Re: [perpass] OpenPGP mail/news header

Paul Wouters <paul@nohats.ca> Thu, 28 August 2014 14:54 UTC

Return-Path: <paul@nohats.ca>
X-Original-To: perpass@ietfa.amsl.com
Delivered-To: perpass@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BFC5F1A06F7 for <perpass@ietfa.amsl.com>; Thu, 28 Aug 2014 07:54:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.546
X-Spam-Level:
X-Spam-Status: No, score=-1.546 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RP_MATCHES_RCVD=-0.668, URI_HEX=1.122] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BFdwEGoRNyuk for <perpass@ietfa.amsl.com>; Thu, 28 Aug 2014 07:54:23 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [76.10.157.69]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D8C11A06F5 for <perpass@ietf.org>; Thu, 28 Aug 2014 07:54:23 -0700 (PDT)
Received: from bofh.nohats.ca (bofh.nohats.ca [127.0.0.1]) by bofh.nohats.ca (Postfix) with ESMTP id B46DD813B2; Thu, 28 Aug 2014 10:54:21 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=nohats.ca; s=default; t=1409237661; bh=FwGBh1QQvO0nBtem4SFfHbBoAeQlsArWlFmXDvclcrY=; h=Date:From:To:cc:Subject:In-Reply-To:References; b=DvArZWukUoCE1N1Y05+yZa+tx5vKwajro9F/tPZL7s1sCjPfHtbO8A7edO/Rxa3Gm 7usOpWrf8k8lZbp5i2go8xesjFTFda0snMQJ1p++THLAyLM6EgBIBTXTXmD9EbPAvt PPNRC3dvTUjYV5GLnQuJCSwsFX1zp4qAGsJ6diHM=
Received: from localhost (paul@localhost) by bofh.nohats.ca (8.14.7/8.14.7/Submit) with ESMTP id s7SEsLJ2017962; Thu, 28 Aug 2014 10:54:21 -0400
X-Authentication-Warning: bofh.nohats.ca: paul owned process doing -bs
Date: Thu, 28 Aug 2014 10:54:20 -0400
From: Paul Wouters <paul@nohats.ca>
To: Simon Josefsson <simon@josefsson.org>
In-Reply-To: <20140828160043.76ae962f@latte.josefsson.org>
Message-ID: <alpine.LFD.2.10.1408281046090.17182@bofh.nohats.ca>
References: <20140828160043.76ae962f@latte.josefsson.org>
User-Agent: Alpine 2.10 (LFD 1266 2009-07-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; format="flowed"; charset="US-ASCII"
Archived-At: http://mailarchive.ietf.org/arch/msg/perpass/m1on5UBCBGUkdRQWLF0FDqGK47k
Cc: perpass@ietf.org
Subject: Re: [perpass] OpenPGP mail/news header
X-BeenThere: perpass@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "The perpass list is for IETF discussion of pervasive monitoring. " <perpass.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/perpass>, <mailto:perpass-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/perpass/>
List-Post: <mailto:perpass@ietf.org>
List-Help: <mailto:perpass-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/perpass>, <mailto:perpass-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Aug 2014 14:54:24 -0000

On Thu, 28 Aug 2014, Simon Josefsson wrote:

> I have updated a six (!) year old document describing the OpenPGP
> mail/news header field.  As it encourages and promotes use of
> encrypted/signed email, I thought it would be relevant to this list.
> All feedback is appreciated, either directly to me or here.
>
> http://tools.ietf.org/html/draft-josefsson-openpgp-mailnews-header-07

I think it would be better to announce both keyid and fingerprint.

Would it be better to use the longer keyid version?

Should a warning be added to the Security Considerations about v3 keys
being vulnerable to forging of fingerprints?
See: https://github.com/coruus/cooperpair/tree/master/keysteak

It would be nice to support OPENPGPKEY DNS records in header as well?

either:

OpenPGP: dns:paul@nohats.ca

or

OpenPGP: dns=ab16de0656382d91838914109ab89a0a4e04321550a1a20ace7a8b66._openpgpkey.nohats.ca

Perhaps add a reference to:

http://tools.ietf.org/html/draft-wouters-dane-openpgp

Paul