[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets
Paul Schaub <[email protected]> Wed, 29 Jul 2026 18:59:15 +0200
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
--===============3268901295057165353== Content-Type: multipart/alternative; boundary=----FOB8MP312RX86KRZKGJVWTEGWMIF0F Content-Transfer-Encoding: 7bit ------FOB8MP312RX86KRZKGJVWTEGWMIF0F Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Do you happen to know the reason, why rfc9580 recommends against storing a = trucation of the 32octet fingerprint on the card? Paul Am 28=2E Juli 2026 21:29:21 MESZ schrieb "Heiko Sch=C3=A4fer" <heiko=2Esch= aefer@posteo=2Ede>: >Hey Simo, > >On 7/28/26 9:23 PM, Simo Sorce wrote: >>> PS: I've implemented the suggested scheme in minipgp6, to see how it >>> feels in practice - and did not encounter any issues=2E >>> That said, I think just about any scheme for what to put in that >>> "fingerprint" field is going to work just fine=2E We really mostly nee= d to >>> pick a single approach that everyone finds acceptable=2E >> Why do you need 12 octects of redundant "version" data? >>=20 >> The chances of collisions over a 20 octect field are very low anyway, >> why do you need a version at all, > >As I just wrote, I don't think any particular scheme for how to use that = field is required to "make this work"=2E >Any number of schemes will work just fine=2E Most of all we need to pick = one=2E > >The scheme I propose maximizes for simple recognizability of post-v4 keys= in card slots=2E >It's one property that one can optimize for, but I'm not massively invest= ed in the approach=2E > >Do you have a specific different goal that you think we should optimize f= or? > >> why not just use the first 20 bytes of the 32 byte fingerprint ? > >This would be a possible alternative design, I briefly mention it here (a= nd I mention why I didn't suggest it as a first proposal): > >https://www=2Eietf=2Eorg/archive/id/draft-hko-openpgp-identifiers-for-leg= acy-devices-00=2Ehtml#name-design-choices > >Thanks, >Heiko > >_______________________________________________ >openpgp mailing list -- openpgp@ietf=2Eorg >To unsubscribe send an email to openpgp-leave@ietf=2Eorg ------FOB8MP312RX86KRZKGJVWTEGWMIF0F Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head></head><body><div dir=3D"auto">Do you happen to know the reason= , why rfc9580 recommends against storing a trucation of the 32octet fingerp= rint on the card?<br><br>Paul</div><br><br><div class=3D"gmail_quote"><div = dir=3D"auto">Am 28=2E Juli 2026 21:29:21 MESZ schrieb "Heiko Sch=C3=A4fer" = <heiko=2Eschaefer@posteo=2Ede>:</div><blockquote class=3D"gmail_quote= " style=3D"margin: 0pt 0pt 0pt 0=2E8ex; border-left: 1px solid rgb(204, 204= , 204); padding-left: 1ex;"> <pre class=3D"net-thunderbird-android__plain-text-message-pre"><div dir=3D= "auto">Hey Simo,<br><br>On 7/28/26 9:23 PM, Simo Sorce wrote:<br></div><blo= ckquote class=3D"gmail_quote" style=3D"margin-bottom: 1ex; --net-thunderbir= d-android__blockquote-default-border-color: #729fcf;"><blockquote class=3D"= gmail_quote" style=3D"margin-bottom: 1ex; --net-thunderbird-android__blockq= uote-default-border-color: #ad7fa8;"><div dir=3D"auto">PS: I've implemented= the suggested scheme in minipgp6, to see how it<br>feels in practice - and= did not encounter any issues=2E<br>That said, I think just about any schem= e for what to put in that<br>"fingerprint" field is going to work just fine= =2E We really mostly need to<br>pick a single approach that everyone finds = acceptable=2E<br></div></blockquote><div dir=3D"auto">Why do you need 12 oc= tects of redundant "version" data?<br><br>The chances of collisions over a = 20 octect field are very low anyway,<br>why do you need a version at all,<b= r></div></blockquote><div dir=3D"auto"><br>As I just wrote, I don't think a= ny particular scheme for how to use that field is required to "make this wo= rk"=2E<br>Any number of schemes will work just fine=2E Most of all we need = to pick one=2E<br><br>The scheme I propose maximizes for simple recognizabi= lity of post-v4 keys in card slots=2E<br>It's one property that one can opt= imize for, but I'm not massively invested in the approach=2E<br><br>Do you = have a specific different goal that you think we should optimize for?<br><b= r></div><blockquote class=3D"gmail_quote" style=3D"margin-bottom: 1ex; --ne= t-thunderbird-android__blockquote-default-border-color: #729fcf;"><div dir= =3D"auto">why not just use the first 20 bytes of the 32 byte fingerprint ?<= br></div></blockquote><div dir=3D"auto"><br>This would be a possible altern= ative design, I briefly mention it here (and I mention why I didn't suggest= it as a first proposal):<br><br><a href=3D"https://www=2Eietf=2Eorg/archiv= e/id/draft-hko-openpgp-identifiers-for-legacy-devices-00=2Ehtml#name-design= -choices">https://www=2Eietf=2Eorg/archive/id/draft-hko-openpgp-identifiers= -for-legacy-devices-00=2Ehtml#name-design-choices</a><br><br>Thanks,<br>Hei= ko<hr>openpgp mailing list -- openpgp@ietf=2Eorg<br>To unsubscribe send an = email to openpgp-leave@ietf=2Eorg<br></div></pre></blockquote></div></body>= </html> ------FOB8MP312RX86KRZKGJVWTEGWMIF0F-- --===============3268901295057165353== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK --===============3268901295057165353==--