[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets

Werner Koch <[email protected]> Thu, 30 Jul 2026 13:37:47 +0200
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
--===============3117390621186031344==
Content-Type: multipart/signed;
 boundary="=Planet-1_Arellano-Felix_Suicide_attack_pink_noise_Manfurov_Reno_NOCS";
	micalg=pgp-sha512; protocol="application/pgp-signature"

--=Planet-1_Arellano-Felix_Suicide_attack_pink_noise_Manfurov_Reno_NOCS
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Hi!

I usually don't follow the discussions on this ML but I noticed the
subject.  Given that Achim an me designed the OpenPGP card specs, here
are some comments:

On Thu, 30 Jul 2026 10:51, Wiktor Kwapisiewicz said:

> The only use for that fingerprint field I know of was for

The primary use case for fingerprint of the OpenPGP cards is to locate
the corresponding public key.  The fingerprint is shorter than the RSA
modulus and thus avoids delays.

Given that RSA usage on cards is anyway a performance problem and its
use is decreasing, it is meanwhile easier to compute the fingerprint
from the public key.  For that the creation date DO is important.

With X448 on v5 and v6 keys things are getting a bit complicate because
we need the key packet version to compute the fingerprint.  GnuPG has no
support for this yet but a method which may work with existing hardware
is to re-use the fingerprint DO to convey extra information.  For
example 15*0x00||<version_octet> could do the job.

> brute-forcing ECDH parameters, a problem that v6 implementations

Actually these should be standardized depending on the curve but in
reality some implementations and also old versions of GnuPG have several
variants for the ECDH parameters.  This should not be a problem for v4
keys because the fingerprint DO can be kept in its original form.


Shalom-Salam,

   Werner

=2D-=20
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

--=Planet-1_Arellano-Felix_Suicide_attack_pink_noise_Manfurov_Reno_NOCS
Content-Type: application/pgp-signature; name="openpgp-digital-signature.asc"

-----BEGIN PGP SIGNATURE-----

iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCams3ixsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMiwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQengMAP4n
y05h25C2RtEAihpOzfropazaRiY4X5J/LN7vs5ZNlQD/QTkIDe7KXZZDrjO+h1Ai
+RJF+cjMgtRPgPxKqDDVrgo=
=vIE5
-----END PGP SIGNATURE-----
--=Planet-1_Arellano-Felix_Suicide_attack_pink_noise_Manfurov_Reno_NOCS--


--===============3117390621186031344==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18Kb3BlbnBncCBt
YWlsaW5nIGxpc3QgLS0gb3BlbnBncEBpZXRmLm9yZwpUbyB1bnN1YnNjcmliZSBzZW5kIGFuIGVt
YWlsIHRvIG9wZW5wZ3AtbGVhdmVAaWV0Zi5vcmcK

--===============3117390621186031344==--