[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
On Wed 2026-07-29 18:20:58 +0100, Andrew Gallagher wrote:
> On 29/07/2026 17:59, Paul Schaub wrote:
>> Do you happen to know the reason, why rfc9580 recommends against storing 
>> a trucation of the 32octet fingerprint on the card?
>
> The MR that introduced it is here:
>
> https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/187
>
> But there's nowhere in that MR discussion or in the linked issue that 
> fully explains why simple truncation is discouraged. Justus did suggest 
> in the issue that if a truncated "fingerprint" was displayed to a user, 
> having an explicit version marker (such as leading repeated bytes) would 
> enable basic debugging by sight (by experienced users), but otherwise 
> there seems to be no strong argument for it.

I think the important bits are in the text itself:

>> unless the relevant spec for the constrained environment has explicit
>> guidance for storing a v5 fingerprint that distinguishes it from a v4
>> fingerprint.

This is the WG saying "we haven't been able to come to a consensus on
how to do it right now, so please don't just stuff arbitrary bytes in
here unless you're following a spec that other people will follow"

If we advance some variant of Heiko's draft, we'll have a "relevant
spec" that allows it.

      --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE-----

wr0EARYKAG8Fgmp7lK4JEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z
LnNlcXVvaWEtcGdwLm9yZxf653Ahglp3rBPus9NDjERAPej1cQbkwekRuhZdGafi
FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAACgJAPkB2qL3nfgKyT+GJewS9QoSuNoO
JuAwN/RZW7q0PBbqvwD/SD2tsFK+m1LiUO9U6ZadMTouCe3vNRL0CxveCft6ZQM=
=N+gS
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.