[PATCH] avoid publishing the GnuPG version by default

Werner Koch wk at gnupg.org
Fri Aug 5 18:27:33 CEST 2016


On Fri,  5 Aug 2016 16:36, dkg at fifthhorseman.net said:

> Yep.  And Hash: isn't necessary (nor is it generated) when doing
> detached signatures or PGP/MIME signatures anyway (the PGP/MIME
> multipart/signed content-type has a micalg= parameter that achieves the

micalg is a problem by itself: For example it does only allow for one
algorithm.  It is also problematic from the processing model because you
need to do a trial signature to figure out the algorithm which will be
used.  And it is often not correctly set, thus for detached signatures
in streaming mode you may better guess the hash algorithm first.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.
 /* Join us at OpenPGP.conf  <https://openpgp-conf.org> */




More information about the Gnupg-devel mailing list