[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01
Falko Strenzke <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hi DKG ---------------------------------------- *Von: *Daniel Kahn Gillmor <[email protected]> *An: *Falko Strenzke <[email protected]>; Daniel Huigens <[email protected]> *Kopie: *[email protected] *Datum: *09.09.2025 20:41:14 *Betreff: *[openpgp] Re: review of draft-ietf-openpgp-persistent-symmetric-keys-01 > On Mon 2025-09-08 07:07:55 +0200, Falko Strenzke wrote: >> Since OpenPGP's genuine use case is communication, I think the draft >> needs to cover that case. You are right that the draft should then >> mention this use case explicitly early in the text. > > I'm not sure what a unique "genuine use case" is supposed to mean, but > i've personally used OpenPGP for backup and restore functionality, as > well as for synchronizing data securely between my own devices. These > aren't really "communication" use cases as i understand them. > > Maybe one way to resolve this simply is to clarify that symmetric keys > are *not* intended or designed to be used for communication between > multiple keyholders, and any such use is out of scope without further > specification. That requires a decision. Daniel's point of view was that he has no intention to disallow it. But I agree with you that without describing a mechanism for secure sharing of symmetric keys, this should not be implemented. Secure sharing would in my view require at a minimum an interoperable mechanism for password-encrypted key export. And I don't expect that Daniel or the WG necessarily wants to specify that now. So in my view the draft should say that sharing symmetric keys requires a mechanism for sharing symmetric keys, which might be specified in the future. But what I think the draft should account for in the private key packets - under the assumption that they will be of a new type - is a list of user IDs this key has been shared with. I think there is consensus that public key packets with symmetric keys should not be exported. So tracking the key holder group in the private key itself would be the logical solution. Best regards, Falko > > --dkg > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] -- MTG AG Dr. Falko Strenzke Executive System Architect Phone: +49 6151 8000-24 E-Mail: [email protected] Web: www.mtg.de MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany Commercial register: HRB 8901 Register Court: Amtsgericht Darmstadt Management Board: Jürgen Ruf (CEO), Tamer Kemeröz Chairman of the Supervisory Board: Dr. Thomas Milde This email may contain confidential and/or privileged information. If you are not the correct recipient or have received this email in error, please inform the sender immediately and delete this email. Unauthorised copying or distribution of this email is not permitted. Data protection information: www.mtg.de/en/privacy-policy _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]