6.0.0-beta1
▾
Tasks
New Task
Search
Photos
Wiki
▾
Tickets
New Ticket
Search
dev.horde.org
Toggle Alerts Log
Help
8/2/25
H
istory
A
ttachments
C
omment
W
atch
Download
Comment on [#3498] PGP and message verification
*
Your Email Address
*
Spam protection
Enter the letters below:
..__.. .. , . || ||\/| \./ | \__||__|| | | \__|
Comment
>> If I get a PGP signed message where the sender or from address is not > >> the one or one to wich the sinature belongs, IMP still tells me "The > >> message has been verified." > >> Shouldn't it complain that the from address does not match the signature? > > > > No it shouldnt - actually its more a philosopical question then a > security question. > > > > I give you SMIME for example, SMIME v2 said - email and certificate > email must match. SMIME v3 says, its no longer required. > > > > The big plus for PGP was always that you are not bound to the > certificate email address (for encrypting i.e.) > > > > To return to your original question - lets assume you have a group > account with multiple members but only the pgp signing key for the > group itself (lets say support) do you think that the signature is > invalid just because it was send by joe average from the support > group ? No. generally speaking - everyone who has the secret key is > normally authorized to sign a message no matter which email address > he uses > >
Attachment
Watch this ticket
N
ew Ticket
M
y Tickets
S
earch
Q
uery Builder
R
eports
Saved Queries
Open Bugs
Bugs waiting for Feedback
Open Bugs in Releases
Open Enhancements
Enhancements waiting for Feedback
Bugs with Patches
Enhancements with Patches
Release Showstoppers
Stalled Tickets
New Tickets
Horde 5 Showstoppers