[openpgp] Re: Review of draft-ietf-openpgp-replacementkey-04

Andrew Gallagher <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On 8 Aug 2025, at 00:30, Andrew Gallagher <[email protected]> wrote:
> 
>> It seems to me that at the minimum, the draft would benefit from some clarifications what types of trust are supposed to be captured by the trust transference through key equivalance and if / how this relates to the contents of the User-ID packets of the certificates in the equivalence group.
>> 
> 
> I agree, and have been thinking along the following lines:
> 
> * “trust” should be reserved for “ownertrust” and is therefore out of scope of this document
> 
> * The input to the Key Equivalence calculation is whether a particular identity claim regarding a key/certificate is considered authentic, or valid, by the receiving implementation. Whether the claim is explicit or implicit, and whether the claim validity derives from the web of trust, or provenance, or the user Just Said So, should not matter for the purposes of this draft.
> 
> * The output of the Key Equivalence calculation is that any valid identity claim (as determined by the previous bullet point) regarding one member of a Key Equivalence Set is automatically valid for all other (current) members of the Key Equivalence Set.
> 
> I think this would avoid the “trust” minefield entirely. And perhaps we should therefore talk about “Identity Equivalence” instead of “Key Equivalence”?

I have made the above changes to the editor’s copy.

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmiaekcACgkQXB7EBNWQ
Zim/Gw//Z44sdAv3G801A5NvVw8sA3skK6Y695VxqubKJM2m7eED/p05Nct58Ywv
QCGHtQc0He4Nc19fzLOGoZtkFLOvbmBMfAaFvDdBRdmBS2iBMCZe9H3twb3oHdKg
K1nfq47kCGWM62ayjYFiiMxE9bjgHwwEGyA7asLkMnUvil6J0vENAnpbR7vuFKq/
k9rmm4kkZ4GCtQlswHTEUwMGpolr/5HlwmmCFaK2MWksxKiAqaUbTqJ67SR3k7+P
jAC+WMnCDWpDMfvxpEjyH3R9HWogW6zejCl23w9jBGGik475/tD3Nni/C6TTLEP6
vVSuYBQ5eelI+SueCyIIU3k8b59qxQvszCzztTRv7Qd6uJVV0lOWTczdcMxjtKiP
JYxZMojemA5Vk+zVQ72KcceS2rZRMiCYljQMKAadL1apExQm1j4trqyS1I3O9pjB
5Yqe8/ptgbjmeFnJW9nORZ6n00cTa9bNokD4S7We7lWcXwWC+17CeNYxei2xk35G
KgtRdHLEhYlILHfxGMpoBw9sqKxFlSAmOTb58u6DnYiVPTHAJfcC7bFYRZoD4Mv1
MLT2xVfBANtSkdGJkUVZpHnSDboxKbTcu8+KuMlbutyVtoVaT9hJUfgHuE71vRvz
xYCGVt5gnIKYqc7USeatEouvGm32AUDYmYjDpLNVoW8dtSqM1DE=
=448y
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.