Post by Nicholas W » Thu, 26 Aug 2004 21:22:39

First of all sorry if my question is OT: I just don't know where to
post it, so pointers to more appropriate groups are welcome.

I'm using Mutt with GPG, and I want to publish my key in my headers
using the appropriate X headers.
I know that X headers aren't standardized, so I can put inside them
quite everything I want, but I'm interested in common practices and
better ways to distribute GPG keys.

By now I put inside my headers something like that:

my_hdr X-GPG-Keyserver: hkp://subkeys.pgp.net
my_hdr X-GPG-Fingerprint: D3C2 DB93 DF6A 601B A32B CEB1 4020 7E71 0DAA

Thoughts ?


Post by Igor Ivano » Thu, 26 Aug 2004 21:32:57

Just and clearsign your messages and users will
automagically get your key from keyservers.




Post by s. keelin » Sat, 28 Aug 2004 05:24:55

On Wed, 25 Aug 2004 14:22:39 +0200, Nicholas Wieland < XXXX@XXXXX.COM >:


See my headers for my approach.

Post by Peter H. C » Sat, 28 Aug 2004 12:08:25

First thought: why? signatures etc contain the key id that was used to
make the signature etc. If your key is on public keyservers, it can be
automatically fetched by the program doing the signature verification.
People smart enough to look for key info in headers are usually smart
enough to have turned on automatic keyfetching. Who are you providing
this information to?

Post by Nicholas W » Sat, 28 Aug 2004 21:41:10

Well, I'm not an expert, I've read the fine manual thinking that it was
the right approach ...
Probably you're right, but, for example, what happens if someone read
mails offline (like me) ?


Post by Paul Walke » Sun, 29 Aug 2004 03:27:13

Given that PGP keys are usually at least a couple of K each, please don't do
this. Put your key on a keyserver, and put the fingerprint in the headers.
That's just as good.

Post by Peter H. C » Sun, 29 Aug 2004 07:34:27

Reading manuals is the right approach. Sometimes the manuals get a
little out of date, or put together by people that don't know all the
details or read a preliminary RFC written by someone else that didn't
know what they were talking about either. I don't know how many people
have asked about their favorite OS's implementation of RFC3514...

"Why do you want to do this?" questions aren't posed as a challenge of
"why do you have the right to know?" but to make sure that the right
problem is being solved.

They'll have to go online to get your key, won't they? Just read the
mail again, the key gets added to the public ring, and it's there for
future offline reading.

Post by Peter H. C » Sun, 29 Aug 2004 07:36:23

That's what the OP was talking about doing, and it's not generally
necessary with PKE software not written by monkeys on *** .

Post by Rocco Rutt » Sun, 29 Aug 2004 21:16:12

If you're the recipient, it requires you to get a signed mail so that
you get the key if auto-fetching is enabled. But maybe you see a
non-signed mail on a public list and want to start a private
conversation using encryption so that you need to fetch the key by hand.
Or you search the web for mails on mailing lists from a certain person
you not yet received a mail from and thus need information about the key
to get it by hand. Or...

bye, Rocco

Post by Paul Walke » Mon, 30 Aug 2004 20:15:53

No, the original poster was talking about putting the whole key in his
headers. I'm suggesting just the fingerprint, so that people can compare the
fingerprint of the key they get from the keyservers with the key that was
used to sign the message. Monkeys on any kind of drug don't really enter
into it.


Post by Nicholas W » Mon, 30 Aug 2004 21:39:09

- Paul Walker :

When I say I want to "publish" my key in my headers I mean exactly what
Peter said ... My fault, my english is not so good :)
Thanks everyone, I'll do as Paul suggested.