Re: [openpgp] [Gpg4win-users-en] WKD for OpenPGP certificate "Intevation File Distribution Key <distribution-key@intevation.de>"

Bernhard Reiter <bernhard@intevation.de> Thu, 08 August 2019 10:04 UTC

Return-Path: <bernhard@intevation.de>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD0E61202BA for <openpgp@ietfa.amsl.com>; Thu, 8 Aug 2019 03:04:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.897
X-Spam-Level:
X-Spam-Status: No, score=-1.897 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DNvKjita7XaL for <openpgp@ietfa.amsl.com>; Thu, 8 Aug 2019 03:04:11 -0700 (PDT)
Received: from kolab.intevation.de (kolab.intevation.de [212.95.107.133]) by ietfa.amsl.com (Postfix) with ESMTP id 9553612012B for <openpgp@ietf.org>; Thu, 8 Aug 2019 03:04:11 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by kolab.intevation.de (Postfix) with ESMTP id 464A2621F0 for <openpgp@ietf.org>; Thu, 8 Aug 2019 12:04:10 +0200 (CEST)
X-Virus-Scanned: by amavisd-new at intevation.de
Received: from kolab.intevation.de ([127.0.0.1]) by localhost (kolab.intevation.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dK2KNfxCDcE9 for <openpgp@ietf.org>; Thu, 8 Aug 2019 12:04:09 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1]) by kolab.intevation.de (Postfix) with ESMTP id 809E9627AD for <openpgp@ietf.org>; Thu, 8 Aug 2019 12:04:09 +0200 (CEST)
Received: from ploto.hq.intevation.de (ploto.hq.intevation.de [192.168.11.18]) (Authenticated sender: bernhard.reiter@intevation.de) by kolab.intevation.de (Postfix) with ESMTPSA id 5F85F621F0; Thu, 8 Aug 2019 12:04:09 +0200 (CEST)
From: Bernhard Reiter <bernhard@intevation.de>
To: gpg4win-users-en@wald.intevation.org
Date: Thu, 08 Aug 2019 12:04:08 +0200
User-Agent: KMail/1.9.10 (enterprise35 0.20141209.518c4af)
Cc: Thomas Arendsen Hein <thomas@intevation.de>, Daniel Kahn Gillmor <dkg@fifthhorseman.net>, openpgp@ietf.org
References: <20190807152824.494103316.thomas@intevation.de>
In-Reply-To: <20190807152824.494103316.thomas@intevation.de>
X-KMail-QuotePrefix: >
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="nextPart2601583.aPrAMXyRQg"; protocol="application/pgp-signature"; micalg="pgp-sha1"
Content-Transfer-Encoding: 7bit
Message-Id: <201908081204.08647.bernhard@intevation.de>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/Sk17iTOryDmvWfXXAdRrFvv3lho>
Subject: Re: [openpgp] [Gpg4win-users-en] WKD for OpenPGP certificate "Intevation File Distribution Key <distribution-key@intevation.de>"
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 08 Aug 2019 10:04:26 -0000

Am Mittwoch 07 August 2019 15:49:36 schrieb Thomas Arendsen Hein:
> OpenPGP keys are needed when you want to encrypt to someone
> _or_ when you want to verify a signature made by someone else.
>
> WKD should support these two basic use cases.

The short answer is: Only publishing one active pubkey does this already,
when you receive or send an email.

As for old email's signatures, one good solution is that you will have the 
pubkey already in your database with a record when you have gotten it and 
from where. Otherwise you get in from a keyserver and check other data, like
third party signature with the special case of a signatures by the new key.
There are more possibilities as well.

However this is a brief and simplified answer, because I think we should put 
the discussion where most of it was done which is gnupg-devel and not on a 
list for users.

Regards,
Bernhard




-- 
www.intevation.de/~bernhard   +49 541 33 508 3-3
Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner