Recovery of PCSECURE files and bogus GnuPG algorithms

Brian M. Carlson karlsson@hal-pc.org
Wed Jun 19 09:20:01 2002


--nmemrqcdn5VTmUEE
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Jun 19, 2002 at 05:14:25AM +0100, john clark wrote:
>=20
>=20
> > #--------------------
> > default-key jed
> > load-extension tiger
> > cipher-algo twofish
> > digest-algo tiger192
> > #--------------------

This is the issue. Loading tiger isn't a problem, but forcing it above
all others is. It cannot even be used, because it is too big for DSA and
it won't work with RSA and ElGamal because it doesn't have a proper
ASN.1 OID. Signing with tiger is a bad idea (I like it too, but everyone
has to give some things up). Try RIPEMD160 instead. Also, forcing
twofish may not work on older PGPs. Try --pgp6. What your friend may be
trying to do may better be accomplished with --default-preference-list
and --personal-{cipher,digest,compress}-preferences.

--=20
Brian M. Carlson <karlsson@hal-pc.org> <http://decoy.wox.org/~bmc> 0x560553=
E7
<LIM> mmmm, multitextured donuts....
<knghtbrd> LIM: with fruit filling?
<LIM> knghtbrd: chocolate cream...

--nmemrqcdn5VTmUEE
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7a-cvs (GNU/Linux)
Comment: Ubi libertas, ibi patria.

iQEVAwUBPRAw9eWR/8lWBVPnAQM68Qf/S6Kx4oxwOoeHrVd49uQK5+q6EARB0wyd
hcicIyU5s8scKsaqKODI//wDw1Yt/TQ0EePLH3gZNbyue8tHw0UmGIBnsgjs7gxW
NmDx39d/hDP2qjZv0Ci65OtXOPcFsxVymSn0g+v59gkUV76z5rfH/YYvFP66nTef
Xu8ihERk5A/yixtPLd7ljk/kP4hoA3oAvOPp4ijYtWlZ/darhk2vUYf0r4cv1rdA
JyOHRY2jFK8HjnnIkmBX+dcC7k7H+V+CDJjkUPnDZkrvQoIdPMXl4e4KVAkpX4Ff
wgGsywUcelVbrSYo4WQ3LGWW721oIulzTLNTZnuwPtyi+u/0lttZYA==
=W53x
-----END PGP SIGNATURE-----

--nmemrqcdn5VTmUEE--