ietf-openpgp
[Top] [All Lists]

Re: WG Last Call: draft-ietf-openpgp-formats

1998-06-25 15:50:45

Re the last call:

A few minor queries someone might like to comment on, this one I think
is still not resolved:

- Gary Howlands attack which can undetectably garble unsigned
  encrypted messages ... has this was been fixed?

  If not perhaps we could either fix it (include optional? unsigned
  digest inside message) or have wording added to highlight that
  unsigned encrypted messages offer little protection against garbling.

Also:

- Is it defined that an implementation would keep processing packets
  until it gets to a terminal packet (terminal packets being
  literal packets, or the text of a clear signed message)?

  This is important as it allows super-encryption, and allows
  encrypted messages to contain clear signed messages (which William
  Geiger uses) plus it would be useful for experimental combinations
  people may use.

Adam

<Prev in Thread] Current Thread [Next in Thread>