[openpgp] Re: Key Flags subpacket interpretation question

Daphne Shaw <[email protected]> Tue, 30 Dec 2025 09:08:25 -0500
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
> On Dec 23, 2025, at 4:09 PM, Daniel Kahn Gillmor <[email protected]> wrote:
> 
> Thanks Daphne, Andrew, and Wyllys for this discussion about User IDs and
> Key Flags.  Sorry I'm just catching up on this thread.
> 
> On Fri 2025-11-07 12:33:00 -0500, Daphne Shaw wrote:
>> So long as the user ID key usage flags (the flags pertaining to the
>> primary key) allow for certification (i.e. it's allowed to have
>> subkeys at all),
> 
> I wanted to note (with no hats on) that i'm not sure Daphne's take on
> this is the consensus semantics of the "certification" key usage flag.
> 
> As i understand it, the fact that the primary key *is* a primary key is
> what allows subkey bindings (and user ID self-sigs, for that matter --
> how else would you know what key usage flags are permitted?  there's a
> chicken and egg problem here if you interpret it the other way).
> 
> The certification flag indicates that the key in question is expected to
> be used to certify *other* certificates (that is, by adding a
> certification signature over someone else's primary key + user ID).

This is correct, and I misremembered the wording from 4880, much less 9580, mea culpa!

... and given that I was one of the people who suggested the 4880 wording to improve on the 2440 wording (the 2440 text required primary keys to be capable of signing, not certification), I really should have remembered that.

Daphne

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]