[openpgp] Re: PQC requires urgent semantic cleanup

Heiko Schäfer <[email protected]> Thu, 20 Nov 2025 14:52:00 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hello Andrew, list,

thanks for raising this set of questions about OpenPGP temporal 
semantics, and for working on draft-gallagher-openpgp-signatures, so we 
will hopefully one day have a document that clarifies these matters in 
writing.


1. First off, I share your sentiment that it's preferable for OpenPGP 
semantics to deal gracefully with "minimization" of certificates.
Dropping historical self-signatures from the current representation of a 
certificate has been common practice for decades. And as you outline, it 
may become even more necessary in a PQC future.

2. Generally, I think we'd do well to keep the (temporal) validity 
semantics as simple as reasonably possible.
Complexity is the enemy of both a) interoperability between 
implementations, and b) users understanding what's going on with their 
artifacts.

Striking the right balance there is obviously a hard task, as tradeoffs 
tend to be.

3. Finally, even though the semantics of OpenPGP have not been clearly 
laid out in text for the past decades, I seems worthwhile to avoid 
unnecessary divergence from user expectations that have developed over 
OpenPGP's long history.


After reading your mail, I was wondering if looking at the old PGP.com 
implementations (from around the publication of RFC 2440) would clarify 
some of the unstated, implicit intent and semantics that the drafters of 
that RFC shared.
One impression I got from this digging is that the PGP.com folks' intent 
for the "Signature Expiration Time" subpacket was actually to serve as a 
"Certification Expiration Time", in today's terminology.

The published PGP.com code bases seem to very cleanly apply:

- "Signature Expiration Time" subpackets to calculate temporal validity 
of certifications over User IDs, and
- "Key Expiration Time" to calculate temporal validity of component keys.

However, a brief glance at the GnuPG codebase seems to indicate that 
GnuPG handles the contents of "Signature Expiration Time" subpackets in 
some other contexts, now.
And indeed, there is a historical email thread (from 1999) that seems to 
raise the idea of applying that subpacket's contents in other contexts 
than User ID certifications [1].
So it would appear that GnuPG diverged from PGP.com without any clear 
discussion in the WG that I could find.


My conclusion from looking at this history is that semantics 
clarifications are long overdue.
And that confusing semantics complexity has been introduced at various 
points of OpenPGP's history (possibly sometimes even accidentally), 
often without arriving at anything that looks to me like consensus on 
this list.

I hope we can undo some of this complexity by processing 
draft-gallagher-openpgp-signatures.

Thanks,
:) Heiko

PS: As suggested in the discussion at IETF 124, working through 
bite-sized chunks of the topics raised in 
draft-gallagher-openpgp-signatures seems like a pragmatic strategy to me 
as well.
Clarifying semantics questions that the Interop Test Suite already 
touches on could be a natural starting point.
Once those semantics are clarified, maybe we can iteratively come up 
with additional test cases that cover more testable semantics questions.


[1]: 
https://mailarchive.ietf.org/arch/msg/openpgp/WyqsIF4-qRmv_iZNVtIlsvKzmYw/

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]