Question about: "gpg: WARNING: message was not integrity protected"

Werner Koch wk at gnupg.org
Thu Oct 21 10:58:05 CEST 2004


On Tue, 19 Oct 2004 13:33:04 +0200, Scholz Ulrich said:

> So why do I still get this message?  And what does it tell me?  Am I doing
> something wrong here?

That message is on purpose to remind people that they should use the
MDC feature.  MDC is automagically handled through the preferences
system but with symmetrical only encrypted mails we don't have them
and thus we need to print the warning in all cases.

The MDC features solves a problem when an attacker modifies parts of
an encrypted messages, e.g. by cutting out some parts, and the user
did not noticed a couple of garbled characters (he might think this is
line noise). 

This integrity protection is used independly from a signature.


Shalom-Salam,

   Werner




More information about the Gnupg-users mailing list