[openpgp] Re: Encryption subkey selection
Daniel Huigens <d.huigens@protonmail.com> Tue, 06 May 2025 08:06 UTC
Return-Path: <d.huigens@protonmail.com>
X-Original-To: openpgp@mail2.ietf.org
Delivered-To: openpgp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id C026E253B3FB for <openpgp@mail2.ietf.org>; Tue, 6 May 2025 01:06:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.095
X-Spam-Level:
X-Spam-Status: No, score=-2.095 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=protonmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zv0R94h09Y2o for <openpgp@mail2.ietf.org>; Tue, 6 May 2025 01:06:36 -0700 (PDT)
Received: from mail-10629.protonmail.ch (mail-10629.protonmail.ch [79.135.106.29]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id C81DC253B38F for <openpgp@ietf.org>; Tue, 6 May 2025 01:06:36 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1746518795; x=1746777995; bh=GEGQMbAu5felf92zSjRYpXdDEe36IpTD+B5ZdgoAmms=; h=Date:To:From:Cc:Subject:Message-ID:In-Reply-To:References: Feedback-ID:From:To:Cc:Date:Subject:Reply-To:Feedback-ID: Message-ID:BIMI-Selector:List-Unsubscribe:List-Unsubscribe-Post; b=rW11ylrMDECHI9IYC5b8feSa4WQ+XrntNJo7pSBWUkLQeIjY1oDj/62teAqEi3n8R XIgmnXarf3vWsenlCGkft28PnNmIy8FoOvztfIcEO/7MCg8prA2RInHrx/PDBAJILY 3tvjbMtaz5tvqqgqEO3FsC0awmC+IPF7i/nhO/PzmfR3fzK6tVfQUV+LLmVPhU2ufF +s9SfQd//d7rl6Wi16bN/puDkZc6om3HgCx+OAxbdK12SJPxTiJ+KjAdrVQ7Ak82VG XRIwJAV22hB14JiOPOpyyUkmz+MtFE2y3Xl7BTS0T30pAXeUYA69FeycSeaLdtPFAt Je1g1axx+qjfQ==
Date: Tue, 06 May 2025 08:06:30 +0000
To: Falko Strenzke <falko.strenzke@mtg.de>
From: Daniel Huigens <d.huigens@protonmail.com>
Message-ID: <Ef6BOqB4sJojhX8zVFA6lCxASrnsV1rG_bF85V4_YHy1SutHgh3BW5f2hTNppvMcUOpmjtcMCiEYVVkAxcMLDMYAiUm2v-MN6qHRvqYYS-M=@protonmail.com>
In-Reply-To: <0d7e2367-c6fa-483b-af3b-59cdb0a98c1f@mtg.de>
References: <87h631mvol.fsf@thinbox> <dI4YtuyWCyCqKizRafc2sNHBFSRSuQEt-03l8CBI-bRD4SPN7701nRDLFYtu0hwve96cG3Q4kIglx6oVTIAiJbVJseQRzLrt2AoKpSLes28=@protonmail.com> <87ecxupx9w.fsf@europ.lan> <ToH9iWOoC_CgdIu1k9gaMAaNzpZ5nwHbPScoiuJr_RIQpz6Wv1Z7qY9iaKepYMwLlynVkNytyotr-FWEFRBA5saNHy7N_1dmbcMC310quFM=@protonmail.com> <878qnahdhv.fsf@fifthhorseman.net> <0d7e2367-c6fa-483b-af3b-59cdb0a98c1f@mtg.de>
Feedback-ID: 2934448:user:proton
X-Pm-Message-ID: eaad67c5d05d628422cccc7fe8773136e5d33017
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="b1=_DAS69VgSeD3UTXg0PkvWOOfeygA5edOBDA7l0hoI"
Message-ID-Hash: LPIXZDJL6TGL25J2EQTBFLVGHWXKN5IP
X-Message-ID-Hash: LPIXZDJL6TGL25J2EQTBFLVGHWXKN5IP
X-MailFrom: d.huigens@protonmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Daniel Kahn Gillmor <dkg@fifthhorseman.net>, openpgp@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: Encryption subkey selection
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/MhYX0rB3OK46u8XHQPCMOuhbLHU>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi Falko, On Tuesday, May 6th, 2025 at 08:22, Falko Strenzke wrote: >> > > Preferring the higher algorithm ID doesn't work for a simple reason: there are different security levels for each algorithm stacked one after another as code points (2 for ML-KEM currently). This means that the suggested selection mechanism might result in the preference of strictly weaker keys. Saying that the proposal "doesn't work" is a very strong statement but what I think you mean is: it might lead to suboptimal outcomes in certain cases, namely if someone has a certificate with two encryption subkeys, one of which is 1. weaker and 2a. has a later creation timestamp or 2b. an equal creation timestamp and a higher algorithm ID. My question would be: why would the certificate holder want to create such a certificate? Do such certificates already exist in the wild? If we all agree on this encryption subkey selection algorithm, we can just agree to not do that, and give the stronger subkey a higher creation timestamp. Or, for future algorithms we can tweak the algorithm, if needed. I would also like to note that we don't achieve optimal outcomes in all cases in the current implementations. For example, two out of three implementations don't achieve post-quantum security for the PQC test vectors with multiple subkeys, as noted in the parallel thread. With this proposal, that would be fixed. So, I think it's strictly an improvement over the status quo :) Best, Daniel
- [openpgp] Encryption subkey selection Justus Winter
- [openpgp] Re: Encryption subkey selection Andrew Gallagher
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Bart Butler
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Andrew Gallagher
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Daniel Huigens
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Daniel Huigens
- [openpgp] Re: Encryption subkey selection Andrew Gallagher
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Andrew Gallagher
- [openpgp] Re: Encryption subkey selection Justus Winter
- [openpgp] Re: Encryption subkey selection Daniel Huigens
- [openpgp] Re: Encryption subkey selection Daniel Kahn Gillmor
- [openpgp] Re: Encryption subkey selection Falko Strenzke
- [openpgp] Re: Encryption subkey selection Daniel Huigens
- [openpgp] Re: Encryption subkey selection Daniel Huigens
- [openpgp] Re: Encryption subkey selection Johannes Roth
- [openpgp] Re: Encryption subkey selection Daniel Huigens