The standard-resolver option makes it work, how strange. I can see the system trys to resolve the SRV record and then after that an A/AAAA record.
- Craig On Mon, 26 Nov 2018 at 18:45, Werner Koch <w...@gnupg.org> wrote: > On Sun, 25 Nov 2018 22:22, csm...@debian.org said: > > It seems it needs the SRV record and fails wrong without it. > > Checking on the same system looking up that SRV record I get the > > expected NXDOMAIN error. > > That seems to be a Debian specific problem; with a dirmngr started by > the gpg command, I get this with master (and pretty sure also with 2.2.11): > > DBG: chan_7 <- KEYSERVER --clear hkp://keyring.debian.org > DBG: chan_7 -> OK > DBG: chan_7 <- KS_GET -- 0xDF50FEA5 > DBG: dns: libdns initialized > DBG: dns: getsrv(_pgpkey-http._tcp.keyring.debian.org) -> 0 records > DBG: dns: resolve_dns_name(keyring.debian.org): Success > resolve_dns_addr for 'keyring.debian.org': 'keyring.debian.org' > [already known] > resolve_dns_addr for 'keyring.debian.org': 'keyring.debian.org' > [already known] > DBG: dns: resolve_dns_name(keyring.debian.org): Success > DBG: chan_7 -> S SOURCE http://keyring.debian.org:11371 > DBG: (20847 bytes sent via D lines not shown) > > Can you please test with > > standard-resolver > no-use-tor > > in dirmngr.conf ? > > > -- > Die Gedanken sind frei. Ausnahmen regelt ein Bundesgesetz. >
2018-11-26 22:49:04 dirmngr[14811.0] certificate '/etc/ssl/certs/ca-certificates.crt' already cached 2018-11-26 22:49:04 dirmngr[14811.0] permanently loaded certificates: 136 2018-11-26 22:49:04 dirmngr[14811.0] runtime cached certificates: 0 2018-11-26 22:49:04 dirmngr[14811.0] trusted certificates: 136 (135,0,0,1) 2018-11-26 22:49:04 dirmngr[14811.6] handler for fd 6 started 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> # Home: /home/csmall/.gnupg 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> # Config: /home/csmall/.gnupg/dirmngr.conf 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> OK Dirmngr 2.2.11 at your service 2018-11-26 22:49:04 dirmngr[14811.6] connection from process 14810 (1000:1000) 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 <- GETINFO version 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> D 2.2.11 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> OK 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 <- KEYSERVER --clear hkp://keyring.debian.org 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 -> OK 2018-11-26 22:49:04 dirmngr[14811.6] DBG: chan_6 <- KS_GET -- 0xDF50FEA5 2018-11-26 22:49:04 dirmngr[14811.6] DBG: dns: getsrv(_pgpkey-http._tcp.keyring.debian.org) -> 0 records 2018-11-26 22:49:09 dirmngr[14811.6] DBG: dns: resolve_dns_name(keyring.debian.org): Success 2018-11-26 22:49:09 dirmngr[14811.6] resolve_dns_addr for 'keyring.debian.org': 'keyring.debian.org' [already known] 2018-11-26 22:49:09 dirmngr[14811.6] resolve_dns_addr for 'keyring.debian.org': 'keyring.debian.org' [already known] 2018-11-26 22:49:09 dirmngr[14811.6] number of system provided CAs: 136 2018-11-26 22:49:09 dirmngr[14811.6] DBG: Using TLS library: GNUTLS 3.5.19 2018-11-26 22:49:09 dirmngr[14811.6] DBG: http.c:connect_server: trying name='keyring.debian.org' port=11371 2018-11-26 22:49:14 dirmngr[14811.6] DBG: dns: resolve_dns_name(keyring.debian.org): Success 2018-11-26 22:49:14 dirmngr[14811.6] DBG: http.c:1877:socket_new: object 0x00007f663034a020 for fd 7 created 2018-11-26 22:49:14 dirmngr[14811.6] DBG: http.c:request: 2018-11-26 22:49:14 dirmngr[14811.6] DBG: >> GET /pks/lookup?op=get&options=mr&search=0xDF50FEA5 HTTP/1.0\r\n 2018-11-26 22:49:14 dirmngr[14811.6] DBG: >> Host: keyring.debian.org:11371\r\n 2018-11-26 22:49:14 dirmngr[14811.6] DBG: http.c:request-header: 2018-11-26 22:49:14 dirmngr[14811.6] DBG: >> \r\n 2018-11-26 22:49:14 dirmngr[14811.6] DBG: chan_6 -> S PROGRESS tick ? 0 0 2018-11-26 22:49:15 dirmngr[14811.6] DBG: http.c:response: 2018-11-26 22:49:15 dirmngr[14811.6] DBG: >> HTTP/1.1 200 OK\r\n 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Date: Mon, 26 Nov 2018 11:49:14 GMT' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Server: Apache' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'X-Content-Type-Options: nosniff' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'X-Frame-Options: sameorigin' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Referrer-Policy: no-referrer' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'X-Xss-Protection: 1' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Vary: Accept-Encoding' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'X-Clacks-Overhead: GNU Terry Pratchett' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Connection: close' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: 'Content-Type: text/html; charset=ISO-8859-1' 2018-11-26 22:49:15 dirmngr[14811.6] http.c:RESP: '' 2018-11-26 22:49:15 dirmngr[14811.6] DBG: chan_6 -> S SOURCE http://keyring.debian.org:11371 2018-11-26 22:49:15 dirmngr[14811.6] DBG: (20847 bytes sent via D lines not shown) 2018-11-26 22:49:15 dirmngr[14811.6] DBG: chan_6 -> OK 2018-11-26 22:49:15 dirmngr[14811.6] DBG: chan_6 <- BYE 2018-11-26 22:49:15 dirmngr[14811.6] DBG: chan_6 -> OK closing connection 2018-11-26 22:49:15 dirmngr[14811.6] handler for fd 6 terminated