[openpgp] Re: Ideas for alternative user interface terms for OpenPGP structures
Paul Schaub <[email protected]> Thu, 26 Feb 2026 18:42:26 +0100
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hey! My 2 cents: I got used to refer to TPKs as either "OpenPGP Certificates" or "OpenPGP public keys" (I prefer OpenPGP Certificates though). For TSKs, I use the term "OpenPGP Key". This follows the terminology from https://openpgp.dev/book/certificates.html which I also used for BCs new high level API and for PGPainless' 2.0 API. Referring to a certificate as "pattern" feels wrong. Happy Hacking Paul Am 26.02.26 um 11:37 schrieb Kai Engert: > Hello, > > this message isn't about protocols, algorithms or packet structures. > It's just about user interface terms. > > I have been struggling with the use of the term "certificate" in the > context of OpenPGP. My pain points are: > - it implies third party certification even when there is none, > which is often missing in OpenPGP transferable keys. > - it overlaps with the established use of the term with S/MIME, > which is particularly relevant in applications that offer > both OpenPGP and S/MIME functionality to users. > > The alternative term "OpenPGP public key" also isn't perfect, because > the objects that users work with contain more than just the public key. > > Also overall, I think the terms "OpenPGP certificate" and "OpenPGP > public key" and "secret key" are difficult to understand for users. > (Especially when the word key is used for the public key, because in > human language, a key is used for unlocking something, so there is > risk of confusing secret and public keys. That's an argument for > avoiding the term key when talking about public keys to users.) > > I'd like to propose an alternative set of terms for OpenPGP objects to > be used in user interfaces, to make it easier for users to understand. > > I propose the term "Message Crypto Patterns" (or Mail Crypto Patterns) > (MCP) as a user understandable abstraction as a replacement for > "transferable public key" or "OpenPGP certificate. > > Based on the name, users can tell "this is the thing I need to make > cryptography work" and because cryptography is about transforming an > object, "this is the pattern that is used for the transformation". > > UI language could say Alice tries to find Bob's MCP. She can find > candidate MCPs. She could see that one of them is a certified MCP > (because it contains a certification signature). Alice can manually > verify an MCP. > > An MCP can contain multiple individual patterns. (That's why the > suggested expanded form of the acronym says patterns, not pattern.) > > The MCP can contain an encryption pattern (encryption subkey) and/or a > signature pattern (signing subkey). > > Alice uses the encryption pattern from Bob's MCP to encrypt a message > for Bob. To verify a signed message from Bob, Alice checks that the > signature matches Bob's signing pattern. > > Patterns can be old (expired/revoked), new patterns can get added. An > MCP can get updated to contain a new pattern. > > It would also work to say "Bob's MCP contains a Post-Quantum > encryption pattern". (The PQ pattern is a more advanced pattern to > transform messages in a stronger way.) > > The counterpart is the Message Crypto Secret (MCS), which contains the > private crypto material. > > What do you think? I'm looking forward to your feedback. > > Thanks, > Kai > > > > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]