Re: [openpgp] Issuer Fingerprint

Peter Gutmann <pgut001@cs.auckland.ac.nz> Fri, 17 June 2016 19:02 UTC

Return-Path: <pgut001@cs.auckland.ac.nz>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 93DF112D9DF for <openpgp@ietfa.amsl.com>; Fri, 17 Jun 2016 12:02:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.626
X-Spam-Level:
X-Spam-Status: No, score=-5.626 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-1.426] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auckland.ac.nz
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H0Wx_ut-SIef for <openpgp@ietfa.amsl.com>; Fri, 17 Jun 2016 12:02:11 -0700 (PDT)
Received: from mx4.auckland.ac.nz (mx4.auckland.ac.nz [130.216.125.248]) (using TLSv1.2 with cipher RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ED02C12D9DB for <openpgp@ietf.org>; Fri, 17 Jun 2016 12:02:08 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=auckland.ac.nz; i=@auckland.ac.nz; q=dns/txt; s=mail; t=1466190129; x=1497726129; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=SxXKDGUjA3q949ruLC50qNHSp2CVaNcgvxstOMDKiF8=; b=FE3ZZaGsVLyl67tWCGnfFBfF80S5MZW+BTBs8bhEkExtf2vdbAgNctzi l/dlsmL4W0QplG0fSqFgvuVA9FeNgDtsnMDuZNDto1Zdj9BB5Lu1bQscv 7vxf3mRdmp9t13STAsbIFDHUskH3a/1iZO45D+Y5/9klf3tDTuV0YHw+m yxH1NP/C456a2EcPLkU9zLXWtAcnUozOM9sZfsh40wlFxUm2Ivu/nDqaC KFiyASYQdQMStbbuCDT/OoNRBDBOGS5GpPe/24hGYEhd0L8Swy5/o0HR2 E2aytCV6Qap+ipRYKqYvAmSqi+5pVAQqAcqkgKXRU0P66IZVTKApaJwl8 Q==;
X-IronPort-AV: E=Sophos;i="5.26,484,1459771200"; d="scan'208";a="91977715"
X-Ironport-HAT: MAIL-SERVERS - $RELAYED
X-Ironport-Source: 130.216.4.171 - Outgoing - Outgoing
Received: from uxchange10-fe4.uoa.auckland.ac.nz ([130.216.4.171]) by mx4-int.auckland.ac.nz with ESMTP/TLS/AES256-SHA; 18 Jun 2016 07:02:07 +1200
Received: from UXCN10-5.UoA.auckland.ac.nz ([169.254.5.93]) by uxchange10-fe4.UoA.auckland.ac.nz ([169.254.109.63]) with mapi id 14.03.0266.001; Sat, 18 Jun 2016 07:02:06 +1200
From: Peter Gutmann <pgut001@cs.auckland.ac.nz>
To: Werner Koch <wk@gnupg.org>, Vincent Breitmoser <look@my.amazin.horse>
Thread-Topic: [openpgp] Issuer Fingerprint
Thread-Index: AQHRxVv+XkgLTKRZjUCqSa/FVCgLe5/oG7mAgADZDYD//zg6gIAA326vgAT9/1Y=
Date: Fri, 17 Jun 2016 19:02:05 +0000
Message-ID: <9A043F3CF02CD34C8E74AC1594475C73F4CA3941@uxcn10-5.UoA.auckland.ac.nz>
References: <87mvmp5rmi.fsf@wheatstone.g10code.de> <CABtrr-Vrv-S_2htPECqLR+Butqr9GzwvPaXfqEyW2fBRW__o_w@mail.gmail.com> <87mvmnyknu.fsf@wheatstone.g10code.de> <20160614132705.GA28122@littlepip.fritz.box>, <8760tbygok.fsf@wheatstone.g10code.de>
In-Reply-To: <8760tbygok.fsf@wheatstone.g10code.de>
Accept-Language: en-NZ, en-GB, en-US
Content-Language: en-NZ
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.6.2.5]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/qG0TFy4wmrEDvzFP5X1YySR5tpA>
Cc: "openpgp@ietf.org" <openpgp@ietf.org>, Joseph Lorenzo Hall <joe@cdt.org>
Subject: Re: [openpgp] Issuer Fingerprint
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Jun 2016 19:02:17 -0000

Werner Koch <wk@gnupg.org> writes:

>I strongly disagree for OpenPGP.  The MUSTs, SHOULDs, and MAYs have been
>carefully designed and implemented in a sensible way.  Thus there are no real
>world interoperability problems between OpenPGP implementations.

Uhh, I'll have to disagree (strongly) with that, perhaps from the point of GPG
this is true since it's the de facto reference implementation that everyone
makes their code compatible with, but when you need to interop across non-GPG
implementations it can get pretty hairy, I've had to reverse-engineer source
code and create instrumented versions of other apps that hex-dump data so I
can see what they're doing.  I've also had to do that with GPG on a couple of
occasions where the spec was unclear on which data needed to be processed in
which way.  I assume that a lot, if not all, the code out there is written to
be compatible with the GPG de facto profile, in the same way that SSH code is
written to be compatible with the OpenSSH (server) and Putty (client) de facto
profiles.

Peter.