[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-02.txt
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <BEeS2ActRDMBc7u_4OgmX06FsbP4SQRe-bS1rRTWUUjJEay00OYlNcp7hxhHwCY3Y1dMU3XKXF346dBAVwiQrGxvJKz6iznQyNC1u9LC1Cs=@protonmail.com> |
Hi Andrew & Johannes & all, On Friday, January 24th, 2025 at 18:32, Andrew Gallagher wrote: >> An implementation MUST NOT assume that Key Equivalence Bindings have any permanent significance. (...) > > Is the above clarification acceptable to the WG? This makes sense to me. The implementation will (need to) evaluate the binding at the time that it wants to use (one of) the keys, which seems natural. >>> B might want to state "I am a replacement for A". But in doing so, B forms an equivalence binding with A and legitimates the use of A's subkeys. Do we need a possibility to state "I replace this key but I don't want anyone to use it as fallback”? I'm not sure this makes sense to me; can't/shouldn't I just revoke or expire key A in that case? Also, A will only be used as a fallback to B if the sending implementation doesn't support key B. Is there any use case to being able to say something like, "existing correspondents may continue to communicate with me using key A, but new correspondents (looking up my key from a keyserver) must use key B, even if they don't support it"? That seems like a strange request to me. Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]