[openpgp] Algorithms vs packets in forwarding and PSK
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <Hc3ISJioGLKTY8w-xL2U4-c2UDlDmBR6QZ2IJ_s_PzKT7kpnG9tc1yV0doyJZe9E-X8yvsiJDiyVyvmuQ-iDC03tpNtVnAl2YDHZ9-FJKys=@protonmail.com> |
Hi all,
Last month we had two parallel threads about whether to define new
algorithms or new packet(s) in the forwarding and persistent symmetric
keys drafts.
My informal impression is that the direction folks are leaning in is
to define new algorithms for forwarding, and a new key packet for
persistent symmetric keys (but reuse the other packets).
Yesterday I had a call with Aron and we both agreed that it would look
slightly strange to be inconsistent here, though we didn't reach a
conclusion beyond that, so we thought we'd ask the WG again to make
sure :)
We basically have a 3x3 grid of options:
A) Forwarding
1. Define new algorithms; reuse private key and PKESK packets
2. Define a new key packet and a new FKESK packet
3. Define a new FKESK packet, reuse the private key packet
B) Persistent symmetric keys
1. Define new algorithms; reuse private key, PKESK and signature
packets
2. Define all new packets
3. Define a new key packet, reuse other packets, also define new
algorithms or the special value 0
(When reusing packets, we should probably introduce new key flags,
to be able to distinguish the uses of the key.)
Of course, there are some semantic differences between forwarding and
persistent symmetric keys, that could potentially lead to a different
decision making sense for both.
In particular, for forwarding:
- The key can be used to decrypt forwarded messages, but not encrypt
directly (only via the forwarding parameter)
- The key parameters are the same as those of existing algorithms for
all algorithms we care about, though this may not always be the case
- The message parameters are the same plus some additional ones
For persistent symmetric keys:
- The key can be used to encrypt and decrypt, or "sign" and "verify",
respectively
- The key parameters are new
- The message parameters are also new
In both cases, there's no corresponding public key.
For those that have followed or are interested in both discussions,
please let us know what your preferred option is. If your preferred
option differs between the two drafts, please also indicate which
factor makes you prefer a different outcome :)
Thanks!
Best,
Daniel
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]