Questions about LibrePGP specification

Falko Strenzke falko.strenzke at mtg.de
Thu Jun 20 12:29:19 CEST 2024


After looking into some specifications in the LibrePGP draft 01, I have 
the following questions and comments. Any clarification is appreciated.

 1. Section "5.2.4. Computing Signatures"
     1. Comment: This section makes statements about v6 signatures, but
        the hashed data for v6 signatures is not given. It seems it
        hardly makes sense to describe v6 signatures in such an
        incomplete manner and it might be better to give either a
        complete description or not to mention them at all.
     2. Comment: In the same section it says "when a V5 or V6 signature
        is made over a key, the hash data starts with the octet 0x9a for
        V5 and 0x9b for V6,". This is wrong since for v6 signatures, the
        hashed data start with the salt.
 2. Section "12.1. Key Structures"
     1. Question: This section makes User ID Packet optional for v4
        keys. Is that a mistake? Is it possibly meant that this
        requirement is removed for certificates with a v5 primary key?
     2. related Question: This section says nothing about the structure
        of v5 keys. Wouldn't that be necessary? What is the requirement
        of v5 certificates specifically regarding User ID Packets?

- Falko

-- 

*MTG AG*
Dr. Falko Strenzke

Phone: +49 6151 8000 24
E-Mail: falko.strenzke at mtg.de
Web: mtg.de <https://www.mtg.de>

<https://www.linkedin.com/search/results/all/?fetchDeterministicClustersOnly=true&heroEntityKey=urn%3Ali%3Aorganization%3A13983133&keywords=mtg%20ag&origin=RICH_QUERY_SUGGESTION&position=0&searchId=d5bc71c3-97f7-4cae-83e7-e9e16d497dc2&sid=3S5&spellCorrectionEnabled=false> 


	

MTG AG - Dolivostr. 11 - 64293 Darmstadt, Germany
Commercial register: HRB 8901
Register Court: Amtsgericht Darmstadt
Management Board: Jürgen Ruf (CEO), Tamer Kemeröz
Chairman of the Supervisory Board: Dr. Thomas Milde

This email may contain confidential and/or privileged information. If 
you are not the correct recipient or have received this email in error,
please inform the sender immediately and delete this email.Unauthorised 
copying or distribution of this email is not permitted.

Data protection information: Privacy policy 
<https://www.mtg.de/en/privacy-policy>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://librepgp.org/pipermail/librepgp-discuss/attachments/20240620/0197ec09/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4813 bytes
Desc: Kryptografische S/MIME-Signatur
URL: <https://librepgp.org/pipermail/librepgp-discuss/attachments/20240620/0197ec09/attachment.bin>


More information about the LibrePGP-discuss mailing list