[openpgp] Re: Using OpenPGP card hardware security devices with modern key packets

Heiko Schäfer <heiko.schaefer@posteo.de> Mon, 24 August 2026 17:50 UTC

Return-Path: <heiko.schaefer@posteo.de>
X-Original-To: openpgp@mail2.ietf.org
Delivered-To: openpgp@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id B85EE12E85FF8 for <openpgp@mail2.ietf.org>; Mon, 24 Aug 2026 10:50:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1787593855; bh=xy9/uXoYODV5N1cYxho6C2vU41sZCh1YXXPSB/ix5B0=; h=Date:Subject:To:References:From:In-Reply-To; b=l0jbx8aOgVrRq2Canw8SJgn1DbK1Ecoaw+cD16o54jisDFv0KDLbp+3fJYT/Q33Kt qVHrQ07jeOZ0FJ840ANcGGJjpljBqR7FAn3+FUaT0RtqeEA+RHXIxYIdlII4TZSE4Q Ua+tRGS1JvuRx9tes2YotxSIHNUA5+a1RYIxBNCM=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -4.397
X-Spam-Level:
X-Spam-Status: No, score=-4.397 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=posteo.de
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id L7cWJ4_IdFYA for <openpgp@mail2.ietf.org>; Mon, 24 Aug 2026 10:50:55 -0700 (PDT)
Received: from mout01.posteo.de (mout01.posteo.de [185.67.36.65]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 051BF12E85FF3 for <openpgp@ietf.org>; Mon, 24 Aug 2026 10:50:55 -0700 (PDT)
Received: from submission (posteo.de [185.67.36.169]) by mout01.posteo.de (Postfix) with ESMTPS id E641A240027 for <openpgp@ietf.org>; Mon, 24 Aug 2026 19:50:46 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=posteo.de; s=1984.8680eb; t=1787593846; bh=/F9Kz68aEtl0G7TJVGQWtThBwcrTrDzdEki5MX9qoG0=; h=Message-ID:Date:MIME-Version:Subject:To:From:Content-Type: Content-Transfer-Encoding:From; b=e20aNB+f8f+Fs+9U+is/3n42VVGzuOf6hQd93C8yGV8yYIUjhaxJKW8VSWfkb6Fmx SyxWSFzNjPhuWILJVEb/QtGXfNfWXVLXirBfpflb977TPAEZorqfBessd//+Q09Sx+ Sqs0TAslIsOR+fup2UffGesuiGAl6axY1BYAM8IlEW+WoJ9UtVji7FrTbBMJI7CJMb Sxvsvs3nudq9jkwdiiE9+RyEVgoXQt9YlU0KZ3z4/qchofRZfy6Z6C7JH/F9JJdD3R MTHzEekerI4oRE3iP/5+YbOPFTS7FOPkofTGUSH/tSx5/cx4J9VZbyrgC5Ssntj5jm AgSmmZUgaSDTQ==
Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4hTJNk42knz6trs for <openpgp@ietf.org>; Mon, 24 Aug 2026 19:50:46 +0200 (CEST)
Received: from services.empire.hs (services.foundation.hs [192.168.21.4]) by mail.foundation.hs (Postfix) with ESMTP id 14C4F705C5 for <openpgp@ietf.org>; Mon, 24 Aug 2026 19:50:46 +0200 (CEST)
Received: from [192.168.30.220] (p5dd42bd0.dip0.t-ipconnect.de [93.212.43.208]) by services.empire.hs (Postfix) with ESMTPSA id D17FCC1B83F for <openpgp@ietf.org>; Mon, 24 Aug 2026 19:50:45 +0200 (CEST)
Message-ID: <074bfa87-f720-4d23-a4f3-bd86c0558ffa@posteo.de>
Date: Mon, 24 Aug 2026 17:50:46 +0000
MIME-Version: 1.0
To: openpgp@ietf.org
References: <05fef4e4-93e8-486d-bc5f-74e627e72cb3@posteo.de> <a171db75be763e131372ec68fd096aa42be87cdb.camel@redhat.com> <56b72dc9-c49f-4036-ae8a-09ed90c28acb@posteo.de> <8d31485d51700a746e1dc3b6997c839c8f48a236.camel@redhat.com> <878q6tn41y.fsf@josefsson.org> <a2b18701-b7d1-4922-b11e-7dd7321cc219@posteo.de> <d9599499-0738-4bb3-979f-95efe569ce50@riseup.net> <c0a698eb-81ff-47a9-a3fd-e15d1e091517@posteo.de> <c708e192-dcb6-492d-bfbe-ed10d467ecfd@posteo.de> <25fd7444-7652-44da-b00b-ed86005f33d7@riseup.net> <87ik57tp2j.fsf@fifthhorseman.net>
Content-Language: en-US
From: Heiko Schäfer <heiko.schaefer@posteo.de>
In-Reply-To: <87ik57tp2j.fsf@fifthhorseman.net>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: 5RROJKJVW2CU5GRVMFBE4HKQ6IEVNFPH
X-Message-ID-Hash: 5RROJKJVW2CU5GRVMFBE4HKQ6IEVNFPH
X-MailFrom: heiko.schaefer@posteo.de
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-openpgp.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [openpgp] Re: Using OpenPGP card hardware security devices with modern key packets
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/theeVDftw-TM1hZXaVmoNfwfPdg>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Owner: <mailto:openpgp-owner@ietf.org>
List-Post: <mailto:openpgp@ietf.org>
List-Subscribe: <mailto:openpgp-join@ietf.org>
List-Unsubscribe: <mailto:openpgp-leave@ietf.org>

Hello dkg, all,

thank you again for the comments, dkg, and everyone else.

I have published a new revision of the document that I hope addresses 
all of the concerns raised so far (and that hopefully also clarifies all 
of the questions that were raised - some implicit).

Further feedback is of course welcome.

Thanks,
:) Heiko


On 8/18/26 5:40 PM, Daniel Kahn Gillmor wrote:
> Hi Heiko, all--
>
> I've read this draft and i think it is a worthwhile contribution for
> people who want to use OpenPGP with secret key material backed by
> smartcards.
>
> I like that it's narrowly scoped, but maybe in some sections the scope
> is a bit unclear.  The draft presents itself in some cases as generic
> "how to use limited storage for larger key identifiers" but more
> concretely in other cases as the particular "v6 key identifiers on an
> OpenPGP smartcard".
>
> For example, §2.1 is very particular (v6-only, OpenPGP smartcard), but
> §6.2.2 appears to be partway to generic (OpenPGP smartcard, but any
> version > 4). I know that formally the IETF has blessed only one version
> greater than v4, which is v6, but if the goal is to make it work for
> future IETF versions (or for LibrePGP's claimed/squatted "v5" format for
> that matter) then you might want to tighten up the text to make it
> clearer how to apply it to an as-yet-unspecified version.
>
> Maybe the best scope would be "hardware device with an exactly 20 octet
> identifier and an OpenPGP key with version > 4".
>
> I really appreciated §6.2.2's concrete description of how to recalculate
> the fingperint from material available from an OpenPGP card.  However,
> i'm not sure what an implementation should do if that calculation
> doesn't match the material in the identifier slot.  (i'm also not sure
> what an implementation should do in that case with a v4 public key in
> hardware, for that matter!)  Perhaps this document could offer some
> guidance on what a safe thing to do is in that circumstance?
>
> On Tue 2026-08-18 11:55:00 +0200, Paul Schaub wrote:
>> I'd like for the working group to adopt the proposal in order to have a
>> stable specification to refer upstream to.
> Heiko hasn't publicly called for WG adoption, or indicated whether he's
> willing to give control of the doc to the WG.  Consulting the group's
> charter, this does seem like it could fall under the general rubric of:
>
>     "provide guidance to OpenPGP libraries and/or applications."
>
> Though it's not mentioned as a specific topic in the lengthy menu
> presented in the current charter.
>
> Knowing that there are two distinct OpenPGP implementations interested
> in interoperability across hardware devices is meaningful for the
> working group, though.  Thanks for the implementer's report!
>
> Regards,
>
>          --dkg
>
> _______________________________________________
> openpgp mailing list -- openpgp@ietf.org
> To unsubscribe send an email to openpgp-leave@ietf.org