[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Sks-devel] v3 keys with subkeys?
From: |
David Shaw |
Subject: |
Re: [Sks-devel] v3 keys with subkeys? |
Date: |
Thu, 11 Dec 2003 13:54:29 -0500 |
User-agent: |
Mutt/1.5.5i |
On Thu, Dec 11, 2003 at 07:43:27PM +0100, Peter Palfrader wrote:
> Hi,
>
> If you look at C149DC41 on kjsl you will find a v3 key with a subkey.
> sks keyservers have the key, but drop all the subkeys.
>
> I was not aware that v3 keys could have subkeys; should sks handle this
> or is this just a broken key?
V3 keys cannot have subkeys. rfc2440bis-09, section 10.1: "V3 keys
MUST NOT have subkeys."
Historically this wasn't clear, and so there are a few V3 keys with
subkeys around. Given that they are against the spec, you could make
a case for dropping them or keeping them or anything in between.
David