[openpgp] Re: Primary Key Binding sigs on authentication sub keys

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi, Daniel.

On 22 Jan 2025, at 16:40, Daniel Huigens <[email protected]> wrote:
> 
> we could also consider
> deprecating authentication subkeys entirely, and say that an application
> that (for some reason) wants to do authentication using OpenPGP, should
> use a dedicated key/certificate, and just use a normal signing (sub)key?

I think it’s a good idea to maintain the domain separation between data signing and authentication, since authentication typically signs over a short-lived challenge rather than a long-lived message. For example I can imagine a future scenario where it would make sense to have a post-quantum signing subkey (for robustness) together with a traditional authentication subkey (for compatibility).

In addition, authentication subkeys are widespread in the wild. The fact that they don’t have a specified OpenPGP signature mechanism hasn’t stopped people from using them, so surely it is better to regularise this usage pattern than deprecate it?

On a broader note, IMO we should bear in mind that OpenPGP has not historically been a strictly-defined or strictly-obeyed specification, and so discrepancies between the language of the specs and established practice crop up on a regular basis - which should not be surprising considering its organic history. I’m therefore not convinced that a literalist reading of the specs is always helpful.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmeRJHYACgkQXB7EBNWQ
ZinrTQ//ang8di6OYCqEY9ivokKG2fcti+dHIdftxVP363wi/zMBTVdCjI0qVs2w
/FFfLYv336itujB4p/g+04Jy0hjxSDQrBp8xFfauOpe6poq+n4zVgBPR6dELa51x
BMDmC7EhOf61T57k7T2O9nRJ6LFcyEThTofch5t8R5nIvGwUgvcmLAAh2AmIZA9r
jM4VoEZNKPmp450cndyiUEo1V0A/dzAO1+IJbz0pdfznFVkM1eCksufmlvicffgq
Ul4F+zdoY1kXi36ekEG5IPvLxq0e3VEQlLR9RVm6TYxsCyfDrJolxdFxmmS8judU
U8venHR1Qej6PmFCGotOqcls+AmDhhvwlVHuRbVM3ZEeQrCi82J3eVMhd/qB2qr9
SN3ukkNKJ+MZONjlSsXJi5Em0lOTFyko+v5V6tXxBCIF6AtfN3KI0EsUo3tjhPLX
V6/GzlTdM3u95azTAUssYIq2BLxY3e0jFD/sbY5gKURJTn3YUdNYf4vRkKZOk7hb
FDZ+7tu9C3SuYp+CY0KH6WD1uPdcDW1fTRBdoYVflPxi42u/OY4ZvWgHF9Xwv063
IX/FTTuGavNESh/tTZDFQ4gH/XIcZvZhC3GWX5zypUXQw7f8/o816TWi1qy7pUFt
WImMuV8oy70vvi8hzoHEikKR4Ql2kQ4ralDMsItGLRzBIoz3RsQ=
=SWJL
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.