[openpgp] adding validate-userid to the sopv subset

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hey OpenPGP folks--

I'm looking at adding sop's "validate-userid" subcommand (which does
simple one-hop User ID validation from a set of fully trusted
authorities) to the next revision of the sopv verification-only subset.

My reasoning for this is that the functionality from an OpenPGP
perspective is very similar -- it's just a different type of OpenPGP
signature being checked.  And, it would make it possible to use a sopv
implementation to implement identity-checked signature verification.

I'm collecting feedback on this proposal at:

  https://gitlab.com/dkg/openpgp-stateless-cli/-/merge_requests/47

There is also a separate request to make "validate-userid" fancier than
a simple one-hop validator (See
https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/121) but for sopv
1.2 i'm inclined to just keep it at a one-hop mechanism for the moment.

I'd love to hear feedback, either on-list or in the issue tracker.

    --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 227 B)
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQRjrBGOWy5dZsiKhad4C4VO2cK0lgUCaBK0UwAKCRB4C4VO2cK0
lqYiAQCngfZFMr6DEMQIFqZ2MS8XrIEDzxzoNR4rYUMxlhvE6QD/f2DvvfCsQKz6
TVfqvuE53I8Sen2rODKtg9+/NLKN8QQ=
=4+Px
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.