[openpgp] Re: Forwarding for v6 follow-up
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi Aron--
On Fri 2025-07-25 17:17:06 +0000, Aron Wussler wrote:
> ## FKESK
>
> This is the alternative presented earlier today. To convey the message
> information needed to decrypt for the forwardee KDF, we create a new
> packet: Forwarding Key Encrypted Session Key Packet.
[…]
> ## New algorithm ID
>
> We can re-use the PKESK and add the needed information into the
> algorithm specific data. No additional packet needed, just define a
> new codepoint e.g. "Forwarded X25519" (note that not all algorithms
> allow forwarding) so we'd have to do just a couple.
Thanks for this interesting choice.
As an implementer/maintainer/debugger i think i prefer the new algorithm
ID over FKESK.
When a forwarding manager hands off a secret key to the forwardee, the
forwardee needs to know about this new form of algorithm anyway to be
able to decrypt forwarded messages, so this seems appropriate to me.
Regards,
--dkg
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]