[openpgp] adding validate-userid to the sopv subset
Daniel Kahn Gillmor <dkg@fifthhorseman.net> Wed, 30 April 2025 23:37 UTC
Return-Path: <dkg@fifthhorseman.net>
X-Original-To: openpgp@mail2.ietf.org
Delivered-To: openpgp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 315D22367D4A for <openpgp@mail2.ietf.org>; Wed, 30 Apr 2025 16:37:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.398
X-Spam-Level:
X-Spam-Status: No, score=-4.398 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=fifthhorseman.net header.b="dvq62mIO"; dkim=pass (2048-bit key) header.d=fifthhorseman.net header.b="Zius+ZTN"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6eG7herka51B for <openpgp@mail2.ietf.org>; Wed, 30 Apr 2025 16:37:58 -0700 (PDT)
Received: from che.mayfirst.org (che.mayfirst.org [162.247.75.118]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BCA5A2367D33 for <openpgp@ietf.org>; Wed, 30 Apr 2025 16:37:58 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019; t=1746056278; h=from : to : subject : date : message-id : mime-version : content-type : from; bh=OxuOD7ukuYAXwclRFJi9KAzhvxaZeeuTv2sXFldX/KY=; b=dvq62mIOggUMQ/wnkD6DAtXVsKB7KU+KB8eBJc7nyiBzl0tkC1gNCub4IT8+WEdgqJrCY hdYDYu46G5LbbBYBA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019rsa; t=1746056278; h=from : to : subject : date : message-id : mime-version : content-type : from; bh=OxuOD7ukuYAXwclRFJi9KAzhvxaZeeuTv2sXFldX/KY=; b=Zius+ZTN8E18YV3K8ydouOO66qKpukCmlpCLohX8QXIChiPExvwfPUsktEXQs6skQ4Nuu eOIOEbPR41Dck/IWKz77MfJQH1AvtM/bUcstBn+7947bVrGCbr+pBnZcyLVR+n/0ZUv5mpf yM6wiD/p/iFIrzzexscZk3Xf176g9rAaDQ07KYF43in97ZzY6Z76Zbi/rIZcCnB00lf0Mz5 DjG0LOKjWaxFOlksSdkYKSrj2fCug/YCKYeC/iAVtP7bY81YpH0Q+ZgmeZ4TWsGlmdk6WAh OR+sRhRDCnXCuzLh+VqRhBmxNUNa6QjeGUprv+dzFwzb3pqrrY5Yw3Ct24dg==
Received: from fifthhorseman.net (AMERICAN-CI.ear2.NewYork6.Level3.net [4.59.214.2]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1)) (No client certificate requested) by che.mayfirst.org (Postfix) with ESMTPSA id 48ABAF9B1 for <openpgp@ietf.org>; Wed, 30 Apr 2025 19:37:58 -0400 (EDT)
Received: by fifthhorseman.net (Postfix, from userid 1000) id DCDDF13F6AA; Wed, 30 Apr 2025 19:37:55 -0400 (EDT)
From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
To: openpgp@ietf.org
Autocrypt: addr=dkg@fifthhorseman.net; prefer-encrypt=mutual; keydata= xjMEZXEJyxYJKwYBBAHaRw8BAQdA5BpbW0bpl5qCng/RiqwhQINrplDMSS5JsO/YO+5Zi7HNFzxk a2dAZmlmdGhob3JzZW1hbi5uZXQ+wsARBBMWCgB5AwsJB0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmcS78JIJ7JbALqPiKEmva7/Pp16WwXWm9hbe5+B/UvnfwMVCggCmwEC HgEWIQTUdwQMcMIValwphUm7fpEBSV5r9wUCZadfkAUJBdnwRQAKCRC7fpEBSV5r9yNXAP442N0c zvisBroQSKKpo+OWm2JpnEJWoVheeJvoRtkBGQEA+edHylby8IGcNccq7rmM2rAXdofvrU1o6qow V+mmDwbOMwRnio4OFgkrBgEEAdpHDwEBB0Cw9HzJFl9lZn3UBaUqSMSgxjcdbd0MwNVcGZ8t8wdN EcLAvwQYFgoBMQWCZ4qODgkQu36RAUlea/dHFAAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9p YS1wZ3Aub3JnhcN+tn41cAg01Kk56zcAfpdsh8j98PDe00mqKPfFvaYCmwK+oAQZFgoAbwWCZ4qO DgkQeAuFTtnCtJZHFAAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnxsD8Sk5P Wgx8c/Zseo6OlCjyDC+Ogm17gTaUUIpxjWYWIQRjrBGOWy5dZsiKhad4C4VO2cK0lgAAdcQA/1RG dmrmvVxkBY2qNPjtERNwPga8Pf4IdlenrZ03NXM4AQC+TDHMpD7d5obEvUy8GYI3oThzYItPP8vv ChY+wbaIBRYhBNR3BAxwwhVqXCmFSbt+kQFJXmv3AAAKbgD+K1MZXnRKPdmA8DgNysyGRZY8cSVH HQcC7ZAAtV3i2+wA/0CyOYrbFYbyTRALgoERR07OHFoP+fJopQLMNQARVUELzjgEZ4qN+RIKKwYB BAGXVQEFAQEHQDTGlR+Qmn334e+bPqvojJVdFsiBf0leAAHP+ESqop8NAwEIB8LAAAQYFgoAcgWC Z4qN+QkQu36RAUlea/dHFAAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnA5Lw b3wOOcoodImuVNw4PYq1U65FDC1Q2JMFIcJXqF0CmwwWIQTUdwQMcMIValwphUm7fpEBSV5r9wAA 6egA/j3QANSmogZ5VTF5KlI+BBye9ud/w9j7RLcCHU6u8AA1AQC3FGaNuv+uWOSa+eeEoI/aZrGd X5el8b/m6aXDDxDjDg==
Date: Wed, 30 Apr 2025 19:37:55 -0400
Message-ID: <87ldrhgqzw.fsf@fifthhorseman.net>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: 7ZQQRRI7ME55O4PAOZ4ULZY2L3Y32W3J
X-Message-ID-Hash: 7ZQQRRI7ME55O4PAOZ4ULZY2L3Y32W3J
X-MailFrom: dkg@fifthhorseman.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] adding validate-userid to the sopv subset
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/SMbj2rVB0qYcFZwgBK9aXROy508>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
Hey OpenPGP folks-- I'm looking at adding sop's "validate-userid" subcommand (which does simple one-hop User ID validation from a set of fully trusted authorities) to the next revision of the sopv verification-only subset. My reasoning for this is that the functionality from an OpenPGP perspective is very similar -- it's just a different type of OpenPGP signature being checked. And, it would make it possible to use a sopv implementation to implement identity-checked signature verification. I'm collecting feedback on this proposal at: https://gitlab.com/dkg/openpgp-stateless-cli/-/merge_requests/47 There is also a separate request to make "validate-userid" fancier than a simple one-hop validator (See https://gitlab.com/dkg/openpgp-stateless-cli/-/issues/121) but for sopv 1.2 i'm inclined to just keep it at a one-hop mechanism for the moment. I'd love to hear feedback, either on-list or in the issue tracker. --dkg
- [openpgp] adding validate-userid to the sopv subs… Daniel Kahn Gillmor
- [openpgp] Re: adding validate-userid to the sopv … Michael Richardson
- [openpgp] Re: adding validate-userid to the sopv … Daniel Kahn Gillmor
- [openpgp] Re: adding validate-userid to the sopv … Daniel Kahn Gillmor