[openpgp] Re: Proposal: Provider-assisted OpenPGP key disc overy

Michael Richardson <[email protected]> Wed, 15 Jul 2026 21:26:29 +0200
Newsgroups gmane.ietf.openpgp
Message-ID <359992.1784143589@dyas>
--===============6796500954321780173==
Content-Type: multipart/signed; boundary="=-=-=";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=-=-=
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable


Daniel Kahn Gillmor <[email protected]> wrote:
    > On Wed 2026-07-15 10:22:37 +0000, Bart Butler wrote:

    >> I will point out that getting the major ESPs to use such a registry
    >> will absolutely never happen.

    > Presumably Bart's description of "major e-mail service providers
    > (ESPs)" refers to Microsoft and Google, but not to Proton itself. =E2=
=98=BA

    > It's entirely possible that users whose e-mail addresses are controll=
ed
    > by these major platforms will be unable to make use of the kind of
    > automated OpenPGP certificate discovery you're contemplating, due to
    > recalcitrance of their ESP.

Yeah.
If one could get three of (proton, fastmail, tuta, zoho, mailbox) to
implement, I think it would be a win.
Someone on google or outlook can still just generate a key and bring it to
some keysigning party.

I'm rather unclear why the "endorsement" that was in the first email is
different than a regular openpgp signature... I used sign stuff from
[email protected].

    > I think the question for the WG is whether it is sufficient to build a
    > mechanism that works for users *not* in that group, given that the WG
    > has no control over the business decisions of these entities.

    > From my perspective, it seems reasonable to do that kind of work, as
    > long as we're realistic about the reach.  The goal for e-mail is a
    > functioning federated system.

+1.

=2D-
Michael Richardson <[email protected]>, Sandelman Software Works
 -=3D IPv6 IoT consulting =3D-                      *I*LIKE*TRAINS*




--=-=-=
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCgAdFiEERK+9HEcJHTJ9UqTMlUzhVv38QpAFAmpX3uUACgkQlUzhVv38
QpC3dAf/fO6nW51vLNnKOo9ZazezaIo9myyqLs3h8lXDNA8AkJlZuPRwDrxVQNG1
af+8w15N/vNbON4Ig6c7WLnEGNmb2TyoaHrQ6riibgwek04SstutYdpQMYoTjg+H
ld81u9X3dHrLBBKr5c8u9rnKTCP1xsySvRkhWEZIGOIXMeIlrvKp67u1WwT+qLEq
Lqfyml7gADnu3G+kUY/HCwdNtRNpbRewkKFUXjNNIHt+h2tPBZPuLKtqzi13AmX/
rUU1ENEXtcL4SuLSUkUxV/Y/d9UOaA8u1CnnjB53r+sC2ne3azHUfmOwcelNWPLx
ty0PZJi0vz0cJhcOzknNwcwBQ6Q45Q==
=ltC0
-----END PGP SIGNATURE-----
--=-=-=--


--===============6796500954321780173==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt
YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt
YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK

--===============6796500954321780173==--