[openpgp] Re: Another review of draft-ietf-openpgp-replaceme ntkey-04
Aron Wussler <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <aFPUWReWT_1VL5Y3WcPVVaLIRKLoCe79vBIycGkSVE9fNRsY-6T9as2MvALNFAZ0D2v5JH1FKouyAf-EyeKPbOT34TE_PLU9LNWHHv1it8k=@wussler.it> |
Hi Andrew, > Hm, yes this is a bit crufty - it used to be a statement about the (now removed) “no replacement” flag and so directly described the format of the Replacement Key subpacket. It now describes the semantics of a different subpacket. > > However, after looking at it again I also think section 5.1.1 (Reasons for Revocation) is misplaced, since most of it has general application and is not specific to Key Equivalence. I will restructure. Yeah, I agree that could be a good option > > Section 4: Flag bit 0x40 - Why the 2nd bit out of all of them? > > > In the original draft, bit 0x80 (only) was specified as a “no replacement” bit, so 0x40 was chosen as the next available bit. “No replacement" was obsoleted in draft-ietf-02 after noting that it duplicated the semantics of the “reason for revocation” subpacket, but “inverse” was left where it was for avoidance of confusion. > > For consistency with other flag bit allocations, we could potentially move it to 0x01 instead? Like it > > Section 5.2: "It is also suggested that the key owner asks"... We're getting into RFC 6919 land. I would propose to make it normative (MAY?). > > > I’m not sure that normative language would be appropriate, since this note does not describe application behaviour but user behaviour. We could instead use normative language to say that a client MAY or SHOULD prompt the user to take action? What the user does thereafter is out of our control… ;-) Indeed. I don't know if we should include it at all - but if we do it should probably be on the app. > > Section 6: "When encrypting to herself..." to: > > > > > When encrypting messages to themselves, key owners are MAY use the a different encryption subkey selection algorithm as the one used for their correspondents. > > > As dkg pointed out, this sentence MAY be unnecessary ;-) But I’ll keep this alternative wording in hand... It's a neat explicit exception to the should, but I agree it's not necessary Thank *you* for the great draft :) Cheers, Aron -- Aron Wussler Sent with ProtonMail, OpenPGP key 0x7E6761563EFE3930 _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0FgmiU2UAJkH5nYVY+/jkwRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmcZ/7CQOfMHI3zA1qh+eIkF48twYwfKTr060PNZ dBsDdhYhBIuVslFfa7tqthSdVX5nYVY+/jkwAAAO2gD/aLo/sdeAhQLNQ88a 0OJA0udYnQ/b6RL/rNQNsvwfz6EA/2xRCFkgqZ3wZyA95T8HUdlcqOwqeXT4 8TDv8YCoQ/AI =M7ZQ -----END PGP SIGNATURE-----