Re: [openpgp] additional 1 week last call on diffs from -10 to -12 of crypto-refresh

Werner Koch <wk@gnupg.org> Wed, 18 October 2023 08:10 UTC

Return-Path: <prvs=065592945f=wk@gnupg.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6A338C151075 for <openpgp@ietfa.amsl.com>; Wed, 18 Oct 2023 01:10:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=gnupg.org
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qT__sCHzqNXe for <openpgp@ietfa.amsl.com>; Wed, 18 Oct 2023 01:09:58 -0700 (PDT)
Received: from ellsberg.gnupg.com (ellsberg.gnupg.com [IPv6:2a01:4f8:151:7306::2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2065BC14CE5F for <openpgp@ietf.org>; Wed, 18 Oct 2023 01:09:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=gnupg.org; s=20181017; h=Content-Type:MIME-Version:Message-ID:In-Reply-To:Date: References:Subject:Cc:To:From:Sender:Reply-To:Content-Transfer-Encoding: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=PdzrXu0rynTEml+oyeRtUCDcmlWyaKeQy1ukBleCNdw=; b=Jx38rQzsQ0xQDv1ktNa90tvSn6 0K5+3U8yiHd3/2E4MjehXyFfrKxbYsovVktV4/FKOS8N0Pe1TdOt6QRmvvfeng1O0hVX/h1wQUpHu nkap59V2qCmX6rMvwuTn46FuqCOLvXcdRY0aL0R3Crv2qNyYZNXIc3wVzLK3tVO8f3jc=;
Received: from uucp by ellsberg.gnupg.com with local-rmail (Exim 4.94.2 (Devuan)) (envelope-from <wk@gnupg.org>) id 1qt1co-0004Bs-Cv for <openpgp@ietf.org>; Wed, 18 Oct 2023 10:09:54 +0200
Received: from wk by jacob.g10code.de with local (Exim 4.96 (Devuan)) (envelope-from <wk@gnupg.org>) id 1qt1bs-0003VS-06; Wed, 18 Oct 2023 10:08:56 +0200
From: Werner Koch <wk@gnupg.org>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Cc: "openpgp@ietf.org" <openpgp@ietf.org>
References: <0a95a4f1-2708-45ac-bd43-fa885e3a5ac5@cs.tcd.ie>
X-message-flag: Mails containing HTML will not be read! Please send only plain text.
Jabber-ID: wk@jabber.gnupg.org
Mail-Followup-To: Stephen Farrell <stephen.farrell@cs.tcd.ie>, "openpgp@ietf.org" <openpgp@ietf.org>
Date: Wed, 18 Oct 2023 10:08:55 +0200
In-Reply-To: <0a95a4f1-2708-45ac-bd43-fa885e3a5ac5@cs.tcd.ie> (Stephen Farrell's message of "Wed, 18 Oct 2023 02:05:39 +0100")
Message-ID: <87pm1cxsh4.fsf@jacob.g10code.de>
User-Agent: Gnus/5.13 (Gnus v5.13)
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=Emergency_management_Blowfish_Leuken-Baden_penrep_CCS_kilderkin_Worl"; micalg="pgp-sha256"; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/BLgKYP9CbGtMsIJRV3Ws9jh57Tw>
Subject: Re: [openpgp] additional 1 week last call on diffs from -10 to -12 of crypto-refresh
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Oct 2023 08:10:02 -0000

Hi!

It should not come to a surprise that I don't agree with that diff or
the I-D at all.  My reasons have been given multiple times and were not
addressed in a substantial way.  Neither were concerns from other
members addressed.

The new I-D has a high potential to destroy the repudiation of the
OpenPGP protocol as a reliable and secure system with an advertence on
backward compatibility and real world usage.

Over the last couple of years the GnuPG and RNP implementations of
OpenPGP have been deployed in highly critical environments and were
often preferred over CMS/X.509 when it came to the replacement of
symmetric encryption by public key encryption.  Willfully destroying
backward compatibility and adding extra complexity is not what such
deployments need.


Shalom-Salam,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein