[openpgp] Re: [Technical Errata Reported] RFC9580 (845 4)

Heiko Schäfer <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
I believe at least two more instances of this class of 
imprecision/omission exist in RFC 9580:


1) In 5.5.3:

 > "Secret MPI values can be encrypted using a passphrase. [..] The 
cipher for encrypting the MPIs is specified in the Secret Key packet."

This and the following paragraphs don't mention the case of "native" 
secret key representations.


2) In 11.2:

 > "A point on an elliptic curve will always be represented on the wire 
as an MPI."

The omission of "native non-Mpi encoding" for the new Ed/X 25519/448 
variants might also be at least mildly confusing to readers.

The following sections in chapter 11 also seem to imply that all EC data 
is encoded as Mpi.

In particular, in 11.3, all three entries in the table seem to imply 
variants of "MPI" encoding. The case of "native" fixed length encoding 
seems to be missing.


Thanks,
Heiko


On 6/12/25 5:55 PM, Daniel Kahn Gillmor wrote:
> This erratum is correct.  Not all OpenPGP signature packets conclude
> with a series of MPIs.
>
> I recommend marking it as "verified".
>
> Thanks for catching this, Tim!
>
>    --dkg
>
> On Sat 2025-06-07 14:47:27 -0700, RFC Errata System wrote:
>> The following errata report has been submitted for RFC9580,
>> "OpenPGP".
>>
>> --------------------------------------
>> You may review the report below and at:
>> https://www.rfc-editor.org/errata/eid8454
>>
>> --------------------------------------
>> Type: Technical
>> Reported by: Tim Geiser <[email protected]>
>>
>> Section: 5.2.3
>>
>> Original Text
>> -------------
>> One or more MPIs comprising the signature. This portion is
>> algorithm specific.
>>
>> Corrected Text
>> --------------
>> One or more MPIs comprising the signature, or plain octets with no
>> MPI header. This portion is algorithm specific.
>>
>> Notes
>> -----
>> The final bullet point of 5.2.3 is not, strictly speaking, correct. Ed25519 and Ed448 have signatures that are not MPIs but rather "native" octet strings. These algorithms do not have "one or more MPIs" - they have zero MPIs and only the octet string (of length 64 or 114). Prior to the introduction of these algorithms that statement was correct - every other signature algorithm uses MPI(s).
>>
>> Instructions:
>> -------------
>> This erratum is currently posted as "Reported". (If it is spam, it
>> will be removed shortly by the RFC Production Center.) Please
>> use "Reply All" to discuss whether it should be verified or
>> rejected. When a decision is reached, the verifying party
>> will log in to change the status and edit the report, if necessary.
>>
>> --------------------------------------
>> RFC9580 (draft-ietf-openpgp-crypto-refresh-13)
>> --------------------------------------
>> Title               : OpenPGP
>> Publication Date    : July 2024
>> Author(s)           : P. Wouters, Ed., D. Huigens, J. Winter, Y. Niibe
>> Category            : PROPOSED STANDARD
>> Source              : Open Specification for Pretty Good Privacy
>> Stream              : IETF
>> Verifying Party     : IESG
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.