Check to implement:
An implementation MUST ensure that a valid direct-key signature is present before using a v6 key. This prevents certain attacks where an adversary strips a self-signature specifying a key expiration time or certain preferences.
Is my understanding correct that self signatures are always done by the primary key, i.e., an encryption subkey directkey self-signature is issued by the primary key?
What about signature subkeys with key usage flag 0x01?
Check to implement:
Is my understanding correct that self signatures are always done by the primary key, i.e., an encryption subkey directkey self-signature is issued by the primary key?
What about signature subkeys with key usage flag 0x01?