Received: by 2002:ac0:e350:0:0:0:0:0 with SMTP id g16csp136701imn; Fri, 29 Jul 2022 02:13:40 -0700 (PDT) X-Google-Smtp-Source: AGRyM1sMOAYM/LFNdldumGnQo+BzMEVsJ9ePQdeTYaVImhFbvufdkwADTPaMpaYwzniMKkrOzrjJ X-Received: by 2002:a05:6402:440c:b0:43a:1124:e56a with SMTP id y12-20020a056402440c00b0043a1124e56amr2711069eda.134.1659086020153; Fri, 29 Jul 2022 02:13:40 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1659086020; cv=none; d=google.com; s=arc-20160816; b=QAroy/eHTiltjTD0Fuqo4qrJzGQKqW2KQ3bJbQB5Ebd2EzJB+3VlNHLmrdvF8WpgNF 34qnvIPBAbSnKK11t3yF9CI1Dfovrio4nlyfjoJfE9U5BA+2Uu5FNuYzgPBBP+zBbNnR ii4Gy4cU3sCIxvcITGqW0DGsoJZg742dBLm5a4HJXCQw+pxni0Im9/gHdCf1hnt73YcA yhT0HyjBPSW/AAnp5dy4vQBXe59ex/KV+FyV/1Kyftph0h6dXatFWI2u6FqJciYh1AOZ VnsrxljiEB/2ROeiS6+15B801CmD95bJBXtcYr9TW4CCt0Pver3qULjm3Yd5olHMyd6S l1fQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=tAfuCia8g3UGLQjPkQqMIogLpqoBvseGFs11sBYSBWc=; b=bwUoD14KYtGMMfuD9ZTdwpYstvUovBSURlBbMqDcMEWY0084L02QvR8T/Ir2rGBFxM toI/nur6gBmFBz0Msv0JeQV0ceJ3MnzyKnIXsBhC+W0OiDYc5zB+YkbKwOQTJUkya8s6 15DprAWO1M2enA9cjRcQX1aFL4j8G4BxlPtVaJXw53UTG+1a1g4Dn+ZVLxSaXFj17YzM LexRr1UVou/q9XxrsnYkBxR0PGwQt7wc20wNmkkdfSyv9Jr8IPNct4Y4pWbVXElEDP/7 WcWddSDm1NdQLdJYC6zzo7+KGjFuWaoeIcRrO3rGvI83SzDuDSg2eVz4F8Jy9ItfoUwn SFpQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=dAhK3qlN; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id ch30-20020a0564021bde00b0043bea1ef410si2588558edb.394.2022.07.29.02.13.14; Fri, 29 Jul 2022 02:13:40 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=dAhK3qlN; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234830AbiG2JLg (ORCPT + 99 others); Fri, 29 Jul 2022 05:11:36 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47682 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229520AbiG2JLd (ORCPT ); Fri, 29 Jul 2022 05:11:33 -0400 Received: from mail-pf1-x429.google.com (mail-pf1-x429.google.com [IPv6:2607:f8b0:4864:20::429]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id ACFE77AC2E; Fri, 29 Jul 2022 02:11:32 -0700 (PDT) Received: by mail-pf1-x429.google.com with SMTP id o12so4111775pfp.5; Fri, 29 Jul 2022 02:11:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc; bh=tAfuCia8g3UGLQjPkQqMIogLpqoBvseGFs11sBYSBWc=; b=dAhK3qlNLVMH1/IkAssvtHxsuZv95YEeaKjQM1jt++T0Ec0Eod8tiJRf503fuujft2 YbgEYlIVLWycgSn2QNcFdD8FuRKc5D+JNCPPP6SgsFSeJED9DOIREu8sRw8K/2MpGDMm b44mSDp/gVKW8cjNTeRGTxoN+g1C+2BqHV1cj4NkeL+bCPny3DvlhWSHMG4DZZr5XIps AUL9kMO/1SW1/r6SjXfI4+PZFR1fOId5BXJkQyfV3sa7ZFZymnhQdqobY+OebRvOIUea D/bEWMkt0Tg+fqgBdULHbampU4wto8pU9sR3DGoolJ89l7ITOmJUxEmk3hKF/ZQPQjjb NUdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc; bh=tAfuCia8g3UGLQjPkQqMIogLpqoBvseGFs11sBYSBWc=; b=IZUt1jegFIiZewx+H/28DSLM9wTjMGbgkU8wIgMS5/iGgU7Vs6t5R5X4MpgirqLrDT MsbAVDEZ1Cpa9fzJvBSIJ+zg4LGX9+tAkpdIOS7z/aEYqYfJNC+Qx3o5Z2iwQCSIYTy4 ZAIH1DS5OkfO56ZY/qjca5zgU3u0f9Eu4wo3UycopUqRyBlrJyFuvL/oHP+tzXltlezC Z0VMUJKI8dkAKRYTxmyHI6Rt6+7stCSSrbllez18HanyEvKTmvGUEiqbr6gzXx47bZnH WUGaL7tNszRnXfVAqUi1Oj9o5dbcmWxYbtlV2vT+Kp5p2D+uc/GJx3ye5J/eT0T2IK0z T2PQ== X-Gm-Message-State: AJIora9kP/nWEJfu51LHah3XIjaGL6jwoxb2AthxlABUACHIqGKUaZyF h3Tnj8Dc06nADojNYRJaT2GMfvHmz0U= X-Received: by 2002:a63:b56:0:b0:41a:495a:2a26 with SMTP id a22-20020a630b56000000b0041a495a2a26mr2206570pgl.411.1659085892129; Fri, 29 Jul 2022 02:11:32 -0700 (PDT) Received: from debian.me (subs32-116-206-28-14.three.co.id. [116.206.28.14]) by smtp.gmail.com with ESMTPSA id bt21-20020a17090af01500b001f1ea1152aasm69925pjb.57.2022.07.29.02.11.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 29 Jul 2022 02:11:31 -0700 (PDT) Received: by debian.me (Postfix, from userid 1000) id A834E104A60; Fri, 29 Jul 2022 16:11:27 +0700 (WIB) Date: Fri, 29 Jul 2022 16:11:26 +0700 From: Bagas Sanjaya To: Konstantin Ryabitsev Cc: Jonathan Corbet , linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org Subject: Re: [PATCH v1 3/5] maintainer-pgp-guide: update ECC support information Message-ID: References: <20220727-docs-pgp-guide-v1-0-c48fb06cb9af@linuxfoundation.org> <20220727-docs-pgp-guide-v1-3-c48fb06cb9af@linuxfoundation.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline In-Reply-To: <20220727-docs-pgp-guide-v1-3-c48fb06cb9af@linuxfoundation.org> X-Spam-Status: No, score=-0.6 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,RCVD_IN_SORBS_WEB,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Thu, Jul 28, 2022 at 04:57:06PM -0400, Konstantin Ryabitsev wrote: > > - If for some reason you prefer to stay with RSA subkeys, just replace > - "ed25519" with "rsa2048" in the above command. Additionally, if you > - plan to use a hardware device that does not support ED25519 ECC > - keys, like Nitrokey Pro or a Yubikey, then you should use > - "nistp256" instead or "ed25519." > + Note, that if you plan to use a hardware device that does not > + support ED25519 ECC keys, you should choose "nistp256" instead or > + "ed25519." > nistp256 isn't just ECC key algo other than ed25519. In fact, it is a part of NIST curve family (the others are nistp384 and nistp521). Maybe we can just say "If unsure, or if your hardware device does not support ED25519, use one of NIST curves (nistp256, nistp384, or nistp521) instead". -- An old man doll... just what I always wanted! - Clara