[openpgp] Re: Fwd: New Version Notification for draft-gall agher-email-invisible-signatures-00.txt

Steffen Nurpmeso <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <20250508170548.g9NV9uDc@steffen%sdaoden.eu>
Daniel Kahn Gillmor wrote in
 <[email protected]>:
 |On Wed 2025-05-07 22:01:18 +0200, Steffen Nurpmeso wrote:
 |> May i ask why the hp="clear" parameter was added?  Isn't it enough
 |> to create the Sig: header?  The "cryptographic payload" begins
 |> directly after the Sig: header.
 |
 |An invisible signature always signs the header fields known to the
 |sending MUA, as generally recommended in
 |draft-ietf-lamps-header-protection, which says:
 |
 |>>> all Header Fields gain end-to-end cryptographic integrity and
 |>>> authenticity by being copied directly into the Cryptographic Payload
 |
 |The draft includes the hp="clear" parameter in alignment with that
 |specification, see:
 |
 |   https://www.ietf.org/archive/id/draft-ietf-lamps-header-protection-25.ht\
 |   ml#name-content-type-parameter-hp

Thanks, that i have not read yet, i am still at (and not ready
with) 24.  (Imagine-wise i still fail, as at least in the main
header order is such a thing, and why should any intermediate
which really mangles care and only prepend or append?  Ie:
i *think* it is a marker for now.  But do not answer: i will read
that once in a while, and likely learn thus.)

 |One curious side effect of this alignment is that it might be possible
 |to convert a message with an invisible signature into an RFC 3156-style
 |multipart/signed message.  And maybe vice versa?

Regarding the thing as such Michael Richardson has already said,
what i could only reiterate.  (I gave an opinion when the item
came up last, maybe a year ago?)  But since there is now a draft,
you know.  Also .. the draft uses multipart/mixed, which the
discussion back then did not, i think.  This is pretty clever, is
it?  Of course it requires MIME as such, and with MIME as such,
we come back to Michael Richardson.  (And moreover my real problem
with the WG topic as such is that the public key cannot simply be
extracted and saved and thereafter used, which one gets for free
with S/MIME.  Maybe now with Sig: there will be a Sig: covered
PKey: that can be used to verify Sig: as well as be saved?  That
is cool.  With multipart/signed one needs to attach the key and
then sign the whole thing, which makes for several parts which
MUAs potentially can misunderstand.  Shall there be any.)

 |         --dkg

By the way in some troubling private message thread i said that
i really think that you do a very good job as a moderator.
I do not a lot moderators as interested, swift, balancing, maybe
oss-security.  Thanks!

 --End of <[email protected]>

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.