[Enigmail] PGP indicates enigmail signed messages are invalid

Faramir faramir.cl at gmail.com
Mon Apr 13 01:26:37 PDT 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Moonchild escribió:
> John Clizbe wrote:

> So, it just means I've never run into anyone so far who uses RFC4880
> encryption/signing, with all the contacts I have ;-)

  All my regular contacts are RFC4880 compliant...

> I do like to note I have been using my existing (IDEA) cypher keys to
> sign and encrypt without any additional DLL installed with GnuPG. So
> IDEA is supported. I was wondering about that when I installed
> Enigmail/GnuPG as I knew some algorhythms were not used by the open
> source solutions by default, but everything worked.

  I think if IDEA algorithm is not available, GPG uses 3DES... I never
fully understood that part...


> Maybe so, but like I said in my current situation I need full backwards
> compatibility. I don't see being restricted to IDEA, 3DES and CAST5 and
> the hashes MD5, SHA1 and RIPEMD160 as much of a restriction. Apparently,
> all my peers so far have used these cyphers and hashes as well. (weren't
> those good enough, or what?)

  Yes, but MD5 was considered secure some years ago, now it's not
considered secure anymore, and SHA1 seems to be going on the same
road... of course it's not something anybody can do (probably, very few
people can forge a signature made with MD5), but... the idea is to move
before the status reaches the "woman and children goes first" level...

  Best Regards
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iQEcBAEBCAAGBQJJ4vc9AAoJEMV4f6PvczxAuwQH/jJCcWFgMsNEDWAAjUZCWuUa
G+bYwjCBZBkmaS7SY82AS94XVsJIqNIodcRk7ddtYxZfCM5RIpfg9qRxgJVSK4xy
qjzduNorJZ5+OmHJgSurMHnLxYLcrXy858HQnHzRmxqLYf9XazI046y9H/ECAt+7
7XVYbdkOk1pukex0JvQvLtWYuPjunShwAzLp7pVHil8Cf4BzFPZpXD6jjSbluUyA
kG6cJZJjCi0yDCDYFkx5LhWY/2YzELB/rrP6bw7Uia1cn5RRSUlrwqIQTZ+XMalX
KAEWRndDq8E190cVqEnsDtr8ee2GcfoZUiU7inD2aUnLe54KFKnL2DDAdwhBfWU=
=Si39
-----END PGP SIGNATURE-----


More information about the Enigmail mailing list