[openpgp] Re: Ideas for alternative user interface terms for OpenPGP structures

Simo Sorce <[email protected]> Thu, 26 Feb 2026 12:32:03 -0500
Newsgroups gmane.ietf.openpgp
Organization Red Hat
Message-ID <[email protected]>
On Thu, 2026-02-26 at 11:50 +0000, Andrew Gallagher wrote:
> On 26/02/2026 10:37, Kai Engert wrote:
> > 
> > I have been struggling with the use of the term "certificate" in the 
> > context of OpenPGP. My pain points are:
> > - it implies third party certification even when there is none,
> >    which is often missing in OpenPGP transferable keys.
> > - it overlaps with the established use of the term with S/MIME,
> >    which is particularly relevant in applications that offer
> >    both OpenPGP and S/MIME functionality to users.
> 
> It is possible to have an X509 "self-signed certificate" which is 
> closely analogous to an OpenPGP certificate with no third-party 
> signatures. The primary conceptual difference between an OpenPGP 
> certificate and an X509 one is that OpenPGP certificates that share a 
> primary key can be merged into a single object, while X509 requires 
> separate certificate objects for each certification.
> 
> Have you had feedback where users have been confused between X509 and 
> OpenPGP uses of the terminology?
> 
> > The alternative term "OpenPGP public key" also isn't perfect, because 
> > the objects that users work with contain more than just the public key.
> 
> I think you'll find little disagreement on this point. :-)
> 
> > I propose the term "Message Crypto Patterns" (or Mail Crypto Patterns) 
> > (MCP) as a user understandable abstraction as a replacement for 
> > "transferable public key" or "OpenPGP certificate.
> 
> I fear "pattern" is both novel in a cryptography context and generic, 
> and so falls between two stools. Cryptographers will be confused but 
> users will not be enlightened.

I would be harsher and say that pattern is extremely ambiguous in this
case, a pattern is a behavior you observe generally repeated over time
or over similar situations, it is not "a thing I need", at least not in
English (in my experience, but then I have an American influence so who
knows :-)

But the point is that I think pattern is much worse and far removed
from the concept of "identity" that an OpenPGP certificate conveys than
the term certificate.

I would agree with Bruce Walzer that "PGP Identity", or maybe "PGP
Identity Token" if you want to objectify it a bit more, would be more
appropriate and understandable.

"PGP Public Token" (or "PGP Public Identity Token / PGP-PIT) could also
be used to emphasize that this is not a secret object but a public
identity token you present to others.

> Beware also that "MCP" is already a (trendy!) acronym for Model Context 
> Protocol.

MCP these days is definitely burned as usable acronym.

So long Multi Computation Party ...


-- 
Simo Sorce
Distinguished Engineer
RHEL Crypto Team
Red Hat, Inc

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]