On Tue, Jul 21, 2026 at 12:13:40AM -0400, Julian Anderson wrote: > Hello, > > On Mon, Jul 20, 2026 at 8:36 PM CS Sushi Man via devel < > [email protected]> wrote: > > > I have read *some* of the ITEF mailing lists that mentioned > > LibrePGP (using my spare time). It seems that some very *odd* > > things have occurred. I must thank you Simo, for bringing this > > issue further into my attention. I wouldn't have noticed this, if > > it weren't for you. According to this email, it appears that the > > compromise specification has been changed, without the awareness of > > at least two stakeholders. [then Julian writes a detailed and patient reply, citing sources and history; thanks!]
[CS Sushi Man via wrote:] > > If true, this would essentially mean that this consensus is of > > the OpenPGP specification designers, rather than the stakeholders. As discussed over and over and over, all over the 'net, all through the years since that happened, no, that was not really the case, since the specification designers *are* people who both implement and use OpenPGP tools. I personally would be grateful if these discussions were *not* rehashed over and over and over again on this list, especially since some of them have already taken place before announcing this Change Proposal :) Actually, on that note... a piece of advise to you, if I may? When you read a Fedora Change Proposal, and you see some point that seems to only be mentioned in passing without going into detail, please do not assume that this is a spur-of-the-moment whim. From my experience watching from the sidelines over the years, it is very rare for a Change Proposal to be filed at all if the arguments and steps outlined in it have not already been discussed within some team, or on the Fedora lists at large. So if you see something for the first time, it would be prudent to assume that this is not necessarily the first time it has been brought up for discussion :) (of course I realize that the *point* of filing a Change Proposal is to invite further discussion on *some* of the aspects, and that some proposals can even be withdrawn; this does not contradict what I wrote above) In this specfic case, the OpenPGP/LibrePGP schism was a BIG thing when it first happened, and it is still a big thing now. Though I will try very hard not to go into personal opinion here, I still have to say that the decision by the GnuPG developers was a) weird, b) unexpected once one takes into account the history of the OpenPGP WG discussions, and c) somewhat heavy-handed. Why heavy-handed? Well, because it *immediately* placed *many* software projects, not just open-source ones, but certainly many open-source ones, in the very difficult position of having to choose which implementation to use. Okay, so this is the only piece of personal opinion I will allow myself: if the GnuPG developers thought that inertia would make users not switch and thus continue to use GnuPG/LibrePGP, that was both heavy-handed and, well, wrong :) Since then, many open-source projects have either started exploring or outright announced their intention to switch from GnuPG to an OpenPGP implementation for their infrastructure and tools. I daresay that in no case was this decision taken lightly, since everyone involved must have realized that this will involve a non-trivial amount of reworking. In pretty much all cases, this decision was taken after some amount of public discussion. In ALL cases, this decision was announced well in advance of any actual change to allow everyone time to prepare. So... IMHO, the decision to switch from GnuPG to an OpenPGP tool should, in itself, not be up for discussion here :) Again IMHO, the only part that remains to be discussed is how to make the actual change to the spec files, which seems to be happening in the rest of this thread. G'luck, Peter -- Peter Pentchev [email protected] [email protected] [email protected] PGP key: https://www.ringlet.net/roam/roam.key.asc Key fingerprint 2EE7 A7A5 17FC 124C F115 C354 651E EFB0 2527 DF13
signature.asc
Description: PGP signature
-- _______________________________________________ devel mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
