ietf-openpgp
[Top] [All Lists]

Re: [openpgp] Non-SHA-1 fingerprints in signatures [was: Proposal for a separable ring signature scheme...]

2014-03-14 09:36:46
On 03/14/2014 10:24 AM, Peter Pentchev wrote:
On Thu, Mar 13, 2014 at 10:39:31PM -0400, Vincent Yu wrote:
Thanks for the info. I will likely follow your suggestion and modify
my proposal to use V4 fingerprints rather than key IDs.

Hm, how exactly would this deal with the existence of multiple signing
subkeys, all associated with the same master public key?  Your current
proposal explicitly allows for that, using the key IDs; I guess there
might be a need to include *both* the fingerprint of the master key
*and* some kind of identification of the subkey actually used for
signing.

Isn't there a V4 fingerprint defined for every key, including for each subkey? I think it would be okay just to include the fingerprints of all possible signing keys, regardless of whether they are primary keys or subkeys.

If I've misunderstood something, please let me know.

Thanks,
Vincent

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp
<Prev in Thread] Current Thread [Next in Thread>