[openpgp] Re: Call for adoption: draft-gallagher-openpgp-h kp-10 (Ends 2026-05-14)

Andrew Gallagher <[email protected]> Thu, 30 Apr 2026 15:49:45 +0100
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Thanks, Stephen.

I (perhaps obviously!) support adoption of this draft.

To give some history, Daphne wrote the first iteration of this draft way 
back in 2003, and it has been used as a reference document for multiple 
keyserver implementations and OpenPGP clients for over twenty years. It 
was never adopted by the WG, and therefore never became an official RFC 
despite its ecosystem-wide importance.

I restarted work on it in 2023, after it became clear that a graceful 
migration to RFC9580 required keyservers to gate the distribution of v6 
certificates through an API change. This, combined with twenty years of 
experience in the field, suggested that a full refresh of the HKP API 
was overdue.

In 2025, Daniel reorganised the v2 API to make it more RESTful, and the 
resulting spec is what the hockeypuck and KOO keyserver projects have 
jointly agreed to implement.

This document therefore serves two purposes - it formalises (after a 
twenty year delay!) the de-facto HKP v1 standard used by the majority of 
the OpenPGP installed base, and it introduces a refreshed v2 API-first 
specification to meet foreseeable future needs.

The v2 API supports both traditional keyserver search use cases, as well 
as domain-based canonical lookups, is informed by the recent experience 
of WKD and Hagrid deployments, and attempts to conform to modern API 
best practice.

I believe this specification is a necessary precondition for widespread 
deployment of RFC9580, and therefore strongly recommend that it be adopted.

Thanks,
Andrew.

On 30/04/2026 15:21, Stephen Farrell via Datatracker wrote:
> This message starts a openpgp WG Call for Adoption of:
> draft-gallagher-openpgp-hkp-10
> 
> This Working Group Call for Adoption ends on 2026-05-14
> 
> Abstract:
>     This document specifies a series of conventions to implement an
>     OpenPGP keyserver using the Hypertext Transfer Protocol (HTTP).  As
>     this document is a codification and extension of a protocol that is
>     already in wide use, strict attention is paid to backward
>     compatibility with these existing implementations.
> 
> Please reply to this message and indicate whether or not you support adoption
> of this Internet-Draft by the openpgp WG. Comments to explain your preference
> are greatly appreciated. Please reply to all recipients of this message and
> include this message in your response.
> 
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [2].
> Appropriate IPR disclosures required for full conformance with the provisions
> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
> 
> Thank you.
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-gallagher-openpgp-hkp/
> 
> There is also an HTMLized version available at:
> https://datatracker.ietf.org/doc/html/draft-gallagher-openpgp-hkp-10
> 
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-gallagher-openpgp-hkp-10
> 
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]