Encrypt & Sign

David Shaw dshaw at jabberwocky.com
Fri Jan 14 17:25:59 CET 2005


On Fri, Jan 14, 2005 at 03:55:05PM +0000, Shaun Lipscombe wrote:
> Is there any particular reason why one must be done before the other?
> 
> I.E. Sign & Encrypt over Encrypt & Sign.
> 
> Does signing encrypted data help people determin the key for example
> (just guessing)

The reason is that by doing sign & encrypt (that is, sign a document
and then encrypt the signed document) you protect the identity of the
signer.  There is no particular reason why one is better than the
other, but generally people like the identity protection aspect of
S&E.

David



More information about the Gnupg-users mailing list