Re: Re: Invalid packet types in generated RSA PGP key

David Hook <dgh-rTAZ0PM/[email protected]>
Newsgroups gmane.comp.encryption.bouncy-castle.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Actually, I think I'm confused. I was just rereading the commentary, if
the s2k usage is 0, there shouldn't be sha-1 digest.

I will have another look at this.

Regards,

David

On 17/05/18 03:27, David Hook wrote:
> > Ask them to read the last paragraph of Section 5.5.3 RFC 4880. > > "
The two-octet checksum that follows the algorithm-specific portion is >
the algebraic sum, mod 65536, of the plaintext of all the algorithm- >
specific octets (including MPI prefix and data). With V3 keys, the >
checksum is stored in the clear. With V4 keys, the checksum is >
encrypted like the algorithm-specific data. This value is used to >
check that the passphrase was correct. However, this checksum is >
deprecated; an implementation SHOULD NOT use it, but should rather > use
the SHA-1 hash denoted with a usage octet of 254. The reason for > this
is that there are some attacks that involve undetectably > modifying the
secret key." > > There is further discussion on this earlier in Section
5.5.3 as well. > > Regards, > > David > > On 16/05/18 22:15, Paul Schaub
wrote: >> Hi! >> >> Am 15.05.2018 um 11:03 schrieb Paul Schaub: >>> I
openend an issue on the pgpdump repo: >>>
https://github.com/kazu-yamamoto/pgpdump/issues/23 >> As Heiko Stamer
and Kazu Yamamoto pointed out [1], BC 1.59 seems to >> append the SHA1
hash (20 bytes) instead of a 2 byte checksum after the >> secret key.
Apparently that is against RFC-4880 and breaks pgpdump. >> >> [1]: >>
https://github.com/kazu-yamamoto/pgpdump/issues/23#issuecomment-389495218
>> > > >
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iF4EAREIAAYFAlr8cgwACgkQbqHzoYMuRw7C0gEAkpnljH/xW36kH+x5wSdZlY0d
HMRsH3dyVMD8Sb3doY4A/Rep4G7AHWwhBspdxfJC9swD7FHfPa0YOKc9iwpjEv/P
=wOwd
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.