Re: How to update a self-signature?

Werner Koch <wk@gnupg.org> Mon, 27 August 2001 19:02 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA27292 for <openpgp-archive@odin.ietf.org>; Mon, 27 Aug 2001 15:02:34 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]]) by above.proper.com (8.11.6/8.11.3) id f7RIjF524155 for ietf-openpgp-bks; Mon, 27 Aug 2001 11:45:15 -0700 (PDT)
Received: from kasiski.gnupg.de (porta.u64.de [194.77.88.106]) by above.proper.com (8.11.6/8.11.3) with ESMTP id f7RIjCD24151 for <ietf-openpgp@imc.org>; Mon, 27 Aug 2001 11:45:12 -0700 (PDT)
Received: from uucp by kasiski.gnupg.de with local-rmail (Exim 3.22 #1 (Debian)) id 15bSGg-0000Tn-00; Mon, 27 Aug 2001 21:41:54 +0200
Received: from wk by alberti.gnupg.de with local (Exim 3.22 #1 (Debian)) id 15bRR3-0000ad-00; Mon, 27 Aug 2001 20:48:33 +0200
To: ietf-openpgp@imc.org
Subject: Re: How to update a self-signature?
References: <p05100303b7aaf65aff68@[192.168.1.180]> <008601c12c52$1b6181c0$c23fa8c0@transarc.ibm.com> <p0510031fb7ab945664e5@[192.168.1.180]> <002b01c12d74$b105fb20$c23fa8c0@transarc.ibm.com> <20010827094849.A26895@akamai.com> <87y9o5imcn.fsf@alberti.gnupg.de> <20010827123540.A834@akamai.com>
From: Werner Koch <wk@gnupg.org>
Organisation: g10 Code GmbH
X-PGP-KeyID: 621CC013
X-Request-PGP: finger://wk@g10code.com
Date: Mon, 27 Aug 2001 20:48:32 +0200
In-Reply-To: <20010827123540.A834@akamai.com> (David Shaw's message of "Mon, 27 Aug 2001 12:35:40 -0400")
Message-ID: <87y9o5gwzj.fsf@alberti.gnupg.de>
Lines: 27
User-Agent: Gnus/5.090004 (Oort Gnus v0.04) Emacs/20.7
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

On Mon, 27 Aug 2001 12:35:40 -0400, David Shaw said:

> to really revoke a revocation.  I assume you mean revoking a user ID
> revocation by re-signing the user ID?

Yes. I talked with Florian about this recently.

> I'm only trying to make a case for what happens if after everything is
> worked out and the implementation ends up with more than one valid

There shouldn't be any date conflicts with self-signatures - but it
may happen.  The way to handle it for a general purpose implemention is
to ignore all signatures during key import which are older than
existing one. That you ignore all self-signatures which are invalid
should be clear.

So I do not see a problem before the year 2106 and most of us won't see
it ever.

Ciao,

   Werner

-- 
Werner Koch        Omnis enim res, quae dando non deficit, dum habetur
g10 Code GmbH      et non datur, nondum habetur, quomodo habenda est.
Privacy Solutions                                        -- Augustinus