[openpgp] Re: Using OpenPGP card hardware security devices w ith modern key packets
Heiko Schäfer <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
Hello dkg, all, thank you again for the comments, dkg, and everyone else. I have published a new revision of the document that I hope addresses all of the concerns raised so far (and that hopefully also clarifies all of the questions that were raised - some implicit). Further feedback is of course welcome. Thanks, :) Heiko On 8/18/26 5:40 PM, Daniel Kahn Gillmor wrote: > Hi Heiko, all-- > > I've read this draft and i think it is a worthwhile contribution for > people who want to use OpenPGP with secret key material backed by > smartcards. > > I like that it's narrowly scoped, but maybe in some sections the scope > is a bit unclear. The draft presents itself in some cases as generic > "how to use limited storage for larger key identifiers" but more > concretely in other cases as the particular "v6 key identifiers on an > OpenPGP smartcard". > > For example, §2.1 is very particular (v6-only, OpenPGP smartcard), but > §6.2.2 appears to be partway to generic (OpenPGP smartcard, but any > version > 4). I know that formally the IETF has blessed only one version > greater than v4, which is v6, but if the goal is to make it work for > future IETF versions (or for LibrePGP's claimed/squatted "v5" format for > that matter) then you might want to tighten up the text to make it > clearer how to apply it to an as-yet-unspecified version. > > Maybe the best scope would be "hardware device with an exactly 20 octet > identifier and an OpenPGP key with version > 4". > > I really appreciated §6.2.2's concrete description of how to recalculate > the fingperint from material available from an OpenPGP card. However, > i'm not sure what an implementation should do if that calculation > doesn't match the material in the identifier slot. (i'm also not sure > what an implementation should do in that case with a v4 public key in > hardware, for that matter!) Perhaps this document could offer some > guidance on what a safe thing to do is in that circumstance? > > On Tue 2026-08-18 11:55:00 +0200, Paul Schaub wrote: >> I'd like for the working group to adopt the proposal in order to have a >> stable specification to refer upstream to. > Heiko hasn't publicly called for WG adoption, or indicated whether he's > willing to give control of the doc to the WG. Consulting the group's > charter, this does seem like it could fall under the general rubric of: > > "provide guidance to OpenPGP libraries and/or applications." > > Though it's not mentioned as a specific topic in the lengthy menu > presented in the current charter. > > Knowing that there are two distinct OpenPGP implementations interested > in interoperability across hardware devices is meaningful for the > working group, though. Thanks for the implementer's report! > > Regards, > > --dkg > > _______________________________________________ > openpgp mailing list -- [email protected] > To unsubscribe send an email to [email protected] _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]