Skip to content

Conversation

@rrrooommmaaa
Copy link
Contributor

This PR selects a usable key among all received from Wkd

close #3017

@rrrooommmaaa rrrooommmaaa force-pushed the issue-3017-wkd-many-keys branch from 695aef6 to 0e287cc Compare February 6, 2021 10:37
@rrrooommmaaa
Copy link
Contributor Author

@tomholub Looks like human@flowcrypt.com fails due to a problem unrelated to this PR.
https://openpgpkey.flowcrypt.com/.well-known/openpgpkey/flowcrypt.com/policy is not reachable.
As for revoked keys -- our goal might be not only to skip them from Wkd's response, but to update ContactStore so these keys won't be usable. How do you think about it?

@tomholub
Copy link
Collaborator

tomholub commented Feb 7, 2021

As for revoked keys -- our goal might be not only to skip them from Wkd's response, but to update ContactStore so these keys won't be usable. How do you think about it?

Definitely - but maybe not in this PR. There is another issue #3018 to look into that as a followup.

That is also related to issue #3332

I think the overall sequence could be:

Right now, since there is only one public key per recipient email, we'd have to create some logic that would be quite different (I think) from the final situation. Right now, let's say the recipient rotates the key. Old one is revoked, new one is available. We would have to throw out the old (revoked) one and replace it with the new one. As opposed to, after we support several pubkeys per recipient, we can independently update the revoked ones and also all of the valid ones that WKD returns - save them all. Then only once we try to email that recipient (or verify their emails) will we choose the right public key from all of the ones that are available.

@tomholub
Copy link
Collaborator

tomholub commented Feb 7, 2021

@tomholub Looks like human@flowcrypt.com fails due to a problem unrelated to this PR. https://openpgpkey.flowcrypt.com/.well-known/openpgpkey/flowcrypt.com/policy is not reachable.

Sorry, fixed

@rrrooommmaaa rrrooommmaaa marked this pull request as ready for review February 7, 2021 11:36
@rrrooommmaaa
Copy link
Contributor Author

I think the overall sequence could be:

Ok, so this PR is ready to merge, as I understood.

Copy link
Collaborator

@tomholub tomholub left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

return alice; // advanced for incorrect@localhost
},
'/.well-known/openpgpkey/localhost/hu/66iu18j7mk6hod4wqzf6qd37u6wejx4y?l=some.revoked': async () => {
return validAmongRevoked;
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I just noticed - we are returning armored keys here on the WKD endpoints but that does not reflect how WKD returns keys (which should be unarmored bytes, concatenated). I'll make another issue for this.

@tomholub tomholub merged commit 563730c into master Feb 7, 2021
@tomholub tomholub deleted the issue-3017-wkd-many-keys branch February 7, 2021 12:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

WKD evaluate all received keys

3 participants