3 ms·
I think you've misunderstood something. sq has no problem generating certificates with subkeys. Here's the default structure. Notice that we actually include
by nwalfield 6y ago
I think you've misunderstood something. sq has no problem generating certificates with subkeys. Here's the default structure. Notice that we actually include a separate signing subkey by default. This makes it harder to use a data signature where e.g. a self signature is expected and vice verse. This can help protect against some collision attacks, among others.
$ sq key generate -u '<alice@example.org>' --export /tmp/alice.pgp; sq inspect /tmp/alice.pgp
/tmp/alice.pgp: Transferable Secret Key.
Fingerprint: 99E2 68B5 F5A2 45E9 4A9F A1FB F10A BDD2 C1BC 2478
Public-key algo: EdDSA Edwards-curve Digital Signature Algorithm
Public-key size: 256 bits
Secret key: Unencrypted
Creation time: 2021-02-15 21:34:45 UTC
Expiration time: 2024-02-16 15:01:06 UTC (creation time + P1095DT62781S)
Key flags: certification
Subkey: E54F CB2B 4619 FDB9 680A 974C 94D7 9D77 395B 8A7C
Public-key algo: EdDSA Edwards-curve Digital Signature Algorithm
Public-key size: 256 bits
Secret key: Unencrypted
Creation time: 2021-02-15 21:34:45 UTC
Expiration time: 2024-02-16 15:01:06 UTC (creation time + P1095DT62781S)
Key flags: signing
Subkey: 62BF 9E6B C022 D3FB 681F 5279 2B09 341C EDFE 0AF9
Public-key algo: ECDH public key algorithm
Public-key size: 256 bits
Secret key: Unencrypted
Creation time: 2021-02-15 21:34:45 UTC
Expiration time: 2024-02-16 15:01:06 UTC (creation time + P1095DT62781S)
Key flags: transport encryption, data-at-rest encryption
UserID: <alice@example.org>
- colineartheta 6y agoI wondered if I was misunderstanding something, thank you for the response and correction. It was, “For instance, it is not currently possible to add new subkeys to a certificate”, that I thought was acknowledging this, but looking closer it seems to just be different terminology [0] than I’m familiar with. Looking forward to giving this a try! [0]https://wiki.debian.org/Subkeys https://wiki.debian.org/Subkeys
- nwalfield 6y agoRight. The sq cli does not have an subcommand to add new subkeys to an existing certificate. But it can use such certificates, and when it generates a certificate, it, by default, generates a certificate with subkeys. This functionality will, of course, be added to sq (it is possible to do this using the library). We just haven't gotten to it yet. It's not that the functionality is hard to implement. But, we want to have a clean CLI, and there are many possible options. We want to expose them in a sensible way that does not overwhelm the user.