ietf-openpgp
[Top] [All Lists]

Re: Question about MDC Packets

2002-07-22 12:48:57

On 7/22/02 12:10 PM, "Len Sassaman" <rabbi(_at_)quickie(_dot_)net> wrote:

In RFC 2440-bis5:5.13, it says:

 There is a corresponding feature in the features signature subpacket
 that denotes that an implementation can properly use this packet
 type. An implementation SHOULD NOT use this packet when encrypting
 to a recipient that does not state it can use this packet, and
 SHOULD prefer this to older Symmetrically Encrypted Data Packet when
 possible.

This doesn't, however, give any indication of what to do when using pure
symmetric encryption. What is the preferred behavior when symmetrically
encrypting a file using AES? Should an OpenPGP implementation use the MDC
by default?

Do you know anything about who is going to be decrypting it? Do you have
some reasonable expectation they can understand it? If so, then yes.

There is nothing wrong with an implementation being somewhat weasely. If you
make the guess that if someone wants to use AES, then the target is modern
enough to understand an MDC, you'd probably be right. You could even
convincingly harumph if someone does *not* use an MDC but went to the
trouble to do AES.

Incidentally, it's important that people start using MDCs more.

    Jon


<Prev in Thread] Current Thread [Next in Thread>