curve25519 and encryption capabilities

Kristian Fiskerstrand kristian.fiskerstrand at sumptuouscapital.com
Fri Sep 19 22:39:32 CEST 2014


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 09/19/2014 10:34 PM, Daniel Kahn Gillmor wrote:
> Hi Werner--
> 

..

>> 
>> ECDH (encryption) is 18 ECDSA (signing) should be 19
> 
> Ah, right.  signing-capable keys are indeed ID 19.
> 
>> The keys are technically exchangeable.
> 
> That's a little weird.  it seems in some sense like we're heading
> back to ID 2 and 3 (RSA encrypt-only and RSA sign-only), which i
> thought the community had moved away from in favor of generic ID 1
> (RSA).  but in practice, since we want to discourage reuse of keys
> in different

Although the keys are technically exchangable, they have different
fields when parsing c.f. rfc6637 (see the kdf parts for ecdh), so
separate algo-id makes it cleaner to parse it.

- -- 
- ----------------------------
Kristian Fiskerstrand
Blog: http://blog.sumptuouscapital.com
Twitter: @krifisk
- ----------------------------
Public OpenPGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
- ----------------------------
"Excellence is not a singular act but a habit. You are what you do
repeatedly."
(Shaquille O'Neal)
-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJUHJSCAAoJEPw7F94F4TagBK8P/1fLoCHZbiq6KMq6sKx3xesf
/Xzb9jcZ4cIAIDfXt8aAwFWkV6uAB2rcGe9RLk3JundifRaTXEyWROVHtOcLayC7
L/kEmsZ4YfMyV9ci1a9cTZlAE+O5TbgkTCEEB9sMqQNsTc8Pqml+XBr4UH3n1U19
ieRRGAjrfnT1vQywOMjU6Z8V7KL8t23sEslPiOh6zKMgPSvICtndbpLe0yTcZpb1
FMfCK03JXDWrRri8zn2O0miXBu9YmOf6rgvBZSaj7SadRPolcED/YG3jvJcN6dbq
UPTOYN3qnvE0n3xKj699BcR3bog9/cR95sFpVPI512sG+BET0yR8CHBlhjWVdAU5
/HIk5x31juSIVHY0H4aMi5y8QvoeJPtYWpXON8ODau/9QhwYzj4B8RrfiSXYamTu
dsv1JVX/lVCRGcg7m0m1Qxa2HGGXdHvH2DcfYoPEmwJP0y7flI/YPUfdgNM80rgE
56Q+AYy1M1nz6f6FJk4U+YmZmJYE52e6nH4AdCQ9uJH4qauJfYCwKi5srYmxIbxs
w6+r/w6gpMAYW4gJlJsO0vDIKj8TJaUz6y/dDpoJbZi+qmOuOcQLoLlWd/uMNshp
DWngByGua7DjwfSnZMUVHgrPPDZGmcMHOVNzczKH1PcNSGl5tIzTLyKjyGuwPV+l
XwCCxE5kO8AMKFRJDCOH
=zp/g
-----END PGP SIGNATURE-----



More information about the Gnupg-devel mailing list