[openpgp] Primary Key Binding sigs on authentication subkeys

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi, all.

A recent discussion [1] on the pm/g-c repo raised a question about some of the wording in RFC9580. Section 10.1.5 [2] says:

> Each Subkey packet MUST be followed by one Signature packet, which should be a Subkey Binding signature issued by the top-level key. For subkeys that can issue signatures, the Subkey Binding signature MUST contain an Embedded Signature subpacket with a Primary Key Binding signature (Type ID 0x19) issued by the subkey on the top-level key.

The question arising is: what does “subkeys that can issue signatures” mean? Historically, many implementations (including gnupg) interpreted this narrowly to mean “subkeys with the 0x02 key flag”, and we can see in the SKS dataset that there are a huge number of auth subkeys in the wild without primary key binding sigs.

While it is relatively harmless to add the embedded backsig to new authentication key binding signatures, I believe enforcing this on existing keys is an unnecessary breaking change. It is also not clear what attack this mitigates.

IMO we must clarify this, however there are several options for how to do so:

1. Make the backsig optional on authentication subkeys, e.g. by modifying section 10.1.5 to read “subkeys with the 0x02 flag”.
2. Make the backsig optional on v4 authentication subkeys, but mandatory on v6.
3. Specifically recommend against using backsigs on any auth subkeys.

There may be other options.

IMO it would also be very helpful to spell out the motivation behind the primary key binding signature, so that future spec authors can determine when to require it on novel signature types.

I would be happy to add any agreed language to draft-signatures for future reference. [3]

Thanks,
A

[1] https://github.com/ProtonMail/go-crypto/pull/265
[2] https://www.rfc-editor.org/rfc/rfc9580.html#section-10.1.5-8
[3] https://datatracker.ietf.org/doc/html/draft-gallagher-openpgp-signatures

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmeI230ACgkQXB7EBNWQ
ZimmRA/+OFymv32hex903J0yoVJONPmgBu/FR1CvYMRJPjYzYZR2s7zHJAn2piju
ZsQHS8Qh7WGh/FzcSAIXledGH2lQNeU9VLJIzQTyzEEG45kREeuX0VZ/qfobAwue
mA28gjRPhdqVIJH590/MiQPxVTtYV/X89RwSZC5kilHig7jlJwaqDKPR2HkLTbVD
tGVZ9wTWzEXRHspFp0YQHfWd+URcJvKyBMWgLoMgB76fBmPEBsc91dJmweokGMGH
HbNrImmgW4weaV1NN8qMwW2bdOTMpdqIbY+BDETxQ3qiOK3nelCMZZcUAOCYm2PS
PDXjgDMYDKQ4t1KnBtR1uCib+/WxtxHSBLsrmbOfWNjFlQ1AuzC5J7gy/PQUzrju
JY8g8541T5ByyyT4eE+IvEHo5zhRKTrOKgcXa0VleqMY4tlehAx9ffTcjb/ATr+w
+2Fjlz1i1hBOFZZl+STw6HeIumz/KIYnB71uJSfA5kbGVMe5DwNRnIU7Ct1eOIBk
wExy2kX9j67baVje+0Dx10KbwYU+At52mQGrcpw13oEhPxs7hfu8ot0aNvmnEab2
FAlUmqb2x69n79MqvcTMws/qwPbIsvcgLFoLZN13GuKalB9xGjhofEiuKd+htndb
DSe5RMWXSG9QGzBT8atIUX0HYxRaYE3UnPas5WA1KQe67zjbILs=
=6TYU
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.