[openpgp] Re: OpenPGP WG next steps discussion
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <E8Oa0XjPHVvD7OmnNVAQ3mjeyRBxH9Um4-kBchhEuKMj8K39s-9VX47w9lk9D_wd3Uv3CR_aNvA7L7yJZ0kNQoABxzSHnrTLCg5QkAgqas8=@protonmail.com> |
Hi Simon, We are interested in Key Transparency for OpenPGP, and have shipped a version of it: https://proton.me/files/proton_keytransparency_whitepaper.pdf IMO, what would be most interesting is to do a standardized version of this based on the work of the Key Transparency WG. In my view, this doesn't necessarily require an OpenPGP extension to carry transparency information; that could instead be added to the HKP API, for example. That way, we also don't need a distinction between pre-certs (which are added to the transparency log) and post-certs with transparency information (which are distributed) like CT has, which simplifies the design. Best, Daniel On Wednesday, September 17th, 2025 at 09:10, Simon Josefsson <[email protected]> wrote: > Hi > > Some ideas for future work: > > - FrodoKEM support > - Classic McEliece support > - Hybrid signatures > - Interop considerations with LibrePGP > - Extensions for Transparency log chain assertions > > I've been trying to reach folks interested in the last one, to brigde > the PGP and Sigstore/Sigsum communities to see if we can get PGP to > support transparency chained signatures somehow. If anyone is > interested in exploring this, let me know. I think a PGP extension to > carry transparency information of the signature/publickey would be > fairly simple to specify. > > /Simon > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]