[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <i2kyUomrlEqy5ywhlDBQJ8_k8wNYBzUTVBK5XVf55EBVBX_LB_faqZBq1JWRM827O81egs41okxZjKLnOGdBCRzJ_75BLpRTndcwVMAvsFM=@protonmail.com> |
Hi Falko (& dkg), On Thursday, September 11th, 2025 at 15:37, Falko Strenzke <[email protected]> wrote: >> Maybe one way to resolve this simply is to clarify that symmetric keys >> are *not* intended or designed to be used for communication between >> multiple keyholders, and any such use is out of scope without further >> specification. > > That requires a decision. Daniel's point of view was that he has no intention to disallow it. But I agree with you that without describing a mechanism for secure sharing of symmetric keys, this should not be implemented. Secure sharing would in my view require at a minimum an interoperable mechanism for password-encrypted key export. And I don't expect that Daniel or the WG necessarily wants to specify that now. In the current draft, persistent symmetric keys are (for now) stored in secret key packets, which can be password-encrypted in a TSK. Even if we switch to a dedicated persistent symmetric key packet, I'd imagine we'd model it after the secret key packet, and keep similar functionality. IMHO that would be useful not only for communication but also simply for storing the persistent symmetric keys securely for private usage. > So in my view the draft should say that sharing symmetric keys requires a mechanism for sharing symmetric keys, which might be specified in the future. In principle, an application could implement their own mechanism for sharing persistent symmetric keys based on the above, either between multiple clients using the same account, or between multiple accounts (for communication). The former is already needed (also for asymmetric private keys) and is not standardized either in the OpenPGP WG. So, I don't fully agree that standardizing this is a strict requirement for usage. > But what I think the draft should account for in the private key packets - under the assumption that they will be of a new type - is a list of user IDs this key has been shared with. I think there is consensus that public key packets with symmetric keys should not be exported. So tracking the key holder group in the private key itself would be the logical solution. In my view, this could also be managed by the application by storing metadata external to the key. Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]