From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: =?utf-8?Q?Bj=C3=B6rn?= Bidar Newsgroups: gmane.emacs.help Subject: Re: Verifying signed mail in Gnus Date: Wed, 02 Nov 2022 22:52:47 +0200 Message-ID: <875yfxdqow.fsf@thaodan.de> References: <87a65cz3xl.fsf@gmail.com> <87pme8w6w5.fsf@disroot.org> <878rkwxjis.fsf@gmail.com> <87wn8fzs58.fsf@mat.ucm.es> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="3024"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) To: help-gnu-emacs@gnu.org Original-X-From: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Wed Nov 02 21:53:32 2022 Return-path: Envelope-to: geh-help-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1oqKjr-0000c0-2s for geh-help-gnu-emacs@m.gmane-mx.org; Wed, 02 Nov 2022 21:53:31 +0100 Original-Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1oqKjS-0006dn-Ce; Wed, 02 Nov 2022 16:53:06 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1oqKjM-0006dd-Q9 for help-gnu-emacs@gnu.org; Wed, 02 Nov 2022 16:53:00 -0400 Original-Received: from thaodan.de ([185.216.177.71]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1oqKjI-0005Me-IP for help-gnu-emacs@gnu.org; Wed, 02 Nov 2022 16:53:00 -0400 Original-Received: from odin (dsl-trebng12-b04885-76.dhcp.inet.fi [176.72.133.76]) by thaodan.de (Postfix) with ESMTPSA id 3937BD08CC6 for ; Wed, 2 Nov 2022 22:52:48 +0200 (EET) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=thaodan.de; s=mail; t=1667422368; bh=hjmjTgGCbkp5oLCXqIgo7i8nS9ojJ1GkF9XReTlecDc=; h=From:To:Subject:In-Reply-To:References:Date; b=j3eOZp5DonZiu0hd1jpivq3ckej5NCHwO1rpMlxKyy2A/vKUCVC7ErlNLv2fAhnNG qIzLQVYd+oiqXsTWKNYmS8PzXIYfV46V8c0HviNAZQfNDuuTTngD0Dr2F+rtVvkF01 uEKodbLk7jYYgkwbBrBMYk9Afg8n/fngyZ+HPbncutwhJn+6P0Vc3IrV46ZH8uJLBV zA7btegFgFZOPNZ+TSecM7hElNmVAxXPsQiuO8EPDMu+q5f12iL5JHDY5weMvvSo7t N+DAeGL0drPmtdCWIPOQnKJe85qK1iVAe1X/3ZiSjUsQ1C2citpMnZdNDEbrb3iYjN MJb3QtCmXIpA9Qzq7R/OudHQLppz5gzIUdytmxdQ3cGybWCxRK9g8Z1i8+1Emdy8lZ QmciW/Bo9TtIF22hxtjFlIqJzx1QxHeKLX6l/vk5Y7WosrcqOQoCVjnGHkB4DhCWh7 d0vauZKG/GyzpmNu8XxzeXJFVPiWC39cQIBeDGqIZ0JMV1WVCzawW47ZNwBQT9fG0c KvfArx5WQ6DcSGO1AHxwUpZ+GmzJUU0oiv55oETBh1TgtkTeN+W8P/XfdW5JnX7hiX 7I8BveCig/1RijVS8gEv99nwPswkR7m1DoJtKsWmIri7vpdxWp72Ah+wNaMJ1p3tyV Bo2HWHPAvFNrvpwd+yHTWJz8= In-Reply-To: <87wn8fzs58.fsf@mat.ucm.es> (Uwe Brauer's message of "Mon, 31 Oct 2022 20:53:39 +0100") Received-SPF: pass client-ip=185.216.177.71; envelope-from=bjorn.bidar@thaodan.de; helo=thaodan.de X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: help-gnu-emacs@gnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Users list for the GNU Emacs text editor List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Original-Sender: "help-gnu-emacs" Errors-To: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Xref: news.gmane.io gmane.emacs.help:140584 Archived-At: Uwe Brauer writes: > 1. The public key interchange is so much simpler (but see below > risks), since the public key is always embedded in your signature There are movement on going to improve that notably autocrypt. The only downside is that email clients in general aren't that good or good to adapt to new standards. > 2. SMIME support is basically shipped in most MTA, moreover the key > generation is also much simpler for newbies. What I see quite often that PKCS#11 is not always implemented in all programs that use similar certificates as SMIME where as for pgp it was never an issue to use hardware tokens since most programs us gpg. > 3. IF you have the all the relevant CAs installed (which might not > always be the case), the authentification is done automatically, > for GNU/Linux for example by the ggpsm program which is used > usually by emacs. I think that is also possible with pgp but it depends on your pgp program and your email program. Clients such as Kmail can do these things automatically I think. > 4. Some government agencies already provide SMIME keys for their > residents, for example Spain. Some governments or agencies support pgp, quite often security researchs offer it. In Germany some of parts justice system support pgp, although I haven't seen them distribute their keys on a keyserver. Br, Bj=C3=B6rn