[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01

Falko Strenzke <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi DKG

----------------------------------------

*Von: *Daniel Kahn Gillmor <[email protected]>
*An: *Falko Strenzke <[email protected]>; Daniel Huigens <[email protected]>
*Kopie: *[email protected]
*Datum: *09.09.2025 20:41:14
*Betreff: *[openpgp] Re: review of draft-ietf-openpgp-persistent-symmetric-keys-01

> On Mon 2025-09-08 07:07:55 +0200, Falko Strenzke wrote:
>> Since OpenPGP's genuine use case is communication, I think the draft
>> needs to cover that case. You are right that the draft should then
>> mention this use case explicitly early in the text.
>
> I'm not sure what a unique "genuine use case" is supposed to mean, but
> i've personally used OpenPGP for backup and restore functionality, as
> well as for synchronizing data securely between my own devices.  These
> aren't really "communication" use cases as i understand them.
>
> Maybe one way to resolve this simply is to clarify that symmetric keys
> are *not* intended or designed to be used for communication between
> multiple keyholders, and any such use is out of scope without further
> specification.

That requires a decision. Daniel's point of view was that he has no intention to disallow it. But I agree with you that without describing a mechanism for secure sharing of symmetric keys, this should not be implemented. Secure sharing would in my view require at a minimum an interoperable mechanism for password-encrypted key export. And I don't expect that Daniel or the WG necessarily wants to specify that now.

So in my view the draft should say that sharing symmetric keys requires a mechanism for sharing symmetric keys, which might be specified in the future.

But what I think the draft should account for in the private key packets - under the assumption that they will be of a new type - is a list of user IDs this key has been shared with. I think there is consensus that public key packets with symmetric keys should not be exported. So tracking the key holder group in the private key itself would be the logical solution.

Best regards,
Falko

>
>         --dkg
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]


-- 

MTG AG
Dr. Falko Strenzke
Executive System Architect

Phone: +49 6151 8000-24
E-Mail: [email protected]
Web: www.mtg.de


MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email. Unauthorised
copying or distribution of this email is not permitted.

Data protection information: www.mtg.de/en/privacy-policy

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.