[149167] in cryptography@c2.net mail archive
[Cryptography] Does PGP use sign-then-encrypt or encrypt-then-sign?
daemon@ATHENA.MIT.EDU (Stephan Neuhaus)
Tue Jan 21 13:38:18 2014
X-Original-To: cryptography@metzdowd.com
Date: Tue, 21 Jan 2014 17:01:35 +0100
From: Stephan Neuhaus <stephan.neuhaus@tik.ee.ethz.ch>
To: cryptography@metzdowd.com
Errors-To: cryptography-bounces+crypto.discuss=bloom-picayune.mit.edu@metzdowd.com
Dear list,
I'll be darned if I can find in RFC4880 how to do both encryption and
signature in OpenPGP. Knowing that both naively doing sign-then-encrypt
and encrypt-then-sign have their problems, surely it can't be that,
right? So what *is* actually happening in OpenPGP? And where does it
say that in the RFC?
Fun,
Stephan
_______________________________________________
The cryptography mailing list
cryptography@metzdowd.com
http://www.metzdowd.com/mailman/listinfo/cryptography