Re: V3 secret keys

Ben Laurie <ben@algroup.co.uk> Tue, 07 February 2006 11:51 UTC

Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1F6RNx-00053t-D2 for openpgp-archive@megatron.ietf.org; Tue, 07 Feb 2006 06:51:53 -0500
Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id GAA16787 for <openpgp-archive@lists.ietf.org>; Tue, 7 Feb 2006 06:50:07 -0500 (EST)
Received: from above.proper.com (localhost.vpnc.org [127.0.0.1]) by above.proper.com (8.12.11/8.12.9) with ESMTP id k17BYCMk025490; Tue, 7 Feb 2006 03:34:12 -0800 (PST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by above.proper.com (8.12.11/8.12.9/Submit) id k17BYCMm025489; Tue, 7 Feb 2006 03:34:12 -0800 (PST)
X-Authentication-Warning: above.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mail.links.org (mail.links.org [217.155.92.109]) by above.proper.com (8.12.11/8.12.9) with ESMTP id k17BYBLQ025483 for <ietf-openpgp@imc.org>; Tue, 7 Feb 2006 03:34:12 -0800 (PST) (envelope-from ben@algroup.co.uk)
Received: from [193.133.15.218] (localhost [127.0.0.1]) by mail.links.org (Postfix) with ESMTP id 8E4A133C3F; Tue, 7 Feb 2006 11:34:10 +0000 (GMT)
Message-ID: <43E8853A.2060400@algroup.co.uk>
Date: Tue, 07 Feb 2006 11:32:10 +0000
From: Ben Laurie <ben@algroup.co.uk>
User-Agent: Thunderbird 1.5 (Windows/20051201)
MIME-Version: 1.0
To: Hal Finney <hal@finney.org>
CC: nagydani@epointsystem.org, vedaal@hush.com, ietf-openpgp@imc.org
Subject: Re: V3 secret keys
References: <20060207020728.EF80857FAE@finney.org>
In-Reply-To: <20060207020728.EF80857FAE@finney.org>
X-Enigmail-Version: 0.93.0.0
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 7bit

Hal Finney wrote:
> Daniel Nagy writes:
>> I sincerely hope that this whole mess will be cleaned up with V5, where
>> there seems to be a consensus not to implement encrypted private key packets
>> at all, but put unencrypted private key packets into integrity protected
>> symmetrically encrypted packets instead.
> 
> I haven't participated in the recent discussion, partly because I think
> it is a little premature until we get the current spec put to bed.
> 
> I am not sure I like this idea.  We'll need to retain the old mechanism
> for many years at least, requiring us to support yet another set of
> incompatible mechanisms.  And I don't know if the new proposal really
> simplifies things much.

Surely you should already support this method?

> Complications have been pointed out regarding sending multiple keys
> encrypted with different passphrases, requiring us to explicitly support
> multiply-concatenated symmetric-encryption & SKESK packets, which is
> not necessary at present.

It isn't?

> It might require us to bite the bullet and
> clarify exactly what sequences of packets are legal, with possible
> backwards-compatibility problems.

Hmm. My implementation will eat _any_ sequence of packets.

-- 
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff