[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-05.txt
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Organization | MTG AG |
| Message-ID | <[email protected]> |
Hi Andrew, I reviewed version 05. I think all my comments have been adequately addressed, thanks for that. I have a few minor comments on the new version: - The beginning of Section 4.2 seems to imply that since there may be only one RKS in one signature, there can only be a single RKSP in the whole certificate. That doesn't seem to work out since according to RFC 9580 <https://www.rfc-editor.org/rfc/rfc9580.html#name-openpgp-version-6-certifica>, v6 keys can have any number of Direct Key Signatures. Later, under Section 5.1, something is said about RKSPs "new" Direct Key Signatures overriding the "older" ones, here I think the clarity could be enhanced as to whether this covers multiple Direct Key Signatures to be present simultaneously or not. Also already Section 4.2 should clarify this aspect. - In the figures in Sections 4.2 and A.3 it says "Reverse RKSP", but I think according to the new terminology it should say "*Backwards RKSP*". - Editorial only: Section 5.1.2: "If so, they may (in some circumstances) send messages encrypted to one of the certificates but addressed to an identity that it does not claim." I suggest for better readability: => " [...] to an identity that *this particular certificate* does not claim." Best regards, Falko Am 17.08.25 um 16:24 schrieb Andrew Gallagher: > Hi, all. > > I have made several changes to the Key Replacement draft to address concerns recently raised both on the list and privately, and to fix up various nits. These have now been published on the datatracker as draft-ietf-openpgp-replacementkey-05 (see below). > > The terminology changes alone have touched a significant number of the lines in the draft, however the majority of the changes are editorial. There have been a few small BCP14 changes (MUST/SHOULD), but none to the wire format. > > The following questions raised by dkg remain open. I asked for other opinions, but nobody else has yet responded: > > * The size and conditional inclusion of the target record length field (currently 2 octets and unconditional). > * Whether to specify (here or elsewhere?) that all unknown revocation reasons are hard. > > I also have not yet made dkg’s suggested changes to the structure of the examples section. I believe I have addressed the remainder of dkg’s feedback, as well as all of Aron’s and Falko’s (but please feel free to correct me!). > > In addition, there are two tickets open in the issue tracker [1] for earlier design suggestions to enable finer-grained controls of encryption subkey selection. The rough consensus for both was “won’t do”, and I am not aware of this consensus having changed in the meantime. > > If you have submitted feedback, please check that it has either been addressed, or is listed above. If someone else’s feedback is listed above and you have not yet expressed an opinion, please feel free to do so. If any feedback has not been satisfactorily addressed, or if you have new feedback about any other matter, please let me know. > > Thanks, > A > > [1]https://gitlab.com/andrewgdotcom/openpgp-replacementkey/-/issues/ > > >> On 17 Aug 2025, at 15:08,[email protected] wrote: >> >> Internet-Draft draft-ietf-openpgp-replacementkey-05.txt is now available. It >> is a work item of the Open Specification for Pretty Good Privacy (OPENPGP) WG >> of the IETF. >> >> Title: OpenPGP Key Replacement >> Authors: Daphne Shaw >> Andrew Gallagher >> Name: draft-ietf-openpgp-replacementkey-05.txt >> Pages: 23 >> Dates: 2025-08-17 >> >> Abstract: >> >> This document specifies a method in OpenPGP to suggest a replacement >> for an expired, revoked, or deprecated primary key. >> >> The IETF datatracker status page for this Internet-Draft is: >> https://datatracker.ietf.org/doc/draft-ietf-openpgp-replacementkey/ >> >> There is also an HTMLized version available at: >> https://datatracker.ietf.org/doc/html/draft-ietf-openpgp-replacementkey-05 >> >> A diff from the previous version is available at: >> https://author-tools.ietf.org/iddiff?url2=draft-ietf-openpgp-replacementkey-05 >> >> Internet-Drafts are also available by rsync at: >> rsync.ietf.org::internet-drafts >> >> >> _______________________________________________ >> openpgp mailing list [email protected] >> To unsubscribe send an email [email protected] > > _______________________________________________ > openpgp mailing list [email protected] > To unsubscribe send an email [email protected] -- *MTG AG* Dr. Falko Strenzke Phone: +49 6151 8000 24 E-Mail: [email protected] Web: mtg.de <https://www.mtg.de> ------------------------------------------------------------------------ MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email.Unauthorised copying or distribution of this email is not permitted. Data protection information: Privacy policy <https://www.mtg.de/en/privacy-policy> _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
smime.p7s
(application/pkcs7-signature, 4.9 KB) - not displayed