[openpgp] Re: Review of draft-ietf-openpgp-replacementkey-04
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi, Falko. On 12 Aug 2025, at 07:04, Falko Strenzke <[email protected]> wrote: Am 08.08.25 um 01:30 schrieb Andrew Gallagher: I think we can describe Key Equivalence Groups without referring specifically to User ID packets, but rather to the underlying concept that such packets represent - an identity “claim”. Such a claim can be explicit (there’s a User ID with a self-signature over it), or implicit (I found this in an Autocrypt header). We don’t need to get into such details in this draft, but I think it’s good to keep them in mind when drawing up suitably generic language. I see the following potential technical problem: Eve has an existing key with a single user ID [email protected] . Alice trusts that Eve rightfully owns this email address. Now at some point Eve creates a new key and sets the Replacement Key Subpackets in both the the old and the new key such that there is key equivalence established between them. The new key also happens to contain the User ID [email protected] . Will Alice now trust that Eve also controls this email address? Equivalence doesn’t mean that all userids are valid, it means that they are *as* valid for one primary key as they are for any other in the equivalence set. If [email protected] is claimed by one cert but not verified, then a receiving implementation will treat it as claimed but not verified by the other cert of the set. Put another way, Alice does not “trust eve’s key” - she trusts a particular userid claimed by eve’s key. Does that help? A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]