ietf-openpgp
[Top] [All Lists]

Re: [openpgp] A way to securely define cleartext signature charset

2018-09-08 13:27:53
Hi,

On Saturday, September 8, 2018 4:43:25 PM CEST Marcus Brinkmann wrote:
Why not a hashed signature subpacket?

Mostly because in an Application you can already use the information from the 
header before you do any OpenPGP parsing / signature verification.

E.g. in a MUA you usually want to show the data while you are verifying the 
signature. A charset Header could be easily parsed by a MUA and taken as a 
suggestion how to present the data.

There might also be the case where you know the charset was changed in 
transfer and you have to convert the charset back to get the correct 
bytestream that matches the signature before passing it to your OpenPGP 
backend.

That is not to say that I'm totally against a subpacket, if the correct 
charset would be known after verification / parsing it would also help.

Best Regards,
Andre

-- 
Andre Heinecke |  ++49-541-335083-262  | http://www.intevation.de/
Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998
Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner

Attachment: signature.asc
Description: This is a digitally signed message part.

_______________________________________________
openpgp mailing list
openpgp(_at_)ietf(_dot_)org
https://www.ietf.org/mailman/listinfo/openpgp