[openpgp] Re: adding validate-userid to the sopv subset

Michael Richardson <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Daniel Kahn Gillmor <[email protected]> wrote:
    > I'm looking at adding sop's "validate-userid" subcommand (which does
    > simple one-hop User ID validation from a set of fully trusted
    > authorities) to the next revision of the sopv verification-only subset.

So the answers the question: can I (given my current "trust anchors",
e.g. "trust ultimate") validate userid XYZ?

    > My reasoning for this is that the functionality from an OpenPGP
    > perspective is very similar -- it's just a different type of OpenPGP
    > signature being checked.  And, it would make it possible to use a sopv
    > implementation to implement identity-checked signature verification.

Yes, it sounds reasonable, but it does stray into keyring management.
I agree that it fits into stateless, no secret key, etc. though.

Who/when would use it?
Would it be used in, for instance, SBOM verification?

    > There is also a separate request to make "validate-userid" fancier than
    > a simple one-hop validator (See
    > https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/121) but for sopv
    > 1.2 i'm inclined to just keep it at a one-hop mechanism for the moment.

In the olden days, I would use one of the find a path from A->B web sites to
do that... then discover which people I needed to bug to sign some key so
that we'd have a trusted path.

--
]               Never tell me the odds!                 | ipv6 mesh networks [
]   Michael Richardson, Sandelman Software Works        |    IoT architect   [
]     [email protected]  http://www.sandelman.ca/        |   ruby on rails    [

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 511 B)
-----BEGIN PGP SIGNATURE-----

iQFFBAEBCgAvFiEEbsyLEzg/qUTA43uogItw+93Q3WUFAmgTipURHG1jckBzYW5k
ZWxtYW4uY2EACgkQgItw+93Q3WX1+ggAiEIm5Lth6zknl1sZ1ozqwf7edUMe0iNu
MAfM1dCx/DI5Nr9oW8vuaZuFAewm2gVpqas/l7OHGZDkLb/EcxHGB3mofeB2YyVn
EMZm7vCz1U3ZB8nWw6uK+9v1f1XdDaWUOmtyPOsS9QR0jRY4GuTh6wUww2mWnnCr
HnHi13TvU216VJuPDL1fyeTou4TPi2p4zlf8/l3OisdHb8ZlvDLJwg3Jjh+pswgl
hE58KkEdKR6CGauxOWDgQMwEmtunSZ4U/50RLWYUN9HBXDNfCARtmGdESM30zGb5
9hGj+oY1Ox/jjRJymQ1enImtoliSsRTY+fNzQZLeXZTEpYdiAaOJYA==
=TClQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.