[openpgp] Re: v4+v6
Daniel Huigens <d.huigens@protonmail.com> Mon, 10 February 2025 10:04 UTC
Return-Path: <d.huigens@protonmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DFDF5C1D4CE6 for <openpgp@ietfa.amsl.com>; Mon, 10 Feb 2025 02:04:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.104
X-Spam-Level:
X-Spam-Status: No, score=-2.104 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=protonmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ntDx2N_COW82 for <openpgp@ietfa.amsl.com>; Mon, 10 Feb 2025 02:04:28 -0800 (PST)
Received: from mail-4322.protonmail.ch (mail-4322.protonmail.ch [185.70.43.22]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 93679C1D3DCE for <openpgp@ietf.org>; Mon, 10 Feb 2025 02:04:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1739181866; x=1739441066; bh=H2rrSN/v9/TLFqJOcgodQOmm0AUwe3H6ByTNh4N5bhY=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector:List-Unsubscribe:List-Unsubscribe-Post; b=Np3HzYifbi7+dfHmnFeblDahUYC18Yvm74DZnyyKAruQvsbICKtt1+wvrdbTRMfnj 7ay1UaW3ytxbQFTgcefWr97yWqp6IOv6JdBMqEs+9MYbVSmENk8n5zJ2E5W6nx6Jjl Chp5zjkjYZVRPLkJXTnCTi82mn8Y81MZzIm6GwQV8+MRCnBwwoPcGYtPVtHeTBgEPg Zwnj6Tog4dxYjZTFK+Y83WGUYL2kFtauVG/77gVfbursLnFVaD2q6GbxVX7ISkTV4n a59Ol5AiRgsEpWKJG1ZY/ubRE2viz8P6p4f//RkgFw+VQQf/VMkTtKkyusvf7Dp5Q8 8cPGW1hIJ4zJA==
Date: Mon, 10 Feb 2025 10:04:19 +0000
To: "Neal H. Walfield" <neal@walfield.org>
From: Daniel Huigens <d.huigens@protonmail.com>
Message-ID: <2TILmXlRqQuH38CSPgkT_AH9aB3GlY1QD3Ij69k1EpvBHkdE4z7KAIG1JzQqPv6z48ePIbIbRaf0dkmo88c_7kOlIjhvB5b8W8-oYG2mg4o=@protonmail.com>
In-Reply-To: <87h653fd5p.wl-neal@walfield.org>
References: <87h653fd5p.wl-neal@walfield.org>
Feedback-ID: 2934448:user:proton
X-Pm-Message-ID: b05f98415596e0117ed4cb5181be3d688d660075
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: FJVQVEIYIWFCSDOCW2FLLJ74IPYLEAN5
X-Message-ID-Hash: FJVQVEIYIWFCSDOCW2FLLJ74IPYLEAN5
X-MailFrom: d.huigens@protonmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF OpenPGP <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: v4+v6
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/-G71BNLTWiMiwe7tf1F3rNMj898>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi Neal :) >From my point of view, the most important use case for having a v6 key will be PQC. So, I'll focus on that part of your email: On Sunday, February 9th, 2025 at 14:41, Neal H. Walfield wrote: > This scheme works, because it it possible to use the same key material > for both v4 and v6 keys. It works less well for PQC, but I think it > still partially works, because some PQC algorithms use a composite > scheme. > > Given a certificate with an ML-DSA-65+Ed25519 primary key, (I think) > it is possible to extract just the Ed25519 public key, and compute the > corresponding v4 or v6 key. So we can go from a PQC certificate to v4 > or v6 certificate. The PQC draft says not to do this: https://www.ietf.org/archive/id/draft-ietf-openpgp-pqc-06.html#name-key-generation-2. Generally, reusing key material in different contexts is not advised, though I don't know whether there's a practical attack in this case, but it'd make the security analysis harder (or even fail to hold, formally speaking, as the text suggests). > Given a v4 or v6 key, we can't figure out the fingerprint of the > corresponding PQC key, because we don't have the PQC public key. But > if the PQC certificate is available, we can look it up by its Ed25519 > public key. Looking up the v6 (PQC) key from a keyserver when you only have a v4 key would seem like the most useful/important part of this, but this would only be possible if keyservers would allow looking up PQC keys by the Ed25519 public key, which seems complicated. Also, in general (even in the non-PQC case) this seems like a somewhat fragile way to look up a v6 key from a v4 key, because you don't know whether they reused the key material as you suggest, so the request might be insufficient (and conversely they might not have a v6 key at all, so the request might also be wasted). In essence, compared to this proposal, the key replacement draft places additional work on the key holder, to make things more straightforward and reliable for the key "consumers", so to speak. And I'd argue that's probably a good trade-off to make. Best, Daniel
- [openpgp] v4+v6 Neal H. Walfield
- [openpgp] Re: v4+v6 Paul Schaub
- [openpgp] Re: v4+v6 Andrew Gallagher
- [openpgp] Re: v4+v6 Neal H. Walfield
- [openpgp] Re: v4+v6 Daniel Huigens
- [openpgp] Re: v4+v6 Neal H. Walfield
- [openpgp] Re: v4+v6 Neal H. Walfield
- [openpgp] Re: v4+v6 andrewg
- [openpgp] Re: v4+v6 Johannes Roth
- [openpgp] Re: v4+v6 Daniel Huigens