[openpgp] Re: Using DNS Handles with OpenPGP
Andrew Gallagher <andrewg@andrewg.com> Wed, 12 February 2025 11:53 UTC
Return-Path: <andrewg@andrewg.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B6CD0C14F6E4 for <openpgp@ietfa.amsl.com>; Wed, 12 Feb 2025 03:53:04 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.107
X-Spam-Level:
X-Spam-Status: No, score=-2.107 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=andrewg.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a0jXiACHhHHy for <openpgp@ietfa.amsl.com>; Wed, 12 Feb 2025 03:52:59 -0800 (PST)
Received: from fum.andrewg.com (fum.andrewg.com [IPv6:2a01:4f9:c011:23ad::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BED7CC14F617 for <openpgp@ietf.org>; Wed, 12 Feb 2025 03:52:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=andrewg.com; s=andrewg-com; t=1739361174; bh=O4eQeJVFhoKd7vet78bl/1rXS5PfAUOswlyF1XJs/wE=; h=From:Subject:Date:In-Reply-To:Cc:To:References:From; b=YUqa60ucZL0FGgoUTmrPoLaHlQ1RmVpVmb2Wx7Bip5kr4lIxg6ABj3Y187uaPIAi7 Kuw6McPdbCwxm7hZFgRHKagxvMwahbjMmieWQT41W8WHc5ihCmLezKd3Qma2UmU2Sj WegtmCOBsMSB6wHJnFU0kp/aUWv/R5aw46He9Wmj9dzohvG9i0ysZF2XZkzeFvIkFj r5DPyFTmtIMnJIOZR+c6u2vrusSMVbVLboq9iXDVniEF4103rZ/05u4dinwYQ+i464 dGW2uWqMsFKvpTuaoMW+cmjz17skkqtGfgXfBv+jXxmc5hwZYXnXNIy+2d7/qT8BA8 k1sl/Gb7c/IlA==
Received: from smtpclient.apple (serenity [IPv6:fc93:5820:7349:eda2:99a7::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by fum.andrewg.com (Postfix) with ESMTPSA id B508B5DE48; Wed, 12 Feb 2025 11:52:54 +0000 (UTC)
From: Andrew Gallagher <andrewg@andrewg.com>
Message-Id: <758335F4-6A25-445C-8836-69FAA17E4A44@andrewg.com>
Content-Type: multipart/signed; boundary="Apple-Mail=_7996ACA5-14D6-4E79-A96A-35EA9EB953B2"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.9\))
Date: Wed, 12 Feb 2025 11:52:39 +0000
In-Reply-To: <CAMm+LwgxtvAhqqjCayqEzUcQcezJDLBTLW=Fza149vYGK=gheQ@mail.gmail.com>
To: Phillip Hallam-Baker <phill@hallambaker.com>
References: <CAMm+LwgxtvAhqqjCayqEzUcQcezJDLBTLW=Fza149vYGK=gheQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3731.700.6.1.9)
Message-ID-Hash: W7DGND2HSJRYNUVOWORB5OMQLJJLP4IO
X-Message-ID-Hash: W7DGND2HSJRYNUVOWORB5OMQLJJLP4IO
X-MailFrom: andrewg@andrewg.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF OpenPGP <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: Using DNS Handles with OpenPGP
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/RkxHnJ3MNUmJWC24clmHWzxyE0Y>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hi, Phillip. On 7 Feb 2025, at 21:29, Phillip Hallam-Baker <phill@hallambaker.com> wrote: > > So putting OpenPGP keys into the DNS directly seems like a bad idea. Better to use signed contacts and put the root of trust for the contact manager into the DNS: > > _mesh.phill.hallambaker.com <http://mesh.phill.hallambaker.com/>. IN TXT "dsa=mbqn-a3es-zbye-xp3o-w6et-pqug-go5v@@example.com <http://example.com/>" > > So what this does is bind my DNS handle to my Mesh direct service address which is a root-o-trust/service address pair. And then people can do a fetch to get my public contact assertion signed under that root o' trust and verify it. If my zone is DNSSEC signed, we have a fairly solid trust path for establishing TOFU. > > And that contact assertion would hold my SSH credentials OpenPGP credentials, etc. etc. Right now I am just transferring the IANA protocol names into my JSON serialization. This proposal sounds to me like it can already be done by combining WKD and Keyoxide [1] - WKD binds the key to the domain, and Keyoxide binds the various other identities to the key. Or am I missing an extra subtlety? A [1] www.keyoxide.org
- [openpgp] Using DNS Handles with OpenPGP Phillip Hallam-Baker
- [openpgp] Re: Using DNS Handles with OpenPGP Andrew Gallagher
- [openpgp] Re: Using DNS Handles with OpenPGP Phillip Hallam-Baker