ietf-openpgp
[Top] [All Lists]

Re: Short intro on the K-R attack [Re: private key language]

2005-12-30 06:04:49

Jon Callas wrote:
* There must therefore be some security consideration note that calls
out that implementations need to do consistency checks on keys,
particularly when signing.

I propose that we improve the packets when we do V5, but put in the
security consideration now. Does that sound reasonable?

Yes.

-- 
http://www.apache-ssl.org/ben.html       http://www.thebunker.net/

"There is no limit to what a man can do or how far he can go if he
doesn't mind who gets the credit." - Robert Woodruff