On 03/05/18 12:40, Moritz Wirth wrote:
What about only accepting valid keys and removing all revoked or
expired
keys from the database?
I assume you mean "remove the user-id packets of all revoked or expired
keys"? You would have to retain at least the revocation signature and
the primary key, to make sure that nobody tried to re-upload a
non-revoked copy of the key, and to make sure that the keyservers still
served their primary purpose of distributing key revocations.
But the primary key could itself be considered personal data...
_______________________________________________
Sks-devel mailing list
address@hidden
https://lists.nongnu.org/mailman/listinfo/sks-devel