[openpgp] Re: v4+v6
"Neal H. Walfield" <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi Paul, Thanks for taking a look. On Sun, 09 Feb 2025 17:53:43 +0100, Paul Schaub wrote: > > By using the same key material and the same meta-data, it is possible > to transform a v4 key packet into a v6 key packet and vica-versa [...] > > I'm not sure about the vice-versa part. My instinct would tell me there might be dragons when "downgrading" a v6 > certificate into a v4 one, even though I cannot come up with a concrete idea for an attack. So treat this as just an > articulation of my gut feelings :D I'm also less sure about this part, and I hope others who understand the cryptography better than I do can comment. > All in all its a nice idea, although its not universally applicable > to all certs (e.g. legacy/weak keys). > > Also, some popular key types (legacy x25519, legacy ed25519) MUST NOT be used with v6, so I guess you'd > transform them to the new key type, which is no longer a bijection, as the v4 cert might also use the new > non-legacy algorithms. You're right. I failed to note that this proposal only applies to the intersection of algorithms and constraints specified by RRC 4880 and RFC 9580. :) Neal _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]