Importing public key from keys.openpgp.org fails with "no user ID"
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
gnupg2 (Debian) |
Fix Released
|
Unknown
|
|||
gnupg2 (Ubuntu) |
Confirmed
|
Undecided
|
Unassigned |
Bug Description
Running (up to date) 18.04 LTS I'm trying to import a public key from the somewhat new but OpenPGP key spamming resistant key server at keys.openpgp.org:
$ curl -s 'https:/
gpg: key 0x7BE5A11FA37E8721: no user ID
gpg: Total number processed: 1
$
This key fails to import (GPG does not report that any keys were imported).
$ gpg --version | head -n2
gpg (GnuPG) 2.2.4
libgcrypt 1.8.1
$
This makes it impossible to use most of the keys stored on the keys.openpgp.org keyserver and forces users (who want / need to use key servers) to instead work with SKS keyservers which do not prevent signature spamming, on a GPG build which lacks fixes against signature spamming. Which puts Ubuntu 18.04 LTS users at great risk of becoming victims of signature spamming, breaking their GPG installations in ways which are difficult to debug.
This issue has been previously discussed and solved in Debian at https:/
ProblemType: Bug
DistroRelease: Ubuntu 18.04
Package: gnupg 2.2.4-1ubuntu1.2
ProcVersionSign
Uname: Linux 5.0.0-27-generic x86_64
ApportVersion: 2.20.9-0ubuntu7.7
Architecture: amd64
CurrentDesktop: ubuntu:GNOME
Date: Sun Sep 15 16:20:13 2019
SourcePackage: gnupg2
UpgradeStatus: No upgrade log present (probably fresh install)
CVE References
Changed in gnupg2 (Debian): | |
status: | Unknown → Fix Released |
Some more context:
"New" keys.openpgp.org key server: /keys.openpgp. org/about/ news#2019- 06-12-launch
https:/
Isses with SKS keyservers: /medium. com/@mdrahony/ are-sks- keyservers- safe-do- we-need- them-7056b49510 1c
https:/
OpenPGP certificate (key signature) flooding / spam: /www.vice. com/en_ us/article/ 8xzj45/ someone- is-spamming- and-breaking- a-core- component- of-pgps- ecosystem /gist.github. com/rjhansen/ 67ab921ffb4084c 865b3618d695527 5f /dkg.fifthhorse man.net/ blog/openpgp- certificate- flooding. html /nvd.nist. gov/vuln/ detail/ CVE-2019- 13050
https:/
https:/
https:/
https:/