Reaction to potential PGP schism
Stephan Verbücheln <[email protected]> Thu, 14 Dec 2023 10:29:17 +0000
| Newsgroups | gmane.linux.debian.devel.general,gmane.linux.debian.devel.security |
|---|---|
| Message-ID | <[email protected]> |
Hello everyone As you probably know, Debian relies heavily on GnuPG for various purposes, including: - developer communication - signing of tarballs and patches - automated processes such as update validation by APT The OpenPGP Working Group at IETF is currently working on a new standard. https://datatracker.ietf.org/doc/draft-ietf-openpgp-crypto-refresh/ Due to different opinions, some people (including notably the GnuPG team) have quit the IETF Working Group and proposed their own LibrePGP standard. https://librepgp.org/ Notably remaining in the IETF Working Group are people from Proton Mail (maintaining OpenPGP.JS) and Sequoia PGP (free implementation in Rust). The disagreements are about details such as algorithms and file formats which make both standards incompatible. How can Debian deal with this? Should Debian intervene to prevent the worst? Regards Stephan
signature.asc
(application/pgp-signature, 260 B)
-----BEGIN PGP SIGNATURE----- iIwEABYIADQWIQRB1rjSpCJd8a7h6mNgNUJZCjx8YgUCZXrY/RYcdmVyYnVlY2hl bG5AcG9zdGVvLmRlAAoJEGA1QlkKPHxiTzYA/0Ams9dAJaJuSoJ0WYxAFuLcSimf LSlnfXxelZJwu3tNAQC4sUnzWOh45WscW0Fv6yyGNxJkB5hnX5BohyYNYZ6uBw== =hDFJ -----END PGP SIGNATURE-----