[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets

Heiko Schäfer <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <[email protected]>
Hello dkg, all,

thank you again for the comments, dkg, and everyone else.

I have published a new revision of the document that I hope addresses 
all of the concerns raised so far (and that hopefully also clarifies all 
of the questions that were raised - some implicit).

Further feedback is of course welcome.

Thanks,
:) Heiko


On 8/18/26 5:40 PM, Daniel Kahn Gillmor wrote:
> Hi Heiko, all--
>
> I've read this draft and i think it is a worthwhile contribution for
> people who want to use OpenPGP with secret key material backed by
> smartcards.
>
> I like that it's narrowly scoped, but maybe in some sections the scope
> is a bit unclear.  The draft presents itself in some cases as generic
> "how to use limited storage for larger key identifiers" but more
> concretely in other cases as the particular "v6 key identifiers on an
> OpenPGP smartcard".
>
> For example, §2.1 is very particular (v6-only, OpenPGP smartcard), but
> §6.2.2 appears to be partway to generic (OpenPGP smartcard, but any
> version > 4). I know that formally the IETF has blessed only one version
> greater than v4, which is v6, but if the goal is to make it work for
> future IETF versions (or for LibrePGP's claimed/squatted "v5" format for
> that matter) then you might want to tighten up the text to make it
> clearer how to apply it to an as-yet-unspecified version.
>
> Maybe the best scope would be "hardware device with an exactly 20 octet
> identifier and an OpenPGP key with version > 4".
>
> I really appreciated §6.2.2's concrete description of how to recalculate
> the fingperint from material available from an OpenPGP card.  However,
> i'm not sure what an implementation should do if that calculation
> doesn't match the material in the identifier slot.  (i'm also not sure
> what an implementation should do in that case with a v4 public key in
> hardware, for that matter!)  Perhaps this document could offer some
> guidance on what a safe thing to do is in that circumstance?
>
> On Tue 2026-08-18 11:55:00 +0200, Paul Schaub wrote:
>> I'd like for the working group to adopt the proposal in order to have a
>> stable specification to refer upstream to.
> Heiko hasn't publicly called for WG adoption, or indicated whether he's
> willing to give control of the doc to the WG.  Consulting the group's
> charter, this does seem like it could fall under the general rubric of:
>
>     "provide guidance to OpenPGP libraries and/or applications."
>
> Though it's not mentioned as a specific topic in the lengthy menu
> presented in the current charter.
>
> Knowing that there are two distinct OpenPGP implementations interested
> in interoperability across hardware devices is meaningful for the
> working group, though.  Thanks for the implementer's report!
>
> Regards,
>
>          --dkg
>
> _______________________________________________
> openpgp mailing list -- [email protected]
> To unsubscribe send an email to [email protected]

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.