Re: Digital signature in muLinux - tests wanted

From: Lars.Nordstrom@abc.se
Date: Tue Nov 07 2000 - 04:38:57 CET


  
-----BEGIN PGP SIGNED MESSAGE-----

  
Hello.

On 2000-11-06 mulinux@sunsite.auc.dk said:

 mu>So, if someone is able to extract my public-key from the 2th
 mu>message, it is also able to decifrate the 1th message. In this
 mu>case, please, resent the 1th message in clear-text on the list.

Sorry I have to say this but you have got everything exactly
backwards. :-)

I can't decrypt this message. PGP beeps loudly at me and says:

>File is encrypted. Secret key is required to read it.
>This message can only be read by:
> Michele Andreoli <m.andreoli@tin.it>
>
>You do not have the secret key needed to decrypt this file.
>
>For a usage summary, type: pgp -h
>For more detailed help, consult the PGP User's Guide.

Your _public_ key is used to encrypt messages to you and then
you decrypt it with your _secret_ key.

The public key can also be used by me to verify your PGP
signature on a message.

So, if you want to send me an encrypted message:

Encrypt it with my public key.
Sign it with your secret key.

To read it I must:
Verify your signature with your public key.
Decrypt it with my secret key.

I will sign this message and send my public key in a separate
message to the list so you can verify my signature. If you want,
you can also encrypt and send a message directly to me using my
public key. If you sign it with your secret key I can verify
your signature with the key you sent to the list.

I will also encrypt this message with your public key and send
it to the list. You can then decrypt it and compare the two.

There are some issues with mail readers and PGP that I perhaps
can help you with. There can be some trouble with charsets and
transfer encoding and such.

I do hope the key you sent to the list is only for testing
purposes. A 512 bit key is considered by many to be low
security. 1024 or, better, 2048 bits should be used for a
"production" key.

Thank goodness you didn't send your secret key to the list!!!!

Regards,
Lars

DANGER DANGER Computer store ahead...hide wallet.

Net-Tamer V 1.10.1 - Registered

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: cp850
Comment: Requires PGP version 2.6 or later.

iQEVAgUBOgdMtWOz1ftDd91ZAQFSTggAqNdYf2gQDLNp+NNvQsUZ84fKT7iSWprQ
X9EwqSADzGr9q4132q9XuBZ3XdE5yQL8SnVATqBKOimOadAbwuZgk7Z1dOGQrskK
n7ogVBv2f5W5a+Tpf3GtyLpDlFLV1qsL4u9OHbRYJhzIYGtmtiSp0is88+oC+HBt
TpaM+0QrkIS2pBHcJxb9wbuMrnSUR1gs4omhVWEBU3rQNO+aBV2wsoIldVu2su2Z
S0Aey0/gfg6FJntCNziF6DdUczDsumDnlv2UWFd4mcmVJW1oZwTLJyh4K2Qeiwez
xEu4zgn14zB1V5HPUxWnEvXTDAzo9/iy76IW9hHz8vmTVgM243MH3A==
=HCM4
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: mulinux-unsubscribe@sunsite.auc.dk
For additional commands, e-mail: mulinux-help@sunsite.auc.dk



This archive was generated by hypermail 2.1.6 : Sat Feb 08 2003 - 15:27:16 CET