Skip to content

gpg.mozilla.org is broken (probably for good) #727

@ajvb

Description

@ajvb

gpg.mozilla.org is busted at the moment and it is likely that it will stay this way. Mozilla has been wanting to retire it for a while, and it looks like it might happen here quickly.

Currently, this keyserver is hardcoded as the default for sops, and can only be changed using an env var (SOPS_GPG_KEYSERVER).

I think that in the short term, it might be best to switch to a different SKS server, with hkps.pool.sks-keyservers.net being the most likely candidate in my mind.

In the longer term, I'd want to consider some combination of:

  1. Switching to age as our recommended default - Add support for age. #688
  2. Supporting Keybase and recommending it as the default - Support key fetching from keybase.io #200

I don't think we should remove SKS-based key fetching, but we should consider moving away from it. The SKS keyserver network is not doing to well - https://code.firstlook.media/the-death-of-sks-pgp-keyservers-and-how-first-look-media-is-handling-it

Metadata

Metadata

Assignees

Labels

bugpriority/highHigh priority issues (e.g. bugs that do not have a workaround or issues that affect many)

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions