From 2430cda297d06ff2af8f68c1bd4341025dcba0b3 Mon Sep 17 00:00:00 2001
From: Vincent Breitmoser
+ Short answer: No. +
+ ++ A "third party signature" is a signature on a key + that was made by some other key. + Most commonly, + those are the signatures produced when "signing someone's key", + which are the basis for + the "Web of Trust". + For a number of reasons, + those signatures are not currently distributed + via keys.openpgp.org. +
+ ++ The killer reason is spam. + Third party signatures allow attaching arbitrary data to anyone's key, + and nothing stops a malicious user from + attaching so many megabytes of bloat to a key + that it becomes practically unusable. + Even worse, + they could attach offensive or illegal content. +
+ ++ There are ideas to resolve this issue. + For example, signatures could be distributed with the signer, + rather than the signee. + Alternatively, we could require + cross-signing by the signee before distribution + to support a + caff-style + workflow. + If there is enough interest, + we are open to working with other OpenPGP projects + on a solution. +
+