I've never stated that we should follow in GnuPG's footsteps. In
fact, I'd rather have a united cryptographic standard, which is
technologically coherent, and secure. My point is that this forking
event in its entirety, is *extremely* odd, and almost nonsensical.

  Nobody has the time to drudge through years of archives to figure
out what the consensus may be. I'm not even sure if those documents
you linked to even *mention* the issues brought up by LibrePGP. It
would be convenient if you could post links to some of the
conversations that they've had regarding LibrePGP maintainers'
specific talking points, and opinions. It isn't required to re
litigate, if the former litigation can be brought into the
spotlight for everyone to see; being that I'm personally unaware
that this former litigation has occurred.

  You're still assuming the LibrePGP maintainers to be in the
wrong. I don't know whether they're wrong. Stating that they're
wrong, with little-to-no reason, besides "causing fragmentation,"
does *not* help your standing.

  Considering that the fork has occurred, I would expect to see
links to at least one mailing list discussion as to *why* LibrePGP
maintainers were unable to convince stakeholders with their talking
points. Was it because of their technical standing, and LibrePGP's
inability to interop with *current,* long-standing implementations,
which have proven themselves to be robust over the years, and
trusted by many programmers around the world? Is there some kind of
in-the-near-future thing that I'm unaware of (like future-proofing
for a post-quantum event)?

  It still isn't clear to me how OpenPGP has arrived to this
consensus, or whether this consensus even exists. This strikes me
as being extremely odd, and should *clearly* be investigated
further.

  I expect better argumentation out of a technical mailing list...


Sent with Proton Mail secure email.

On Monday, July 20th, 2026 at 17:26, Simo Sorce <[email protected]> wrote:

> On Mon, 2026-07-20 at 20:48 +0000, CS Sushi Man via devel wrote:
> >   I'm unaware of this consensus, and I'm also unaware of the
> > implications the decisions made by the OpenPGP WG may have in the
> > future. Could you tell me the specifics of these protocol changes,
> > and why LibrePGP is the responsible party? I'd rather have
> > the criticisms being made by the LibrePGP team *be addressed,*
> > rather than have them be ignored, and swept under the rug.
> >
> > https://gnupg.org/blog/20260320-some-criticism-matter.html
> >
> >   I'd also like to see what the OpenPGP WG has to say about
> > LibrePGP, and again, *address* the concerns of the LibrePGP
> > maintainers. In particular, since you are on the RHEL crypto team,
> > why don't you lead this discussion?
> 
> I have no reason to rehash pubic knowledge, if you are curious you can
> go here: https://datatracker.ietf.org/wg/openpgp/documents/ and read
> the documents and the mailing list threads.
> 
> I am not sure why the link above matters at all. The "LibrePGP
> maintainers" had a voice in the OpenPGP WG like everyone else.
> 
> OpenPGP is a standard, the standard is discussed and negotiated and
> agreed in IETF. GnuPG decided they know better than all other
> stakeholders but apparently were also not able to convince the other
> stakeholders that they had better technical arguments.
> 
> When the WG, through rough consensus decided that the right way to deal
> with the evolution of the OpenPGP standard did not match exactly what
> the GnuPG maintainer wanted they decided to isolate themselves and
> become incompatible with the rest of the world.
> 
> It is their choice and they are fully free to do that, but that does
> not mean we need to follow it, or re-litigating their choice over and
> over.
> 
> We need to use standards for interoperability, and OpenPGP is a
> *standard* debated and resolved the proper way within a super-partes
> body called IETF. LibrePGP can be called a specification, but it is not
> an interoperable standard governed by a proper standardization body,
> therefore we can't rely on it going forward. It is that simple.
> 
> Best,
> Simo.
> 
> --
> Simo Sorce
> Distinguished Engineer
> RHEL Crypto Team
> Red Hat, Inc
> 
> --
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to