[pkg-gnupg-maint] Bug#884367: Bug#884367: gnupg2: Please bring skel files back as documentation/examples

Daniel Kahn Gillmor dkg at fifthhorseman.net
Thu Dec 14 19:04:08 UTC 2017


On Thu 2017-12-14 12:47:12 -0500, Matthew Gabeler-Lee wrote:
> My case was looking for essentially documentation on the recommendations 
> for some parameters that I think default to empty.

the recommendation is to use the default :)

> In particular I was having trouble with keys.gnupg.net and was
> wondering if there was a newer recommended server to use, hoping to
> find that in an updated copy of that sample file.

for modern gpg, the "keyserver" argument in gpg.conf is deprecated
anyway, since that's something that should go in dirmngr.conf instead.

but dirmngr defaults to a sensible choice -- see the --keyserver
documentation in dirmngr(8) for details:

       If no keyserver is explicitly configured, dirmngr will use the
       built-in default of hkps://hkps.pool.sks-keyservers.net.

This is better than keys.gnupg.net because it doesn't leak your
keyserver traffic directly to your ISP.

I'm closing this ticket because i think it's been resolved, but feel
free to reopen it if you have more suggestions.

In general, the recommendation should be "use the defaults" -- and in
cases where that's not happening, we should fix the defaults!  feel free
to open more bug reports if there are defaults that you think can be
improved.  even if upstream doesn't want to change them right now, we're
willing to improve the defaults for debian users in general.

Thanks for taking care to look into the details of the GnuPG packaging!

       --dkg



More information about the pkg-gnupg-maint mailing list