You are viewing an old revision of this page.
An OpenPGP KeyServer run by the PGPCorporation.
A list of issues includes:
- When viewed as a RobotCA the PGPGlobalDirectory is signifcantly weaker than other RobotCAs in that it sends verifications unencrypted and unsigned.
- The server strips signatures from keys not registered with it.
- The server does not appear to provide any method of viewing signatures on the keys it serves.
- The key used to sign keys is not itself viewable through the server.
- Signatures and keys published on other key servers do not appear to migrate to the PGPGlobalDirectory, and visa versa.
- Server asks users to sign the directory verification key without any independent verification.
- Signatures issued by the RobotCA do not use a policy URL.
See:
https://keyserver-beta.pgp.com/