[openpgp] Re: Primary Key Binding sigs on authentication sub keys
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi, Daniel. On 22 Jan 2025, at 16:40, Daniel Huigens <[email protected]> wrote: > > we could also consider > deprecating authentication subkeys entirely, and say that an application > that (for some reason) wants to do authentication using OpenPGP, should > use a dedicated key/certificate, and just use a normal signing (sub)key? I think it’s a good idea to maintain the domain separation between data signing and authentication, since authentication typically signs over a short-lived challenge rather than a long-lived message. For example I can imagine a future scenario where it would make sense to have a post-quantum signing subkey (for robustness) together with a traditional authentication subkey (for compatibility). In addition, authentication subkeys are widespread in the wild. The fact that they don’t have a specified OpenPGP signature mechanism hasn’t stopped people from using them, so surely it is better to regularise this usage pattern than deprecate it? On a broader note, IMO we should bear in mind that OpenPGP has not historically been a strictly-defined or strictly-obeyed specification, and so discrepancies between the language of the specs and established practice crop up on a regular basis - which should not be surprising considering its organic history. I’m therefore not convinced that a literalist reading of the specs is always helpful. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmeRJHYACgkQXB7EBNWQ ZinrTQ//ang8di6OYCqEY9ivokKG2fcti+dHIdftxVP363wi/zMBTVdCjI0qVs2w /FFfLYv336itujB4p/g+04Jy0hjxSDQrBp8xFfauOpe6poq+n4zVgBPR6dELa51x BMDmC7EhOf61T57k7T2O9nRJ6LFcyEThTofch5t8R5nIvGwUgvcmLAAh2AmIZA9r jM4VoEZNKPmp450cndyiUEo1V0A/dzAO1+IJbz0pdfznFVkM1eCksufmlvicffgq Ul4F+zdoY1kXi36ekEG5IPvLxq0e3VEQlLR9RVm6TYxsCyfDrJolxdFxmmS8judU U8venHR1Qej6PmFCGotOqcls+AmDhhvwlVHuRbVM3ZEeQrCi82J3eVMhd/qB2qr9 SN3ukkNKJ+MZONjlSsXJi5Em0lOTFyko+v5V6tXxBCIF6AtfN3KI0EsUo3tjhPLX V6/GzlTdM3u95azTAUssYIq2BLxY3e0jFD/sbY5gKURJTn3YUdNYf4vRkKZOk7hb FDZ+7tu9C3SuYp+CY0KH6WD1uPdcDW1fTRBdoYVflPxi42u/OY4ZvWgHF9Xwv063 IX/FTTuGavNESh/tTZDFQ4gH/XIcZvZhC3GWX5zypUXQw7f8/o816TWi1qy7pUFt WImMuV8oy70vvi8hzoHEikKR4Ql2kQ4ralDMsItGLRzBIoz3RsQ= =SWJL -----END PGP SIGNATURE-----