Replacement Key

David Shaw <dshaw@akamai.com> Tue, 28 August 2001 15:47 UTC

Received: from above.proper.com (above.proper.com [208.184.76.39]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA13487 for <openpgp-archive@odin.ietf.org>; Tue, 28 Aug 2001 11:47:18 -0400 (EDT)
Received: from localhost (localhost [[UNIX: localhost]]) by above.proper.com (8.11.6/8.11.3) id f7SFRTv26800 for ietf-openpgp-bks; Tue, 28 Aug 2001 08:27:29 -0700 (PDT)
Received: from claude.kendall.akamai.com (walrus.ne.mediaone.net [65.96.217.45]) by above.proper.com (8.11.6/8.11.3) with ESMTP id f7SFRSD26796 for <ietf-openpgp@imc.org>; Tue, 28 Aug 2001 08:27:28 -0700 (PDT)
Received: (from dshaw@localhost) by claude.kendall.akamai.com (8.9.3/8.9.3) id LAA11165 for ietf-openpgp@imc.org; Tue, 28 Aug 2001 11:27:18 -0400
Date: Tue, 28 Aug 2001 11:27:18 -0400
From: David Shaw <dshaw@akamai.com>
To: ietf-openpgp@imc.org
Subject: Replacement Key
Message-ID: <20010828112718.A11092@akamai.com>
Mail-Followup-To: ietf-openpgp@imc.org
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
X-PGP-Key: 2048R/3CB3B415/4D 96 83 18 2B AF BE 45 D0 07 C4 07 51 37 B3 18
X-URL: http://www.jabberwocky.com/
X-Phase-Of-Moon: The Moon is Waxing Gibbous (77% of Full)
X-Pointless-Random-Number: 123
X-Silly-Header: It sure is.
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

I welcome any comment on the replacement key draft that just got
posted.  

The point, in case you haven't seen the draft yet, is a way for a user
to specify the key that replaces a revoked or expired key.  General
purpose implementations can use this information to use the new key
(presumably with a warning) if a user requests the old one.  It would
also be useful to automatically fetch the new key from keyservers.

Keyservers could use this to present the proper key (again, with a
warning) if an expired/revoked key is requested.

In particular I'd like to hear opinions on the variable sized
subpacket.  There are other variable sized subpackets in OpenPGP, but
I wonder if this one might not save us much.

David

-- 
David Shaw          |  Technical Lead
<dshaw@akamai.com>  |  Enterprise Content Delivery
617-250-3028        |  Akamai Technologies