[openpgp] Re: Signing-only primary keys

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Wed 2025-04-23 12:04:29 +0200, Wiktor Kwapisiewicz wrote:
> Is my reasoning valid that dropping the "C" key flag is okay or is 
> anyone aware of practical issues with it?

I'm also not aware of any practical problems you're likely to have with
a primary key without the certification usage flag.

It's entirely possible that there are implementations that will accept
certifications from such a key.

Andrew Gallagher opened a request for a new test like that here:

   https://gitlab.com/sequoia-pgp/openpgp-interoperability-test-suite/-/issues/160

Maybe someone wants to nudge the interop test suite in that direction?
It should be pretty easily discoverable with `sop validate-userid`.

      --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQRjrBGOWy5dZsiKhad4C4VO2cK0lgUCaBKwMgAKCRB4C4VO2cK0
lqyzAP9kdB/N8MPyyNvJQyYtPyHfEGqXwvR20JNYyr0PFysz2QEA9jWoOOFlBZL/
u4wJ1kA45ZC8srKO+Nay2VKrrw5j7gc=
=BUUk
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.