aboutsummaryrefslogtreecommitdiffstats
path: root/util/pka.c (follow)
Commit message (Collapse)AuthorAgeFilesLines
* Switch to a hash and CERT record based PKA system.Werner Koch2015-02-261-204/+201
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | * util/pka.c: Rewrite. (get_pka_info): Add arg fprbuflen. Change callers to pass this. * util/strgutil.c (ascii_strlwr): New. * configure.ac: Remove option --disable-dns-pka. (USE_DNS_PKA): Remove ac_define. * g10/getkey.c (parse_auto_key_locate): Always include PKA. -- Note that although PKA is now always build, it will only work if support for looking up via DNS has not been disabled. The new PKA only works with the IPGP DNS certtype and shall be used only to retrieve the fingerprint and optional the key for the first time. Due to the security problems with DNSSEC the former assumption to validate the key using DNSSEC is not anymore justified. Instead an additional layer (e.g. Trust-On-First-Use) needs to be implemented to track change to the key. Having a solid way of getting a key matching a mail address is however a must have. More work needs to go into a redefinition of the --verify-options pka-lookups and pka-trust-increase. The auto-key-locate mechanism should also be able to continue key fetching with another method once the fingerprint has been retrieved with PKA. Signed-off-by: Werner Koch <[email protected]> This is a backport from master. (backported from commit 2fc27c8696f5cf2ddf3212397ea49bff115d617b)
* Removed some set but unused vars.Werner Koch2011-08-091-3/+1
|
* Fix bug#1307Werner Koch2011-08-091-14/+18
| | | | | This is a backport of the fixes for 2.0. There is only one real bug, the other changes are for clarity and for more picky compilers.
* Minor changes to help the VMS portWerner Koch2010-09-281-9/+16
|
* Switched to GPLv3.Werner Koch2007-10-231-4/+2
| | | | | Updated gettext.
* * argparse.c (default_strusage): Copyright 2007.David Shaw2007-04-151-1/+2
| | | | | * cert.c, srv.c, pka.c: Need arpa/inet.h for ntohs().
* Implemented PKA trust modelWerner Koch2005-07-281-2/+2
|
* Implemented PKA trust modelWerner Koch2005-07-281-0/+254