On Tue, Jul 21, 2026 at 12:13:40AM -0400, Julian Anderson wrote:
> Hello,
> 
> On Mon, Jul 20, 2026 at 8:36 PM CS Sushi Man via devel <
> [email protected]> wrote:
> 
> >   I have read *some* of the ITEF mailing lists that mentioned
> > LibrePGP (using my spare time). It seems that some very *odd*
> > things have occurred. I must thank you Simo, for bringing this
> > issue further into my attention. I wouldn't have noticed this, if
> > it weren't for you. According to this email, it appears that the
> > compromise specification has been changed, without the awareness of
> > at least two stakeholders.
[then Julian writes a detailed and patient reply, citing sources and history; 
thanks!]

[CS Sushi Man via wrote:]
> >   If true, this would essentially mean that this consensus is of
> > the OpenPGP specification designers, rather than the stakeholders.

As discussed over and over and over, all over the 'net, all through
the years since that happened, no, that was not really the case, since
the specification designers *are* people who both implement and use
OpenPGP tools. I personally would be grateful if these discussions
were *not* rehashed over and over and over again on this list,
especially since some of them have already taken place before
announcing this Change Proposal :)

Actually, on that note... a piece of advise to you, if I may?
When you read a Fedora Change Proposal, and you see some point that
seems to only be mentioned in passing without going into detail,
please do not assume that this is a spur-of-the-moment whim.
From my experience watching from the sidelines over the years, it is
very rare for a Change Proposal to be filed at all if the arguments
and steps outlined in it have not already been discussed within
some team, or on the Fedora lists at large. So if you see something
for the first time, it would be prudent to assume that this is not
necessarily the first time it has been brought up for discussion :)

(of course I realize that the *point* of filing a Change Proposal is
to invite further discussion on *some* of the aspects, and that
some proposals can even be withdrawn; this does not contradict what
I wrote above)

In this specfic case, the OpenPGP/LibrePGP schism was a BIG thing
when it first happened, and it is still a big thing now. Though
I will try very hard not to go into personal opinion here, I still
have to say that the decision by the GnuPG developers was
a) weird, b) unexpected once one takes into account the history of
the OpenPGP WG discussions, and c) somewhat heavy-handed.

Why heavy-handed? Well, because it *immediately* placed *many*
software projects, not just open-source ones, but certainly many
open-source ones, in the very difficult position of having to
choose which implementation to use. Okay, so this is the only piece
of personal opinion I will allow myself: if the GnuPG developers
thought that inertia would make users not switch and thus continue
to use GnuPG/LibrePGP, that was both heavy-handed and, well, wrong :)

Since then, many open-source projects have either started exploring
or outright announced their intention to switch from GnuPG to
an OpenPGP implementation for their infrastructure and tools.
I daresay that in no case was this decision taken lightly, since
everyone involved must have realized that this will involve
a non-trivial amount of reworking. In pretty much all cases, this
decision was taken after some amount of public discussion.
In ALL cases, this decision was announced well in advance of any
actual change to allow everyone time to prepare.

So... IMHO, the decision to switch from GnuPG to an OpenPGP tool
should, in itself, not be up for discussion here :) Again IMHO,
the only part that remains to be discussed is how to make
the actual change to the spec files, which seems to be happening
in the rest of this thread.

G'luck,
Peter

-- 
Peter Pentchev  [email protected] [email protected] [email protected]
PGP key:        https://www.ringlet.net/roam/roam.key.asc
Key fingerprint 2EE7 A7A5 17FC 124C F115  C354 651E EFB0 2527 DF13

Attachment: signature.asc
Description: PGP signature

-- 
_______________________________________________
devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedoraproject.org/archives/list/[email protected]
Do not reply to spam, report it: 
https://forge.fedoraproject.org/infra/tickets/issues/new

Reply via email to