Re: [openpgp] Combining signature with signer's public key

"Neal H. Walfield" <neal@walfield.org> Fri, 11 December 2020 08:54 UTC

Return-Path: <neal@walfield.org>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EDCD93A0825 for <openpgp@ietfa.amsl.com>; Fri, 11 Dec 2020 00:54:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id X_z5U82mA_fl for <openpgp@ietfa.amsl.com>; Fri, 11 Dec 2020 00:54:39 -0800 (PST)
Received: from mail.dasr.de (mail.dasr.de [217.69.77.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28E8C3A0822 for <openpgp@ietf.org>; Fri, 11 Dec 2020 00:54:39 -0800 (PST)
Received: from pd9e79cc0.dip0.t-ipconnect.de ([217.231.156.192] helo=forster.huenfield.org) by mail.dasr.de with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.86_2) (envelope-from <neal@walfield.org>) id 1kneCD-00029b-2K; Fri, 11 Dec 2020 08:54:37 +0000
Received: from grit.huenfield.org ([192.168.20.9] helo=grit.walfield.org) by forster.huenfield.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <neal@walfield.org>) id 1kneCC-00008b-QI; Fri, 11 Dec 2020 09:54:36 +0100
Date: Fri, 11 Dec 2020 09:54:36 +0100
Message-ID: <87ft4cyb77.wl-neal@walfield.org>
From: "Neal H. Walfield" <neal@walfield.org>
To: holger krekel <holger@merlinux.eu>
Cc: Kai Engert <kaie@kuix.de>, openpgp@ietf.org
In-Reply-To: <20201211083114.GI184802@beta>
References: <48be3fcf-cdce-9ef4-655b-63b6dddf9310@kuix.de> <20201211083114.GI184802@beta>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM/1.14.9 (Gojō) APEL/10.8 EasyPG/1.0.0 Emacs/26 (x86_64-pc-linux-gnu) MULE/6.0 (HANACHIRUSATO)
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset="US-ASCII"
X-SA-Exim-Connect-IP: 192.168.20.9
X-SA-Exim-Mail-From: neal@walfield.org
X-SA-Exim-Scanned: No (on forster.huenfield.org); SAEximRunCond expanded to false
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/wmDybWilGt9JFIE6luv5nL7jcKs>
Subject: Re: [openpgp] Combining signature with signer's public key
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 11 Dec 2020 08:54:44 -0000

Hi Holger,

On Fri, 11 Dec 2020 09:31:14 +0100,
holger krekel wrote:
> the reason several e-mail app implementors decided for a header 
> in the discussions leading up to the Autocrypt spec in 2017
> was precisely to not confuse users with weird attachments. related FAQ: 
> https://autocrypt.org/faq.html#why-are-you-using-headers-rather-than-attached-keys 
> 
> What do you find problematic about it?  It's been used in several mail
> apps (including Thunderbird/Enigmail up until TB78 in August 2020) and
> did not cause any UX issues or complaints. I'd kindly ask you to consider
> not inventing another method now without strong reason.

Thanks for brining this up.  My response was too narrow, and your
recommendation is better.  In particular, it has the nice advantage
that it is possible to attach the sender's certificate (and some other
meta-data) even if the message is not signed.

Neal