[openpgp] Re: Key and Certificate Management in SOP
Heiko Schäfer <heiko.schaefer@posteo.de> Fri, 06 September 2024 15:57 UTC
Return-Path: <heiko.schaefer@posteo.de>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA3F8C14F6B0 for <openpgp@ietfa.amsl.com>; Fri, 6 Sep 2024 08:57:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.103
X-Spam-Level:
X-Spam-Status: No, score=-2.103 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=posteo.de
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CjtikmLgThXy for <openpgp@ietfa.amsl.com>; Fri, 6 Sep 2024 08:57:49 -0700 (PDT)
Received: from mout02.posteo.de (mout02.posteo.de [185.67.36.66]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 87367C14F61F for <openpgp@ietf.org>; Fri, 6 Sep 2024 08:57:48 -0700 (PDT)
Received: from submission (posteo.de [185.67.36.169]) by mout02.posteo.de (Postfix) with ESMTPS id 3F19C240101 for <openpgp@ietf.org>; Fri, 6 Sep 2024 17:57:46 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.de; s=2017; t=1725638266; bh=cQ6QQed2WIKy01OtNGnE+22vKWtyU1LgO0aIfvjp1yc=; h=Content-Type:Message-ID:Date:MIME-Version:Subject:To:From:From; b=UqCIVCyJdJFGXBHXpaG7a6+os8+mQsabQK52kMsy369NeVDzOLLY27XoYm8yjRVd6 PdA+kzQU37HCfIwpapklskviN7KAmHwKhvMXuqjHefGnAsFR/v2R+5StAK3Q/p6602 rNafl8mHij2yV7SuNPNlZ+nRWyyb7QXDVkMfJbVUEeV0Pq2nkCYgSaRtgjm7fK1g/j 1zfajowNAq6sCXUuwwU+lUAt+oKBjtp9GFSvBwqqd6XRC/1dIHsB0lWxaiVQCRJS8z g60SY2hcbRE2HXWKi+Nok8bmXy5hMeDFNsn6stPT8LLDnbc7/R7T3OV0N7yAKfweyU HY15biBW23Bhw==
Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4X0gqG093Xz6twZ for <openpgp@ietf.org>; Fri, 6 Sep 2024 17:57:45 +0200 (CEST)
Received: from services.foundation.hs (services.foundation.hs [192.168.21.4]) by mail.foundation.hs (Postfix) with ESMTP id 9F19B705C5 for <openpgp@ietf.org>; Fri, 6 Sep 2024 17:57:45 +0200 (CEST)
Content-Type: multipart/alternative; boundary="------------3BANlY2zMbCzwugTSuK2uKNs"
Message-ID: <af5259aa-31c6-4acf-93b1-b15104554c27@posteo.de>
Date: Fri, 06 Sep 2024 15:57:44 +0000
MIME-Version: 1.0
To: openpgp@ietf.org
References: <87ed5xwt8p.fsf@fifthhorseman.net>
Content-Language: en-US
From: Heiko Schäfer <heiko.schaefer@posteo.de>
In-Reply-To: <87ed5xwt8p.fsf@fifthhorseman.net>
Message-ID-Hash: NOEG4XFVUZHMPVCMNWXGCNDRPWTRCA3Q
X-Message-ID-Hash: NOEG4XFVUZHMPVCMNWXGCNDRPWTRCA3Q
X-MailFrom: heiko.schaefer@posteo.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Re: Key and Certificate Management in SOP
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/07Ou-a9O1mUSKMKp5QssOUh0KBA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hey dkg, great to see the SOP spec grow more capabilities! On 9/6/24 1:55 AM, Daniel Kahn Gillmor wrote: > I'm preparing to add four new subcommands for OpenPGP Key and > Certificate Management to the Stateless OpenPGP API: > > sop update-keys (keep an OpenPGP secret key "up-to-date") > sop merge-certs (merge OpenPGP certificates that share primary keys) > > sop certify (certify a User ID in a cert) > sop validate-certs (verify a User ID-to-cert binding) One of my recurring concerns in the OpenPGP ecosystem is terminology, and the clarity/non-overlap of our terms. From that perspective, I'm concerned about the command name "validate-certs". While the command deals with "Certificates", it seems to mostly be concerned with "User IDs" (and signature packets). So based on our discussion just now, I think it would be good to replace the "cert" fragmentwith "userid".Something like "sop validate-userids" would strike me as strictly less potentially confusing. Heiko
- [openpgp] Key and Certificate Management in SOP Daniel Kahn Gillmor
- [openpgp] Re: Key and Certificate Management in S… Heiko Schäfer
- [openpgp] Re: Key and Certificate Management in S… Daniel Kahn Gillmor