Signing headers (was Re: Evolution signatures)

Adrian 'Dagurashibanipal' von Bidder avbidder@fortytwo.ch
Sat Aug 9 07:03:03 2003


--Boundary-02=_6DIN/ry1YFmamdb
Content-Type: text/plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Content-Description: signed data
Content-Disposition: inline

On Friday 08 August 2003 21:06, David Shaw wrote:
> On Wed, Aug 06, 2003 at 01:26:37PM -0500, Kyle Hasselbacher wrote:

> > I consider some headers (especially the subject) to be part of the
> > communication of a message.  As such, I'd like to protect the privacy a=
nd
> > integrity of those parts the same way as the message itself, as much as
> > that's possible.
>
> PGP/MIME can handle this using a message/rfc822 content-type.
> Essentially, it puts the entire message, headers and all, inside the
> encrypted or signed portion of the mail.

Damn. I guess this simple idea pretty much makes my thingy obsolete. All=20
that's needed is (i) to teach MUAs to generate such messages and to (ii)=20
merge inner headers into the outer headers when displaying a message with=20
multipart/{signed,encrypted}[message/rfc822] content type. (merging the=20
headers, because I want my MUA to interpret some of the headers added in=20
transport, such as the List-... headers and the X-Spam-Status headers - but=
 I=20
don't want the space-eating display of the double headers.)

cheers
=2D- vbi (Hmm. I *should* start looking at coding this in my mailer. Is the=
re a=20
store where one can buy a few weeks of spare time?)

=2D-=20
MuMlutlitithtrhreeaadededd s siigngnatatuurere

--Boundary-02=_6DIN/ry1YFmamdb
Content-Type: application/pgp-signature
Content-Description: signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iKcEABECAGcFAj80gPpgGmh0dHA6Ly9mb3J0eXR3by5jaC9sZWdhbC9ncGcvZW1h
aWwuMjAwMjA4MjI/dmVyc2lvbj0xLjUmbWQ1c3VtPTVkZmY4NjhkMTE4NDMyNzYw
NzFiMjVlYjcwMDZkYTNlAAoJEIukMYvlp/fW5f0An1eX2PVO0GJSvj+E/rcqXpjY
rmwWAJ4o1cUbJjWYRsp/EnKdZbZM4bNfTQ==
=lndu
-----END PGP SIGNATURE-----
Signature policy: http://fortytwo.ch/legal/gpg/email.20020822?version=1.5&md5sum=5dff868d11843276071b25eb7006da3e

--Boundary-02=_6DIN/ry1YFmamdb--