[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sks-devel] SKS should not accept or replay non-exportable certifica
From: |
Phil Pennock |
Subject: |
Re: [Sks-devel] SKS should not accept or replay non-exportable certifications |
Date: |
Sat, 14 Sep 2013 21:52:46 -0700 |
On 2013-09-14 at 20:46 -0500, John Clizbe wrote:
> 2) JimBob lsigns his own key, creating a non-exportable selfsig then delsigs
> all of the exportable selfsigs. This is shooting oneself in the foot. If we
> honor no-export on a selfsig, we create keys with UIDs that have no binding
> signature. THIS IS VERY VERY BAD. I think the RFC folks should probably have
> been more explicit on this case, but to be fair, it's probably a use case they
> did not anticipate.
I can see a use for this. If I'm creating a PGP-using role service,
managed by several people, where the key needs to be online in the role
account, I might want to avoid letting the service's own PGP key be
something that others can import and provide signatures for. It's
explicitly a service which can be set to trust other keys, but should
not be trusted by other people.
That key would probably have some lsigns on a few PGP keys belonging to
the people who administer the service.
It's a decent way to declare that a key should not appear in public
keyrings such as those in keyservers, while still being able to *use*
PGP and automatically maintain trust paths.
I do *not* think that it is censorship for a keyserver to honour an
attribute of a signature, where the attribute is covered by the
signature. If a signature is marked 'local', honouring its own conveyed
wishes is not censorship, it's discretion.
-Phil
pgp88U1uFaxYV.pgp
Description: PGP signature
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, (continued)
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, John Clizbe, 2013/09/13
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Robert J. Hansen, 2013/09/13
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Daniel Kahn Gillmor, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Robert J. Hansen, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Daniel Kahn Gillmor, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, John Clizbe, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Jason Harris, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications,
Phil Pennock <=
- [Sks-devel] SKS should not accept or propagate User IDs with no self-sigs [was: SKS should not accept or replay non-exportable certifications], Daniel Kahn Gillmor, 2013/09/17
- Re: [Sks-devel] SKS should not accept or propagate User IDs with no self-sigs [was: SKS should not accept or replay non-exportable certifications], ClarusComms OpenPGP Services, 2013/09/18
- Re: [Sks-devel] SKS should not accept or propagate User IDs with no self-sigs [was: SKS should not accept or replay non-exportable certifications], Johan van Selst, 2013/09/18
- Re: [Sks-devel] SKS should not accept or propagate User IDs with no self-sigs [was: SKS should not accept or replay non-exportable certifications], Stephan Seitz, 2013/09/18
- Re: [Sks-devel] SKS should not accept or propagate User IDs with no self-sigs [was: SKS should not accept or replay non-exportable certifications], John Clizbe, 2013/09/18
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, Jason Harris, 2013/09/14
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, kwadronaut, 2013/09/15
- Re: [Sks-devel] SKS should not accept or replay non-exportable certifications, David Shaw, 2013/09/15