Re: Signature calculation language

Jon Callas <jon@callas.org> Tue, 18 April 2006 19:26 UTC

Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1FVvqb-0007dy-0S for openpgp-archive@lists.ietf.org; Tue, 18 Apr 2006 15:26:49 -0400
Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1FVvqY-0001pe-OP for openpgp-archive@lists.ietf.org; Tue, 18 Apr 2006 15:26:48 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id k3IIxPVU018381; Tue, 18 Apr 2006 11:59:25 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id k3IIxPpA018380; Tue, 18 Apr 2006 11:59:25 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (merrymeet.com [63.73.97.162]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id k3IIxOkt018373 for <ietf-openpgp@imc.org>; Tue, 18 Apr 2006 11:59:24 -0700 (MST) (envelope-from jon@callas.org)
Received: from keys.merrymeet.com (63.73.97.166) by merrymeet.com with ESMTP (Eudora Internet Mail Server X 3.2.7) for <ietf-openpgp@imc.org>; Tue, 18 Apr 2006 11:59:23 -0700
Received: from [192.168.2.164] ([63.251.255.85]) by keys.merrymeet.com (PGP Universal service); Tue, 18 Apr 2006 11:59:23 -0700
X-PGP-Universal: processed; by keys.merrymeet.com on Tue, 18 Apr 2006 11:59:23 -0700
Mime-Version: 1.0 (Apple Message framework v749.3)
In-Reply-To: <87psqa6ds2.fsf@wheatstone.g10code.de>
References: <20051011222500.0352B57EF9@finney.org> <20051012025034.GA5034@jabberwocky.com> <87psqa6ds2.fsf@wheatstone.g10code.de>
Content-Type: text/plain; charset="US-ASCII"; delsp="yes"; format="flowed"
Message-Id: <F3CC0ECB-CF04-4A2F-B040-1476357A2228@callas.org>
Content-Transfer-Encoding: 7bit
From: Jon Callas <jon@callas.org>
Subject: Re: Signature calculation language
Date: Tue, 18 Apr 2006 11:59:32 -0700
To: OpenPGP <ietf-openpgp@imc.org>
X-Mailer: Apple Mail (2.749.3)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22


On 12 Oct 2005, at 6:55 AM, Werner Koch wrote:

>
> On Tue, 11 Oct 2005 22:50:34 -0400, David Shaw said:
>
>> I support making 0x19 backsigs a MUST.
>
> I concur with David.  I am actually a heavy user of signing subkeys
> because they allow to keep the primary key offline.
>

Section 10.1 says:

    Each Subkey packet MUST be followed by one Signature packet, which
    should be a subkey binding signature issued by the top level key.
    For subkeys that can issue signatures, the subkey binding signature
    MUST contain an embedded signature subpacket with a primary key
    binding signature (0x19) issued by the subkey on the top level key.

And I think this does make it a MUST.

If there should be anything else (or this is wrong, unclear, etc.),  
just let me know.

	Jon