[openpgp] Re: Analysis document
Andrew Gallagher <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <[email protected]> |
On 10 Jul 2025, at 13:36, Daniel Huigens <[email protected]> wrote: > > But, I agree it would be valuable to more explicitly forbid signing over arbitrary binary data (and text data that is not encoded using UTF-8) using a signature of type=text. Perhaps this could be included in Andrew's signature semantics draft <https://datatracker.ietf.org/doc/html/draft-gallagher-openpgp-signatures>, as well. If this were forbidden, it would add some novel failure modes. For example, if I sign over a UTF-8 document with a text signature, and it turns out that there is an invalid UTF-8 character in it (say, a mishandled surrogate), is the signature invalid? Even if there’s no malleability risk? A _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEKR55odxVrielLu+DXB7EBNWQZikFAmhv2t4ACgkQXB7EBNWQ Zinq9RAAmR2+a5UAxI+qd5xy526cTqMJgyhALh8RlTmgEKt0Zg9GBt7N27oJrK/9 8xzai3iCphS3ui7zu4r236PV7Tt2qyZfdvtJ0onSW2KJvIEwqloXrUNevbUf59/k OvjyGN08sle96BAx3PY+YAJCV93mhs8/p//mJahZQ16fpiRz/aosglQ/GodYFsv+ KGzliiaja+WVbP4DuNQ5mt2U9Nmbze/8+ZAI6wMcsZMqyPEvnYakfVR4MrCT8hHY 2YBEXyQWIhqDH8s+/Oo0KFo8om/erqL+5hzu6NXJ3Ey/erSTfOw0fy0GP77M3swl D5bV9ahII85gMbaiZxMCDBUJxvcbLVOfJrC5Pod4RjcJ6vateM+iH8VQN4fOwzGT 7dCVMumO1wH1zfbAb2ypY4veefRi00UDCg0NHXaBIVeEwVMZIvJreJx5UPzhF1+j AMNlKzk6jCDYkP2raLvqaGaUiEgO3GuAMTZmJxvJjweADdWqpmg7AZj9MU78b2Bm h5EAVXXw0e89zQyhJbZYoKco1mWRfAjFe5gvdaosx5w+LJSJ0WsiUpcJzqsnbLLR Ys35hnazZjjlir8F/d7FfHvG3np1GDB/MT5Sic01zr3ZVb3On97pU9MsM2ed7m8p 5aHtyVltiTt37tpWFH5n/aBR+Z6ezb5i/zZkLs9AlOARlG8nyGk= =AGTz -----END PGP SIGNATURE-----