[openpgp] Re: Key Flags subpacket interpretation question

Daniel Huigens <[email protected]> Tue, 30 Dec 2025 11:20:11 +0000
Newsgroups gmane.ietf.openpgp
Message-ID <ekiCgJ5v_CMgIdid0rTsv8u2kR-BX7H4_evTBjsX9itzziDeag_RH1RzeUfacFim1ZXOYH3mAK-0qKcabnSZh8_UVNd_C6keqLXNTGAgFZM=@protonmail.com>
On Wednesday, December 24th, 2025 at 06:52, Daniel Kahn Gillmor wrote:
> As i understand it, the fact that the primary key is a primary key is
> what allows subkey bindings (and user ID self-sigs, for that matter --
> how else would you know what key usage flags are permitted? there's a
> chicken and egg problem here if you interpret it the other way).
> 
> The certification flag indicates that the key in question is expected to
> be used to certify other certificates (that is, by adding a
> certification signature over someone else's primary key + user ID).

Indeed, this is confirmed by RFC9580 section 5.2.3.10:

   A cryptographically valid self-signature should be accepted
   from any primary key, regardless of what Key Flags (Section 5.2.3.29)
   apply to the primary key.  In particular, a primary key does not need
   to have 0x01 set in the first octet of the Key Flags order to make a
   valid self-signature.

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]