[openpgp] Re: OpenPGP WG next steps discussion
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 16 Sep 2025, at 00:24, Daniel Kahn Gillmor <[email protected]> wrote: > > Please respond to this thread to point out work that you think might be > worth adopting, or to describe a specific need in the OpenPGP space, > even if there is no draft already crafted. Hi, Daniel. I am currently in the process of preparing a new draft for HKP, and intend to submit it for adoption once it is ready. > And the list of active documents with "openpgp" in the title contains many options A significant number of these are my fault, sorry. Of the ones in my name (or that I have contributed to) I think the following are the most useful: 1. The “Semantic cleanup project” consisting of draft-dkg-openpgp-revocation, draft-gallagher-openpgp-signatures and draft-gallagher-openpgp-attributes (just expired, update pending) should IMO be considered as a group. I notice that people have started to refer to draft-signatures in discussions here, which I find encouraging. I believe this is difficult but necessary work, and although these documents are nowhere near ready for publication, I believe they (or something like them) should be adopted in the near future. 2. draft-gallagher-openpgp-grease describes a method for production code to perform interop testing in the field, inspired by TLS GREASE. It is a nice to have rather than necessary feature, but I think it would be very useful, particularly for keyservers. I would implement this in Hockeypuck if it were adopted. 3. draft-gallagher-openpgp-media-types is also to some extent a "nice to have", but I would prefer if we could come to some agreement so that HKPv2 can use proper media types instead of "application/octet-stream" when serving binary certificates. Of the drafts not belonging to me, I think draft-huigens-openpgp-signature-salt-notation is a no-brainer and should be fast-tracked. I also feel that draft-dkg-openpgp-1pa3pc and draft-dkg-openpgp-sop have been around long enough and are implemented widely enough that their adoption is long overdue. I would also be willing to contribute to the following chartered topics, although they are not a high priority: * context binding * forward secrecy One non-chartered topic that I think should be added to the charter is a standardised JSON representation. I’m aware of at least three projects (hockeypuck, rpgp and sq) that either already have or are currently working on JSON representations of openpgp objects, and I think it would be a good idea if these were aligned. > In the past, we've organized a list of potential OpenPGP topics and conducted a poll to see which ones the working group wants to adopt. I aim to set up a similar poll once people have had a chance to identify the work they consider active and worthwhile. I think one notable flaw of the previous poll was that it only asked which topics people wanted to work on. I think this is incomplete, since there may be topics that nobody particularly wants to (or feels able to) work on, but which they still think should be done (by the proverbial Someone™). I think any future poll should therefore have two questions: 1. What topics do you want to see worked on? 2. What topics would you be willing to work on? If these give different answers, that’s a sign. Not a good one, but a useful one... Thanks, A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmjJLuUACgkQXB7EBNWQ ZilZfw/9HNY0On8oizN7JkGxwy8iu+UUMDFiHDtGakyMocBqI30wkPnMpDbcZUPM Yd5y77uValy1KybeZYc1sLT6RjfL+snjUWDM9njF05scgZjQxEzwaTHREXGLyuvd TTWNp6KFb6mCJ1a4ljMeyBd7hC9gCFUN2ij+EOLV1v0p5m6sWYvAC9d/ysB+5eHe 95OIOSn3rshjatX0EidCUZG5aDnHVBz+IzMAp4H4xpydf579BF9x7PUEuWbZFaOX XzCwBwNlEFQw/pbeFFRrRYa70baMdGJWQJEzwO18q8eYMGNZMH6CtPalzzwQK7kL dXrlrkM0Q7HRWG6UFnAkTlnjY1P/i3JoIFtij0faHnzPCWqTt0CIcrcApndKYc9v gk/qg3RuwD9kw1bHhKmlhqoU1dmWBWS+dglFqgIEhL9V3FDegg2mvK3lptpw3WiC SwHooNq7vHpeRxEaVqdLW0H5cYQxIn8EeeTDYN/bBZ2wZK3h2M3xoaNUQN8nndPs GetqAnb04dCVOyPKUw530taXkTfwIBN7Nxc3Doah/lL8NyRttjr0QIbkhbFS8MT5 rZAgw1S6uDl7U5Kn5ioGCYPhQvwl9ge+t+///aSQqI/007W7Y+BzfL/ML8u13fKi FnoP94VWH8dMsgSklNG9VI8aDSBoxdJW8mce7O3fwoKyWtIRZvI= =124T -----END PGP SIGNATURE-----