dirmngr.log > allow-ocsp > interesting but on my end I use pool.sks-keyservers.net and there were no issues - well how often you download or upload a key to the server? If I search for a key it takes like 3sec - and yes I think it goes via dirmngr - but sorry no time to bother setting up a config. The config I find here is the default cat ~/.gnupg/dirmngr.conf ###+++--- GPGConf ---+++### disable-ldap debug-level basic log-file socket:///home/pizza/.gnupg/log-socket ###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET # GPGConf edited this configuration file. # It will disable options before this marked block, but it will # never change anything below these lines. > and then I fired up Evolution and opened emails with gpg sigs, but > still no data in the file ~/dirmngr.log. :-( > > What I suspect the problem to be, and what is alluded to on the > sks-keyservers status page, is that there is a big > inconsistency/availability with their servers (they have more off-pool > servers listed than in-pool). Obviously it's a freebie so complaints seem > childish, but it is an important service.. just like pool.ntp.org (which > ironically Debian has taken responsibility for at least sanitizing that > with debian.pool.ntp.org) > > -Jim P. Some time ago keyservers got consolidated - so now we have pool.sks-keyservers.net. I am not sure if you are taking this with prejudices - might be only your setup. I know dirmngr is somehow coupled with gpg, but never bothered to look into that as it was always working properly. The keyserver is not configured in ~/.gnupg/dirmngr.conf but in ~/.gnupg/gpg.conf Show your ~/.gnupg/gpg.conf (or at least the relevant parts) regards
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-27 01:40 +0100 |
| Message-ID | <xvVqq-6i9-17@gated-at.bofh.it> |
| In reply to | #205768 |
On Wed, 2019-02-27 at 00:45 +0100, deloptes wrote: > Jim Popovitch wrote: > > > On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote: > > > Jim Popovitch wrote: > > > > > > > What's up with dirmngr? If dirmngr is installed Evolution > > > > often takes ages to open signed emails. If dirmngr is not > > > > installed then (according to p.d.o/buster/dirmngr) "the parts > > > > of the GnuPG suite that try to interact with the network will > > > > fail" > > > > > > > > How can dirmngr be so tightly integrated but work so poorly > > > > querying services? /r > > > > > > why should it be dirmngrs fault? perhaps it is a kind of buster > > > or other issue. > > > > > > Try to find out where the waiting is coming from and post back. > > > For example waiting for keyserver to respond or similar or > > > waiting for something to time out. > > > > Glad you asked! > > > > dirmngr uses sks-keyservers.net which has at least one NS with > > issues: > > https://ednscomp.isc.org/ednscomp/0f65feeaa7 > > > > Hmm, I just wonder why you would need to run dirmngr all the time, or > each time you have to read encrypted mail. you should have imported > the keys locally. I don't choose to run dirmngr all the time, something within Evolution or gpg-agent makes that choice, and there's no way for me to know who on the d-u@l.d.o is going to sign their emails therefore I can't pre- import their keys. > I even do not see any evidence that it is dirmngr that is blocking. > When I start the gpg client and search for a key I see dirmngr is > started > > $ while true; do ps -A | grep dir; sleep 1; done > > > But more to the point, It's not an easy program to debug.... > > > > Following man page, I created ~/.gnupg/dirmngr.conf and populated > > it > > with: > > verbose > > debug-level expert > > keyserver na.pool.sks-keyservers.net > > disable-ipv6 > > disable-ldap > > log-file ~/dirmngr.log > > allow-ocsp > > > > interesting but on my end I use pool.sks-keyservers.net and there > were no issues - well how often you download or upload a key to the > server? I hardly ever upload, but reading this list results in 2 or 3 key downloads every few hours. > If I search for a key it takes like 3sec - and yes I think it goes > via dirmngr - but sorry no time to bother setting up a config. > > The config I find here is the default > cat ~/.gnupg/dirmngr.conf > > ###+++--- GPGConf ---+++### > disable-ldap > debug-level basic > log-file socket:///home/pizza/.gnupg/log-socket > ###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET > # GPGConf edited this configuration file. > # It will disable options before this marked block, but it will > # never change anything below these lines. Interesting. My 2 Stretch systems did not have that file by default, I had to create it. > > and then I fired up Evolution and opened emails with gpg sigs, but > > still no data in the file ~/dirmngr.log. :-( > > > > What I suspect the problem to be, and what is alluded to on the > > sks-keyservers status page, is that there is a big > > inconsistency/availability with their servers (they have more off- > > pool servers listed than in-pool). Obviously it's a freebie so > > complaints seem childish, but it is an important service.. just > > like pool.ntp.org (which ironically Debian has taken responsibility > > for at least sanitizing that with debian.pool.ntp.org) > > > > -Jim P. > > Some time ago keyservers got consolidated - so now we have > pool.sks-keyservers.net. I am not sure if you are taking this with > prejudices - might be only your setup. :-) I do run a clean, simple, tighten-down, secure setup. One of those things is a DNSSEC validating recursor.... which I now see that dnsviz reports DNSSEC errors in... wait for it... sks-keyservers.net <sigh> http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/ Now, imagine if pool.ntp.org had those DNSSEC problems and the impact it would have on the world. > I know dirmngr is somehow coupled with gpg, but never bothered to > look into that as it was always working properly. > The keyserver is not configured in ~/.gnupg/dirmngr.conf but in > ~/.gnupg/gpg.conf > > Show your ~/.gnupg/gpg.conf (or at least the relevant parts) ~$ cat .gnupg/gpa.conf default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705 keyserver hkp://na.pool.sks-keyservers.net advanced-ui -Jim P.
[toc] | [prev] | [next] | [standalone]
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Date | 2019-02-27 08:10 +0100 |
| Message-ID | <xw1vQ-1Un-9@gated-at.bofh.it> |
| In reply to | #205769 |
Jim Popovitch wrote: > On Wed, 2019-02-27 at 00:45 +0100, deloptes wrote: >> Jim Popovitch wrote: >> >> > On Tue, 2019-02-26 at 20:31 +0100, deloptes wrote: >> > > Jim Popovitch wrote: >> > > >> > > > What's up with dirmngr? If dirmngr is installed Evolution >> > > > often takes ages to open signed emails. If dirmngr is not >> > > > installed then (according to p.d.o/buster/dirmngr) "the parts >> > > > of the GnuPG suite that try to interact with the network will >> > > > fail" >> > > > >> > > > How can dirmngr be so tightly integrated but work so poorly >> > > > querying services? /r >> > > >> > > why should it be dirmngrs fault? perhaps it is a kind of buster >> > > or other issue. >> > > >> > > Try to find out where the waiting is coming from and post back. >> > > For example waiting for keyserver to respond or similar or >> > > waiting for something to time out. >> > >> > Glad you asked! >> > >> > dirmngr uses sks-keyservers.net which has at least one NS with >> > issues: >> > https://ednscomp.isc.org/ednscomp/0f65feeaa7 >> > >> >> Hmm, I just wonder why you would need to run dirmngr all the time, or >> each time you have to read encrypted mail. you should have imported >> the keys locally. > > I don't choose to run dirmngr all the time, something within Evolution > or gpg-agent makes that choice, and there's no way for me to know who > on the d-u@l.d.o is going to sign their emails therefore I can't pre- > import their keys. > by all the time I mean each time Evolution opens a signed mail. I use Trinity Desktop and there - I only see that signature could not be verified. BTW if you are advanced Linux user as it seems to be ... you may try Trinity - saves a lot of troubles - but depends what you expect from it. >> I even do not see any evidence that it is dirmngr that is blocking. >> When I start the gpg client and search for a key I see dirmngr is >> started >> >> $ while true; do ps -A | grep dir; sleep 1; done >> >> > But more to the point, It's not an easy program to debug.... >> > >> > Following man page, I created ~/.gnupg/dirmngr.conf and populated >> > it >> > with: >> > verbose >> > debug-level expert >> > keyserver na.pool.sks-keyservers.net >> > disable-ipv6 >> > disable-ldap >> > log-file ~/dirmngr.log >> > allow-ocsp >> > >> >> interesting but on my end I use pool.sks-keyservers.net and there >> were no issues - well how often you download or upload a key to the >> server? > > I hardly ever upload, but reading this list results in 2 or 3 key > downloads every few hours. > So it might be a configuration to automatically search and download keys not present - what if you configure to manually do so (this might be in Evolution or at system level for the user) >> If I search for a key it takes like 3sec - and yes I think it goes >> via dirmngr - but sorry no time to bother setting up a config. >> >> The config I find here is the default >> cat ~/.gnupg/dirmngr.conf >> >> ###+++--- GPGConf ---+++### >> disable-ldap >> debug-level basic >> log-file socket:///home/pizza/.gnupg/log-socket >> ###+++--- GPGConf ---+++### Thu 06 Dec 2018 01:45:13 AM CET >> # GPGConf edited this configuration file. >> # It will disable options before this marked block, but it will >> # never change anything below these lines. > > Interesting. My 2 Stretch systems did not have that file by default, I > had to create it. > Yes it is created by the Trinity Kgpg app AFAIR. >> > and then I fired up Evolution and opened emails with gpg sigs, but >> > still no data in the file ~/dirmngr.log. :-( >> > >> > What I suspect the problem to be, and what is alluded to on the >> > sks-keyservers status page, is that there is a big >> > inconsistency/availability with their servers (they have more off- >> > pool servers listed than in-pool). Obviously it's a freebie so >> > complaints seem childish, but it is an important service.. just >> > like pool.ntp.org (which ironically Debian has taken responsibility >> > for at least sanitizing that with debian.pool.ntp.org) >> > >> > -Jim P. >> >> Some time ago keyservers got consolidated - so now we have >> pool.sks-keyservers.net. I am not sure if you are taking this with >> prejudices - might be only your setup. > > :-) I do run a clean, simple, tighten-down, secure setup. One of those > things is a DNSSEC validating recursor.... which I now see that dnsviz > reports DNSSEC errors in... wait for it... sks-keyservers.net <sigh> > > http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/ > > Now, imagine if pool.ntp.org had those DNSSEC problems and the impact > it would have on the world. > I am sure not only sks-keyservers.net reports back, but I agree this might be part of the issue you report. >> I know dirmngr is somehow coupled with gpg, but never bothered to >> look into that as it was always working properly. >> The keyserver is not configured in ~/.gnupg/dirmngr.conf but in >> ~/.gnupg/gpg.conf >> >> Show your ~/.gnupg/gpg.conf (or at least the relevant parts) > > ~$ cat .gnupg/gpa.conf > default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705 > keyserver hkp://na.pool.sks-keyservers.net > advanced-ui > I don't have the protocol (hkp) - but the point was to remove the keyserver from dirmngr.conf - not sure if it is right for your DE though. regards
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-28 12:20 +0100 |
| Message-ID | <xwrTj-3Az-1@gated-at.bofh.it> |
| In reply to | #205773 |
On Wed, 2019-02-27 at 08:03 +-0100, deloptes wrote: +AD4 by all the time I mean each time Evolution opens a signed mail. I use +AD4 Trinity Desktop and there - I only see that signature could not be +AD4 verified. Ah, i see. For me (Stretch/Cinnamon) dirmngr is started when Evolution encounters the first sig, and dirmngr remains running until system shutdown. +AD4 BTW if you are advanced Linux user as it seems to be ... you may try +AD4 Trinity - saves a lot of troubles - but depends what you expect from it. Thanks, I'll certainly look into that more. On a related note I highly recommend Cinnamon for it's clean looks and ease of use. :-) +AD4 +AD4 +AD4 I even do not see any evidence that it is dirmngr that is blocking. +AD4 +AD4 +AD4 When I start the gpg client and search for a key I see dirmngr is +AD4 +AD4 +AD4 started +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +ACQ while true+ADs do ps -A +AHw grep dir+ADs sleep 1+ADs done +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 But more to the point, It's not an easy program to debug.... +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 Following man page, I created +AH4-/.gnupg/dirmngr.conf and populated +AD4 +AD4 +AD4 +AD4 it +AD4 +AD4 +AD4 +AD4 with: +AD4 +AD4 +AD4 +AD4 verbose +AD4 +AD4 +AD4 +AD4 debug-level expert +AD4 +AD4 +AD4 +AD4 keyserver na.pool.sks-keyservers.net +AD4 +AD4 +AD4 +AD4 disable-ipv6 +AD4 +AD4 +AD4 +AD4 disable-ldap +AD4 +AD4 +AD4 +AD4 log-file +AH4-/dirmngr.log +AD4 +AD4 +AD4 +AD4 allow-ocsp +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 interesting but on my end I use pool.sks-keyservers.net and there +AD4 +AD4 +AD4 were no issues - well how often you download or upload a key to the +AD4 +AD4 +AD4 server? +AD4 +AD4 +AD4 +AD4 I hardly ever upload, but reading this list results in 2 or 3 key +AD4 +AD4 downloads every few hours. +AD4 +AD4 +AD4 +AD4 So it might be a configuration to automatically search and download keys not +AD4 present - what if you configure to manually do so (this might be in +AD4 Evolution or at system level for the user) I can't find anywhere in .gnupg/+ACo or Evolution config where that would be setup. :-( +AD4 +AD4 +AD4 If I search for a key it takes like 3sec - and yes I think it goes +AD4 +AD4 +AD4 via dirmngr - but sorry no time to bother setting up a config. +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 The config I find here is the default +AD4 +AD4 +AD4 cat +AH4-/.gnupg/dirmngr.conf +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +ACMAIwAjACsAKwAr---- GPGConf ---+-+-+-+ACMAIwAj +AD4 +AD4 +AD4 disable-ldap +AD4 +AD4 +AD4 debug-level basic +AD4 +AD4 +AD4 log-file socket:///home/pizza/.gnupg/log-socket +AD4 +AD4 +AD4 +ACMAIwAjACsAKwAr---- GPGConf ---+-+-+-+ACMAIwAj Thu 06 Dec 2018 01:45:13 AM CET +AD4 +AD4 +AD4 +ACM GPGConf edited this configuration file. +AD4 +AD4 +AD4 +ACM It will disable options before this marked block, but it will +AD4 +AD4 +AD4 +ACM never change anything below these lines. +AD4 +AD4 +AD4 +AD4 Interesting. My 2 Stretch systems did not have that file by default, I +AD4 +AD4 had to create it. +AD4 +AD4 +AD4 +AD4 Yes it is created by the Trinity Kgpg app AFAIR. +AD4 +AD4 +AD4 +AD4 +AD4 and then I fired up Evolution and opened emails with gpg sigs, but +AD4 +AD4 +AD4 +AD4 still no data in the file +AH4-/dirmngr.log.+AKAAoA:-( +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 What I suspect the problem to be, and what is alluded to on the +AD4 +AD4 +AD4 +AD4 sks-keyservers status page, is that there is a big +AD4 +AD4 +AD4 +AD4 inconsistency/availability with their servers (they have more off- +AD4 +AD4 +AD4 +AD4 pool servers listed than in-pool).+AKAAoA-Obviously it's a freebie so +AD4 +AD4 +AD4 +AD4 complaints seem childish, but it is an important service.. just +AD4 +AD4 +AD4 +AD4 like pool.ntp.org (which ironically Debian has taken responsibility +AD4 +AD4 +AD4 +AD4 for at least sanitizing that with debian.pool.ntp.org) +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 -Jim P. +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 Some time ago keyservers got consolidated - so now we have +AD4 +AD4 +AD4 pool.sks-keyservers.net. I am not sure if you are taking this with +AD4 +AD4 +AD4 prejudices - might be only your setup. +AD4 +AD4 +AD4 +AD4 :-) I do run a clean, simple, tighten-down, secure setup. One of those +AD4 +AD4 things is a DNSSEC validating recursor.... which I now see that dnsviz +AD4 +AD4 reports DNSSEC errors in... wait for it...+AKA-sks-keyservers.net +ADw-sigh+AD4 +AD4 +AD4 +AD4 +AD4 http://dnsviz.net/d/pool.sks-keyservers.net/dnssec/ +AD4 +AD4 +AD4 +AD4 Now, imagine if pool.ntp.org had those DNSSEC problems and the impact +AD4 +AD4 it would have on the world. +AD4 +AD4 +AD4 +AD4 I am sure not only sks-keyservers.net reports back, but I agree this might +AD4 be part of the issue you report. +AD4 +AD4 +AD4 +AD4 I know dirmngr is somehow coupled with gpg, but never bothered to +AD4 +AD4 +AD4 look into that as it was always working properly. +AD4 +AD4 +AD4 The keyserver is not configured in +AH4-/.gnupg/dirmngr.conf but in +AD4 +AD4 +AD4 +AH4-/.gnupg/gpg.conf +AD4 +AD4 +AD4 +AD4 +AD4 +AD4 Show your +AH4-/.gnupg/gpg.conf (or at least the relevant parts) +AD4 +AD4 +AD4 +AD4 +AH4AJA cat .gnupg/gpa.conf +AD4 +AD4 default-key 3F1C1EF2E6019EAC646CE45227155EB4C45A2705 +AD4 +AD4 keyserver hkp://na.pool.sks-keyservers.net +AD4 +AD4 advanced-ui +AD4 +AD4 +AD4 +AD4 I don't have the protocol (hkp) - but the point was to remove the keyserver +AD4 from dirmngr.conf - not sure if it is right for your DE though. Thanks for that, testing that now+ACE -Jim P.
[toc] | [prev] | [next] | [standalone]
| From | Curt <curty@free.fr> |
|---|---|
| Date | 2019-02-28 14:00 +0100 |
| Message-ID | <xwts5-4v3-9@gated-at.bofh.it> |
| In reply to | #205810 |
On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote: >> >> I don't have the protocol (hkp) - but the point was to remove the keyserver >> from dirmngr.conf - not sure if it is right for your DE though. > > Thanks for that, testing that now! Perhaps unrelated to your plight, but have you tried another pool? ping times to the North American pool from here (outside Lutèce) are significantly higher (if that even means anything) than those to the other pools I tried (primary, European, Oceania). https://sks-keyservers.net/overview-of-pools.php > -Jim P. > > -- When you have fever you are heavy and light, you are small and swollen, you climb endlessly a ladder which turns like a wheel. Jean Rhys, Voyage in the Dark
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-28 15:20 +0100 |
| Message-ID | <xwuHv-5uc-9@gated-at.bofh.it> |
| In reply to | #205817 |
On Thu, 2019-02-28 at 12:56 +0000, Curt wrote: > On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote: > > > > > > I don't have the protocol (hkp) - but the point was to remove the > > > keyserver > > > from dirmngr.conf - not sure if it is right for your DE though. > > > > Thanks for that, testing that now! > > Perhaps unrelated to your plight, but have you tried another pool? > ping times to the North American pool from here (outside Lutèce) are > significantly higher (if that even means anything) than those to the > other pools I tried (primary, European, Oceania). > > https://sks-keyservers.net/overview-of-pools.php I originally switched from the default SKS pool to the NA pool (I live in Atlanta, GA, USA) because I thought that the NA pool might reduce/eliminate any latency issues for me. I do plan to test further with with a custom pool of just 1 or 2 well-known key servers in the closest proximity (net'wise) to me. -Jim P.
[toc] | [prev] | [next] | [standalone]
| From | Jim Popovitch <jim@k4vqc.com> |
|---|---|
| Date | 2019-02-28 18:50 +0100 |
| Message-ID | <xwxYJ-7lM-7@gated-at.bofh.it> |
| In reply to | #205819 |
On Thu, 2019-02-28 at 09:12 -0500, Jim Popovitch wrote: > On Thu, 2019-02-28 at 12:56 +0000, Curt wrote: > > On 2019-02-28, Jim Popovitch <jim@k4vqc.com> wrote: > > > > > > > > I don't have the protocol (hkp) - but the point was to remove > > > > the > > > > keyserver > > > > from dirmngr.conf - not sure if it is right for your DE though. > > > > > > Thanks for that, testing that now! > > > > Perhaps unrelated to your plight, but have you tried another pool? > > ping times to the North American pool from here (outside Lutèce) > > are > > significantly higher (if that even means anything) than those to > > the > > other pools I tried (primary, European, Oceania). > > > > https://sks-keyservers.net/overview-of-pools.php > > I originally switched from the default SKS pool to the NA pool (I > live in Atlanta, GA, USA) because I thought that the NA pool might > reduce/eliminate any latency issues for me. I do plan to test > further with with a custom pool of just 1 or 2 well-known key > servers in the closest proximity (net'wise) to me. ha! it turns out that at least half of na.pool.sks-keyservers.net are IPs in Europe. /sigh -Jim P.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web