[openpgp] Re: [Technical Errata Reported] RFC9580 (845 4)
Heiko Schäfer <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
I believe at least two more instances of this class of imprecision/omission exist in RFC 9580: 1) In 5.5.3: > "Secret MPI values can be encrypted using a passphrase. [..] The cipher for encrypting the MPIs is specified in the Secret Key packet." This and the following paragraphs don't mention the case of "native" secret key representations. 2) In 11.2: > "A point on an elliptic curve will always be represented on the wire as an MPI." The omission of "native non-Mpi encoding" for the new Ed/X 25519/448 variants might also be at least mildly confusing to readers. The following sections in chapter 11 also seem to imply that all EC data is encoded as Mpi. In particular, in 11.3, all three entries in the table seem to imply variants of "MPI" encoding. The case of "native" fixed length encoding seems to be missing. Thanks, Heiko On 6/12/25 5:55 PM, Daniel Kahn Gillmor wrote: > This erratum is correct. Not all OpenPGP signature packets conclude > with a series of MPIs. > > I recommend marking it as "verified". > > Thanks for catching this, Tim! > > --dkg > > On Sat 2025-06-07 14:47:27 -0700, RFC Errata System wrote: >> The following errata report has been submitted for RFC9580, >> "OpenPGP". >> >> -------------------------------------- >> You may review the report below and at: >> https://www.rfc-editor.org/errata/eid8454 >> >> -------------------------------------- >> Type: Technical >> Reported by: Tim Geiser <[email protected]> >> >> Section: 5.2.3 >> >> Original Text >> ------------- >> One or more MPIs comprising the signature. This portion is >> algorithm specific. >> >> Corrected Text >> -------------- >> One or more MPIs comprising the signature, or plain octets with no >> MPI header. This portion is algorithm specific. >> >> Notes >> ----- >> The final bullet point of 5.2.3 is not, strictly speaking, correct. Ed25519 and Ed448 have signatures that are not MPIs but rather "native" octet strings. These algorithms do not have "one or more MPIs" - they have zero MPIs and only the octet string (of length 64 or 114). Prior to the introduction of these algorithms that statement was correct - every other signature algorithm uses MPI(s). >> >> Instructions: >> ------------- >> This erratum is currently posted as "Reported". (If it is spam, it >> will be removed shortly by the RFC Production Center.) Please >> use "Reply All" to discuss whether it should be verified or >> rejected. When a decision is reached, the verifying party >> will log in to change the status and edit the report, if necessary. >> >> -------------------------------------- >> RFC9580 (draft-ietf-openpgp-crypto-refresh-13) >> -------------------------------------- >> Title : OpenPGP >> Publication Date : July 2024 >> Author(s) : P. Wouters, Ed., D. Huigens, J. Winter, Y. Niibe >> Category : PROPOSED STANDARD >> Source : Open Specification for Pretty Good Privacy >> Stream : IETF >> Verifying Party : IESG > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]