[openpgp] Re: PQC requires urgent semantic cleanup
Heiko Schäfer <[email protected]> Thu, 20 Nov 2025 14:52:00 +0000
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hello Andrew, list, thanks for raising this set of questions about OpenPGP temporal semantics, and for working on draft-gallagher-openpgp-signatures, so we will hopefully one day have a document that clarifies these matters in writing. 1. First off, I share your sentiment that it's preferable for OpenPGP semantics to deal gracefully with "minimization" of certificates. Dropping historical self-signatures from the current representation of a certificate has been common practice for decades. And as you outline, it may become even more necessary in a PQC future. 2. Generally, I think we'd do well to keep the (temporal) validity semantics as simple as reasonably possible. Complexity is the enemy of both a) interoperability between implementations, and b) users understanding what's going on with their artifacts. Striking the right balance there is obviously a hard task, as tradeoffs tend to be. 3. Finally, even though the semantics of OpenPGP have not been clearly laid out in text for the past decades, I seems worthwhile to avoid unnecessary divergence from user expectations that have developed over OpenPGP's long history. After reading your mail, I was wondering if looking at the old PGP.com implementations (from around the publication of RFC 2440) would clarify some of the unstated, implicit intent and semantics that the drafters of that RFC shared. One impression I got from this digging is that the PGP.com folks' intent for the "Signature Expiration Time" subpacket was actually to serve as a "Certification Expiration Time", in today's terminology. The published PGP.com code bases seem to very cleanly apply: - "Signature Expiration Time" subpackets to calculate temporal validity of certifications over User IDs, and - "Key Expiration Time" to calculate temporal validity of component keys. However, a brief glance at the GnuPG codebase seems to indicate that GnuPG handles the contents of "Signature Expiration Time" subpackets in some other contexts, now. And indeed, there is a historical email thread (from 1999) that seems to raise the idea of applying that subpacket's contents in other contexts than User ID certifications [1]. So it would appear that GnuPG diverged from PGP.com without any clear discussion in the WG that I could find. My conclusion from looking at this history is that semantics clarifications are long overdue. And that confusing semantics complexity has been introduced at various points of OpenPGP's history (possibly sometimes even accidentally), often without arriving at anything that looks to me like consensus on this list. I hope we can undo some of this complexity by processing draft-gallagher-openpgp-signatures. Thanks, :) Heiko PS: As suggested in the discussion at IETF 124, working through bite-sized chunks of the topics raised in draft-gallagher-openpgp-signatures seems like a pragmatic strategy to me as well. Clarifying semantics questions that the Interop Test Suite already touches on could be a natural starting point. Once those semantics are clarified, maybe we can iteratively come up with additional test cases that cover more testable semantics questions. [1]: https://mailarchive.ietf.org/arch/msg/openpgp/WyqsIF4-qRmv_iZNVtIlsvKzmYw/ _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]