Re: Where can I buy OpenPGP smartcards?

2008-01-02 Thread Alon Bar-Lev
On 1/2/08, Matt Alexander <[EMAIL PROTECTED]> wrote: > I'm looking at a possible deployment of OpenPGP smartcards at my company and > want to ensure that I have multiple vendors. > Thanks! > ~Matt Hello, You can use almost any PKCS#11 enabled smartcard if you use: http://gnupg-pkcs11.sourceforge.

Generic question: Correct content-type?

2008-01-02 Thread Alexander W. Janssen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, this is a more generic question. I use Thunderbird + Enigmail on several machines. I never touched any of the advanced features and never got problems with someone until now. I've sent an encrypted email - as inline PGP - and my buddy's Mutt coul

Re: pipes cgi and gnupg

2008-01-02 Thread Brad Tilley
On linux, would it be possible to use the Linux Key retention service to overcome this: http://www.ibm.com/developerworks/linux/library/l-key-retention.html On Jan 2, 2008 3:46 AM, Werner Koch <[EMAIL PROTECTED]> wrote: > Note that all users on the machine will see the passphrase in the output >

Where can I buy OpenPGP smartcards?

2008-01-02 Thread Matt Alexander
Does anyone know if any of the following cards are OpenPGP compatible and will work with GnuPG? http://smartcardfocus.com/shop/ilp/se~5/p/index.shtml Or is the card at... http://www.kernelconcepts.de/en/shop/products/security.shtml?hardware The only option? Are there any other compan

Re: Ignoring expiration dates

2008-01-02 Thread Werner Koch
On Wed, 2 Jan 2008 15:39, [EMAIL PROTECTED] said: > Actually, this is a very old discussion. I've come to accept that > it's okay to choose the maximum, but I still don't buy that's the only > choice. 8-) Okay. We have have hard expiration dates on the todo list but nothing you will see any t

GPG Decryption of a PGP encrypted zip file resulting in garbled zip file

2008-01-02 Thread Steve Liu
Hello, I'm a newbie here, but I have a problem decrypting a zip file encrypted with pgp. I was trying to subscribe to the gpg group, but it didn't reply, so I couldn't post there. So I thought I'd ask the folks here. The problem is this, I generate a standard 2048-bit ELG-E key and sent off the

Re: fatal: zlib inflate problem: invalid distance code

2008-01-02 Thread João Grilo
Hello again, First of all, thanks for the quick reply. The checksum did reveal that there are differences. I know this isn't directly related to GnuPG, but since the file in question is so big (100gigs), and I don't have physical access to the original file any more, is it possible to simply tran

Re: Ignoring expiration dates

2008-01-02 Thread Florian Weimer
* Werner Koch: > On Wed, 2 Jan 2008 13:53, [EMAIL PROTECTED] said: > >> Oh well, this is a bit counterintuitive because the expiration time is >> a hard fact in X.509, and rather fuzzy in OpenPG. > > I don't agree that it is fuzzy in OpenPGP; it is well defined. For v3 keys, it is, but not for v

Re: Ignoring expiration dates

2008-01-02 Thread Werner Koch
On Wed, 2 Jan 2008 13:53, [EMAIL PROTECTED] said: > Oh well, this is a bit counterintuitive because the expiration time is > a hard fact in X.509, and rather fuzzy in OpenPG. I don't agree that it is fuzzy in OpenPGP; it is well defined. The fact that you may change the expiration time does not

Re: Ignoring expiration dates

2008-01-02 Thread Florian Weimer
* Werner Koch: > On Wed, 2 Jan 2008 09:55, [EMAIL PROTECTED] said: > >> Is it possible to ignore the key expiration date during encryption? > > Not with gpg. With gpgsm you may try --debug-ignore-expiration. Oh well, this is a bit counterintuitive because the expiration time is a hard fact in X

Re: fatal: zlib inflate problem: invalid distance code

2008-01-02 Thread John Clizbe
João Grilo wrote: > Recently, I was asked to backup and archive a ton of sensitive data, so > I used gpg keep it away from evil eyes. > > Now, trying to recover it on a different machine, it fails with the > following error: > debian:~# gpg mybigbackupfile.tar.gz.gpg > gpg: CAST5 encrypted data >

Re: Ignoring expiration dates

2008-01-02 Thread Werner Koch
On Wed, 2 Jan 2008 09:55, [EMAIL PROTECTED] said: > Is it possible to ignore the key expiration date during encryption? Not with gpg. With gpgsm you may try --debug-ignore-expiration. Salam-Shalom, Werner -- Die Gedanken sind frei. Auschnahme regelt ein Bundeschgesetz. __

fatal: zlib inflate problem: invalid distance code

2008-01-02 Thread João Grilo
Hello, Recently, I was asked to backup and archive a ton of sensitive data, so I used gpg keep it away from evil eyes. Now, trying to recover it on a different machine, it fails with the following error: debian:~# gpg mybigbackupfile.tar.gz.gpg gpg: CAST5 encrypted data gpg: encrypted with 1 pass

Ignoring expiration dates

2008-01-02 Thread Florian Weimer
Is it possible to ignore the key expiration date during encryption? Unfortunately, people tend to set expiration dates without thinking about the consequences. It's not always possible to get a new self-signature in a reasonable time frame. -- Florian Weimer<[EMAIL PROTECTED]> B

Re: pipes cgi and gnupg

2008-01-02 Thread Werner Koch
On Sat, 29 Dec 2007 04:03, [EMAIL PROTECTED] said: > os.system("echo %s | gpg --batch --password-fd 0 -d %s > d.out" os.system("echo %s | gpg --batch --password-fd 0 --output - -d %s > d.out" Note that all users on the machine will see the passphrase in the output of ps(1). You are better ofd