Re: Can I revitalise an old key-pair?

2013-09-01 Thread John Clizbe
Pete Stephenson wrote: > On Sun, Sep 1, 2013 at 2:57 PM, MartinHvidberg wrote: >> Or do I need to get one of my old computers up and running, hoping to find >> some sort of key file there. > > If you go through your old systems and are able to find the relevant > secret key files or the GPG/PGP k

Re: Recommended key size for life long key

2013-09-09 Thread John Clizbe
; guesses, and the ultimate result would be an awful lot of confusion. A > great deal of heat and very little light. > > > [3] These guesses are completely made up, and I'm just using the names > of random people within the community. And Rob's friend, John Clizbe, has

Re: GPG and Outlook revisited

2013-09-09 Thread John Clizbe
Chris De Young wrote: > Hello, > > It's been some time since I looked at options for integrating GPG and > Outlook on Windows, and at the time there seemed to be no particularly > good solutions. GPG4Win/Enigmail/Thunderbird works great for my personal > use, but work mandates Outlook, and in l

Re: Fedora GPG Key Server

2013-09-09 Thread John Clizbe
Marcio B. Jr. wrote: > On Sat, Sep 7, 2013 at 7:28 AM, Werner Koch wrote: >> On Thu, 5 Sep 2013 22:22, marcio.barb...@gmail.com said: >>> https://lists.fedoraproject.org/pipermail/announce/2013-September/003180.html >> >> Please do not post a mere link. This assume that everyone is online and >>

Re: Signature timestamp ordering and dissecting

2013-09-18 Thread John Clizbe
kwadronaut wrote: > Hi, > > Up until now, I always see signatures on a key ordered in chronological > fashion, with GnuPG, sks' web interface and enigmail. It's always in a > format with day, month and year (sometimes year-month-day or another > format of that data). Now I'm curious to see when a

Re: CryptoList - Looking for beta testers

2013-09-22 Thread John Clizbe
Kenneth Jones wrote: > Hmmm... Last two messages from Daniel prompt my Thunderbird/Enigmail setup > that an OpenPGP secret key is needed to decrypt the message (which nonetheless > shows up in cleartext). What's happening? Is it signed with a public key? Can > you do that? Why would one wnt to? >

Re: OpenPGP Smartcard + signing email = two signatures?

2013-10-11 Thread John Clizbe
Pete Stephenson wrote: > Hi all, > > I use Thunderbird, Enigmail, and GnuPG on Windows 7 (among others). > > I have my primary cert/sign key on one smartcard and two subkeys > (signature + encryption) on another. I have the "force signature PIN" > option enabled for both cards. > > Tonight I was

Re: Selecting your own key with Enigmail

2013-10-23 Thread John Clizbe
Johan Wevers wrote: > On 23-10-2013 2:26, Olav Seyfarth wrote: > >> have you set your key HERE : >> https://www.enigmail.net/documentation/per-account.php ? > > Ah, not for this mail address. Thanks, I had not found this option. > Testing the signature now. OpenPGP menu --> Preferences. Click [

Re: add a request for advocating crypto to the crypto tools

2013-10-23 Thread John Clizbe
Hauke Laging wrote: > Hello, > > due to its rather little visibility for the average user this affects GnuPG > less than its GUIs (the mail clients in particular). It may well be used in > the GnuPG documentation (man, info, www). But I assume that many GUI (or more > general: crypto tool) deve

Re: trying to find a folder

2014-01-28 Thread John Clizbe
fa-ml wrote: > On Fri, Jan 24, 2014 at 04:37:11PM -0800, Justin Quakenbush wrote: >> wheres my gnupg folder? >> > > Have you tried checking 'man gpg' (search for 'FILES')? It should be > ~/.gnupg/ , echo $GNUPGHOME to make sure. GNUPGHOME isn't set by default. It is for overriding the default loc

Re: trying to find a folder

2014-01-28 Thread John Clizbe
Justin Quakenbush wrote: > wheres my gnupg folder? On Mac OS X (you're using Applemail) and other *nix platforms, it is ~/.gnupg, which is a shortcut for $HOME/.gnupg. A directory named .gnupg in your main user folder. Since the name begins with '.' it is normally hid from Finder and other file ma

Re: It's 2014. Are we there yet?

2014-04-10 Thread John Clizbe
or so this subject comes up, and my answers are unchanged > from last time: start by reading up on academic papers studying this > exact problem. For a while John Clizbe and I kept a list of good > papers, but I have to confess I haven't been keeping up on the latest > literature. Still,

Re: It's 2014. Are we there yet?

2014-04-14 Thread John Clizbe
gt; from last time: start by reading up on academic papers studying this > exact problem. For a while John Clizbe and I kept a list of good > papers, but I have to confess I haven't been keeping up on the latest > literature. Still, our last list is pretty good reading. > >

Re: adele

2014-06-11 Thread John Clizbe
Robert J. Hansen wrote: >>> Is there a source code or a recipe available somewhere? Is it written in >> >> Not that I know. > > I believe John Clizbe has a copy of the Adele source code. I still have the copy from when the Enigmail team translated to message file

Re: Docs central, with 'Email Self-Defence'

2014-06-15 Thread John Clizbe
Kristy Chambers wrote: > Although some people would probably deny, that it's not the job > gnupg.org to provide a good tutorial about using gpg for e-mail-security > with some other gpg-related software like Enigmail+Thunderbird, I would > really appreciate it. Bad tutorials on the web reaffirm my

Re: riseup.net OpenPGP Best Practices article

2014-06-26 Thread John Clizbe
Robert J. Hansen wrote: >> Even if they did intercept them, are the Americans any good at >> interrogating a horse? > > Yes. We are world champions at beating dead horses. To interrogate a > horse, first simply shoot it in the head, and then we can leverage our > dead-horse-beating skills in ord

Re: On the advisability of stronger digests than SHA-1 in OpenPGP certifications [was: Re: riseup.net OpenPGP Best Practices article]

2014-06-27 Thread John Clizbe
Kristian Fiskerstrand wrote: > On 06/27/2014 03:54 PM, shm...@riseup.net wrote: > > >> Robert J. Hansen: >>> On 6/26/2014 5:57 PM, Daniel Kahn Gillmor wrote: PGP 8 was released over a decade ago, that's hardly a modern implementation: >>> >>> And yet, it still conforms (largely) to RF

Re: New to OpenPGP getting frustrated.

2014-06-28 Thread John Clizbe
Aaron Chelf wrote: > Okay so I'm using Open PGP software in conjunction with Thunderbird in > Linux. I've figured out about everything except the only way I can add > public keys to my key ring so far is to save them as an attachment from > an e-mail sent to me. > How can I just copy a public key

Fwd: [Enigmail] [ANN] Enigmail v1.7 available

2014-07-19 Thread John Clizbe
As there are many Enigmail users who read this list, but not [Enigmail], I'm forwarding the announcement of the newest release of Enigmail, v1.7. There are quite a few changes in this release. As Patrick writes in the announcement: > As usually, it will take up to two weeks until the version will

Re: Thoughts on Keybase

2015-01-07 Thread John Clizbe
Robert J. Hansen wrote: > Keybase (https://keybase.io) is trying to solve the Web of Trust problem > in a new way. They're currently in beta, but I was able to snag an > invitation. (I have no invites to give out, unfortunately.) The > following is just a write-up on how it works and what my

Re: Thoughts on Keybase

2015-01-07 Thread John Clizbe
John Clizbe wrote: > Does look interesting. Anyone have and willing to share an invite? > > Reply off-list please. > Invite received. Thanks to those who offered. -J -- John P. Clizbe Inet: John (a) Gingerbear DAWT net SKS/Enigmail/PGP-EKP

Re: GPG Shell works but GnuPG commands fail - UPDATE

2009-03-02 Thread John Clizbe
HORNBOSTEL, LIBBY A (ATTSI) wrote: > Many hours of tinkering has given me a solution. > > Although I haven't found an explanation for why the GPA product throws a > fatal error, I have conquered getting the GnuPG commands to work. I > found that the order of the commands and options are significa

Re: surrendering one's passphrase to authorities

2009-03-03 Thread John Clizbe
gerry_lowry (alliston ontario canada) wrote: > unfortunately, it's likely that certain countries handle this using torture. Folks on this list have said for years that rubber-hose key extraction is orders of magnitude faster than brute-force computation. -- John P. Clizbe In

Re: surrendering one's passphrase to authorities

2009-03-04 Thread John Clizbe
gerry_lowry (alliston ontario canada) wrote: > on vedaal's laptop design ... > > [5] marry the drive to the motherboard so that removing the drive > to another computer would cause the drive to self destruct. > > [6] design the drive as a secondary only never bootable drive; >

Re: GnuPG and Windows XP Home

2009-03-16 Thread John Clizbe
Alf Wernersson wrote: > I'm trying to install GPG on my Laptop running XP Home. After the > install process I run CMD and write "GPG --version". This seems to be > OK. After that I write "GPG --list-keys and receive following message: > Does not GPG4win support Windows XP? Any suggestions? I have

Re: Using GPG exported key

2009-04-01 Thread John Clizbe
Joao Paulo Fernandes wrote: > Hi everyboby, > > Im exporting my gpg key from my unix server > gpg --armor --output "key.txt" --export myserver > > i import the key.txt in other computer > gpg --import key.txt > > i trust ultimately the myserver key with --edit-key > but i still get the error wh

Re: Etiquette for other people's signatures in responses

2009-04-08 Thread John Clizbe
Brian Mearns wrote: > Hey, I'm relatively new to PGP and I just wanted to get some feedback > on the proper etiquette for quoting signed messages in responses. > Clearly, it's inappropriate to edit a person's response if they're > signed it, but is it considered rude to remove their signature from

Re: Files to Backup

2009-04-11 Thread John Clizbe
Mike -- EMAIL IGNORED wrote: > > Thanks for this. This auto-key retrieval sounds like something > I would like to disable. Is there a way to do that? Not turning it on would seem like an obvious solution. It's not on by default. It allows GnuPG to automatically search and fetch keys needed to

Re: Keyserver doesn't honour signature removal

2009-04-12 Thread John Clizbe
Dominik George wrote: > due to dome issues, I have pretty many signatures on my key that I don't > want (or need) anymore. I can remove them locally, but when sending the > key to the keyserver afterwards, the changes are just ignored. That is correct, by design keyservers are merge only. It preve

Re: hi

2009-04-14 Thread John Clizbe
legal wrote: > hi, > > I am having trouble uploading the my public key to the keyserver. > > thanks > elias You'll need to be a bit more specific for anyone to offer meaningful assistance. At this point, all anyone could do is speculate. Is this an Enigmail issue or a GnuPG issue? No way for us

Re: keyservers

2009-04-20 Thread John Clizbe
Alexander Ulrich wrote: > Hashimoto writes: >>The key posted in one keyserver will be synchronized with all of the >>other > > Yes. Normally within a hour or two. The SKS keyservers use a very fast and efficient protocol to exchange updates. Updates are emailed to other keyservers runni

Re: OpenPGP digital signature query

2009-04-20 Thread John Clizbe
Darshan Jain wrote: > Can OpenPGP digital signature be used to comply to FDA's 21 CFR Part 11 > , or does it mandatorally require X.509 or PKI based signatures > > http://en.wikipedia.org/wiki/Title_21_CFR_Part_11 You check the DHHS HIPAA page, http://www.hhs.gov/ocr/hipaa/ ? Might be a bit more

Re: Further thoughts on Windows Install

2009-04-21 Thread John Clizbe
david wrote: > Hi All, > > installing GnuPG Enigmail on pro 2000 I have to import files from this > linux laptop - are file conventions the same? At present. This may change in some future version of GnuPG > (a) put linux hard drive on usb and scan for keys public and private via > enigmail or g

Re: Just a thought

2009-04-25 Thread John Clizbe
david wrote: > Hi all, > > Late here in Cyprus, in Thunderbird, OpenPGP I can sign and encrypt - > but say I cc'd to a few people - because if those people are in my key > ring will it encrypt for each? If a valid key can be located for each recipient, the message will be encrypted to all. If a s

Re: Just a thought

2009-04-25 Thread John Clizbe
Ingo Klöcker wrote: > On Saturday 25 April 2009, John Clizbe wrote: >> >> The message will be encrypted once with a symmetric cipher and >> session key. Then the session key is encrypted to each recipient's >> public key and the encrypted session keys are attached t

Re: Just a thought

2009-04-26 Thread John Clizbe
David Shaw wrote: > On Apr 25, 2009, at 6:14 PM, John Clizbe wrote: >> >> Enigmail passes GnuPG a list of recipients to encrypt to. It does not >> generate separate messages, only the one. This is a constraint of >> Thunderbird's architecture. >> >>

Re: WinPT & Enigmail don't show the same keys

2009-04-29 Thread John Clizbe
Joel C. Salomon wrote: > John W. Moore III wrote: >> Joel C. Salomon wrote: >> > I was under the impression that GnuPG kept track of everything, but I >> > noticed that Windows Privacy Tray and Enigmail do not always show the >> > same keys. >> > Can someone explain to me what's going on with my s

Re: Looking for a good port80 static-DNS keyserver

2009-04-29 Thread John Clizbe
Brian Mearns wrote: > > Thanks, John. I was unaware of the status page, I think that will be > helpful. I'm not sure offhand which servers have been "buggy", but I > believe I've connected to http://keys.gnupg.net/ in the past and been > presented with a blank page, for instance. Not all servers p

Re: questions: no input file, and pascal programming

2009-05-01 Thread John Clizbe
Philip wrote: > Hi > I have some questions about gpg > 1. using gpg command line, can I pass data to be encrypted to gpg that > isn't in a file? For example if I want to encrypt "Mary had a little > lamb" to a an asc file but I don't want to put that text onto the hard > drive unencrypted first.

Re: problems with http://www.gnupg.org

2009-05-05 Thread John Clizbe
Philip wrote: > all the links from http://www.gnupg.org/docs.html are dead > for example > http://www.gnupg.org/howtos.en.html > 404 Not Found > The requested URL /howtos.en.html was not found on this server. > > I tried to email the webmaster but the email is bouncing > > I can't access http://w

Re: Use GPG to create encrypted files readable by PGP

2009-05-06 Thread John Clizbe
gpg2.20.mani...@dfgh.net wrote: > Dear Members : > Could you (or the list ) help me with the following : > - I have an source xl file - say something dot xls > - I wish to encrypt this and the recipient is say Mr. Y > - I wish to have an encrypted result file that is recognized and > readable by

Re: delete bad UID from key on keyserver?

2009-05-08 Thread John Clizbe
Anonymous Remailer wrote: > Hi, > > One of my email accounts is unusable so I deleted the UID from my key > and uploaded it to the keyserver. That accomplished nothing so now I > figured out I should of invalidated the UID and then uploaded it. I > can't do that now because I deleted the UID from

Re: Photo's in keys?

2009-05-14 Thread John Clizbe
Allen Schultz wrote: > RE: including a photo uid, which is commonly stripped by public > keyservers (http://fifthhorseman.net/key-transition-2007-06-15.txt) > > Are there any limits on the photo in the keys, format/extension, > size, etc? Will GPG resize if necessary? And the basic command > to ad

Re: RSA+RSA is now the default

2009-05-25 Thread John Clizbe
Nicholas Cole wrote: > It's a small point and I don't mean to get side-tracked, but if any > front-ends have used this menu, I rather fear that you have replaced > one evil (not using the right default) with a worse one - presenting > one thing in the front end and doing another behind the scenes!

Re: GnuPG Win Patch File Installation Help

2009-05-25 Thread John Clizbe
shrzic0973 wrote: > I'm a new user to GnuPG. I just installed GnuPG 1.4.9. I see there is > also a Patch File 'gnupg-1.4.8-1.4.9.diff.bz2' with this release that > needs to be installed but I cannot find any information on how to do this. > Can someone provide the correct procedures to install this

Re: how to sign files inside a folder?

2009-05-26 Thread John Clizbe
Faramir wrote: > Hello, > I saw a question in the support list in Spanish language, and it is > about how to sign files inside a folder, in Windows OS, without using > additional tools. The goal is to have a tree of folders, with files > inside, and to sign individually each file (with detach

Re: how to sign files inside a folder?

2009-05-26 Thread John Clizbe
John Clizbe wrote: > Faramir wrote: >> Hello, >> I saw a question in the support list in Spanish language, and it is >> about how to sign files inside a folder, in Windows OS, without using >> additional tools. The goal is to have a tree of folders, with f

Re: Security Concern: Unsigned Windows Executable

2009-06-02 Thread John Clizbe
Doug Bateman wrote: > I challenged myself to verify all software that I download on my new > machine is verified and signed. Sadly, Win-GnuPG let me down. Heres why. What's Win-GnuPG? Are you referring to the windows installer build of GnuPG from http://www.gnupg.org/download/ as such? It's just

Re: gpgshell and gnupg 2.x?

2009-06-04 Thread John Clizbe
Allen Schultz wrote: > Couple of questions. Is there a mailing list for gpgshell? Not that I know of. > If not, Does GPGShell support gnupg 2.x? Maybe? But why should it? Everything OpenPGP related is provided by GnuPG 1.4. GnuPG's added X.509 functions aren't needed by GPGshell. There still

Re: Security Concern: Unsigned Windows Executable

2009-06-12 Thread John Clizbe
Doug Bateman wrote: > Here's an interesting question why does GnuPG.org bother providing a > GPG signature with it's downloaded files? To check the integrity and authenticity of the downloaded file? Not everyone is bootstrapping GnuPG onto a new machine or even using Windows. > So this raises

Re: GnuPG 2 under Windows

2009-06-19 Thread John Clizbe
Joel C. Salomon wrote: > Is a build of GnuPG more recent that 1.4.9 available for Windows? Not sure why there would be. 1.4.9 is the latest release of the 1.4-STABLE branch. What is it you're looking for? Current development snapshots of what will be 1.4.10 may be built for use on Windows, but it

Re: GnuPG 2 under Windows

2009-06-21 Thread John Clizbe
Joel C. Salomon wrote: > Joel C. Salomon wrote: >> Is a build of GnuPG more recent than 1.4.9 available for Windows? > > To rephrase my question /per/ the subject line: Is there a build of > GnuPG 2 available for Windows? Putting the question you wish answered in the /message body/ is usually th

Re: "Signature verification failed"

2009-06-21 Thread John Clizbe
Joel C. Salomon wrote: > I’m using Thunderbird 2.0.0.21 + Enigmail 0.95.7 (20080808) with GnuPG > 1.4.9 under Windows. On some messages (e.g., this recent one from > Thomas Bohn: ) I get > the message, “Error - signature verification failed; click Pen icon for > details”. The error message from G

Re: "Signature verification failed"

2009-06-22 Thread John Clizbe
Joel C. Salomon wrote: > Michel Messerschmidt wrote: >> Hm, I get a good signature here: > > Ingo Klöcker wrote: >> Same here (using KMail): >> Message was signed by tho...@bohnomat.de (Key ID: 0x61C7F5B569274BBB). >> The signature is valid, but the key's validity is unknown. > > Hmm and double h

Re: Exposing email addresses on key servers

2009-06-29 Thread John Clizbe
Daniel Kahn Gillmor wrote: > On 06/29/2009 07:27 PM, reynt0 wrote: >> I guess WK's comment is about complete strangers sending you >> email? > > I think that wasn't his point. I think Werner's point was that when > people send encrypted mail, they use a mail user agent (e.g. thunderbird > with en

Re: 8192bit RSA keys

2009-07-10 Thread John Clizbe
Werner Koch wrote: > On Fri, 10 Jul 2009 04:57, joelcsalo...@gmail.com said: >> martin f krafft wrote: >>> ... 8192bit [keys]. >> >> http://xkcd.com/538/ > > No need to remember that URL; the online help tells you ;-) > OK then. How about /this/ one to illustrate >= 8k RSA keys in practical ter

Re: Setting up SKS Keyserver

2009-08-11 Thread John Clizbe
Sebastian Wiesinger wrote: > Hi, > > I'm thinking about setting up an SKS Keyserver. My question is, is > there some sort of mailinglist or something where this is ontopic? The sks-devel mailing list, see http://lists.nongnu.org/mailman/listinfo/sks-devel for subscription info > As I understand

Re: 1.4.10rc1 vs. OS X 10.6

2009-09-01 Thread John Clizbe
Joseph Oreste Bruni wrote: > I tried compiling 1.4.10rc1 on Mac OS X 10.6 without success. > > During "make" the compile bombed here: > > ... > mv -f .deps/mpih-mul.Tpo .deps/mpih-mul.Po > gcc -DHAVE_CONFIG_H -I. -I.. -I.. -I../include-g -O2 -Wall -Wno- > pointer-sign -MT mpiutil.o -MD -MP -

Re: Question about GnuPG Shell 1.0

2009-09-18 Thread John Clizbe
Csabi wrote: > Hello, > > I have Windows XP with GnuPG 1.4.9 installed. > I wanted to install GNUPG Shell 1.0 but when i clicked to "install" > > GPG Shell works fine but i would like to try the GnuPG Shell. > > Do You have any idea to resolve the problem? Have you asked on GnuPG Shell's supp

Re: Question about GnuPG Shell 1.0

2009-09-19 Thread John Clizbe
Allen Schultz wrote: > Csabi wrote: >> I have Windows XP with GnuPG 1.4.9 installed. > ... >> GnuPG not installed on your system. Please, install it first. > > Have you set the System PATH and then tried the installation again? Is > it possible GPG Shell uses PATH and other windows settings for lo

Re: Question about GnuPG Shell 1.0

2009-09-19 Thread John Clizbe
John Clizbe wrote: > Allen Schultz wrote: >> Csabi wrote: >>> I have Windows XP with GnuPG 1.4.9 installed. >> ... >>> GnuPG not installed on your system. Please, install it first. >> >> Have you set the System PATH and then tried the installation aga

Re: choosing an encryption target from a User ID

2009-09-22 Thread John Clizbe
Daniel Kahn Gillmor wrote: > when encrypting messages to a user ID with multiple matching keys with > full calculated validity, gpg seems to just choose the "first" matching > key, for some definition of "first" -- i think it's decided by > chronological age of first import into the local keyring.

Re: Details of signature verification status-fd lines

2009-09-23 Thread John Clizbe
Werner Koch wrote: > On Wed, 23 Sep 2009 16:16, bmea...@ieee.org said: > >> By the way, are there any python or PHP bindings for GPGME? > > Yes, there are several of them and we should really compile a list of > them or actually add them to the distribution. It would be a huge help if added to t

Re: No secret key under different account

2009-10-30 Thread John Clizbe
David Gray wrote: > > Hi, > Thanks for the info, that makes sense. > > That does however mean that I will end up with two sets of keyring files, > does anyone know a way to share them to certain priv'd users on a server. Add the extra keyring(s) with 'keyring ' or 'secret-keyring ' line(s) in

Re: Using single subkey for both signing and encryption?

2009-11-01 Thread John Clizbe
gpg.me...@spamgourmet.com wrote: > Hi, I just have a basic question about subkeys. When I create an RSA > subkey I only have the option to create one for signing or encryption, > not both. Why is that? There's nothing different about the keys > themselves, is there? Is there supposed to be some

Re: No secret key under different account

2009-11-02 Thread John Clizbe
David Gray wrote: > > What are peoples thoughts on which is the best option: > > a) copy the secring.gpg & pubring.gpg files to the second user account? > b) export and import the keys to the second user account? > c) add a reference to the second account's gpg.conf file? it depends on what

Re: gpg.conf

2009-11-02 Thread John Clizbe
David Gray wrote: > Hello John, > > Thanks for the man page and skeleton file for gpg.conf, both very useful. Anytime > The main issue at the moment (thread: "No secret key under different > account") is how > to access the keyring files under a different account. I'm looking for the > be

Re: Multiple Identities

2009-11-16 Thread John Clizbe
T. Howell-Cintron wrote: > I'm roughly familiar with GnuPG and have used it in the past when I had > a single presence, a single e-mail address, etc. > > I'm in a position now where I'm using multiple e-mail addresses, for > different purposes, but want to share the same key for the sake of > s

Re: [gpgol] bug in GPA during decryption

2009-11-17 Thread John Clizbe
benoit.an...@orange-ftgroup.com wrote: > Hello, > > have installed Gpg4win 2.0.1 (2009-09-28). Default setup. > am running windows XP SP2 > outlook 2003 -(11.8206.8221) SP3 > > I managed to create the keys and import someelse key. > No pbm sending encrypted email - they are ok at the destinatio

Re: Problem with the agent, gpg2

2009-11-17 Thread John Clizbe
Mario Castelán Castro wrote: > November 17th for gnupg-users@gnupg.org > > I need GNU PG 2 because i want to get out of the 1024 bits limit and > SHA forced for DSA, i want my next key (2010-2012) to be more secure > and accept some SHA2. GnuPG 2.0 is not needed for DSA > 1024 GnuPG 1.4.x has su

Re: digital signature primary key and encryption subkey

2009-11-18 Thread John Clizbe
M.B.Jr. wrote: > Thanks again, David. > > The last dumb question, I promise, would be: There aren't any dumb questions. > how can I see my primary key and my subkey as well? $ gpg --list-key 0x0x608d2a10 pub 1024D/608D2A10 2003-03-06 uid John P. Clizbe uid

Re: GnuPG private key resilience against off-line brute-force attacks (was: Re: Backup of private key)

2009-11-28 Thread John Clizbe
Robert J. Hansen wrote: > David Shaw wrote: >> Difficult question to answer, since everyone is going to wave around >> their opinion. :) > > There are some empirical facts which may be useful, though -- like > observing the RC5-64 project was able to break a 64-bit key via a > massive distributed

Re: verify gcc download

2009-12-29 Thread John Clizbe
David Durham wrote: > Hello, > > I am trying to verify the download of a gcc-4.1.0.tar.bz2 file. I also > downloaded the corresponding gcc-4.1.0.tar.bz2.sig file. I have tried > gpg --verify gcc-4.1.0.tar.bz2.sig gcc-4.1.0.tar.bz2, but it says "can't > check signature, public key not found." Does

Re: Passphrase error

2010-01-06 Thread John Clizbe
Andre Lee wrote: > gpg: public key decryption failed: bad passphrase > gpg: decryption failed: secret key not available > > I've had an issue with running gpg commands via Oracle BPEL before but > the change to the new server fixed it in the TEST. Now I have this new > issues on another server i

Re: How to turn off mail delivery but NOT unsubscribe? Nabble forum instead.

2010-01-09 Thread John Clizbe
BenXS wrote: > > I would like to use this mailing-list through the forum emulation of Nabble > at > > http://old.nabble.com/GnuPG---User-f959.html > > I don't need any posting delivery by email any more but would like to stay > subscribed to be able to post questions. > > However when I go to

Re: distributing ones public key (email)

2010-01-19 Thread John Clizbe
Robert J. Hansen wrote: > On 1/19/10 11:46 PM, Matthew Krotzer wrote: >> What is the best way to let people know you use gpg in an email >> signature? > > Some email clients (Thunderbird+Enigmail, for instance) let you put a > kind of note to other users hidden in the email headers. These things,

Re: help needed to load idea.dll in Vista32

2010-01-31 Thread John Clizbe
Doman Name Administrator wrote: > Hello, > > We are trying to change over to Mozilla Thunderbird 3 w/OpenPGP on a 32 > bit Vista machine. The primary reason being a PGP signature we need to > continue to use originally created in 1999. > > Of course we have already downloaded and intalled the i

Re: key question

2010-02-24 Thread John Clizbe
Tobias Holz wrote: > Hey Folks, > i successfully installed gnupg on my Win7 machine. I want to use it > with Thunderbird to encrypt personal eMails. > Now I've got some questions: > 1) What does happen if I lose my private key? Can I burn it to a CD/DVD? If you lose your secret key or forget your

Re: key question

2010-02-25 Thread John Clizbe
MFPA wrote: > On Thursday 25 February 2010 at 3:53:23 AM, in > , John Clizbe wrote: >> MFPA wrote: >>> Hi John > >>> On Thursday 25 February 2010 at 12:17:36 AM, you wrote: > >>>> It is also a good idea to send your key to the keyservers. >

Re: key question

2010-02-26 Thread John Clizbe
MFPA wrote: >> I never understood how anyone would want to use PGP for e-mail privacy, >> and, subsequently, keep the public key a secret! I don't see any reason >> why a person would keep his key off the public keyservers, short of >> preventing spam. And you know what, he would get spammed any

Re: key question

2010-02-27 Thread John Clizbe
This may be a dup - I think the original went out with the wrong From addr MFPA wrote: > Hi > On Saturday 27 February 2010 at 6:11:29 AM, in > , Robert J. Hansen wrote: >>> In any case, I've never seen a convincing argument *for* including email >>> addresses in the UID of a PGP key. Nor have w

Re: key question

2010-02-27 Thread John Clizbe
MFPA wrote: > Hi > On Saturday 27 February 2010 at 6:11:29 AM, in > , Robert J. Hansen wrote: >>> In any case, I've never seen a convincing argument *for* including email >>> addresses in the UID of a PGP key. Nor have we seen compelling arguments for their omission as a general rule >> First,

Re: Offline Primary Key

2010-03-01 Thread John Clizbe
David Shaw wrote: > > Didn't someone write a nice HOWTO about offline private keys at one point? I > thought there was one out there, but can't find it at the moment. Can anyone > post the URL for Philip? > Adrian von Bidder's page is the only one that memory serves up: http://fortytwo.ch/gpg/su

Re: Migrating from PGP to GPG question

2010-03-05 Thread John Clizbe
Daniel Kahn Gillmor wrote: > On 03/05/2010 01:30 AM, Smith, Cathy wrote: >> The gpg --list-sig shows that the keys are signed. Do I need to create a >> new signature key, and re-sign all the public keys that I imported? > > I think the simplest thing for you to do is to modify the ownertrust of >

Re: updprefs command and changing key

2010-03-12 Thread John Clizbe
Faramir wrote: > Just a question, and I don't have any intention about doing it, but, > is there a way to disable the usage of 3DES in GnuPG, when encrypting? Sure, the source is available -- the result just won't be a valid OpenPGP implementation any longer. Now for my "Just a Question": Why o

Re: updprefs command and changing key

2010-03-13 Thread John Clizbe
MFPA wrote: > On Saturday 13 March 2010 at 12:07:08 AM, in > , David Shaw > wrote: >> On Mar 12, 2010, at 6:31 PM, Faramir wrote: >>> is there a way to disable the usage of 3DES in GnuPG, when >>> encrypting? >> Patch the source :) >> There is no way other than that. > > Wouldn't "--disable-cipher

Re: WikiLeaks Crackers

2010-04-08 Thread John Clizbe
Faramir wrote: > David Shaw escribió: >> On Apr 7, 2010, at 3:18 AM, Andre Amorim wrote: > >>> What type of encryption the WikiLeaks said to have broken? AES ? > ... >> I do not think that this is a break of any serious crypto, though. If >> someonecould arrange for AES or any other strong cipher

Re: Crypto Stick released!

2010-05-10 Thread John Clizbe
Olav Seyfarth wrote: > Hi *, > > english version: > http://www.privacyfoundation.de/crypto_stick/crypto_stick_english/ That's the only page I've seen in English, Olav. Check the Shop links: http://www.privacyfoundation.de/shop/ and http://www.privacyfoundation.de/shop/crypto-stick.html Googl

Re: new Installation... configure issues

2010-05-24 Thread John Clizbe
raviraj kondraguntla wrote: > > Hi, > I am trying to install the gnupg 1.4.10 on solaris 10 server, I have > received the below error > > configure:3550: /opt/SUNWspro/bin/cc --version >&5 > ./configure: line 3551: /opt/SUNWspro/bin/cc: No such file or directory > configure:3553: $? = 127 > conf

Re: new Installation... configure issues

2010-05-25 Thread John Clizbe
raviraj kondraguntla wrote: > > All, > Thanks for your reply. > I checked the package GCC, it is showing that it was already installed. > $ pkginfo | grep -i gcc > system SUNWgcc gcc - The GNU C compiler > system SUNWgccruntime GCC Runtime libr

Re: ...key belongs to ...

2010-05-29 Thread John Clizbe
Michael D. Berger wrote: > On a Linux box, in encrypting a file with gpg, I get this query: > >It is NOT certain that the key belongs to the person named >in the user ID. If you *really* know what you are doing, >you may answer the next question with yes. > >Use this key anyway?

Re: What is the "list keyring content" command?

2010-06-07 Thread John Clizbe
Hauke Laging wrote: > > I hope there is a "tell me what this is" command that does nothing else (so > that it can be safely used). If it is a keyring, list the content (like now > without a command), if it is an encrypted file it would be nice to know that > (and the recipients' key IDs) WITHOU

Re: Keyserver spam example

2010-06-11 Thread John Clizbe
Mark H. Wood wrote: > On Thu, Jun 10, 2010 at 05:57:50PM +0200, Joke de Buhr wrote: >> You do not sacrifice legitimate incoming mail because there is an RFC that >> clearly states mailservers do not operate from dynamic IP addresses. >> Therefore >> they can not be considered valid. > > If ther

Re: Setting up SKS Keyserver

2010-06-21 Thread John Clizbe
Роман Шерстюк wrote: > Good day! > Sorry for disturb, please. > I have been setup SKS server on Linux Debian 5.0.3 and I'd like to ask Perhaps your post would get a better answer on the SKS list, sks-de...@nongnu.org > you how can I see detailed statistic. Assuming the statistics code ran at

Re: Help for a newby - gen-key error message

2010-06-23 Thread John Clizbe
VH Dolcourt wrote: > This is a Windows 7 question: > > I was able to mouse around in Google and found out how to modify the > proper PATH environment variable. Therefore, at the command prompt I'm > able to execute gpg without having to migrate to the directory where gpg > lives. The good news is

Re: "No-Keyserver" (and other) flags on keys

2010-06-27 Thread John Clizbe
Dan Mahoney, System Admin wrote: > The ones I've seen have enough awareness of what's in a key to pull a key > apart and determine who's signed it, when, and when it's expired. Is > there more than that to read these bits? Again:step zero may be to > determine what the internal format is. Th

Re: "No-Keyserver" (and other) flags on keys

2010-06-28 Thread John Clizbe
Dan Mahoney, System Admin wrote: > > I'm also not aware of how servers synchronize, but if it's a different > protocol than the standard single-key-request protocol, then there's an > easy metric to say "don't hand out keys with this flag via this protocol". For SKS (taken from the current SKS

Re: Relative path in GPG.conf

2010-07-04 Thread John Clizbe
Csabi wrote: > Can somebody help me? > I have Windows XP. > I just installed the newest Thunderbird Portable 3.0.1 and GPG for > Thunderbird Portable 1.4.10 and the EnigMail Extension to my USB drive. > The Gpg.exe in the GPG for Thunderbird Portable 1.4.10 is always search > my keyrings in the def

Re: setuping local/standalone keyserver

2010-07-21 Thread John Clizbe
Peter Pentchev wrote: > On Tue, Jul 20, 2010 at 12:50:53PM +0530, Prasanth Thandra wrote: >> Hi, >> i configured gnupg 2.0.15 on RHEL4 which is a mialserver. >> i am able to generate keypairs. >> now i want to setup a keyserver either on localhost or as a standalone. >> please let me know how to do

Re: setuping local/standalone sks keyserver

2010-08-03 Thread John Clizbe
Prasanth Thandra wrote: > On Tue, Jul 20, 2010 at 12:50:53PM +0530, Prasanth Thandra wrote: I already replied this on July 21, but it would appear it never reached you so allow me to quote myself in these two top sections (>+) >> i configured gnupg 2.0.15 on RHEL4 which is a mialserver. >> i am a

  1   2   3   4   5   >