[openpgp] Re: Key Flags subpacket interpretation question

Daniel Kahn Gillmor <[email protected]> Tue, 23 Dec 2025 16:09:57 -0500
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Thanks Daphne, Andrew, and Wyllys for this discussion about User IDs and
Key Flags.  Sorry I'm just catching up on this thread.

On Fri 2025-11-07 12:33:00 -0500, Daphne Shaw wrote:
> So long as the user ID key usage flags (the flags pertaining to the
> primary key) allow for certification (i.e. it's allowed to have
> subkeys at all),

I wanted to note (with no hats on) that i'm not sure Daphne's take on
this is the consensus semantics of the "certification" key usage flag.

As i understand it, the fact that the primary key *is* a primary key is
what allows subkey bindings (and user ID self-sigs, for that matter --
how else would you know what key usage flags are permitted?  there's a
chicken and egg problem here if you interpret it the other way).

The certification flag indicates that the key in question is expected to
be used to certify *other* certificates (that is, by adding a
certification signature over someone else's primary key + user ID).

I hope this is a useful contribution!

              --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]