[openpgp] Fwd: New Version Notification for draft-gallagher-email-invisible-signatures-00.txt

Andrew Gallagher <andrewg@andrewg.com> Sat, 03 May 2025 10:55 UTC

Return-Path: <andrewg@andrewg.com>
X-Original-To: openpgp@mail2.ietf.org
Delivered-To: openpgp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 5EC682463C8C for <openpgp@mail2.ietf.org>; Sat, 3 May 2025 03:55:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=andrewg.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id WTulmbGnfrbe for <openpgp@mail2.ietf.org>; Sat, 3 May 2025 03:55:07 -0700 (PDT)
Received: from fum.andrewg.com (fum.andrewg.com [IPv6:2a01:4f9:c011:23ad::1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5A3A92463C82 for <openpgp@ietf.org>; Sat, 3 May 2025 03:55:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=andrewg.com; s=andrewg-com; t=1746269705; bh=O0h8p4/CGb5z02+FjsJQ61hWCMzPRqXn3aL+8eal7l8=; h=From:Subject:Date:References:Cc:To:From; b=LWG8a1jPxCJqLkzAnvB7gB+DwoDXcqCU6458EqTMwArQDW6TF7+smsWEu1oEt4Lok 1P8f9fb41OvgjOuDceahTSKRsj6Q9ZjdeB0dJJX/6DhQP+yQ2Kt2JeCeC5qdv29cah GALhDqpAfGAG3NGv6PPMkTjZve0QJkhjRdmFZAD5EgsIIeea8U0MNM78vJj7ninK+Z AZ0dWV3BWNstbm8pDpt12bLndYPWxtvN4sqpD61OIJCXo4IwstBZs8wsqpCzMPgxad g2+ow5E8Pl9d1zRo1xv8fxuGps4OsqC5/XS4cj7QIoBzs6iGqFGFsVYVx5f7FeqjjS HZ4/phuWdvWFw==
Received: from smtpclient.apple (serenity [IPv6:fc93:5820:7349:eda2:99a7::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by fum.andrewg.com (Postfix) with ESMTPSA id 710965E357; Sat, 3 May 2025 10:55:05 +0000 (UTC)
From: Andrew Gallagher <andrewg@andrewg.com>
Content-Type: multipart/signed; boundary="Apple-Mail=_67CEE351-FC92-45A3-A153-3202C910216C"; protocol="application/pgp-signature"; micalg="pgp-sha512"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3731.700.6.1.10\))
Date: Sat, 03 May 2025 11:54:46 +0100
References: <174626909298.338737.10420965667394729319@dt-datatracker-58d4498dbd-6gzjf>
To: IETF OpenPGP WG <openpgp@ietf.org>
Message-Id: <5E01CE52-2B15-48BA-BCEE-4E7FAB7FBD02@andrewg.com>
X-Mailer: Apple Mail (2.3731.700.6.1.10)
Message-ID-Hash: ONVEZOGZFOEKHI6UKAGZD5G64OJ4YDVX
X-Message-ID-Hash: ONVEZOGZFOEKHI6UKAGZD5G64OJ4YDVX
X-MailFrom: andrewg@andrewg.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: OpenPGP-based Email Encryption <openpgp-email@enigmail.net>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Fwd: New Version Notification for draft-gallagher-email-invisible-signatures-00.txt
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/tTfiZ3H-SM81GyFqEJg2RoLKYMM>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

Hi, all.

I have just uploaded a first draft that specifies a potential replacement for cleartext-signed MIME email. This arose from one of the discussions at the 9th OpenPGP Email Summit last month, where DKG, Kai and I agreed to draw up a proposal based on the views expressed by the attendees.

Instead of including the signature as an attachment, we propose that the signature is contained within a novel MIME header in the top-level MIME part. The principal advantage of this is that naive MUAs should silently ignore unknown MIME-part headers, which addresses the “unknown attachment” UX problem when using traditional PGP/MIME.

While this proposal only specifies an OpenPGP message format, it should be extensible to similar signed-only MIME formats.

Comments welcome!

Thanks,
Andrew.

> Begin forwarded message:
> 
> From: internet-drafts@ietf.org
> Subject: New Version Notification for draft-gallagher-email-invisible-signatures-00.txt
> Date: 3 May 2025 at 11:44:52 IST
> To: "Andrew Gallagher" <andrewg@andrewg.com>, "Daniel Gillmor" <dkg@fifthhorseman.net>, "Daniel Kahn Gillmor" <dkg@fifthhorseman.net>, "Kai Engert" <kaie@thunderbird.net>
> 
> A new version of Internet-Draft
> draft-gallagher-email-invisible-signatures-00.txt has been successfully
> submitted by Andrew Gallagher and posted to the
> IETF repository.
> 
> Name:     draft-gallagher-email-invisible-signatures
> Revision: 00
> Title:    Invisible End-to-End E-mail Signatures
> Date:     2025-05-02
> Group:    Individual Submission
> Pages:    19
> URL:      https://www.ietf.org/archive/id/draft-gallagher-email-invisible-signatures-00.txt
> Status:   https://datatracker.ietf.org/doc/draft-gallagher-email-invisible-signatures/
> HTMLized: https://datatracker.ietf.org/doc/html/draft-gallagher-email-invisible-signatures
> 
> 
> Abstract:
> 
>   This document deals with end-to-end cryptographically signed e-mail.
>   It introduces a novel structure for signed e-mail that is designed to
>   avoid creating any disturbance in legacy e-mail clients.  This
>   "invisible" signature structure removes disincentives for signing
>   e-mail.
> 
> 
> 
> The IETF Secretariat
> 
>