Re: Fwd: OpenPGP interoperability issues with gnupg >= 2.4
"Anna (cybertailor) Vyalkova" <[email protected]> Tue, 7 Feb 2023 11:37:14 +0500
| Newsgroups | dev.linux.lists.distributions |
|---|---|
| Message-ID | <[email protected]> |
> Hi all, > > I am one of the package maintainers of gnupg on Arch Linux. > DISCLAIMER: Since December 2022 I am also a contracted developer for the > Sequoia project (an alternative implementation of the OpenPGP standard > in Rust). > > We (Levente Polyak and I) are writing to you because you are the > maintainers of gnupg on other downstream distributions. > With gnupg 2.4.0 a change has been merged [1], which has gpg operate > with certificate material in a way that is incompatible with the > upcoming IETF approved "crypto-refresh" approach. > This means, that e.g. messages encrypted using a key generated with > gnupg >= 2.4.0 will not be compatible with OpenPGP implementations > following the upcoming IETF standard. Please read this message to understand the background: https://lists.gnupg.org/pipermail/gnupg-devel/2022-December/035230.html > While this has especially integrators such as Thunderbird [2] and > keyserver authors worried, it is also a concern for us as a downstream > distributor of gnupg. > Some of you have already updated gnupg to >= 2.4.0 in some form, but we > would like to take the time and open the discussion on this topic, as we > believe that the change is harmful to the larger OpenPGP ecosystem. > > We are currently still shipping 2.2.x due to (only now resolved) issues > with our distribution keyring. However, we are wondering how to proceed > with gnupg in the future, as it will also negatively affect the trust > model of our own distribution. > > Several scenarios seem likely (depending on adoption): > > * notifying users of upcoming incompatibilities if they create a key > with gnupg >= 2.4.0 > * shipping/ using gnupg 2.2.x alongside (or exclusively) for as long as > possible > * undoing the change in gnupg > > We would like to raise awareness and gather some feedback of current > packagers of gnupg to form a broader response to this issue. > > As mail threads with large To: headers might get very tedious for > discussing this topic, we would also like to invite you to > #openpgp-interop on libera.chat [3]. So, is it a real problem or just FUD? How is it different from u-config people's aggression towards pkgconf?