[openpgp] Re: adding validate-userid to the sopv subset
Michael Richardson <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Daniel Kahn Gillmor <[email protected]> wrote: > I'm looking at adding sop's "validate-userid" subcommand (which does > simple one-hop User ID validation from a set of fully trusted > authorities) to the next revision of the sopv verification-only subset. So the answers the question: can I (given my current "trust anchors", e.g. "trust ultimate") validate userid XYZ? > My reasoning for this is that the functionality from an OpenPGP > perspective is very similar -- it's just a different type of OpenPGP > signature being checked. And, it would make it possible to use a sopv > implementation to implement identity-checked signature verification. Yes, it sounds reasonable, but it does stray into keyring management. I agree that it fits into stateless, no secret key, etc. though. Who/when would use it? Would it be used in, for instance, SBOM verification? > There is also a separate request to make "validate-userid" fancier than > a simple one-hop validator (See > https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/121) but for sopv > 1.2 i'm inclined to just keep it at a one-hop mechanism for the moment. In the olden days, I would use one of the find a path from A->B web sites to do that... then discover which people I needed to bug to sign some key so that we'd have a trusted path. -- ] Never tell me the odds! | ipv6 mesh networks [ ] Michael Richardson, Sandelman Software Works | IoT architect [ ] [email protected] http://www.sandelman.ca/ | ruby on rails [ _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 511 B)
-----BEGIN PGP SIGNATURE----- iQFFBAEBCgAvFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmgTipURHG1jckBzYW5k ZWxtYW4uY2EACgkQgItw+93Q3WX1+ggAiEIm5Lth6zknl1sZ1ozqwf7edUMe0iNu MAfM1dCx/DI5Nr9oW8vuaZuFAewm2gVpqas/l7OHGZDkLb/EcxHGB3mofeB2YyVn EMZm7vCz1U3ZB8nWw6uK+9v1f1XdDaWUOmtyPOsS9QR0jRY4GuTh6wUww2mWnnCr HnHi13TvU216VJuPDL1fyeTou4TPi2p4zlf8/l3OisdHb8ZlvDLJwg3Jjh+pswgl hE58KkEdKR6CGauxOWDgQMwEmtunSZ4U/50RLWYUN9HBXDNfCARtmGdESM30zGb5 9hGj+oY1Ox/jjRJymQ1enImtoliSsRTY+fNzQZLeXZTEpYdiAaOJYA== =TClQ -----END PGP SIGNATURE-----