[openpgp] Transparency in OpenPGP (was: Re: OpenPGP WG n ext steps discussion)

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <gmpbGKhHo3Pob57LhxBS0bm2iZmLtRayec3_TZwZuOAL9IlusxyFSRFXRy2ZnTomiq7O0SNJ9IsSK2VRRY7jF-uzn-UimPxyD7XbzZps49U=@protonmail.com>
On Wednesday, September 17th, 2025 at 12:00, Andrew Gallagher wrote:

> On 17 Sep 2025, at 10:41, Simon Josefsson <[email protected]> wrote:
>
>> Are you (or someone else) also interested in how to commit a PGP
>> signature into a transparency log, and store the transparency chain
>> commitment in a PGP extension?
>
> In PGP, surely “key transparency” and “signature transparency” are the same thing? After all, anyone can generate key material - the object that needs to be entered into a transparency log is the certification signature(s) over that key material.

It could be, but doesn't strictly need to be like that. In our implementation of KT, the information in the transparency log is the key fingerprints, and some other metadata. It could also be the full certificate (bundle).

Also, the technology might be similar but the goal and distribution of information could be different.

If you're distributing a software package and a signature, using various protocols and channels, then I could imagine adding transparency information to the latter could be convenient.

By contrast, when distributing keys, if we're settling on HKP as the "protocol to rule them all", so to speak, then the simplest solution would be to add transparency information there, IMHO.

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.