How to select a particular public key when verifying a signature?

MFPA expires2011 at ymail.com
Sat Dec 17 17:55:41 CET 2011


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hi


On Saturday 17 December 2011 at 2:22:28 PM, in
<mid:E1Rbv9g-0001Bi-00.pv4-bk-ru at f107.mail.ru>, Vladimir A. Pavlov
wrote:

> Consider the following situation.

> I have two friends: Alice and Bob. I added their
> publick keys (Alice's AAAAAAAA and Bob's BBBBBBBB) to
> my keyring. Now Bob sends me a signed file. When I
> verify the signature the file appears to be signed by
> Alice's key. But gpg doesn't give me an error, it just
> tells me the file was signed with AAAAAAAA key so that
> I have to look at the message and discover the key
> doesn't correspond to the sender.

> Bob has obviously got Alice's key

Bob has possibly got Alice's key. The more obvious conclusion is that
Bob has simply forwarded a file that Alice signed. Of course, both
possibilities need to be considered.


- --
Best regards

MFPA                    mailto:expires2011 at ymail.com

No man ever listened himself out of a job
-----BEGIN PGP SIGNATURE-----

iQCVAwUBTuzJlqipC46tDG5pAQoG3gP7BeV+QV6wOZXk9yhtaoOn6qTuyEtFxeXA
NQMT7nnPsbOzSXi4HOmBVKuPr4S9ClZHMlIWuXoR8M3qnkPPEcMtPcRsq8vQz4FN
7hpQnuEtHhhBGlMP9NYK1G7Y0Edqwue/QwjoqkELIGctc/n0niBHnYXRNtCP5Nwy
uKv+T0MOyFM=
=ChN3
-----END PGP SIGNATURE-----




More information about the Gnupg-users mailing list