[openpgp] Re: Review of draft-ietf-openpgp-replacementkey-04
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | MTG AG |
| Message-ID | <[email protected]> |
Am 07.08.25 um 01:46 schrieb Andrew Gallagher: >> The term "trust" is both overused and underspecified in OpenPGP. Can we >> replace it here eto make it say what we mean specifically? here are >> some ambiguous/unclear statements: >> >> - calculating partial trust values >> - trust pathways >> - trust statement >> - infer any trust value >> >> I think we can leave the term "Web of Trust" in the text, but maybe use >> it with a reference to some document that describes it? >> https://sequoia-pgp.gitlab.io/sequoia-wot/ is one example (though it >> hasn't been submitted to the datatracker as far as i'm aware). > I think most (all?) of these are established Web of Trust terms? It would be nice if there was a more official document to reference though 😉 I think it would make sense that this draft explicitly defines what key equivalence technically means. To use the word "trust" in that explanation might make sense, then it needs to be defined as well of course. In my understanding, there are two flavours of trust that can be seen as relevant here: A) Direct Entity Trust. This means that I trust the keys in a certificate to be owned by a certain entity. B) User-ID Trust. This means that I trust the certificate to identify the correct user ID as associated with the key. In other words, even if I don't know the entity, I trust that the same entity controls the the service(s) (e.g., email) associated with the user ID and the key in the certificate. I think that for the draft it is not necessary to actually distinguish these two for the purpose of key equivalence, but it might make sense to mention them both – if they both apply. That naturally raises the question in how far User IDs matter in the "key equivalence group" (a term I suggest that could be used in the draft also). If neither certificate carries User ID packets, trust transference should clearly be possible (case A). But if both carry user ID packets with a) partial overlap or b) no overlap at all, is trust transference also possible? At least for what I mention under "B) User-ID Trust" above, the case b) seems a bit confusing. It seems to me that at the minimum, the draft would benefit from some clarifications what types of trust are supposed to be captured by the trust transference through key equivalance and if / how this relates to the contents of the User-ID packets of the certificates in the equivalence group. Best regards, Falko -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected] Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.9 KB) - not displayed