[openpgp] Algorithms vs packets in forwarding and PSK

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <Hc3ISJioGLKTY8w-xL2U4-c2UDlDmBR6QZ2IJ_s_PzKT7kpnG9tc1yV0doyJZe9E-X8yvsiJDiyVyvmuQ-iDC03tpNtVnAl2YDHZ9-FJKys=@protonmail.com>
Hi all,

Last month we had two parallel threads about whether to define new
algorithms or new packet(s) in the forwarding and persistent symmetric
keys drafts.

My informal impression is that the direction folks are leaning in is
to define new algorithms for forwarding, and a new key packet for
persistent symmetric keys (but reuse the other packets).

Yesterday I had a call with Aron and we both agreed that it would look
slightly strange to be inconsistent here, though we didn't reach a
conclusion beyond that, so we thought we'd ask the WG again to make
sure :)

We basically have a 3x3 grid of options:

A) Forwarding
   1. Define new algorithms; reuse private key and PKESK packets
   2. Define a new key packet and a new FKESK packet
   3. Define a new FKESK packet, reuse the private key packet
B) Persistent symmetric keys
   1. Define new algorithms; reuse private key, PKESK and signature
      packets
   2. Define all new packets
   3. Define a new key packet, reuse other packets, also define new
      algorithms or the special value 0

(When reusing packets, we should probably introduce new key flags,
to be able to distinguish the uses of the key.)

Of course, there are some semantic differences between forwarding and
persistent symmetric keys, that could potentially lead to a different
decision making sense for both.

In particular, for forwarding:
- The key can be used to decrypt forwarded messages, but not encrypt
  directly (only via the forwarding parameter)
- The key parameters are the same as those of existing algorithms for
  all algorithms we care about, though this may not always be the case
- The message parameters are the same plus some additional ones

For persistent symmetric keys:
- The key can be used to encrypt and decrypt, or "sign" and "verify",
  respectively
- The key parameters are new
- The message parameters are also new

In both cases, there's no corresponding public key.

For those that have followed or are interested in both discussions,
please let us know what your preferred option is. If your preferred
option differs between the two drafts, please also indicate which
factor makes you prefer a different outcome :)

Thanks!

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.