[openpgp] Re: Fwd: New Version Notification for draft-gall agher-email-invisible-signatures-00.txt
Steffen Nurpmeso <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <20250508170548.g9NV9uDc@steffen%sdaoden.eu> |
Daniel Kahn Gillmor wrote in <[email protected]>: |On Wed 2025-05-07 22:01:18 +0200, Steffen Nurpmeso wrote: |> May i ask why the hp="clear" parameter was added? Isn't it enough |> to create the Sig: header? The "cryptographic payload" begins |> directly after the Sig: header. | |An invisible signature always signs the header fields known to the |sending MUA, as generally recommended in |draft-ietf-lamps-header-protection, which says: | |>>> all Header Fields gain end-to-end cryptographic integrity and |>>> authenticity by being copied directly into the Cryptographic Payload | |The draft includes the hp="clear" parameter in alignment with that |specification, see: | | https://www.ietf.org/archive/id/draft-ietf-lamps-header-protection-25.ht\ | ml#name-content-type-parameter-hp Thanks, that i have not read yet, i am still at (and not ready with) 24. (Imagine-wise i still fail, as at least in the main header order is such a thing, and why should any intermediate which really mangles care and only prepend or append? Ie: i *think* it is a marker for now. But do not answer: i will read that once in a while, and likely learn thus.) |One curious side effect of this alignment is that it might be possible |to convert a message with an invisible signature into an RFC 3156-style |multipart/signed message. And maybe vice versa? Regarding the thing as such Michael Richardson has already said, what i could only reiterate. (I gave an opinion when the item came up last, maybe a year ago?) But since there is now a draft, you know. Also .. the draft uses multipart/mixed, which the discussion back then did not, i think. This is pretty clever, is it? Of course it requires MIME as such, and with MIME as such, we come back to Michael Richardson. (And moreover my real problem with the WG topic as such is that the public key cannot simply be extracted and saved and thereafter used, which one gets for free with S/MIME. Maybe now with Sig: there will be a Sig: covered PKey: that can be used to verify Sig: as well as be saved? That is cool. With multipart/signed one needs to attach the key and then sign the whole thing, which makes for several parts which MUAs potentially can misunderstand. Shall there be any.) | --dkg By the way in some troubling private message thread i said that i really think that you do a very good job as a moderator. I do not a lot moderators as interested, swift, balancing, maybe oss-security. Thanks! --End of <[email protected]> --steffen | |Der Kragenbaer, The moon bear, |der holt sich munter he cheerfully and one by one |einen nach dem anderen runter wa.ks himself off |(By Robert Gernhardt) _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]