Pawel Shajdo wrote: > > I think this is public more keyservers design problem than GD. Keyserver > should accept new signatures only from key owner. >
Hm, maybe to define a "key upload format" which must be signed with the uploaded key itself (analogon of PKCS#10)? Of course, the public key itself should have some flag set to "signed upload only" so that the server doesn't accept it without the corresponding signature.
signature.asc
Description: OpenPGP digital signature
_______________________________________________ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users