[openpgp] Review of draft-ietf-openpgp-replacementkey-04

Falko Strenzke <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
I made a review of draft-ietf-openpgp-replacementkey-04 
<https://www.ietf.org/archive/id/draft-ietf-openpgp-replacementkey-04.html>. 
I think this draft is very mature. As far as I can see, it describes all 
relevant aspects of the newly proposed subpacket. The described 
mechanism addresses the problem of key migration appropriately in my view.

I have only some minor editorial remarks.


    Editorial Remarks

  * Introduce the abbreviation “TPK” properly.


      https://www.ietf.org/archive/id/draft-ietf-openpgp-replacementkey-04.html#name-the-replacement-key-subpack

  * First sentence of the section: reference to section by “from there”
    requires to move the reference out of the brackets.
  * Quote: “The absence of a Replacement Key subpacket SHOULD NOT be
    interpreted as meaning that there is no replacement (or original)
    for the current primary key.” → Move “or original” out of the
    brackets. It is not a clarification, but addresses a different case.


      https://www.ietf.org/archive/id/draft-ietf-openpgp-replacementkey-04.html#name-trust-and-validation-of-the

  * It would be nice if this section also had an introductionary
    sentence before the first subsection.


      https://www.ietf.org/archive/id/draft-ietf-openpgp-replacementkey-04.html#name-key-equivalence-binding

  * A formality: This section should also explicitly introduce the
    concept of “key equivalence”. So far it does only explicitly
    introduces only “key equivalence binding”. Later, in Section 6, the
    term “key equivalence” is used once. So it makes sense to modify an
    existing sentence or add one explaining the concept under this name.
    I conjecture that it will most likely be the same as “key
    equivalence binding”. The other option is of course to replace the
    occurrence of “key equivalence” without the word “binding”.
  * Quote: “If one primary key is validated for use in a particular
    context, then any primary key that has a Key Equivalence Binding
    with it (together with any bound subkeys) is also valid,”
      o Is “valid” the correct term here? I think the equivalence
        binding is addressing trust transference. Validity of a key
        seems to cover a broader range of aspects. The security
        considerations section also uses the term “trust”, which is in
        my view correct.
  * Quote: “b) contains a Replacement Key subpacket that does not refer
    to the other key.” -> append to the sentence " … to the other key in
    the same direction as did the previous Replacement Key Subpacket"

Falko


-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: [email protected]
Web: mtg.de <https://www.mtg.de>

------------------------------------------------------------------------

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.