Re: PGP security models, was Summary of IETF LC for draft-ietf-dane-openpgpkey

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Simon Josefsson wrote:
>Tony Finch <dot@xxxxxxxx> writes:
>> The user should notice this since their encrypted mail will appear to come
>> from their mail provider not from the sender. (PGP signature doesn't
>> match 822 From:)
>
>Not really -- OpenPGP does not reveal anything about the identity of the
>encrypting entity.  If the mail provider signed the email, it would be
>noticeable, but there is no requirement to sign encrypted emails.

This can be solved by having the sender also sign the key used to encrypt
the e-mail. No idea how much work it is to add this.





[Index of Archives]     [IETF Annoucements]     [IETF]     [IP Storage]     [Yosemite News]     [Linux SCTP]     [Linux Newbies]     [Fedora Users]