duraconf
duraconf copied to clipboard
remove keyserver in gpg.conf and include dirmng.conf (CVE-2019-13050)
As described in https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f
the mitigations includes
- Open
gpg.confin a text editor. Ensure there is no line starting withkeyserver. If there is, remove it. - Open
dirmngr.confin a text editor. Add the linekeyserver hkps://keys.openpgp.orgto the end of it.
So at the very least, the gpg.conf file needs reviewing. I'm looking for a good known configuration with sane defaults, came up empty so far.
@lestephane, have you found another source on a more up-to-date and hardened gpg.conf file?