[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets
Daniel Kahn Gillmor <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On Wed 2026-07-29 18:20:58 +0100, Andrew Gallagher wrote:
> On 29/07/2026 17:59, Paul Schaub wrote:
>> Do you happen to know the reason, why rfc9580 recommends against storing
>> a trucation of the 32octet fingerprint on the card?
>
> The MR that introduced it is here:
>
> https://gitlab.com/openpgp-wg/rfc4880bis/-/merge_requests/187
>
> But there's nowhere in that MR discussion or in the linked issue that
> fully explains why simple truncation is discouraged. Justus did suggest
> in the issue that if a truncated "fingerprint" was displayed to a user,
> having an explicit version marker (such as leading repeated bytes) would
> enable basic debugging by sight (by experienced users), but otherwise
> there seems to be no strong argument for it.
I think the important bits are in the text itself:
>> unless the relevant spec for the constrained environment has explicit
>> guidance for storing a v5 fingerprint that distinguishes it from a v4
>> fingerprint.
This is the WG saying "we haven't been able to come to a consensus on
how to do it right now, so please don't just stuff arbitrary bytes in
here unless you're following a spec that other people will follow"
If we advance some variant of Heiko's draft, we'll have a "relevant
spec" that allows it.
--dkg
_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE----- wr0EARYKAG8Fgmp7lK4JEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z LnNlcXVvaWEtcGdwLm9yZxf653Ahglp3rBPus9NDjERAPej1cQbkwekRuhZdGafi FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAACgJAPkB2qL3nfgKyT+GJewS9QoSuNoO JuAwN/RZW7q0PBbqvwD/SD2tsFK+m1LiUO9U6ZadMTouCe3vNRL0CxveCft6ZQM= =N+gS -----END PGP SIGNATURE-----