ietf-openpgp
[Top] [All Lists]

Re: "Yes, I can handle PGP/MIME"

2004-04-22 04:35:01

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Tuesday 20 April 2004 17.12, David Shaw wrote:
I'll leave it to the folks advocating a notation solution to propose
something for that ;)

My proposal would be to use the reserved '@'-less notation namespace, 
and establish a pseudo-hierarchy just for the case notations for other 
areas of application should ever be needed. The name of the notation 
would be 'email.mimeencoding', the value either 'rfc3156' or 
'clearsigned'. (I considered specifying rfc2440 instead, but I fear 
that's not clear enough as rfc3156-formatted email will still use 
rfc2440 technology...)

Also, the specification should IMHO state that the default for v4 keys 
without this notation should be to use what the user specifies 
explicitely, or make a guess based on other data (mail headers of the 
mail I'm replying to, features of the key of the recipient, whatever 
the MUA developers can think of), or use PGP/MIME in the absence of any 
such information.

This would have to go into an RFC (of its own - as stated, I don't think 
it should go into 2440++ since it is entirely application related), I 
guess, if this should become a standard.  I question, however, if there 
is any chance that this is ever going to get implemented - I guess the 
gnupg side would be easy enough (set it on key generation or selfsig 
generation), but I don't know about the MUA side (and I certainly won't 
spend any efforts there, even though I'd welcome the feature.)

One big drawback: all this is only useful when a key of the recipient is 
available. The situation I'm having a problem with is where the 
recipient does *not* have a public key at all, so all this won't solve 
that :-(

But the happy conclusion: this certainly should not affect further work 
on rfc2440++

greetings
- -- vbi

- -- 
The content of this message may or may not reflect the opinion of me, my
employer, my girlfriend, my cat or anybody else, regardless of the fact
whether such an employer, girlfriend, cat, or anybody else exists.  I
(or my employer, girlfriend, cat or whoever) disclaim any legal
obligations resulting from the above message.  You, as the reader of
this message, may or may not have the permission to redistribute this
message as a whole or in parts, verbatim or in modified form, or to
distribute any message at all.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
Comment: get my key from http://fortytwo.ch/gpg/92082481

iKcEARECAGcFAkCHrdtgGmh0dHA6Ly9mb3J0eXR3by5jaC9sZWdhbC9ncGcvZW1h
aWwuMjAwMjA4MjI/dmVyc2lvbj0xLjUmbWQ1c3VtPTVkZmY4NjhkMTE4NDMyNzYw
NzFiMjVlYjcwMDZkYTNlAAoJECqqZti935l6z2cAn1tTsN3BqJXoF+A1TQxwsCMA
9Kw1AKCBTXmx2gC+UNOVjTav3tbbm5rFiw==
=1feP
-----END PGP SIGNATURE-----


<Prev in Thread] Current Thread [Next in Thread>