RFC 9580 specifies most OpenPGP formats and mechanisms. Some of them have also been specified in earlier OpenPGP RFCs.
This document provides a rough overview of formats and mechanisms and their origin, and outlines implementation support.
The following set of formats and mechanisms is widely supported. It interoperates with all implementations of OpenPGP of the last many years.
Formats:
- Version 4 Keys
- Version 4 Signatures
- SEIPDv1 encryption
Algorithms:
- Asymmetric cryptography:
- EdDSA/ECDH over Curve 25519
- RSA
- Symmetric encryption: AES (128, 192 and 256)
- Hash algorithms: SHA-2 (SHA-256, SHA-384, SHA-512, SHA-224)
The following set of cryptographic algorithms is also long-established. However, these algorithms are less universally supported. They should probably only be produced if a specific need indicates their use.
Algorithms:
- Asymmetric cryptography:
- ECDSA/ECDH over NIST P 256, 384, 521 curves (originally from RFC 6337)
- ECDSA/ECDH over brainpool P256r1, P384r1, P512r1 curves (not currently available in rPGP)
- Symmetric encryption: Twofish, Camellia 128, 192 and 256 (RFC 5581)
The following set of formats and mechanisms is widely supported in most modern implementations of OpenPGP. Notably, however, GnuPG does not yet implement support for the new formats in RFC 9580. So interoperability of these formats and mechanisms is limited to the (large and growing) set of other implementations.
Formats:
- Version 6 Keys
- Version 6 Signatures
- SEIPDv2 encryption
Algorithms:
- EdDSA/ECDH with Curve 448
- AEAD encryption (in modes OCB, EAX and GCM)
- Hash algorithms: SHA-3 (SHA3-256, SHA3-512)
Note that RFC 9580 defines new algorithm ids and names for use of Curve 25519 with EdDSA and ECDH (the new algorithms are named "Ed25519" and "X25519" in RFC 9580). These new formats exist in parallel to the commonly used Curve 25519 formats, but with a much simpler wire format. The old variants are named "EdDSALegacy with Ed25519Legacy" and "ECDH with Curve25519Legacy" in RFC 9580.
While these newly specified OpenPGP algorithms don't use different cryptographic mechanisms, they are not interchangeable with the pre-existing ones.
RFC 9980 defines post-quantum algorithm extensions for OpenPGP.
- Asymmetric cryptography:
- ML-DSA-65+Ed25519, ML-DSA-87+Ed448 (hybrid signatures)
- SLH-DSA-SHAKE 128s, 128f, 256s (hash-based signature scheme)
- ML-KEM-768+X25519, ML-KEM-1024+X448 (hybrid encryption)
Of these, ML-KEM-768+X25519 keys may be used as encryption subkeys of v4 keys. All other of the PQC algorithms may only be used in v6 OpenPGP keys.
rPGP implements full support for RFC 9980, feature-gated as pqc.
These formats and algorithms should not be produced anymore. However, under some circumstances it may be useful and appropriate to read existing artifacts, and interact with them. Note that in some cases interacting with legacy artifacts may require additional caution!
Formats:
- Version 2/3 Keys
- Version 2/3 Signatures
- SED encryption format
Algorithms:
- Asymmetric cryptography:
- DSA (especially with small key sizes)
- RSA with small key sizes
- Elgamal encryption (not supported by rPGP)
- Symmetric encryption: IDEA, DES, CAST5, Blowfish
- Hash algorithms: MD5, SHA-1 and RIPEMD-160
- ECDSA/ECDH over Secp256k1
- GnuPG's "OCB" encryption (rPGP has read-only support for this format)
- ASCII armoring
- Cleartext signature framework