[openpgp] Re: Primary Key Binding sigs on authentication sub keys
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <tIhav3cCbJLSw89FGpA2p8xRlysJCk5P41NESZjBVdJL9tnrCiM-Oezdq7lMk1SjdurUxGLBUU4yePr4TgYSZdNPglCiZXs7WaNbt-0I6EQ=@protonmail.com> |
Hi Stephan, I am not proposing to change the specification in this thread. In the PR that Andrew linked, I proposed to align our implementation with text in the specification that predates my involvement and is present in RFC4880, Section 11.1: For subkeys that can issue signatures, the subkey binding signature MUST contain an Embedded Signature subpacket with a primary key binding signature (0x19) issued by the subkey on the top-level key. Similarly, the idea of authenticating using OpenPGP signatures was not raised by me but by RFC4880, Section 2.2: 2.2. Authentication via Digital Signature The digital signature uses a hash code or message digest algorithm, and a public-key signature algorithm. The sequence is as follows: (...) If you or anyone else is of the opinion that this text is wrong, please propose to change it, but surely you'd agree that it's a good thing for the specification and its implementations to match. Finally, I'll note that the changes in RFC9580 were not solely proposed by me but by a group of people, all of whom (in my view) had the best interest of OpenPGP in mind, and not only for email. It's a shame that not all implementations were on board and that things turned out the way they did, but I won't rehash that further here. Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]