Corporate use of gnupg

Robert J. Hansen rjh at
Thu Feb 14 06:24:14 CET 2008

Quoting gnupg at
> And what do they want to do with the recieved emails? The only possibility I
> see is to put everyone's private keys and passowrds into a safe - then you
> can decrypt sent and received mail later.

Same problem exists with PGP's ADK feature, which should really be  
named an ARR, for Additional Recipient Request.  While ADK usage can  
be enforced within the ADK-using group (mostly: there are some  
caveats), emails from outside the group going in to the group are  
under no such restrictions.

