Re: [openpgp] Transporting certificates in messages [was: Re: Transport public keys inside the message body]
Andrew Gallagher <andrewg@andrewg.com> Mon, 19 February 2024 16:35 UTC
Return-Path: <andrewg@andrewg.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B7CF9C14F71F for <openpgp@ietfa.amsl.com>; Mon, 19 Feb 2024 08:35:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewg.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KllsolKJHNMo for <openpgp@ietfa.amsl.com>; Mon, 19 Feb 2024 08:35:34 -0800 (PST)
Received: from fum.andrewg.com (fum.andrewg.com [IPv6:2a01:4f9:c011:23ad::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5347CC14F726 for <openpgp@ietf.org>; Mon, 19 Feb 2024 08:35:33 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=andrewg.com; s=andrewg-com; t=1708360531; bh=9TNKlga6QO3WUgWBDH/NSqvZMLiBjnrI75d5rysYB9I=; h=Subject:From:In-Reply-To:Date:Cc:References:To:From; b=Mnf0CDsA/ZHbNkr2JW1XnEwCGj7qVkonahJOFruzI1gmCiEwAjHUIjUjfSRmY/CzJ khsm6UWwY5/Fgwf7mmIy+az/Jpl6QeFT33cXcIGIFXE/E9ShrXrubp8/rHvjy8cRnC mVVKHzM9mqqnVs5c8mLBrRjTYCHnnwjFlW1SDUoZneRYcER5T6W07BmhMOVcfPnDqF 3BBWW7L2s7vNS/N8t3pqPhD7ZQENFHjkhWaiZ7baqtd1DXTQekMeMNLp5JYVwmUyZx rSoda+hQ9Vzk4GsUiG1S9Ouuqwq9gwEpKEHqyAerKUuznJwLeIZCKaFn/hYhrkge7Y gFgTy2IIkiSGw==
Received: from smtpclient.apple (serenity [IPv6:fc93:5820:7349:eda2:99a7::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by fum.andrewg.com (Postfix) with ESMTPSA id 385495DE73; Mon, 19 Feb 2024 16:35:31 +0000 (UTC)
Content-Type: multipart/signed; boundary="Apple-Mail=_2A5FFD7E-2BCA-4A65-BF71-33555877CC0E"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.1\))
From: Andrew Gallagher <andrewg@andrewg.com>
In-Reply-To: <87jzn01lwc.fsf@fifthhorseman.net>
Date: Mon, 19 Feb 2024 16:35:14 +0000
Cc: openpgp@ietf.org
Message-Id: <901242E7-A574-4F92-8B15-466400AFF3AF@andrewg.com>
References: <33b847dd-2dfc-4741-a415-d4636642fef1@kuix.de> <87jzn52s5z.fsf@fifthhorseman.net> <f4db1928-4036-4b98-83b6-ca8af429a85e@kuix.de> <FD720EA6-B932-43F1-8ADD-FF7DC4EF1313@andrewg.com> <8BE5C271-1014-418C-9E39-EA7E6A321F7A@andrewg.com> <pg0s0blGEl1EsRSx0nWrflFqtqV7UCOApjWD1pZytzlgmfjyLDxp3He_FOtWIYNZHIJ627oNhqmvI_Lj7Mk9HyI51h2kSp-E8VAZ4C-vmg8=@pm.me> <C50634A0-142F-4168-AB5B-6DDE1ED3B4B8@andrewg.com> <87jzn01lwc.fsf@fifthhorseman.net>
To: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
X-Mailer: Apple Mail (2.3731.700.6.1.1)
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/KSJI3P_ukMFUnUqddZKKFxykZu8>
Subject: Re: [openpgp] Transporting certificates in messages [was: Re: Transport public keys inside the message body]
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Feb 2024 16:35:38 -0000
On 19 Feb 2024, at 16:03, Daniel Kahn Gillmor <dkg@fifthhorseman.net> wrote:
>
> In draft-ietf-lamps-header-protection, the recommended scheme ("Injected
> Headers") includes many headers on internal MIME parts that do not begin
> with Content-* and the extensive testing that was done for that draft
> revealed no clear problems doing so.
Good to know! In that case, the header doesn’t need to be `Content-*`.
> I'll also note that if the signature itself is part of the headers of a
> MIME part (as opposed to of the message itself), that makes the
> header-protection work more challenging; the signature cannot sign all
> the headers if the signature itself is a header. so there's a bit of
> fancy footwork that needs to be done to be able to calculate the
> underlying stream to be signed, which should really include all the
> Injected Headers.
>
> This becomes significantly simpler if the signature in a signed-only
> message is just transported as a header field on the message itself, as
> opposed to on a MIME part.
One thing that did occur to me over the weekend was that many OpenPGP plugins (mailvelope, GnuPGTools, etc.) rely on the MUA to expose an API, rather than manipulating the message directly, and that most such APIs restrict access to rfc822 headers and MIME structure. Any proposed replacement should of course take that into account, and may limit what is practical. See for example the “Content-Disposition: attachment; filename=signature.asc” header that Apple Mail will add to the signature MIME part on this message, which is not required by RFC3156, and does nothing to discourage receiving MUAs from incorrectly treating the signature as an attached data file.
A
- [openpgp] Transport public keys inside the messag… Kai Engert
- Re: [openpgp] Transport public keys inside the me… Simon Josefsson
- Re: [openpgp] Transport public keys inside the me… Kai Engert
- Re: [openpgp] Transport public keys inside the me… Simon Josefsson
- Re: [openpgp] Transport public keys inside the me… Bart Butler
- Re: [openpgp] Transport public keys inside the me… Wyllys Ingersoll
- Re: [openpgp] Transport public keys inside the me… Steffen Nurpmeso
- Re: [openpgp] Transport public keys inside the me… Werner Koch
- Re: [openpgp] Transport public keys inside the me… Bart Butler
- Re: [openpgp] Transport public keys inside the me… Kai Engert
- Re: [openpgp] Transport public keys inside the me… Bart Butler
- Re: [openpgp] Transport public keys inside the me… Kai Engert
- Re: [openpgp] Transport public keys inside the me… Bart Butler
- Re: [openpgp] Transport public keys inside the me… Andrew Gallagher
- Re: [openpgp] Transport public keys inside the me… Kai Engert
- Re: [openpgp] Transport public keys inside the me… Daniel Kahn Gillmor
- Re: [openpgp] Transport public keys inside the me… Simon Josefsson
- Re: [openpgp] Transport public keys inside the me… Daniel Kahn Gillmor
- [openpgp] Transporting certificates in messages [… Daniel Kahn Gillmor
- Re: [openpgp] Transporting certificates in messag… Peter Gutmann
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Bart Butler
- Re: [openpgp] Transporting certificates in messag… Orie Steele
- Re: [openpgp] Transporting certificates in messag… Kai Engert
- Re: [openpgp] Transporting certificates in messag… Daniel Kahn Gillmor
- Re: [openpgp] Transporting certificates in messag… Kai Engert
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Kai Engert
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Bart Butler
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Bart Butler
- Re: [openpgp] Transporting certificates in messag… Daniel Kahn Gillmor
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- [openpgp] Alternate signed-only e-mail structure … Daniel Kahn Gillmor
- Re: [openpgp] Alternate signed-only e-mail struct… Stephen Farrell
- Re: [openpgp] Alternate signed-only e-mail struct… andrewg
- Re: [openpgp] Alternate signed-only e-mail struct… Daniel Huigens
- Re: [openpgp] Alternate signed-only e-mail struct… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Johannes Roth
- Re: [openpgp] Transporting certificates in messag… Daniel Kahn Gillmor
- Re: [openpgp] Transporting certificates in messag… Michael Richardson
- Re: [openpgp] Transporting certificates in messag… Daniel Huigens
- Re: [openpgp] Transporting certificates in messag… Steffen Nurpmeso
- Re: [openpgp] Transporting certificates in messag… Steffen Nurpmeso
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher
- Re: [openpgp] Transporting certificates in messag… Andrew Gallagher