Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1261071 > unrolled thread

Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring

Started byJulian Andres Klode <jak@debian.org>
First post2025-09-12 10:50 +0200
Last post2025-09-16 03:20 +0200
Articles 4 — 4 participants

Back to article view | Back to linux.debian.bugs.dist

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring Julian Andres Klode <jak@debian.org> - 2025-09-12 10:50 +0200
    Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring Guillem Jover <guillem@debian.org> - 2025-09-12 16:10 +0200
      Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring "Christian T. Steigies" <cts@debian.org> - 2025-09-12 18:50 +0200
        Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring Christoph Anton Mitterer <calestyo@scientia.org> - 2025-09-16 03:20 +0200

#1261071 — Bug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring

FromJulian Andres Klode <jak@debian.org>
Date2025-09-12 10:50 +0200
SubjectBug#1103625: modernize-sources: use .pgp file extension for debian-archive-keyring
Message-ID<Lu7DI-eIWi-59@gated-at.bofh.it>
On Wed, Aug 27, 2025 at 01:41:19PM +0200, Guillem Jover wrote:
> Hi!
> 
> [ I discussed this with Julian on IRC some time ago, but forgot to
>   forward that here, doing that now, and this report was used as a
>   reference somewhere else, so better to clarify things here. ]
> 
> On Sat, 2025-04-19 at 21:02:47 +0200, Julian Andres Klode wrote:
> > On April 19, 2025 8:30:19 PM GMT+02:00, "Christian T. Steigies" <cts@debian.org> wrote:
> > >Package: apt
> > >Version: 3.0.0
> > >Severity: wishlist
> 
> > >an upgrade offered to modernize my sources, so I did.
> > >Just seconds before I saw the message from the upgraded
> > >debian-archive-keyring:
> > >  Certificate (keyring) files in /usr/share/keyrings now have the
> > >  file extension .pgp, rather than .gpg.
> > >Shouldn't a just modernized source use the new file extension as well?
> 
> > So the .pgp extension is reserved for PGP messages, not keys.
> > 
> > This needs to be resolved by the IETF WG, and the change in the
> > keyring package was premature.
> > 
> > The only file extension for keys is .asc for armored ones.
> 
> I think that to keep using .gpg is worse, because I don't think there's
> even a MIME type for .gpg? At least none that I could see in the
> /etc/mime.types anyway. For example file --mime-types returns the correct
> thing anyway.
> 
> My take is that the MIME definition is not exhaustive, so I don't see a
> conflict if it's "missing types". And my perception is that MIME types
> get registered after demonstrated usage?
> 
> Julian asked if file did application/pgp-keys for .pgp keys, and this
> was my reply:
> 
>   $ file --mime-type /usr/share/keyrings/debian-archive-trixie-automatic.pgp
>   /usr/share/keyrings/debian-archive-trixie-automatic.pgp: application/pgp-keys
> 
> It just checks the contents the same with a .gpg one for example:
> 
>   $ file --mime-type /usr/share/keyrings/debian-maintainers.gpg
>   /usr/share/keyrings/debian-maintainers.gpg: application/pgp-keys
> 
> So I don't see much of a problem here, and I think it would be best if we
> could move away from this naming pattern, as that entrenches GnuPG usage
> as a synonym for OpenPGP which seems rather unfortunate.
> 
> And for example for the apt modernize stuff I think it would be great if
> it could check whether the current pathname referred is a symlink and
> then use that (or perhaps if the symlink target is named .pgp if you want
> to be more specific).
> 
> Julian then replied that the code could be made to just look for a
> .pgp first.

Now the uapi group standardized .openpgp as the file extension
for keys in the 

    File Hierarchy for the Verification of OS Artifacts (VOA)

specification, but also specifies they must be ASCII armored,
that is, they match our .asc extension.

So this of course begs the question of whether to support .openpgp
as an extension, but also maybe we should prefer .asc - despite .asc
having higher overhead - since it's a nicer file format to work
with in practical applications.
-- 
debian developer - deb.li/jak | jak-linux.org - free software dev
ubuntu core developer                              i speak de, en

[toc] | [next] | [standalone]


#1261113

FromGuillem Jover <guillem@debian.org>
Date2025-09-12 16:10 +0200
Message-ID<LucDn-eMty-11@gated-at.bofh.it>
In reply to#1261071
Hi!

On Fri, 2025-09-12 at 08:59:10 +0200, Julian Andres Klode wrote:
> On Wed, Aug 27, 2025 at 01:41:19PM +0200, Guillem Jover wrote:
> > On Sat, 2025-04-19 at 21:02:47 +0200, Julian Andres Klode wrote:
> > > So the .pgp extension is reserved for PGP messages, not keys.
> > > 
> > > This needs to be resolved by the IETF WG, and the change in the
> > > keyring package was premature.
> > > 
> > > The only file extension for keys is .asc for armored ones.
> > 
> > I think that to keep using .gpg is worse, because I don't think there's
> > even a MIME type for .gpg? At least none that I could see in the
> > /etc/mime.types anyway. For example file --mime-types returns the correct
> > thing anyway.
> > 
> > My take is that the MIME definition is not exhaustive, so I don't see a
> > conflict if it's "missing types". And my perception is that MIME types
> > get registered after demonstrated usage?

And to clarify, I think .pgp has pre-existing demonstrated usage, from
even before GnuPG was around.

> > Julian asked if file did application/pgp-keys for .pgp keys, and this
> > was my reply:
> > 
> >   $ file --mime-type /usr/share/keyrings/debian-archive-trixie-automatic.pgp
> >   /usr/share/keyrings/debian-archive-trixie-automatic.pgp: application/pgp-keys
> > 
> > It just checks the contents the same with a .gpg one for example:
> > 
> >   $ file --mime-type /usr/share/keyrings/debian-maintainers.gpg
> >   /usr/share/keyrings/debian-maintainers.gpg: application/pgp-keys
> > 
> > So I don't see much of a problem here, and I think it would be best if we
> > could move away from this naming pattern, as that entrenches GnuPG usage
> > as a synonym for OpenPGP which seems rather unfortunate.
> > 
> > And for example for the apt modernize stuff I think it would be great if
> > it could check whether the current pathname referred is a symlink and
> > then use that (or perhaps if the symlink target is named .pgp if you want
> > to be more specific).
> > 
> > Julian then replied that the code could be made to just look for a
> > .pgp first.
> 
> Now the uapi group standardized .openpgp as the file extension
> for keys in the 
> 
>     File Hierarchy for the Verification of OS Artifacts (VOA)
> 
> specification, but also specifies they must be ASCII armored,
> that is, they match our .asc extension.
> 
> So this of course begs the question of whether to support .openpgp
> as an extension, but also maybe we should prefer .asc - despite .asc
> having higher overhead - since it's a nicer file format to work
> with in practical applications.

I don't find the .openpgp extension choice to be great. It is very long,
it is going to be confusing alongside the pre-existing usage of .pgp for
binary artifacts, and it ignores the existing usage of .asc. I could
agree that «.asc» was not a great choice (given its potentially generic
naming), but I think it's pretty ubiquitously recognized as OpenPGP ASCII
Armor by now.

I'd rather we do not make this even more confusing. :/

Thanks,
Guillem

[toc] | [prev] | [next] | [standalone]


#1261129

From"Christian T. Steigies" <cts@debian.org>
Date2025-09-12 18:50 +0200
Message-ID<Luf8e-eNXk-21@gated-at.bofh.it>
In reply to#1261113
Hi,
On Fri, Sep 12, 2025 at 03:59:41PM +0200, Guillem Jover wrote:
> 
> I don't find the .openpgp extension choice to be great. It is very long,
> it is going to be confusing alongside the pre-existing usage of .pgp for
> binary artifacts, and it ignores the existing usage of .asc. I could
> agree that «.asc» was not a great choice (given its potentially generic
> naming), but I think it's pretty ubiquitously recognized as OpenPGP ASCII
> Armor by now.
> 
> I'd rather we do not make this even more confusing. :/

I agree. For someone who used PGP already in the previous millenium, .asc
obviously means ascii armor. But I don't really care what you chose, I
reported the bug only because the usage was inconsistent and I found it
confusing. I am sorry that this is wasting so much of your time.

thanks,
Christian

[toc] | [prev] | [next] | [standalone]


#1261639

FromChristoph Anton Mitterer <calestyo@scientia.org>
Date2025-09-16 03:20 +0200
Message-ID<Lvswp-fDwd-1@gated-at.bofh.it>
In reply to#1261129
Hey.

Just for the records:

I've just stumbled over:
https://datatracker.ietf.org/doc/draft-gallagher-openpgp-media-types/

Still a draft, obviously...

But AFAIU, that would add a .pgp extension (see Table 4 in chapter 5)
for un-armored OpenPGP packet sequences.


Cheers,
Chris.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web