[openpgp] Re: Signing-only primary keys
Paul Schaub <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hey Wiktor, for some time, PGPainless was requiring the 'C' flag on primary keys, as I had erroneously interpreted 'other keys' to mean subkeys of the same certificate too. However, for quite a while now, this misunderstanding has been cleared up, so PGPainless should behave as you expect. Paul Am 23. April 2025 12:04:29 MESZ schrieb Wiktor Kwapisiewicz <[email protected]>: >Hi folks, > >I've got a question about using signing-only primary keys. > >In our project we're creating certificates that will be used only for signing artifacts (for example packages). They are not meant to issue third-party certifications and I thought that, following the principle of least privilege, it would be good to drop the Certification flag from the primary key altogether and leave only the Signing key flag. > >Our initial tests seem to indicate that signing-only-primary-key certificates don't cause any problems (tested implementations: gpg, rsop, sqop). Inspecting the certificate in GnuPG revealed that it adds the "C" flag anyway :) > >I didn't see any further tests at https://tests.sequoia-pgp.org/ but maybe I overlooked it. > >I've browsed https://www.rfc-editor.org/rfc/rfc9580#name-key-flags and https://www.rfc-editor.org/rfc/rfc4880#section-5.2.3.21 and the key flag 0x01 is clearly marked as concerning "other keys" which we don't want in this use-case. > >Is my reasoning valid that dropping the "C" key flag is okay or is anyone aware of practical issues with it? > >Thanks for your time! > >Kind regards, >Wiktor > >P.S. The MR dropping the flag is at https://gitlab.archlinux.org/archlinux/signstar/-/merge_requests/206 > >_______________________________________________ >openpgp mailing list -- [email protected] >To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]