[openpgp] Re: Another review of draft-ietf-openpgp-replaceme ntkey-04

Aron Wussler <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <aFPUWReWT_1VL5Y3WcPVVaLIRKLoCe79vBIycGkSVE9fNRsY-6T9as2MvALNFAZ0D2v5JH1FKouyAf-EyeKPbOT34TE_PLU9LNWHHv1it8k=@wussler.it>
Hi Andrew,


> Hm, yes this is a bit crufty - it used to be a statement about the (now removed) “no replacement” flag and so directly described the format of the Replacement Key subpacket. It now describes the semantics of a different subpacket.
> 

> However, after looking at it again I also think section 5.1.1 (Reasons for Revocation) is misplaced, since most of it has general application and is not specific to Key Equivalence. I will restructure.

Yeah, I agree that could be a good option

> > Section 4: Flag bit 0x40 - Why the 2nd bit out of all of them?
> 

> 

> In the original draft, bit 0x80 (only) was specified as a “no replacement” bit, so 0x40 was chosen as the next available bit. “No replacement" was obsoleted in draft-ietf-02 after noting that it duplicated the semantics of the “reason for revocation” subpacket, but “inverse” was left where it was for avoidance of confusion.
> 

> For consistency with other flag bit allocations, we could potentially move it to 0x01 instead?

Like it

> > Section 5.2: "It is also suggested that the key owner asks"... We're getting into RFC 6919 land. I would propose to make it normative (MAY?).
> 

> 

> I’m not sure that normative language would be appropriate, since this note does not describe application behaviour but user behaviour. We could instead use normative language to say that a client MAY or SHOULD prompt the user to take action? What the user does thereafter is out of our control… ;-)

Indeed. I don't know if we should include it at all - but if we do it should probably be on the app.

> > Section 6: "When encrypting to herself..." to:
> > 

> > > When encrypting messages to themselves, key owners are MAY use the a different encryption subkey selection algorithm as the one used for their correspondents.
> 

> 

> As dkg pointed out, this sentence MAY be unnecessary ;-) But I’ll keep this alternative wording in hand...

It's a neat explicit exception to the should, but I agree it's not necessary

Thank *you* for the great draft :)

Cheers,
Aron

--
Aron Wussler
Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0FgmiU2UAJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmcZ/7CQOfMHI3zA1qh+eIkF48twYwfKTr060PNZ
dBsDdhYhBIuVslFfa7tqthSdVX5nYVY+/jkwAAAO2gD/aLo/sdeAhQLNQ88a
0OJA0udYnQ/b6RL/rNQNsvwfz6EA/2xRCFkgqZ3wZyA95T8HUdlcqOwqeXT4
8TDv8YCoQ/AI
=M7ZQ
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.