[openpgp] Re: certification with Persistent Symmetric Keys (PSKs)?

Andrew Gallagher <andrewg@andrewg.com> Tue, 15 September 2026 15:55 UTC

Received: from fum.andrewg.com (fum.andrewg.com [135.181.198.78]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature ECDSA (prime256v1) server-digest SHA256) (No client certificate requested) by mx.ietf.org (Postfix) with ESMTPS id 8508730 for <openpgp@ietf.org>; Tue, 15 Sep 2026 15:55:58 +0000 (UTC)
Authentication-Results: mx.ietf.org; dkim=pass header.d=andrewg.com header.s=andrewg-com header.b=sKRJpYX9; dmarc=pass (policy=quarantine) header.from=andrewg.com; spf=pass (mx.ietf.org: domain of andrewg@andrewg.com designates 135.181.198.78 as permitted sender) smtp.mailfrom=andrewg@andrewg.com
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=andrewg.com; s=andrewg-com; t=1789487751; bh=L3/6ZOFl4xu/bMVMTw9WkF0N/luiVzCXL109jAWaiVE=; h=From:Subject:Date:References:Cc:In-Reply-To:To:From; b=sKRJpYX90A9aaFppAT8DZShsc692oBwcc+PFgxocDzfdnv1K3GF9w/PS5Ekjhts+t aL8ynzRZ7KUh7QMnWQRhwUeWrFvb8auE6BEqTOH34iVo8RLacOMa50TtWRK4mTXQ9c Tx5w9ybU38QqJAovxZNTHLt7JcPVwj9FOw5Fs+mGo/MJbfnsENtt/RGJIatny5pRH/ TV2/Q2GLOw0F4WerwCacxt47TGVGK90o2y74AKICeKXAg3MByyPLLRkB4kI+KsR8yC 76epHaOKBk19yL0FbLrlyrgkLefEtfRxQ4lJdvj4kgg6eCOa6+QwSv25oCTU/Tki/+ y8/KktyeB7Buw==
Received: from smtpclient.apple (unknown [80.233.57.71]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by fum.andrewg.com (Postfix) with ESMTPSA id CDF745E664; Tue, 15 Sep 2026 15:55:50 +0000 (UTC)
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
From: Andrew Gallagher <andrewg@andrewg.com>
Mime-Version: 1.0 (1.0)
Date: Tue, 15 Sep 2026 17:55:39 +0200
Message-Id: <3BB5A250-E0F9-45E4-A99D-676A2355B44D@andrewg.com>
References: <Su8SvnPtFINHJwBJjbc65ELmCIEPoP9AlgeXjxQ-1LTZ4DjrTYZPT9dnQqpANvnOOBEHCY63pDoLrIMMOHSb0BpDCnqNnL5qQwMFgJbENfY=@protonmail.com>
In-Reply-To: <Su8SvnPtFINHJwBJjbc65ELmCIEPoP9AlgeXjxQ-1LTZ4DjrTYZPT9dnQqpANvnOOBEHCY63pDoLrIMMOHSb0BpDCnqNnL5qQwMFgJbENfY=@protonmail.com>
To: Daniel Huigens <d.huigens=40protonmail.com@dmarc.ietf.org>
X-Mailer: iPhone Mail (23G83)
X-Spamd-Bar: /
Message-ID-Hash: NIOYD5UBJMTDBB7XW7765D4UJQF6J2TI
X-Message-ID-Hash: NIOYD5UBJMTDBB7XW7765D4UJQF6J2TI
X-MailFrom: andrewg@andrewg.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; header-match-openpgp.ietf.org-0; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: openpgp@ietf.org
X-Mailman-Version: 3.3.10
Precedence: list
Subject: [openpgp] Re: certification with Persistent Symmetric Keys (PSKs)?
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/f999lUdeHty868T5CkZw1r2O22I>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

On 15 Sep 2026, at 15:14, Daniel Huigens <d.huigens=40protonmail.com@dmarc.ietf.org> wrote:
> 
> It would be especially nice though if there's someone else who wants to
> use persistent symmetric keys in the future who wants to weigh in on
> whether having metadata in self-signatures (and revocation signatures)
> in PSKs would be useful for them. But, maybe that's too much to ask :)

I think having an independent use case for PSKs would be generally beneficial. I don’t think it should be a blocker, but it would help us work through some of the tradeoffs. 

A