Skip to content

ca-cert-file option deprecated in GnuPG 2.1 #294

@a3nm

Description

@a3nm

Hello,

The OpenPGP Best Practices guide https://help.riseup.net/en/gpg-best-practices instructs users to add the following to ~/.gnupg/gpg.conf:

keyserver-options ca-cert-file=/path/to/CA/sks-keyservers.netCA.pem

However, for users running GnuPG 2.1, this will result in the following warning:

gpg: keyserver option 'ca-cert-file' is obsolete; please use 'hkp-cacert' in dirmngr.conf

Further, it will be ignored according to https://www.gnupg.org/documentation/manuals/gnupg/GPG-Configuration-Options.html

I think the guide should be updated accordingly, though I'm not sure whether the more recent option is supported on older versions that people may still be using.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions