[openpgp] Re: [Dance] Key digest companion for RFC 7929 OPENPGPKEY

Andrew Gallagher <[email protected]> Fri, 21 Nov 2025 10:49:26 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi, Petr.

On 21/11/2025 10:36, Petr Menšík wrote:
> 
> My primary motivation was to provide easy check whether that user has 
> changed his key.

When you say "changed his key" do you mean "updated his existing key", 
or "published a new key"? These use cases are quite different and will 
probably need to be tackled separately.

> I think there is no need to create different owner name to different 
> record type, they are closely related. But I propose to publish two 
> records on that name. Both OPENPGPKEY and OPENPGPFP. For checking 
> validity of existing keys OPENPGPFP record query would be enough. Once 
> you get information your keyid has not changed, you do not have to query 
> the key data (again). If you will get NXDOMAIN response to OPENPGPFP 
> query on the shared owner name, then you do not have to query OPENPGPKEY 
> record anymore. You already know it is not there.

Note that when someone modifies their public key, it will have the same 
"key ID" (we should probably use "fingerprint", because "key ID" has a 
specific, slightly different meaning in OpenPGP). Any mechanism that 
returns just a fingerprint will not be able to represent modified states 
of an existing key.

I do see value in being able to publish a "last modified" or "unchanged" 
state to reduce network traffic, but maybe it's better represented by a 
timestamp?

A

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]