Can't use local mailvelope keyserver

T. Initus's Avatar

T. Initus

27 Aug, 2019 10:32 PM

Hi,

I configured a local mailvelope keyserver, which works well if queried manually using hkps:

openssl s_client -connect 192.0.2.15:443
GET /pks/lookup?op=get&keyId=0xabcdef1234567890&options=mr

However when using gpgtools/GPG Keychain and setting the keyserver there to 192.0.2.15, all I get is "bad server".

When observing traffic with Wireshark, i notice the ssl connection being terminated right after the key exchange.

I've tried to run a "fake" ssl server using openssl s_server on port 443, but all I get is the same behaviour.

Using: GPG Suite 2019.1 2542n, GPG Kychain 1.5 1579n

  1. 1 Posted by T. Initus on 27 Aug, 2019 10:34 PM

    T. Initus's Avatar

    Since there were these automated suggestions: There is no firewall issue, since openssl is able to connect.

  2. 2 Posted by T. Initus on 28 Aug, 2019 07:05 AM

    T. Initus's Avatar

    I however have the impression it is unlikely to be a certificate issue either, since:

    $ /usr/local/MacGPG2/bin/dirmngr -vvvv --no-detach (...) dirmngr[2891.0]: Vertrauenswürdiges Zertifikat `/Users/t/keyserver.pem' wurde geladen
    (...) OK Dirmngr 2.2.17 at your service
    KEYSERVER hkps://keyserver.example.org
    OK
    KS_GET (fingerprint)
    dirmngr[2891.0]: resolve_dns_addr for 'keyserver.example.org': 'keyserver.example.org' [already known]
    S SOURCE https://keyserver.example.org:443
    (...) OK

    works just fine and as expected.

  3. Support Staff 3 Posted by Luke Le on 17 Sep, 2019 12:49 PM

    Luke Le's Avatar

    Hmm... kannst du bitte mal debug logging aktivieren für dirmngr:

    echo "debug-level guru" >> ~/.gnupg/dirmngr.conf
    echo "debug-all" >> ~/.gnupg/dirmngr.conf
    echo "log-file /tmp/dirmngr.log" >> ~/.gnupg/dirmngr.conf
    killall dirmngr

    Dann einen versuch in GPG Keychain ausführen den keyserver zu switchen und /tmp/dirmngr.log hier anhängen.

    Danke!

Reply to this discussion

Internal reply

Formatting help / Preview (switch to plain text) No formatting (switch to Markdown)

Attaching KB article:

»

Attached Files

You can attach files up to 10MB

If you don't have an account yet, we need to confirm you're human and not a machine trying to post spam.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac