Page MenuHome GnuPG

Remove DANE (DNSSEC) support
Open, Needs TriagePublic

Description

Currently Gnupg (e.g. 2.5.14) lists DANE as supported, e.g. in https://gnupg.org/documentation/manuals/gnupg/GPG-Configuration-Options.html#index-auto_002dkey_002dlocate

However https://dev.gnupg.org/T4464 and https://dev.gnupg.org/T4618 show that this support is not really complete and maintained. So Werner stated:

DANE for OpenPGP is an experimental RFC (RFC-7929) and it is likely that we will remove the support because it is too hard for most users to add keys to a zone. Further a validating resolver on the desktop is too hard to maintain and the cause of too many other failures. And no, unbound etc is not an option because it is not usable by the majority of GnuPG users.

Removing it is a task that should be done to remove old, rarely used code and make the documentation more correct in this place.