Skip to content

Check v6 direct-key self signature #3

Description

@TJ-91

Check to implement:

An implementation MUST ensure that a valid direct-key signature is present before using a v6 key. This prevents certain attacks where an adversary strips a self-signature specifying a key expiration time or certain preferences.

Is my understanding correct that self signatures are always done by the primary key, i.e., an encryption subkey directkey self-signature is issued by the primary key?
What about signature subkeys with key usage flag 0x01?

Metadata

Metadata

Assignees

No one assigned

    Labels

    v6 req. deferred to upstreamA requirement for v6 which we don't implement and which we need to inform the upstream project about

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions