[openpgp] Key and Certificate Management in SOP

Daniel Kahn Gillmor <dkg@fifthhorseman.net> Thu, 05 September 2024 23:55 UTC

Return-Path: <dkg@fifthhorseman.net>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4BF2EC1CAF43 for <openpgp@ietfa.amsl.com>; Thu, 5 Sep 2024 16:55:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=fifthhorseman.net header.b="Nx7mn7r6"; dkim=pass (2048-bit key) header.d=fifthhorseman.net header.b="UD8YtssN"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TJLnWpPqRw9q for <openpgp@ietfa.amsl.com>; Thu, 5 Sep 2024 16:55:40 -0700 (PDT)
Received: from che.mayfirst.org (che.mayfirst.org [IPv6:2001:470:1:116::7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AF49BC19ECB6 for <openpgp@ietf.org>; Thu, 5 Sep 2024 16:55:40 -0700 (PDT)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019; t=1725580538; h=from : to : subject : date : message-id : mime-version : content-type : from; bh=OJShC/JjertA6lrA4NtPK7VzAulXNN4Z2BsAIYHqaus=; b=Nx7mn7r6kElUAvrzJru2HlAsBhJUYvbj3J1WWkOK69A3Q6f9D2LSxnw+6BzzkXnje+xkF mF9EXx5ZmVusz9WBQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=fifthhorseman.net; i=@fifthhorseman.net; q=dns/txt; s=2019rsa; t=1725580538; h=from : to : subject : date : message-id : mime-version : content-type : from; bh=OJShC/JjertA6lrA4NtPK7VzAulXNN4Z2BsAIYHqaus=; b=UD8YtssNO//Q3J7v06ZfLDYwLmM3ZyHOczQ9hafwbEQ7+5/Z+bdIWDvtAxYJahuJ4c4Uy XJsyNYjivtoH0XHWq+8RMtSgLh6KEDVzgmzK6+i5u4VOUoNXtVl1TMw5/UjWucVRPp0JS2H xhdFNnbPavRd7R/koA5aTcxS6s3HVwsOBpVtG/MwDN6xMXN9zh6JYC9sqHAGqMRX1Nws8SP brGo7GS7of/d66HBo3p23X3uMVj3an6kew6Q+Z+a5xkAXPnO7zbaKaLmrsSaaqcnv4UDR91 7V9zEoULLi9M+Kcq96RCHoSpmIHMaFXEIm4qVlisJRJMb7xepCYRiN06lKGA==
Received: from fifthhorseman.net (lair.fifthhorseman.net [108.58.6.98]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (secp384r1) server-digest SHA384) (No client certificate requested) by che.mayfirst.org (Postfix) with ESMTPSA id 58615F9B2 for <openpgp@ietf.org>; Thu, 5 Sep 2024 19:55:38 -0400 (EDT)
Received: by fifthhorseman.net (Postfix, from userid 1000) id 292DA13F681; Thu, 05 Sep 2024 19:55:35 -0400 (EDT)
From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>
To: openpgp@ietf.org
Autocrypt: addr=dkg@fifthhorseman.net; prefer-encrypt=mutual; keydata= xjMEZXEJyxYJKwYBBAHaRw8BAQdA5BpbW0bpl5qCng/RiqwhQINrplDMSS5JsO/YO+5Zi7HCi QQfFgoAMQWCZadnIAUJBdtHCwMLCQcDFQoIApsBAh4BFiEE1HcEDHDCFWpcKYVJu36RAUlea/ cACgkQu36RAUlea/edDQD+M2QjnoEyu/TjI+gRXBpXQ5jCsnnp9FdYhaSSUW/vZ8kBAJByWlj A9aMfVaVrmvgcYw7jzJz+gmZspBRB++5LZ20NzRc8ZGtnQGZpZnRoaG9yc2VtYW4ubmV0PsLA EQQTFgoAeQMLCQdHFAAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnEu/CS CeyWwC6j4ihJr2u/z6delsF1pvYW3ufgf1L538DFQoIApsBAh4BFiEE1HcEDHDCFWpcKYVJu3 6RAUlea/cFAmWnX5AFCQXZ8EUACgkQu36RAUlea/cjVwD+ONjdHM74rAa6EEiiqaPjlptiaZx CVqFYXnib6EbZARkBAPnnR8pW8vCBnDXHKu65jNqwF3aH761NaOqqMFfppg8GzjMEZXEJyxYJ KwYBBAHaRw8BAQdAjX25Fq2Q9IUFeHy6yByIQPBnFOedFliuEiCIUzJsENDCwMUEGBYKAS1HF AAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnwqKWsw56uoWVLIFcs7ZecJ gwpsSNevWCzbviKQ8yRLUCmwK+oAQZFgoAbwWCZXEJywkQdy0WHjXNS4FHFAAAAAAAHgAgc2F sdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnEIJSOxuw2y/UJmg5M3BLpN0JYjODZpXiEVFu 1byARzMWIQR0vATEPYYIS+hnLAZ3LRYeNc1LgQAAsH8BAKg1C5LK/D7pSkXCD+jfTSP+CqM58 iHLjh4vKhpOKsTJAQCHldtEjxJ1ksPTFgG9HihHH7qc6/wvvLw77ETMpwlrAxYhBNR3BAxwwh VqXCmFSbt+kQFJXmv3BQJlp1+rBQkCF4lgAAoJELt+kQFJXmv3ydsA/2roQZ2Jm/7iUrg/2C5 ClWA/xbvPC31LyMkGGH2/rq8tAP9BgqLuCPnNTVPqeX9+9qqMmaFq7wmvjq5I+yycAw9CDc44 BGVxCcsSCisGAQQBl1UBBQEBB0BZMsRrRaaeFSYMF1ZdfRmVgBriDUIr99eDQ085BK14DgMBC AfCwAYEGBYKAG5HFAAAAAAAHgAgc2FsdEBub3RhdGlvbnMuc2VxdW9pYS1wZ3Aub3JnsazAWX tEHUPmSTmcRZAIsAsNiO8k0hdjsfRlRVipgJgCmwwWIQTUdwQMcMIValwphUm7fpEBSV5r9wU CZadfqwUJAheJYAAKCRC7fpEBSV5r90AjAPwLgY1iKiFJEj32SVD5f721929l79VxQB5FlQss x1n5kQEA6Uct2tPvbB6T7p5KG3Gl+tbi7oJAuxFmpkpW5/N2Owg=
Date: Thu, 05 Sep 2024 19:55:34 -0400
Message-ID: <87ed5xwt8p.fsf@fifthhorseman.net>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="=-=-="; micalg="pgp-sha512"; protocol="application/pgp-signature"
Message-ID-Hash: MQB24NHADZH7PZ7Y65Y7DO3T5YBTAZW5
X-Message-ID-Hash: MQB24NHADZH7PZ7Y65Y7DO3T5YBTAZW5
X-MailFrom: dkg@fifthhorseman.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [openpgp] Key and Certificate Management in SOP
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/ZSyE2trvIbrWdy3LB3TLeIL_k0s>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

Hey OpenPGP folks--

I'm preparing to add four new subcommands for OpenPGP Key and
Certificate Management to the Stateless OpenPGP API:

   sop update-keys      (keep an OpenPGP secret key "up-to-date")
   sop merge-certs      (merge OpenPGP certificates that share primary keys)

   sop certify          (certify a User ID in a cert)
   sop validate-certs   (verify a User ID-to-cert binding)

The changes are pending in git right now, on the main branch, and i
welcome feedback on them from implementers and from potential users of
the sop interface.

   https://gitlab.com/dkg/openpgp-stateless-cli

You can see the "editor's copy" here:

   https://dkg.gitlab.io/openpgp-stateless-cli/

"sop update-keys" should generally keep a secret key "alive" so that you
can use "sop extract-cert" to get a "fresh" certificate going forward.
it leaves quite a bit of leeway to implementers, which i hope will help
us surface best practices across implementations.

"sop merge-certs" should be pretty straightforward: you've got an
OpenPGP cert, which might have some updates.  You find another copy of
the same cert somewhere else, which might have different updates, and
you want the consolidation of all the updates.

And I've tried to model "sop certify" and "sop validate-certs" on "sop
sign" and "sop verify".


 ----

As usual, my goal is to present a minimally useful interface initially,
one that can be directly used and tested against in the interoperability
test suite.

I'm planning to publish a new revision of the draft within the next week
(the latest version recently expired, whoops).  If you've got feedback
on these changes (or if you want to get any other reasonable changes in
before i publish the new draft, please open gitlab issues or reply
on-list.

Happy hacking,

        --dkg