From e10f47cb4d3b1f05d57ad0aad7b352e697606a3e Mon Sep 17 00:00:00 2001 From: Tharre Date: Mon, 4 Sep 2017 15:49:23 +0200 Subject: gnupg: fix keyserver configuration GnuPG only honors the last given keyserver[0]. So specifying multiple keyservers does nothing. Furthermore, hkps requires the certificate file to be specified[1], which may or may be installed. IPv6 may also cause problems, and gpg does not retry if a connection fails. For these reasons, we use the IPv4 only pool of sks. [0] https://lists.gnupg.org/pipermail/gnupg-users/2003-May/018147.html [1] https://sks-keyservers.net/overview-of-pools.php --- .gnupg/gpg.conf | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.gnupg/gpg.conf b/.gnupg/gpg.conf index 77b71a8..70f1734 100644 --- a/.gnupg/gpg.conf +++ b/.gnupg/gpg.conf @@ -6,7 +6,4 @@ encrypt-to 0xC8F0B2F4 # automatically fetch keys keyserver-options auto-key-retrieve - -keyserver hkps://hkps.sks-keyservers.net -keyserver hkp://pool.sks-keyservers.net -keyserver http://pgp.mit.edu +keyserver hkp://ipv4.pool.sks-keyservers.net -- cgit v1.2.3-70-g09d2