[openpgp] Re: Primary Key Binding sigs on authentication sub keys

Stephan Verbücheln <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Wed, 2025-01-22 at 17:31 +0000, Daniel Huigens wrote:
> OK, my bad. I wasn't aware that this functionality is used in
> practice.
> Mainly out of curiosity, which services/software support
> authenticating in this way?

Dear Daniel

Please note that PGP is not only used for email. One could even argue
that due to its low adaption among the total number of email users,
other use cases are much more relevant for the privacy and integrity of
the greater Internet-using public, e.g. signing Git commits, tags and
release tarballs.

SSH authentication is another non-email use case, and note that this is
not limited to manual remote shell access by human beings but also Git
clone/pull/push, file transfer via SFTP, backups with rsync and so on.
How the authentication key is used is defined by the SSH protocol, not
by OpenPGP. It does not make sense to invent your own authentication
mechanism in the RFC.

Since you did not even know that PGP auth keys are commonly used for
SSH, maybe you should slow down instead of pushing forward before
breaking everything. This again smells like Proton trying to change PGP
with only their own use case of email in mind, already causing schism
in the PGP community. I am genuinely worried about much more than just
my friends being unable to decrypt my emails with a client of their
choice.

Also note that many PGP use cases require that the users manage their
keys personally. Proton managing PGP keys for their users disqualifies
the PGP key for other use cases such as release signatures. There was a
discussion at Debian to ban Proton for maintainers because of this.

Regards
Stephan

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.