[openpgp] Re: Key Flags subpacket interpretation question
Daphne Shaw <[email protected]> Tue, 30 Dec 2025 09:08:25 -0500
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
> On Dec 23, 2025, at 4:09 PM, Daniel Kahn Gillmor <[email protected]> wrote: > > Thanks Daphne, Andrew, and Wyllys for this discussion about User IDs and > Key Flags. Sorry I'm just catching up on this thread. > > On Fri 2025-11-07 12:33:00 -0500, Daphne Shaw wrote: >> So long as the user ID key usage flags (the flags pertaining to the >> primary key) allow for certification (i.e. it's allowed to have >> subkeys at all), > > I wanted to note (with no hats on) that i'm not sure Daphne's take on > this is the consensus semantics of the "certification" key usage flag. > > As i understand it, the fact that the primary key *is* a primary key is > what allows subkey bindings (and user ID self-sigs, for that matter -- > how else would you know what key usage flags are permitted? there's a > chicken and egg problem here if you interpret it the other way). > > The certification flag indicates that the key in question is expected to > be used to certify *other* certificates (that is, by adding a > certification signature over someone else's primary key + user ID). This is correct, and I misremembered the wording from 4880, much less 9580, mea culpa! ... and given that I was one of the people who suggested the 4880 wording to improve on the 2440 wording (the 2440 text required primary keys to be capable of signing, not certification), I really should have remembered that. Daphne _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]