[openpgp] Re: Certificate discovery over HKP

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <-0Idgc9O4unvMWFMaXJXFqwK7IJCVXnK2ElLGWK8XjHd3juaDt-bShTiuu0V8KCDR_Uubqjr33I4F-A8xp9KpZkoJcORRXSHII9NXNaU64s=@protonmail.com>
Hi Andrew & all,

In the discussion at the summit, it was mentioned that DNS over HTTPS
could be used as a proxy by clients who need it. So, even if we go with
the SRV option, I don't think we need to build anything related to that
into keyservers, tbh.

As Bart mentioned at the summit, it would be useful for us to be able to
tell customers with custom domains to set a SRV record (obviously we
already have to tell them to set a bunch of other DNS records anyway),
as opposed to having to serve an openpgpkey subdomain for them and
request a TLS cert for that and so on.

> we can require that policy file lookups are covered by a
> TLS certificate, but cannot yet require that SRV records be
> covered by DNSSEC

In theory we could require that, it's just a question of whether the
security gain is worth preventing sites without DNSSEC from using this,
right?

Also, in the cold-email case, the most serious attack a MITM could do
is to prevent the OpenPGP cert from being served altogether, and that's
possible in either case (e.g. by just removing the openpgpkey subdomain
DNS record). So, the case where the distinction matters is if you
already have a valid cert, and would replace it with a new cert from a
keyserver, without requiring e.g. a replacement key subpacket or
other evidence that the new certificate is authentic.

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.