[openpgp] Re: ML-KEM and ML-DSA secret key format
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
The reason why the PKCS8 discussion in LAMPS is relevant to OPENPGP is because one can hope that there will be support in OPENPGP products for smaller/personal HSMs (USB tokens). The tokens might get used with a variety of protocols. Today, signing of software is largely a PGP thing not an S/MIME thing. (It's different in the MS-MSI space) Particularly when it comes to signing git commits. My opinion is that there are very few situations where it's better to move a private key rather than just have two or more signing keys be validated. At least -- in an PKIX situation with a certification authority. I think that YUM, and APT based systems can now specify a PGP keyring for each source, and a signature from any key in that keyring is valid. (And we've finally moved beyond mixing all the keys up for the different sources) Having a way to backup a private key from one token to another one seems (rather than generating a new key) might be operationally important for in the software signing space. I don't think the same considerations apply to individual use personal keys. I also think that OPENPGP key format allows us to have multiple private keys attached to a single identity, and for those keys to reside on distinct tokens. I admit that I've never tried this, but I ought to already. -- Michael Richardson <[email protected]> . o O ( IPv6 IøT consulting ) Sandelman Software Works Inc, Ottawa and Worldwide _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 515 B)
-----BEGIN PGP SIGNATURE----- iQFKBAEBCgA0FiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmfCCacWHG1jcitpZXRm QHNhbmRlbG1hbi5jYQAKCRCAi3D73dDdZceIB/9u/6ddB2vhqnU1cOoatrdJ6xNn DNBdRz9xH3HEbvZh9v2pkAFOj3RQ/J+rwCvg6M2yVhQbiP5CCrMC0JLySQKW+W4P KFtqTx1D480j5xfnXlaw4GdeUFJoddYpt+pr85AJxWKe6yfVX3Dv0MqFkJo0qynW 0zdbwAS41az+UnQzqjp85QdMCvBj7TV7begqc9rbin5qCgJ7aQb5EoZNqGEZonh+ gewzFFXVofg1zSE8nTdFEfST2m61VGswJ8xigyVg/QJ4p69/7yAy/qJshm7Opz7+ 0Eg2MnBZJy5dXPL5xyCoDiTRse8lHx8kcBcrO0weLREYAO1p4KWA2Qn6dFya =JIJ/ -----END PGP SIGNATURE-----