[openpgp] Re: Using DNS Handles with OpenPGP
Phillip Hallam-Baker <phill@hallambaker.com> Mon, 17 February 2025 21:20 UTC
Return-Path: <hallam@gmail.com>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D838CC1D3DE4 for <openpgp@ietfa.amsl.com>; Mon, 17 Feb 2025 13:20:19 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.651
X-Spam-Level:
X-Spam-Status: No, score=-1.651 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FORGED_FROMDOMAIN=0.001, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=0.25, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xeNBJj_JdHHx for <openpgp@ietfa.amsl.com>; Mon, 17 Feb 2025 13:20:15 -0800 (PST)
Received: from mail-qv1-f43.google.com (mail-qv1-f43.google.com [209.85.219.43]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 15E75C1D4A99 for <openpgp@ietf.org>; Mon, 17 Feb 2025 13:20:11 -0800 (PST)
Received: by mail-qv1-f43.google.com with SMTP id 6a1803df08f44-6e6827984b2so12449896d6.1 for <openpgp@ietf.org>; Mon, 17 Feb 2025 13:20:10 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1739827210; x=1740432010; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=L3QC1bHz/suedaJhTgDOjr5HDeIHpwUCl6RiD+hd7bU=; b=or0vGR7lM6NW5l3DvN8uKjMmp7f1n000OS+0LeNYx2Gy5qegNhHnVzNIgoQFQ0Gxl8 VV203b15DCE6FYb5LMJpgDg4OB6uhjVEuuVneOBUVka8DTFaMjH3LcdngbdzRVgmr7BR gnCh4aJtuCNI4TrQi92wSftMjJwlsM6H8T8lmnbZ2oTKpH2w6tsWxtVpkaf8NYDfBroV r2NQBYUcH0uA7/sFFxJVjXs0F1p4GapUXgdQ7bVFrFTq5XhjKuQtKS6S8ynQcWRGvF/R wkea1+NKyOrl1oYxmmpHDFLvbyj6kApDFrUlZ8YowMbh15byWEo/SZdxk5uVbi7/UXXO VS6w==
X-Gm-Message-State: AOJu0YxDpcXP7gSKTe0HeGIKRGvKQXO3g95acEX6Y+hIu42AI7a2FdCO u4vaDuH3LLIk0SEuvfm7XxND/+gzlNett9aIaOvpLszIjy+bbS7o5r7yedxQUOuG7kBJxyd0r5p u17yhm4axr6FryH1aFSRMq93V/ZqkWQbM
X-Gm-Gg: ASbGncu7a56M2HXa0eYYAybeH33tNP70OyXGkszaRuLA3EUxJEWjFICUKsHDNx3FJdA 2E0MJx0aj1vaFIJyPMz6MV/xg7Negkf5Jy8f9bA2Ql1miMjshHlgKYOMw/bhVxZe4fio6KNMe3Q ==
X-Google-Smtp-Source: AGHT+IEA+F+f9F4ZLODhgekmoTTQDd8dNJ6Lr1kg8mlwWfMBV4gkIZ5nsdbQh3yrTPhB+ydZRtU4IzJqAqvrusD6WNs=
X-Received: by 2002:a05:6214:20aa:b0:6e1:5076:c3ff with SMTP id 6a1803df08f44-6e66cd2420amr205500696d6.36.1739827209903; Mon, 17 Feb 2025 13:20:09 -0800 (PST)
MIME-Version: 1.0
References: <CAMm+LwgxtvAhqqjCayqEzUcQcezJDLBTLW=Fza149vYGK=gheQ@mail.gmail.com> <758335F4-6A25-445C-8836-69FAA17E4A44@andrewg.com>
In-Reply-To: <758335F4-6A25-445C-8836-69FAA17E4A44@andrewg.com>
From: Phillip Hallam-Baker <phill@hallambaker.com>
Date: Mon, 17 Feb 2025 16:19:58 -0500
X-Gm-Features: AWEUYZnbRL3TTKN0jp3ptwnUzld7ypCWTbMNCLyMP8ldsa6T-JKQKG-dVoFFujQ
Message-ID: <CAMm+LwgY621DW18qpAu=xgMfzqXfpnE3hLXZ6T8KOfAfVng67Q@mail.gmail.com>
To: Andrew Gallagher <andrewg@andrewg.com>
Content-Type: multipart/alternative; boundary="000000000000d12738062e5d16a8"
Message-ID-Hash: IZMVUWMHUFWDKMJNXZ2WR2XKZ6KTE3B3
X-Message-ID-Hash: IZMVUWMHUFWDKMJNXZ2WR2XKZ6KTE3B3
X-MailFrom: hallam@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: IETF OpenPGP <openpgp@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: Using DNS Handles with OpenPGP
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/mcJnmFhZ4DnpIrlc4YtcyZb51qA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>
I have revised my approach substantially since. The Mesh is now gone from my scheme, I am using JSContact instead. The only Mesh technology I am using now is UDF which is basically a better way to do fingerprints with Base32 that makes them suited for a bunch of purposes without conflicts. And I am only using a very small part of that. This approach is very similar to what you propose with KeyOxide, but JSContact seems to be pretty well thought out as far as working with OpenPGP and S/MIME for email security, there is a currently active IETF WG. I think there would have to be a pretty good reason not to use JSContact before looking outside IETF. Putting WKD information into the contact is obviously a good idea. On Wed, Feb 12, 2025 at 6:52 AM Andrew Gallagher <andrewg@andrewg.com> wrote: > Hi, Phillip. > > On 7 Feb 2025, at 21:29, Phillip Hallam-Baker <phill@hallambaker.com> > wrote: > > > So putting OpenPGP keys into the DNS directly seems like a bad idea. > Better to use signed contacts and put the root of trust for the contact > manager into the DNS: > > _mesh.phill.hallambaker.com. IN TXT > "dsa=mbqn-a3es-zbye-xp3o-w6et-pqug-go5v@@example.com" > > So what this does is bind my DNS handle to my Mesh direct service address > which is a root-o-trust/service address pair. And then people can do a > fetch to get my public contact assertion signed under that root o' trust > and verify it. If my zone is DNSSEC signed, we have a fairly solid trust > path for establishing TOFU. > > And that contact assertion would hold my SSH credentials OpenPGP > credentials, etc. etc. Right now I am just transferring the IANA protocol > names into my JSON serialization. > > > This proposal sounds to me like it can already be done by combining WKD > and Keyoxide [1] - WKD binds the key to the domain, and Keyoxide binds the > various other identities to the key. Or am I missing an extra subtlety? > > A > > [1] www.keyoxide.org >
- [openpgp] Using DNS Handles with OpenPGP Phillip Hallam-Baker
- [openpgp] Re: Using DNS Handles with OpenPGP Andrew Gallagher
- [openpgp] Re: Using DNS Handles with OpenPGP Phillip Hallam-Baker