[openpgp] Re: review of draft-ietf-openpgp-persistent-symmet ric-keys-01
Andrew Gallagher <[email protected]> Mon, 20 Oct 2025 13:53:56 +0100
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 05/09/2025 10:42, Daniel Huigens wrote: > > On Thursday, September 4th, 2025 at 16:18, Falko Strenzke > <[email protected]> wrote: >> >> - Do you think that using time stamping signatures is the right way? >> > From reading section 3.5 and 3.6 of draft-gallagher-openpgp-signatures, > my understanding is that timestamping signatures are to be used to sign > documents, while Third Party Confirmation Signatures (0x50) are to be > used to sign signatures. The latter is closer to the use case I > described previously. (That doesn't necessarily mean that creating a > timestamping signature with a symmetric key isn't useful, perhaps it is, > but it's not what I had in mind originally.) > > Further, section 3.6 says: > > By default, a Third Party Confirmation signature makes no claim > about the validity of the other signature, just its existence, and > makes no claim whatsoever about the subject of that signature. This > interpretation MAY be modified by adding notation subpackets, the > meaning of which are application-dependent. > > > Which I think doesn't quite reach your goal of fully specifying a > mechanism. However, personally I think it could be defensible to define > a subpacket or notation for this purpose (of denoting whether the > countersigned signature was observed to be valid or invalid) in draft- > gallagher-openpgp-signatures. Andrew is currently on vacation so we may > have to wait for his opinion :) > > In any case, I'm happy to point from draft-ietf-openpgp-persistent- > symmetric-keys to draft-gallagher-openpgp-signatures for suggestions on > how to use persistent symmetric signing keys. Sorry, I'm really late replying to this! I agree that third party confirmation signatures are a better choice for this use case. The idea would be that Alice signs over Bob's signature packet with an 0x50 signature and adds notations describing the context and outcome of the verification she just performed. These notations don't need to be in the IETF namespace, since they are presumably for her own private use, but publishing them in an INFORMATIONAL or other non-standards track document might be nice. Alice would then store her 0x50 signature in an embedded signature subpacket in the unhashed area of Bob's original signature. A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]