Questions about Web Key Directory I-D version 06

Wiktor Kwapisiewicz wiktor at metacode.biz
Wed May 23 20:35:27 CEST 2018


Hello,

I'm implementing Web Key Directory support in OpenKeychain and have
some questions about the current version of the draft: 06 [0].

1. The draft does not specify if redirects should be followed,
for example, for this URL:

  https://example.org/.well-known/openpgpkey/hu/iy9q119eutrkn8s1mk4r39qejnbu3n5q

If the HTTP response is a redirect code (301, etc.) should it be
followed? As far as I can see both gnupg and servers in the wild
(e.g. kernel.org) utilize redirects. Are there any restrictions
to these redirects (e.g. only to https schemes? or is http also
allowed?).

2. The I-D mentions in several places Content-Type:
application/octet-string, I think this is a typo, it should be
application/octet-stream.

Sub-question: is there no better media type? I've browsed the IANA
registry, sadly application/pgp-keys is only for armored keys (RFC 3156 [1]).

Thank you for your time!

Kind regards,
Wiktor

[0]: https://datatracker.ietf.org/doc/draft-koch-openpgp-webkey-service/

[1]: https://tools.ietf.org/html/rfc3156#section-7

-- 
*/metacode/*



More information about the Gnupg-devel mailing list