Re: GPG USAGE HOWTO 1 (was: Re: AM report on Thierry Bourrillon)
On Tue, Apr 17, 2001 at 12:48:24AM +0200, Peter Palfrader wrote:
> When I sign a key I confirm than
> o the person can receive and read mail at all mailboxes I sign.
This latter one can be achieved by the following:
1. Generate a nonce, eg, with something like
{ date; uptime; cat /etc/passwd; } | md5sum
and note it down.
2. Send the following message encrypted with the key you have been
given to the email address you wish to verify:
Please send me back the nonce; I require you to do this before I
will sign your key.
Nonce: <insert it here>
3. Don't sign the email address until the correct nonce has been
received in return.
Julian
--
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Julian Gilbey, Dept of Maths, Queen Mary, Univ. of London
Debian GNU/Linux Developer, see http://people.debian.org/~jdg
Donate free food to the world's hungry: see http://www.thehungersite.com/
Reply to: