Penguin
Note: You are viewing an old revision of this page. View the current version.

An OpenPGP KeyServer run by the PGPCorporation.

A list of issues includes:

  1. When viewed as a RobotCA the PGPGlobalDirectory is signifcantly weaker than other RobotCAs in that it sends verifications unencrypted and unsigned.
  2. The server strips signatures from keys not registered with it.
  3. The server does not appear to provide any method of viewing signatures on the keys it serves.
  4. The key used to sign keys is not itself viewable through the server.
  5. Signatures and keys published on other key servers do not appear to migrate to the PGPGlobalDirectory, and visa versa.
  6. Server asks users to sign the directory verification key without any independent verification.
  7. Signatures issued by the RobotCA do not use a policy URL.

See: https://keyserver-beta.pgp.com/