[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets

Paul Schaub <[email protected]> Wed, 29 Jul 2026 18:59:15 +0200
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
--===============3268901295057165353==
Content-Type: multipart/alternative;
 boundary=----FOB8MP312RX86KRZKGJVWTEGWMIF0F
Content-Transfer-Encoding: 7bit

------FOB8MP312RX86KRZKGJVWTEGWMIF0F
Content-Type: text/plain;
 charset=utf-8
Content-Transfer-Encoding: quoted-printable

Do you happen to know the reason, why rfc9580 recommends against storing a =
trucation of the 32octet fingerprint on the card?

Paul

Am 28=2E Juli 2026 21:29:21 MESZ schrieb "Heiko Sch=C3=A4fer" <heiko=2Esch=
aefer@posteo=2Ede>:
>Hey Simo,
>
>On 7/28/26 9:23 PM, Simo Sorce wrote:
>>> PS: I've implemented the suggested scheme in minipgp6, to see how it
>>> feels in practice - and did not encounter any issues=2E
>>> That said, I think just about any scheme for what to put in that
>>> "fingerprint" field is going to work just fine=2E We really mostly nee=
d to
>>> pick a single approach that everyone finds acceptable=2E
>> Why do you need 12 octects of redundant "version" data?
>>=20
>> The chances of collisions over a 20 octect field are very low anyway,
>> why do you need a version at all,
>
>As I just wrote, I don't think any particular scheme for how to use that =
field is required to "make this work"=2E
>Any number of schemes will work just fine=2E Most of all we need to pick =
one=2E
>
>The scheme I propose maximizes for simple recognizability of post-v4 keys=
 in card slots=2E
>It's one property that one can optimize for, but I'm not massively invest=
ed in the approach=2E
>
>Do you have a specific different goal that you think we should optimize f=
or?
>
>> why not just use the first 20 bytes of the 32 byte fingerprint ?
>
>This would be a possible alternative design, I briefly mention it here (a=
nd I mention why I didn't suggest it as a first proposal):
>
>https://www=2Eietf=2Eorg/archive/id/draft-hko-openpgp-identifiers-for-leg=
acy-devices-00=2Ehtml#name-design-choices
>
>Thanks,
>Heiko
>
>_______________________________________________
>openpgp mailing list -- openpgp@ietf=2Eorg
>To unsubscribe send an email to openpgp-leave@ietf=2Eorg

------FOB8MP312RX86KRZKGJVWTEGWMIF0F
Content-Type: text/html;
 charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head></head><body><div dir=3D"auto">Do you happen to know the reason=
, why rfc9580 recommends against storing a trucation of the 32octet fingerp=
rint on the card?<br><br>Paul</div><br><br><div class=3D"gmail_quote"><div =
dir=3D"auto">Am 28=2E Juli 2026 21:29:21 MESZ schrieb "Heiko Sch=C3=A4fer" =
&lt;heiko=2Eschaefer@posteo=2Ede&gt;:</div><blockquote class=3D"gmail_quote=
" style=3D"margin: 0pt 0pt 0pt 0=2E8ex; border-left: 1px solid rgb(204, 204=
, 204); padding-left: 1ex;">
<pre class=3D"net-thunderbird-android__plain-text-message-pre"><div dir=3D=
"auto">Hey Simo,<br><br>On 7/28/26 9:23 PM, Simo Sorce wrote:<br></div><blo=
ckquote class=3D"gmail_quote" style=3D"margin-bottom: 1ex; --net-thunderbir=
d-android__blockquote-default-border-color: #729fcf;"><blockquote class=3D"=
gmail_quote" style=3D"margin-bottom: 1ex; --net-thunderbird-android__blockq=
uote-default-border-color: #ad7fa8;"><div dir=3D"auto">PS: I've implemented=
 the suggested scheme in minipgp6, to see how it<br>feels in practice - and=
 did not encounter any issues=2E<br>That said, I think just about any schem=
e for what to put in that<br>"fingerprint" field is going to work just fine=
=2E We really mostly need to<br>pick a single approach that everyone finds =
acceptable=2E<br></div></blockquote><div dir=3D"auto">Why do you need 12 oc=
tects of redundant "version" data?<br><br>The chances of collisions over a =
20 octect field are very low anyway,<br>why do you need a version at all,<b=
r></div></blockquote><div dir=3D"auto"><br>As I just wrote, I don't think a=
ny particular scheme for how to use that field is required to "make this wo=
rk"=2E<br>Any number of schemes will work just fine=2E Most of all we need =
to pick one=2E<br><br>The scheme I propose maximizes for simple recognizabi=
lity of post-v4 keys in card slots=2E<br>It's one property that one can opt=
imize for, but I'm not massively invested in the approach=2E<br><br>Do you =
have a specific different goal that you think we should optimize for?<br><b=
r></div><blockquote class=3D"gmail_quote" style=3D"margin-bottom: 1ex; --ne=
t-thunderbird-android__blockquote-default-border-color: #729fcf;"><div dir=
=3D"auto">why not just use the first 20 bytes of the 32 byte fingerprint ?<=
br></div></blockquote><div dir=3D"auto"><br>This would be a possible altern=
ative design, I briefly mention it here (and I mention why I didn't suggest=
 it as a first proposal):<br><br><a href=3D"https://www=2Eietf=2Eorg/archiv=
e/id/draft-hko-openpgp-identifiers-for-legacy-devices-00=2Ehtml#name-design=
-choices">https://www=2Eietf=2Eorg/archive/id/draft-hko-openpgp-identifiers=
-for-legacy-devices-00=2Ehtml#name-design-choices</a><br><br>Thanks,<br>Hei=
ko<hr>openpgp mailing list -- openpgp@ietf=2Eorg<br>To unsubscribe send an =
email to openpgp-leave@ietf=2Eorg<br></div></pre></blockquote></div></body>=
</html>
------FOB8MP312RX86KRZKGJVWTEGWMIF0F--


--===============3268901295057165353==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt
YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt
YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK

--===============3268901295057165353==--