[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-02.txt
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi, all. Before I finalise a fresh draft for key replacement, I’d like to gauge the WG’s opinion on two particular matters that arose from Johannes’s earlier email. The first issue is the “stickiness” of key equivalence. It is not clear from the current draft whether a replacement key that has a key equivalence binding should be considered valid indefinitely, even if the original key is hard revoked, or the equivalence binding is otherwise broken. In a separate discussion on the tb-planning list, Kai Engert said that he would prefer a “non-sticky” scenario. I have therefore proposed wording to clarify that Key Equivalence is *not* sticky: > An implementation MUST NOT assume that Key Equivalence Bindings have any permanent significance. > For example, if an MUA relies solely upon a Key Equivalence Binding between A and B to validate B, the validity of B at a future date depends on the continuing validity of the Key Equivalence Binding. > If the binding is no longer valid, and there are no other trust pathways to B, then B is no longer valid. > It is therefore RECOMMENDED that applications attempt to find alternative trust pathways for replacement certificates. > The optimal method of obtaining alternative trust pathways is application-dependent, and therefore beyond the scope of this document. > It should be noted however that similar time evolution concens also apply to other methods of validation, such as WoT. Is the above clarification acceptable to the WG? https://gitlab.com/andrewgdotcom/openpgp-replacementkey/-/merge_requests/20/diffs Johannes also suggested that encryption fallback may not be desirable in all circumstances: >> B might want to state "I am a replacement for A". But in doing so, B forms an equivalence binding with A and legitimates the use of A's subkeys. Do we need a possibility to state "I replace this key but I don't want anyone to use it as fallback”? I have therefore proposed a change to the wire format of the target records, and modifies the semantics so that encryption fallback is only performed if a flag bit is set on the corresponding inverse target record: > * If there is an equivalence binding, the subkeys in the first listed original certificate SHOULD be considered next. > If none of those are usable, or if the Encryption Fallback flag is not set in the inverse target record, then the subkeys in the next original certificate (if any) SHOULD be considered, and so forth. This means that in order for fallback encryption to be performed, the flag bit must be explicitly set, rather than assumed. This is a significant change to the behaviour of the subpacket. Does the WG agree that this change is useful? If so, is the proposed language clear? https://gitlab.com/andrewgdotcom/openpgp-replacementkey/-/merge_requests/17/diffs Thanks, A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmeTzpcACgkQXB7EBNWQ ZilaiBAAopcwMSiVAYAAMrQIAvQbeigY232t9EKJ+xHWG4Ymyx2XBc9E+q42dcGd 4b03Z0eVeZBVZjQwZFy4dlfp9AnW8PIgY1xrDyGOKVHh71stUsLCMttXJAe/w3IW u0OvTzmFSDIAYquy/fS+kr4YqQM9Pmw/zszcTxM5Hgsi5JleB+oXMHjuKx4Pm8Ah 8B01OODswIQSBwZzarBdjsvb9DQzBVT2B6V9tehFYToRgZK0L0n2Vv0zfnWVpDOs Ul9nvoOJ9VaPl6ra6sYaetM3HXGyQcNL1zAdOnKDDPNTWEqaXe5u4is+KWsPpscg 1qD8LNqjy0s4L9MaCPfgZ/Bgf12r5t19xp9WXO5J4PLWSO0O+drTMa4opbpcRmSK LEelib8t8Zdb3y4pedDisnLbO9j1ROEKmSneqS3/ZzIrB1TFnzgljYtPFx9tbAw3 QzoyUwiSxhnB54uuaGkHOnyLf9Gt44ybb0ouz9RUQ4cMMXgVUJGXwxVbIwv4Cx6+ fXuKexrcAKn9NqZCGf7htJzMZOLH8nh8NTM/ime9PRythekSy1jgrVeEPTLPdo4t DoceRyoD7JBFNF/N9y/gDrwqZSmvm2aNe7V6RkzuwKUlXSstk+qJBdvhMZBZ9DV8 mIxWWkXMkLUzZ6/VeGHikvRu7Ig3e9aFo6eAKnNWPrVnxYTno04= =ZSnu -----END PGP SIGNATURE-----