Re: [openpgp] A way to securely define cleartext signature charset

Andre Heinecke <aheinecke@intevation.de> Tue, 11 September 2018 11:01 UTC

Return-Path: <aheinecke@intevation.de>
X-Original-To: openpgp@ietfa.amsl.com
Delivered-To: openpgp@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D3ADC130E7A for <openpgp@ietfa.amsl.com>; Tue, 11 Sep 2018 04:01:34 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zJea6_JSQFQM for <openpgp@ietfa.amsl.com>; Tue, 11 Sep 2018 04:01:33 -0700 (PDT)
Received: from kolab.intevation.de (kolab.intevation.de [212.95.107.133]) by ietfa.amsl.com (Postfix) with ESMTP id A84F5130E73 for <openpgp@ietf.org>; Tue, 11 Sep 2018 04:01:32 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by kolab.intevation.de (Postfix) with ESMTP id 07B576246B for <openpgp@ietf.org>; Tue, 11 Sep 2018 13:01:32 +0200 (CEST)
X-Virus-Scanned: by amavisd-new at intevation.de
Received: from kolab.intevation.de ([127.0.0.1]) by localhost (kolab.intevation.de [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6QuKzpsKqg3D for <openpgp@ietf.org>; Tue, 11 Sep 2018 13:01:31 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1]) by kolab.intevation.de (Postfix) with ESMTP id 2E17A6265E for <openpgp@ietf.org>; Tue, 11 Sep 2018 13:01:31 +0200 (CEST)
Received: from esus.localnet (81-5-224-141.hdsl.highway.telekom.at [81.5.224.141]) (Authenticated sender: andre.heinecke@intevation.de) by kolab.intevation.de (Postfix) with ESMTPSA id 007C06246B; Tue, 11 Sep 2018 13:01:30 +0200 (CEST)
From: Andre Heinecke <aheinecke@intevation.de>
To: openpgp@ietf.org
Cc: Vincent Breitmoser <look@my.amazin.horse>, Werner Koch <wk@gnupg.org>
Date: Tue, 11 Sep 2018 13:01:30 +0200
Message-ID: <4596731.BY6HxoI61K@esus>
User-Agent: KMail/5.2.3 (Linux/4.9.0-8-amd64; KDE/5.28.0; x86_64; ; )
In-Reply-To: <F4P93M9CHV.3ULRUJS01EYZG@my.amazin.horse>
References: <2069480.MVc5JfVDOz@esus> <87r2i0xsul.fsf@wheatstone.g10code.de> <F4P93M9CHV.3ULRUJS01EYZG@my.amazin.horse>
MIME-Version: 1.0
Content-Type: multipart/signed; boundary="nextPart1841864.LKsFlQjK8a"; micalg="pgp-sha256"; protocol="application/pgp-signature"
Archived-At: <https://mailarchive.ietf.org/arch/msg/openpgp/6th4j1jNn7bmNz62dTrj9tXlqYk>
Subject: Re: [openpgp] A way to securely define cleartext signature charset
X-BeenThere: openpgp@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Ongoing discussion of OpenPGP issues." <openpgp.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/openpgp>, <mailto:openpgp-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/openpgp/>
List-Post: <mailto:openpgp@ietf.org>
List-Help: <mailto:openpgp-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/openpgp>, <mailto:openpgp-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 11 Sep 2018 11:01:35 -0000

On Tuesday, September 11, 2018 12:50:11 PM CEST Vincent Breitmoser wrote:
> > A minor issue is that my Application might temporarily show the wrong
> > representation before the verification is done but I guess that is indeed
> > minor.
> 
> Cleartext signatures are typically short. Is there a reason for even showing 
the
> text before the signature is verified and the charset known?

In GnuPG we have the option "auto-key-retrieve" which I prefer to use. That 
option will fetch an unknown  signing key from remote sources e.g. Keyserver 
or WKD, which can take a while. But as I said, this is a minor issue.

Regards,
Andre

-- 
Andre Heinecke |  ++49-541-335083-262  | http://www.intevation.de/
Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998
Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner