[openpgp] Re: Review of draft-ietf-openpgp-replacementkey-04
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 8 Aug 2025, at 00:30, Andrew Gallagher <[email protected]> wrote: > >> It seems to me that at the minimum, the draft would benefit from some clarifications what types of trust are supposed to be captured by the trust transference through key equivalance and if / how this relates to the contents of the User-ID packets of the certificates in the equivalence group. >> > > I agree, and have been thinking along the following lines: > > * “trust” should be reserved for “ownertrust” and is therefore out of scope of this document > > * The input to the Key Equivalence calculation is whether a particular identity claim regarding a key/certificate is considered authentic, or valid, by the receiving implementation. Whether the claim is explicit or implicit, and whether the claim validity derives from the web of trust, or provenance, or the user Just Said So, should not matter for the purposes of this draft. > > * The output of the Key Equivalence calculation is that any valid identity claim (as determined by the previous bullet point) regarding one member of a Key Equivalence Set is automatically valid for all other (current) members of the Key Equivalence Set. > > I think this would avoid the “trust” minefield entirely. And perhaps we should therefore talk about “Identity Equivalence” instead of “Key Equivalence”? I have made the above changes to the editor’s copy. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmiaekcACgkQXB7EBNWQ Zim/Gw//Z44sdAv3G801A5NvVw8sA3skK6Y695VxqubKJM2m7eED/p05Nct58Ywv QCGHtQc0He4Nc19fzLOGoZtkFLOvbmBMfAaFvDdBRdmBS2iBMCZe9H3twb3oHdKg K1nfq47kCGWM62ayjYFiiMxE9bjgHwwEGyA7asLkMnUvil6J0vENAnpbR7vuFKq/ k9rmm4kkZ4GCtQlswHTEUwMGpolr/5HlwmmCFaK2MWksxKiAqaUbTqJ67SR3k7+P jAC+WMnCDWpDMfvxpEjyH3R9HWogW6zejCl23w9jBGGik475/tD3Nni/C6TTLEP6 vVSuYBQ5eelI+SueCyIIU3k8b59qxQvszCzztTRv7Qd6uJVV0lOWTczdcMxjtKiP JYxZMojemA5Vk+zVQ72KcceS2rZRMiCYljQMKAadL1apExQm1j4trqyS1I3O9pjB 5Yqe8/ptgbjmeFnJW9nORZ6n00cTa9bNokD4S7We7lWcXwWC+17CeNYxei2xk35G KgtRdHLEhYlILHfxGMpoBw9sqKxFlSAmOTb58u6DnYiVPTHAJfcC7bFYRZoD4Mv1 MLT2xVfBANtSkdGJkUVZpHnSDboxKbTcu8+KuMlbutyVtoVaT9hJUfgHuE71vRvz xYCGVt5gnIKYqc7USeatEouvGm32AUDYmYjDpLNVoW8dtSqM1DE= =448y -----END PGP SIGNATURE-----