@techreport{autocrypt-openpgp-v2-cert-03, number = {draft-autocrypt-openpgp-v2-cert-03}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-autocrypt-openpgp-v2-cert/03/}, author = {Daniel Kahn Gillmor and Holger Krekel and Friedel Ziegelmayer}, title = {{Autocrypt v2 OpenPGP Certificates and Transferable Secret Keys}}, pagetotal = 49, year = 2026, month = jul, day = 6, abstract = {This document describes the "Autocrypt v2 Certificate", a standard structure for an OpenPGP certificate for Internet messaging. It offers defense against store-now-decrypt-later attacks from quantum computers through post-quantum hybrid cryptography. It also enables reliable deletion ("Forward Secrecy") of received messages even when adversaries capture encrypted messages in transit and later compromise the user's message archive and secret keys. The design uses deterministically ratcheted rotating encryption subkeys with predictable expiration combined with coordinated secret key material destruction. This document also describes the structure, use, and maintenance of the OpenPGP Transferable Secret Key that corresponds with the Autocrypt v2 Certificate.}, }