OpenPGP certificate flooding
OpenPGP certificate flooding
Posted Jul 4, 2019 0:18 UTC (Thu) by pabs (subscriber, #43278)In reply to: OpenPGP certificate flooding by vadim
Parent article: OpenPGP certificate flooding
For context; the proper way to get signatures on your OpenPGP key is that signers use caff or similar to send email containing signatures to the UIDs on your key to verify that the key holder also owns the email addresses. On receiving the emails the key holder imports the signatures and forwards their key to the keyserver network.
So my proposal fits into the proper workflow for obtaining and distributing signatures (that most communities use) and as a bonus eliminates both spam signatures and improperly distributed signatures that haven't verified UID control or haven't even verified fingerprints. Of course the signer and key holder could workaround this using other more manual transports, but hopefully those would be deprecated in all the tools surrounding signing.