An Administrator in an organisation should be able through the registry (kleopatrarc registry config mechanism) to set a key as a designated revoker for all newly created keys. This will mean adding support for ‐‐add‐desig‐revoker to GPGME.
Description
Description
Revisions and Commits
Revisions and Commits
Related Objects
Related Objects
- Mentioned In
- T6882: Make ADSK configurable for new keys
- Mentioned Here
- T7133: Add feature to load designated revoker from LDAP
Event Timeline
Comment Actions
Although it is implemented in gnupg-2.2 we should add another feature: Iff this option is configured, gpg shall try to load the requested key from LDAP in the same manner as it does for a trusted-key.
Comment Actions
I think it would be cleaner to create a separate ticket for making gpg fetch the requested key from LDAP.
Comment Actions
I've moved the gpg task to a new ticket, T7133: Add feature to load designated revoker from LDAP
The Kleopatra task is obsolete, as it was noticed that the proposed option is already in gpg and should not be implemented twice.