[openpgp] Re: Certificate discovery over HKP
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <-0Idgc9O4unvMWFMaXJXFqwK7IJCVXnK2ElLGWK8XjHd3juaDt-bShTiuu0V8KCDR_Uubqjr33I4F-A8xp9KpZkoJcORRXSHII9NXNaU64s=@protonmail.com> |
Hi Andrew & all, In the discussion at the summit, it was mentioned that DNS over HTTPS could be used as a proxy by clients who need it. So, even if we go with the SRV option, I don't think we need to build anything related to that into keyservers, tbh. As Bart mentioned at the summit, it would be useful for us to be able to tell customers with custom domains to set a SRV record (obviously we already have to tell them to set a bunch of other DNS records anyway), as opposed to having to serve an openpgpkey subdomain for them and request a TLS cert for that and so on. > we can require that policy file lookups are covered by a > TLS certificate, but cannot yet require that SRV records be > covered by DNSSEC In theory we could require that, it's just a question of whether the security gain is worth preventing sites without DNSSEC from using this, right? Also, in the cold-email case, the most serious attack a MITM could do is to prevent the OpenPGP cert from being served altogether, and that's possible in either case (e.g. by just removing the openpgpkey subdomain DNS record). So, the case where the distinction matters is if you already have a valid cert, and would replace it with a new cert from a keyserver, without requiring e.g. a replacement key subpacket or other evidence that the new certificate is authentic. Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]