I have read *some* of the ITEF mailing lists that mentioned
LibrePGP (using my spare time). It seems that some very *odd*
things have occurred. I must thank you Simo, for bringing this
issue further into my attention. I wouldn't have noticed this, if
it weren't for you. According to this email, it appears that the
compromise specification has been changed, without the awareness of
at least two stakeholders.

https://mailarchive.ietf.org/arch/msg/openpgp/zTQNT914Av0LOR_tFsowfHvijA4/

  I'll also add a few emails from the GnuPGP side:

https://lists.gnupg.org/pipermail/gnupg-devel/2023-February/035271.html
https://lists.gnupg.org/pipermail/gnupg-devel/2023-February/035272.html
https://lists.gnupg.org/pipermail/gnupg-devel/2023-February/035276.html
https://lists.gnupg.org/pipermail/gnupg-devel/2023-February/035280.html
https://lists.gnupg.org/pipermail/gnupg-devel/2023-February/035281.html

  A broad search of this archive for `LibrePGP`, can be found here:

https://mailarchive.ietf.org/arch/browse/openpgp/?q=LibrePGP

, the most useful emails in the ITEF archive seem to be dated
earlier (circa. 2023). Feel free to dig around. There's likely more
goodies that I haven't found yet, or perhaps there are some emails
in there which significantly counter my current position? :-)

  If true, this would essentially mean that this consensus is of
the OpenPGP specification designers, rather than the stakeholders.
These mailing list discussions appear to be lacking in
technicality, which is strange for a task force focused on
*engineering.* I'd expect more argumentation out of a technical
mailing list...

  I now believe that GnuPGP's maintainers have technical standing,
and that the current ITEF OpenPGP specification was likely forced
through the committee in bad faith. This is my opinion, and I 
believe that everyone reading, should read these emails
yourselves, including emails that I have *not* chosen to be
linked. Please, come to your own conclusions about what might be
happening here, and feel free to state them loud and clear.

  Compatibility is the current hot-topic. Be very careful, stop and
*think* when you see this word being used. This word may be used
improperly in this mailing list in the very near future, as well as
some other words, like "interoperability." Check and make sure that
they are using the technical definitions of these words, and that
their usage of the word is coherent, and sound.

---

  A bit offtopic, but I am *extremely* curious. Simo, could you
please tell me why DMARC is failing from RedHat domains? Do you
know who/what's responsible? I suspect that you would have an
answer, considering that you have discussed DKIM on the ITEF
mailing list.

https://mailarchive.ietf.org/arch/msg/openpgp/BNlpN_YFVd7KeFQ3w-SFuojSLUE/

https://forge.fedoraproject.org/infra/tickets/issues/12487

  I don't know how RedHat is organized, however, since this issue
has been discussed for almost a year, it is near inexcusable that
this is still an issue. Is this your responsibility, or is it the
responsibility of an email infrastructure team at RedHat, or
Fedora? It strikes me that you seem to have not commented on this
issue, and that you suddenly appeared, only to throw GnuPG under
the bus.


Sent with Proton Mail secure email.

On Monday, July 20th, 2026 at 17:26, Simo Sorce <[email protected]> wrote:

> On Mon, 2026-07-20 at 20:48 +0000, CS Sushi Man via devel wrote:
> >   I'm unaware of this consensus, and I'm also unaware of the
> > implications the decisions made by the OpenPGP WG may have in the
> > future. Could you tell me the specifics of these protocol changes,
> > and why LibrePGP is the responsible party? I'd rather have
> > the criticisms being made by the LibrePGP team *be addressed,*
> > rather than have them be ignored, and swept under the rug.
> >
> > https://gnupg.org/blog/20260320-some-criticism-matter.html
> >
> >   I'd also like to see what the OpenPGP WG has to say about
> > LibrePGP, and again, *address* the concerns of the LibrePGP
> > maintainers. In particular, since you are on the RHEL crypto team,
> > why don't you lead this discussion?
> 
> I have no reason to rehash pubic knowledge, if you are curious you can
> go here: https://datatracker.ietf.org/wg/openpgp/documents/ and read
> the documents and the mailing list threads.
> 
> I am not sure why the link above matters at all. The "LibrePGP
> maintainers" had a voice in the OpenPGP WG like everyone else.
> 
> OpenPGP is a standard, the standard is discussed and negotiated and
> agreed in IETF. GnuPG decided they know better than all other
> stakeholders but apparently were also not able to convince the other
> stakeholders that they had better technical arguments.
> 
> When the WG, through rough consensus decided that the right way to deal
> with the evolution of the OpenPGP standard did not match exactly what
> the GnuPG maintainer wanted they decided to isolate themselves and
> become incompatible with the rest of the world.
> 
> It is their choice and they are fully free to do that, but that does
> not mean we need to follow it, or re-litigating their choice over and
> over.
> 
> We need to use standards for interoperability, and OpenPGP is a
> *standard* debated and resolved the proper way within a super-partes
> body called IETF. LibrePGP can be called a specification, but it is not
> an interoperable standard governed by a proper standardization body,
> therefore we can't rely on it going forward. It is that simple.
> 
> Best,
> Simo.
> 
> --
> Simo Sorce
> Distinguished Engineer
> RHEL Crypto Team
> Red Hat, Inc
> 
> --
-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to