[openpgp] Re: Encryption subkey selection

Bart Butler <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <-r7DKP-up_y2Y19C3aR7UREiHK6ddwWmMF9wJ55R52gaDYWBiRBQYI5rMI6HXFbuWqZC9ykPncT3fj9Mu48g6S6P4wahJDwziqDkFZ0i5cc=@pm.me>
Hi Andrew and Falko,
I think “use existing implementation behavior” would be better for cases where no suitable subkeys with ESS are found. Assigning zero would seemingly mandate that if the subkeys with nonzero ESS were found to be unusable every other subkey that was usable would have to be used together, which is in general different than current implementation behavior and is an odd side effect.  -Bart
On Mon, Apr 7, 2025 at 9:36 AM, Andrew Gallagher &lt;[email protected]&gt; wrote:  Hi, Falko.



On 7 Apr 2025, at 07:50, Falko Strenzke &lt;[email protected]&gt; wrote:

&gt;

&gt; But I think we need to define a default rank that is assigned to a subkey in the case that at least one encryption subkey in the certificate carries the ESS. That would probably be "0".



This would be reasonable. Another option would be to treat such encryption subkeys as “do not automatically select”. This might seem to render the subkey unusable, but some clients allow the user to manually override the default subkey selection algorithm, in which case it could still be used. It’s worth noting that gnupg appears to now interpret the “reserved for adsk” key flag this way.



A

_______________________________________________

openpgp mailing list -- [email protected]

To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 249 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wnUEARYIACcFAmfzin0JEJkFRGXvMx5EFiEEPBWRN4GH7qbKJ/qsmQVEZe8z
HkQAAMlgAP9hoFxtcN0WaEk3+Kq3HvGGFHCEEH2njjq0G+tGx3TVbQD+K8ZU
+RFRYZKoS/pNLDoCKIrkpZohEnQAWYRWw0DWiwM=
=zIvy
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.