[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: GPG USAGE HOWTO 1 (was: Re: AM report on Thierry Bourrillon)



On Tue, Apr 17, 2001 at 12:48:24AM +0200, Peter Palfrader wrote:
> When I sign a key I confirm than
>  o  the person can receive and read mail at all mailboxes I sign.

This latter one can be achieved by the following:

1. Generate a nonce, eg, with something like
    { date; uptime; cat /etc/passwd; } | md5sum
   and note it down.

2. Send the following message encrypted with the key you have been
   given to the email address you wish to verify:
     Please send me back the nonce; I require you to do this before I
     will sign your key.
     Nonce: <insert it here>

3. Don't sign the email address until the correct nonce has been
   received in return.

   Julian

-- 
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

         Julian Gilbey, Dept of Maths, Queen Mary, Univ. of London
       Debian GNU/Linux Developer,  see http://people.debian.org/~jdg
  Donate free food to the world's hungry: see http://www.thehungersite.com/



Reply to: