[openpgp] Re: Signing-only primary keys
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On Wed 2025-04-23 12:04:29 +0200, Wiktor Kwapisiewicz wrote:
> Is my reasoning valid that dropping the "C" key flag is okay or is
> anyone aware of practical issues with it?
I'm also not aware of any practical problems you're likely to have with
a primary key without the certification usage flag.
It's entirely possible that there are implementations that will accept
certifications from such a key.
Andrew Gallagher opened a request for a new test like that here:
https://gitlab.com/sequoia-pgp/openpgp-interoperability-test-suite/-/issues/160
Maybe someone wants to nudge the interop test suite in that direction?
It should be pretty easily discoverable with `sop validate-userid`.
--dkg
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE----- iHUEARYKAB0WIQRjrBGOWy5dZsiKhad4C4VO2cK0lgUCaBKwMgAKCRB4C4VO2cK0 lqyzAP9kdB/N8MPyyNvJQyYtPyHfEGqXwvR20JNYyr0PFysz2QEA9jWoOOFlBZL/ u4wJ1kA45ZC8srKO+Nay2VKrrw5j7gc= =BUUk -----END PGP SIGNATURE-----