Section One BBS

Welcome, Guest.


Subject: Re: never use SHA1 Date: Fri Jan 10 2020 09:21 am
From: Wilfred van Velzen To: August Abolins

Hi August,

On 2020-01-10 05:55:01, you wrote to me:

 AA>>> Further to your preceding message, you sent it signed with
 AA>>> SHA1.

 WvV>> Yeah, I already thought so. It's the default in my older
 WvV>> gpg version. Let me try and change that...

 AA> TB 2.0.0.24 warned me with this:

 AA> gpg command line and output:
 AA> C:\Program Files\gnupg\bin\gpg.exe
 AA> gpg: Signature made 01/09/20 17:20:12 Eastern Standard Time
 AA> gpg:                using RSA key 3BB37DA84A97932B
 AA> gpg: BAD signature from "Wilfred van Velzen <wvvelzen@gmail.com>" 
[unknown]

 AA> It is warning me that you are not the person who claims to have written
 AA> that?

No, than it would say something different. This just means the cleartext, has
been changed from it's original when you verify it.

 AA> Maybe the new and old gpg programs are using different local key files
 AA> on your pc?

Nope.

I just tested the original text on my windows pc at work, and I get:

gpg: WARNING: no command supplied.  Trying to guess what you mean ...
gpg: Signature made 01/09/20 23:20:12 W. Europe Standard Time
gpg:                using RSA key 3BB37DA84A97932B
gpg: Good signature from "Wilfred van Velzen <wvvelzen@gmail.com>" [full]
gpg:                 aka "Wilfred van Velzen <wilfred@vvlzn.nl>" [unknown]
gpg:                 aka "[jpeg image of size 5943]" [unknown]

So...?

Maybe Tommi and/or Mark can try to verify it.

Bye, Wilfred.

--- FMail-lnx64 2.1.0.18-B20170815
 * Origin: FMail development HQ (2:280/464)

Previous Message       Next Message
In Reply To: never use SHA1 (August Abolins)
Replies: never use SHA1 (August Abolins)