Re: [openpgp] key distribution by email strategy
Steffen Nurpmeso <steffen@sdaoden.eu> Mon, 14 December 2020 21:20 UTC
Return-Path: <steffen@sdaoden.eu>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 384A13A12B0 for <openpgp@ietfa.amsl.com>; Mon, 14 Dec 2020 13:20:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level:
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 905ZDZTpUEa9 for <openpgp@ietfa.amsl.com>; Mon, 14 Dec 2020 13:20:30 -0800 (PST)
Received: from sdaoden.eu (sdaoden.eu [217.144.132.164]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5456D3A12AE for <openpgp@ietf.org>; Mon, 14 Dec 2020 13:20:29 -0800 (PST)
Received: by sdaoden.eu (Postfix, from userid 1000) id 8C61316057; Mon, 14 Dec 2020 22:20:26 +0100 (CET)
Date: Mon, 14 Dec 2020 22:20:26 +0100
From: Steffen Nurpmeso <steffen@sdaoden.eu>
To: John Scott <jscott@posteo.net>
Cc: openpgp@ietf.org
Message-ID: <20201214212026.aFyyN%steffen@sdaoden.eu>
In-Reply-To: <23083923.ouqheUzb2q@t450>
References: <20201211202818.bul-I%steffen@sdaoden.eu> <2L846BD1235O5.2AHC2UF19W9NU@my.amazin.horse> <20201212220825.jMcf-%steffen@sdaoden.eu> <23083923.ouqheUzb2q@t450>
Mail-Followup-To: John Scott <jscott@posteo.net>, openpgp@ietf.org
User-Agent: s-nail v14.9.20-84-g7268a84d
OpenPGP: id=EE19E1C1F2F7054F8D3954D8308964B51883A0DD; url=https://ftp.sdaoden.eu/steffen.asc; preference=signencrypt
BlahBlahBlah: Any stupid boy can crush a beetle. But all the professors in the world can make no bugs.
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/zNvX80JbUpiQWuGELUPkcsYB05U>
Subject: Re: [openpgp] key distribution by email strategy
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 Dec 2020 21:20:32 -0000
Hello. John Scott wrote in <23083923.ouqheUzb2q@t450>: |On Saturday, December 12, 2020 5:08:25 PM EST Steffen Nurpmeso wrote: |> I'd rather have the same for OpenPGP, a signed message with the |> public thing extractable embedded, then i at least know that the |> signer had the private key for that public thing at hand. |I don't think it's standard but GnuPG enables this with the --include-key- |block and --auto-key-import pair of options: | |--include-key-block |> This option is used to embed the actual signing key into a |> data signature. The embedded key is stripped down to a |> single user id and includes only the signing subkey used to |> create the signature as well as as valid encryption subkeys. |> All other info is removed from the key to keep it and thus |> the signature small. This option is the OpenPGP counterpart |> to the gpgsm option --include-certs. | |--auto-key-import |> This is an offline mechanism to get a missing key for |> signature verification and for later encryption to this key. |> If this option is enabled and a signature includes an |> embedded key, that key is used to verify the signature and |> on verification success that key is imported. The default is |> --no-auto-key-import. |> |> On the sender (signing) site the option --include-key-block |> needs to be used to put the public part of the signing key as |> “Key Block subpacket” into the signature. Very interesting! I did not know that indeed, i am still with gpg 1.4 ;-), but gnupg 2.25 is standard in CRUX-Linux, too, so. Yes, that is a very, very good thing then, in my opinion! Begs the question, if i will implement OpenPGP support next year (after the MIME rewrite that thing needs first), can i somehow integrate this with email when using standard OpenPGP MIME format. --steffen | |Der Kragenbaer, The moon bear, |der holt sich munter he cheerfully and one by one |einen nach dem anderen runter wa.ks himself off |(By Robert Gernhardt)
- [openpgp] Combining signature with signer's publi… Kai Engert
- Re: [openpgp] Combining signature with signer's p… vedaal
- Re: [openpgp] Combining signature with signer's p… brian m. carlson
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Werner Koch
- Re: [openpgp] Combining signature with signer's p… holger krekel
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Hanno Böck
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Kai Engert
- Re: [openpgp] Combining signature with signer's p… Wiktor Kwapisiewicz
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- Re: [openpgp] Combining signature with signer's p… Kai Engert
- Re: [openpgp] Combining signature with signer's p… Neal H. Walfield
- [openpgp] Put Signature in an Email's Header Neal H. Walfield
- Re: [openpgp] Put Signature in an Email's Header Kai Engert
- [openpgp] key distribution by email strategy Kai Engert
- Re: [openpgp] key distribution by email strategy Andrew Gallagher
- Re: [openpgp] key distribution by email strategy Kai Engert
- Re: [openpgp] Put Signature in an Email's Header Bart Butler
- Re: [openpgp] key distribution by email strategy Heiko Schaefer
- Re: [openpgp] key distribution by email strategy Werner Koch
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] key distribution by email strategy Vincent Breitmoser
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] key distribution by email strategy John Scott
- Re: [openpgp] key distribution by email strategy Steffen Nurpmeso
- Re: [openpgp] Put Signature in an Email's Header Daniel Kahn Gillmor
- Re: [openpgp] Put Signature in an Email's Header Benjamin Kaduk