[openpgp] Re: Primary Key Binding sigs on authentication sub keys
Stephan Verbücheln <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 2025-01-22 at 17:31 +0000, Daniel Huigens wrote: > OK, my bad. I wasn't aware that this functionality is used in > practice. > Mainly out of curiosity, which services/software support > authenticating in this way? Dear Daniel Please note that PGP is not only used for email. One could even argue that due to its low adaption among the total number of email users, other use cases are much more relevant for the privacy and integrity of the greater Internet-using public, e.g. signing Git commits, tags and release tarballs. SSH authentication is another non-email use case, and note that this is not limited to manual remote shell access by human beings but also Git clone/pull/push, file transfer via SFTP, backups with rsync and so on. How the authentication key is used is defined by the SSH protocol, not by OpenPGP. It does not make sense to invent your own authentication mechanism in the RFC. Since you did not even know that PGP auth keys are commonly used for SSH, maybe you should slow down instead of pushing forward before breaking everything. This again smells like Proton trying to change PGP with only their own use case of email in mind, already causing schism in the PGP community. I am genuinely worried about much more than just my friends being unable to decrypt my emails with a client of their choice. Also note that many PGP use cases require that the users manage their keys personally. Proton managing PGP keys for their users disqualifies the PGP key for other use cases such as release signatures. There was a discussion at Debian to ban Proton for maintainers because of this. Regards Stephan _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]