[openpgp] Re: Review of draft-ietf-openpgp-replacementkey-04

Falko Strenzke <[email protected]>
Newsgroups gmane.ietf.openpgp
Organization MTG AG
Message-ID <[email protected]>
Am 07.08.25 um 01:46 schrieb Andrew Gallagher:
>> The term "trust" is both overused and underspecified in OpenPGP.  Can we
>> replace it here eto make it say what we mean specifically?  here are
>> some ambiguous/unclear statements:
>>
>> - calculating partial trust values
>> - trust pathways
>> - trust statement
>> - infer any trust value
>>
>> I think we can leave the term "Web of Trust" in the text, but maybe use
>> it with a reference to some document that describes it?
>> https://sequoia-pgp.gitlab.io/sequoia-wot/ is one example (though it
>> hasn't been submitted to the datatracker as far as i'm aware).
> I think most (all?) of these are established Web of Trust terms? It would be nice if there was a more official document to reference though 😉

I think it would make sense that this draft explicitly defines what key 
equivalence technically means. To use the word "trust" in that 
explanation might make sense, then it needs to be defined as well of course.

In my understanding, there are two flavours of trust that can be seen as 
relevant here:

A) Direct Entity Trust. This means that I trust the keys in a 
certificate to be owned by a certain entity.

B) User-ID Trust. This means that I trust the certificate to identify 
the correct user ID as associated with the key. In other words, even if 
I don't know the entity, I trust that the same entity controls the the 
service(s) (e.g., email) associated with the user ID and the key in the 
certificate. I think that for the draft it is not necessary to actually 
distinguish these two for the purpose of key equivalence, but it might 
make sense to mention them both – if they both apply.

That naturally raises the question in how far User IDs matter in the 
"key equivalence group" (a term I suggest that could be used in the 
draft also). If neither certificate carries User ID packets, trust 
transference should clearly be possible (case A). But if both carry user 
ID packets with a) partial overlap or b) no overlap at all, is trust 
transference also possible? At least for what I mention under "B) 
User-ID Trust" above, the case b) seems a bit confusing.

It seems to me that at the minimum, the draft would benefit from some 
clarifications what types of trust are supposed to be captured by the 
trust transference through key equivalance and if / how this relates to 
the contents of the User-ID packets of the certificates in the 
equivalence group.

Best regards,
Falko

-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: [email protected]
Web: mtg.de <https://www.mtg.de>

------------------------------------------------------------------------

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
smime.p7s (application/pkcs7-signature, 4.9 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.