[openpgp] Re: Call for adoption: draft-gallagher-openpgp-h kp-10 (Ends 2026-05-14)
Andrew Gallagher <[email protected]> Wed, 6 May 2026 23:45:53 +0100
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 04/05/2026 16:42, Michael Richardson wrote: > > Andrew Gallagher <[email protected]> wrote: >> If you mean "when do they upload detached revocations as opposed to >> revoked certificates?" then the answer is "when they're using legacy >> software". In practice, this means "GnuPG"... > > ... The "detached revocations" argument goes back years, and is unlikely to be resolved at this point. See e.g. https://dev.gnupg.org/T4393 and https://dev.gnupg.org/T6900 The "mixed keyring" format is specifically a workaround for T6900. > We have not yet, as a society, figured out how our credentials need to be > retired when we pass away (or go senile). That's almost the same as losing > secret key material. That's why I'm saying there needs to be a lifecycle > model. Many modern services encourage people to set "trusted contacts" who can reset passwords or manage their accounts on their behalf. This seems to me to be more appropriate and scalable than asking keyservers to act as trusted (centralised) authorities. But YMMV, not everyone agrees with those tradeoffs. And I don't think we should actively prevent people from asking a keyserver operator to act in trust, if that is what they want. I think this is a bigger discussion for another document. :-) Thanks, Andrew _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]