3 ms·
> I have my own domain, so maybe OPENPGPKEY record in my domain as well > DNS-Based Authentication of Named Entities (DANE) Bindings for OpenPGP WKD has some
by Whatitat90 7y ago
> I have my own domain, so maybe OPENPGPKEY record in my domain as well
> DNS-Based Authentication of Named Entities (DANE) Bindings for OpenPGP
WKD has some benefits over OPENPGPKEY - it keeps the request confidential (as WKD uses plain HTTPS). WKD is just easier to get right, that's why it's more broadly supported. GnuPG, that supports both of them, defaults to WKD. If OPENPGPKEY request is made it seems GnuPG doesn't even validate DNSSEC signatures: https://lists.gnupg.org/pipermail/gnupg-users/2011-December/043361.html https://lists.gnupg.org/pipermail/gnupg-users/2011-December/...