[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets

Daniel Kahn Gillmor <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hi Heiko, all--

I've read this draft and i think it is a worthwhile contribution for
people who want to use OpenPGP with secret key material backed by
smartcards.

I like that it's narrowly scoped, but maybe in some sections the scope
is a bit unclear.  The draft presents itself in some cases as generic
"how to use limited storage for larger key identifiers" but more
concretely in other cases as the particular "v6 key identifiers on an
OpenPGP smartcard".

For example, §2.1 is very particular (v6-only, OpenPGP smartcard), but
§6.2.2 appears to be partway to generic (OpenPGP smartcard, but any
version > 4). I know that formally the IETF has blessed only one version
greater than v4, which is v6, but if the goal is to make it work for
future IETF versions (or for LibrePGP's claimed/squatted "v5" format for
that matter) then you might want to tighten up the text to make it
clearer how to apply it to an as-yet-unspecified version.

Maybe the best scope would be "hardware device with an exactly 20 octet
identifier and an OpenPGP key with version > 4".

I really appreciated §6.2.2's concrete description of how to recalculate
the fingperint from material available from an OpenPGP card.  However,
i'm not sure what an implementation should do if that calculation
doesn't match the material in the identifier slot.  (i'm also not sure
what an implementation should do in that case with a v4 public key in
hardware, for that matter!)  Perhaps this document could offer some
guidance on what a safe thing to do is in that circumstance?

On Tue 2026-08-18 11:55:00 +0200, Paul Schaub wrote:
> I'd like for the working group to adopt the proposal in order to have a 
> stable specification to refer upstream to.

Heiko hasn't publicly called for WG adoption, or indicated whether he's
willing to give control of the doc to the WG.  Consulting the group's
charter, this does seem like it could fall under the general rubric of:

   "provide guidance to OpenPGP libraries and/or applications."

Though it's not mentioned as a specific topic in the lengthy menu
presented in the current charter.

Knowing that there are two distinct OpenPGP implementations interested
in interoperability across hardware devices is meaningful for the
working group, though.  Thanks for the implementer's report!

Regards,

        --dkg

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
signature.asc (application/pgp-signature, 324 B)
-----BEGIN PGP SIGNATURE-----

wr0EARYKAG8FgmqEfNQJEHgLhU7ZwrSWRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z
LnNlcXVvaWEtcGdwLm9yZ7ZhEJBvO8pXKjhN/JhAYZb6bZmw3j2vDnevolO2c59P
FiEEY6wRjlsuXWbIioWneAuFTtnCtJYAAG3BAP9/qA4ql0MedyFyI4VhIzxHFERa
TTxrENdQ7DFfM9Mk7gD9HA0l7NJXJ6/GZ4JuzeZ9O2374tNMd9TE5d4gJC/YCQ4=
=KvHe
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.