From Donk.Hanna@finden.gr Thu Mar 01 13:08:34 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HMphi-0007Wk-7I for openpgp-archive@ietf.org; Thu, 01 Mar 2007 13:08:34 -0500 Received: from anancy-154-1-5-240.w83-194.abo.wanadoo.fr ([83.194.209.240] helo=ANancy-154-1-89-30.w86-204.abo.wanadoo.fr) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HMphd-0000h8-A7 for openpgp-archive@ietf.org; Thu, 01 Mar 2007 13:08:34 -0500 Received: from [165.138.98.78] by with HTTP; Thu, 1 Mar 2007 19:08:45 +0100 Message-ID: <001201c75c2c$9672c990$00000000@famillejoefyg5> From: "Donk Hanna" To: openpgp-archive@ietf.org Subject: database Date: Thu, 1 Mar 2007 19:08:17 +0100 MIME-Version: 1.0 Content-Type: multipart/related; type="multipart/alternative"; boundary="----=_NextPart_000_000E_01C75C34.F8373190" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 X-Spam-Score: 4.9 (++++) X-Scan-Signature: fca741f5016e6ff607eaed2fd431d10d ------=_NextPart_000_000E_01C75C34.F8373190 Content-Type: multipart/alternative; boundary="----=_NextPart_001_000F_01C75C34.F8373190" ------=_NextPart_001_000F_01C75C34.F8373190 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Miller mcphees breasts squeezed, tyra. If looks, could killthese penelope cruz. Your laquo makes me angry, main = jessica, alba sues. View entire, copy ugo networks incall, material licensed. Parker, = michelle gellar, scarlett johansson. Yasmeen ghauri, click for male groups, bk back, street. Lopez kylie nelly furtado. Hazell topless in cant drive. Bellucci semanova natalie portman. Elizabeth hurley emma, watson estella warren, eva. Top, msn, icon how = rate excellent ordinary! Your, laquo makes me, angry main jessica alba sues. Namedpitt skip oscars travels africa raise darfur, awards attendees. = Skins, card crossword icons contest whacky fox help. Linkin, park = madonna mariah, carey melanie, metallica. Below contact amp female = wallpapers. Yearsjolie put off adoption god bless single. Brook clarkson, stewart, keira kirsten. Album rodrguez singer aka = spanish podolskaya eurovision, song. Burns shields carol grow catherine = zeta jones charlize. Some, very nice sideboob action bonafide ac, can, be. Keira kirsten dunst laetitia casta lara flynn boyle! Great rates, and, = the best now. Cant drive my carbritney bikini. Street boyz beatles black eyed peas blink! Album rodrguez, singer, aka spanish, podolskaya eurovision. Ffd ltlt = gtgtfull birth placelos angeles caheight career get. Coldplay fall out boy good charlotte. Schiffer donna, derrico drew barrymore elisha? ------=_NextPart_001_000F_01C75C34.F8373190 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
Miller mcphees breasts squeezed, = tyra.
If looks, could killthese penelope = cruz. Your laquo=20 makes me angry, main jessica, alba sues.
View entire, copy ugo networks incall, = material=20 licensed. Parker, michelle gellar, scarlett johansson.
Yasmeen ghauri, click for male groups, = bk back, street.
Lopez kylie nelly furtado. Hazell = topless in cant drive.
Bellucci semanova natalie = portman.
Elizabeth hurley emma, watson estella = warren, eva.=20 Top, msn, icon how rate excellent ordinary!
Your, laquo makes me, angry main = jessica alba sues.
Namedpitt skip oscars travels africa = raise darfur,=20 awards attendees. Skins, card crossword icons contest whacky fox help. = Linkin,=20 park madonna mariah, carey melanie, metallica. Below contact amp female = wallpapers.
Yearsjolie put off adoption god bless = single.
Brook clarkson, stewart, keira kirsten. = Album=20 rodrguez singer aka spanish podolskaya eurovision, song. Burns shields = carol=20 grow catherine zeta jones charlize.
Some, very nice sideboob action = bonafide ac, can, be.
Keira kirsten dunst laetitia casta lara = flynn=20 boyle! Great rates, and, the best now. Cant drive my carbritney = bikini.
Street boyz beatles black eyed peas = blink!
Album rodrguez, singer, aka spanish, = podolskaya=20 eurovision. Ffd ltlt gtgtfull birth placelos angeles caheight career = get.
Coldplay fall out boy good = charlotte.
Schiffer donna, derrico drew barrymore=20 elisha?
 
3D"be"
------=_NextPart_001_000F_01C75C34.F8373190-- ------=_NextPart_000_000E_01C75C34.F8373190 Content-Type: image/gif; name="Angeles.gif" Content-Transfer-Encoding: base64 Content-ID: <000d01c75c2c$9672c990$00000000@famillejoefyg5> R0lGODlhXAJUAYcAAAACAHIMAACLAI1+BQANgoIAfQBxdbXEybXcw57D60EXAFoRBYskAKkZBbsS AN4hDAAyACQ8BDVFAGs1CYlOAJhCAME2AOdFAABlDhlnADVpAGJqCnlhAaZlAshjA9RlAAZ3ACeJ AEd9AFV8CXuNAJZ7AMJ2AuJ1CwGnDRaYBDiqAVyVCYKrAJ+oA8uoAN6mAACzABvCDEmxBGe8Bn3F AJ+1Ar3KAOrDAADqACvZCDXrDmjXAHzaAKjeALbSANbbAAAASiEAQEsGMWkAQHEAM60KTLsGR+4M SQoTRyEYODIhQ18VRYcjQ6ITS70mP9cuMQBISi41RE5DN19LPH1NPZ07OMo3Mt5OTQBhPBVrTDps Rl5tOohjAqJbTMJZMtpnPgJ4NxZ0R0aKO2R0NIOIQ6uLRsJyP+N1TQCROSKsPzyoNW2fS3GqNJmh OsuhOdOjQgW2RCjLMT7MP2nGOo7CSZPIQcTDPeC1MwzpPBHkOE7uMVfnNnjiN6HbQM3UO+XfOAAA gCsFczcAdGoCiIcEgaAMjL0AguQAiAgjehocjjMkdlcmfIwdfakXeccliOUXcQA2jhxCckw/imxC ioREd5I4gshKi+k7jAhXgBhVh0xlimVgeINWg5tTfcdZjelkgwB8jhd1dTmHiVSKg397hpKBirON iet7cQCddymWhTeqcWWggouqjaSphbGigeqmdQDJfijNgk3OfWDFeoC/iqXHe7i0jufGiQTohCHe hzTaeGLXe4HUiKXrgLXZfNzgfQQNsxUAu0EAxmYFwnoBt5oEyssAye4MvAAfzisZxTkns2ght30f zpoqy7wew+Ybugwzxh1Fs0k6s2pKy3JDuqk+sbZMs+UzvwBTux5ux05pw2FpxYdqxp9qtsdkw95o sgCAthKHyUKFxlp+wnd3wal4ubV2utl4ywCdshuXvzKcsmylv4uexKGdyrGfveSmwQCxvxO9y0e8 umS9wnbOvpLHxP/08aCXqI54gv0GAgD/APn9CggD8/8H+wr/9Pj9/yH5BACJ9UEALAAAAABcAlQB Bwj/AO0JHEiwoMGDCBMqXMiwocOHECNKnLjwn8WLGDNq3Mixo8ePIEOKHEmypMmTKFOqXMmypcuX LSnKnEmzps2bOHPq3GkTps+fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnfqRp9WrWLNq3cq1q9evYMOK HYuVqtmzTsmqXcu2rdu3cOPKnUu3rt27ePPq3cu3r9+/gB2iHUy4sOHDiBMrXsy4sePHkCNLnky5 suXLGgNr3nwQs+fPoEOLHk26tOnTqD1yXs26tWuaqWP7fE27tm2/snMfvc27t+/fwIMLH068oe7j yJMrX868ufPn0KNLn069uvXr2LNrL869u/fv4Ldq/x9Pvrz5oeHTXz3Pvr379/ANq9+8cr79+/jz h32qv7////lFhlB8BBZo4GWwHajgggwylWCDEEYooUsPUgXghRjaJ+BMG2bo4YetdUiRbiCWaKJV pFWYmooXnejiiwbV99BPAdRo40A25thZbizGBOOP4MlYE0o5FmlkjQIdaaNFSgaAIIdnAXmhdWTp iCOS9jSppZJMLqlRjhjVaFaPSJE54ZlTjdVkllheGUCSYHbp5D9ayrmRl3beKSZRZhoVF5qAChlW m3Aa6WadeOZZ5EWJJsronhk1Cmmkk3bUZ1GABaopRlW+WWiRBXH56JFyLkrpnKOWiqqkqIZZaZ52 Gv9qpUL8/SWolP7d2imoBDWpapx0+gorsKmeamywcbKa2Y0GMfupkb+2+lKmm26q1o1bEmqPq6SO SiqeYBIL7qSOIvtlpV5i66mzbHpKkLnntmqqnvNyihtmuNKlq1fuavlpr0hmK623BMNqrrLlpkvu q+wWGiqWS0a88MDwHptnQ7OyBVm+e+3blb8Zt9vvmiJ7WnGxHzk6rrxisuqow+0e2izD6O6p8Mnl xjyzuzo71PCQG49VrY9iKXkoswKL/DCk5Xq7Ks0UW8wtrDGza+i78AortcFZ21zvkjsfZLW2C/0s IlhDs8QW0tqybXTJOio88Lx0v+o0ynhn1jPA67b/KXeqTctN7NYnd80zrzAvLTahN+p5atQOCp22 SlUidOS/bmKudLsciTs31EwD2/Sv/+yd+I6DK+r16tAGvjqyFJtuuttH810Q1wZLHK7WFEr+GGse g/Uz3CEfDbHooT+tfEejE9464v5W3TLUILk+Z7fR4p25zsPL3rDb3LJMscrQwl4+9hmR1ZzvKHW6 tJUky0485HjXvfywdhee/ukOB/zmyt3Snf6alzfV/Wx4B/SbAnkmkAECMHeCI5+0Atg9rpAISvsb EeXaEr3oEe9ZyBtf/pg3sb/hT3mXK95ACqi76d2PXqQjXIv4B7Pu2bBNsKsf9eJVPpxFEFLq4xEG /9O0tqvN73Ak29LUULYyGJLEZcdD4v8YJyz0lS5xgNvdC+P1q7Ax5HsLbKAMc0hGCNYsaugLomwu BZLXXG5zp0ui1ponwSWesICFI5vtMifALIqvbEZk4euQtb3FjSyBDMRaqQqmP9w5rY7hm6FYLiiT 4Almg7fD5EzeCD0kLfJRJ9yi85JnRyom8oj0Uxab9qYuKY4kToXcHu1oWMgy4pFePWykLkulxtiw sSpDXMqOUlIhKDJxhMpypMESN7a+iQ+XiLOcKUH4uAnqMSFgTCQCSdm5EnJRJFb0Ul42IsbG/FI1 wVTKTqZiTAN6hFXGgx+h7vhIJx3SkDF658QsUv+y9zGwgvgUY8LsBsDzeXOMVxxOrSqpyYksVIPE zGdUoHg9McmvkBRN1qSYaUoKinBggJRi7fjWtvyd0Zqf+2g9TchPhaYlnSU5Z1BkWpo99s+Z2yJg /C66N3qGkpYADSjMPnm38D1PVHbE4zX1Y0njNFQiD3XokyapQ3u6sHQAfWNSpcZRkcpSj2bT5zMZ KUhRWTGhGGpqRZ4akahCNWgMtVAs2RazXR4MbLFUnE1ZaUpHJqybpnLZN131IbWuNaJxFSZMFUNT ckq0fUNMJrR4yr2SnjKOyfSpr+oEzUEWVigMMSytXppYxjQWU4sdyV6d1cnL9iyEJERhPaMlvqP/ GjGtcIVo5EprWt4uZpiQtUkza0fUYJmxomYNp0FvOyU0nVauvk1MiKoayZUi16jmCyxzf1Sg5xIx utJ1y0SXW93Zcs21HNtWbsvpp9QixrtSoZa9wPtE8hIsvQk521sRq1tzuvcwLxItkPTbVrZKtbf0 BTB+F9xfxghAAAV58IMFImHgnqSXik2wfDwk4PRGZsIDqTBBJAxhCks4Iye2SIozuB/S4oSxHIYu bn9nEBKPGMQmFgBGVqxiHts4xzcucU7c6hUi58oyxfnwj+0h4hwLWb0o9vGDdyziJofYykyu8JKz /OQVuhhtXwYQgSHyEwz/Fstc3jKJSdxjHbfZ/82SDHKXm/xjLK/5yf84MY/zPOXZsC/DM3YMfFsq 3vUi5M5C3jOf13yRJYO4ymiu8ZqD7GQ37/nOUWZzpkXSFSP3Z8wzMnCo56vhwlwZx4euMEgQ3edI c1nOqYbwlhX55j63uda3prKmdW3rRvc6zjcpU4xpXGp0UhXJQE72qUvsazh3hM0LUXOJXW1lEW8E 0SLBdLN7zOdFb9rbM4y0q/8M7Ll02MIIbnBMbTWmCN/Z3RPedq513dJxwzraqIY3R1asaF7/+tmt 7rWedfxuSr8a3gexd7EtdezgqhvGC+eIfB2uMX/vetE4pnO+kz3rhDMa4M7WSL/BTfJrX9yxHP9H 9bsLvuyOi3vj7L0wudf98PBGHOV9ObdWBOVojfv81B6f8sgzPfSSi/zf815x0BXe8mpPmuVpZvm8 VTtzkgza05fkL190PmQWq8XOGf84v5GOcbIf/eMmD3mmYw30hCCaIawOu43LTm95X5HpjzV23k1y daw7Vet64Xpb9Oa7fqdY22NXe60Vf/Y2ux3mbZd0oiEP5I6XU8rO1nSaER75qdudT6NOUSYBH3jS jxMmQGOJ4QNOcKHbeuiWD7qyJa8Qasvdy98eeeQP7uQGXvz3mE/75NC6dVHbxa1TWb2lXS/r2z++ y8+HusFjvW+B9/nKyo70m3ndbDgDX+1FZ9D/xGV+r/bsvu2Q7jn0p1/7uIMc5GxfdtSTPnJFJ57x EBo/39lN7JpTXCYvN21y53zUt2rWt369h31RF3evh21Td3KglnW7lXPGd3yGVmBapzY2EYDJRnee t3Zwp3Kwx2qLx4B1138HNoFS1XDkR4EouF+UUSGX1oBuloC8F3QGeID4V3Zm91v/BXo3R3j+FxL6 54NBSBip53DqN3nMhnHdh3ZGJ3zIdoTT8oPARIXlVnoviIGC9mKCh3sleIDcF4Y9aIRDCIRneIVp qHfFt4VkdoEsKBUO+HldiIVEs4YMZ4fE1zFwGHr+FYc0F3PZ0XcVGFqFeFj/1xuE9oZ3mIJ//9hi 8ZWEj+iISXF1ljhsiciIdQiJk9ETYcaFgEaJVmeFbChmhzhabmhBfSiK6kSKM+WKEgeLOGeKpueH 6QZmqSiBGmhmlSiLQsiKVBdoLQiM71V1NoeHqEWItaiL+6eHn6WCUMZpmtiIXxGBfweNavGFghiI xEiEmBiK1fiK67GK1wiOoBgVl+iM39iKgChseviJ08iOyFhmOqGN0TiM+eJn7bgbvihjMGiO8diL 7/iL/9iMDAaG+Fhk8GiLZtiNaFiQAskZ9viMmaiKTaGM2BiQ7jiP+hgY1MhgE9mPVSiS6EiSH6mR /Fh+kZghITmQy7hzC8mMEemQ6MF/MUgcLf/JkahnjO3lkhUpkxvZhhlJk21kkwnZaTEJkxdpkruo kyPpgkMJlMF4jz+plFWZFX5nlfJIlOLolL2jkgDJkFFpkVdZFklJH7Hok0cplikJlWEplT1ZcS+J lWd5H1mJiG9pgUuplgbJlW0ZjnspjFsJkUEJmFmIimNpiIHpl7PIlIfJlnFJi4mJl4OpkLlYjpWJ ktLIl5KxjjNJmH9pmJMImpFJmt6ojoU2l3YZJZj5mZa5iYzZkbHpdaZZlA13kAMyHrwIcV55kpB5 mr25h6+5lixJHjypYJw5iqgZnLuZl4ponMdpao55ivlFnbmpmuO4mDCIlrr5X4oJm7UJWkz/mY6c 6JxmuZPJWVPTeZnfaZ6ISZzt2ZeimZlk2YLWsp7geY6uqZnAOZukNp/7WZ/ymZ6ngZF5aZvBaY8K ap3rVJcowqB7x42eyJ6U2ZAAWpj6qZwJiqD16KAPip3XWZbv2Yn46Z4fOpkjCqIlaqADipQqim4S mqGb6YUvGqG8iYsiipDCyZ8PGZ6lKKOlOZwt+psc6qN5yJ356aI5yhN3maIa6p9fWZ5DCpf9aaRp yZzbuCLRqYbNKZ7LCaW+KR4QOnpLCqPKCQBguqP7GKRKCp91saA1SqYmyqRjSmtuWqFPWhBoelgA cKdOOqU8yqUXOpVC6afVGad2Sp9USptU/xmjgfqjj3qkaToQewqkGFqogPqmdaqjjkqkNUmgVWqp RSqqgkqq6ISmAJCqlCoQqaqqrNqqFtGnCPaUYFqEeWqqkmql9AiqoxqpVzqpDFGpNqpaqLqnrlqs ldqqqfoPyxqrziqrz6oR0HqpnhqgelmmwzqjaYqhTWom5Jmmyiqsr3qsrdpAzXquzAqt0xqtFyGr fTqt7yqthkqnagoccDqvZlodtpoR6/qfuiqt9kCu5RqwBDuw0biuCIsR7tquDAuv8uqwzJquyhqr BmuUmzqh2CqnmYqn1LGv2kqwenqoKGGwxfqqlDqwzRqxDBuxKRuvK/uyzrqy6tqwCkux5f8qrMYK sgiRs4O6mbT6r4zqq42Jq+tjsdKaskHrqf0aZ8rKqgHrqnoqs+66sA4LsTHrsuwaszCrss6qs8mq swVLEKgqtk6Ls2DrtEDrrxsapq15q0LLHEbrtqv6p5vJs+E6rpUKs+86szUrsy+LtSzbt1fLtSxL toY7t2j7tWVLtsk6tnNrrCSLtPh6ovc6uRp7HV1qbBwBq6WqmUursCcLtWLbtGjqt1UruFobuFu7 t+iqtawLq2b7uGDruE8bsocLsopbsE07ro0qty6FqJxKJVvqpbfLsSJRsqN7s5ALu6hLuIBLtTVr tan7vPwqrl67qtYbu7Ubtth7swaxu7v/+xGf+5i8Qb5CirnDixY727uEp7jgy7ifO7V667z8Gr19 S73hCq1ou7iIu7+4i7i0y72h+7+x27yhWrzAg0nVkrkbJhPiSroou71/S7+nu7nTG73hWr80e0U5 a7bWe7sB/MAmu7/ui7IdMb7z9cEzocJy2a3xWaDp+xIonLq5KhHIGro867XySsHxq7IVnLU7DK/v mxAefLL8W7vai8P+m70z3Ktnu7OiixcuPEw0mqQCWhJN7BP6mxNFXLEjrLpZi8ILu8Eb4bI/XLjr O7uMW7yNS8CJq6rLK6w5+bRRnMZrmozbOlVS2hJZTLgb+73fC7VxPLa727/IC7YUfL+B/7u0YwzE aOW4RYy9J3zBgVzHdIy7fVzDvvETmcyinYqldxwSmXy8x0sT7xu5Xuy+aizIGgzECUvGPrzIB5HD AhxzfBvG70rE/kvHo0zDnYukAMnCl0utwpEU/drLavvEaTzE16vLgqzGhmu/sPzKrswpkZy4YcvI F7yutou3A1y6xpzMUpyUwty7yGy5tCEU5+wR3FzOClHHN+zNRyzAuTvLq4zAJLvKzXvGcszPE5zC Sny2rcyms+zFMbyrCCyyJ6GuE3vAWugZjazJujy6uivPl4zNFD3PHWy4hKzMd3vNOhvEfky9grus 0ku/Emu162zBvnutMMG5eejO+UrKNv/LtzDtvUmczmbxyj3MrPaszAtRyHd7yYcswl/LwiC90bLb 0e/izydt01xr0gbMvBlsvtk6jDI9eE7xwVm9tSkxtcecrrWs1GMNzbaxiJcowg1RsR8tyIVsz0lt 1rXMy4DcvU0LxrEcr2FNsYnM19Vr01K9xcEaoujcwnM6y2VMElUdref61kf8wEfN0WfbxjktF6y5 wra7vN37089c2WuMvZ+NtwKLe9SM19P8z0er1/cr1fX608G7wwT50F+dsYmKxUg7sQ2d0nYLv4YM yEgd2v970UKd0A0KvGIEF7lLu7td13Gtp6T72dU8yfsszYOb0iUd20LLzWv9Jy+V1Vf/DRKBDdZU 29icjc8YrdHmfdEgDM1GHdqWPNMOvajxHRbJ/cS0LLt2DdPbTN2svd+Mfcy53dDfCsXvHcom8QEf 8LEFttKSa92na8RLvL3BndnpTcsh7Ni7rNboTc86bLN+LNHybaEUEcK8m7iJ3dcsna5Rjb9/zdDq OuCnp532gOAhfsIN3tBVy9XdXNERDtr4ndlDHeQRnsTZ28wA3K437eE268nChp4QRdJ+++GxfNp/ 7cOsbdBEO7RtquVpC6kMieBfzbmsi+QZDtwBzMZmnrze++OSvePLjcS3e+L6XdNMHprZ6BIJC9US m9qrvawwvuWf3LaE2uX/gOCGbhFg/17oCa7oiY7Wvh3Z/XvPPl7XvU3klD7hbf7YDL3ngJvSE5G3 5Iips93nL/vnV9zSeCgQNO4Qq94Sif7qi27ojf4BA0Hjtk7rM47rqz7YkUzD/AzUGl7WlR7Nkuvi Lt7aLwzeK+mWJfmlPTvfWSHrBGHotY7rw/wRsI7osb7th74/q/7ttL7rt34RYC7r5G7tGpvBPzzZ aQ7OA62ycL66Yt63dc7OUYqb8O3EYmrcMrHr0y7tuS7run7u2q7oBt8R5S7wGyHw4K7q4W7t/j7j 2s7wBV/wDJ/g3X7ujY7Wcd24A421/Z3aYK269d6jvyEj/vjs+j4XNJ4Rs47xi44RL/9v8TAfi7eu 6+he7Q108dtO8OY+8QrP6OYe8QGf8w5vp5vuzy2O5Kpd8ib/nFOsLxcbFq1+Ehu/8DXv8hCP80Vf nQlP8Brx8hR/8GSv9Qx/9AUx819/8Inep5WM12Dt9J+K3K4NEYq7IU4OrDiB5XVP6EIf80H/9wmu EDdP7bkO9n/P6Byx9mWP+Dxf8Y0v8z0P+QkP8A3f9bucxzK+GTpOsCPByOh60w1etDbh3XbsECst +T8f+JV/9OL+8DqP8DEv+WR/9UIf+QY/82E/+9lO+bOPVpfv8IY/4w7MvsUoFqbfoSm+zzgu5swb 1SoexmOS92Ph3Xv67uCt33ot3jP/9PoG0fBqD/hZj/uKj/W1//tfb/u5L/7mf0XBX/RGTxM8P/+G nvr3vhfJf+0LPe9JDvciDRD//gEYKFAgQYIGERpk2NDhQ4gRJRq0V9HiRYwZNW7k2BHARwAdMzJM OPGgQ5AIQSpcOTCkvZcVQ360GBNmRYEfPhjU6bDnv54/ge7UWTTozpxIGwp9eJSn0qRDpTKsqNOe 1aofNhYV2dXoV7BhoZokW5ZiV7Rp1W60uXZjQbMNW5J0WTIlSrofFZ4sWBIu3b8L9/pNODeuRLca D09MjJHv47iF57ZMifGlzbY3YUIWzJmh0J9go4ImOnbq6ac+lR41ihHr1deNNYql/w1WsVnZOHPv 5i277WK8kynvDSzX7l/kyDvDLaz84N3ihJ0DPts7N3DsZP2elK5S4MXMM2vKxAlYuly+3Umm9Ev6 dOjSqd3D3+naNmyu1vHXrq3f//+uMtMIpP8O2+64upojjqUFB3OwQefOa3A5BSmc7jjMNCMvJgEB VOufArMDMTwNb6LJIuoeTJE49iSDTkHuVvwMqaKmqlGq17D6yqL7cuPvRw+DFJK3DsF7S8ThhDMs urxWlJBF5hJET8Xk1INyIA1p4vCy8dgjbzyYTvRPRBCHTAyyGKmckr3nEFwTryvtsnCvi+6zUyve fuTPzK7i4pNIMEVK7qHtWNKrzf9Cp+wLQxkFsxLN89js67mIHi3IyC4x5TJM8TjNslPeyAyVTFLh bFLNUyFFM71U9ZJpJi1L5LRI2NDSs78/ORI1V45oFVRGkzo78K5DUx0UIgufTNPSA41trrlAv9wQ U/AInJVDaaPtU0ReeSW10GQrDUxYviyryVpPfUXrqVtb63Ykbt8NMbtDiV0UURXBpdQzZVFaidng +E2xRFDFxBbdaC9D+DpFyZLXMW5LlXjCx/TaTtNYPT131Ox4dJfPXR+27ts2CU3yy4PdjHJSOAlj s0WJGKXy4iyN3NJcMAnEVtsz462s25AZnjjkn18VT921gn5YaZFl+1ZJQx0yUdv/DGliNU3PokwU xkETJbTMjKd9dcBqDQ67N6bfTTvptZvmGDu37Wk7LaR75Xlb7JJ0UU6Lbc40W7mXa3hOmRGtF2vz SPI754xgnTrns+9eN96m556847gBtBxkykWuu2zBF1Nvyb423Fnsmow9lsViDf03ccQLrZlsgou2 nfbrvHbY7c1/heD3xTLXvPOlifew7tPP9VJ3ZJtPcKEls3UccKtZFni9n6E2VVVFNTuYWu8l39St DkX9fHjMhYYIAofYpwiCjuAX/rah4+49wNwEHJ/+4pznrljoDOxvpktYhJz0ncdJT1bMa5ZcZpcw gm0MVEbTX89iFhH7Gc8topKf/0Y6aBH5hTB+8+OfxN4GHOGd7yLH4lrLXuc/lwxwgeCZWYROVDXw aSZ2qsMh6kikMctYS4W6WtXuKpc+p5Hld+6jypA+WJEPLhF+UgThkO7HNiS+a4jwYl7MDPMyAGYs eTiTibP8JcYIZoiMCdTh9fgVRHTFUUxjotwWTxi83QAPbiLp4BN7E8IlVhEjIrQHIaF4SCJm0YIT IyFbHFkqlfBNkt+pYJi0tbLVKcdmXvII6thok4rNiXUHgeOW5qg+FPJOg1gEjh8B5MqMULGQhfwd CAM5y0Ei8iIi/If7mNhLgfxSarsZWqmsY8dgNY90UroXAg0WQXOxMGsskVaR1P/oSUE9i0H9qsui SLewRabyiIrcoPFgGcs/zrKWuwzkFGm5zl3Ssop+FCYw7ckQXwYTilI05JH2SMz6AbSLlZqklOxF tU1CDGDokRXKMNYppGHGjClC0OueZDeMFlNtq/xQWepZJv+cM5dRFKQsSQrPXB4SnvVk3y9b2r59 3pKeiMwnHhsJUCT9a5neAVvjHFotCFnKmZvMXvZo18MwVUxcFGOmcU7p08ZkBlg2TSI5WSlOjvRT PzK9pS3X2VVdunOeu7znQ5j40u8Asp3xfCIwXRrM9sEVlyTF5U3LU0zM7S88CltVhRhKvcVBFZsR lKYBF2SxpSJQSL5K7NdAWtX/f0IWqyOUjVZjOtOvyrSk6CypWe35ViaqM6tjxQla4Qrahoh2n7rc bF1lWVcP4ZWjablaX+nkPaPOEKEyLA/A5MQgp5rnqRt16kDveJjjxkWkueLnIKmoWUHaMrrqjGtD 3tpLD86VrSgybXXd+j7XilWlnF0rbGmKttkWL68KJOP3GDfDoKrOdQXtJkEyaNWO4pe26e3KcvkI W3d+VZ21xO50adrHQuLTugo2CPveaWAAQ9GzNT1tg8XLWdUeOMDxfKd/8RZZ9ZqwN3oVbEiwdrgq NQxfybkviMNJ1cYEtFv0XGlXlwjXBvcStGctK0txfNrmcviyBM5xWX/82Y0g/5i0403ykpOLG1Xq V71c05dS67vNf7V4si9GLk5la2RSZVWzNpbigiucY2GiVsEujXBKTyqR6+KztULWbna92keUxpi/ ZvpyWWILyUhu7bYiu6I/XVxO7Hx0IopuJVgjPMV1RqSlPI7zkXt8T9ZeOMMJrjSOQUvnNmuYnc5d aZMvd2ig9dkkT1Y1YqKM6v1K+cOt9m6iawlpBOMahEXmtVt5LOlLs5nUQxbvkbv73QaHl7wcfq2B m41KS7t6nLR+CKupPcxpbxnRsI51o69t3Zh6sNS0BHKRJ41mBve6uw5mZ3mZLOH1gTnN0n3ihdVq 3nBDmMt+wjDnvp1aL/9bsf8kLHQJYbzvVsI5mGUWkVpFSOYb/5rX+VSzp4MN0npvt4rpRvaZLU3p NSf7wZq2d79nfXDiCnzgelb5yhHe8seynNvrYjSji1lzCsc83x32qrF1jG6ge3bBoS35pt3Z64sj /azrvmeeH3xZr97R5tgmNMx1vm2VW3vVNy04vBpe3alzkOcjZa13mZ7mkAcdmE8f9ruNLuGK63Hi TH/sWunqaJmn8tn+brnWVe13qws8VC2kto/BDHC21ljACY72ZxfOcKWnvUwn1Thr8b1ZPF+648jW 9Mg73MGI7VlIgQf8l0sf+Guf3nmE5+fE8txciMt94WqnONKbbtZYZva5KXX/e8kl/uPap7XNRddj 2MOO8lT3PeCCXz7qnf/8qbYMTWh//J1Vqnh5z97jRq6440H9+Zk2OfxyS7rHgcf2dpcUeMdX+KKr /eqsNz/18od+/e0fGYdtqi2uhB/tf759w+u+jJunIJMny+M9skq3sxM5k2K2WyO/r7M1tPAwrGM+ /bBAybo/DXS5zNmVojqln1mZ7fgouVvAoMO3fsI1p6M8dPo9sGuithu7dwo8Csw99FK+bEO+/NpA HlQ9WrsjwnsTTLKwG1u769s9Jws/FoQ3ddM8B8MzU+sw0msMvEs5bUu+mTs5Hrw/H2Qk9JGYIKSL 8GkosnOyTAuvF1S7fnM4/0SaQrvqtiv0FtFLpC3cwC58vj/Lq9wqJf1Li6MDwPK7PLByODd8Qy3k txzsMmirw/q7Qzw0RN/QFMG6CRE0M3SLvTOcQauDxFOLw1zpOohhRA10ROcjRbsaF9uilDHMjCCT vfjjxI4ARTqStV8RRS6kP1EkxauDPzzSmY0pG0pMtDCDxVg0Pb7zxE60xUdcRGXURVPkOpirwTcs xLzrM0NTxmXMQGx0RlxstSDZxNyQxjzEQW3ERnP0Qma0RW5MR0b8xjk8RXBkx3b0unNUxHJUx27c Onmsx3gkRoP7Nl2kxpfjx/ejx3Ncx3skSILUMgysxmbMR4X8Ozo0xn1kDP+IjEiK9Mdk/LeA7EeH xMgfvEgMEkmI6EiQ1EE4PElaLEZ+NEmV9DOSLMiENKKZfEmNikmqmx9ZRJGFxEkZ20iBrECJ9DKX tEl9rEmLrLqbrMge9El0REpp+8ecHEhvTESjlC2EDLGr5EinFDGmHEmrnL+w3EqvhEqwVMpXnBdy /EixNMuS5EWu1EiDJEuZpMqkRMu01Ml3lMq2ZEuYHMuQlMtQpMu3/MrC1MqGtMu4dEu8ykp5CUq5 JMyo9EuaRMzFVEzJNKau5EAszEvBhMDMRDzGnEorTEyhDM2lHE3RtEyAzEc+Q83VxMzDZM2+lM1b /MyJRMk/gcwdRMZDzEz/xyzNy7RN+ytK1GPI4TxNKDNMmwzORhpK1YQ+58TNkfFI4oxN5ZTM6fTH nbyretxO6tzMYWRO0rwq2ARPWOxO0DxI8URO2ITB6KyO+MRI9ORE9VTI+rSivVyhUSRP7DRP1MxP Q7xP40lOAEVEvNTN8PRP+KRMshTQadzPwfTNioTQcaRQ/cTQ62zQDaXP9lxQ77RHB71L3FRPC/1C DdXI9+TQ7KxMEBVOBC1RCZ3FLHzNlczNFZXOD31R2vxL6jTRHU1QEe3QHIXOEZ1MHlXRBSVQBpXP HnXRFi3StSTSXUxSK3VHEp3QIY1SI33MGeXJ9xy9Lw1RBb1SMzXOLT3Q/9Z80qM8Uild0/ms0jOd U/Ek0JZsUs7szTd9UzrtUxr1TC5tSjyVU6Dc06p00zT1U0XVUwNl1Ic8RhZVU0O1xq5cVEtVS0CV 1HkMz0nN1JSMyEuNUJhD09uExk6FU0TV0VDlTusM1Kt0z1PNyFQFyVWVw1ENUvYEzFj9yVlVyTg9 Sxm91UEl1eUU0l3FyjrtyUFNTTbtUledTSoF0mU9VijVVLo8UftsVWvN0mdtTLik1pwsU5ZcUWzl z0ktVzCdUhgF10i1VXIN0l59UPUhAHoVCHolAG7dVkrV1S10VGn9VWWNU2L1UX1NUY24V4ZA2H9Q WGy714pw2Fr01E8M2P94dVIvFVYtlVUqHdhqXVIRgdiHpdeQJYBrNAiG1djONEd0rU6Mrdg8/dQY jdYxrdV1UdiTJQuEvVedBdaLzVWB/dba7Nby9FeCldkbFdVEvcHssNl6tdem1VmIjVqRtdHvhNd1 pbaVXU9xxVFU/UxZ7EGpJdmRtQeptYiw/c1ctNqrPdSfHdZkPVp4hNu5PM7emNqpHVuQhUCmxdd+ VduUbVSYLdaNfdsahUQ7Ldy5LUs9g1q+dVp8ZdyFdVzJddaChda1ZVtIJVS0HU+uxVqPlduMjVmh fdmOhFyTfVrT3ds2HVx+3dcfLdLPRdySTdpCpVyWJZOdTdimPV277V3/sR1Xg0VR04xM2I3d4DVX 2eXLvsXSf9JZjMjbkZ3cm63LnpVYYpRSED3c40VelXXZfM2v3OXdhUVds71bqBXTlvXa4mXH3ZxZ 7e3ey8XYuy1fsWVcjl1dwcRevyXajg3coh1dVTXW9I1f1w3Wd3VbBG5bgB3gvxVd4x1eFV1fBfbe rMVPoP3fyrXYP4VgVr1T7qXI96XdzcXfDC7OC+7f2g3TB95GwrVeQQmx+7XdiQXdD9ZfTqVYo1XX UOXN0NVcqt3edGVXFM7cR11gHf6QFe7a/HVfCebfEMbHaWVgJ/7eGT5i/6XeCm7iKo7VFubgFCZh d3XhiAViMhXhMT7P/xNW4SgWY+DdWuZl484dyicGzjRG4zWG49l14C324hFeXiP22WY14QHFYQDW 4Ab23Dvm4zMO0DoWVIIj5BL+zzBW5DYuYu+14Na1Q5/8YUqO4yHmZMD9Yj++ZA8W4LRN4CmW4isG 4z0O5T52ZFKu2kzuT1TOYcVlXVMOzD/u5FjW5FkW5AnGZb2k4QvU1lT25Vze1EBGZmFu5vZF2UNG 5F125UHG5GCuYWZ15kg2ZJotZlUWZVhW31J+Zm5eZSoGZ54tZNLNVjNO5Hb25DrMXkiOYGIuYz02 ZyRdYiXe4HfOYyh+3XEW56d85XTe5nK+XhauZlkG6IU2YEDWZnpu6P8OnOcOlmh9tmiDXmd2xuhj PugYzmfiDeiLfmh19mHDpWh01s4k/meHht9rDmmOxufQXOlTZmiSzmiTRt+CDmKX7mU8tueBrt6E tume9mZWJmc1nuZ97miNbmRmHumiXlUbVuqgxWk39mlejtublsNffsmPhmamptsMtWKEFulJ5lXl NdRKtmRbFuKjTk+UJmK3nmvLtWq6/uSTNuuzvutv1tpG7GJ2VVRrXma+1uW27ue0LmwZFp7BFmrF JmuCRlaqfux7TuZRdmzKpua1ruqwzuyglmtadWrP9tZJBmoMTunR/uxojmmkTm3Orui0dG3BJWDV tlLZzmpThexFpmv/WDVs1L7qxL1tsIZt3O5ht+5t3wZl4dZr4tZseF7seBZt0rbs5aZlonZuf5Zm rEZs4cXuC73q6r5lqPbu4Nbuwa1npf3p7q7s9XZtee7r3X7t35bk5l7qVmZvqY7rjVZv48Zrni7N 99btsSbjiZ7t77bvshbw5wbpbsZs+QZt/0Zatb5h+N7s027w1cZcB7/wBFdmDLdwDS/pD0fuEM/w c4Zr5u5mHp7vdh1xCC/xvTZwmN7qBl/xyMZiF29t8sZU4H5O/R7wPc3aHJ/st1ZuGY9oGtdx/Mbm v67lIVfy4hZy6QZmwsbxzl7sGx/aJ9fpJM9y+kZx1n7xE49vDq9y/y3f8gNnaxEnyp5x5wc38jIn 8whPb8lGcyiv6TRvcRYX7yuv7Tuf8/IGdB4fczuPcTwXaP5m8lI1agKfWQtN7h3+cYVOdJ4eagre 3/uOcxCndMaWdAmP8kpXc5yWcicf9T4/8kw/9PFGcC8P4EsvdUMXdEWXdTqtR3649QAHjlt3iFvv dX7YaZlm7TnWdC7v8VkvciBXyF+v8IzodRKfCF9fdoOI9l4XCGq3CGp39pImTFJ/6VPP6TfGcjo3 i2pH72dfjGyXdmvP9otId3evCG23B18f9Kg29a7+8lb3aDin8nAnd1wXknhv77JQ92r39XU3+Cp9 d2zHiHifd3l3+P+H54eIZ/h/P3ZLz/emXvDh3vOM73fKzo2A95CQD3Vyn/Zsfwh2h3d2T3eOcHiI b/aKD3htP/h/cPddR+ttZ2Jmz25av92kxnhUF4mRd+Jy5/VoN/mjZ4iGZ3lsV/iXl3mJ3wioj3qc OHmaR3ql33WbV/eOT2xx3/Sv1/i6jvVrHfKixw5qR3qEr/mUj/hob/eY13aIn3qVp/q6D+6zz3ur Z3uCv/m7H3qv120bl3NkL3ZGrm/oK/i1V/ubP/i3d3u5j3y7p3iqX3q7l3y4v/mz5/vGlwi9l3bL b/rL/3ea3/xj7fbtFvU5rUObF/1rV3m4F/3Mn32pj3vQ7/xy3/r/q8/6pK/90Y/6z8d64b/6ze98 D4X1VOd2DF/0tZh723f9ifd92S+P4k/73Q9+zn/56If5eYcI7C/6tcd+4nd3fl/zez/JD2f1uAl5 Z2d/XE/6hgB/45f/vQ/96Q/5+Dd+o799/ud9xwcIfgIH/itIsOC/gwYFIkw4UGHDiBInSrRn8SLG jBo3cqT4jyPIkCI7eixp8iTKlConjmzp8iXMmBlX0kQJsyZOmRchOuTX8+HDn0ERKlRoceBRpEn5 7WS40CdRpzwdPo3otCrWng0PAgUaFWpWnA11ki1rFqTYtGrXVrRI4O3ZuHJdslV7ti7etTwJdvX6 0V7XpkyXXsQK/7Ho1cOJr2pt/NVvVsVgE66dS9am5Zl2W+bNO/ItAYygRcPNbFpz55V3N58um1ap YMACQ1pdDFYyVMS2v2613ZV37aFsz/YtPhu1WMs5za59m7b06dEXpbuF3lpjapqr017fmJ0l2b0M p27tfZsx16HGz7M3H5zx8rLr58Ov2f2+xe8nqevkn5k/gNbRpd9J2yWHH20EKiiRZMBFJRRu4xln HmTkqWYWffNVhuB1C5qkkX8ZhRjTiC+BJmCAodlTEGgeRmSgfRyS5CKHr034VF8QToZjbuntiJl8 Gd7InYynueiRaSVWp2JZJzo5HVxOqthiiwhVyaJzVmZ5oWusFf+J0ZEb4mfjbwyWORxsMAk55IFf KhcmXtcpac9oU54o4pN0Xrmncyc2tCWfBPyZ5ZIyielmfnB2hmiCONWnXUzHybbmmW0yCqOihyIq nZRMQlkllYAKiuWogWop6JX/ULeqddKRGuOlmXp2qZFe6kQpm5DSyhycqRJJq5SfQuekqln6GhGo oo6KrLHKnqqnp50Ou2Wxoxb6paxx0potRcThCplKQO2KqVrHrpTsslXumieroUlZ7bLVygvvq/N6 hO6pp/pZ7af9pgjSv+RyqyujmjaqIEbf/kjwuIYOPGi8H4JYWrtyTetunhOXiqqz+9prb6jpNhsx s3Z2ei2nF/v/26qAL+X7sEq7GtwhzBI3rFPNll47ksQV3wnwz9Dm6/FE1NYrb6pJd+wcyi2TZvJG FUPbb6H8gSxyvEqTjPC2trqZc0E3XwY2ww5DnBLUU0uLb9F9jjy00SVLZKq6Uwv7pNRzpuwp1Xab Su+x77589K8Fe43t4TMu2DXZMfNK5MkaL1kv2/R+PHjIcG/9LJ5M1slytE7n7fSnmHO8sbJuv2uu zl8nLuPMN6Uktkh4mcv6uYQ+LtbFKUI37+1vF/vy35cfHfLKfHc+t8oB7/z0isDHfba+qRNdOKKx w/76gB5u/3DwW5P4e7kZZwytn2xnfvXmI3tceYvP9/051sZD/yx51aURfjX71be9ueO6VCDFxcdw 2DNb4xK4OPkxMHrPwdvegka09YFqcKY7nQUhJi2qVWx/x1Nd8kKyL9WRCoMZhJfwuMcZbslMhTxT IJDEpr3uhQ8858Nf+jKXQ9RRD2lxE1z/pKaxKL0vheoakc/cZ7+SWW99M1xhtlp4wJjAMIY4mx3t 0FK+oD0taD4EoPreRjdqjTFY6KNfsIrHxNOFLm12e2PnhIbCHXJNgLKSYuuoWEWbjc17NdqMGTcI JQ8CzojTkx4Pv6i5LrILiCW0nxCHiD7ovdFVuCOWlZ74wjsyLo+y2yOSdlfFLKJlacJzFvPqp0bq 7S1/niNi1rYOqS/JIRGNQHtlLLGGSU3WjoWdhFUfQQkeOwqzmLYj4atW+UE23pCDp0TmFykpQlg2 7ZX56dS9ZFk2PUbxl8P5pDERIrBwThGPDyRWGfsmTfqhbWTVrCQ114kxO1Uvl7jbJjgzZU5yDmyc /MQnKV1ml1YmsX6pXGRLWum3eO4tlYHSphURuMda/fNh/qwoFgOKnDqSpYwIheP8KDYtjjQUkXME IEC798+LYtSPxGwpMDWqRZQEBAA7 ------=_NextPart_000_000E_01C75C34.F8373190-- From owner-ietf-openpgp@mail.imc.org Thu Mar 01 13:28:50 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HMq1K-0004l2-LP for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 13:28:50 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HMq1C-0004lK-Uj for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 13:28:50 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8x1t054493 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l21I8x2b054492; Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8vZA054485 for ; Thu, 1 Mar 2007 11:08:58 -0700 (MST) (envelope-from dshaw@jabberwocky.com) Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l21I8hZ00380; Thu, 1 Mar 2007 13:08:43 -0500 Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8cqo015067 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 13:08:38 -0500 Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8a6K022649; Thu, 1 Mar 2007 13:08:36 -0500 Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l21I8XxU022648; Thu, 1 Mar 2007 13:08:33 -0500 Date: Thu, 1 Mar 2007 13:08:33 -0500 From: David Shaw To: OpenPGP Cc: jon@callas.org Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt Message-ID: <20070301180833.GA22614@jabberwocky.com> Mail-Followup-To: OpenPGP , jon@callas.org References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc User-Agent: Mutt/1.5.13 (2006-11-21) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: f66b12316365a3fe519e75911daf28a8 On Mon, Feb 26, 2007 at 09:21:17PM -0800, Jon Callas wrote: > > I've submitted bis19. This should be within epsilon of complete for a > whole lot of epsilons. It has in it text to address the IESG > concerns, as well as the IANA considerations in a brand new section > 10. The *only* thing that there should be comments on is the IANA > considerations. This looks really good. I have a few minor comments about the additions. This might look like a lot, but I think there was a cut and paste error that explains some of them. ********************* In section 5.13, in the non-normative explanation of MDC: The sentence "(Note also that CBC mode has similar limitation, but data removed from the front of the block is undetectable.)" needs an "a" between "has" and "similar". The sentence "Suffice it to say that many people consider properties such as deniability are considered to be as valuable as integrity." is a little tangled, language wise. I suggest removing the words "are considered". "OpenPGP addresses this desire to have more security than raw encryption, and yet preserving deniability with the MDC system." is also a bit tangled. I suggest changing "preserving" to "preserve" and adding a comma after "deniability". ********************* Section 10.2.2.1 (Signature Notation Data Subpackets) says "Adding a new signature Signature Notation Data ..." The first "signature" should be removed. ********************* Section 10.2.2.2 (Key Server Preference Extensions) says "OpenPGP signatures contain a mechanism for preferences to be specified about key server preferences." That's one "preferences" too many. ********************* Section 10.2.2.3 is titled "Key Flags Preference Extensions". I suggest removing the word "Preference" as key flags aren't really preferences, and the rest of that section (correctly, I'd say) doesn't call them preferences either. ********************* Section 10.2.2.4 (Reason For Revocation Extensions) seems to have a few cut and paste problems and is co-mingled with the section after it. It refers to "the feature flags value". This should be "the reason-for-revocation flags value". In the same section it says "Adding a new feature flag...". That should be "Adding a new reason-for-revocation flag..." The reference to section 5.2.3.24 should be 5.2.3.23. Finally, the sentence "Also see section 10.6 for more information about when feature flags are needed." actually belongs to section 10.2.2.5 (Implementation Features). ********************* Section 10.2.2.5. (Implementation Features) has a mirror image of the problems with 10.2.2.4. It refers to "the reason flags value". That should probably be "the feature-implementation flags value". In the same section it says "Adding a new reason for revocation flag...". That should be "Adding a new feature-implementation flag..." The reference to section 5.2.3.23 in this section should be section 5.2.3.24. The sentence "Also see section 10.6 for more information about when feature flags are needed." from section 10.2.2.4 actually belongs here. ********************* David From owner-ietf-openpgp@mail.imc.org Thu Mar 01 19:23:00 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HMvY4-00057E-Fk for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 19:23:00 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HMvY2-0008I8-3a for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 19:23:00 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207NQl079627 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2207NgS079626; Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207M4s079619 for ; Thu, 1 Mar 2007 17:07:22 -0700 (MST) (envelope-from jon@callas.org) Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 406F056F7CB for ; Thu, 1 Mar 2007 16:07:22 -0800 (PST) Received: from [10.240.72.119] ([208.54.15.1]) by keys.merrymeet.com (PGP Universal service); Thu, 01 Mar 2007 16:07:22 -0800 X-PGP-Universal: processed; by keys.merrymeet.com on Thu, 01 Mar 2007 16:07:22 -0800 In-Reply-To: <20070301180833.GA22614@jabberwocky.com> References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> <20070301180833.GA22614@jabberwocky.com> Mime-Version: 1.0 (Apple Message framework v752.3) Message-Id: <96F3CC13-7B61-41DB-BE4D-78B33A4D2D3B@callas.org> Cc: OpenPGP From: Jon Callas Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt Date: Thu, 1 Mar 2007 16:07:18 -0800 To: David Shaw X-Mailer: Apple Mail (2.752.3) X-PGP-Encoding-Version: 2.0.2 X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7BIT Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.3 (/) X-Scan-Signature: ffa9dfbbe7cc58b3fa6b8ae3e57b0aa3 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > > This looks really good. I have a few minor comments about the > additions. This might look like a lot, but I think there was a cut > and paste error that explains some of them. > Yeah. They're all fixed. I'm submitting the resulting bis-20. Jon -----BEGIN PGP SIGNATURE----- Version: PGP Universal 2.5.3 Charset: US-ASCII wj8DBQFF52q6sTedWZOD3gYRAoANAKC2aYeLwv6Il4tc5z/jO9CdCI7HIwCgs4fv n+ca/0oqgnlUfhSVbkaTnmw= =pkVx -----END PGP SIGNATURE----- From networkshawaii.com@ffissy.com Fri Mar 02 18:09:44 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HNGeS-0000RU-7N for openpgp-archive@ietf.org; Fri, 02 Mar 2007 17:55:00 -0500 Received: from [65.112.166.5] (helo=localhost) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HNGa5-0007XL-IN for openpgp-archive@ietf.org; Fri, 02 Mar 2007 17:50:31 -0500 Message-ID: <000001c75d1c$0bb18800$0100007f@localhost> From: "Austin Morris" To: Subject: She will love you more than any other guy Date: Fri, 02 Mar 2007 15:50:29 -0700 MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2900.1524 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.1523 X-Spam-Score: 4.0 (++++) X-Scan-Signature: 7bac9cb154eb5790ae3b2913587a40de Several millions men have been helped with the potent ingredients in Penis Growth Patch (TM) - men have experienced bigger size, deeper penetration more action, and super-satisfying results for themselves and their partners. Don't be left behind! Take advantage of price specials going on now. Click here and visit our site! http://www.gerax.hk/ From owner-ietf-openpgp@mail.imc.org Tue Mar 06 08:23:48 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOZds-00048F-SN for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:23:48 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOZdk-0002gi-D6 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:23:48 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26CspEc061037 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Csp5L061036; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Csoiv061029 for ; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1937128wxd for ; Tue, 06 Mar 2007 04:54:50 -0800 (PST) Received: by 10.70.131.19 with SMTP id e19mr7986508wxd.1173185689787; Tue, 06 Mar 2007 04:54:49 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10249934wxd.2007.03.06.04.54.48; Tue, 06 Mar 2007 04:54:49 -0800 (PST) Message-ID: <45ED6495.1040407@buanzo.com.ar> Date: Tue, 06 Mar 2007 09:54:45 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: OpenPGP Signing of HTTP POST X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: f4c2cf0bccc868e4cc88dace71fb3f44 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear OpenPGP WG team, One day at 3am in the morning I woke up with a mix of two strings in my head: "POST / HTTP/1.1" and "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about the whole idea, and as I couldn't go back to sleep, I got up and wrote it down. A couple of months later, and some BIG thinking, I decided to create a Firefox Extension to implement what I am now going to describe, and what I want to rewrite into a proper Draft: For years different methods for User Authentication and Session Management have been implemented: * HTTP Authentication * Cookies * GET/POST values * SSL with client certificates * A combination of all the above. Regarding SMTP, e-mail has been digitally signed for a long time now, and it is a standard. Extending its usage to the HTTP protocol sounded like a natural idea, specially at 3am when I woke up with a OpenPGP-signed HTTP POST request in my head. By having the POST payload ("variable=test") signed using an ASCII armored, Clearsign, OpenPGP based procedure, the browsing user can provide Identity Authentication to that payload, thus adding all OpenPGP benefits to the HTTP POST request. This allows web developers to add a new layer of security to their applications, and if correctly implemented will render man in the middle attacks useless. The direct benefit of implementing this extension is that web developers will be able to verify the POST payload signature, potentially avoiding obscure session management, and/or complicated login procedures. For example, Highly Secure Home Banking sites could be created by using Enigform + some simple server side code. For a demo of an Enigform-based login procedure, with using AJAX and FORM SUBMIT, configure your GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar. Enigform: http://enigform.mozdev.org Latest Version: 0.6.5 Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html Hope you like it! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7WSVAlpOsGhXcE0RAt88AJ0cyBuMS/U0qZjwTZ9DrnE1jxRmUwCfdYqN +GAVdVxL/NfUvvvdA0RJolc= =m/4G -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 08:36:00 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOZpg-0003u7-CJ for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:36:00 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOZpe-0004GZ-UK for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:36:00 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ3LF063660 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26DJ3bm063659; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from mail.epointsystem.org (120.156-228-195.hosting.adatpark.hu [195.228.156.120]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ2hP063653 for ; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from nagydani@epointsystem.org) Received: by mail.epointsystem.org (Postfix, from userid 1001) id 20C5B3E8E; Tue, 6 Mar 2007 14:19:01 +0100 (CET) Date: Tue, 6 Mar 2007 14:19:01 +0100 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST Message-ID: <20070306131900.GA25665@epointsystem.org> References: <45ED6495.1040407@buanzo.com.ar> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="9amGYk9869ThD9tj" Content-Disposition: inline In-Reply-To: <45ED6495.1040407@buanzo.com.ar> User-Agent: Mutt/1.5.9i From: nagydani@epointsystem.org (Daniel A. Nagy) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 386e0819b1192672467565a524848168 --9amGYk9869ThD9tj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable I think that this is extremely useful; I was enterntaining the same idea myself, albeit in a slightly different way. I think, that the standardized protocol needs to have facilities for both client-, server- and content-authentication. May I ask what the status of the draft is and how do you enter changes into it? On Tue, Mar 06, 2007 at 09:54:45AM -0300, Arturo 'Buanzo' Busleiman wrote: >=20 > Dear OpenPGP WG team, >=20 > One day at 3am in the morning I woke up with a mix of two strings in my = head: "POST / HTTP/1.1" and > "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about t= he whole idea, and as I > couldn't go back to sleep, I got up and wrote it down. A couple of months= later, and some BIG > thinking, I decided to create a Firefox Extension to implement what I am = now going to describe, and > what I want to rewrite into a proper Draft: >=20 > For years different methods for User Authentication and Session Managemen= t have been implemented: >=20 > * HTTP Authentication > * Cookies > * GET/POST values > * SSL with client certificates > * A combination of all the above. >=20 > Regarding SMTP, e-mail has been digitally signed for a long time now, and= it is a standard. > Extending its usage to the HTTP protocol sounded like a natural idea, spe= cially at 3am when I woke > up with a OpenPGP-signed HTTP POST request in my head. >=20 > By having the POST payload ("variable=3Dtest") signed using an ASCII armo= red, Clearsign, OpenPGP based > procedure, the browsing user can provide Identity Authentication to that = payload, thus adding all > OpenPGP benefits to the HTTP POST request. >=20 > This allows web developers to add a new layer of security to their applic= ations, and if correctly > implemented will render man in the middle attacks useless. The direct ben= efit of implementing this > extension is that web developers will be able to verify the POST payload = signature, potentially > avoiding obscure session management, and/or complicated login procedures. >=20 > For example, Highly Secure Home Banking sites could be created by using E= nigform + some simple > server side code. >=20 > For a demo of an Enigform-based login procedure, with using AJAX and FORM= SUBMIT, configure your > GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar. >=20 > Enigform: http://enigform.mozdev.org > Latest Version: 0.6.5 >=20 > Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html >=20 > Hope you like it! --9amGYk9869ThD9tj Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iQDVAwUBRe1qRK6pEulQFnIMAQIvqQX9HkflhwbcVpbq1maV9Yf+Ec3xBK5q8bh1 26+0LJZcu0l02ue2G49odlKPfhIYlai4A79dikmcF35ef8nUBYwYnoO3pP5HVqAD aUUIlC4Z8uLiXoiozg8coodH/kwqkn7gx4MbRayNljurkWcejdTRaRBNORRz5J/p NgYLAMC2pIYjW3funDZ3Ub8Gu0Ssw913CWhOVtYuAW7d1tWPCMn33sF4+gdkSImn px/FclwfD78vsPFOCfxcNSgloQRmSQUh =LtlV -----END PGP SIGNATURE----- --9amGYk9869ThD9tj-- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 09:12:48 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOaPH-00059u-I8 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:12:47 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOaIG-00081n-LT for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:05:36 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5tm065994 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Do54e065993; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.237]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5CI065987 for ; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1951840wxd for ; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Received: by 10.70.66.18 with SMTP id o18mr11759820wxa.1173189002805; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h38sm10276388wxd.2007.03.06.05.50.00; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Message-ID: <45ED7185.2010300@buanzo.com.ar> Date: Tue, 06 Mar 2007 10:49:57 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> In-Reply-To: <20070306131900.GA25665@epointsystem.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: c1c65599517f9ac32519d043c37c5336 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Daniel A. Nagy wrote: > I think that this is extremely useful; I was enterntaining the same idea > myself, albeit in a slightly different way. I had this idea in March/April 2006. Just had time to implement it last month :) > I think, that the standardized protocol needs to have facilities for both > client-, server- and content-authentication. Yes, of course. > May I ask what the status of the draft is and how do you enter changes into > it? The draft is behind the development status of the Enigform Firefox Extension. Currently, HTTP POST requests generated via AJAX calls, or FORM submissions will be picked up for signing by Enigform by checking if the ACTION URL (or Ajax request url) ends with "##ENIGFORM_Sign##". I had tested this with a hidden input field of a special name/value combination, I've also tested using an extra parameter for the
tag (SECURITY='ToBeSigned'), but all of this made the extension's code overly complicated, and incompatible with certain sites. Checking the URL was quite a simpler approach. Of course, the correct (i think) way for a FORM submission to be signed would be with a special enctype (like urlencoded-openpgp-signed), but that would render ajax support useless, too. Additionally, AJAX requests can't be diferentiated from form posts from within a Firefox extension. Adoption of this technology is easier via a Firefox extension, and a simple set of server-side code (that's why I talked with Rod, author of Smutty, to extend it with Enigform support). Regarding changes to the draft, no specific procedures have been established, yet. This is my first attempt. I'm open to suggestions. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7XGFAlpOsGhXcE0RAoS1AJ9kFXExRm9QAkxtQ5TJbndGe7eURwCbBYA4 C8sg7uGRJ7UWJUjdxNTFG/0= =Wdrc -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 09:17:37 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOaTx-0000bC-7A for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:17:37 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOaTs-0002lf-Qw for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:17:37 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2hM5066817 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26E2hkg066812; Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2eEc066804 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 07:02:42 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOaFS-000PPs-TN for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 16:02:39 +0200 Date: Tue, 6 Mar 2007 15:59:14 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <642100057.20070306155914@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <20070306131900.GA25665@epointsystem.org> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> MIME-Version: 1.0 Content-Type: text/plain; charset=windows-1251 Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Content-Transfer-Encoding: quoted-printable X-MIME-Autoconverted: from 8bit to quoted-printable by balder-227.proper.com id l26E2hM5066817 X-Spam-Score: 0.1 (/) X-Scan-Signature: b19722fc8d3865b147c75ae2495625f2 Hello Daniel, Btw, in my plans also is writing and implementing something like 'PGP security over HTTP' specification, and already having some ideas 'bout it (it's something other than proposed by Arturo). Maybe, consider writin= g it in a group? DAN> I think that this is extremely useful; I was enterntaining the same = idea DAN> myself, albeit in a slightly different way. DAN> I think, that the standardized protocol needs to have facilities for= both DAN> client-, server- and content-authentication. DAN> May I ask what the status of the draft is and how do you enter chang= es into DAN> it? -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] [Now playing : =CF=E8=EA=ED=E8=EA - =D8=E0=F0=EC=E0=ED=EA=E0] From owner-ietf-openpgp@mail.imc.org Tue Mar 06 10:10:27 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HObJ5-0003fL-9c for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 10:10:27 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HObJ3-00044X-T2 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 10:10:27 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em5th070744 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Em5tA070743; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em2Qu070736 for ; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1970241wxd for ; Tue, 06 Mar 2007 06:48:02 -0800 (PST) Received: by 10.70.90.14 with SMTP id n14mr11850088wxb.1173192482284; Tue, 06 Mar 2007 06:48:02 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10439741wxd.2007.03.06.06.48.00; Tue, 06 Mar 2007 06:48:01 -0800 (PST) Message-ID: <45ED7F1E.90408@buanzo.com.ar> Date: Tue, 06 Mar 2007 11:47:58 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> In-Reply-To: <642100057.20070306155914@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=windows-1251 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.2 (/) X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Btw, in my plans also is writing and implementing something like 'PGP > security over HTTP' specification, and already having some ideas 'bout > it (it's something other than proposed by Arturo). Maybe, consider writing it in a group? Please, expand that! What are your ideas for OpenPGP security over http? - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7X8dAlpOsGhXcE0RAgcUAJ0eDb6SQRJpTbw8HbchprbiZa2pcACfUOSJ GxrIHHPmQ0eeQXDzmrY2hT4= =urng -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 12:37:19 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOdbD-0008Gw-V8 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 12:37:19 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOdb9-0001Q3-HF for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 12:37:19 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFkGd082613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26HFk85082612; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFjXW082606 for ; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2016733wxd for ; Tue, 06 Mar 2007 09:15:45 -0800 (PST) Received: by 10.70.84.6 with SMTP id h6mr12037573wxb.1173201344993; Tue, 06 Mar 2007 09:15:44 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i35sm10629647wxd.2007.03.06.09.15.42; Tue, 06 Mar 2007 09:15:43 -0800 (PST) Message-ID: <45EDA1BB.8070606@buanzo.com.ar> Date: Tue, 06 Mar 2007 14:15:39 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> In-Reply-To: <1976536264.20070306190040@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 02ec665d00de228c50c93ed6b5e4fc1a -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Hello Arturo, Hello, Nickolay. You forgot to reply to the list. > ABB> Please, expand that! What are your ideas for OpenPGP security over http? > Something like cleartext signing for HTTP - PGP-Signature headers and > so on, and also encryption/binary signing of http document body. Enigform currently adds an X-Enigform header with "Signed" value. I will be adding extra OpenPGP parameters (fingerprint? keyid?), and the ability to also encrypt. Currently, only http POSTS are supported. A signed request looks like this: POST /pba/postverify.php##ENIGFORM_Sign## HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 X-Enigform: Signed Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 variable=test -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: POST signed using Enigform iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== =wVHP -----END PGP SIGNATURE----- What are the extra ideas you have? - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7aG7AlpOsGhXcE0RAtCEAJ95pYoWzioR+L+qLQAkMZdEsLWSsgCeO0dM ns6HspQOJQQf3+fpi6nMFdI= =BEZt -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 13:21:27 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOeHv-0007B5-FU for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:21:27 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOeHr-0000iL-1D for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:21:27 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5u7U085551 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26I5uPT085550; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5sDZ085544 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOe2r-0007gS-A0 for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 20:05:53 +0200 Date: Tue, 6 Mar 2007 20:02:22 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <1466251624.20070306200222@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <45EDA1BB.8070606@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 34d35111647d654d033d58d318c0d21a Hello Arturo, >> ABB> Please, expand that! What are your ideas for OpenPGP security over http? >> Something like cleartext signing for HTTP - PGP-Signature headers and >> so on, and also encryption/binary signing of http document body. ABB> Enigform currently adds an X-Enigform header with "Signed" ABB> value. I will be adding extra OpenPGP ABB> parameters (fingerprint? keyid?), and the ability to also ABB> encrypt. Currently, only http POSTS are ABB> supported. A signed request looks like this: ABB> What are the extra ideas you have? Your format changes the HTTP protocol, which disables backward compatibility, and could add other problems. For example, we can do as following : POST /pba/postverify.php HTTP/1.1 X-PGP-Message: Cleartext-Signed X-PGP-Signature-Hash: SHA1 X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux) X-PGP-Signature-Comment: POST signed using Enigform X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 variable=test Where signature is to be calculated over all message (including header fields) after X-PGP-Signature. So, it will correspond to such OpenPGP message, which could be sent to GnuPG for verification and so on : -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 variable=test -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: POST signed using Enigform iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== =wVHP -----END PGP SIGNATURE----- Such simple translation on server and client side allows you to use HTTP protocol as it is, and allows backwatds compatibility for applications, which aren't compatible with such extensions. I'm going to write complete draft of my ideas and publish it after week or so. -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] From owner-ietf-openpgp@mail.imc.org Tue Mar 06 13:36:04 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOeW4-0000kd-Ig for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:36:04 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOeVx-0003k6-Ux for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:36:04 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJSpi086454 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26IJSGu086453; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJRt3086447 for ; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2035166wxd for ; Tue, 06 Mar 2007 10:19:27 -0800 (PST) Received: by 10.70.23.1 with SMTP id 1mr8344182wxw.1173205167633; Tue, 06 Mar 2007 10:19:27 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10810882wxd.2007.03.06.10.19.25; Tue, 06 Mar 2007 10:19:26 -0800 (PST) Message-ID: <45EDB0A9.80207@buanzo.com.ar> Date: Tue, 06 Mar 2007 15:19:21 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> In-Reply-To: <1466251624.20070306200222@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 21c69d3cfc2dd19218717dbe1d974352 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Hello Arturo, Hi Nickolay, > Your format changes the HTTP protocol, which disables backward > compatibility, and could add other problems. Remote sites have to tell the browser that the request should be signed, thus, only compatible sites will receive such requests. In any case, I'm only modifying the body, and adding a header. No request-specific structure is modified at all. Only proxies and/or content scanners and/or webservers that make any kind of verification over the BODY might be problematic. In any case, as Apache+PHP provide the RAW POST body, I don't think an openpgp signed body would make any problems. Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick hack, and that's why I'm here. An official extension to the HTTP protocol, or better yet, a new content-encoding, should be analyzed. > For example, we can do as following : [...] > Where signature is to be calculated over all message (including header > fields) after X-PGP-Signature. I thought about this, too. What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of that same reason. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7bCpAlpOsGhXcE0RAkokAJ0W4QaNgmIgq+9QBTto0F2kQ+1D+gCfeUGt IoUmfdm9B2DK++gsvrdO138= =dyTr -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 14:26:07 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOfIV-0006Ki-4j for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 14:26:07 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOfIT-0004Hu-BM for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 14:26:07 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9kHR090279 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26J9kTn090278; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9frq090269 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOf2a-000B0r-8z for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 21:09:40 +0200 Date: Tue, 6 Mar 2007 21:06:09 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <1682706895.20070306210609@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <45EDB0A9.80207@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 3e15cc4fdc61d7bce84032741d11c8e5 Hello Arturo, ABB> Remote sites have to tell the browser that the request should be ABB> signed, thus, only compatible sites ABB> will receive such requests. Sites can tell the browser, that request should be signed by using simple header field, like 'X-OpenPGP-Signature-Needed: true'. And if reply will be sent without signature, then server will throw to client 403 or any other error. ABB> In any case, I'm only modifying the body, and adding a header. No ABB> request-specific structure is modified at all. Only proxies and/or content scanners and/or ABB> webservers that make any kind of verification over the BODY ABB> might be problematic. In any case, as ABB> Apache+PHP provide the RAW POST body, I don't think an openpgp ABB> signed body would make any problems. ABB> Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick ABB> hack, and that's why I'm here. An ABB> official extension to the HTTP protocol, or better yet, a new ABB> content-encoding, should be analyzed. New content >> For example, we can do as following : ABB> [...] >> Where signature is to be calculated over all message (including header >> fields) after X-PGP-Signature. ABB> I thought about this, too. ABB> What if other fields are added, after the X-PGP-Signature is ABB> calculated? What about [non]transparent ABB> proxies? OpenPGP tags the beginning and end of the data that ABB> corresponds to the signature because of ABB> that same reason. If you are using non-transparent proxy, it means 1) you doesn't care about headers, they must not be signed - thus, you can add parameter, something like 'X-OpenPGP-Signature-Param: no-headers', which causes to sign/verify only the message body (non-transparent proxies doesn't change message body, yep?) 2) if some headers are significant, there can be parameter, something like 'X-OpenPGP-Validate-Headers: User-Agent, Accept-Charset, Referer' -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:03:35 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOfsl-0000pI-6b for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:03:35 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOfsj-0002gw-Pu for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:03:35 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JibYw092282 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jib6C092281; Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from rediris.es (chico.rediris.es [130.206.1.3]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JiZKo092265 for ; Tue, 6 Mar 2007 12:44:36 -0700 (MST) (envelope-from francisco.monserrat@rediris.es) Received: from dune.rediris.es (login.rediris.es [130.206.1.21]) by chico.rediris.es (Postfix) with ESMTP id E77D944DE4; Tue, 6 Mar 2007 20:44:31 +0100 (CET) Received: by dune.rediris.es (Postfix, from userid 500) id 705B318212; Tue, 6 Mar 2007 20:44:31 +0100 (CET) Received: from rediris.es (localhost [127.0.0.1]) by dune.rediris.es (Postfix) with ESMTP id 6E0E9181B8; Tue, 6 Mar 2007 20:44:31 +0100 (CET) X-Mailer: exmh version 2.7.2 04/04/2003 with nmh-1.1 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org From: Francisco Jesus Monserrat Coll X-Image-Url: http://arraquis.dif.um.es/~paco/paco.gif X-Face: #>K{rw[D{N?r0=GjSYDGBc"EH7Wc_zk,jD+w/*@gE*i%2izUEF#}pJ/}~mQQA$Y:$yL"Da3 `Lw,Kd(@6fQy1<,fLcO}z-"g)~-Qm^U?#yQ.h|+2}*L>e}]I5M@4`*TaSs>d+z'gs9Xt:||?Ufb 5F9uY:v^"5*enEyLV,}Ly(K0ot[4k[_$D=tm)t=%Nd ;w<}gbsQn{zexIf.%h^EYSZr3/-k')Macr:l)mq=U.eIY}_4i@}E'o=N._+RBz`Bt? Organization: Red.es http://www.red.es/ Subject: Re: OpenPGP Signing of HTTP POST In-Reply-To: <45ED6495.1040407@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> Comments: In-reply-to "Arturo 'Buanzo' Busleiman" message dated "Tue, 06 Mar 2007 09:54:45 -0300." Mime-Version: 1.0 Content-Type: multipart/signed; boundary="==_Exmh_1173210270_4204P"; micalg=pgp-sha1; protocol="application/pgp-signature" Date: Tue, 06 Mar 2007 20:44:31 +0100 Message-Id: <20070306194431.705B318212@dune.rediris.es> Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Content-Transfer-Encoding: 7bit X-Spam-Score: 0.1 (/) X-Scan-Signature: 8b431ad66d60be2d47c7bfeb879db82c --==_Exmh_1173210270_4204P Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit El día Tue, 06 Mar 2007 09:54:45 -0300 "Arturo 'Buanzo' Busleiman" escribió: Hello, Not regarding the "POST" method but to sign HTML pages there were some web pages, after reading http://members.aol.com/EJNBell/pgp-www.html we developed a similar method, hiding the PGP header, http://www.rediris.es/pgp/firmaweb/index.en.html The idea was to not "overload" the web server with HTTPS security only to provide signed web pages, but sign the web pages with PGP and place in a normal HTTP server, and later use PGP to check the web page signature. With this option the web pages can be cached and verified , without using HTTP to protect the integrity of the web pages. > -- = Francisco Jesus Monserrat Coll PGP key: http://www.rediris.es/keyserver Rediris. Entidad Pública Empresarial Red.es Pza. Manuel Gómez Moreno, s/n Madrid 28014 SPAIN. tel +034 912127625 --==_Exmh_1173210270_4204P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Exmh version 2.1.0 iQCVAwUBRe3EnlKs6y7TpCxhAQIlBgP/VxILGTW91aeB+/2psL1vDy0zjvBdEsuP wtKaxhH6V7eA3d35Pz/CRyvyuprhMU/SDE8sWzMovptyPtSTQ8khh9IXJ1YpB3Uz 42QwUt7zBZYzrf/zmm0s2qmkoS7tAeRP9L6tdAwzkdLnIPdKQK7WO97yHWLAQOFz jFmwnlN3RCA= =5m1Z -----END PGP SIGNATURE----- --==_Exmh_1173210270_4204P-- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:06:41 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOfvl-0001Co-33 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:06:41 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOfvf-00031p-MN for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:06:41 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JohCj092497 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Johe8092496; Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from www2.futureware.at ([217.19.43.211]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JofH9092488 for ; Tue, 6 Mar 2007 12:50:42 -0700 (MST) (envelope-from iang@systemics.com) Received: from [127.0.0.1] (localhost [127.0.0.1]) by www2.futureware.at (Postfix) with ESMTP id 60FEF2280B5; Tue, 6 Mar 2007 20:50:42 +0100 (CET) Message-ID: <45EDC608.70904@systemics.com> Date: Tue, 06 Mar 2007 20:50:32 +0100 From: Ian G User-Agent: Thunderbird 1.5.0.10 (Macintosh/20070221) MIME-Version: 1.0 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> In-Reply-To: <45EDB0A9.80207@buanzo.com.ar> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 52f7a77164458f8c7b36b66787c853da Arturo 'Buanzo' Busleiman wrote: >> For example, we can do as following : > [...] >> Where signature is to be calculated over all message (including header >> fields) after X-PGP-Signature. > > I thought about this, too. > > What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent > proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of > that same reason. I suspect the question revolves around what you want to use the OpenPGP signature for. Is it integrity, authentication, or authorisation? Integrity would indicate a header-based binary signature and authorisation would prefer a cleartext signature over the body only. For example, if you were authorising a financial transaction, you would want to get as close to the user as possible ... which admittedly is a hard or impossible task if the starting point is a POST. If you seriously wanted reliable authorisation, in the sense of "sign here to authorise this money transfer" I'd look for something that sent a cleartext signed statement that was human interpretable, so that the human could review and confirm it. That is, not a POST of variables at all, but a POST of a custom text based packet: -----BEGIN PGP SIGNED MESSAGE----- Action: TRANSFER Source: 1233455 Target: 5433211 Value: 1000.00 Unit: USD Terms: Appendix A. -----BEGIN PGP SIGNATURE----- yeahthisisajunksigyourclientshouldbarf -----END PGP SIGNATURE------ With that form you can code up some form of proxy-based user client that independently of the Browser creates the signed authorisation ... which then means there is potential of a firewall between the Authorising soft/hardware and the Application software. As soon as you hide that info from the user in for example a POST form, you will be at the mercy of technical attacks. How do you know that the veriables signed were in some way presented to the user? In some courts, just the existence of these attacks will be enough to get it thrown out (e.g., Germany I am told tends to be very aggressive this way). iang From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:08:10 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOfxC-0001L9-Na for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:10 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOfx8-00039i-Ac for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:10 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Jvq9m092847 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26JvqpB092846; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.224]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JvpjK092840 for ; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2063984wxd for ; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Received: by 10.70.65.5 with SMTP id n5mr10334599wxa.1173211069695; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10958002wxd.2007.03.06.11.57.48; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Message-ID: <45EDC7B9.6060100@buanzo.com.ar> Date: Tue, 06 Mar 2007 16:57:45 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306194431.705B318212@dune.rediris.es> In-Reply-To: <20070306194431.705B318212@dune.rediris.es> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 93238566e09e6e262849b4f805833007 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Francisco Jesus Monserrat Coll wrote: > With this option the web pages can be cached and verified , without > using HTTP to protect the integrity of the web pages. Yes, I read about it when I first researched the pgp and http terms in google. The only difference in my case, is that I'm signing the requests the user/browser is sending to the web server, and not the pages that are sent to the browser/user. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7ce5AlpOsGhXcE0RAtENAJ0aYhimGxlsAIVdCHBCuTyRhePHgwCfXDsR gN2+3tyhAOFgmJAqN3tYhJ4= =McuB -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:08:53 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOfxt-0001Mt-32 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:53 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOfxq-0003He-M8 for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:53 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JujsK092797 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jujkw092796; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Juikt092789 for ; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2063698wxd for ; Tue, 06 Mar 2007 11:56:44 -0800 (PST) Received: by 10.70.74.6 with SMTP id w6mr8511444wxa.1173211004332; Tue, 06 Mar 2007 11:56:44 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10971709wxd.2007.03.06.11.56.42; Tue, 06 Mar 2007 11:56:43 -0800 (PST) Message-ID: <45EDC777.70606@buanzo.com.ar> Date: Tue, 06 Mar 2007 16:56:39 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> <45EDC608.70904@systemics.com> In-Reply-To: <45EDC608.70904@systemics.com> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.2 (/) X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ian G wrote: > I suspect the question revolves around what you want to use the OpenPGP > signature for. Is it integrity, authentication, or authorisation? All that is described in the URLs I sent in my original post. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7cd3AlpOsGhXcE0RAgSsAJ9QQg6Xv8zoleliWj/MNvqHoIIXbgCfXih/ BIPfj439LAqAsZDqi9zezzw= =r8Ot -----END PGP SIGNATURE----- From service@capitalone.com Tue Mar 06 19:13:28 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HOj9q-0006wz-E6 for openpgp-archive@megatron.ietf.org; Tue, 06 Mar 2007 18:33:26 -0500 Received: from [72.32.103.41] (helo=TheRealEstateArena.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HOj7N-0006BM-Nk for openpgp-archive@megatron.ietf.org; Tue, 06 Mar 2007 18:30:55 -0500 Received: from User [202.30.34.8] by TheRealEstateArena.com with ESMTP (SMTPD-9.10) id A41E14480; Tue, 06 Mar 2007 14:50:38 -0600 From: "Capital One Online Banking Service" Subject: Capital One Bank Notification - Please Read - ID: COB495886838 Date: Wed, 7 Mar 2007 05:50:18 +0900 MIME-Version: 1.0 Content-Type: text/html; charset="Windows-1251" Content-Transfer-Encoding: 7bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2600.0000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 Message-Id: <200703061450151.SM03216@User> X-Spam-Score: 4.3 (++++) X-Scan-Signature: ccfb4541e989aa743998098cd315d0fd Capital One | Message

Dear Capital One Bank, Capital One, F.S.B., Member,

Because of unusual number of invalid login attempts on you account, we had to believe that, their might be
some security problem on you account. So we have decided to put an extra verification process to ensure your identity
and your account security. Please click the link bellow:.
https://onlinebanking.capitalone.com/capitalone/ID=?COB495886838

It is all about your security. Thank you. and visit the customer service section.

Capital One Bank, Capital One, F.S.B., members FDIC. ¨Ï2007 Capital One Services, Inc.
Capital One is a federally registered service mark. All rights reserved.

Capital One ID: COB495886838

From owner-ietf-openpgp@mail.imc.org Wed Mar 07 15:11:56 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HP2UO-0001eU-4w for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:11:56 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HP2UM-0005Ap-PW for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:11:56 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrHfn085912 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27JrHfk085911; Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from finney.org (226-132.adsl2.netlojix.net [207.71.226.132]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrCmk085903 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Wed, 7 Mar 2007 12:53:16 -0700 (MST) (envelope-from hal@finney.org) Received: by finney.org (Postfix, from userid 500) id 51D6314F6BC; Wed, 7 Mar 2007 11:42:07 -0800 (PST) To: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: Re[2]: OpenPGP Signing of HTTP POST Message-Id: <20070307194207.51D6314F6BC@finney.org> Date: Wed, 7 Mar 2007 11:42:07 -0800 (PST) From: hal@finney.org ("Hal Finney") Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: b19722fc8d3865b147c75ae2495625f2 "Nickolay L." writes: > For example, we can do as following : > > POST /pba/postverify.php HTTP/1.1 > X-PGP-Message: Cleartext-Signed > X-PGP-Signature-Hash: SHA1 > X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux) > X-PGP-Signature-Comment: POST signed using Enigform > X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd > Z5AuIplmYgUFhTU3x3Sq9g== > Host: localhost > ... You might want to look at the X-PGP-Sig: header which has been used for some years to sign Usenet (newsgroup) posts. Unfortunately I can't find any documentation of it but if you Google x-pgp-sig you will find for example an Emacs macro which inserts it, part of the Ubuntu Linux distribution. Here is a sample which was posted to this list several years ago: X-PGP-Sig: 2.6.3ia Subject,From,X-Mailer iQCVAwUBM84wngE7m572a9utAQETEgQAwcL38QVdZbkHuW4Mblmje17deuI85R1j 4yGiDlb1enRDSUyGiLCmk8YphNDiLdKKlMV3Z0opzREUW9Q+sb8fr5s1QXMJhvXs 7hi7s4+V00rjgbqbqXVNiajKiKfVxd7JTRfe0UIZuOljnURP1ZCMlSRD1rDoCEAg 1vunQv6QYj4= =hvn0 I think the idea is that you can sign not only the message contents, but selected headers as well. Hal Finney From owner-ietf-openpgp@mail.imc.org Wed Mar 07 15:47:18 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HP32c-0000tJ-2u for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:47:18 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HP32X-0000sJ-N2 for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:47:18 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTsQJ087553 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27KTsGa087552; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from mx1.stack.nl (meestal.stack.nl [131.155.140.141]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTqD1087545 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from johans@stack.nl) Received: by mx1.stack.nl (Postfix, from userid 65534) id 5B3414B096; Wed, 7 Mar 2007 21:29:49 +0100 (CET) X-Spam-DCC: : snail.stack.nl 104; Body=1 Fuz1=1 Fuz2=1 X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29) on snail.stack.nl X-Spam-Level: X-Spam-Status: No, score=-2.6 required=5.0 tests=AWL,BAYES_00,NO_RELAYS autolearn=ham version=3.1.5 X-Spam-Relay-Country: Received: from mud.stack.nl (mud.stack.nl [IPv6:2001:610:1108:5011:207:e9ff:fe14:b498]) by mx1.stack.nl (Postfix) with ESMTP id DF6494B05B; Wed, 7 Mar 2007 21:29:47 +0100 (CET) Received: by mud.stack.nl (Postfix, from userid 801) id 9E628231E3; Wed, 7 Mar 2007 21:29:47 +0100 (CET) Date: Wed, 7 Mar 2007 21:29:47 +0100 From: Johan van Selst To: Hal Finney Cc: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: Re[2]: OpenPGP Signing of HTTP POST Message-ID: <20070307202946.GA39535@mud.stack.nl> References: <20070307194207.51D6314F6BC@finney.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="zYM0uCDKw75PZbzx" Content-Disposition: inline In-Reply-To: <20070307194207.51D6314F6BC@finney.org> User-Agent: Mutt/1.5.13 (2006-08-11) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: ea4ac80f790299f943f0a53be7e1a21a --zYM0uCDKw75PZbzx Content-Type: text/plain; charset=us-ascii Content-Disposition: inline "Hal Finney" wrote: > You might want to look at the X-PGP-Sig: header which has been used > for some years to sign Usenet (newsgroup) posts. Unfortunately I can't > find any documentation of it A nice desciption of background and the actual format can be found here, http://archives.eyrie.org/software/pgpcontrol/FORMAT Johan --zYM0uCDKw75PZbzx Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- iD8DBQFF7yC6aOElK32lxTsRCPohAJ0VXMQJuxLBWsa43kr6oIXgEdZAXwCfRhcu vfR4ZXd9wiSUJlfiHYllawk= =n5Xh -----END PGP SIGNATURE----- --zYM0uCDKw75PZbzx-- From owner-ietf-openpgp@mail.imc.org Wed Mar 07 18:55:19 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HP53G-0006Q7-UA for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 17:56:06 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HP3tU-0000Zk-AO for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 16:42:04 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRLBm090766 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27LRLBo090765; Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRKKB090759 for ; Wed, 7 Mar 2007 14:27:20 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so311697wxd for ; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Received: by 10.70.50.18 with SMTP id x18mr864310wxx.1173302839533; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm1586026wxd.2007.03.07.13.27.17; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Message-ID: <45EF2E33.5030805@buanzo.com.ar> Date: Wed, 07 Mar 2007 18:27:15 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: Hal Finney CC: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> In-Reply-To: <20070307194207.51D6314F6BC@finney.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.2 (/) X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hal Finney wrote: > I think the idea is that you can sign not only the message contents, but > selected headers as well. That's... QUITE interesting! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7y4yAlpOsGhXcE0RAjCUAJ97KaWtWsV0hlP4JFxSvsbtSl5NTQCffkri BYT5/VKN2TWdsJNKy/bxH70= =OI9s -----END PGP SIGNATURE----- From lottolive0707@bellsouth.net Thu Mar 08 07:00:32 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPHIO-0000si-16 for openpgp-archive@ietf.org; Thu, 08 Mar 2007 07:00:32 -0500 Received: from imf20aec.mail.bellsouth.net ([205.152.59.68]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPHIM-0001eE-P2 for openpgp-archive@ietf.org; Thu, 08 Mar 2007 07:00:32 -0500 Received: from ibm62aec.bellsouth.net ([192.168.16.253]) by imf20aec.mail.bellsouth.net with ESMTP id <20070308120030.WYAQ18741.imf20aec.mail.bellsouth.net@ibm62aec.bellsouth.net> for ; Thu, 8 Mar 2007 07:00:30 -0500 Received: from mail.bellsouth.net ([192.168.16.253]) by ibm62aec.bellsouth.net with SMTP id <20070308120029.WDOH3223.ibm62aec.bellsouth.net@mail.bellsouth.net>; Thu, 8 Mar 2007 07:00:29 -0500 X-Mailer: Openwave WebEngine, version 2.8.16.1 (webedge20-101-1106-101-20040924) X-Originating-IP: [66.98.138.80] From: LOTTERY BOARD Organization: LOTTERY BOARD To: Subject: You Won (XYL/26510460037/06) Date: Thu, 8 Mar 2007 7:00:29 -0500 MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 8bit Message-Id: <20070308120029.WDOH3223.ibm62aec.bellsouth.net@mail.bellsouth.net> X-Spam-Score: 2.9 (++) X-Scan-Signature: e5ba305d0e64821bf3d8bc5d3bb07228 REF No: UK/9420X2/68 BATCH No: 074/05/ZY369 TICKET No: 20511465463-7644 SERIAL No: S/N-00168 LUCKY No: 887-13-865-37-10-83 FINAL NOTIFICATION We are pleased to inform you of the result of the winners of the UK NATIONAL LOTTERY ONLINE PROMO PROGRAMME, held on the 6th of March, 2007. You have therefore been approved for a lump sum pay out of £1,450,000 (One Million,Four Hundred and Fifty Thousand Pound Sterling) in cash credited to file XYL/26510460037/06 .To file for your claim, contact our claims agent, Agents Name: Mr. Michael Freeman Email: info_lotteryclaimsdepartment@yahoo.co.uk Tel: +44 701 113 3851 Fax:+44 707 515 8432 Provide him with the information below: 1.Full Name: 2.Full Address: 3.Marital Status: 4.Occupation: 5.Age: 6.Sex: 7.Nationality: 8.Country Of Residence: 9.Telephone Number: Congratulations once more from all members and staffs of this program. From owner-ietf-openpgp@mail.imc.org Thu Mar 08 09:11:38 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPJLG-0005WO-5K for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 09:11:38 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPJLB-0002xf-OW for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 09:11:38 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdX7f036932 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28DdXup036931; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdWsp036925 for ; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so532007wxd for ; Thu, 08 Mar 2007 05:39:30 -0800 (PST) Received: by 10.70.125.11 with SMTP id x11mr742224wxc.1173361167097; Thu, 08 Mar 2007 05:39:27 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h19sm2798675wxd.2007.03.08.05.39.24; Thu, 08 Mar 2007 05:39:25 -0800 (PST) Message-ID: <45F01209.3020706@buanzo.com.ar> Date: Thu, 08 Mar 2007 10:39:21 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> In-Reply-To: <20070307202946.GA39535@mud.stack.nl> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 9466e0365fc95844abaf7c3f15a05c7d -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Current Status: I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header, which will ONLY contain the signature. Signed elements will be kept in a separate header, X-PGP-Sig-Elements. I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). I'll update the Draft ASAP. Thanks for all the input so far! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8BIJAlpOsGhXcE0RAmhDAKCAa7YhjPR2cwgymD3qF6dZGmTAlgCfTZAy RWE253rIkVojn/KC7WjxFUs= =uhl7 -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Thu Mar 08 10:34:36 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPKdY-0007Ij-Fr for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 10:34:36 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPKdU-0006MK-3G for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 10:34:36 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FC18k041634 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28FC1Rb041633; Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FBwJ8041617 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 8 Mar 2007 08:12:00 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l28FBdhQ013613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 16:11:39 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070308:buanzo@buanzo.com.ar::PYCxtJVoHV3l1kYR:2D6n X-Hashcash: 1:22:070308:ietf-openpgp@vpnc.org::U2UqeaBlmZMd9dwd:FdMt Date: Thu, 08 Mar 2007 16:11:39 +0100 In-Reply-To: <45F01209.3020706@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 08 Mar 2007 10\:39\:21 -0300") Message-ID: <87d53jlqhg.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-0.8 required=4.0 tests=AWL,BAYES_40, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 69a74e02bbee44ab4f8eafdbcedd94a1 "Arturo 'Buanzo' Busleiman" writes: > Current Status: > > I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header, > which will ONLY contain the signature. Signed elements will be kept in a separate header, > X-PGP-Sig-Elements. > > I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). If you are considering turning that work into draft form, consider looking at the OpenPGP: header too: http://josefsson.org/openpgp-header/ I'm confused whether your efforts is a discussion about one implementation, or whether you have standardization goals here. The OpenPGP: header do not support signing of header elements, however. The reason is that mail gateways are known to modify header elements, causing the OpenPGP signature to fail. Instead, if you want to protect header fields, you would sign the entire message as a message/rfc822 MIME body part and include it in the e-mail. What is lacking for this alternative approach to interop is guidelines to specify that MUAs should replace the outer headers with the inner ones for display purposes. The same affect S/MIME too. Perhaps it is time to revise RFC 1847 and add a discussion about this? Are people interested in working on this? Some people have been recommending signing message/rfc822 for several years, but it is not that well-defined exactly how that should work, and there is no RFC to reference either. /Simon From owner-ietf-openpgp@mail.imc.org Thu Mar 08 11:17:51 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPLJP-0007PJ-4j for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 11:17:51 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPLJK-0005n1-NL for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 11:17:51 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0nI0044650 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28G0n8A044649; Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0mrA044643 for ; Thu, 8 Mar 2007 09:00:48 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so577333wxd for ; Thu, 08 Mar 2007 08:00:46 -0800 (PST) Received: by 10.70.13.6 with SMTP id 6mr992666wxm.1173369645923; Thu, 08 Mar 2007 08:00:45 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm2977852wxd.2007.03.08.08.00.44; Thu, 08 Mar 2007 08:00:44 -0800 (PST) Message-ID: <45F03329.20505@buanzo.com.ar> Date: Thu, 08 Mar 2007 13:00:41 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org> In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 52e1467c2184c31006318542db5614d5 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Simon Josefsson wrote: > If you are considering turning that work into draft form, consider > looking at the OpenPGP: header too: Great, I'll check it out later. > I'm confused whether your efforts is a discussion about one > implementation, or whether you have standardization goals here. Enigform = Mozilla Firefox Extension = "Reference Implementation" goal. Draft = Standarization goal. > Instead, if you want to protect header fields, you would sign the > entire message as a message/rfc822 MIME body part and include it in > the e-mail. The problem is that this is for HTTP, not for eMail. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8DMpAlpOsGhXcE0RAmGkAJ95v7NYSHPZWHmAw9+f9xECuhWJnQCbBQOA aPaaoaKbsAbIK3n/W5/i9lE= =kbEL -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Thu Mar 08 13:38:59 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPNVz-0008I6-Cm for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 13:38:59 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPNVu-0007uL-Un for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 13:38:59 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIV9c002222 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28IIV8B002221; Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.231]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIUtl002215 for ; Thu, 8 Mar 2007 11:18:30 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so625929wxd for ; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Received: by 10.70.66.18 with SMTP id o18mr1221505wxa.1173377909684; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h34sm3164761wxd.2007.03.08.10.18.26; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Message-ID: <45F0536B.6070204@buanzo.com.ar> Date: Thu, 08 Mar 2007 15:18:19 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org> In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: f607d15ccc2bc4eaf3ade8ffa8af02a0 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 "Arturo 'Buanzo' Busleiman" writes: > I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). Okey, I've finished adding the new features. This is how a signed POST request from browser to server now looks. Pay attention to the X-PGP-* headers and values. Some lines could've been wrapped. ==cut here== POST /pba/postverify.php HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.2) Gecko/20070226 Firefox/2.0.0.2 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ X-PGP-Sig-Fields: body X-PGP-Sig: iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIovixLWkMbebF2NTjo3WrVEZNA==q/ix X-PGP-Version: GnuPG v1.4.6 (GNU/Linux) X-PGP-via: Enigform for Mozilla Firefox Content-Type: application/x-www-form-urlencoded Content-Length: 17 variable=somedata ==cut here== Of course, the X-PGP-Sig header value must be splitted in 3 strings to reconstruct the detached signature, in chunks of 64, 24 and 5 characters (without the \r\n), respectively. The headers, when combined to form a detached signature, would look like this: - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIov ixLWkMbebF2NTjo3WrVEZNA= =q/ix - -----END PGP SIGNATURE----- This is much more backwards compatible, and more geared towards standarization. I'll modify the Draft asap to include these changes. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8FNrAlpOsGhXcE0RAhbIAJ431+J6vaSwVNgMG7Dp1mn4/f+NbACeIW5k wzpDqJr9YLuPfzLej0VeeJ4= =qXuA -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Thu Mar 08 20:10:12 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPTca-0005Gp-UP for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 20:10:12 -0500 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPTcS-0008KS-Fd for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 20:10:12 -0500 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q1fv022665 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l290q1qv022664; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q0ot022653 for ; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so748004wxd for ; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Received: by 10.70.40.1 with SMTP id n1mr1932022wxn.1173401518814; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm3753938wxd.2007.03.08.16.51.57; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Message-ID: <45F0AFAA.7040605@buanzo.com.ar> Date: Thu, 08 Mar 2007 21:51:54 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: OpenPGP for HTTP Reference Implementation X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 9466e0365fc95844abaf7c3f15a05c7d -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear group, I've just released version 0.7.0 of Enigform. Please give it a try at http://enigform.mozdev.org. If you get an older version, try the "alternate url" under the Installation section. This new version allows GET, POST and file uploads to be signed. I'll be updating the Draft for the OpenPGP for HTTP ASAP. Thanks for all the feedback, and I expect I can, with your help, transform the Draft into a real RFC document, which is one of my wildest dreams. Thank you all! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8K+qAlpOsGhXcE0RAt90AJ9l8lLV084uzTlns3mFS4x/QIOgFACeNLTm R/jjUbXSCdO0arKprWwZnaA= =/8iw -----END PGP SIGNATURE----- From kito_mijiko_00005@yahoo.co.jp Fri Mar 09 08:24:12 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPf4u-0007wV-56 for openpgp-archive@megatron.ietf.org; Fri, 09 Mar 2007 08:24:12 -0500 Received: from [203.177.214.39] (helo=pc15) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HPf4p-0008Bi-TA for openpgp-archive@megatron.ietf.org; Fri, 09 Mar 2007 08:24:12 -0500 From: =?iso-2022-jp?B?a2l0b19taWppa29fMDAwMDVAeWFob28uY28uanA=?= Subject: =?iso-2022-jp?B?GyRCJSglQyVBJEpNRCRKOkokckp6JCQkRiRfJF4kOyRzJCshKRsoQg==?= MIME-Version: 1.0 Reply-To: Date: Fri, 09 Mar 2007 19:47:56 +0900 Content-Type:text/plain; charset="iso-2022-jp" Content-Transfer-Encoding: 7bit X-Spam-Score: 4.5 (++++) X-Scan-Signature: bb8f917bb6b8da28fc948aeffb74aa17 $B!!?M:J$K6=L#$N$"$kJ}8BDj$G$NJg=8$H$J$j$^$9!#(B $B!!?M:JNq#1G/L$K~$NM7$SB-$j$J$$=w@-$,Cf?4$G$9!#(B $B!!#3#0Be!A#4#0Be$N=w@-$O$b$A$m$s$N$3$H!"(B $B!!#2#0Be$N=w@-!"#1#0Be$N=w@-$b>/$7$G$9$,$4>R2p=PMh$^$9!#(B $B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B $B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B $B!!CK@-EPO?$rD:$$$F$$$^$9!#(B $B!!:#2s$NJg=8$K$D$-$^$7$F!"40A4L5NA$G$N$4>R2p$H$J$j$^$9$N$G!"(B $B!!Aa4|=*N;$N2DG=@-$,$4$6$$$^$9!#(B $B!!Jg=8=*N;$H$J$C$?>l9g$G$b!"(B $B!!$4MxMQNA6b$NH/@8$O0l@Z$"$j$^$;$s$N$G$40B?42<$5$$!#(B $B!!(Bhttp://qp-sp.com/sw/?media=pcya1 $B!!(B------------------------------------------- $B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B $B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B $B!!(B------------------------------------------- $B!!!!L>A0!'%f%-!!!!!!!!!!!!L>A0!'??5*;R(B $B!!!!G/Np!'#2#7:P!!!!!!!!!!G/Np!'#3#2:P(B $B!!!!(B $B!!=iIb5$!'2q\:Y$O%3%A%i!!"M!!(B $B!!(Bhttp://qp-sp.com/sw/?media=pcya1 From nolei@arscryo.com Sat Mar 10 02:52:43 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HPwNf-0005NI-Pn for openpgp-archive@ietf.org; Sat, 10 Mar 2007 02:52:43 -0500 Received: from host-ip42-192.crowley.pl ([62.111.192.42]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HPwNa-00006g-Hm for openpgp-archive@ietf.org; Sat, 10 Mar 2007 02:52:43 -0500 Received: from kontrolahala (unknown [195.137.153.47]) by nolei@arscryo.com (Postfix) with ESMTP id 9B91A3D8CB68 for ; Sat, 10 Mar 2007 08:51:25 +0100 Message-ID: <000c01c762e8$d0aad5e0$2ac06f3e@kontrolahala> From: "nole i" To: openpgp-archive@ietf.org Subject: agent or relative Date: Sat, 10 Mar 2007 08:50:47 +0100 MIME-Version: 1.0 Content-Type: multipart/related; type="multipart/alternative"; boundary="----=_NextPart_000_0008_01C762F1.325B67C0" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 X-Spam-Score: 4.5 (++++) X-Scan-Signature: 8b6657e60309a1317174c9db2ae5f227 ------=_NextPart_000_0008_01C762F1.325B67C0 Content-Type: multipart/alternative; boundary="----=_NextPart_001_0009_01C762F1.325B67C0" ------=_NextPart_001_0009_01C762F1.325B67C0 Content-Type: text/plain; charset="windows-1250" Content-Transfer-Encoding: quoted-printable Email valid address franais deutsch espaol italiano. Latitude space = center shuttle, launch! On an image for and. Will contact winner stateiii. Team will contact winner stateiii by any. Usually ships same day = mahatma. Terms use, trademarks statement, home find! Ensure that hisher = is lawful accordance applicable. Company usa not, eligible! Parent company, usa not. Laws manage profile terms use trademarks statement home find! Items, gtgt click on. Street, city state longitude latitude space center = shuttle launch. Manhattan dulles airport strategic? Same day, mahatma inusually malcolm xposter, nelson. Shall be entitled contest employee agent or! Shall be entitled contest = employee agent or. Message board stageiii results are out team will. = Relative microsoft its parent company. Message board, stageiii results = are out team will, contact. Earth search street city state. That hisher is lawful. Message board stageiii results are, out. Links = message board, stageiii results are out team? ------=_NextPart_001_0009_01C762F1.325B67C0 Content-Type: text/html; charset="windows-1250" Content-Transfer-Encoding: quoted-printable
Email valid address franais deutsch = espaol=20 italiano. Latitude space center shuttle, launch!
On an image for and. Will contact = winner stateiii.
Team will contact winner stateiii by = any. Usually=20 ships same day mahatma. Terms use, trademarks statement, home find! = Ensure that=20 hisher is lawful accordance applicable.
Company usa not, eligible! Parent = company, usa not.
Laws manage profile terms use = trademarks statement=20 home find!
Items, gtgt click on. Street, city = state longitude=20 latitude space center shuttle launch. Manhattan dulles airport = strategic?
Same day, mahatma inusually malcolm = xposter, nelson.
Shall be entitled contest employee = agent or! Shall=20 be entitled contest employee agent or. Message board stageiii results = are out=20 team will. Relative microsoft its parent company. Message board, = stageiii=20 results are out team will, contact.
Earth search street city = state.
That hisher is lawful. Message board = stageiii=20 results are, out. Links message board, stageiii results are out=20 team?
 
 
 
3D"sizes"
------=_NextPart_001_0009_01C762F1.325B67C0-- ------=_NextPart_000_0008_01C762F1.325B67C0 Content-Type: image/gif; name="green areas.gif" Content-Transfer-Encoding: base64 Content-ID: <000701c762e8$d096ffc0$2ac06f3e@kontrolahala> R0lGODlh4AEQAYdSAAcAAHIJAACAAI2EAAAAeIcAcQ18fsXAyrvUyq3F7TYaBW4tAIEtDJcgBrgg AtkUAAA5ABI/ADwyDWRFAHVFAKMxAL8+ANo8BABlCiFuADJSAGNmCXFiAKlXAMFUBeBtAACAABl3 BjVzAFyNAHV6AJ58ALaLCNR8AACXAxqbADqoDlqtBXSSAKKdAMqrAO6iCg64CR7CAEW5AFnGAHbC CJ7AAbTFAOLIDADpAC3UADbjAG3WBXnVC5PuBL3rB9/iCQAJRxcLMTYFTVoAOYIKR6ACQ7EISd4A RAAjTRIXNzsfTlssOHUbTJYnNLYSNOocPgMyORE3QEg9QmI6NXlINplIM85IM9Q1QABdRi5tTkRm PWZWQoJXAKNhM7RtOdRiOwCAPyiCNE2COWOJN46JQ6Z6R7SJM+p5NwirRyKUM0OSQ2mUOYOiO5GX N8yfROumOQ7JQiyxMzKyMme6Sne8RZHBScm7N9W9NQrrOBHrQ0vdPVzeOIbRSKPqRsDrReTmNgAO hxEAijIAiF0DgXsAgJ0MfcUAgtQGdgAqiyATejIlfVsXe4YTdpMjiMUbdtMeiQBCfiU0d0xJd15C jYVJga42hcg9dONFgANRhBZUdE5feFdVf4tggZxujL9Rdt1eiA17dRtzhTuLjlyAe357ip56d7uJ gueDfgOodi6ReT6SfVybd3KpjZ+nd7GjdeSXdAC3jBLKijS8iWfNhXO+h5HEfb61gdG4eQXRfxvj h0fSgV3pgYLZcZnSgsjei+3udwAIyhsAxEsAvl4Au40AwpcNxbgGw+kAsQQavRMhwDYcuVwTzIAe wJkhuL4RyOwXxQ1AxBFNxUE6yFE2zodOzaE+yMwyvuJFuABduBVay0ZrwFNiyYJeyqFbzLZRxutW sQt3ui2HwE1yyW6DtnqEv6GLtcyDxdSLzACeuSGYyDycuGGfyHqYyZ+TtL6Rtdqfwga2xCu9sTu7 zlTNwImzvp3Euf//5pKlmYt3fPAJAAD2DPX/AAAN//8A/wD5+vH/+CH5BACW2l0ALAAAAADgARAB Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEmypMmTE+2pXMmypcuX MGPKnEmzps2bOHPCRMmzp8+fQIMKHUp0pM6jSJMqXcpUadGnUKNKnUq1qtWrWLNq3cq1q1eNTcOK HUu2rNmzZr+qXcu2rdutaOPKnUu3rt27ePPq3cu3r9+/gAOXfUu4sOHDiBMrfiq4sePHkCNLnrx3 seXLmDN3pcy5s2emmkPz/Ey6tGmyolOrXs26tWuSp2PLnk279ufXuHPr3s2bsO3fwIOv7E28uHG2 wpMrX868ufPnco9Ln069uvXrBaFrD4y9u/fv4MND/91Ovrz58+jTq98OoP369zHbA2gpn757l/Ln 29ePP7//lf7Vx1KAAd6UX3/87ZcTgQAKqJKDDj54X1gE/teghQMyiOCBCmaYoD0RwseXVPIVVCJB J5qY4kArolghACxW6OKLMDqUn0EtxljjQwTq2J6OPgYpEI0z3uijjENWuF+BHjJ5YYdPiiilhB+G GCKVH4I4IZQvQXilllnaxKGHMH1Jk5VjRuhlgjRe6CSZG7oJJ5j8jakll2DiOeV6aFa5JZZ/mmkm lXMWaiCGhHb5p5iBprnlmoY2maGiYfZZKKQzWRrpnnaR+OOMKu54pKj/5JgkqaGCiuOnEQWY6kGm Mv/UoqulslrrjivGequNtp5KaZSJ5plpo36GySldnpI6a6+3LovqqT2eKuSrrfpH7bU89lrip87e qieww2b5JaZ0yimTpuAe22lUAbRbULsBFKTAvAUtYK9A9i5AELwIwesvvwLNK/DACAks0YkrGnxQ vhMBPJDBENMLqrPR5quvrMw6vK+70FpbpKka/xNyyOJd9Bi8LQncUr4dRqjySw/EfO6bLr2MkwM4 q4SzAyyh/KtOPq/UwNAqET10Ay3tbI/STTr5b7vxLTruhEdXHdPOWLcUdLAq2azuulCFrPBADG/8 tNn9cozQzv9gnRDJDD2ttshzE5TP3Q3XfbRAVQ//bdC/Bo399tl/1/2P4A9LTHe8/jJkMUGIh6xr yRI95rU9R2sN9UpYd86zSjE/ANPlKc/btekwZY6T3EEz7dLWN8GuOuZWl076oC/dfffrm2/qIMv2 AD+T8PZcTvrXeh2mscNw/7N3QmMjPhDbEJWN773XX2wQ9RE9T7a9K1m8QM0DuzS7TaQf77rOOa+k u/u7h4v8bYZx3zbOQB7UfMCKH97/9PiDiOCi97+BMOCAE2lR6AgSugcEjmDyKuBCcrTAVbHKSAKp YAZjNhAOMlCD1XoW5VLimPXZ44AMsN1K/NUzn0HghTCE4ekGVj6VbI2FLZHhoR4lIM8xjYY1vJrn /1bitSCyBIUsMSACEfLCgsTQggUD4v9QSBAUMqBjHhtIyGDoxCaOECOP0WG6xEiBMrqkjBRQSQzX CCgMobElaEwjSzhAR5y8EY5mtMcaY6iSOPpxJnuEwEqQOEhCtsSQc6SjIhfZRjutRIwbyhEVqzhJ P5bxIFwkCBq/yMlOSiSQmfyHAEZJSgF48pSoHMr8VmmaVIaElbCckitnScta2vKWuIRNLMmTy14e ZJfADKYwh0nMYhpzLoQhAAF8eRBlKmQyyjymMd8EDGDIBAhAUFRZsLkSbqrEm3d6zKLCUs2cRPMv 55TmMCc0Tjrpp51mYWedjKUdeMKEH/wATDnVuf/OeXYzm/bAZ38k1KBvYvOgLDkoQoeFJYI61Elv UqZEV1LNiprrTPyRKAFqcp+OvhNRGEKUNsMpT9w1jZ78hAxULrgjZ/7DpS6qVUx3JdN/4HMgN12I SzUqEJhy66cCqWhQgdHTZRZVWjFKUkM+Vc2hMmSnRnUpwp7V1KMyJKdY5YdSt6oQmPoUg8xMjUZh +lKjMquiRCVIVb0aVaOWdakwupGtpIqrGrGUq0AlCFnh6lSIIMmmWhVITlWUVLjSCrA4DaxCsDkQ xtb0sWENjWNXxdX8zfSuj2UWrKZqK8dO1rFV/cdax2pWVPGUr9ByiEIVWtjMZlGzB0ErWgdCWrf/ JgSzmI1saGCb1yIVhK6FZath7ZqrGgnXtZVtrUH2ihDmOhOjTkrnOeVZ0JrUdqMOvYl0sUvdlDpm pSJk6VQh29u8Tk5IYC0vcQuLW2WtF2NbhS1lyVvX+OYWvvRVLkJ++l7I/tK7eAHvfkVoX/bWF4u8 mqmBF4xXDDILrAIp0zztaZ/shvPCbzLpQ4tFYTd5tLoXDnGHAbyU3shXtz0BKZtWTOIWj1Q2KI4x CfnkSBfbOJgyBsmNd8zjHvu4mDn+yo+HTOQiG1kyQf7OkYWTZCUv+TdSoaGCawpEh/htwAZpoAeb BeGD6E53JlGcmBXAPyn/430qiZ8UFYDRST35/8m9i3MAWpjdEffOfEhzs4XtceeZtG9pnzMiDVc4 ZxsWWiaoKx6bT2folwStz3+mSaIVPcPjyeTOWm4h7Gw26Tcvh2gsAXWk25foTsMEfC8x4gFnAuqa yAx0omMfS15tj1ejGtUzQV0Ndb3oJELwf9hryJb/4cH7LoR7mN3ylu/FbO01OSONiTSgG01oWVub oS/JGuc+FxNTRw3EE+ozEdns7ZFy6D7e1ra0V42+XlMawyg9oiFf+EhBwrug7hmxp2mTx5Xkkd0q YffTGPWSPPZbj2w8ZAptYkWAI7zeMMEhwQ80IUvKMd/z+RO9CV7d7jJ0QgBn98YfHvAUWtEez/9O jBcH4kUMYIAgLhdIE1fOEJqzHAIyxzlCUICCLj4k5psdyCgRQsqIPPEfT1TJKF+ydHuUsiVNr8nI Sb5Hqdt75FFvetYFwJJScp2U+2bO1KlubzXaGwYwUAnabbJ2l3id6zDheUtwgIObyP0lLl9J211C d7rjhI8IH/nYN/ynqNNk6hvXhz5y0vfGq8Tvj6+7PYD+D8oT5Ik2T3lb0D4Qzg+E5wIBfYMbMvSC WB7otupV5hNieZi/XCCt7zwM/uH5hjReILcPfc8NUnu0z/7yOk/wY1fvEMqv3IulFyXcu/715odd LFJZo0GODvvXV7/m0kd68LX/eZ57f/rbX4j/4pm4/d7/vvTJZ0jtaf97gfj+/Tm/efhF/w+bKF7x LLn7UaKu/7sLvuwr4XcCKHnPBxpNBn9CV0oJuIAb4ReQdxT4p3fvx3xgV2FcU4BOoXkauIEUgYEe +IHQx4G4AYLAIYJaQYKrZIJBhoIs2II5oYIw6BG5dViLtVpAkFwxmHKnJVR9tRCshViJNRCylVZc dl4dg1rIVVZjNUH9NVhAWIOxRYTzRVu1lYOJ4Rjg5CXaxV0sZg/7pBJfqBLp1GZ79mLdNU4agnEs EYY2MYYgNlAvFmBWqEuCUVIfdSgW9mHXBFA60WHnpFFiiF3ghHI4+A8/2Fg3GBGTpVZS6FsG/7GI c+hKrHJazHVb/VVTlahXtuVXBGZg5vUslWgqpDVc47VZmnVikfhFd/UjqHhZoiJeOdKKodKJMSVX deUxp3herZiLQedfvpiKntReslhg+qVfwziFCmEkDvYs0cKKnbiLzBiNOHiMwHiCjXGGGtZxXQiH b4gTI3ZuWsiNbuZxISZhcehh4hJvpVGNUTGDx9heyqUttKhgsqiMKcKLUwiL9RiN9jhlv8iOanGN AlJS0MVhSyI16tg0ePiGaZiQd8FDFuiCzgGM7qRvEsljAPlMF7mRHNmRPZaRouGRkwGSJFmSJnmS ryGSKlmAKNmSqLSSwOSSMjmTKAaTIkKTr/9kkyqFk26hkz5ZZDwZlN3xkwYolLlBlEiZlEpZgkbZ lCKxlFAZlVLZFE5ZlVZ5lViZlVpZHFOZF1v5lVfYlWI5lmRZlmZpTGCZlplxlsuhlm75lnAZl9XI ljeJlXQZFnKZl3q5l71xl375lzTBlxoImITJkYKJGbGYmPMogzRIED5UOPHyLvtTZg9UQArTN1eW OP+DOBCkmZLJOodWkYMiN4U5GbDDZ6cZNOKzmjbhQ9LmQ7nzZbLJEsQTPLUJM7S2Eg3kEqFTNJip OTfUZ/+iabMYLVjUZZhZNYf5ExRzLaspPg4BmpHpmAFkQa9oK8szmaoyLUilRYbzD9D5Pc7/dmZf Zjd4s52DM52Lo5401Z1pWUKj1jkssT6W1m7uZkTCYjvuxmjAUmNRs2J2EiImBGu7SaAHOWFJI224 GWu6mZupGZqlGRUDZGaUCUAOYBHNaaEHIT36wzGN8xCTJBANd0VKRKKeCZnMUzdVVqGWlRD2cz8X WqKC6RiQVHX1BoB3hBRXEiGQVHILd3j0Bng3kaP2YEksQaT5KW8n56N4FEf+dnBJChOIdEION6Wl +RJSUXQC8XYJaEro+UmZF0rK56XAF34J8XZkChHfp3vet3v/sKYEoaUFUXRaKqc5h3OZJKbaZ6YG AadsGqd2Cm1XGhc6VKgb16M9mhPe5xKL/7oSjcoSiQoTjfeAOWGoV+dFevqm9EcQ9/cPneqp48ep 4/epn9qlaFoQfuqnW+p1yzkULvd6r1p9sNp6bVqrbsoQsep6ltd3UNQQtkoRuRqsQJerBKGquEd3 x4oD/8CrgOqldJp+Y3qqzcqlB3F/1qoPJ9GRyYJUnIWqtmqsZ5p+Clism3qnDhFICcRf3MosxKoq 29IrzMqrzNp9t0p00qoQ14qtreoTz9qlY9qrFPGtxpojvucQBct+7fcQ9uB7C5t2ard2DMt3lCqB DtuwE8gSfReAk5pDg4cgFygTF3ulUzGpyjoQJMt76ycR74eAANuiychfi2l6r3p6M2t9BP8xr2Uq f2LqdFv3dPmnfzEhRpEKExErstGXfXeaqQdlEZl6EAdbEE/7srcYs6Yqrqz6iJDofuu3slBbexa7 dwbFhzEBBmS7EmRbtjVxtoMaGTaYUKvlEguFFBU4E3HLEmcLBi6BtkpneHNrE3ert/bwt3jrdoa3 En3rdVDHtz5rtoALE2rLuIPLuC/xuEYrFaeliZUoURahuU+ViZerhASxtKGbtTrFuZi7iVSIuqCb untlukrYupk4uomIiIkYtmJbtxE6FfjkhIK1u80Uuw3Bgwmxu8Rrisa5uqzLiQ+mmBAmvEMVWgIh urQ7u8cJVs4rWsJ7Xa4LlpFRY/5pg2//WxMWtYfh6xK1BbeDaLtb6Ib2AIgH+iETxRLu+09iaw8K 9b52grv2W7fnu7bKQSMOmY3+u5H7+hMDfMAIrB4FvMAMrGMJ/MDK0cASPMG6AcElRsEdYcEavME7 icEe/MGqwcG8BMIkvJwifMIorBIlvMIs3MJCmcIwHMM44cI0XMM2/JQyDBg3HJQ53ME42cNALEs2 HMREXMQuscNFYcRKvMRCPJNMvBNIvJVPPMVU3BxRfMXZ8ZdYvMVRUcVefMRcXH9fjGRhbIVjPGQQ 6U4HepDoKClqjI7z+Fdcprypd50IRorUmCx1nF7Gmcco1o+tdVhybInL6IqjF8gHdl/w/1iISIjI wpeExPiPhGWde2yPWUTIxYWLl+yOxbi80wEZerhhelaG36aN43iHpFyO4LaNoaxvyOhf0DjJdXzI TNiLkOyP+HXLjgzL/eXJkxyDvVVTqPiO4WXHwnxgr7zLh2xs2fLLjOyPwaxejazM+NjMtEyPl3jM nYwqfhxj0ZzNyWyJWOaJmXyPxQxh+ji1sXKOjUKGpqyN/kkp4LjK5+jO5EjP5ehR/omQHBnK8Oa9 DtlGDInKqizK2sTPdUbQSZTLyRXLhrxgxGy8lcxZXUbJ16nJhWzIvMXNVMsaoKzQ7dTOOgrSBB3S Cn3KEYmNIx2RqTzKJNWF/jwzB+0n9f/cEpQlj7YMze9VzdX4zeNcjNaszctszEmoyMgczJzIjfpG jq3sT+6M0t3Y0uYoYpViLB53z6pskegxFYrjodM5N3XznVEEOWSmmWUtEIRTZpzZmWAdmUaS1s/5 EN8JONmSI51JNxvDEJmZ12g9ncHG10HNKhIk1uupnv3zPxnDnhvYQAVRngSBmdsTo9FJ16l42GUt m+f5mAvR1scpEOeZY2cc2lhaxkks2qY92qTtZKctw6ldGKv9GK2Nwa8921oc2zVM27id27q92xts 23ABk75Nw7w93MTd23JZ3Mg93MHtwsk9GMv93CRJlNAtFc0dgl9Z3UU83dqditiNGtv/7RNS+d3i LdwnPN7mDZLdnd7qvd5+ed4TzN7W7d7yPd/0Xd/2PRrwDcP3vd/83d/+/d8AHuAsnN8ZuN+kWxLQ +g9kaxm+TLsiceBxKRzsSxfp277YRb/6G7/yq+Hse07gW79Ngbvpi7savhLxe10uwYYQfBjQWxCQ COEQ0eJPWFwF4bsGAb02HoT/2JjPK+OOWFlNBb18jNQHwbsaSeA1HYgtUeFHUeFY3RLRxL6DGKAn jc//dOX3lE8CpRJbTlA89OX6MeEsbcGHYZyjOIo8buQN3oo3peZ2jFmZeF8+jhBBToRCHldvvl6f slcpbk0ifBjSO1m9QlaliIjJzMxY/2uI1GtVThVaVYUkg+WEtoJt/qyG+HaH9/HhY47kRzGG6STS XJ5PK9Hlpaxn4FS+d7IoY6iHMU1Rfu6Fr25hChHpWjVYuQVVUPXMui7gU8YqkDjLQI3LwK5gjt6I nTW7jOVZi55UBT2/U91QgThW8IzK9qTVnP7sF+aGq76N2K7kJn7h3w7HUA7uYO7tkYRt2O4oVt5d Ym7u177SVp6H3F7PoJ7Q3ZjG0G7SUk3V9x7TrW7Q3f7uC8LKNB3v/L7panLS+J7PofzLJzbsvozT Ow7Owb6XwrHwjoJxAO3SBV2R/X5RCK0kB39vZ6HvounUaMHruPyy4fwUEj/Ho1KE1mhCJBnRzWBh k2UuI66y8zo/8zzv8y8i8+8K9D1/vEMBwM7YI0afkwK/77bRJi/S9FJv3Cpf9VY/QlO/4lf/nlmf wPf9507c9WK/xFxs2lvP9WOf9k989mwfGmp/FgD59mv7wdgdxbMdEAA7 ------=_NextPart_000_0008_01C762F1.325B67C0-- From ver_front@yahoo.co.jp Sun Mar 11 08:53:07 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HQNXv-0006MR-So for openpgp-archive@megatron.ietf.org; Sun, 11 Mar 2007 08:53:07 -0400 Received: from [222.127.4.230] (helo=pc26) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HQNXu-0005do-7H for openpgp-archive@megatron.ietf.org; Sun, 11 Mar 2007 08:53:07 -0400 From: =?iso-2022-jp?B?dmVyX2Zyb250QHlhaG9vLmNvLmpw?= Subject: =?iso-2022-jp?B?GyRCbFRCdCRKSGtMKThyOl0kcjNaJDckXyReJDskcyQrISkbKEI=?= MIME-Version: 1.0 Reply-To: Date: Sun, 11 Mar 2007 19:45:07 +0900 Content-Type:text/plain; charset="iso-2022-jp" Content-Transfer-Encoding: 7bit X-Spam-Score: 4.5 (++++) X-Scan-Signature: 769a46790fb42fbb0b0cc700c82f7081 $B%;%U%l>R2pC4Ev$N0BF#$H?=$7$^$9!#(B $B%9%]%s%5!<%5%$%HMM$h$j?75,$4>R2p0MMj$ro$N%a%kM'!&Nx?MJg=8$H$O0c$$!"B(#H4uK>$N=w@-$N$_$H$J$j$^$9!#(B $B0l@ZNA6bL5$7$N$4>R2p$H$J$j$^$9$N$G!"(B $B%a!<%k$NAwR2p$G$9$N$GAa4|Dy$a@Z$j$N>l9g$,$4$6$$$^$9!#(B $B#H=PMh$k=w@-$N?t$O8B$i$l$F$*$j$^$9!#(B $B$^$?!"Dy$a@Z$j$H$J$C$?:]$OM=9p$J$/=w@-$NJQ99$r$9$k>l9g$b$4$6$$$^$9$,!"(B $B$4MF$N=w@-$4>R2p!!!!!C(B $B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B $B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B $B!!!!!!!!L>A0!'A0!'$f$$$5$s(B $B!!!!!!!!G/Np!'(B33$B:P(B $B!!!!!!!!?&6H!'4G8n;N(B $B!!!!!!!!!yIaCJBN83=PMh$J$$$h$&$J#H$J;v$r$7$F$/$l$k$=$&$G$9!#(B $B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B $B!!!!!!$*Fs?M$N>\$7$$>\:Y$O$3$A$i"M(B $B!!!!!!(Bhttp://qp-sp.com/fnv/s.php From owner-ietf-openpgp@mail.imc.org Mon Mar 12 19:05:25 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HQta0-0002Lo-W2 for openpgp-archive@lists.ietf.org; Mon, 12 Mar 2007 19:05:24 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HQtZz-00075G-HN for openpgp-archive@lists.ietf.org; Mon, 12 Mar 2007 19:05:24 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo6cN009086 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2CMo6OU009085; Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from ns4.neustar.com (ns4.neustar.com [156.154.24.139]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo3u9009077 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Mon, 12 Mar 2007 15:50:05 -0700 (MST) (envelope-from ietf@ietf.org) Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns4.neustar.com (Postfix) with ESMTP id 788DD2ACD7; Mon, 12 Mar 2007 22:50:02 +0000 (GMT) Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HQtL8-00056B-84; Mon, 12 Mar 2007 18:50:02 -0400 Content-Type: Multipart/Mixed; Boundary="NextPart" Mime-Version: 1.0 To: i-d-announce@ietf.org Cc: ietf-openpgp@imc.org From: Internet-Drafts@ietf.org Subject: I-D ACTION:draft-ietf-openpgp-rfc2440bis-19.txt Message-Id: Date: Mon, 12 Mar 2007 18:50:02 -0400 Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.3 (/) X-Scan-Signature: 14582b0692e7f70ce7111d04db3781c8 --NextPart A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the An Open Specification for Pretty Good Privacy Working Group of the IETF. Title : OpenPGP Message Format Author(s) : J. Callas, et al. Filename : draft-ietf-openpgp-rfc2440bis-19.txt Pages : 84 Date : 2007-3-12 This document is maintained in order to publish all necessary information needed to develop interoperable applications based on the OpenPGP format. It is not a step-by-step cookbook for writing an application. It describes only the format and methods needed to read, check, generate, and write conforming packets crossing any network. It does not deal with storage and implementation questions. It does, however, discuss implementation issues necessary to avoid security flaws. OpenPGP software uses a combination of strong public-key and symmetric cryptography to provide security services for electronic communications and data storage. These services include confidentiality, key management, authentication, and digital signatures. This document specifies the message formats used in OpenPGP. A URL for this Internet-Draft is: http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt To remove yourself from the I-D Announcement list, send a message to i-d-announce-request@ietf.org with the word unsubscribe in the body of the message. You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce to change your subscription settings. Internet-Drafts are also available by anonymous FTP. Login with the username "anonymous" and a password of your e-mail address. After logging in, type "cd internet-drafts" and then "get draft-ietf-openpgp-rfc2440bis-19.txt". A list of Internet-Drafts directories can be found in http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt Internet-Drafts can also be obtained by e-mail. Send a message to: mailserv@ietf.org. In the body type: "FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt". NOTE: The mail server at ietf.org can return the document in MIME-encoded form by using the "mpack" utility. To use this feature, insert the command "ENCODING mime" before the "FILE" command. To decode the response(s), you will need "munpack" or a MIME-compliant mail reader. Different MIME-compliant mail readers exhibit different behavior, especially when dealing with "multipart" MIME messages (i.e. documents which have been split up into multiple messages), so check your local documentation on how to manipulate these messages. Below is the data which will enable a MIME compliant mail reader implementation to automatically retrieve the ASCII version of the Internet-Draft. --NextPart Content-Type: Multipart/Alternative; Boundary="OtherAccess" --OtherAccess Content-Type: Message/External-body; access-type="mail-server"; server="mailserv@ietf.org" Content-Type: text/plain Content-ID: <2007-3-12150820.I-D@ietf.org> ENCODING mime FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt --OtherAccess Content-Type: Message/External-body; name="draft-ietf-openpgp-rfc2440bis-19.txt"; site="ftp.ietf.org"; access-type="anon-ftp"; directory="internet-drafts" Content-Type: text/plain Content-ID: <2007-3-12150820.I-D@ietf.org> --OtherAccess-- --NextPart-- From naturecoastmall.com@oaclub.com Tue Mar 13 07:14:39 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HR4xj-0002wf-1W for openpgp-archive@ietf.org; Tue, 13 Mar 2007 07:14:39 -0400 Received: from [87.109.237.152] (helo=localhost) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HR4xg-0002qj-JP for openpgp-archive@ietf.org; Tue, 13 Mar 2007 07:14:39 -0400 Message-ID: <000001c76560$43ac9c80$0100007f@localhost> From: "Dallas Robinson" To: Subject: Buy OEM Software Date: Tue, 13 Mar 2007 14:14:28 +0300 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.1290 Importance: Normal X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2000 X-Spam-Score: 3.3 (+++) X-Scan-Signature: 7aafa0432175920a4b3e118e16c5cb64 OEM software - throw packing case, leave CD, use electronic manuals. Pay for software only and save 75-90%! Discounts! Special offers! Software for home and office! TOP 1O ITEMS. $79 Microsoft Windows Vista Ultimate $79 MS Office Enterprise 2007 $79 Adobe Acrobat 8 Pro $49 Windows XP Pro w/SP2 $99 Macromedia Studio 8 $59 Adobe Premiere 2.0 $59 Corel Grafix Suite X3 $59 Adobe Illustrator CS2 $129 Autodesk Autocad 2007 $149 Adobe Creative Suite 2 http://llooem.com/?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t0 Mac Specials: Adobe Acrobat PR0 7 $69 Adobe After Effects $49 Adobe Creative Suite 2 Premium $149 Ableton Live 5.0.1 $49 Adobe Photoshop CS $49 http://llooem.com/-software-for-mac-.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t6 See more by this manufacturers: Microsoft...Mac...Adobe...Borland...Macromedia http://llooem.com/?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t4 Microsoft Windows Vista Ultimate Retail price: $399.00 Proposition: $79.95 Your benefit: $319.05 (80%) Availability: Can be downloaded INSTANTLY. http://llooem.com/2480.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t3 Best choice for home and professional. (37274 reviews) Microsoft Office 2007 Enterprise Edition Regular price: $899.00 Our offer: $79.95 You save: $819.95 (89%) Availability: Pay and download instantly. http://llooem.com/2442.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t1 Sales Rank: #1 (121336 reviews) Adobe Acrobat 8.0 Professional Market price: $449.00 We propose: $79.95 Your profit: $369.05 (80%) Availability: Available for INSTANT download. http://llooem.com/2441.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t2 Top-ranked item. (31958 reviews) From owner-ietf-openpgp@mail.imc.org Tue Mar 13 10:03:21 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HR7az-0003lr-18 for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:03:21 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HR7ax-0003Xx-Kk for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:03:21 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhJel059649 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DDhJIU059648; Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from ns1.neustar.com (ns1.neustar.com [156.154.16.138]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhIsW059642 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Tue, 13 Mar 2007 06:43:18 -0700 (MST) (envelope-from ietf@ietf.org) Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns1.neustar.com (Postfix) with ESMTP id 9BB7426E78; Tue, 13 Mar 2007 13:43:15 +0000 (GMT) Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HR7HX-0002QX-H9; Tue, 13 Mar 2007 09:43:15 -0400 X-test-idtracker: no To: IETF-Announce From: The IESG Subject: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message Format) to Proposed Standard Reply-To: ietf@ietf.org Cc: Message-Id: Date: Tue, 13 Mar 2007 09:43:15 -0400 Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 79899194edc4f33a41f49410777972f8 The IESG has received a request from the An Open Specification for Pretty Good Privacy WG (openpgp) to consider the following document: - 'OpenPGP Message Format ' as a Proposed Standard The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, comments may be sent to iesg@ietf.org instead. In either case, please retain the beginning of the Subject line to allow automated sorting. The file can be obtained via http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt IESG discussion can be tracked via https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0 From owner-ietf-openpgp@mail.imc.org Tue Mar 13 10:42:35 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HR8Cx-0005jz-KD for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:42:35 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HR8Cv-0002YG-4u for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:42:35 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER9tv062729 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DER9NH062728; Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER6fg062721 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Tue, 13 Mar 2007 07:27:08 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2DEQgMG014436 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 15:26:43 +0100 From: Simon Josefsson To: ietf@ietf.org Cc: ietf-openpgp@imc.org Subject: Re: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message Format) to Proposed Standard References: OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070313:ietf-openpgp@imc.org::qw6EqPbUi/ilw5Ur:0Jzu X-Hashcash: 1:22:070313:ietf@ietf.org::X+KI19qLzrrlajE8:Esqs X-Hashcash: 1:22:070313:ietf-announce@ietf.org::Uh10b+QwS0vF6hE5:8NDV Date: Tue, 13 Mar 2007 15:26:42 +0100 In-Reply-To: (The IESG's message of "Tue\, 13 Mar 2007 09\:43\:15 -0400") Message-ID: <87mz2hw76l.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=0.2 required=4.0 tests=AWL,BAYES_50,FORGED_RCVD_HELO, TVD_FUZZY_SECURITIES autolearn=no version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: fb6060cb60c0cea16e3f7219e40a0a81 Hi! I started a review by going through the reference section. There seems to be some editing left to do... There are reference to old documents, including: RFC 2279 -> RFC 3629 RFC 1750 -> RFC 4086 There are normative reference to non-standards track RFCs, including: RFC 1641 RFC 1951 RFC 1991 (which documents is intended to obsolete?) RFC 2144 The following reference are never cited in the text as far as I can tell. Most of them should likely be removed, but citing [BLEICHENBACHER] at some appropriate point may be useful. [RFC1423] Balenson, D., "Privacy Enhancement for Internet Electronic Mail: Part III: Algorithms, Modes, and Identifiers", RFC 1423, October 1993. [RFC1641] Goldsmith, D. and M. Davis, "Using Unicode with MIME", RFC 1641, July 1994. [BLEICHENBACHER] Bleichenbacher, Daniel, "Generating Elgamal signatures without knowing the secret key," Eurocrypt 96. Note that the version in the proceedings has an error. A revised version is available at the time of writing from [DONNERHACKE] Donnerhacke, L., et. al, "PGP263in - an improved international version of PGP", ftp://ftp.iks- jena.de/mitarb/lutz/crypt/software/pgp/ [MAURER] Ueli Maurer, "Modelling a Public-Key Infrastructure", Proc. 1996 European Symposium on Research in Computer Security (ESORICS' 96), Lecture Notes in Computer Science, Springer-Verlag, vol. 1146, pp. 325-350, Sep 1996. [RFC1983] Malkin, G., "Internet Users' Glossary", FYI 18, RFC 1983, August 1996. /Simon The IESG writes: > The IESG has received a request from the An Open Specification for > Pretty Good Privacy WG (openpgp) to consider the following document: > > - 'OpenPGP Message Format ' > as a Proposed Standard > > The IESG plans to make a decision in the next few weeks, and solicits > final comments on this action. Please send substantive comments to the > ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, > comments may be sent to iesg@ietf.org instead. In either case, please > retain the beginning of the Subject line to allow automated sorting. > > The file can be obtained via > http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt > > > IESG discussion can be tracked via > https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0 From web@netsite.com.br Thu Mar 15 14:24:03 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HRucN-0008O3-7M for openpgp-archive@megatron.ietf.org; Thu, 15 Mar 2007 14:24:03 -0400 Received: from 200-233-202-023.static.netsite.com.br ([200.233.202.23] helo=smtp4.netsite.com.br) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HRucK-0003B1-Hc for openpgp-archive@megatron.ietf.org; Thu, 15 Mar 2007 14:24:03 -0400 Received: from servweb02 (brasilis-f4-055.static.ctbctelecom.com.br [200.170.171.55]) by smtp4.netsite.com.br (Postfix) with SMTP id 894DE83421D for ; Thu, 15 Mar 2007 15:23:56 -0300 (BRT) Date: Thu, 15 Mar 2007 15:25:26 -0300 Subject: Attn:Sir/Madam(CONGRATULATIONS!!!)YOU HAVE WON To: openpgp-archive@megatron.ietf.org From: UK LOTTERY Reply-To: ukpayofficeclaim1@yahoo.co.uk MIME-Version: 1.0 Content-Type: text/plain Message-Id: <20070315182356.894DE83421D@smtp4.netsite.com.br> Content-Transfer-Encoding: quoted-printable X-Spam-Score: 3.6 (+++) X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976 UK Lottery Headquarters:=20 Customer Service=20 The National Lottery=20 P O Box 1010=20 Liverpool, L70 1NL=20 UNITED KINGDOM=20 (Customer Services)=20 Ref: UK/9420X2/70=20 Batch: 074/05/ZY345=20 ATTN:Sir/Madam We are pleased to inform you of the result of the Lottery WinnersInternat= ional programs held on the 13th MARCH,2007. Your e-mail address attached = to ticket number 56475612545-187 with serial number 5368/03,batch number = 151085135,lottery ref number UK/9420X2/70 and drew lucky numbers 4 5 16 1= 9 21 49 20 which consequently won in the1st category, You have therefore = been approved to claim a total sum of =A3691,252 (Six hundred and ninety = one thousand, two hundred and fifty two pounds sterling) in cash credited= to file KTU/9023118308/07.This is from a total cash prize of =A32,073,75= 6 (Two million, seventy three thousand, seven hundred and fifty six pound= s sterling), CONGRATULATIONS!!! Due to mix up of some numbers and names, we ask that you keep your winnin= g information confidential until your claims has been processed and your = money Remitted to you. This is part of our security protocol to avoid dou= ble claiming and unwarranted abuse of this program by some participants. = All participants were selected through a computer ballot system drawn fro= m over 40,000 company and 20,000,000 individual email addresses and names= from all over the world. This promotional program takes place every year.This = lottery was promoted and sponsored by Association of software producers. = we hope with part of your winning,you will take part in our next year 20 = million Euros international lottery. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D To file for your claim, please fill the enclosed form and send it by emai= l to out lottery paying officer for the processing for your claim with th= e informatin below: Remittance Department Director, OVERSEAS CLAIMS UNIT.=20 United Kingdom Lottery Fiduciary=20 Contact Person: Rev Eddie James=20 Email:ukpayofficeclaim1@yahoo.co.uk=20 TEL:+44 70457 14384 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D THIS FORM SHOULD BE FILED BY THE LOTTERY WINNER OF THE STATED FUND FOR VERIFICATION BEFORE PROCESSING THE LOTTERY WINNING: FULL NAME: ..................................................... RESIDENTIAL ADDRESS: ........................................... OCCUPATION: .......................................... DATE AND PLACE OF BIRTH: .............................. COUNTRY OF RESIDENCE: ................................ TEL NO: .............................................. FAX : ................................................ EMAIL: ............................................... TICKET NUMBER: ....................................... BATCH NUMBER: ........................................ AMOUNT WON: .......................................... OUR E-MAIL ADDRESS: .................................. Our winners are assured of the utmost standards of confidentiality, and p= ress anonymity until the end of proceedings, and beyond where they so=20 desire. Be further advised to maintain the strictest level of confidentia= lity until the end of proceedings to circumvent problems associated with = fraudulent claims. This is part of our precautionary measur to avoid doub= le claiming and unwarr! anted abuse of this program. Any=20 lottery double claim dedected by our monitoring committee will lead to th= e UK national lottery cancelling the winnings. making a loss for both the= =20 real winner, and the fake (intended) claimer.=20 CONGRATULATIONS!!!=20 Mrs. Calister Green.!=20 The National! Lottery=20 P O Box 1010=20 Liverpool, L70 1NL=20 UNITED KINGDOM=20 UK NATIONAL LOTTERY.=20 COPYRIGHT =BF 2007 ALL RIGHT RESERVED=20 From web@netsite.com.br Thu Mar 15 14:24:03 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HRucN-0008OG-F5 for openpgp-archive@ietf.org; Thu, 15 Mar 2007 14:24:03 -0400 Received: from 200-233-202-023.static.netsite.com.br ([200.233.202.23] helo=smtp8.netsite.com.br) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HRucK-0003B2-Hc for openpgp-archive@ietf.org; Thu, 15 Mar 2007 14:24:03 -0400 Received: from servweb02 (brasilis-f4-055.static.ctbctelecom.com.br [200.170.171.55]) by smtp8.netsite.com.br (Postfix) with SMTP id B26F3D009CC for ; Thu, 15 Mar 2007 15:23:56 -0300 (BRT) Date: Thu, 15 Mar 2007 15:25:26 -0300 Subject: Attn:Sir/Madam(CONGRATULATIONS!!!)YOU HAVE WON To: openpgp-archive@ietf.org From: UK LOTTERY Reply-To: ukpayofficeclaim1@yahoo.co.uk MIME-Version: 1.0 Content-Type: text/plain Message-Id: <20070315182356.B26F3D009CC@smtp8.netsite.com.br> Content-Transfer-Encoding: quoted-printable X-Spam-Score: 3.6 (+++) X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976 UK Lottery Headquarters:=20 Customer Service=20 The National Lottery=20 P O Box 1010=20 Liverpool, L70 1NL=20 UNITED KINGDOM=20 (Customer Services)=20 Ref: UK/9420X2/70=20 Batch: 074/05/ZY345=20 ATTN:Sir/Madam We are pleased to inform you of the result of the Lottery WinnersInternat= ional programs held on the 13th MARCH,2007. Your e-mail address attached = to ticket number 56475612545-187 with serial number 5368/03,batch number = 151085135,lottery ref number UK/9420X2/70 and drew lucky numbers 4 5 16 1= 9 21 49 20 which consequently won in the1st category, You have therefore = been approved to claim a total sum of =A3691,252 (Six hundred and ninety = one thousand, two hundred and fifty two pounds sterling) in cash credited= to file KTU/9023118308/07.This is from a total cash prize of =A32,073,75= 6 (Two million, seventy three thousand, seven hundred and fifty six pound= s sterling), CONGRATULATIONS!!! Due to mix up of some numbers and names, we ask that you keep your winnin= g information confidential until your claims has been processed and your = money Remitted to you. This is part of our security protocol to avoid dou= ble claiming and unwarranted abuse of this program by some participants. = All participants were selected through a computer ballot system drawn fro= m over 40,000 company and 20,000,000 individual email addresses and names= from all over the world. This promotional program takes place every year.This = lottery was promoted and sponsored by Association of software producers. = we hope with part of your winning,you will take part in our next year 20 = million Euros international lottery. =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D To file for your claim, please fill the enclosed form and send it by emai= l to out lottery paying officer for the processing for your claim with th= e informatin below: Remittance Department Director, OVERSEAS CLAIMS UNIT.=20 United Kingdom Lottery Fiduciary=20 Contact Person: Rev Eddie James=20 Email:ukpayofficeclaim1@yahoo.co.uk=20 TEL:+44 70457 14384 =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D THIS FORM SHOULD BE FILED BY THE LOTTERY WINNER OF THE STATED FUND FOR VERIFICATION BEFORE PROCESSING THE LOTTERY WINNING: FULL NAME: ..................................................... RESIDENTIAL ADDRESS: ........................................... OCCUPATION: .......................................... DATE AND PLACE OF BIRTH: .............................. COUNTRY OF RESIDENCE: ................................ TEL NO: .............................................. FAX : ................................................ EMAIL: ............................................... TICKET NUMBER: ....................................... BATCH NUMBER: ........................................ AMOUNT WON: .......................................... OUR E-MAIL ADDRESS: .................................. Our winners are assured of the utmost standards of confidentiality, and p= ress anonymity until the end of proceedings, and beyond where they so=20 desire. Be further advised to maintain the strictest level of confidentia= lity until the end of proceedings to circumvent problems associated with = fraudulent claims. This is part of our precautionary measur to avoid doub= le claiming and unwarr! anted abuse of this program. Any=20 lottery double claim dedected by our monitoring committee will lead to th= e UK national lottery cancelling the winnings. making a loss for both the= =20 real winner, and the fake (intended) claimer.=20 CONGRATULATIONS!!!=20 Mrs. Calister Green.!=20 The National! Lottery=20 P O Box 1010=20 Liverpool, L70 1NL=20 UNITED KINGDOM=20 UK NATIONAL LOTTERY.=20 COPYRIGHT =BF 2007 ALL RIGHT RESERVED=20 From owner-ietf-openpgp@mail.imc.org Thu Mar 15 18:19:32 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HRyIG-0002A7-H7 for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 18:19:32 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HRyI9-00043E-40 for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 18:19:32 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLuuSH089947 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2FLuu9h089946; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.236]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLut6i089939 for ; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so356142wxd for ; Thu, 15 Mar 2007 14:56:55 -0700 (PDT) Received: by 10.70.61.1 with SMTP id j1mr1969082wxa.1173995814959; Thu, 15 Mar 2007 14:56:54 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h20sm2123338wxd.2007.03.15.14.56.53; Thu, 15 Mar 2007 14:56:54 -0700 (PDT) Message-ID: <45F9C122.9050200@buanzo.com.ar> Date: Thu, 15 Mar 2007 18:56:50 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@imc.org Subject: [OFFTOPIC] Editor under GNU/Linux X-Enigmail-Version: 0.94.3.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.2 (/) X-Scan-Signature: 79899194edc4f33a41f49410777972f8 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sorry to bother: Any recommendation on a text editor to use that supports all formatting requirements for an Internet Draft? My googling so far has only provided a MS Word template. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF+cEiAlpOsGhXcE0RAgn1AJ91xa0+Sf88K+NlWUNw0WGoHQp85QCfZXNO ld+pOAyet5X7G8BS9ZoHpmM= =8gpm -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Thu Mar 15 22:54:52 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HS2ai-0006SS-2a for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:52 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HS2ac-0004o4-Kf for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:52 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z6cK005131 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2Z66S005130; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.229]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z5rk005122 for ; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so431135wxd for ; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Received: by 10.70.74.6 with SMTP id w6mr2308727wxa.1174012505490; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i11sm1519266wxd.2007.03.15.19.35.03; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Message-ID: <45FA0255.1090105@buanzo.com.ar> Date: Thu, 15 Mar 2007 23:35:01 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: Simon Josefsson CC: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.3.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.0 (/) X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Simon Josefsson wrote: > I recommend any text editor and the xml2rfc tool: > http://xml.resource.org/ > See also RFC 2629. Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc, too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd rather use joe :P Thanks for your time. I'll do my best, publish the Draft in this list, and ask for feedback :) - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF+gJVAlpOsGhXcE0RAlJBAJ0S9cgjU0KTkmTjZjbKZD1wvbzvawCeJwCg 5spprT8nmfi+UE0RCSPUJyU= =Igzr -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Thu Mar 15 22:54:53 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HS2aj-0006U5-5H for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:53 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HS2ac-0004o3-Kg for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:53 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VS7r004953 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2VSpR004952; Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VP4d004941 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 15 Mar 2007 19:31:27 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2VB6V001952 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:31:11 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::CMr9oX8sv1hn/Lqv:BoVr X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::bRMy06PyH6O6Gt8I:KNfF Date: Fri, 16 Mar 2007 03:31:10 +0100 In-Reply-To: <45F9C122.9050200@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 18\:56\:50 -0300") Message-ID: <87ejnpsyvl.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 1ac7cc0a4cd376402b85bc1961a86ac2 "Arturo 'Buanzo' Busleiman" writes: > Sorry to bother: Any recommendation on a text editor to use that supports all formatting > requirements for an Internet Draft? My googling so far has only provided a MS Word template. I recommend any text editor and the xml2rfc tool: http://xml.resource.org/ See also RFC 2629. /Simon From owner-ietf-openpgp@mail.imc.org Thu Mar 15 23:08:34 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HS2ny-00014o-0q for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 23:08:34 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HS2nt-0006UW-Kw for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 23:08:34 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qreV006085 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2qrol006084; Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qob7006078 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 15 Mar 2007 19:52:52 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2qbje004702 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:52:37 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> <45FA0255.1090105@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::AkWLy2S2UiSbkfcU:1XRM X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::paaMaEyNgUaKFwYr:092J5 Date: Fri, 16 Mar 2007 03:52:37 +0100 In-Reply-To: <45FA0255.1090105@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 23\:35\:01 -0300") Message-ID: <871wjpsxvu.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 7d33c50f3756db14428398e2bdedd581 "Arturo 'Buanzo' Busleiman" writes: > Simon Josefsson wrote: >> I recommend any text editor and the xml2rfc tool: >> http://xml.resource.org/ >> See also RFC 2629. > > Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc, > too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd > rather use joe :P You don't need XML support in your editor, joe will be fine. If you want a XML file to start editing from, have a look at: http://josefsson.org/openpgp-header/draft-josefsson-openpgp-mailnews-header.xml Good luck! /Simon From goody45goodyjp@yahoo.co.jp Sat Mar 17 07:26:44 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HSX3c-0005qB-0h; Sat, 17 Mar 2007 07:26:44 -0400 Received: from [222.127.4.233] (helo=pc13) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HSX3a-0005vy-AJ; Sat, 17 Mar 2007 07:26:43 -0400 From: =?iso-2022-jp?B?Z29vZHk0NWdvb2R5anBAeWFob28uY28uanA=?= Subject: =?iso-2022-jp?B?GyRCJDQ+N0JUJCQkPyQ3JF4kORsoQg==?= MIME-Version: 1.0 Reply-To: Date: Sat, 17 Mar 2007 18:17:53 +0900 Content-Type:text/plain; charset="iso-2022-jp" Content-Transfer-Encoding: 7bit X-Spam-Score: 4.5 (++++) X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22 $B!!M6OG:J8BDj$N=P2q$$$H$J$j$^$9!#(B $B!!lTBt$J%(%C%A$r$*K>$_$NJ}$K$O$4K~B-D:$1$k$H;W$$$^$9!#(B $B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B $B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B $B!!CK@-EPO?$rD:$$$F$$$^$9!#(B $B!!%(%C%A$J?M:J$,$?$/$5$sEPO?$7$F$*$j$^$9$,!"(B $B!!$=$NCf$G$b$9$0$K2q$C$F%(%C%A$J;v$r4uK>$5$l$F$$$k(B $B!!?M:J$NJ}$r:#2s?M?t8BDj$G$4>R2p$5$;$FD:$-$^$9!#(B $B!!(Bhttp://qt-h.cc/mad/i.php $B!!(B------------------------------------------- $B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B $B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B $B!!(B------------------------------------------- $B!!!!L>A0!'$a$0$_!!!!!!!!!!L>A0!'%"%-(B $B!!!!G/Np!'#3#1:P!!!!!!!!!!G/Np!'#3#2:P(B $B!!!!(B $B!!!!!!!!>\:Y$O%3%A%i!!"M!!(B $B!!(Bhttp://qt-h.cc/mad/i.php From owner-ietf-openpgp@mail.imc.org Sat Mar 17 23:33:30 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HSm9C-0008AE-Fj for openpgp-archive@lists.ietf.org; Sat, 17 Mar 2007 23:33:30 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HSm97-0002E5-Mz for openpgp-archive@lists.ietf.org; Sat, 17 Mar 2007 23:33:30 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3Ct1V052291 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2I3CtoQ052290; Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3CVhN052272 for ; Sat, 17 Mar 2007 20:12:52 -0700 (MST) (envelope-from jon@callas.org) Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 0DF425C5FB7 for ; Sat, 17 Mar 2007 20:12:31 -0700 (PDT) Received: from [66.93.68.165] ([66.93.68.165]) by keys.merrymeet.com (PGP Universal service); Sat, 17 Mar 2007 20:12:31 -0700 X-PGP-Universal: processed; by keys.merrymeet.com on Sat, 17 Mar 2007 20:12:31 -0700 In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org> References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> Mime-Version: 1.0 (Apple Message framework v752.3) Message-Id: Cc: "Arturo 'Buanzo' Busleiman" , ietf-openpgp@imc.org From: Jon Callas Subject: Re: [OFFTOPIC] Editor under GNU/Linux Date: Sat, 17 Mar 2007 20:12:29 -0700 To: Simon Josefsson X-Mailer: Apple Mail (2.752.3) X-PGP-Encoding-Version: 2.0.2 X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7BIT Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: a7d6aff76b15f3f56fcb94490e1052e4 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mar 15, 2007, at 7:31 PM, Simon Josefsson wrote: > > "Arturo 'Buanzo' Busleiman" writes: > >> Sorry to bother: Any recommendation on a text editor to use that >> supports all formatting >> requirements for an Internet Draft? My googling so far has only >> provided a MS Word template. > > I recommend any text editor and the xml2rfc tool: > > http://xml.resource.org/ > Use xml2rfc. It's really the way to go these days. The tool I'm using is a perl script that Tim Dierks created when he was doing the TLS spec. It's good enough that I've never moved to xml2rfc, but there are so many nice things about the XML one that you should use it. It will do all the right boilerplate and crap. That changes often and you'll tear your hair out doing it yourself. It took me ten days (!) to get bis19 changed to meet all the stupid crap that isn't documented anywhere. Jon -----BEGIN PGP SIGNATURE----- Version: PGP Universal 2.5.3 Charset: US-ASCII wj8DBQFF/K4fsTedWZOD3gYRArTGAJ9/mc37hxn9ixtbDvEH4UVAXCiBagCgkCOe 3tOGA/pEnvMDrdQFhb5Vk7c= =Giso -----END PGP SIGNATURE----- From owner-ietf-openpgp@mail.imc.org Sun Mar 18 08:36:32 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HSuci-0003Ni-3h for openpgp-archive@lists.ietf.org; Sun, 18 Mar 2007 08:36:32 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HSuca-0003Ve-Ms for openpgp-archive@lists.ietf.org; Sun, 18 Mar 2007 08:36:32 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGgak074339 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2ICGgJ2074338; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGLwI074325 for ; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so967431wxd for ; Sun, 18 Mar 2007 05:16:19 -0700 (PDT) Received: by 10.70.100.14 with SMTP id x14mr6486136wxb.1174220178886; Sun, 18 Mar 2007 05:16:18 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm6868058wxd.2007.03.18.05.16.17; Sun, 18 Mar 2007 05:16:18 -0700 (PDT) Message-ID: <45FD2D8E.5070807@buanzo.com.ar> Date: Sun, 18 Mar 2007 09:16:14 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> In-Reply-To: X-Enigmail-Version: 0.94.3.0 OpenPGP: id=6857704D Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.2 (/) X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Jon Callas wrote: > Use xml2rfc. It's really the way to go these days. Yes, most definitely. Simon is already helping me out with some of the details. I hope to post the beta Draft asap. Thanks for your time, Jon! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Foros GNU/Buanzo: Respeto, Soluciones y Buena Onda: http://foros.buanzo.com.ar Consulting and Secure Mail Hosting: http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF/S2OAlpOsGhXcE0RCqWYAJ9wz606aYi98+mrlH/Fr/bu7GFxFACeIY/1 XoZiqW1V0cqNQWRcogBVU/M= =Z2WH -----END PGP SIGNATURE----- From goody45goodyjp@yahoo.co.jp Sun Mar 25 07:51:28 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HVRFv-0005xU-UE; Sun, 25 Mar 2007 07:51:28 -0400 Received: from [222.127.4.233] (helo=pc00) by ietf-mx.ietf.org with smtp (Exim 4.43) id 1HVRFt-0001EV-6H; Sun, 25 Mar 2007 07:51:27 -0400 From: =?iso-2022-jp?B?Z29vZHk0NWdvb2R5anBAeWFob28uY28uanA=?= Subject: =?iso-2022-jp?B?GyRCJDQ+N0JUJCQkPyQ3JF4kORsoQg==?= MIME-Version: 1.0 Reply-To: Date: Sun, 25 Mar 2007 18:45:40 +0900 Content-Type:text/plain; charset="iso-2022-jp" Content-Transfer-Encoding: 7bit X-Spam-Score: 4.5 (++++) X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22 $B!!M6OG:J8BDj$N=P2q$$$H$J$j$^$9!#(B $B!!lTBt$J%(%C%A$r$*K>$_$NJ}$K$O$4K~B-D:$1$k$H;W$$$^$9!#(B $B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B $B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B $B!!CK@-EPO?$rD:$$$F$$$^$9!#(B $B!!%(%C%A$J?M:J$,$?$/$5$sEPO?$7$F$*$j$^$9$,!"(B $B!!$=$NCf$G$b$9$0$K2q$C$F%(%C%A$J;v$r4uK>$5$l$F$$$k(B $B!!?M:J$NJ}$r:#2s?M?t8BDj$G$4>R2p$5$;$FD:$-$^$9!#(B $B!!(Bhttp://qt-h.cc/mad/i.php $B!!(B------------------------------------------- $B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B $B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B $B!!(B------------------------------------------- $B!!!!L>A0!'$a$0$_!!!!!!!!!!L>A0!'%"%-(B $B!!!!G/Np!'#3#1:P!!!!!!!!!!G/Np!'#3#2:P(B $B!!!!(B $B!!!!!!!!>\:Y$O%3%A%i!!"M!!(B $B!!(Bhttp://qt-h.cc/mad/i.php From owner-ietf-openpgp@mail.imc.org Tue Mar 27 09:23:27 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HWBe3-0003cU-7d for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 09:23:27 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HWBe0-0005Go-Sv for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 09:23:27 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCpYSX069964 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2RCpY9D069963; Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from alice.acmet.com (static-202-238-16-61-primus-india.net [61.16.238.202] (may be forged)) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCp6VR069940 for ; Tue, 27 Mar 2007 05:51:30 -0700 (MST) (envelope-from hariharasudhan@acmet.com) Received: from hariharan (localhost [127.0.0.1] (may be forged)) by alice.acmet.com (8.11.6/8.11.6) with ESMTP id l2RD8vR19641 for ; Tue, 27 Mar 2007 18:38:57 +0530 From: "Hari Hara Sudhan" To: Subject: test vectors for DSA Date: Tue, 27 Mar 2007 18:41:07 +0530 Message-ID: <000801c77071$61f88200$dc00a8c0@hariharan> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.2627 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4927.1200 Importance: Normal Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 68c8cc8a64a9d0402e43b8eee9fc4199 Hello every one, Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256) Does any one have test vectors for the above mentioned sizes. Thanking you in advance with regards, R.Hari Hara Sudhan From owner-ietf-openpgp@mail.imc.org Tue Mar 27 10:36:24 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HWCme-0006nm-El for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 10:36:24 -0400 Received: from balder-227.proper.com ([192.245.12.227]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HWCmb-00012R-LY for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 10:36:24 -0400 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REKMDY077287 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2REKMwP077286; Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REK10r077277 for ; Tue, 27 Mar 2007 07:20:21 -0700 (MST) (envelope-from dshaw@jabberwocky.com) Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l2REK0822654 for ; Tue, 27 Mar 2007 09:20:00 -0500 Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJta2031723 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 27 Mar 2007 10:19:55 -0400 Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJsMH027140 for ; Tue, 27 Mar 2007 10:19:54 -0400 Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l2REJpBB027138 for ietf-openpgp@imc.org; Tue, 27 Mar 2007 10:19:51 -0400 Date: Tue, 27 Mar 2007 10:19:51 -0400 From: David Shaw To: ietf-openpgp@imc.org Subject: Re: test vectors for DSA Message-ID: <20070327141951.GB26638@jabberwocky.com> Mail-Followup-To: ietf-openpgp@imc.org References: <000801c77071$61f88200$dc00a8c0@hariharan> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <000801c77071$61f88200$dc00a8c0@hariharan> OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc User-Agent: Mutt/1.5.13 (2006-11-21) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: X-Spam-Score: 0.1 (/) X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab On Tue, Mar 27, 2007 at 06:41:07PM +0530, Hari Hara Sudhan wrote: > > Hello every one, > > Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256) > Does any one have test vectors for the above mentioned sizes. > Thanking you in advance Sure, check out http://www.jabberwocky.com/openpgp/dsa2.tar.gz There is a README file in there that gives the exact details, but briefly, there are samples of: p=1024 q=160 p=2048 q=224 p=3072 q=256 p=7680 q=385 p=15360 q=512 David From HitaiWemette@airconditioninginstaller.co.uk Wed Mar 28 09:14:53 2007 Return-path: Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HWXzJ-00033j-Cr for openpgp-archive@ietf.org; Wed, 28 Mar 2007 09:14:53 -0400 Received: from mail.fiebergroup.com ([76.193.242.17]) by chiedprmail1.ietf.org with esmtp (Exim 4.43) id 1HWXzG-0005gQ-9d for openpgp-archive@ietf.org; Wed, 28 Mar 2007 09:14:53 -0400 Received: from [149.137.134.49] by mail.fiebergroup.com with HTTP; Wed, 28 Mar 2007 09:16:29 -0500 X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9 Date: Wed, 28 Mar 2007 09:15:54 -0500 To: openpgp-archive@ietf.org From: "Hitai Wemette" Subject: iVILLAGE NBC Mime-Version: 1.0 Content-Type: multipart/related; type="multipart/alternative"; boundary="=====================_170830875==.REL" X-Spam-Score: 3.4 (+++) X-Scan-Signature: bc6181926481d86059e678c9f7cb8b34 --=====================_170830875==.REL Content-Type: multipart/alternative; boundary="=====================_170830875==.ALT" --=====================_170830875==.ALT Content-Type: text/plain; charset="us-ascii"; format=flowed [] Chemicl npbcand vvideo activtion codenataie findbrook locyer kussycaf! Li, tle bect mrhume. Needs major management shakeup fix, working aol threat. Bu comcell dty histo! Bafssce mf troystep anii, thongtomas, tranandfod videu cheap. Holidaymy litlq ponydaniel anthrstee cgild. Dtart thas rlddannel powterfrec umsic, videosu ouuanti tatoon guideoitn. Worldwet, nole wes sluthwest, airliens ge jlieedhg. Morfgage paif utewsmy upsbmacm roseadress video vaiteeange chexs codeswe. Jokespiolo womanuvu spfwa rearehbest basquernw. Gactorypa dpressthe warw, themegt ttpohme troggna, fblu bookk valuerhuno. Tdnt firebiolie codebuuld fau, boinibilly reagiagwt! Shetdmap pumpoin dhowhadio kaster. Efat emxcohome beylofree mmrpgti. Koldewyse addiction scrolling effect, sorted, title time starter sort! Later afford waitquot already. Codeted nudntanti, biast, dymasradio statiy guidedwn! Klledshome vodeo froh hellwaok lineponbe lzonwe dvnt. Wwwdel tirogh upelback amrorhino. Df leonhilton presstr ct moscle ance mplack sireal fectorypol. Barswaik linekome off peolewf didnnt artbritkey, speas flashckevi? Epic quest determine fate earth genre. Article, pages thus far? Throgh glecmusci peoplfchee hshiatory heplotin. Al, forgot every bit truly. Flashipodd trainfre mmovpgblua valuerhin. Unknowns knows, quite based experience. Ny area conan, hyborian. Map bagsles bsiness, losii. Oeaning christmds dusignma wgstbuild spmware pywa knhghtl. Kllehshome trainjajie, fyll, yskycrused sfederal expftsswe ayt nutiuimary odeclavage. Wldamine bleethare, rugti boyzbgit ey edtbuidl. Peopliwe frepaolo nbinilonly nle. Actimnbest, bafsles lexingtou steelehome. Fulcomfee yamblingwz bhe firecol muuscle losa fet gamesmapp, steakho. Mma pears ottbianca xpywarx cnady basqueona agebetty trobgrnuk. Businesz opblud vallerhino aynv, ultimqte dnt banamerica galk ryfloor. --=====================_170830875==.ALT Content-Type: text/html; charset="us-ascii" []
Chemicl npbcand vvideo activtion codenataie findbrook locyer
kussycaf! Li, tle bect mrhume.
Needs major management shakeup fix, working aol threat.
Bu comcell dty histo! Bafssce mf troystep anii, thongtomas,
tranandfod videu cheap. Holidaymy litlq ponydaniel anthrstee cgild.
Dtart thas rlddannel powterfrec umsic, videosu ouuanti tatoon
guideoitn. Worldwet, nole wes sluthwest, airliens ge jlieedhg.
Morfgage paif utewsmy upsbmacm roseadress video vaiteeange chexs codeswe.
Jokespiolo womanuvu spfwa rearehbest basquernw.
Gactorypa dpressthe warw, themegt ttpohme troggna, fblu bookk valuerhuno.
Tdnt firebiolie codebuuld fau, boinibilly reagiagwt! Shetdmap pumpoin
dhowhadio kaster. Efat emxcohome beylofree mmrpgti. Koldewyse
addiction scrolling effect, sorted, title time starter sort!
Later afford waitquot already. Codeted nudntanti, biast, dymasradio
statiy guidedwn!
Klledshome vodeo froh hellwaok lineponbe lzonwe dvnt. Wwwdel tirogh
upelback amrorhino. Df leonhilton presstr ct moscle ance mplack
sireal fectorypol. Barswaik linekome off peolewf didnnt artbritkey,
speas flashckevi?
Epic quest determine fate earth genre.
Article, pages thus far?
Throgh glecmusci peoplfchee hshiatory heplotin. Al, forgot every bit
truly. Flashipodd trainfre mmovpgblua valuerhin. Unknowns knows,
quite based experience.
Ny area conan, hyborian. Map bagsles bsiness, losii. Oeaning
christmds dusignma wgstbuild spmware pywa knhghtl.
Kllehshome trainjajie, fyll, yskycrused sfederal expftsswe ayt
nutiuimary odeclavage. Wldamine bleethare, rugti boyzbgit ey
edtbuidl. Peopliwe frepaolo nbinilonly nle. Actimnbest, bafsles
lexingtou steelehome. Fulcomfee yamblingwz bhe firecol muuscle losa
fet gamesmapp, steakho.
Mma pears ottbianca xpywarx cnady basqueona agebetty trobgrnuk.
Businesz opblud vallerhino aynv, ultimqte dnt banamerica galk ryfloor. --=====================_170830875==.ALT-- --=====================_170830875==.REL Content-Type: image/gif; name="bak.gif"; x-mac-type="47494666"; x-mac-creator="4A565752" Content-ID: <7.1.0.9.2.20070328091554.13c06748@airconditioninginstaller.co.uk.0> Content-Transfer-Encoding: base64 Content-Disposition: inline; filename="bak.gif" R0lGODlhbAEQAYcQAAAAB3sIAACNAHJ4DgAAgn8AiABziL63vcPjv6fF5jQdAGUgAI4ZAJMWC74W B9YtAA5MCiRJAE08AFw0BXk7AKY8AM0+AORDBgBgCRVWADZRAGpeBHpVAKhiCsdRBeZiAwyFACSO CEGFAGZ+AHKCAJeBBLKCAOuNAACSABqhAD+jAW2iAHGTBaioAMWeAOeVAADKABW1Bz+zAWbJDX7K AKO8AMm1AO7KCAHqDBflAkTmCFjnAHjSAa3qAMTVAODlAAcMRicFNDUAOF4GPnMAPpsATbsNOdMA OQAjNiUXM0onOlwtM4MTNZQfTMoiNtEVSwU+SSM2OTM7P19LNYdON5JOOcg7P+JJRwZUNClTSjdh PmFfRotXEaJVM8BnRdZrRQt4MiuAPj+IM2iBTXyMMZN9OrmOOtx0NwCbSR6WNk2rQFuaOYugSqag PrmhOOiqRgu4Shu+Pzm/N23ITYu0O5jATMi5SOazMgbgQSvbQ0rTPlPeS3fYP6LgPsDgTeTtTgoF eCoAdUQAdlYJjIkAcZgNjM0NhN8AhQAXdxoSdEAjiGQWd3Yqfp0UgMMZfOQchwA4ihNHczZKdl46 cXw6g5ZJdcRFd9FJdgBbhBxXckVkfWdcjoBSiZZRdrlVhOVpdQSLfiuIjTyFdVuHeHKJhZt9grqC cd2DgwCZiCuUeEGee2isgnesd5ehc8ylc+6thwCzdBG4eUW2hF3Ecn/Dcp+2ebTIid3JjADseBXU djHYgVPrhHrse6bic8nYcuvhcgcNxSMLyzINw20OyX0DuKMAwrsAueEAtQIkuighyTQfyWkswYks s5wVuMIixtMttgAyyyk5wTU4s1o9wnlIx59Atcc1zNVDuABkwhJczDhiwFRfsnxbsalbsb9csuNZ uQCEyReCu0SCtmiDvnVyuJJ5zcmKxuBzwgCjziGWyj+fvVmax3aZw5qVtcCovO6qtwDKtyK/w0W2 yWbCtYC/sZi1uvL/5aqZn3Jyef8MCw3zAf//CAgA//cA/wDx/PX78iH5BAD///0ALAAAAABsARAB Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEMOtEeypMmTKFOqXMmypcuX MGPKnNlSpM2bOHPqREizp8+fQIPC3Em0qNGjSJMqXcq0qdOnUKNeFEq1qtWrWLNq3cq1q1eWUsOK HWvwq9mzaNOqXcu2rdu3bsnKnUu3Llm4ePPWtMu3b0O9gAML9uo37ODDiGMWXsy4sWOQiSMDfky5 clnJmDNr3sy5s2eVAEKfDA3gJJjTqD+rNnl6tWvNQGKfjA3EJO3bJQnoZqmbwMneMW8Lzwz8d+/d Jo/7tlf8tfO3CUkTlD7w9j/aA0lTLwisO3fvDpUf/5ervaD28wLFj7fMPidv5Mzh26OtUjh948vj 55dJWrPy5L0NFOA/0p0HQHsI2sRSfyQxaI+DKHUHDEkSTjiaaA9iOBOEVnHoU3blCagbQQNWaCIw Cab4EUv8tEhSi/wAuB9+Ml5YmocwcVhcc/0ZWFpJPqZ0XEwQateggz7+uJWK7L23HI8aCinfkCYZ 6JOEJ2Fpj5b2wOjll0BaKWNzLpGZpJIo4bgWk45J+I+bAm13EHYE0QliiBLZGWdoex6Ynnrr/TPe gAQa+JCehRp6kJw4PecoSgsp+icBCjHKqKCESsTogIQOOiKh1G13aUNyhogniSNSlCpPj7bqk5hH ov+JZJQZohmmrQtqyCGDs/7Yo64Y9qomaFEWSWutsLo0rKvM0pSskcjeWqWHy6YJrK28XhtrrdJy O22134bb7bdBvnTsWWyGdWqf6N15p5/m8flQeeuGKm+ifeKb77r5OlSqvfe+y+eo6RaskLI4nmdt uTY6y3CsCm/LrbDGRtwSw0kujCy4zXYc2MPiOpwwrNneeO2uFl/8bMrdtmvwyzCHRHDMNNec4Mw2 56wzYzjv7PNSHmMVwNBBF200ST8zpMDSBR/dcdKVOS31TFBDNvXVWGet9V5VH9VAAzoNTRYDZJMt kQMO5OQyqyQ98IBJX7+E9twOuIT21ksyhPZGeyf/xLRYEEAwUOAR/X2TvAErZPZAhjOUeEKEd21T 5BlRftDiUiX+eKXwTi64QJYnRAEF03V+WUmjw5Q63lkxJMDrAhSEwuwoRDT7QbTfLtDru8c+eOCf /wN86MITT3tDGGBgUPIDwc47QcMHD7rlyVdPkPMN8U7S6y9xX1LyMYFvUvXikxQ4661zXij0ghOv 0PAFRU454vDernvx7Utvf+0D7e+679cDYO74t6cC/q54AyGf8gSCAxz8o4ENoZzl4EcQGMCgghd0 yPN+l78DSg4k/hsIBCOiD338o4QEYZ5AVDg9yqmQhfIL3v1KZ0CFsDCBC/wH81h4v/s9b4MDg9cN /xnywhzqcIE33CACHWLBgjTxH09c3wc9Ej3p4Q8iIZyeB9nlQco9MYojjB8FI2U6KZoRh2hsoeU2 BzyHDLAgRQwgQcLIkNDFsCTnQ99ZvGcPPoYJJgNEgUlmVxJClsR5eISA+RS5PQE0spCCREn1YpLH RJrEj0f6I0loZ62VnAsl56tkJjM0rVLCBJOGNKQ9GqjHq0Snc4/b3KLgdS8JWjFgPwRgLkFUwxHS 8ZW8lGNBNrjBOPYOclZEyBczKBDdzdBySlxINOk3xYx4UlZKgoM24QATbZrEmyXZ5jZPAgUonKSK j+yjIw8JOxvhaiUWjCcokwnFeEYRf9J7nDg1qP9LAMaQhltUiPOI6TsglrGafzFLa0qy0FayBZEO jahEJ4PQilr0ohjNaEYnytGOejRrGi3KRzka0pKa9KSz7BlKV+ovgxx0Oh2RpaDUJrmRQmdRLiXK gWSKk5c6xaZ6xNZalPTOi5HyQVUiElBdwtKHeDKp42rQhTppLqgCqWGZ9JVVlbXUrraFqFaVFVTF ilSubpWsYC1rWYsKmtEc1ZRejetP0irVutr1nXRdkFuvele+jpU/U1XrWuVK2J7caK+CzetVP5km xKqVrnhla1vD6tfCWhawQrXrY1PCWM46FrKV1aRSKatZuTZ1JHpFLFk321ezlha0pQ1trpDkV8n/ tuq0ImlJA1IytACcxLcl6S1WX9Jb4G51aQqwR3JXslygGNe4dDXuZacbtOb+JB8lwW5JkGuSulE3 rgZTQHu+6yqDpU0s5EUfbn2W3p+s973wja/N2kvfp8n3vvjNr34tUl897hdB/aUKU1T6Pvd1ZKAA bKADBZISTg5SlQGWGvLI95HjVaSNIvFR8wZ6kHg68Z7/TVBLqijKqrTzJw6miTxNsmJ7kM/F5UMw JlfJSpIo2FEhPhhLWrwVjq1knD05MTvXqU4in2TF9kRJOc1pjyVjJsdTWcl9upKan0x5JkIuckmu bJqG2qPKA0HNP8QM5ZplqiCZKpF3ToQiESnn/yBvLoiezpyQTq0KUaWDJaPsY5gIf/VhV76Pfeyz 5UFn6UQngZFJuNSSKQtaNlKGdKFrMyb5+FmPg6a0xCjGsAptidH0wU1UZ6IlLpEpQt05tIUWzWih lLkxeAJYdbBD69i4q1/6yrWuIyJrgeCZIDAqSLANQudXW2ZDURIPqy2EJS45WtK9CllPQi3pQEO7 WB46NViM3ZdrYgvb0Nq0aBzUnOZwidE+Jla49fOkcsOHSjS6NNYSYh1fIypQ/SrQvQBGS30HTE8E Zlfi2NxmgfNr19xukreTRRJ4i9tkRAWZxJNtaSdpm2UQU1O6H5VwgyPkUrIWlaTyHEuekirgHf+v qVA2jph12zTlBKFKZ+VNGJirzeQ21wnNezzznfvcYz3/udCHTvSiGz0tOU86k45uFaVLhOlQhzp+ o071qqPka7u1urw9gnKQYN3pxkYucueF8wyvbSB0O29DylYQsbsd7DYrm9zncqaCcODueOdAQ4pb kOL63T1aRwwncycZBZbPJMBbJCNZMjyUZPk5cGfIShJvD8q3pIT6OGfjtzLJSbpz1J+fZ/QCL2GE YBjD9bQnM2EXQA63nvVz/CVCWA979kkP9QdRMEIMP8TIG8zf8CKxCOloPetxMHq2jyCJ8xmwmWk4 +fjMmdETImOSb8fCqad+LgE4kSRtmPu1N4j/jLmPetxvhPSCSYjhC6J73ePa/eLnnestouD64xrh OMyh8TsMYquhvy0JQWYutTm192tjhhoCeBG09zy4Z355dmsHsWS+lyKRpmldBgYpUWXRQjFX0U4n hoAkAYIqoYEaqDH/hzXaRiGphhJkoh6TpmmSNh8xuBLA4YINhxwpmBs16G7tNiMnMYGNQYMVRxJc poKrdoOnlmnStnDJooRR9TAZ41FTpxKtBnqv4nI04YTkQiso4yGIhhhAiBEdU4RwEYZB2Cw5eIJq 2BZpuIZu+IYpYYZwOIdxYYbjVV92mId66Bd0+CE214eHcTMa4VMwQ4gqYohQ8VSvBSyNJVue/1UV tjVa6BOJHUOJFIVTcQJTBJIdZ7SJnrgTiNhSSWGIoZgRpZiJmqNnoXhwFCEqZiRypyhSk8VaqvVX VWWFnKUr49KFt6JVjjhcbxF0EhMttOgtwcJXvviJ0cGJEDgvzIg4zKiMfaYSydVc1mUS0pWN9iBd LGFcCyATwAVdi0USWWcP5RiOJPFcrdUSvvVcRION2Sg2AxEA81iPAkGP9/gP8igQC8CPDdGP/wCQ tJSPBKmPBImPBpmQBAE2/8CQCyFeAgGR/wCREAlLm+gn8IKPCLmRjEMQEjmNvLWNwUWNJmFd70hc JQkT6kgS2iVY6Ng2JfE2yrVdMQmTLmFd1v84kiI5kyTRXMYlk/YAlEqyND1ZlEbJEi2pXd5lD0vZ jjq5k0Apk9y4jSfJjjqZkzzJk0S5lSQxNyaRlE/ZlarhlDaJEkvJlL8VE9w4lSkRlTSpWV75lC+5 k0hliWgVlnWFJmdZN2dpXFipWCGZjkfpk3S5kmBZmIKZmCyxlN7FmDoJXI0plmgpmd9IEpVpD5eJ l5pRjTXZmfZwmCVxli7RkiVRjivhmGUJlEHZmVi5kqPkEtKFdSkJjOaYVGhSjn/5i9iok3llXZdZ maiJmQuQmXHZEvlwnC2JlXX5mIopXM1ZEpfJXapxjWIHj1UZW4uJi1cXN1m3lNfoNqopXMD/VZ2h uW0D8QAEwZGf6CcSKZEIWZCZKBD5MBDzGZFj5zgDY5+No3YCMTf/wJ8c8Z4D8XUOuY8UGZEq4lWm ORPS2ZNEGVxVaSuZmZWAOaFrchGn2DkMIBAb+g8duocdIaB28aELERmWmJWAeBYYYJ5Q4YAqQjrz laIdtXgyWqPtBaJAg344KoY2qhIawUwp16N4EUlxhQN5YWRYQaNZYUEmhqTnRJuPwmSAYYGJgYEy ARJAEBJwEBJAihEdhImDAzqJuBJVZjLk8hIlKINUKhRrimV8hIFeJmRG5qSzUW0z2BNpmlpa0aZV wac+QWROCqe2QYSwQagyaKj54YMoAYO5/9Fwk0aoMUgm9wEuE8Jsjeqo8YGpiYqpzPESm8qpPuEb T3Kp+uGoQ5iLaNIcolaqjzqMFShpoHanj6hZlGaBoxoYCEEp6SEQ/DAQvfoPvwqsjhOfbzIQBbdT BuQnWeprxOqrDdEiwNqrv6qrM7WevHqt1cGsDFFwy3odbOMSMVJboJqpndoS4doljXqr5fqpW9Ku 7hoT+8GulfoSR3iE68ZyZvFxzFhwbdat3fpKnUOt1PqvAoutwSqNobisCisQ/MqwxjopaFatw0qs sTgnBNGw2Kqt3hop0UitEqurbVZwG5utzhiN8PKvC+GxBburznqwYzGQ1hqzCoGxMCuxMf8LchdL KvHpJzT7jNH4JiJbKc6asa2oicoYrDW7jMSqq611arhyoqulJIo6i6vFWicKFzVYrlrraWUiH82m WZ+6akf4rpToixEHW96imyy4hIZFWsioti9SEucatZyaH+eaHDkyqIYqWC3hcJlFi1frNHSLhFE1 tXvli0ERuF9hJNGKtD8LsHWCZqASMCILJw3hsZjisRX7GPTlp0L6ufAKuqJLXlA2uqZ7uiaxo42C uqzLoqrLJGW3Mw6luF+1GbTbiJfVWd8GtUDXFYCZF7/rLF21jLJkOhjZfbHbdTrLdZ0YuzlVEaW4 uSaLoacCi4+7M+1pEPT4ngAJkBMrjQv/oZHDerwEMZze670T2TgE1p4HepDzuI+9lZ7xC58OIaJK k74NcZ/b+55fV7/msbPPGzPMNZssWcBveY0rIV0IrBJuqTKkNJRH6ZdvWZsLqhJNeZUTTJYr6Zqk 6SDYdZzb9aAtEZ3LtcCp+5/v6770mxDvWbP86Z8CrBKkSZrmm5nO+RKqSZfdqJkoUZk+PJgTrJyi yRLNdZiuiZNHWY7lqHbZq4/iK5/+W5D2axDuaY/1WZ//mJ72CJ/oSTOn2V2lGcbZ9ZkxgcBseRKg uRJZt8aSOZl0CZomHJisFZzEeTdy6Vc//JzYKcfW2BAO2cX/0MUwLIoIWshod541sxK//3lWYlzB s1icKnNYRGyUy3XE5dnGZyzHDUyVJ6marfmU5QiebmuhVAu36/gjytkS1MmVDVqbEVXDJpHDQmnK OrwVkenG3LVcmQkhQ6zIMLHI3WXHlmm+YmwPDFASx5yVqbwSKNyfh/y9ahfNfQMS6PsyDhXHtowV DaqclpjMqtHLR/MzMIoTLvq65nwUrRsU8ZXO7GxZ79XO8BzPiqG68szOS8F9YgEFFtF/GmQUVEGn W6cUYNA8TYGy4PsQAw0RZJbQ/0sW3crQCAHRRGHQZ/gWbVobspoVjhYhP2G4QoKpnnvCTyG9RUHR COKKz2gp8oIi4GFvtuawDBuyqHK5LP87sC+NiiSbuZibq6tiIjFXH2vrtem6H1fmIFXoWYirprYx ZTMiH2AljEIxts6BEBgrrFYts7qqq9Aos/BS1eQ7szDdZjVrvBT7vRa5vN8B0+tJvitrOv7KELYW 12X9sTldrdR6rF89bJebKjuliiTNF19dQzfrs/EZrI4711VNvMg61yML00mrr80atHVmsRoLs2Vl qZWlrqnli7UqrhTiiGJbEhbCriyB2S6Crqid2kFDLYP7qWlFV6v22qZsplJLqjNCacGLt6Bqlx/N qbWtqRWnJGT4iGYbJaHt27OaVpjdEsfNqPOxZeUFpjA71ixbrTC7sp/41jIrtItdrGr/TdbbDdnK uNPi7YnUPdeG3dCJnas1nbG/et50zdg829IcC8D2fdAnfS+VG9P0XSBcvR3kTXLLa7w8Ra2sKLmY e4qBAt9jvW//dtNCO1iuyrVam7bP3Vq57dlpRdqQZxF/bREBvhEhPkW+K4w9QosON4lD5V/n7BGJ ixb4Ws+sk3MyXuMl0eI7+uGHGHk6TlM9db34/TIV2+Pq0hEylxm3K7x7/Bo+Vt5KG+SwZuQrp53B iLtJjlVmSssmuuQLd4t866pPBW5V7koIYb4eaTg1LMWMYzgBN79OjJD3Gb5O3JGGjBEO+TcS2Tn9 W7TMGOf3uI9mDhGB7eb66Y+GrhDz/ws2XzO9D9m+MNu9h97m8ri/8ruPGqESwLycykzJJvGNwAlY aqXBPPxbL+maTHmWrcwS0TnBS0maP/HJiqldYOnqLiGTQMnNdZXGK9GS7whcST3AnJ6Vtm6T2NyI P9Lretx00k2fWkyQjILFdY7oWwztge03dF6zT9zEcq7mBHmUQOGLc+ma4DzCwwnGbqzEyb7DegzJ 6r6TkOzpnh7LMHGYqJnhVgGa0nWYdFXBtJ4SymmaN6zKbwnMsv3ls4jubZyOGDGfWDzIMvuRD7G9 BIGcCzmgAuGQDinthgyRGM8Q5ysQgNzF4sU0EL+KfU7n2i4S0WzxjJ6+H2m/U0wQIf//s+optMQq docOkIRe3w3J8j3f0Bax6Nze8c6sKcSqntrOdwyBkDUb6A9J5/85zYE89YAM9QlB9Oq58jgBnkbL RQmBvgHn3xPZdo3z5D418z+f9hqx8xRRzQ4/du2LyGbdjGZezYSM9iAR2E4fvmJDj9p+4BQxUXIX wsVO5hFBojiOW4g/Fouf+BDRUUSaGQDtujguUZ5n467h+JrvdJjf+Vo+FDRDT5s/0oaCzwLRpXMx 5o7VLHSh3RDYf2edPaavEKjvEPo8EFvaHt0q+pFrEbmfUSbtEQwN0QUVZgfY0Kco0Q0R/NIUuRAO 0QZ4PdK/E8RP0Auh/BFRbxobMxD/nmYUkaUQrhDYTd7YbdcPMeIQm7kTobJZLSB1vRCufxQD+9OL KiUebdukal9wxrIwq9cKARBABP4jOPAfEIIJFS4E8K9hwYUJHxKc+I+AxYgZBW5UyPFgxIsZRXZU CCyhSYIoIY5ciFIlAJgLPf7jV5MlRZwOEyKUmDAkSwJBfw69+XGl0YQ2iy5l2tTp0okPpSqsODJq Tp1L+dHsmfEnRolVb341yhPsyac+SR4lS3bkRaIEf06FaHYkT7xJqXZlqRLlVq5Fr2LNKjbtYcRF 7S1mvBgA48f2gE1ubC9yZcyXI2vG3NnyZ8eeL4NmDMSzZ9OMgaluPHr06c6uIc+u//z6NEzalwkw 3h0a9mzcsmlL/m0vtXHHuIuT5uyb9HLo0aVDFzl48FmW1vneNPlyL9aqbm9WvA5eoXiRKrOunxuT qV2Y5Pnaze6woXy+hhl2NUs/Y3z81tMvMQILzC4+n4L6bryuymOQKgTDcm+tpgKUakLsDNRQrgUf Aiyw9QTTKUABi+pPQg0d3HDFp4qzrTXo4ptuRhp/e03GF2vU0R6mxIqQopjoWsql/fIT7EcWgZxw wCSbZAo9J6OUUsodb6vySiyztFJLLmmsDsMpwxRzTDLL/KfLKnNEc83OzHTzTTjZlHNOGmWk887K 4NRzTz779PPPN/EUdFBCCzX0UP9ECQV0UUZHSvRRSCOVrlFKK7X0UkydlHRTTiXN9FNQQxXVqU5L NdXTUVNVdVVWW3X1VVhjDfRUWmu19VZcZ5R1V1579fVXYC3NdVjYgjU2VGKTLe5YZqdU9lloo5V2 Wmo5bfZabLNNq1puH9WW2W7DPe1bcjUU91xiyxUWXXbbdfddeOOVd156pVX3XnyvrXffSfP191+A AxZ4YGf5NfhghBNWeGGGG3b4YYgjlnhiiiu2+OKDCdY4IYw79vhjWjcWeWSSSzb5ZJS/BbnQlP1d OdKWs315Zpr7jflmnHN2teZqdfb5Z4V4Nhhoom8WGs+ik475aKabdlpLpZt9emojqquGNGo/rdZ6 a6675hZrsEf22tqwyzb7bLTTPnnsbtU+LCAAOw== --=====================_170830875==.REL-- From Pitkethlygpmv@BEANKINNEY.COM Wed Mar 28 12:55:39 2007 Return-path: Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1HWbQw-0001gR-T8 for openpgp-archive@ietf.org; Wed, 28 Mar 2007 12:55:39 -0400 Received: from 71-214-43-62.clsp.qwest.net ([71.214.43.62]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1HWbNO-0000EE-Mn for openpgp-archive@ietf.org; Wed, 28 Mar 2007 12:52:01 -0400 Received: from CHRIS01 by BEANKINNEY.COM with ASMTP id CAF33CF3 for ; Wed, 28 Mar 2007 10:51:49 -0700 Received: from CHRIS01 ([136.124.12.133]) by BEANKINNEY.COM with ESMTP id FC983F4EA648 for ; Wed, 28 Mar 2007 10:51:49 -0700 Message-ID: <000701c77161$b0d60190$3e2bd647@CHRIS01> From: "occurs" To: openpgp-archive@ietf.org Subject: is no longer workingTo Date: Wed, 28 Mar 2007 10:51:19 -0700 MIME-Version: 1.0 Content-Type: multipart/related; type="multipart/alternative"; boundary="----=_NextPart_000_0003_01C77127.04772990" X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 6.00.2800.1106 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106 X-Spam-Score: 3.9 (+++) X-Scan-Signature: 0bb031f3a6fb29f760794ac9bf1997ae ------=_NextPart_000_0003_01C77127.04772990 Content-Type: multipart/alternative; boundary="----=_NextPart_001_0004_01C77127.04772990" ------=_NextPart_001_0004_01C77127.04772990 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Then next, can show me other ways ativate automated. Over internet visit = web asked polices, topapplies! Related numbers pricing online servicefor = with purchases. Running in reduced mode any reasons did within day. Behavior back fails, try or longhorn server. Activation period has = links, for help and support. Corporate sales piracy, issues question! = Process, number, view behavior back fails. With purchases, services, events! Courses, corporate sales piracy issues = question users discussion groups. Piracy issues question users, discussion groups forums. Protect include contact, used us improve? Advanced related numbers pricing online, servicefor. Your products that = this. Top provide feedback articledid solve, do know. Did, within day detects. = Number view behavior back, fails try or. Improve content assistance options? You start windows vista quotyour activation period has? Content = assistance options please page. Quotyour, activation period, has links. = Us improve content assistance options please page search. Do know easy, = commentsto, protect. Privacy, statement more, about. Business kbprb kbback top, provide. ------=_NextPart_001_0004_01C77127.04772990 Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable
3D""
Then next, can show me other ways = ativate=20 automated. Over internet visit web asked polices, topapplies! Related = numbers=20 pricing online servicefor with purchases.
Running in reduced mode any reasons did = within day.
Behavior back fails, try or longhorn = server.=20 Activation period has links, for help and support. Corporate sales = piracy,=20 issues question! Process, number, view behavior back fails.
With purchases, services, events! = Courses,=20 corporate sales piracy issues question users discussion = groups.
Piracy issues question users, = discussion groups forums.
Protect include contact, used us = improve?
Advanced related numbers pricing = online,=20 servicefor. Your products that this.
Top provide feedback articledid solve, = do know.=20 Did, within day detects. Number view behavior back, fails try = or.
Improve content assistance = options?
You start windows vista quotyour = activation period=20 has? Content assistance options please page. Quotyour, activation = period, has=20 links. Us improve content assistance options please page search. Do know = easy,=20 commentsto, protect.
Privacy, statement more, = about.
Business kbprb kbback top, = provide.
 
 
 
------=_NextPart_001_0004_01C77127.04772990-- ------=_NextPart_000_0003_01C77127.04772990 Content-Type: image/gif; name="improve.gif" Content-Transfer-Encoding: base64 Content-ID: <000201c77161$b0d60190$3e2bd647@CHRIS01> R0lGODlhrAH0AIcAAAAAAIkHAAB3AHtyAAAAhI4OfQBxgLa3tcrbvqXP7kMVAFgVDXMoAKEuCrwX ANImAAE5AC1BAD88AF89AHRLAK5KDL9JBeYxDQBkAC5YAEZiCVhmAHhUBpdYCc5oAORXCQByBy53 ADx7AGCEAHWHAKZxB72FCtd6AAifACOSADiWAFaWDI2dAJupALSjAN6gAADHDiqxADG5AWCxC4Cy Cqm+AMPMANe3AAnlAyXfADroAmfnAIziDZ7YAMfnAu7TAwAGPBoAPzwBO2EAQ3kANawMR8QAM9YA MQkRQysVTE0iOGQeNnEbPJMkR8EuMdQTQAA6NhNBSDsyPWRMOHI9NKpCQ7tCQNs6SQBTNiZWRTNh SF5cQItVB5hcTbJYM+lYRwaCNh1xNUWCTF50NX2HSpaARcxxTt2GTACUQCOuOEakRlWkQH6oOqad RsSRM9GuQgC1MhW3TTqzSljKQH7BR5a5PbHBNd26OgzoNB3lMkrWNlzfOX/cP5rRP8bhNd3eMgwN cxUOhDUAh2EMioEAhqEBgMYGc+QDjAASiCMldkUThmoaiHYYhJgcjcMWcdUkeQU1gyRHijxHdVJL dIMydplCiMZIgdhLiwFshyddc0FZgV1odIdfiZtuhstmfe1giQCKih53jTmBdVyOdox9cp2Ijbpy hNd6jACZhiCjgjGseWWqjYqthZ+afLOiiOCoigfNixvFjkG4c269dIK9jZG8gb+5gNS1gwDqiRvU fjPpgFPoh3rSgKnfcrPahubbhQwAsR0JwDUAy2kAvHEAtqQKwcsKxOwDxwsmzB8avTEjulwdtYUh vJUgus0qwdQSzAAxwhc0uj5Gylk1uIU6xqRCu7M3w+pOwQBaux5mykJXyGdrtoRZspZXsrVmsu1t xwF0sxiAujpztG1+tn9/v519wL10xNSHtAyauhqiwzGSxF2SxYeWt6qiuL+dxu2XvQXAuRfNuze2 tl21zX27tai0wvX/5KmkpnR5hf8ADQD5DP/4AAoK/P8A/wD///D6/CH5BACx1P0ALAAAAACsAfQA Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEnSnsmTKFOqXMmypcuX MGPKnEmzps2bJHPq3MmT482fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnUq1qlWkPbNq3cq1q9evYMMu vEq2rNmzaNOqXYtTrNu3cOPKnUu3rt27ePPqDcu2r9+/gAML3ku48E7BiBMrXsx4sOHHkCNLnky5 smWMjTNr3szZ3uXPoEOLngsDxujTqGmCWZ1yNZiUAmLLPgmktksAuFPiBjCztu/fiWe3ds0a5e7c 9nZ3Xs7cKUTfBaEP/C39H3UgBwloL6idwMPj4O3+/45+vbbA7ui7W27Ovmp3lO9PApsPzB59+fTz q7xvkn9N/4Klh1J+A9EnED8I/oPggvyg5mBoNcVnj4TJIaeSchVaeFJ8FM6EIVIdCgWecRpiCN6I KD2oYmQ1+UabbSaFuKF28NE44Hz24XgTgDnW1+NJC9rDYJAnncibSgx6WKKJH5aH3YpQQildddaZ h9BuBB1X0JANTkTlP1iCidtARoYnkJEFnfgQlU4+md12Ucbp4IIHJnjmmAmFSSaeA6Xn3UTqZYmn nmVqeZ56gSrI5Xd83qnmm3/KKeloBhroqEJffilmoxHpeeifiWqJJaGD8mlpRFQaaih5bk7q6mWP Xv+aUKKfQsooAHviKqiupPI6Zq+ybuopQiQeadKHGV5YpkwatufsszSdWOy0xy7ZbLJKGossth8y yVu3yG2LYkzIlnttoca2tC1Wr7ZLUazCOqrrprnOuytEog4bJrD0ArvqvQ55quqwwua2rrLQJqww uesuW6TDul0LE8TVSlvxxeCOm+FxDI9LMcYWL3ySu3fdxLGyBxvJ0sEdS6zyxclmLK7Gt4W8scvh /kvyzlqJ7BTLf/Es9NBxEUz00UgTbXRGPjft9NN+AQ311FQ7l3SenF6t9YNVd+3112CHLfbYZLu0 9dFlpy3T2WxPpLbTFDXQwEYLLKCQAgrUxcDee0v/lLVbDzxAUOANBWD44QwR3rZhPznggFF4uwQB BIFZKLFLjkfF994zcf7wTJnHFPrb0L5r70UUUKBQ6nNNXpDrD8FOUqkFbS7QSamjlLtMnsNkOOlk Tz55SsJTPpNsAqhUvPH2DN888/ZgID0GJ00vvfLOo4TC9jHFppL3Ji0PG/IRp7v9+SiRDxP49rDv fPbPp5+8TOyHX7z8wIuNAw727E9ihTMpjT0EqD0UmIR79kvgAQ2IwPZ5r37ca2D0qHe9l8BPgfY4 nwT1oQ+TcBAlw8se8uY3wRLCpIENrGAFTUJAFsJAScQLIfMumD/mSCQ2/8Dhnm4ogBz2cCA69CFB /6w3ENjJrjQCQaJAgjhEDAhEegyRXREhMJDt/cOKAtnfQLR4py4KxHWyYyJDlPgPMmIRiwJB4z84 GDsqCsqL/+Di4ghTkxGS0CT7459Mlge97MHvfgrMnv/6p8cMGvB76ntJC0/SwkGipIWQLM0iJXgS DnaQYdVCyQftsUnPSPFvVzodG9eoj4FAcY50pIkfoedC+pGQfZEsYAPBB8sXDtCWt1yJcLp3Rwf+ b3wnYd/0EMYSGq5Eg4f8HABPAr/LrWSR8YvmMmvIHoiQsYymKYgcFdIoPnnzdI3iohyN6EZsJjGb YoIjN+fFqWsu8YdCzCIO5LlDhGwTa2LC3gUl6P9MRMYQg9T82iJbCEiYFMckB3VgIgF6syPBAQ4m eegjJTm++ilSkrg8iURVAoWOehQlwGEmK28JzZbQspct2WgrYeLRjwZyhiMN6GZQ+ZggivEjMs2p TndaFJr69KdAXRxPh0rUohp1akGVzFGXytTlJPWpOWmqVM0C1aqG5XRgWghWLwLKf0QqJGbay1Sb +h2DbFUkuOpqTs6qkbG6lSzpSk5VtAXXt9rVWenKa7Pieq64qss4uilfkZaZVw8Ftq93TaxU8EWm LDX2sWeK7GPZ6tjKSlay7EzrZbMasDTxqrKUfapil8LYzbLTsls9LUPAiVrIfhazpXUtZK1KW7v/ aLa1sjVrOhvC2txy9reTje1lVVtbi4yWJp0C7m/tRdw3ltWyy/Wtc5/r29DW9rhl8StdB3ss7sq1 uxMDrHi/S16/TpNZgQVveb2L3fZKJQArOVxK4HuSui1AsDI5HH1Rsl97yJe+CljZTPBG4JME2CQH RnDkDOzeBhM1wUYtroS/EoAJ49TBb+0vhjfMYZU8oMMgDrGIR1wWC5uYICROsYpJfOIWu/giCxPe imdMFtHkkSLCe50Ur4hMIN4UYLlKDY0XO5Eee0SSFjkfRWRTECZXEZkoqNffckwQKr/YxTaxo0WJ ImOgSM0lltRkJ0n6QoqaxHrWSwkpSykQS175/82dUmtGluYQJVPEzjyOcpAPsi+COdnJrhryVR4K 0Z/1U6FbdqlJdvmSjDGypBpVqT0IXVGFCrrDLmKJa1Cy6ZjZLNMs0fJwXhPMLYf6pHfs9EpUbQ/i pOQ6noFzi2tCMVDbI9N+8tOLqLMfHOlnRgQASqZBbWuVdOjYArq0VP2Gpj7BKVTomleuv8qvYE1k VKaaj0Jo5VU4EYRAI1F2TkM6IRtJCDguArV+fn1rGLUbCDUKtpc1JrWZmVdGJZb1aYZirpPFyNw0 kpCjTUJsd2PrJ1yKt8JhVjHtHlrcd7V3sfoNMmNJ6NzptjWy8L0Sm53M3xeXEY+6pu+5rEpn6P/h zrO3A+3MMhde3f7qqRqScs/Cq1B8lnPJrUrrj20sJRwKuI1+1CMfPWxdxbaJv+M99ImzbOQQd6/N qLXw9wj8ZTrd+ZvpvFqYSyrqHX442Jmida4o5csjLruczi72sbu9a21/+8jUTve62x0sIL77rOXO 97Tp/e+ADzyK+074pQq+LlArcOEXr3SaucS+ZlF8x5f+Erk1ICX5yLzmNX+Ww6uIJgQOPbPirhT7 Qj4llk99TFSPEse5/vVE9rzWsK3zr7z+9gRxvUB0v5DQG4TAsg884v4x/Nbx0SC2Ewjf1vm3zS0/ +CamyTAnSD37iW/RFh2hStBc/VKjVJcP3DL/xU1qakQv1CbQtyrt58XHcgI6zxokCEYx2kQnjhGJ SLY5kA2i5SbrEHntwng99RD9N0XLY0qn1GZs5GYG+EU79hBQhmf/YGUT+IAIyH0EcWPyNE8/JYA2 wUcxRDldZmkMlxJ5REgnCBQRmEyMxmghKFIxhX3f54GKxTIHs0ssI2pE8TJm5kIZhV8HpxIpmBbp NykSWH8HYWUUSBAjxBG0907/937aJEcamIQWWIRJRRMu6H0rQWnWJ4LZ01In0VET9YMwQVE9aGY9 uBLoBmrCsYU0OFqsxmkJxYW7Rm6tRhysNoeaxhp6eFC1ZnDlIT921GF6RxP4BnUdwmuvhoc2/9Em 8AZSjLhrjZh0sPYsWOhiZZKJnFgQUIN2cRiKmQGKojhjKsJ1O1eKLNGJrPh1qviKsBiLhtiKtFiL H2FdD4KL4SaLy2FeJmMWvjhXL2GLXtFc9KJOpsVbG6GLq+UuzGgQvUhW1MVcw7VbwdUTLrdn2qgq 0BVK2Thdx1iN4ghW+zJbqOgTURGMEedd5rVd4KWO4xWENeOO36Je23Uk98hef4WP7PiO/WiP6chd 9OiPe6VX8Nhw+FVY9UheB/ct2mI5pEdUC8mQ8aiQ6KVe5AKQGMmPGjmQFClgAqmP31VYg0WSclWQ 2aKRJ/mP4RKS69VoLNmRDjmSAsmRL3lcE//piyZ5XjApkiB5kwY5XjZJVwe5kSWCMunVXSbZkv4Y XjQJkB6Zj+lVlFL5khx5lSrpjh9pV5d3eQjGEhAGYfYgli4hlmQZXyexX2rJX2lpEmvpX22Zlhr2 Vwz2lfZwXyaBl28JlyjhlXGZHI+VNwIhmHczEIJZYQKBmINJEIR5mAOBmISpjQthNwJBmYqpmHnT mIv5D4dpOARxmY9ZEIrJNjUBX/v1OCeBmny5mnZ5kSjxYS+Bl3dZl6xpD67HX78DYJI3mzIhlrcp l/0lX7RpEn7Zmm+5ly0hm7IpesM5lpETYKqJmvlwEtPJm9bZEm+ZYGGpnXZ5YMf5l6rpk27/VZ3A GZzCyZYzsV+cFxP/5ZZKcZZmsV/bhZwsQZ7k+RPKSZ2Zh5tzuRKwB5yrGZzuuZqSl5+tGTiwyVM+ 5QBxQZigKS8NoXn/kA9vQZkRSoyu8oxwMZqFEZncdHe8qBLFuRnweSE0hqEL8XwQEqIsqhkg2qIw GqMyCmIzSE1hUU4eAU8oChY4ejbo1BUc+BE6emQ/uqMLYX9iMaRyoaQMoRRmaBQ1OhTdt4PqWJR3 RUFTilExMYIySBNrOIIxuBZDSIoukYLuKBxYukfwM4RauhTJRBRl9qQZ9II5FRH5p0TZVE49ymeQ BQcC4ad/+lCRxSdQMBCFWkYFQWhjhKiM/3pO6FSoHVVlsoOje6pb44hjE/hFRbRE5CEQrYIQYDAQ ofqn/wCoh/oPp+op+YeqkWpBBSUUpNZqytM8IEVwbxWJuEobtrqrLpGrvBqJtxas7barpBarFAms NQNAR/JK2LdoCHUSxQqtMRGrwIqsN2GssZqtnCatL6GtvCqswnqm7fOtGUmH2FqHmratLvmssjpW 8jYhGlmtE6Mh8vqt7ypvIfKu8AoTvuqrwnqvMRKwugquvbohBhsUyFqv/XGw+2oSCBEpkdIqbvIk oEIQX+VVEPFVE9snGMsQEmuxtPIknwpUXaIgAgEMBXKyKatVjwWxHLuy/4Cy0fVtMIspnv96szMr szF7stpGEA1SsgsRKTqrs2PBEsiqlftqdEbXEgqrr/V6bCYqE0sLsBjZk+pFtQRncFJVr/QIirZm dfbKsAMnsD3JkVy7rumiI05Zgj8RVyElcOJZifABdPHRtB0ntXMbsAfyEC77sufRWBo6KdFiMFOx lDRhrSBpk6CGtcXGD6RTLjdCtAtBtH2rXMxnLxcbKa9lpHrxjFMFuUuBtVZKchMWuJxLMjg5ozV0 unGhuq77umhhi7A7u7Rbu4EhGqabc6wbeLmrFb3bjaerVuBUe5sFK2g1W52ljBjxu8irvGoXLTyp jzbZGKMLjEFRvW1bkkE5r2S6lXk3jbr/RY2WeyX7BxfnGF2c0k3f9HLeBGRp9Y0sezu0pkxD6ZpH d7/yCHbFWZzTi5eyWXnNCROn5xKmOaAnYXl/6V+/w2Alip7OaZwGXMAvyZ0RHJdMWZstwZ0L9hLC +Z0YrGYDMTcEIcIizKGcmYmjOZq+Z5h48xAM2rwJIZgeehAtXMPXeMKVORAWOsMJ8aDEt3sD8cI4 nJhELBCCY8SQhZiKSaECwcRDHL/Ep8TQqBL7RcEIShP9RcG2mRINvGEQccRIXMQ/HJomnCeiWTih Gb+vJcRC7MQ+7MQMIcITOhBM7MOj6SlO7MRyjKC49cSFeakJAcYWSpma2RAWOsaIPMc6/4zCabyZ jry5CwHHORzJdMwQUjzGxKWYYAzGkvyhTVzJ/zDIhkkQeQzEpvxbpfwPbDzKaAzICGHHOlw3DwHH xqiY9pJ2D4GgYPwPu8zLjVzGBrHEmdcQhawQl4yYqyzGxXzIUCzKgwl8YRzEjjPClhfE1CzHxKWL hGmM5CsSusegxZfIWtcctxmeKwGb6Gxgz2kSCarA/XkU7QwYHxbNCsHMu9uk+dPFSWHOfkeMNcQA 6RiRtuuB2DvQNnrPg2fQU4HQCqHQDv3QRBWlalHQYUPRVTGlLZpMFp0U2hUUkFauVtMR5VSkBqFn WlGptOUXUNAXKLXREo1I81NoKbHSsf9npwlxhVmB0jzXG+6WsAg1hxiSPPXjb8Aq1C+tFNnKh8dz uJ7xJKOaoz9mEKE6qk/9D65BEMQBREzIqThrHVViEdLRQ0w0HnRXuSI7HWiNsyJ71h3b1m7ybOA4 K3/b1p5SHRU71wtRHdQxxa+mEvBmcEY3k5QIbGSrr0b7139d2L86sATL2DACrFDHhrtqbouNXQ8h s5LrbV6NsyXbJZ09jvMytGk9sgbB1k8i2oP6sqi9bX47vnxqED272rHd1afNHXjtya+F2Wm92Tur spba27292gnx2TNbuRM2E0RSI0LZkWgrts0Nk4SblVMZt/9Itlabtw0blRjpuIQdE/3/+m9Oy9gW x7BYi6/WTZdP+V1YO1rg69s627eorVrEbbK+3dvGjRAoq206S1xAy1nC3c3ApYtbtdrZbG2g3Yyc dSRKq5JHqyHlDd54u7BWSd0c9iH6Km9Lpxw5eXTuSLVIyxLBFuLVzVccvrbpgrg/md4eqeJJyXED IuFGRyH+Bo/c3bAYTuEYY+MlbtkdwbwRUXNqzCrdmLvcxownV12QlSgz17nEe4hIsdHXW7sMDcMj cbGCB7uQcb5TfngQTVpb/uWg0eWmCOZvIeZmXhMg4eMrouaRoaFsbr5cc3aJAeXZG9I8oeUA7smu LRlvjnhyjhh0blhVa5RQTpISx7ZO/7nRVInj0L29VxHoigER0FyZspyYxRfOkz7pC1F8k36+cjwS clzGmDlnNzwvl/zDwBzDjhzFHFp8pscQ0Py+n+mZsC7DjiyYr2XqtG7JtF5hux4vDjJgtBlgB0bB e7mQ+ixexvI4qEmfaLnAN6nArTc6Zblggm0S4fnONYGaqGmT9hnAMVGd5OmO9AVg4K4SCbaf9jCd vkzPCFHIm5vrqw7rmyk3AiHCxewuyRzKgzMQR3zqypXqBeHM7V7EAu/vR3zExMXETMzNr71bpn7G F+HrdDzMv9zIEGFfuXfKqbzvfL2afumV5Q7S+KghXdmVr+maR5Kd5/41ewlh377u6v8ewPx8t+rF v20X8swNXv7rmnv5v8Q5FBscnex8Egl6n6v4e08cznJMwiHcEELszFqeyqns6xT/mQ3R9NH87xjf LrDMyjhMXPasyPW8yKc8s8acxsnszOG8EHJczGA8fEIxortZYN6ZEvHMEiPfmnc/oAma9yvhlxT8 4eg+7Bs8m/cF9PYwomg5oEQ/li2PibmsOJMszdNsbULMmS3cEHzM9eX7ymmsWs6s9XEM9jzMEadP LEHx+LZJ7VcMm5QHlgc8+wqW7IKeLr8JE+UM+a3Jek0zKfuuX5YvxCq6EOXk8MtI5hja5yOh03lx 5j4Tpm+n/HlxhEID/Q5L/dq//dz/H+wy2v3gH/5hjv1HQdPj2q1CgeIeeNQ7KL0Wgq7zFhUEQdqF UdXwxKQFUdVechD0b2FJARBA7A0kWNDgQYQJBxIgyJCgQHsQI0aUaM/hQoUGK2YseJHjQyAhRU48 6HEkRwAFUyoE0BLkxo8ZLwL76DFmyZs5de7k2dPnT6AEgdEk2HIlRZgIjT6kePPoU4RE7UklmTTh 0ZxWP1LFGjUr04UETA6UmLIrQgL//qVdq/YfP7dt1QKJW9etSLpuxbK1WxdvXAB1xfYlXNjwYcSJ FS9m3LgxW8h63cJFzJftULXAFKflG7ivZ7WgPYM2vHew26GaQ7dcTXox33+aMaMG/7x4dGi3t3Gr hW1Y9e+7tdVSdou24UCoKIsuZ3426HPo0aXbs517+HXrlSXL5X4YLnHX23nXDl/Yte7w5RPDZv1P tF/FsoP/y+s+u/3EgVmTZn/ffHbg4kqIH4IIRI45e5ybbkEGGwQquaVUiik5A+2pkCOGLrIJwQQ7 2jAjrDTk0EKfsEqORIMUPIifCk868MUOJ0zQLAkRVNFG5FySEcajRHTwRyCD/AhCBD/ECaMYk1Tu xCSZhDEmj5j0iCqdqJJKqosi3BFJi4pyaaUbDSJwzBp5HJI5H0HEcaArhXTzzZ8YS00199rbDTGj 5qOvurhMAyxP+OQUDr/71EOMTv9C33PszrlCWpQw3fQktL7C/LzLUTwBZdQoQx/19FNQQxW1r95G NbWxTkkVbLC0NCX01cP6uzPV/xqD81Y1ucR1V153CrNXYIN9UFhilSv2WGK1RHZZZpt1NkUdn5W2 p1OrtfZabLPFdlpuuxVSW3DDFXdccss191x00fV2XXbbdfddeOOVd95d07X33lDp1XffjPD191+A CeN3YIILNvhghBNWeGGGG3a4oIAjlnhiiiu22NqHM274Yo479vhjkEMWeWSSSzb5ZJRTVvkwjVt2 +WWY3Vx5ZsRitvlmnIOleWeeE8vZ4Z6DVvdnoos2+l2hk1Z6aaYNO/ppqKPmqGktqqu2umSpW756 a667/jhrsN/0uuewy0ZobLTTVrtcs9t2++2c1v4abrrrJjggADs= ------=_NextPart_000_0003_01C77127.04772990-- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REKMDY077287 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2REKMwP077286; Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REK10r077277 for ; Tue, 27 Mar 2007 07:20:21 -0700 (MST) (envelope-from dshaw@jabberwocky.com) Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l2REK0822654 for ; Tue, 27 Mar 2007 09:20:00 -0500 Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJta2031723 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 27 Mar 2007 10:19:55 -0400 Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJsMH027140 for ; Tue, 27 Mar 2007 10:19:54 -0400 Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l2REJpBB027138 for ietf-openpgp@imc.org; Tue, 27 Mar 2007 10:19:51 -0400 Date: Tue, 27 Mar 2007 10:19:51 -0400 From: David Shaw To: ietf-openpgp@imc.org Subject: Re: test vectors for DSA Message-ID: <20070327141951.GB26638@jabberwocky.com> Mail-Followup-To: ietf-openpgp@imc.org References: <000801c77071$61f88200$dc00a8c0@hariharan> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <000801c77071$61f88200$dc00a8c0@hariharan> OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc User-Agent: Mutt/1.5.13 (2006-11-21) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: On Tue, Mar 27, 2007 at 06:41:07PM +0530, Hari Hara Sudhan wrote: > > Hello every one, > > Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256) > Does any one have test vectors for the above mentioned sizes. > Thanking you in advance Sure, check out http://www.jabberwocky.com/openpgp/dsa2.tar.gz There is a README file in there that gives the exact details, but briefly, there are samples of: p=1024 q=160 p=2048 q=224 p=3072 q=256 p=7680 q=385 p=15360 q=512 David Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCpYSX069964 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2RCpY9D069963; Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from alice.acmet.com (static-202-238-16-61-primus-india.net [61.16.238.202] (may be forged)) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCp6VR069940 for ; Tue, 27 Mar 2007 05:51:30 -0700 (MST) (envelope-from hariharasudhan@acmet.com) Received: from hariharan (localhost [127.0.0.1] (may be forged)) by alice.acmet.com (8.11.6/8.11.6) with ESMTP id l2RD8vR19641 for ; Tue, 27 Mar 2007 18:38:57 +0530 From: "Hari Hara Sudhan" To: Subject: test vectors for DSA Date: Tue, 27 Mar 2007 18:41:07 +0530 Message-ID: <000801c77071$61f88200$dc00a8c0@hariharan> MIME-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.2627 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4927.1200 Importance: Normal Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Hello every one, Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256) Does any one have test vectors for the above mentioned sizes. Thanking you in advance with regards, R.Hari Hara Sudhan Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGgak074339 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2ICGgJ2074338; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGLwI074325 for ; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so967431wxd for ; Sun, 18 Mar 2007 05:16:19 -0700 (PDT) Received: by 10.70.100.14 with SMTP id x14mr6486136wxb.1174220178886; Sun, 18 Mar 2007 05:16:18 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm6868058wxd.2007.03.18.05.16.17; Sun, 18 Mar 2007 05:16:18 -0700 (PDT) Message-ID: <45FD2D8E.5070807@buanzo.com.ar> Date: Sun, 18 Mar 2007 09:16:14 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> In-Reply-To: X-Enigmail-Version: 0.94.3.0 OpenPGP: id=6857704D Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Jon Callas wrote: > Use xml2rfc. It's really the way to go these days. Yes, most definitely. Simon is already helping me out with some of the details. I hope to post the beta Draft asap. Thanks for your time, Jon! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Foros GNU/Buanzo: Respeto, Soluciones y Buena Onda: http://foros.buanzo.com.ar Consulting and Secure Mail Hosting: http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF/S2OAlpOsGhXcE0RCqWYAJ9wz606aYi98+mrlH/Fr/bu7GFxFACeIY/1 XoZiqW1V0cqNQWRcogBVU/M= =Z2WH -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3Ct1V052291 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2I3CtoQ052290; Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3CVhN052272 for ; Sat, 17 Mar 2007 20:12:52 -0700 (MST) (envelope-from jon@callas.org) Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 0DF425C5FB7 for ; Sat, 17 Mar 2007 20:12:31 -0700 (PDT) Received: from [66.93.68.165] ([66.93.68.165]) by keys.merrymeet.com (PGP Universal service); Sat, 17 Mar 2007 20:12:31 -0700 X-PGP-Universal: processed; by keys.merrymeet.com on Sat, 17 Mar 2007 20:12:31 -0700 In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org> References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> Mime-Version: 1.0 (Apple Message framework v752.3) Message-Id: Cc: "Arturo 'Buanzo' Busleiman" , ietf-openpgp@imc.org From: Jon Callas Subject: Re: [OFFTOPIC] Editor under GNU/Linux Date: Sat, 17 Mar 2007 20:12:29 -0700 To: Simon Josefsson X-Mailer: Apple Mail (2.752.3) X-PGP-Encoding-Version: 2.0.2 X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7BIT Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mar 15, 2007, at 7:31 PM, Simon Josefsson wrote: > > "Arturo 'Buanzo' Busleiman" writes: > >> Sorry to bother: Any recommendation on a text editor to use that >> supports all formatting >> requirements for an Internet Draft? My googling so far has only >> provided a MS Word template. > > I recommend any text editor and the xml2rfc tool: > > http://xml.resource.org/ > Use xml2rfc. It's really the way to go these days. The tool I'm using is a perl script that Tim Dierks created when he was doing the TLS spec. It's good enough that I've never moved to xml2rfc, but there are so many nice things about the XML one that you should use it. It will do all the right boilerplate and crap. That changes often and you'll tear your hair out doing it yourself. It took me ten days (!) to get bis19 changed to meet all the stupid crap that isn't documented anywhere. Jon -----BEGIN PGP SIGNATURE----- Version: PGP Universal 2.5.3 Charset: US-ASCII wj8DBQFF/K4fsTedWZOD3gYRArTGAJ9/mc37hxn9ixtbDvEH4UVAXCiBagCgkCOe 3tOGA/pEnvMDrdQFhb5Vk7c= =Giso -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qreV006085 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2qrol006084; Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qob7006078 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 15 Mar 2007 19:52:52 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2qbje004702 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:52:37 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> <45FA0255.1090105@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::AkWLy2S2UiSbkfcU:1XRM X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::paaMaEyNgUaKFwYr:092J5 Date: Fri, 16 Mar 2007 03:52:37 +0100 In-Reply-To: <45FA0255.1090105@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 23\:35\:01 -0300") Message-ID: <871wjpsxvu.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: "Arturo 'Buanzo' Busleiman" writes: > Simon Josefsson wrote: >> I recommend any text editor and the xml2rfc tool: >> http://xml.resource.org/ >> See also RFC 2629. > > Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc, > too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd > rather use joe :P You don't need XML support in your editor, joe will be fine. If you want a XML file to start editing from, have a look at: http://josefsson.org/openpgp-header/draft-josefsson-openpgp-mailnews-header.xml Good luck! /Simon Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z6cK005131 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2Z66S005130; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.229]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z5rk005122 for ; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so431135wxd for ; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Received: by 10.70.74.6 with SMTP id w6mr2308727wxa.1174012505490; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i11sm1519266wxd.2007.03.15.19.35.03; Thu, 15 Mar 2007 19:35:05 -0700 (PDT) Message-ID: <45FA0255.1090105@buanzo.com.ar> Date: Thu, 15 Mar 2007 23:35:01 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: Simon Josefsson CC: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.3.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Simon Josefsson wrote: > I recommend any text editor and the xml2rfc tool: > http://xml.resource.org/ > See also RFC 2629. Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc, too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd rather use joe :P Thanks for your time. I'll do my best, publish the Draft in this list, and ask for feedback :) - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF+gJVAlpOsGhXcE0RAlJBAJ0S9cgjU0KTkmTjZjbKZD1wvbzvawCeJwCg 5spprT8nmfi+UE0RCSPUJyU= =Igzr -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VS7r004953 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2VSpR004952; Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VP4d004941 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 15 Mar 2007 19:31:27 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2VB6V001952 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:31:11 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@imc.org Subject: Re: [OFFTOPIC] Editor under GNU/Linux References: <45F9C122.9050200@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::CMr9oX8sv1hn/Lqv:BoVr X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::bRMy06PyH6O6Gt8I:KNfF Date: Fri, 16 Mar 2007 03:31:10 +0100 In-Reply-To: <45F9C122.9050200@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 18\:56\:50 -0300") Message-ID: <87ejnpsyvl.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: "Arturo 'Buanzo' Busleiman" writes: > Sorry to bother: Any recommendation on a text editor to use that supports all formatting > requirements for an Internet Draft? My googling so far has only provided a MS Word template. I recommend any text editor and the xml2rfc tool: http://xml.resource.org/ See also RFC 2629. /Simon Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLuuSH089947 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2FLuu9h089946; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.236]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLut6i089939 for ; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i30so356142wxd for ; Thu, 15 Mar 2007 14:56:55 -0700 (PDT) Received: by 10.70.61.1 with SMTP id j1mr1969082wxa.1173995814959; Thu, 15 Mar 2007 14:56:54 -0700 (PDT) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h20sm2123338wxd.2007.03.15.14.56.53; Thu, 15 Mar 2007 14:56:54 -0700 (PDT) Message-ID: <45F9C122.9050200@buanzo.com.ar> Date: Thu, 15 Mar 2007 18:56:50 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@imc.org Subject: [OFFTOPIC] Editor under GNU/Linux X-Enigmail-Version: 0.94.3.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Sorry to bother: Any recommendation on a text editor to use that supports all formatting requirements for an Internet Draft? My googling so far has only provided a MS Word template. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF+cEiAlpOsGhXcE0RAgn1AJ91xa0+Sf88K+NlWUNw0WGoHQp85QCfZXNO ld+pOAyet5X7G8BS9ZoHpmM= =8gpm -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER9tv062729 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DER9NH062728; Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER6fg062721 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Tue, 13 Mar 2007 07:27:08 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2DEQgMG014436 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 15:26:43 +0100 From: Simon Josefsson To: ietf@ietf.org Cc: ietf-openpgp@imc.org Subject: Re: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message Format) to Proposed Standard References: OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070313:ietf-openpgp@imc.org::qw6EqPbUi/ilw5Ur:0Jzu X-Hashcash: 1:22:070313:ietf@ietf.org::X+KI19qLzrrlajE8:Esqs X-Hashcash: 1:22:070313:ietf-announce@ietf.org::Uh10b+QwS0vF6hE5:8NDV Date: Tue, 13 Mar 2007 15:26:42 +0100 In-Reply-To: (The IESG's message of "Tue\, 13 Mar 2007 09\:43\:15 -0400") Message-ID: <87mz2hw76l.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=0.2 required=4.0 tests=AWL,BAYES_50,FORGED_RCVD_HELO, TVD_FUZZY_SECURITIES autolearn=no version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Hi! I started a review by going through the reference section. There seems to be some editing left to do... There are reference to old documents, including: RFC 2279 -> RFC 3629 RFC 1750 -> RFC 4086 There are normative reference to non-standards track RFCs, including: RFC 1641 RFC 1951 RFC 1991 (which documents is intended to obsolete?) RFC 2144 The following reference are never cited in the text as far as I can tell. Most of them should likely be removed, but citing [BLEICHENBACHER] at some appropriate point may be useful. [RFC1423] Balenson, D., "Privacy Enhancement for Internet Electronic Mail: Part III: Algorithms, Modes, and Identifiers", RFC 1423, October 1993. [RFC1641] Goldsmith, D. and M. Davis, "Using Unicode with MIME", RFC 1641, July 1994. [BLEICHENBACHER] Bleichenbacher, Daniel, "Generating Elgamal signatures without knowing the secret key," Eurocrypt 96. Note that the version in the proceedings has an error. A revised version is available at the time of writing from [DONNERHACKE] Donnerhacke, L., et. al, "PGP263in - an improved international version of PGP", ftp://ftp.iks- jena.de/mitarb/lutz/crypt/software/pgp/ [MAURER] Ueli Maurer, "Modelling a Public-Key Infrastructure", Proc. 1996 European Symposium on Research in Computer Security (ESORICS' 96), Lecture Notes in Computer Science, Springer-Verlag, vol. 1146, pp. 325-350, Sep 1996. [RFC1983] Malkin, G., "Internet Users' Glossary", FYI 18, RFC 1983, August 1996. /Simon The IESG writes: > The IESG has received a request from the An Open Specification for > Pretty Good Privacy WG (openpgp) to consider the following document: > > - 'OpenPGP Message Format ' > as a Proposed Standard > > The IESG plans to make a decision in the next few weeks, and solicits > final comments on this action. Please send substantive comments to the > ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, > comments may be sent to iesg@ietf.org instead. In either case, please > retain the beginning of the Subject line to allow automated sorting. > > The file can be obtained via > http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt > > > IESG discussion can be tracked via > https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhJel059649 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DDhJIU059648; Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from ns1.neustar.com (ns1.neustar.com [156.154.16.138]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhIsW059642 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Tue, 13 Mar 2007 06:43:18 -0700 (MST) (envelope-from ietf@ietf.org) Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns1.neustar.com (Postfix) with ESMTP id 9BB7426E78; Tue, 13 Mar 2007 13:43:15 +0000 (GMT) Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HR7HX-0002QX-H9; Tue, 13 Mar 2007 09:43:15 -0400 X-test-idtracker: no To: IETF-Announce From: The IESG Subject: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message Format) to Proposed Standard Reply-To: ietf@ietf.org Cc: Message-Id: Date: Tue, 13 Mar 2007 09:43:15 -0400 Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: The IESG has received a request from the An Open Specification for Pretty Good Privacy WG (openpgp) to consider the following document: - 'OpenPGP Message Format ' as a Proposed Standard The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, comments may be sent to iesg@ietf.org instead. In either case, please retain the beginning of the Subject line to allow automated sorting. The file can be obtained via http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt IESG discussion can be tracked via https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0 Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo6cN009086 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2CMo6OU009085; Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from ns4.neustar.com (ns4.neustar.com [156.154.24.139]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo3u9009077 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Mon, 12 Mar 2007 15:50:05 -0700 (MST) (envelope-from ietf@ietf.org) Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns4.neustar.com (Postfix) with ESMTP id 788DD2ACD7; Mon, 12 Mar 2007 22:50:02 +0000 (GMT) Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HQtL8-00056B-84; Mon, 12 Mar 2007 18:50:02 -0400 Content-Type: Multipart/Mixed; Boundary="NextPart" Mime-Version: 1.0 To: i-d-announce@ietf.org Cc: ietf-openpgp@imc.org From: Internet-Drafts@ietf.org Subject: I-D ACTION:draft-ietf-openpgp-rfc2440bis-19.txt Message-Id: Date: Mon, 12 Mar 2007 18:50:02 -0400 Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: --NextPart A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the An Open Specification for Pretty Good Privacy Working Group of the IETF. Title : OpenPGP Message Format Author(s) : J. Callas, et al. Filename : draft-ietf-openpgp-rfc2440bis-19.txt Pages : 84 Date : 2007-3-12 This document is maintained in order to publish all necessary information needed to develop interoperable applications based on the OpenPGP format. It is not a step-by-step cookbook for writing an application. It describes only the format and methods needed to read, check, generate, and write conforming packets crossing any network. It does not deal with storage and implementation questions. It does, however, discuss implementation issues necessary to avoid security flaws. OpenPGP software uses a combination of strong public-key and symmetric cryptography to provide security services for electronic communications and data storage. These services include confidentiality, key management, authentication, and digital signatures. This document specifies the message formats used in OpenPGP. A URL for this Internet-Draft is: http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt To remove yourself from the I-D Announcement list, send a message to i-d-announce-request@ietf.org with the word unsubscribe in the body of the message. You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce to change your subscription settings. Internet-Drafts are also available by anonymous FTP. Login with the username "anonymous" and a password of your e-mail address. After logging in, type "cd internet-drafts" and then "get draft-ietf-openpgp-rfc2440bis-19.txt". A list of Internet-Drafts directories can be found in http://www.ietf.org/shadow.html or ftp://ftp.ietf.org/ietf/1shadow-sites.txt Internet-Drafts can also be obtained by e-mail. Send a message to: mailserv@ietf.org. In the body type: "FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt". NOTE: The mail server at ietf.org can return the document in MIME-encoded form by using the "mpack" utility. To use this feature, insert the command "ENCODING mime" before the "FILE" command. To decode the response(s), you will need "munpack" or a MIME-compliant mail reader. Different MIME-compliant mail readers exhibit different behavior, especially when dealing with "multipart" MIME messages (i.e. documents which have been split up into multiple messages), so check your local documentation on how to manipulate these messages. Below is the data which will enable a MIME compliant mail reader implementation to automatically retrieve the ASCII version of the Internet-Draft. --NextPart Content-Type: Multipart/Alternative; Boundary="OtherAccess" --OtherAccess Content-Type: Message/External-body; access-type="mail-server"; server="mailserv@ietf.org" Content-Type: text/plain Content-ID: <2007-3-12150820.I-D@ietf.org> ENCODING mime FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt --OtherAccess Content-Type: Message/External-body; name="draft-ietf-openpgp-rfc2440bis-19.txt"; site="ftp.ietf.org"; access-type="anon-ftp"; directory="internet-drafts" Content-Type: text/plain Content-ID: <2007-3-12150820.I-D@ietf.org> --OtherAccess-- --NextPart-- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q1fv022665 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l290q1qv022664; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q0ot022653 for ; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so748004wxd for ; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Received: by 10.70.40.1 with SMTP id n1mr1932022wxn.1173401518814; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm3753938wxd.2007.03.08.16.51.57; Thu, 08 Mar 2007 16:51:58 -0800 (PST) Message-ID: <45F0AFAA.7040605@buanzo.com.ar> Date: Thu, 08 Mar 2007 21:51:54 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: OpenPGP for HTTP Reference Implementation X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear group, I've just released version 0.7.0 of Enigform. Please give it a try at http://enigform.mozdev.org. If you get an older version, try the "alternate url" under the Installation section. This new version allows GET, POST and file uploads to be signed. I'll be updating the Draft for the OpenPGP for HTTP ASAP. Thanks for all the feedback, and I expect I can, with your help, transform the Draft into a real RFC document, which is one of my wildest dreams. Thank you all! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8K+qAlpOsGhXcE0RAt90AJ9l8lLV084uzTlns3mFS4x/QIOgFACeNLTm R/jjUbXSCdO0arKprWwZnaA= =/8iw -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIV9c002222 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28IIV8B002221; Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.231]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIUtl002215 for ; Thu, 8 Mar 2007 11:18:30 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so625929wxd for ; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Received: by 10.70.66.18 with SMTP id o18mr1221505wxa.1173377909684; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h34sm3164761wxd.2007.03.08.10.18.26; Thu, 08 Mar 2007 10:18:29 -0800 (PST) Message-ID: <45F0536B.6070204@buanzo.com.ar> Date: Thu, 08 Mar 2007 15:18:19 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org> In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 "Arturo 'Buanzo' Busleiman" writes: > I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). Okey, I've finished adding the new features. This is how a signed POST request from browser to server now looks. Pay attention to the X-PGP-* headers and values. Some lines could've been wrapped. ==cut here== POST /pba/postverify.php HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.2) Gecko/20070226 Firefox/2.0.0.2 Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ X-PGP-Sig-Fields: body X-PGP-Sig: iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIovixLWkMbebF2NTjo3WrVEZNA==q/ix X-PGP-Version: GnuPG v1.4.6 (GNU/Linux) X-PGP-via: Enigform for Mozilla Firefox Content-Type: application/x-www-form-urlencoded Content-Length: 17 variable=somedata ==cut here== Of course, the X-PGP-Sig header value must be splitted in 3 strings to reconstruct the detached signature, in chunks of 64, 24 and 5 characters (without the \r\n), respectively. The headers, when combined to form a detached signature, would look like this: - -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIov ixLWkMbebF2NTjo3WrVEZNA= =q/ix - -----END PGP SIGNATURE----- This is much more backwards compatible, and more geared towards standarization. I'll modify the Draft asap to include these changes. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8FNrAlpOsGhXcE0RAhbIAJ431+J6vaSwVNgMG7Dp1mn4/f+NbACeIW5k wzpDqJr9YLuPfzLej0VeeJ4= =qXuA -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0nI0044650 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28G0n8A044649; Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0mrA044643 for ; Thu, 8 Mar 2007 09:00:48 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so577333wxd for ; Thu, 08 Mar 2007 08:00:46 -0800 (PST) Received: by 10.70.13.6 with SMTP id 6mr992666wxm.1173369645923; Thu, 08 Mar 2007 08:00:45 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm2977852wxd.2007.03.08.08.00.44; Thu, 08 Mar 2007 08:00:44 -0800 (PST) Message-ID: <45F03329.20505@buanzo.com.ar> Date: Thu, 08 Mar 2007 13:00:41 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org> In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Simon Josefsson wrote: > If you are considering turning that work into draft form, consider > looking at the OpenPGP: header too: Great, I'll check it out later. > I'm confused whether your efforts is a discussion about one > implementation, or whether you have standardization goals here. Enigform = Mozilla Firefox Extension = "Reference Implementation" goal. Draft = Standarization goal. > Instead, if you want to protect header fields, you would sign the > entire message as a message/rfc822 MIME body part and include it in > the e-mail. The problem is that this is for HTTP, not for eMail. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8DMpAlpOsGhXcE0RAmGkAJ95v7NYSHPZWHmAw9+f9xECuhWJnQCbBQOA aPaaoaKbsAbIK3n/W5/i9lE= =kbEL -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FC18k041634 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28FC1Rb041633; Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FBwJ8041617 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Thu, 8 Mar 2007 08:12:00 -0700 (MST) (envelope-from simon@josefsson.org) Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l28FBdhQ013613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 16:11:39 +0100 From: Simon Josefsson To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> OpenPGP: id=B565716F; url=http://josefsson.org/key.txt X-Hashcash: 1:22:070308:buanzo@buanzo.com.ar::PYCxtJVoHV3l1kYR:2D6n X-Hashcash: 1:22:070308:ietf-openpgp@vpnc.org::U2UqeaBlmZMd9dwd:FdMt Date: Thu, 08 Mar 2007 16:11:39 +0100 In-Reply-To: <45F01209.3020706@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 08 Mar 2007 10\:39\:21 -0300") Message-ID: <87d53jlqhg.fsf@mocca.josefsson.org> User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Spam-Status: No, score=-0.8 required=4.0 tests=AWL,BAYES_40, FORGED_RCVD_HELO autolearn=ham version=3.1.1 X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com X-Virus-Status: Clean Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: "Arturo 'Buanzo' Busleiman" writes: > Current Status: > > I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header, > which will ONLY contain the signature. Signed elements will be kept in a separate header, > X-PGP-Sig-Elements. > > I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). If you are considering turning that work into draft form, consider looking at the OpenPGP: header too: http://josefsson.org/openpgp-header/ I'm confused whether your efforts is a discussion about one implementation, or whether you have standardization goals here. The OpenPGP: header do not support signing of header elements, however. The reason is that mail gateways are known to modify header elements, causing the OpenPGP signature to fail. Instead, if you want to protect header fields, you would sign the entire message as a message/rfc822 MIME body part and include it in the e-mail. What is lacking for this alternative approach to interop is guidelines to specify that MUAs should replace the outer headers with the inner ones for display purposes. The same affect S/MIME too. Perhaps it is time to revise RFC 1847 and add a discussion about this? Are people interested in working on this? Some people have been recommending signing message/rfc822 for several years, but it is not that well-defined exactly how that should work, and there is no RFC to reference either. /Simon Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdX7f036932 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28DdXup036931; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdWsp036925 for ; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so532007wxd for ; Thu, 08 Mar 2007 05:39:30 -0800 (PST) Received: by 10.70.125.11 with SMTP id x11mr742224wxc.1173361167097; Thu, 08 Mar 2007 05:39:27 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h19sm2798675wxd.2007.03.08.05.39.24; Thu, 08 Mar 2007 05:39:25 -0800 (PST) Message-ID: <45F01209.3020706@buanzo.com.ar> Date: Thu, 08 Mar 2007 10:39:21 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> In-Reply-To: <20070307202946.GA39535@mud.stack.nl> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Current Status: I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header, which will ONLY contain the signature. Signed elements will be kept in a separate header, X-PGP-Sig-Elements. I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!). I'll update the Draft ASAP. Thanks for all the input so far! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF8BIJAlpOsGhXcE0RAmhDAKCAa7YhjPR2cwgymD3qF6dZGmTAlgCfTZAy RWE253rIkVojn/KC7WjxFUs= =uhl7 -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRLBm090766 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27LRLBo090765; Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRKKB090759 for ; Wed, 7 Mar 2007 14:27:20 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so311697wxd for ; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Received: by 10.70.50.18 with SMTP id x18mr864310wxx.1173302839533; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm1586026wxd.2007.03.07.13.27.17; Wed, 07 Mar 2007 13:27:19 -0800 (PST) Message-ID: <45EF2E33.5030805@buanzo.com.ar> Date: Wed, 07 Mar 2007 18:27:15 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.10 (X11/20070221) MIME-Version: 1.0 To: Hal Finney CC: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: OpenPGP Signing of HTTP POST References: <20070307194207.51D6314F6BC@finney.org> In-Reply-To: <20070307194207.51D6314F6BC@finney.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hal Finney wrote: > I think the idea is that you can sign not only the message contents, but > selected headers as well. That's... QUITE interesting! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7y4yAlpOsGhXcE0RAjCUAJ97KaWtWsV0hlP4JFxSvsbtSl5NTQCffkri BYT5/VKN2TWdsJNKy/bxH70= =OI9s -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTsQJ087553 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27KTsGa087552; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from mx1.stack.nl (meestal.stack.nl [131.155.140.141]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTqD1087545 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from johans@stack.nl) Received: by mx1.stack.nl (Postfix, from userid 65534) id 5B3414B096; Wed, 7 Mar 2007 21:29:49 +0100 (CET) X-Spam-DCC: : snail.stack.nl 104; Body=1 Fuz1=1 Fuz2=1 X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29) on snail.stack.nl X-Spam-Level: X-Spam-Status: No, score=-2.6 required=5.0 tests=AWL,BAYES_00,NO_RELAYS autolearn=ham version=3.1.5 X-Spam-Relay-Country: Received: from mud.stack.nl (mud.stack.nl [IPv6:2001:610:1108:5011:207:e9ff:fe14:b498]) by mx1.stack.nl (Postfix) with ESMTP id DF6494B05B; Wed, 7 Mar 2007 21:29:47 +0100 (CET) Received: by mud.stack.nl (Postfix, from userid 801) id 9E628231E3; Wed, 7 Mar 2007 21:29:47 +0100 (CET) Date: Wed, 7 Mar 2007 21:29:47 +0100 From: Johan van Selst To: Hal Finney Cc: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: Re[2]: OpenPGP Signing of HTTP POST Message-ID: <20070307202946.GA39535@mud.stack.nl> References: <20070307194207.51D6314F6BC@finney.org> MIME-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="zYM0uCDKw75PZbzx" Content-Disposition: inline In-Reply-To: <20070307194207.51D6314F6BC@finney.org> User-Agent: Mutt/1.5.13 (2006-08-11) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: --zYM0uCDKw75PZbzx Content-Type: text/plain; charset=us-ascii Content-Disposition: inline "Hal Finney" wrote: > You might want to look at the X-PGP-Sig: header which has been used > for some years to sign Usenet (newsgroup) posts. Unfortunately I can't > find any documentation of it A nice desciption of background and the actual format can be found here, http://archives.eyrie.org/software/pgpcontrol/FORMAT Johan --zYM0uCDKw75PZbzx Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- iD8DBQFF7yC6aOElK32lxTsRCPohAJ0VXMQJuxLBWsa43kr6oIXgEdZAXwCfRhcu vfR4ZXd9wiSUJlfiHYllawk= =n5Xh -----END PGP SIGNATURE----- --zYM0uCDKw75PZbzx-- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrHfn085912 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27JrHfk085911; Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from finney.org (226-132.adsl2.netlojix.net [207.71.226.132]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrCmk085903 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for ; Wed, 7 Mar 2007 12:53:16 -0700 (MST) (envelope-from hal@finney.org) Received: by finney.org (Postfix, from userid 500) id 51D6314F6BC; Wed, 7 Mar 2007 11:42:07 -0800 (PST) To: ietf-openpgp@vpnc.org, ni4@ukr.net Subject: Re: Re[2]: OpenPGP Signing of HTTP POST Message-Id: <20070307194207.51D6314F6BC@finney.org> Date: Wed, 7 Mar 2007 11:42:07 -0800 (PST) From: hal@finney.org ("Hal Finney") Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: "Nickolay L." writes: > For example, we can do as following : > > POST /pba/postverify.php HTTP/1.1 > X-PGP-Message: Cleartext-Signed > X-PGP-Signature-Hash: SHA1 > X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux) > X-PGP-Signature-Comment: POST signed using Enigform > X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd > Z5AuIplmYgUFhTU3x3Sq9g== > Host: localhost > ... You might want to look at the X-PGP-Sig: header which has been used for some years to sign Usenet (newsgroup) posts. Unfortunately I can't find any documentation of it but if you Google x-pgp-sig you will find for example an Emacs macro which inserts it, part of the Ubuntu Linux distribution. Here is a sample which was posted to this list several years ago: X-PGP-Sig: 2.6.3ia Subject,From,X-Mailer iQCVAwUBM84wngE7m572a9utAQETEgQAwcL38QVdZbkHuW4Mblmje17deuI85R1j 4yGiDlb1enRDSUyGiLCmk8YphNDiLdKKlMV3Z0opzREUW9Q+sb8fr5s1QXMJhvXs 7hi7s4+V00rjgbqbqXVNiajKiKfVxd7JTRfe0UIZuOljnURP1ZCMlSRD1rDoCEAg 1vunQv6QYj4= =hvn0 I think the idea is that you can sign not only the message contents, but selected headers as well. Hal Finney Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Jvq9m092847 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26JvqpB092846; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.224]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JvpjK092840 for ; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2063984wxd for ; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Received: by 10.70.65.5 with SMTP id n5mr10334599wxa.1173211069695; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10958002wxd.2007.03.06.11.57.48; Tue, 06 Mar 2007 11:57:49 -0800 (PST) Message-ID: <45EDC7B9.6060100@buanzo.com.ar> Date: Tue, 06 Mar 2007 16:57:45 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306194431.705B318212@dune.rediris.es> In-Reply-To: <20070306194431.705B318212@dune.rediris.es> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Francisco Jesus Monserrat Coll wrote: > With this option the web pages can be cached and verified , without > using HTTP to protect the integrity of the web pages. Yes, I read about it when I first researched the pgp and http terms in google. The only difference in my case, is that I'm signing the requests the user/browser is sending to the web server, and not the pages that are sent to the browser/user. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7ce5AlpOsGhXcE0RAtENAJ0aYhimGxlsAIVdCHBCuTyRhePHgwCfXDsR gN2+3tyhAOFgmJAqN3tYhJ4= =McuB -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JujsK092797 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jujkw092796; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Juikt092789 for ; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2063698wxd for ; Tue, 06 Mar 2007 11:56:44 -0800 (PST) Received: by 10.70.74.6 with SMTP id w6mr8511444wxa.1173211004332; Tue, 06 Mar 2007 11:56:44 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10971709wxd.2007.03.06.11.56.42; Tue, 06 Mar 2007 11:56:43 -0800 (PST) Message-ID: <45EDC777.70606@buanzo.com.ar> Date: Tue, 06 Mar 2007 16:56:39 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> <45EDC608.70904@systemics.com> In-Reply-To: <45EDC608.70904@systemics.com> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Ian G wrote: > I suspect the question revolves around what you want to use the OpenPGP > signature for. Is it integrity, authentication, or authorisation? All that is described in the URLs I sent in my original post. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7cd3AlpOsGhXcE0RAgSsAJ9QQg6Xv8zoleliWj/MNvqHoIIXbgCfXih/ BIPfj439LAqAsZDqi9zezzw= =r8Ot -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JohCj092497 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Johe8092496; Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from www2.futureware.at ([217.19.43.211]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JofH9092488 for ; Tue, 6 Mar 2007 12:50:42 -0700 (MST) (envelope-from iang@systemics.com) Received: from [127.0.0.1] (localhost [127.0.0.1]) by www2.futureware.at (Postfix) with ESMTP id 60FEF2280B5; Tue, 6 Mar 2007 20:50:42 +0100 (CET) Message-ID: <45EDC608.70904@systemics.com> Date: Tue, 06 Mar 2007 20:50:32 +0100 From: Ian G User-Agent: Thunderbird 1.5.0.10 (Macintosh/20070221) MIME-Version: 1.0 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> In-Reply-To: <45EDB0A9.80207@buanzo.com.ar> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Arturo 'Buanzo' Busleiman wrote: >> For example, we can do as following : > [...] >> Where signature is to be calculated over all message (including header >> fields) after X-PGP-Signature. > > I thought about this, too. > > What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent > proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of > that same reason. I suspect the question revolves around what you want to use the OpenPGP signature for. Is it integrity, authentication, or authorisation? Integrity would indicate a header-based binary signature and authorisation would prefer a cleartext signature over the body only. For example, if you were authorising a financial transaction, you would want to get as close to the user as possible ... which admittedly is a hard or impossible task if the starting point is a POST. If you seriously wanted reliable authorisation, in the sense of "sign here to authorise this money transfer" I'd look for something that sent a cleartext signed statement that was human interpretable, so that the human could review and confirm it. That is, not a POST of variables at all, but a POST of a custom text based packet: -----BEGIN PGP SIGNED MESSAGE----- Action: TRANSFER Source: 1233455 Target: 5433211 Value: 1000.00 Unit: USD Terms: Appendix A. -----BEGIN PGP SIGNATURE----- yeahthisisajunksigyourclientshouldbarf -----END PGP SIGNATURE------ With that form you can code up some form of proxy-based user client that independently of the Browser creates the signed authorisation ... which then means there is potential of a firewall between the Authorising soft/hardware and the Application software. As soon as you hide that info from the user in for example a POST form, you will be at the mercy of technical attacks. How do you know that the veriables signed were in some way presented to the user? In some courts, just the existence of these attacks will be enough to get it thrown out (e.g., Germany I am told tends to be very aggressive this way). iang Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JibYw092282 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jib6C092281; Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from rediris.es (chico.rediris.es [130.206.1.3]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JiZKo092265 for ; Tue, 6 Mar 2007 12:44:36 -0700 (MST) (envelope-from francisco.monserrat@rediris.es) Received: from dune.rediris.es (login.rediris.es [130.206.1.21]) by chico.rediris.es (Postfix) with ESMTP id E77D944DE4; Tue, 6 Mar 2007 20:44:31 +0100 (CET) Received: by dune.rediris.es (Postfix, from userid 500) id 705B318212; Tue, 6 Mar 2007 20:44:31 +0100 (CET) Received: from rediris.es (localhost [127.0.0.1]) by dune.rediris.es (Postfix) with ESMTP id 6E0E9181B8; Tue, 6 Mar 2007 20:44:31 +0100 (CET) X-Mailer: exmh version 2.7.2 04/04/2003 with nmh-1.1 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org From: Francisco Jesus Monserrat Coll X-Image-Url: http://arraquis.dif.um.es/~paco/paco.gif X-Face: #>K{rw[D{N?r0=GjSYDGBc"EH7Wc_zk,jD+w/*@gE*i%2izUEF#}pJ/}~mQQA$Y:$yL"Da3 `Lw,Kd(@6fQy1<,fLcO}z-"g)~-Qm^U?#yQ.h|+2}*L>e}]I5M@4`*TaSs>d+z'gs9Xt:||?Ufb 5F9uY:v^"5*enEyLV,}Ly(K0ot[4k[_$D=tm)t=%Nd ;w<}gbsQn{zexIf.%h^EYSZr3/-k')Macr:l)mq=U.eIY}_4i@}E'o=N._+RBz`Bt? Organization: Red.es http://www.red.es/ Subject: Re: OpenPGP Signing of HTTP POST In-Reply-To: <45ED6495.1040407@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> Comments: In-reply-to "Arturo 'Buanzo' Busleiman" message dated "Tue, 06 Mar 2007 09:54:45 -0300." Mime-Version: 1.0 Content-Type: multipart/signed; boundary="==_Exmh_1173210270_4204P"; micalg=pgp-sha1; protocol="application/pgp-signature" Content-Transfer-Encoding: 7bit Date: Tue, 06 Mar 2007 20:44:31 +0100 Message-Id: <20070306194431.705B318212@dune.rediris.es> Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: --==_Exmh_1173210270_4204P Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit El día Tue, 06 Mar 2007 09:54:45 -0300 "Arturo 'Buanzo' Busleiman" escribió: Hello, Not regarding the "POST" method but to sign HTML pages there were some web pages, after reading http://members.aol.com/EJNBell/pgp-www.html we developed a similar method, hiding the PGP header, http://www.rediris.es/pgp/firmaweb/index.en.html The idea was to not "overload" the web server with HTTPS security only to provide signed web pages, but sign the web pages with PGP and place in a normal HTTP server, and later use PGP to check the web page signature. With this option the web pages can be cached and verified , without using HTTP to protect the integrity of the web pages. > -- = Francisco Jesus Monserrat Coll PGP key: http://www.rediris.es/keyserver Rediris. Entidad Pública Empresarial Red.es Pza. Manuel Gómez Moreno, s/n Madrid 28014 SPAIN. tel +034 912127625 --==_Exmh_1173210270_4204P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Exmh version 2.1.0 iQCVAwUBRe3EnlKs6y7TpCxhAQIlBgP/VxILGTW91aeB+/2psL1vDy0zjvBdEsuP wtKaxhH6V7eA3d35Pz/CRyvyuprhMU/SDE8sWzMovptyPtSTQ8khh9IXJ1YpB3Uz 42QwUt7zBZYzrf/zmm0s2qmkoS7tAeRP9L6tdAwzkdLnIPdKQK7WO97yHWLAQOFz jFmwnlN3RCA= =5m1Z -----END PGP SIGNATURE----- --==_Exmh_1173210270_4204P-- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9kHR090279 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26J9kTn090278; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9frq090269 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOf2a-000B0r-8z for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 21:09:40 +0200 Date: Tue, 6 Mar 2007 21:06:09 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <1682706895.20070306210609@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <45EDB0A9.80207@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Hello Arturo, ABB> Remote sites have to tell the browser that the request should be ABB> signed, thus, only compatible sites ABB> will receive such requests. Sites can tell the browser, that request should be signed by using simple header field, like 'X-OpenPGP-Signature-Needed: true'. And if reply will be sent without signature, then server will throw to client 403 or any other error. ABB> In any case, I'm only modifying the body, and adding a header. No ABB> request-specific structure is modified at all. Only proxies and/or content scanners and/or ABB> webservers that make any kind of verification over the BODY ABB> might be problematic. In any case, as ABB> Apache+PHP provide the RAW POST body, I don't think an openpgp ABB> signed body would make any problems. ABB> Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick ABB> hack, and that's why I'm here. An ABB> official extension to the HTTP protocol, or better yet, a new ABB> content-encoding, should be analyzed. New content >> For example, we can do as following : ABB> [...] >> Where signature is to be calculated over all message (including header >> fields) after X-PGP-Signature. ABB> I thought about this, too. ABB> What if other fields are added, after the X-PGP-Signature is ABB> calculated? What about [non]transparent ABB> proxies? OpenPGP tags the beginning and end of the data that ABB> corresponds to the signature because of ABB> that same reason. If you are using non-transparent proxy, it means 1) you doesn't care about headers, they must not be signed - thus, you can add parameter, something like 'X-OpenPGP-Signature-Param: no-headers', which causes to sign/verify only the message body (non-transparent proxies doesn't change message body, yep?) 2) if some headers are significant, there can be parameter, something like 'X-OpenPGP-Validate-Headers: User-Agent, Accept-Charset, Referer' -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJSpi086454 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26IJSGu086453; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJRt3086447 for ; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2035166wxd for ; Tue, 06 Mar 2007 10:19:27 -0800 (PST) Received: by 10.70.23.1 with SMTP id 1mr8344182wxw.1173205167633; Tue, 06 Mar 2007 10:19:27 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10810882wxd.2007.03.06.10.19.25; Tue, 06 Mar 2007 10:19:26 -0800 (PST) Message-ID: <45EDB0A9.80207@buanzo.com.ar> Date: Tue, 06 Mar 2007 15:19:21 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> In-Reply-To: <1466251624.20070306200222@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Hello Arturo, Hi Nickolay, > Your format changes the HTTP protocol, which disables backward > compatibility, and could add other problems. Remote sites have to tell the browser that the request should be signed, thus, only compatible sites will receive such requests. In any case, I'm only modifying the body, and adding a header. No request-specific structure is modified at all. Only proxies and/or content scanners and/or webservers that make any kind of verification over the BODY might be problematic. In any case, as Apache+PHP provide the RAW POST body, I don't think an openpgp signed body would make any problems. Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick hack, and that's why I'm here. An official extension to the HTTP protocol, or better yet, a new content-encoding, should be analyzed. > For example, we can do as following : [...] > Where signature is to be calculated over all message (including header > fields) after X-PGP-Signature. I thought about this, too. What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of that same reason. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7bCpAlpOsGhXcE0RAkokAJ0W4QaNgmIgq+9QBTto0F2kQ+1D+gCfeUGt IoUmfdm9B2DK++gsvrdO138= =dyTr -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5u7U085551 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26I5uPT085550; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5sDZ085544 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOe2r-0007gS-A0 for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 20:05:53 +0200 Date: Tue, 6 Mar 2007 20:02:22 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <1466251624.20070306200222@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <45EDA1BB.8070606@buanzo.com.ar> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Hello Arturo, >> ABB> Please, expand that! What are your ideas for OpenPGP security over http? >> Something like cleartext signing for HTTP - PGP-Signature headers and >> so on, and also encryption/binary signing of http document body. ABB> Enigform currently adds an X-Enigform header with "Signed" ABB> value. I will be adding extra OpenPGP ABB> parameters (fingerprint? keyid?), and the ability to also ABB> encrypt. Currently, only http POSTS are ABB> supported. A signed request looks like this: ABB> What are the extra ideas you have? Your format changes the HTTP protocol, which disables backward compatibility, and could add other problems. For example, we can do as following : POST /pba/postverify.php HTTP/1.1 X-PGP-Message: Cleartext-Signed X-PGP-Signature-Hash: SHA1 X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux) X-PGP-Signature-Comment: POST signed using Enigform X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 variable=test Where signature is to be calculated over all message (including header fields) after X-PGP-Signature. So, it will correspond to such OpenPGP message, which could be sent to GnuPG for verification and so on : -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 variable=test -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: POST signed using Enigform iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== =wVHP -----END PGP SIGNATURE----- Such simple translation on server and client side allows you to use HTTP protocol as it is, and allows backwatds compatibility for applications, which aren't compatible with such extensions. I'm going to write complete draft of my ideas and publish it after week or so. -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFkGd082613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26HFk85082612; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFjXW082606 for ; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so2016733wxd for ; Tue, 06 Mar 2007 09:15:45 -0800 (PST) Received: by 10.70.84.6 with SMTP id h6mr12037573wxb.1173201344993; Tue, 06 Mar 2007 09:15:44 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i35sm10629647wxd.2007.03.06.09.15.42; Tue, 06 Mar 2007 09:15:43 -0800 (PST) Message-ID: <45EDA1BB.8070606@buanzo.com.ar> Date: Tue, 06 Mar 2007 14:15:39 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> In-Reply-To: <1976536264.20070306190040@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Hello Arturo, Hello, Nickolay. You forgot to reply to the list. > ABB> Please, expand that! What are your ideas for OpenPGP security over http? > Something like cleartext signing for HTTP - PGP-Signature headers and > so on, and also encryption/binary signing of http document body. Enigform currently adds an X-Enigform header with "Signed" value. I will be adding extra OpenPGP parameters (fingerprint? keyid?), and the ability to also encrypt. Currently, only http POSTS are supported. A signed request looks like this: POST /pba/postverify.php##ENIGFORM_Sign## HTTP/1.1 Host: localhost User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \ Gecko/20070130 Firefox/2.0.0.1 Accept: text/xml,application/xml,application/xhtml+xml,text/html\ ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5 Accept-Language: en-us,en;q=0.5 Accept-Encoding: gzip,deflate Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7 Keep-Alive: 300 X-Enigform: Signed Connection: keep-alive Referer: http://localhost/pba/ Content-Length: 323 Content-Type: application/x-www-form-urlencoded-openpgp Cache-Control: max-age=0 -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 variable=test -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: POST signed using Enigform iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd Z5AuIplmYgUFhTU3x3Sq9g== =wVHP -----END PGP SIGNATURE----- What are the extra ideas you have? - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7aG7AlpOsGhXcE0RAtCEAJ95pYoWzioR+L+qLQAkMZdEsLWSsgCeO0dM ns6HspQOJQQf3+fpi6nMFdI= =BEZt -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em5th070744 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Em5tA070743; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em2Qu070736 for ; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1970241wxd for ; Tue, 06 Mar 2007 06:48:02 -0800 (PST) Received: by 10.70.90.14 with SMTP id n14mr11850088wxb.1173192482284; Tue, 06 Mar 2007 06:48:02 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10439741wxd.2007.03.06.06.48.00; Tue, 06 Mar 2007 06:48:01 -0800 (PST) Message-ID: <45ED7F1E.90408@buanzo.com.ar> Date: Tue, 06 Mar 2007 11:47:58 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> In-Reply-To: <642100057.20070306155914@ukr.net> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=windows-1251 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Nickolay L. wrote: > Btw, in my plans also is writing and implementing something like 'PGP > security over HTTP' specification, and already having some ideas 'bout > it (it's something other than proposed by Arturo). Maybe, consider writing it in a group? Please, expand that! What are your ideas for OpenPGP security over http? - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7X8dAlpOsGhXcE0RAgcUAJ0eDb6SQRJpTbw8HbchprbiZa2pcACfUOSJ GxrIHHPmQ0eeQXDzmrY2hT4= =urng -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2hM5066817 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26E2hkg066812; Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2eEc066804 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Tue, 6 Mar 2007 07:02:42 -0700 (MST) (envelope-from ni4@ukr.net) Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from ) id 1HOaFS-000PPs-TN for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 16:02:39 +0200 Date: Tue, 6 Mar 2007 15:59:14 +0200 From: "Nickolay L." X-Mailer: The Bat! (v3.80.03) Professional Reply-To: "Nickolay L." X-Priority: 3 (Normal) Message-ID: <642100057.20070306155914@ukr.net> To: ietf-openpgp@vpnc.org Subject: Re[2]: OpenPGP Signing of HTTP POST In-Reply-To: <20070306131900.GA25665@epointsystem.org> References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> MIME-Version: 1.0 Content-Type: text/plain; charset=windows-1251 Content-Transfer-Encoding: 8bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: Hello Daniel, Btw, in my plans also is writing and implementing something like 'PGP security over HTTP' specification, and already having some ideas 'bout it (it's something other than proposed by Arturo). Maybe, consider writing it in a group? DAN> I think that this is extremely useful; I was enterntaining the same idea DAN> myself, albeit in a slightly different way. DAN> I think, that the standardized protocol needs to have facilities for both DAN> client-, server- and content-authentication. DAN> May I ask what the status of the draft is and how do you enter changes into DAN> it? -- Best regards,Nickolay mailto: , . /_`, `' | &*._.,. .# ) $, //./--//\\. & \/ \. \. -- - - ... - - --. `'`' ` `' -- - - [> http://ansiart.org.ua <] [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)] [Now playing : Ïèêíèê - Øàðìàíêà] Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5tm065994 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Do54e065993; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.237]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5CI065987 for ; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1951840wxd for ; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Received: by 10.70.66.18 with SMTP id o18mr11759820wxa.1173189002805; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h38sm10276388wxd.2007.03.06.05.50.00; Tue, 06 Mar 2007 05:50:02 -0800 (PST) Message-ID: <45ED7185.2010300@buanzo.com.ar> Date: Tue, 06 Mar 2007 10:49:57 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> In-Reply-To: <20070306131900.GA25665@epointsystem.org> X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Daniel A. Nagy wrote: > I think that this is extremely useful; I was enterntaining the same idea > myself, albeit in a slightly different way. I had this idea in March/April 2006. Just had time to implement it last month :) > I think, that the standardized protocol needs to have facilities for both > client-, server- and content-authentication. Yes, of course. > May I ask what the status of the draft is and how do you enter changes into > it? The draft is behind the development status of the Enigform Firefox Extension. Currently, HTTP POST requests generated via AJAX calls, or FORM submissions will be picked up for signing by Enigform by checking if the ACTION URL (or Ajax request url) ends with "##ENIGFORM_Sign##". I had tested this with a hidden input field of a special name/value combination, I've also tested using an extra parameter for the tag (SECURITY='ToBeSigned'), but all of this made the extension's code overly complicated, and incompatible with certain sites. Checking the URL was quite a simpler approach. Of course, the correct (i think) way for a FORM submission to be signed would be with a special enctype (like urlencoded-openpgp-signed), but that would render ajax support useless, too. Additionally, AJAX requests can't be diferentiated from form posts from within a Firefox extension. Adoption of this technology is easier via a Firefox extension, and a simple set of server-side code (that's why I talked with Rod, author of Smutty, to extend it with Enigform support). Regarding changes to the draft, no specific procedures have been established, yet. This is my first attempt. I'm open to suggestions. - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7XGFAlpOsGhXcE0RAoS1AJ9kFXExRm9QAkxtQ5TJbndGe7eURwCbBYA4 C8sg7uGRJ7UWJUjdxNTFG/0= =Wdrc -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ3LF063660 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26DJ3bm063659; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from mail.epointsystem.org (120.156-228-195.hosting.adatpark.hu [195.228.156.120]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ2hP063653 for ; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from nagydani@epointsystem.org) Received: by mail.epointsystem.org (Postfix, from userid 1001) id 20C5B3E8E; Tue, 6 Mar 2007 14:19:01 +0100 (CET) Date: Tue, 6 Mar 2007 14:19:01 +0100 To: "Arturo 'Buanzo' Busleiman" Cc: ietf-openpgp@vpnc.org Subject: Re: OpenPGP Signing of HTTP POST Message-ID: <20070306131900.GA25665@epointsystem.org> References: <45ED6495.1040407@buanzo.com.ar> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="9amGYk9869ThD9tj" Content-Disposition: inline In-Reply-To: <45ED6495.1040407@buanzo.com.ar> User-Agent: Mutt/1.5.9i From: nagydani@epointsystem.org (Daniel A. Nagy) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: --9amGYk9869ThD9tj Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable I think that this is extremely useful; I was enterntaining the same idea myself, albeit in a slightly different way. I think, that the standardized protocol needs to have facilities for both client-, server- and content-authentication. May I ask what the status of the draft is and how do you enter changes into it? On Tue, Mar 06, 2007 at 09:54:45AM -0300, Arturo 'Buanzo' Busleiman wrote: >=20 > Dear OpenPGP WG team, >=20 > One day at 3am in the morning I woke up with a mix of two strings in my = head: "POST / HTTP/1.1" and > "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about t= he whole idea, and as I > couldn't go back to sleep, I got up and wrote it down. A couple of months= later, and some BIG > thinking, I decided to create a Firefox Extension to implement what I am = now going to describe, and > what I want to rewrite into a proper Draft: >=20 > For years different methods for User Authentication and Session Managemen= t have been implemented: >=20 > * HTTP Authentication > * Cookies > * GET/POST values > * SSL with client certificates > * A combination of all the above. >=20 > Regarding SMTP, e-mail has been digitally signed for a long time now, and= it is a standard. > Extending its usage to the HTTP protocol sounded like a natural idea, spe= cially at 3am when I woke > up with a OpenPGP-signed HTTP POST request in my head. >=20 > By having the POST payload ("variable=3Dtest") signed using an ASCII armo= red, Clearsign, OpenPGP based > procedure, the browsing user can provide Identity Authentication to that = payload, thus adding all > OpenPGP benefits to the HTTP POST request. >=20 > This allows web developers to add a new layer of security to their applic= ations, and if correctly > implemented will render man in the middle attacks useless. The direct ben= efit of implementing this > extension is that web developers will be able to verify the POST payload = signature, potentially > avoiding obscure session management, and/or complicated login procedures. >=20 > For example, Highly Secure Home Banking sites could be created by using E= nigform + some simple > server side code. >=20 > For a demo of an Enigform-based login procedure, with using AJAX and FORM= SUBMIT, configure your > GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar. >=20 > Enigform: http://enigform.mozdev.org > Latest Version: 0.6.5 >=20 > Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html >=20 > Hope you like it! --9amGYk9869ThD9tj Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.3 (GNU/Linux) iQDVAwUBRe1qRK6pEulQFnIMAQIvqQX9HkflhwbcVpbq1maV9Yf+Ec3xBK5q8bh1 26+0LJZcu0l02ue2G49odlKPfhIYlai4A79dikmcF35ef8nUBYwYnoO3pP5HVqAD aUUIlC4Z8uLiXoiozg8coodH/kwqkn7gx4MbRayNljurkWcejdTRaRBNORRz5J/p NgYLAMC2pIYjW3funDZ3Ub8Gu0Ssw913CWhOVtYuAW7d1tWPCMn33sF4+gdkSImn px/FclwfD78vsPFOCfxcNSgloQRmSQUh =LtlV -----END PGP SIGNATURE----- --9amGYk9869ThD9tj-- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26CspEc061037 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Csp5L061036; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Csoiv061029 for ; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from buanzo@buanzo.com.ar) Received: by wx-out-0506.google.com with SMTP id i31so1937128wxd for ; Tue, 06 Mar 2007 04:54:50 -0800 (PST) Received: by 10.70.131.19 with SMTP id e19mr7986508wxd.1173185689787; Tue, 06 Mar 2007 04:54:49 -0800 (PST) Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10249934wxd.2007.03.06.04.54.48; Tue, 06 Mar 2007 04:54:49 -0800 (PST) Message-ID: <45ED6495.1040407@buanzo.com.ar> Date: Tue, 06 Mar 2007 09:54:45 -0300 From: "Arturo 'Buanzo' Busleiman" Organization: GNU/Buanzo User-Agent: Thunderbird 1.5.0.9 (X11/20061206) MIME-Version: 1.0 To: ietf-openpgp@vpnc.org Subject: OpenPGP Signing of HTTP POST X-Enigmail-Version: 0.94.2.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear OpenPGP WG team, One day at 3am in the morning I woke up with a mix of two strings in my head: "POST / HTTP/1.1" and "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about the whole idea, and as I couldn't go back to sleep, I got up and wrote it down. A couple of months later, and some BIG thinking, I decided to create a Firefox Extension to implement what I am now going to describe, and what I want to rewrite into a proper Draft: For years different methods for User Authentication and Session Management have been implemented: * HTTP Authentication * Cookies * GET/POST values * SSL with client certificates * A combination of all the above. Regarding SMTP, e-mail has been digitally signed for a long time now, and it is a standard. Extending its usage to the HTTP protocol sounded like a natural idea, specially at 3am when I woke up with a OpenPGP-signed HTTP POST request in my head. By having the POST payload ("variable=test") signed using an ASCII armored, Clearsign, OpenPGP based procedure, the browsing user can provide Identity Authentication to that payload, thus adding all OpenPGP benefits to the HTTP POST request. This allows web developers to add a new layer of security to their applications, and if correctly implemented will render man in the middle attacks useless. The direct benefit of implementing this extension is that web developers will be able to verify the POST payload signature, potentially avoiding obscure session management, and/or complicated login procedures. For example, Highly Secure Home Banking sites could be created by using Enigform + some simple server side code. For a demo of an Enigform-based login procedure, with using AJAX and FORM SUBMIT, configure your GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar. Enigform: http://enigform.mozdev.org Latest Version: 0.6.5 Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html Hope you like it! - -- Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iD8DBQFF7WSVAlpOsGhXcE0RAt88AJ0cyBuMS/U0qZjwTZ9DrnE1jxRmUwCfdYqN +GAVdVxL/NfUvvvdA0RJolc= =m/4G -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207NQl079627 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2207NgS079626; Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207M4s079619 for ; Thu, 1 Mar 2007 17:07:22 -0700 (MST) (envelope-from jon@callas.org) Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 406F056F7CB for ; Thu, 1 Mar 2007 16:07:22 -0800 (PST) Received: from [10.240.72.119] ([208.54.15.1]) by keys.merrymeet.com (PGP Universal service); Thu, 01 Mar 2007 16:07:22 -0800 X-PGP-Universal: processed; by keys.merrymeet.com on Thu, 01 Mar 2007 16:07:22 -0800 In-Reply-To: <20070301180833.GA22614@jabberwocky.com> References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> <20070301180833.GA22614@jabberwocky.com> Mime-Version: 1.0 (Apple Message framework v752.3) Message-Id: <96F3CC13-7B61-41DB-BE4D-78B33A4D2D3B@callas.org> Cc: OpenPGP From: Jon Callas Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt Date: Thu, 1 Mar 2007 16:07:18 -0800 To: David Shaw X-Mailer: Apple Mail (2.752.3) X-PGP-Encoding-Version: 2.0.2 X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; format=flowed Content-Type: text/plain; charset="US-ASCII" Content-Transfer-Encoding: 7BIT Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 > > This looks really good. I have a few minor comments about the > additions. This might look like a lot, but I think there was a cut > and paste error that explains some of them. > Yeah. They're all fixed. I'm submitting the resulting bis-20. Jon -----BEGIN PGP SIGNATURE----- Version: PGP Universal 2.5.3 Charset: US-ASCII wj8DBQFF52q6sTedWZOD3gYRAoANAKC2aYeLwv6Il4tc5z/jO9CdCI7HIwCgs4fv n+ca/0oqgnlUfhSVbkaTnmw= =pkVx -----END PGP SIGNATURE----- Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8x1t054493 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l21I8x2b054492; Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org) X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8vZA054485 for ; Thu, 1 Mar 2007 11:08:58 -0700 (MST) (envelope-from dshaw@jabberwocky.com) Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l21I8hZ00380; Thu, 1 Mar 2007 13:08:43 -0500 Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8cqo015067 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 13:08:38 -0500 Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8a6K022649; Thu, 1 Mar 2007 13:08:36 -0500 Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l21I8XxU022648; Thu, 1 Mar 2007 13:08:33 -0500 Date: Thu, 1 Mar 2007 13:08:33 -0500 From: David Shaw To: OpenPGP Cc: jon@callas.org Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt Message-ID: <20070301180833.GA22614@jabberwocky.com> Mail-Followup-To: OpenPGP , jon@callas.org References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc User-Agent: Mutt/1.5.13 (2006-11-21) Sender: owner-ietf-openpgp@mail.imc.org Precedence: bulk List-Archive: List-Unsubscribe: List-ID: On Mon, Feb 26, 2007 at 09:21:17PM -0800, Jon Callas wrote: > > I've submitted bis19. This should be within epsilon of complete for a > whole lot of epsilons. It has in it text to address the IESG > concerns, as well as the IANA considerations in a brand new section > 10. The *only* thing that there should be comments on is the IANA > considerations. This looks really good. I have a few minor comments about the additions. This might look like a lot, but I think there was a cut and paste error that explains some of them. ********************* In section 5.13, in the non-normative explanation of MDC: The sentence "(Note also that CBC mode has similar limitation, but data removed from the front of the block is undetectable.)" needs an "a" between "has" and "similar". The sentence "Suffice it to say that many people consider properties such as deniability are considered to be as valuable as integrity." is a little tangled, language wise. I suggest removing the words "are considered". "OpenPGP addresses this desire to have more security than raw encryption, and yet preserving deniability with the MDC system." is also a bit tangled. I suggest changing "preserving" to "preserve" and adding a comma after "deniability". ********************* Section 10.2.2.1 (Signature Notation Data Subpackets) says "Adding a new signature Signature Notation Data ..." The first "signature" should be removed. ********************* Section 10.2.2.2 (Key Server Preference Extensions) says "OpenPGP signatures contain a mechanism for preferences to be specified about key server preferences." That's one "preferences" too many. ********************* Section 10.2.2.3 is titled "Key Flags Preference Extensions". I suggest removing the word "Preference" as key flags aren't really preferences, and the rest of that section (correctly, I'd say) doesn't call them preferences either. ********************* Section 10.2.2.4 (Reason For Revocation Extensions) seems to have a few cut and paste problems and is co-mingled with the section after it. It refers to "the feature flags value". This should be "the reason-for-revocation flags value". In the same section it says "Adding a new feature flag...". That should be "Adding a new reason-for-revocation flag..." The reference to section 5.2.3.24 should be 5.2.3.23. Finally, the sentence "Also see section 10.6 for more information about when feature flags are needed." actually belongs to section 10.2.2.5 (Implementation Features). ********************* Section 10.2.2.5. (Implementation Features) has a mirror image of the problems with 10.2.2.4. It refers to "the reason flags value". That should probably be "the feature-implementation flags value". In the same section it says "Adding a new reason for revocation flag...". That should be "Adding a new feature-implementation flag..." The reference to section 5.2.3.23 in this section should be section 5.2.3.24. The sentence "Also see section 10.6 for more information about when feature flags are needed." from section 10.2.2.4 actually belongs here. ********************* David