[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-02.txt
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 27 Jan 2025, at 17:03, Daniel Huigens <[email protected]> wrote: > > On Monday, January 27th, 2025 at 17:55, Andrew Gallagher wrote: >> If you have the secret key material to A, yes that would be a better method. Unfortunately loss of secret key material is still a common occurrence. And publishing an escrowed (hard) revocation would invalidate both the forward replacement subpacket and any historical signatures, so a user may not wish to avail of that option. > > Right, OK. > > But, if you lost the key material to key A, what's the use case for key B to say that it's the replacement of A? Nobody should trust that information (without any confirmation), because otherwise anyone could claim to replace anyone else's key. So, it might be best to just publish key B (without any binding to key A), get it verified and so on, and then just tell people manually to use that one (if they're still sending you emails encrypted using key A). It would only work if B was already the (bound equivalent) replacement of A, and then the key holder subsequently lost access to A. It could be years later they misplaced the passphrase or some such. They could still say “upgrade from A to B if you can”, but without encouraging fallback. Admittedly this is a rare scenario... A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmeXvdYACgkQXB7EBNWQ ZilQhw//WaiVEbkxZ/E5YNWqJEgfcATaGOVxbqcNiGOokaObvT5vE8CXI7FGQtdO WPQloehJFl20UFgmODd4j9YVU1uFhGTNPMFqpgoK+Qh9E3J2FogkyMLuWP1Mc4Xm wj0R/AqNvb/DCvnHXJxXEdrWPipeqoIxCnt0qfgmH+2QltvnS+WX8UKV+/FzRSbk XctXII1c7r+roOqEh3dbgdIazGW2THt8r8FK3MxsPNLaYepwwqwFuUiTL8zjkvEZ oLFloHQWFEU50C4ByfSWZlxEoHVe9yxuwPigT9/WnVWgXUEhZRC1TOJAofUHlJ7c pirAVQRJ+xrWibqK2VxPzuSIYmsyaaPt1koCl/QxnNsApHeFMpOSvSIhYbOlFglS NMoZ0JMFrrclO2OYomyhBOCpmd+2695UETTl6A12bYEQs9X5tLucrzXwv4ArtNb6 n5V+pCvbLANYz8n42dFhnsIho4zkPsbSS7079yoFn0PCAg3TojVFZ83ZuLP1fgK3 XcAGc54ExWzjEgxhs6ghSmG4liZRCm8i+dQeZDSEspK87F5mlDE3yHBex5gFdwzN GCMOL/bEITaztOmuz79lHxdcEVbZJJkgRTZoOg18+mcIz5lv/rFHFCTzCcVdjez+ fJ7KAdYaPUIvUkjim+ETihvng635Hs00YnnbSlX9qUmKxLpmXTY= =Ozh3 -----END PGP SIGNATURE-----