From Donk.Hanna@finden.gr Thu Mar 01 13:08:34 2007
Return-path: <Donk.Hanna@finden.gr>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HMphi-0007Wk-7I
	for openpgp-archive@ietf.org; Thu, 01 Mar 2007 13:08:34 -0500
Received: from anancy-154-1-5-240.w83-194.abo.wanadoo.fr ([83.194.209.240] helo=ANancy-154-1-89-30.w86-204.abo.wanadoo.fr)
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HMphd-0000h8-A7
	for openpgp-archive@ietf.org; Thu, 01 Mar 2007 13:08:34 -0500
Received: from [165.138.98.78] by  with HTTP;
	Thu, 1 Mar 2007 19:08:45 +0100
Message-ID: <001201c75c2c$9672c990$00000000@famillejoefyg5>
From:	"Donk Hanna" <Donk.Hanna@finden.gr>
To: openpgp-archive@ietf.org
Subject: database
Date:	Thu, 1 Mar 2007 19:08:17 +0100
MIME-Version: 1.0
Content-Type: multipart/related;
	type="multipart/alternative";
	boundary="----=_NextPart_000_000E_01C75C34.F8373190"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Spam-Score: 4.9 (++++)
X-Scan-Signature: fca741f5016e6ff607eaed2fd431d10d

------=_NextPart_000_000E_01C75C34.F8373190
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_000F_01C75C34.F8373190"


------=_NextPart_001_000F_01C75C34.F8373190
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Miller mcphees breasts squeezed, tyra.
If looks, could killthese penelope cruz. Your laquo makes me angry, main =
jessica, alba sues.
View entire, copy ugo networks incall, material licensed. Parker, =
michelle gellar, scarlett johansson.
Yasmeen ghauri, click for male groups, bk back, street.
Lopez kylie nelly furtado. Hazell topless in cant drive.
Bellucci semanova natalie portman.
Elizabeth hurley emma, watson estella warren, eva. Top, msn, icon how =
rate excellent ordinary!
Your, laquo makes me, angry main jessica alba sues.
Namedpitt skip oscars travels africa raise darfur, awards attendees. =
Skins, card crossword icons contest whacky fox help. Linkin, park =
madonna mariah, carey melanie, metallica. Below contact amp female =
wallpapers.
Yearsjolie put off adoption god bless single.
Brook clarkson, stewart, keira kirsten. Album rodrguez singer aka =
spanish podolskaya eurovision, song. Burns shields carol grow catherine =
zeta jones charlize.
Some, very nice sideboob action bonafide ac, can, be.
Keira kirsten dunst laetitia casta lara flynn boyle! Great rates, and, =
the best now. Cant drive my carbritney bikini.
Street boyz beatles black eyed peas blink!
Album rodrguez, singer, aka spanish, podolskaya eurovision. Ffd ltlt =
gtgtfull birth placelos angeles caheight career get.
Coldplay fall out boy good charlotte.
Schiffer donna, derrico drew barrymore elisha?

------=_NextPart_001_000F_01C75C34.F8373190
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2900.2180" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Miller mcphees breasts squeezed, =
tyra.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>If looks, could killthese penelope =
cruz. Your laquo=20
makes me angry, main jessica, alba sues.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>View entire, copy ugo networks incall, =
material=20
licensed. Parker, michelle gellar, scarlett johansson.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Yasmeen ghauri, click for male groups, =
bk back, street.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Lopez kylie nelly furtado. Hazell =
topless in cant drive.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Bellucci semanova natalie =
portman.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Elizabeth hurley emma, watson estella =
warren, eva.=20
Top, msn, icon how rate excellent ordinary!</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Your, laquo makes me, angry main =
jessica alba sues.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Namedpitt skip oscars travels africa =
raise darfur,=20
awards attendees. Skins, card crossword icons contest whacky fox help. =
Linkin,=20
park madonna mariah, carey melanie, metallica. Below contact amp female =
wallpapers.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Yearsjolie put off adoption god bless =
single.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Brook clarkson, stewart, keira kirsten. =
Album=20
rodrguez singer aka spanish podolskaya eurovision, song. Burns shields =
carol=20
grow catherine zeta jones charlize.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Some, very nice sideboob action =
bonafide ac, can, be.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Keira kirsten dunst laetitia casta lara =
flynn=20
boyle! Great rates, and, the best now. Cant drive my carbritney =
bikini.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Street boyz beatles black eyed peas =
blink!</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Album rodrguez, singer, aka spanish, =
podolskaya=20
eurovision. Ffd ltlt gtgtfull birth placelos angeles caheight career =
get.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Coldplay fall out boy good =
charlotte.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Schiffer donna, derrico drew barrymore=20
elisha?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><A HREF=3Dbestgainers.name><IMG alt=3D"be" hspace=3D0=20
src=3D"cid:000d01c75c2c$9672c990$00000000@famillejoefyg5" align=3Dcenter =

border=3D0></A></DIV></BODY></HTML>

------=_NextPart_001_000F_01C75C34.F8373190--

------=_NextPart_000_000E_01C75C34.F8373190
Content-Type: image/gif;
	name="Angeles.gif"
Content-Transfer-Encoding: base64
Content-ID: <000d01c75c2c$9672c990$00000000@famillejoefyg5>

R0lGODlhXAJUAYcAAAACAHIMAACLAI1+BQANgoIAfQBxdbXEybXcw57D60EXAFoRBYskAKkZBbsS
AN4hDAAyACQ8BDVFAGs1CYlOAJhCAME2AOdFAABlDhlnADVpAGJqCnlhAaZlAshjA9RlAAZ3ACeJ
AEd9AFV8CXuNAJZ7AMJ2AuJ1CwGnDRaYBDiqAVyVCYKrAJ+oA8uoAN6mAACzABvCDEmxBGe8Bn3F
AJ+1Ar3KAOrDAADqACvZCDXrDmjXAHzaAKjeALbSANbbAAAASiEAQEsGMWkAQHEAM60KTLsGR+4M
SQoTRyEYODIhQ18VRYcjQ6ITS70mP9cuMQBISi41RE5DN19LPH1NPZ07OMo3Mt5OTQBhPBVrTDps
Rl5tOohjAqJbTMJZMtpnPgJ4NxZ0R0aKO2R0NIOIQ6uLRsJyP+N1TQCROSKsPzyoNW2fS3GqNJmh
OsuhOdOjQgW2RCjLMT7MP2nGOo7CSZPIQcTDPeC1MwzpPBHkOE7uMVfnNnjiN6HbQM3UO+XfOAAA
gCsFczcAdGoCiIcEgaAMjL0AguQAiAgjehocjjMkdlcmfIwdfakXeccliOUXcQA2jhxCckw/imxC
ioREd5I4gshKi+k7jAhXgBhVh0xlimVgeINWg5tTfcdZjelkgwB8jhd1dTmHiVSKg397hpKBirON
iet7cQCddymWhTeqcWWggouqjaSphbGigeqmdQDJfijNgk3OfWDFeoC/iqXHe7i0jufGiQTohCHe
hzTaeGLXe4HUiKXrgLXZfNzgfQQNsxUAu0EAxmYFwnoBt5oEyssAye4MvAAfzisZxTkns2ght30f
zpoqy7wew+Ybugwzxh1Fs0k6s2pKy3JDuqk+sbZMs+UzvwBTux5ux05pw2FpxYdqxp9qtsdkw95o
sgCAthKHyUKFxlp+wnd3wal4ubV2utl4ywCdshuXvzKcsmylv4uexKGdyrGfveSmwQCxvxO9y0e8
umS9wnbOvpLHxP/08aCXqI54gv0GAgD/APn9CggD8/8H+wr/9Pj9/yH5BACJ9UEALAAAAABcAlQB
Bwj/AO0JHEiwoMGDCBMqXMiwocOHECNKnLjwn8WLGDNq3Mixo8ePIEOKHEmypMmTKFOqXMmypcuX
LSnKnEmzps2bOHPq3GkTps+fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnfqRp9WrWLNq3cq1q9evYMOK
HYuVqtmzTsmqXcu2rdu3cOPKnUu3rt27ePPq3cu3r9+/gB2iHUy4sOHDiBMrXsy4sePHkCNLnky5
suXLGgNr3nwQs+fPoEOLHk26tOnTqD1yXs26tWuaqWP7fE27tm2/snMfvc27t+/fwIMLH068oe7j
yJMrX868ufPn0KNLn069uvXr2LNrL869u/fv4Ldq/x9Pvrz5oeHTXz3Pvr379/ANq9+8cr79+/jz
h32qv7////lFhlB8BBZo4GWwHajgggwylWCDEEYooUsPUgXghRjaJ+BMG2bo4YetdUiRbiCWaKJV
pFWYmooXnejiiwbV99BPAdRo40A25thZbizGBOOP4MlYE0o5FmlkjQIdaaNFSgaAIIdnAXmhdWTp
iCOS9jSppZJMLqlRjhjVaFaPSJE54ZlTjdVkllheGUCSYHbp5D9ayrmRl3beKSZRZhoVF5qAChlW
m3Aa6WadeOZZ5EWJJsronhk1Cmmkk3bUZ1GABaopRlW+WWiRBXH56JFyLkrpnKOWiqqkqIZZaZ52
Gv9qpUL8/SWolP7d2imoBDWpapx0+gorsKmeamywcbKa2Y0GMfupkb+2+lKmm26q1o1bEmqPq6SO
SiqeYBIL7qSOIvtlpV5i66mzbHpKkLnntmqqnvNyihtmuNKlq1fuavlpr0hmK623BMNqrrLlpkvu
q+wWGiqWS0a88MDwHptnQ7OyBVm+e+3blb8Zt9vvmiJ7WnGxHzk6rrxisuqow+0e2izD6O6p8Mnl
xjyzuzo71PCQG49VrY9iKXkoswKL/DCk5Xq7Ks0UW8wtrDGza+i78AortcFZ21zvkjsfZLW2C/0s
IlhDs8QW0tqybXTJOio88Lx0v+o0ynhn1jPA67b/KXeqTctN7NYnd80zrzAvLTahN+p5atQOCp22
SlUidOS/bmKudLsciTs31EwD2/Sv/+yd+I6DK+r16tAGvjqyFJtuuttH810Q1wZLHK7WFEr+GGse
g/Uz3CEfDbHooT+tfEejE9464v5W3TLUILk+Z7fR4p25zsPL3rDb3LJMscrQwl4+9hmR1ZzvKHW6
tJUky0485HjXvfywdhee/ukOB/zmyt3Snf6alzfV/Wx4B/SbAnkmkAECMHeCI5+0Atg9rpAISvsb
EeXaEr3oEe9ZyBtf/pg3sb/hT3mXK95ACqi76d2PXqQjXIv4B7Pu2bBNsKsf9eJVPpxFEFLq4xEG
/9O0tqvN73Ak29LUULYyGJLEZcdD4v8YJyz0lS5xgNvdC+P1q7Ax5HsLbKAMc0hGCNYsaugLomwu
BZLXXG5zp0ui1ponwSWesICFI5vtMifALIqvbEZk4euQtb3FjSyBDMRaqQqmP9w5rY7hm6FYLiiT
4Almg7fD5EzeCD0kLfJRJ9yi85JnRyom8oj0Uxab9qYuKY4kToXcHu1oWMgy4pFePWykLkulxtiw
sSpDXMqOUlIhKDJxhMpypMESN7a+iQ+XiLOcKUH4uAnqMSFgTCQCSdm5EnJRJFb0Ul42IsbG/FI1
wVTKTqZiTAN6hFXGgx+h7vhIJx3SkDF658QsUv+y9zGwgvgUY8LsBsDzeXOMVxxOrSqpyYksVIPE
zGdUoHg9McmvkBRN1qSYaUoKinBggJRi7fjWtvyd0Zqf+2g9TchPhaYlnSU5Z1BkWpo99s+Z2yJg
/C66N3qGkpYADSjMPnm38D1PVHbE4zX1Y0njNFQiD3XokyapQ3u6sHQAfWNSpcZRkcpSj2bT5zMZ
KUhRWTGhGGpqRZ4akahCNWgMtVAs2RazXR4MbLFUnE1ZaUpHJqybpnLZN131IbWuNaJxFSZMFUNT
ckq0fUNMJrR4yr2SnjKOyfSpr+oEzUEWVigMMSytXppYxjQWU4sdyV6d1cnL9iyEJERhPaMlvqP/
GjGtcIVo5EprWt4uZpiQtUkza0fUYJmxomYNp0FvOyU0nVauvk1MiKoayZUi16jmCyxzf1Sg5xIx
utJ1y0SXW93Zcs21HNtWbsvpp9QixrtSoZa9wPtE8hIsvQk521sRq1tzuvcwLxItkPTbVrZKtbf0
BTB+F9xfxghAAAV58IMFImHgnqSXik2wfDwk4PRGZsIDqTBBJAxhCks4Iye2SIozuB/S4oSxHIYu
bn9nEBKPGMQmFgBGVqxiHts4xzcucU7c6hUi58oyxfnwj+0h4hwLWb0o9vGDdyziJofYykyu8JKz
/OQVuhhtXwYQgSHyEwz/Fstc3jKJSdxjHbfZ/82SDHKXm/xjLK/5yf84MY/zPOXZsC/DM3YMfFsq
3vUi5M5C3jOf13yRJYO4ymiu8ZqD7GQ37/nOUWZzpkXSFSP3Z8wzMnCo56vhwlwZx4euMEgQ3edI
c1nOqYbwlhX55j63uda3prKmdW3rRvc6zjcpU4xpXGp0UhXJQE72qUvsazh3hM0LUXOJXW1lEW8E
0SLBdLN7zOdFb9rbM4y0q/8M7Ll02MIIbnBMbTWmCN/Z3RPedq513dJxwzraqIY3R1asaF7/+tmt
7rWedfxuSr8a3gexd7EtdezgqhvGC+eIfB2uMX/vetE4pnO+kz3rhDMa4M7WSL/BTfJrX9yxHP9H
9bsLvuyOi3vj7L0wudf98PBGHOV9ObdWBOVojfv81B6f8sgzPfSSi/zf815x0BXe8mpPmuVpZvm8
VTtzkgza05fkL190PmQWq8XOGf84v5GOcbIf/eMmD3mmYw30hCCaIawOu43LTm95X5HpjzV23k1y
daw7Vet64Xpb9Oa7fqdY22NXe60Vf/Y2ux3mbZd0oiEP5I6XU8rO1nSaER75qdudT6NOUSYBH3jS
jxMmQGOJ4QNOcKHbeuiWD7qyJa8Qasvdy98eeeQP7uQGXvz3mE/75NC6dVHbxa1TWb2lXS/r2z++
y8+HusFjvW+B9/nKyo70m3ndbDgDX+1FZ9D/xGV+r/bsvu2Q7jn0p1/7uIMc5GxfdtSTPnJFJ57x
EBo/39lN7JpTXCYvN21y53zUt2rWt369h31RF3evh21Td3KglnW7lXPGd3yGVmBapzY2EYDJRnee
t3Zwp3Kwx2qLx4B1138HNoFS1XDkR4EouF+UUSGX1oBuloC8F3QGeID4V3Zm91v/BXo3R3j+FxL6
54NBSBip53DqN3nMhnHdh3ZGJ3zIdoTT8oPARIXlVnoviIGC9mKCh3sleIDcF4Y9aIRDCIRneIVp
qHfFt4VkdoEsKBUO+HldiIVEs4YMZ4fE1zFwGHr+FYc0F3PZ0XcVGFqFeFj/1xuE9oZ3mIJ//9hi
8ZWEj+iISXF1ljhsiciIdQiJk9ETYcaFgEaJVmeFbChmhzhabmhBfSiK6kSKM+WKEgeLOGeKpueH
6QZmqSiBGmhmlSiLQsiKVBdoLQiM71V1NoeHqEWItaiL+6eHn6WCUMZpmtiIXxGBfweNavGFghiI
xEiEmBiK1fiK67GK1wiOoBgVl+iM39iKgChseviJ08iOyFhmOqGN0TiM+eJn7bgbvihjMGiO8diL
7/iL/9iMDAaG+Fhk8GiLZtiNaFiQAskZ9viMmaiKTaGM2BiQ7jiP+hgY1MhgE9mPVSiS6EiSH6mR
/Fh+kZghITmQy7hzC8mMEemQ6MF/MUgcLf/JkahnjO3lkhUpkxvZhhlJk21kkwnZaTEJkxdpkruo
kyPpgkMJlMF4jz+plFWZFX5nlfJIlOLolL2jkgDJkFFpkVdZFklJH7Hok0cplikJlWEplT1ZcS+J
lWd5H1mJiG9pgUuplgbJlW0ZjnspjFsJkUEJmFmIimNpiIHpl7PIlIfJlnFJi4mJl4OpkLlYjpWJ
ktLIl5KxjjNJmH9pmJMImpFJmt6ojoU2l3YZJZj5mZa5iYzZkbHpdaZZlA13kAMyHrwIcV55kpB5
mr25h6+5lixJHjypYJw5iqgZnLuZl4ponMdpao55ivlFnbmpmuO4mDCIlrr5X4oJm7UJWkz/mY6c
6JxmuZPJWVPTeZnfaZ6ISZzt2ZeimZlk2YLWsp7geY6uqZnAOZukNp/7WZ/ymZ6ngZF5aZvBaY8K
ap3rVJcowqB7x42eyJ6U2ZAAWpj6qZwJiqD16KAPip3XWZbv2Yn46Z4fOpkjCqIlaqADipQqim4S
mqGb6YUvGqG8iYsiipDCyZ8PGZ6lKKOlOZwt+psc6qN5yJ356aI5yhN3maIa6p9fWZ5DCpf9aaRp
yZzbuCLRqYbNKZ7LCaW+KR4QOnpLCqPKCQBguqP7GKRKCp91saA1SqYmyqRjSmtuWqFPWhBoelgA
cKdOOqU8yqUXOpVC6afVGad2Sp9USptU/xmjgfqjj3qkaToQewqkGFqogPqmdaqjjkqkNUmgVWqp
RSqqgkqq6ISmAJCqlCoQqaqqrNqqFtGnCPaUYFqEeWqqkmql9AiqoxqpVzqpDFGpNqpaqLqnrlqs
ldqqqfoPyxqrziqrz6oR0HqpnhqgelmmwzqjaYqhTWom5Jmmyiqsr3qsrdpAzXquzAqt0xqtFyGr
fTqt7yqthkqnagoccDqvZlodtpoR6/qfuiqt9kCu5RqwBDuw0biuCIsR7tquDAuv8uqwzJquyhqr
BmuUmzqh2CqnmYqn1LGv2kqwenqoKGGwxfqqlDqwzRqxDBuxKRuvK/uyzrqy6tqwCkux5f8qrMYK
sgiRs4O6mbT6r4zqq42Jq+tjsdKaskHrqf0aZ8rKqgHrqnoqs+66sA4LsTHrsuwaszCrss6qs8mq
swVLEKgqtk6Ls2DrtEDrrxsapq15q0LLHEbrtqv6p5vJs+E6rpUKs+86szUrsy+LtSzbt1fLtSxL
toY7t2j7tWVLtsk6tnNrrCSLtPh6ovc6uRp7HV1qbBwBq6WqmUursCcLtWLbtGjqt1UruFobuFu7
t+iqtawLq2b7uGDruE8bsocLsopbsE07ro0qty6FqJxKJVvqpbfLsSJRsqN7s5ALu6hLuIBLtTVr
tan7vPwqrl67qtYbu7Ubtth7swaxu7v/+xGf+5i8Qb5CirnDixY727uEp7jgy7ifO7V667z8Gr19
S73hCq1ou7iIu7+4i7i0y72h+7+x27yhWrzAg0nVkrkbJhPiSroou71/S7+nu7nTG73hWr80e0U5
a7bWe7sB/MAmu7/ui7IdMb7z9cEzocJy2a3xWaDp+xIonLq5KhHIGro867XySsHxq7IVnLU7DK/v
mxAefLL8W7vai8P+m70z3Ktnu7OiixcuPEw0mqQCWhJN7BP6mxNFXLEjrLpZi8ILu8Eb4bI/XLjr
O7uMW7yNS8CJq6rLK6w5+bRRnMZrmozbOlVS2hJZTLgb+73fC7VxPLa727/IC7YUfL+B/7u0YwzE
aOW4RYy9J3zBgVzHdIy7fVzDvvETmcyinYqldxwSmXy8x0sT7xu5Xuy+aizIGgzECUvGPrzIB5HD
AhxzfBvG70rE/kvHo0zDnYukAMnCl0utwpEU/drLavvEaTzE16vLgqzGhmu/sPzKrswpkZy4YcvI
F7yutou3A1y6xpzMUpyUwty7yGy5tCEU5+wR3FzOClHHN+zNRyzAuTvLq4zAJLvKzXvGcszPE5zC
Sny2rcyms+zFMbyrCCyyJ6GuE3vAWugZjazJujy6uivPl4zNFD3PHWy4hKzMd3vNOhvEfky9grus
0ku/Emu162zBvnutMMG5eejO+UrKNv/LtzDtvUmczmbxyj3MrPaszAtRyHd7yYcswl/LwiC90bLb
0e/izydt01xr0gbMvBlsvtk6jDI9eE7xwVm9tSkxtcecrrWs1GMNzbaxiJcowg1RsR8tyIVsz0lt
1rXMy4DcvU0LxrEcr2FNsYnM19Vr01K9xcEaoujcwnM6y2VMElUdref61kf8wEfN0WfbxjktF6y5
wra7vN37089c2WuMvZ+NtwKLe9SM19P8z0er1/cr1fX608G7wwT50F+dsYmKxUg7sQ2d0nYLv4YM
yEgd2v970UKd0A0KvGIEF7lLu7td13Gtp6T72dU8yfsszYOb0iUd20LLzWv9Jy+V1Vf/DRKBDdZU
29icjc8YrdHmfdEgDM1GHdqWPNMOvajxHRbJ/cS0LLt2DdPbTN2svd+Mfcy53dDfCsXvHcom8QEf
8LEFttKSa92na8RLvL3BndnpTcsh7Ni7rNboTc86bLN+LNHybaEUEcK8m7iJ3dcsna5Rjb9/zdDq
OuCnp532gOAhfsIN3tBVy9XdXNERDtr4ndlDHeQRnsTZ28wA3K437eE268nChp4QRdJ+++GxfNp/
7cOsbdBEO7RtquVpC6kMieBfzbmsi+QZDtwBzMZmnrze++OSvePLjcS3e+L6XdNMHprZ6BIJC9US
m9qrvawwvuWf3LaE2uX/gOCGbhFg/17oCa7oiY7Wvh3Z/XvPPl7XvU3klD7hbf7YDL3ngJvSE5G3
5Iips93nL/vnV9zSeCgQNO4Qq94Sif7qi27ojf4BA0Hjtk7rM47rqz7YkUzD/AzUGl7WlR7Nkuvi
Lt7aLwzeK+mWJfmlPTvfWSHrBGHotY7rw/wRsI7osb7th74/q/7ttL7rt34RYC7r5G7tGpvBPzzZ
aQ7OA62ycL66Yt63dc7OUYqb8O3EYmrcMrHr0y7tuS7run7u2q7oBt8R5S7wGyHw4K7q4W7t/j7j
2s7wBV/wDJ/g3X7ujY7Wcd24A421/Z3aYK269d6jvyEj/vjs+j4XNJ4Rs47xi44RL/9v8TAfi7eu
6+he7Q108dtO8OY+8QrP6OYe8QGf8w5vp5vuzy2O5Kpd8ib/nFOsLxcbFq1+Ehu/8DXv8hCP80Vf
nQlP8Brx8hR/8GSv9Qx/9AUx819/8Inep5WM12Dt9J+K3K4NEYq7IU4OrDiB5XVP6EIf80H/9wmu
EDdP7bkO9n/P6Byx9mWP+Dxf8Y0v8z0P+QkP8A3f9bucxzK+GTpOsCPByOh60w1etDbh3XbsECst
+T8f+JV/9OL+8DqP8DEv+WR/9UIf+QY/82E/+9lO+bOPVpfv8IY/4w7MvsUoFqbfoSm+zzgu5swb
1SoexmOS92Ph3Xv67uCt33ot3jP/9PoG0fBqD/hZj/uKj/W1//tfb/u5L/7mf0XBX/RGTxM8P/+G
nvr3vhfJf+0LPe9JDvciDRD//gEYKFAgQYIGERpk2NDhQ4gRJRq0V9HiRYwZNW7k2BHARwAdMzJM
OPGgQ5AIQSpcOTCkvZcVQ360GBNmRYEfPhjU6bDnv54/ge7UWTTozpxIGwp9eJSn0qRDpTKsqNOe
1aofNhYV2dXoV7BhoZokW5ZiV7Rp1W60uXZjQbMNW5J0WTIlSrofFZ4sWBIu3b8L9/pNODeuRLca
D09MjJHv47iF57ZMifGlzbY3YUIWzJmh0J9go4ImOnbq6ac+lR41ihHr1deNNYql/w1WsVnZOHPv
5i277WK8kynvDSzX7l/kyDvDLaz84N3ihJ0DPts7N3DsZP2elK5S4MXMM2vKxAlYuly+3Umm9Ev6
dOjSqd3D3+naNmyu1vHXrq3f//+uMtMIpP8O2+64upojjqUFB3OwQefOa3A5BSmc7jjMNCMvJgEB
VOufArMDMTwNb6LJIuoeTJE49iSDTkHuVvwMqaKmqlGq17D6yqL7cuPvRw+DFJK3DsF7S8ThhDMs
urxWlJBF5hJET8Xk1INyIA1p4vCy8dgjbzyYTvRPRBCHTAyyGKmckr3nEFwTryvtsnCvi+6zUyve
fuTPzK7i4pNIMEVK7qHtWNKrzf9Cp+wLQxkFsxLN89js67mIHi3IyC4x5TJM8TjNslPeyAyVTFLh
bFLNUyFFM71U9ZJpJi1L5LRI2NDSs78/ORI1V45oFVRGkzo78K5DUx0UIgufTNPSA41trrlAv9wQ
U/AInJVDaaPtU0ReeSW10GQrDUxYviyryVpPfUXrqVtb63Ykbt8NMbtDiV0UURXBpdQzZVFaidng
+E2xRFDFxBbdaC9D+DpFyZLXMW5LlXjCx/TaTtNYPT131Ox4dJfPXR+27ts2CU3yy4PdjHJSOAlj
s0WJGKXy4iyN3NJcMAnEVtsz462s25AZnjjkn18VT921gn5YaZFl+1ZJQx0yUdv/DGliNU3PokwU
xkETJbTMjKd9dcBqDQ67N6bfTTvptZvmGDu37Wk7LaR75Xlb7JJ0UU6Lbc40W7mXa3hOmRGtF2vz
SPI754xgnTrns+9eN96m556847gBtBxkykWuu2zBF1Nvyb423Fnsmow9lsViDf03ccQLrZlsgou2
nfbrvHbY7c1/heD3xTLXvPOlifew7tPP9VJ3ZJtPcKEls3UccKtZFni9n6E2VVVFNTuYWu8l39St
DkX9fHjMhYYIAofYpwiCjuAX/rah4+49wNwEHJ/+4pznrljoDOxvpktYhJz0ncdJT1bMa5ZcZpcw
gm0MVEbTX89iFhH7Gc8topKf/0Y6aBH5hTB+8+OfxN4GHOGd7yLH4lrLXuc/lwxwgeCZWYROVDXw
aSZ2qsMh6kikMctYS4W6WtXuKpc+p5Hld+6jypA+WJEPLhF+UgThkO7HNiS+a4jwYl7MDPMyAGYs
eTiTibP8JcYIZoiMCdTh9fgVRHTFUUxjotwWTxi83QAPbiLp4BN7E8IlVhEjIrQHIaF4SCJm0YIT
IyFbHFkqlfBNkt+pYJi0tbLVKcdmXvII6thok4rNiXUHgeOW5qg+FPJOg1gEjh8B5MqMULGQhfwd
CAM5y0Ei8iIi/If7mNhLgfxSarsZWqmsY8dgNY90UroXAg0WQXOxMGsskVaR1P/oSUE9i0H9qsui
SLewRabyiIrcoPFgGcs/zrKWuwzkFGm5zl3Ssop+FCYw7ckQXwYTilI05JH2SMz6AbSLlZqklOxF
tU1CDGDokRXKMNYppGHGjClC0OueZDeMFlNtq/xQWepZJv+cM5dRFKQsSQrPXB4SnvVk3y9b2r59
3pKeiMwnHhsJUCT9a5neAVvjHFotCFnKmZvMXvZo18MwVUxcFGOmcU7p08ZkBlg2TSI5WSlOjvRT
PzK9pS3X2VVdunOeu7znQ5j40u8Asp3xfCIwXRrM9sEVlyTF5U3LU0zM7S88CltVhRhKvcVBFZsR
lKYBF2SxpSJQSL5K7NdAWtX/f0IWqyOUjVZjOtOvyrSk6CypWe35ViaqM6tjxQla4Qrahoh2n7rc
bF1lWVcP4ZWjablaX+nkPaPOEKEyLA/A5MQgp5rnqRt16kDveJjjxkWkueLnIKmoWUHaMrrqjGtD
3tpLD86VrSgybXXd+j7XilWlnF0rbGmKttkWL68KJOP3GDfDoKrOdQXtJkEyaNWO4pe26e3KcvkI
W3d+VZ21xO50adrHQuLTugo2CPveaWAAQ9GzNT1tg8XLWdUeOMDxfKd/8RZZ9ZqwN3oVbEiwdrgq
NQxfybkviMNJ1cYEtFv0XGlXlwjXBvcStGctK0txfNrmcviyBM5xWX/82Y0g/5i0403ykpOLG1Xq
V71c05dS67vNf7V4si9GLk5la2RSZVWzNpbigiucY2GiVsEujXBKTyqR6+KztULWbna92keUxpi/
ZvpyWWILyUhu7bYiu6I/XVxO7Hx0IopuJVgjPMV1RqSlPI7zkXt8T9ZeOMMJrjSOQUvnNmuYnc5d
aZMvd2ig9dkkT1Y1YqKM6v1K+cOt9m6iawlpBOMahEXmtVt5LOlLs5nUQxbvkbv73QaHl7wcfq2B
m41KS7t6nLR+CKupPcxpbxnRsI51o69t3Zh6sNS0BHKRJ41mBve6uw5mZ3mZLOH1gTnN0n3ihdVq
3nBDmMt+wjDnvp1aL/9bsf8kLHQJYbzvVsI5mGUWkVpFSOYb/5rX+VSzp4MN0npvt4rpRvaZLU3p
NSf7wZq2d79nfXDiCnzgelb5yhHe8seynNvrYjSji1lzCsc83x32qrF1jG6ge3bBoS35pt3Z64sj
/azrvmeeH3xZr97R5tgmNMx1vm2VW3vVNy04vBpe3alzkOcjZa13mZ7mkAcdmE8f9ruNLuGK63Hi
TH/sWunqaJmn8tn+brnWVe13qws8VC2kto/BDHC21ljACY72ZxfOcKWnvUwn1Thr8b1ZPF+648jW
9Mg73MGI7VlIgQf8l0sf+Guf3nmE5+fE8txciMt94WqnONKbbtZYZva5KXX/e8kl/uPap7XNRddj
2MOO8lT3PeCCXz7qnf/8qbYMTWh//J1Vqnh5z97jRq6440H9+Zk2OfxyS7rHgcf2dpcUeMdX+KKr
/eqsNz/18od+/e0fGYdtqi2uhB/tf759w+u+jJunIJMny+M9skq3sxM5k2K2WyO/r7M1tPAwrGM+
/bBAybo/DXS5zNmVojqln1mZ7fgouVvAoMO3fsI1p6M8dPo9sGuithu7dwo8Csw99FK+bEO+/NpA
HlQ9WrsjwnsTTLKwG1u769s9Jws/FoQ3ddM8B8MzU+sw0msMvEs5bUu+mTs5Hrw/H2Qk9JGYIKSL
8GkosnOyTAuvF1S7fnM4/0SaQrvqtiv0FtFLpC3cwC58vj/Lq9wqJf1Li6MDwPK7PLByODd8Qy3k
txzsMmirw/q7Qzw0RN/QFMG6CRE0M3SLvTOcQauDxFOLw1zpOohhRA10ROcjRbsaF9uilDHMjCCT
vfjjxI4ARTqStV8RRS6kP1EkxauDPzzSmY0pG0pMtDCDxVg0Pb7zxE60xUdcRGXURVPkOpirwTcs
xLzrM0NTxmXMQGx0RlxstSDZxNyQxjzEQW3ERnP0Qma0RW5MR0b8xjk8RXBkx3b0unNUxHJUx27c
Onmsx3gkRoP7Nl2kxpfjx/ejx3Ncx3skSILUMgysxmbMR4X8Ozo0xn1kDP+IjEiK9Mdk/LeA7EeH
xMgfvEgMEkmI6EiQ1EE4PElaLEZ+NEmV9DOSLMiENKKZfEmNikmqmx9ZRJGFxEkZ20iBrECJ9DKX
tEl9rEmLrLqbrMge9El0REpp+8ecHEhvTESjlC2EDLGr5EinFDGmHEmrnL+w3EqvhEqwVMpXnBdy
/EixNMuS5EWu1EiDJEuZpMqkRMu01Ml3lMq2ZEuYHMuQlMtQpMu3/MrC1MqGtMu4dEu8ykp5CUq5
JMyo9EuaRMzFVEzJNKau5EAszEvBhMDMRDzGnEorTEyhDM2lHE3RtEyAzEc+Q83VxMzDZM2+lM1b
/MyJRMk/gcwdRMZDzEz/xyzNy7RN+ytK1GPI4TxNKDNMmwzORhpK1YQ+58TNkfFI4oxN5ZTM6fTH
nbyretxO6tzMYWRO0rwq2ARPWOxO0DxI8URO2ITB6KyO+MRI9ORE9VTI+rSivVyhUSRP7DRP1MxP
Q7xP40lOAEVEvNTN8PRP+KRMshTQadzPwfTNioTQcaRQ/cTQ62zQDaXP9lxQ77RHB71L3FRPC/1C
DdXI9+TQ7KxMEBVOBC1RCZ3FLHzNlczNFZXOD31R2vxL6jTRHU1QEe3QHIXOEZ1MHlXRBSVQBpXP
HnXRFi3StSTSXUxSK3VHEp3QIY1SI33MGeXJ9xy9Lw1RBb1SMzXOLT3Q/9Z80qM8Uild0/ms0jOd
U/Ek0JZsUs7szTd9UzrtUxr1TC5tSjyVU6Dc06p00zT1U0XVUwNl1Ic8RhZVU0O1xq5cVEtVS0CV
1HkMz0nN1JSMyEuNUJhD09uExk6FU0TV0VDlTusM1Kt0z1PNyFQFyVWVw1ENUvYEzFj9yVlVyTg9
Sxm91UEl1eUU0l3FyjrtyUFNTTbtUledTSoF0mU9VijVVLo8UftsVWvN0mdtTLik1pwsU5ZcUWzl
z0ktVzCdUhgF10i1VXIN0l59UPUhAHoVCHolAG7dVkrV1S10VGn9VWWNU2L1UX1NUY24V4ZA2H9Q
WGy714pw2Fr01E8M2P94dVIvFVYtlVUqHdhqXVIRgdiHpdeQJYBrNAiG1djONEd0rU6Mrdg8/dQY
jdYxrdV1UdiTJQuEvVedBdaLzVWB/dba7Nby9FeCldkbFdVEvcHssNl6tdem1VmIjVqRtdHvhNd1
pbaVXU9xxVFU/UxZ7EGpJdmRtQeptYiw/c1ctNqrPdSfHdZkPVp4hNu5PM7emNqpHVuQhUCmxdd+
VduUbVSYLdaNfdsahUQ7Ldy5LUs9g1q+dVp8ZdyFdVzJddaChda1ZVtIJVS0HU+uxVqPlduMjVmh
fdmOhFyTfVrT3ds2HVx+3dcfLdLPRdySTdpCpVyWJZOdTdimPV277V3/sR1Xg0VR04xM2I3d4DVX
2eXLvsXSf9JZjMjbkZ3cm63LnpVYYpRSED3c40VelXXZfM2v3OXdhUVds71bqBXTlvXa4mXH3ZxZ
7e3ey8XYuy1fsWVcjl1dwcRevyXajg3coh1dVTXW9I1f1w3Wd3VbBG5bgB3gvxVd4x1eFV1fBfbe
rMVPoP3fyrXYP4VgVr1T7qXI96XdzcXfDC7OC+7f2g3TB95GwrVeQQmx+7XdiQXdD9ZfTqVYo1XX
UOXN0NVcqt3edGVXFM7cR11gHf6QFe7a/HVfCebfEMbHaWVgJ/7eGT5i/6XeCm7iKo7VFubgFCZh
d3XhiAViMhXhMT7P/xNW4SgWY+DdWuZl484dyicGzjRG4zWG49l14C324hFeXiP22WY14QHFYQDW
4Ab23Dvm4zMO0DoWVIIj5BL+zzBW5DYuYu+14Na1Q5/8YUqO4yHmZMD9Yj++ZA8W4LRN4CmW4isG
4z0O5T52ZFKu2kzuT1TOYcVlXVMOzD/u5FjW5FkW5AnGZb2k4QvU1lT25Vze1EBGZmFu5vZF2UNG
5F125UHG5GCuYWZ15kg2ZJotZlUWZVhW31J+Zm5eZSoGZ54tZNLNVjNO5Hb25DrMXkiOYGIuYz02
ZyRdYiXe4HfOYyh+3XEW56d85XTe5nK+XhauZlkG6IU2YEDWZnpu6P8OnOcOlmh9tmiDXmd2xuhj
PugYzmfiDeiLfmh19mHDpWh01s4k/meHht9rDmmOxufQXOlTZmiSzmiTRt+CDmKX7mU8tueBrt6E
tume9mZWJmc1nuZ97miNbmRmHumiXlUbVuqgxWk39mlejtublsNffsmPhmamptsMtWKEFulJ5lXl
NdRKtmRbFuKjTk+UJmK3nmvLtWq6/uSTNuuzvutv1tpG7GJ2VVRrXma+1uW27ue0LmwZFp7BFmrF
JmuCRlaqfux7TuZRdmzKpua1ruqwzuyglmtadWrP9tZJBmoMTunR/uxojmmkTm3Orui0dG3BJWDV
tlLZzmpThexFpmv/WDVs1L7qxL1tsIZt3O5ht+5t3wZl4dZr4tZseF7seBZt0rbs5aZlonZuf5Zm
rEZs4cXuC73q6r5lqPbu4Nbuwa1npf3p7q7s9XZtee7r3X7t35bk5l7qVmZvqY7rjVZv48Zrni7N
99btsSbjiZ7t77bvshbw5wbpbsZs+QZt/0Zatb5h+N7s027w1cZcB7/wBFdmDLdwDS/pD0fuEM/w
c4Zr5u5mHp7vdh1xCC/xvTZwmN7qBl/xyMZiF29t8sZU4H5O/R7wPc3aHJ/st1ZuGY9oGtdx/Mbm
v67lIVfy4hZy6QZmwsbxzl7sGx/aJ9fpJM9y+kZx1n7xE49vDq9y/y3f8gNnaxEnyp5x5wc38jIn
8whPb8lGcyiv6TRvcRYX7yuv7Tuf8/IGdB4fczuPcTwXaP5m8lI1agKfWQtN7h3+cYVOdJ4eagre
3/uOcxCndMaWdAmP8kpXc5yWcicf9T4/8kw/9PFGcC8P4EsvdUMXdEWXdTqtR3649QAHjlt3iFvv
dX7YaZlm7TnWdC7v8VkvciBXyF+v8IzodRKfCF9fdoOI9l4XCGq3CGp39pImTFJ/6VPP6TfGcjo3
i2pH72dfjGyXdmvP9otId3evCG23B18f9Kg29a7+8lb3aDin8nAnd1wXknhv77JQ92r39XU3+Cp9
d2zHiHifd3l3+P+H54eIZ/h/P3ZLz/emXvDh3vOM73fKzo2A95CQD3Vyn/Zsfwh2h3d2T3eOcHiI
b/aKD3htP/h/cPddR+ttZ2Jmz25av92kxnhUF4mRd+Jy5/VoN/mjZ4iGZ3lsV/iXl3mJ3wioj3qc
OHmaR3ql33WbV/eOT2xx3/Sv1/i6jvVrHfKixw5qR3qEr/mUj/hob/eY13aIn3qVp/q6D+6zz3ur
Z3uCv/m7H3qv120bl3NkL3ZGrm/oK/i1V/ubP/i3d3u5j3y7p3iqX3q7l3y4v/mz5/vGlwi9l3bL
b/rL/3ea3/xj7fbtFvU5rUObF/1rV3m4F/3Mn32pj3vQ7/xy3/r/q8/6pK/90Y/6z8d64b/6ze98
D4X1VOd2DF/0tZh723f9ifd92S+P4k/73Q9+zn/56If5eYcI7C/6tcd+4nd3fl/zez/JD2f1uAl5
Z2d/XE/6hgB/45f/vQ/96Q/5+Dd+o799/ud9xwcIfgIH/itIsOC/gwYFIkw4UGHDiBInSrRn8SLG
jBo3cqT4jyPIkCI7eixp8iTKlConjmzp8iXMmBlX0kQJsyZOmRchOuTX8+HDn0ERKlRoceBRpEn5
7WS40CdRpzwdPo3otCrWng0PAgUaFWpWnA11ki1rFqTYtGrXVrRI4O3ZuHJdslV7ti7etTwJdvX6
0V7XpkyXXsQK/7Ho1cOJr2pt/NVvVsVgE66dS9am5Zl2W+bNO/ItAYygRcPNbFpz55V3N58um1ap
YMACQ1pdDFYyVMS2v2613ZV37aFsz/YtPhu1WMs5za59m7b06dEXpbuF3lpjapqr017fmJ0l2b0M
p27tfZsx16HGz7M3H5zx8rLr58Ov2f2+xe8nqevkn5k/gNbRpd9J2yWHH20EKiiRZMBFJRRu4xln
HmTkqWYWffNVhuB1C5qkkX8ZhRjTiC+BJmCAodlTEGgeRmSgfRyS5CKHr034VF8QToZjbuntiJl8
Gd7InYynueiRaSVWp2JZJzo5HVxOqthiiwhVyaJzVmZ5oWusFf+J0ZEb4mfjbwyWORxsMAk55IFf
KhcmXtcpac9oU54o4pN0Xrmncyc2tCWfBPyZ5ZIyielmfnB2hmiCONWnXUzHybbmmW0yCqOihyIq
nZRMQlkllYAKiuWogWop6JX/ULeqddKRGuOlmXp2qZFe6kQpm5DSyhycqRJJq5SfQuekqln6GhGo
oo6KrLHKnqqnp50Ou2Wxoxb6paxx0potRcThCplKQO2KqVrHrpTsslXumieroUlZ7bLVygvvq/N6
hO6pp/pZ7af9pgjSv+RyqyujmjaqIEbf/kjwuIYOPGi8H4JYWrtyTetunhOXiqqz+9prb6jpNhsx
s3Z2ei2nF/v/26qAL+X7sEq7GtwhzBI3rFPNll47ksQV3wnwz9Dm6/FE1NYrb6pJd+wcyi2TZvJG
FUPbb6H8gSxyvEqTjPC2trqZc0E3XwY2ww5DnBLUU0uLb9F9jjy00SVLZKq6Uwv7pNRzpuwp1Xab
Su+x77589K8Fe43t4TMu2DXZMfNK5MkaL1kv2/R+PHjIcG/9LJ5M1slytE7n7fSnmHO8sbJuv2uu
zl8nLuPMN6Uktkh4mcv6uYQ+LtbFKUI37+1vF/vy35cfHfLKfHc+t8oB7/z0isDHfba+qRNdOKKx
w/76gB5u/3DwW5P4e7kZZwytn2xnfvXmI3tceYvP9/051sZD/yx51aURfjX71be9ueO6VCDFxcdw
2DNb4xK4OPkxMHrPwdvegka09YFqcKY7nQUhJi2qVWx/x1Nd8kKyL9WRCoMZhJfwuMcZbslMhTxT
IJDEpr3uhQ8858Nf+jKXQ9RRD2lxE1z/pKaxKL0vheoakc/cZ7+SWW99M1xhtlp4wJjAMIY4mx3t
0FK+oD0taD4EoPreRjdqjTFY6KNfsIrHxNOFLm12e2PnhIbCHXJNgLKSYuuoWEWbjc17NdqMGTcI
JQ8CzojTkx4Pv6i5LrILiCW0nxCHiD7ovdFVuCOWlZ74wjsyLo+y2yOSdlfFLKJlacJzFvPqp0bq
7S1/niNi1rYOqS/JIRGNQHtlLLGGSU3WjoWdhFUfQQkeOwqzmLYj4atW+UE23pCDp0TmFykpQlg2
7ZX56dS9ZFk2PUbxl8P5pDERIrBwThGPDyRWGfsmTfqhbWTVrCQ114kxO1Uvl7jbJjgzZU5yDmyc
/MQnKV1ml1YmsX6pXGRLWum3eO4tlYHSphURuMda/fNh/qwoFgOKnDqSpYwIheP8KDYtjjQUkXME
IEC798+LYtSPxGwpMDWqRZQEBAA7

------=_NextPart_000_000E_01C75C34.F8373190--




From owner-ietf-openpgp@mail.imc.org Thu Mar 01 13:28:50 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HMq1K-0004l2-LP
	for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 13:28:50 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HMq1C-0004lK-Uj
	for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 13:28:50 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8x1t054493
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 1 Mar 2007 11:08:59 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l21I8x2b054492;
	Thu, 1 Mar 2007 11:08:59 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8vZA054485
	for <ietf-openpgp@imc.org>; Thu, 1 Mar 2007 11:08:58 -0700 (MST)
	(envelope-from dshaw@jabberwocky.com)
Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56])
	by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l21I8hZ00380;
	Thu, 1 Mar 2007 13:08:43 -0500
Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28])
	by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8cqo015067
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 1 Mar 2007 13:08:38 -0500
Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1])
	by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8a6K022649;
	Thu, 1 Mar 2007 13:08:36 -0500
Received: (from dshaw@localhost)
	by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l21I8XxU022648;
	Thu, 1 Mar 2007 13:08:33 -0500
Date: Thu, 1 Mar 2007 13:08:33 -0500
From: David Shaw <dshaw@jabberwocky.com>
To: OpenPGP <ietf-openpgp@imc.org>
Cc: jon@callas.org
Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt
Message-ID: <20070301180833.GA22614@jabberwocky.com>
Mail-Followup-To: OpenPGP <ietf-openpgp@imc.org>, jon@callas.org
References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org>
OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc
User-Agent: Mutt/1.5.13 (2006-11-21)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: f66b12316365a3fe519e75911daf28a8


On Mon, Feb 26, 2007 at 09:21:17PM -0800, Jon Callas wrote:
> 
> I've submitted bis19. This should be within epsilon of complete for a  
> whole lot of epsilons. It has in it text to address the IESG  
> concerns, as well as the IANA considerations in a brand new section  
> 10. The *only* thing that there should be comments on is the IANA  
> considerations.

This looks really good.  I have a few minor comments about the
additions.  This might look like a lot, but I think there was a cut
and paste error that explains some of them.

*********************
In section 5.13, in the non-normative explanation of MDC:

The sentence "(Note also that CBC mode has similar limitation, but
data removed from the front of the block is undetectable.)" needs an
"a" between "has" and "similar".

The sentence "Suffice it to say that many people consider properties
such as deniability are considered to be as valuable as integrity."
is a little tangled, language wise.  I suggest removing the words "are
considered".

"OpenPGP addresses this desire to have more security than raw
encryption, and yet preserving deniability with the MDC system." is
also a bit tangled.  I suggest changing "preserving" to "preserve" and
adding a comma after "deniability".

*********************

Section 10.2.2.1 (Signature Notation Data Subpackets) says "Adding a
new signature Signature Notation Data ..."  The first "signature"
should be removed.

*********************

Section 10.2.2.2 (Key Server Preference Extensions) says "OpenPGP
signatures contain a mechanism for preferences to be specified about
key server preferences."  That's one "preferences" too many.

*********************

Section 10.2.2.3 is titled "Key Flags Preference Extensions".  I
suggest removing the word "Preference" as key flags aren't really
preferences, and the rest of that section (correctly, I'd say) doesn't
call them preferences either.

*********************

Section 10.2.2.4 (Reason For Revocation Extensions) seems to have a
few cut and paste problems and is co-mingled with the section after
it.

It refers to "the feature flags value".  This should be "the
reason-for-revocation flags value".

In the same section it says "Adding a new feature flag...".  That
should be "Adding a new reason-for-revocation flag..."

The reference to section 5.2.3.24 should be 5.2.3.23.

Finally, the sentence "Also see section 10.6 for more information
about when feature flags are needed." actually belongs to section
10.2.2.5 (Implementation Features).

*********************

Section 10.2.2.5. (Implementation Features) has a mirror image of the
problems with 10.2.2.4.

It refers to "the reason flags value".  That should probably be "the
feature-implementation flags value".

In the same section it says "Adding a new reason for revocation
flag...".  That should be "Adding a new feature-implementation
flag..."

The reference to section 5.2.3.23 in this section should be section
5.2.3.24.

The sentence "Also see section 10.6 for more information about when
feature flags are needed." from section 10.2.2.4 actually belongs
here.

*********************

David




From owner-ietf-openpgp@mail.imc.org Thu Mar 01 19:23:00 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HMvY4-00057E-Fk
	for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 19:23:00 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HMvY2-0008I8-3a
	for openpgp-archive@lists.ietf.org; Thu, 01 Mar 2007 19:23:00 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207NQl079627
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 1 Mar 2007 17:07:23 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2207NgS079626;
	Thu, 1 Mar 2007 17:07:23 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207M4s079619
	for <ietf-openpgp@imc.org>; Thu, 1 Mar 2007 17:07:22 -0700 (MST)
	(envelope-from jon@callas.org)
Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161])
	(Authenticated sender: jon)
	by merrymeet.com (Postfix) with ESMTP id 406F056F7CB
	for <ietf-openpgp@imc.org>; Thu,  1 Mar 2007 16:07:22 -0800 (PST)
Received: from [10.240.72.119] ([208.54.15.1])
  by keys.merrymeet.com (PGP Universal service);
  Thu, 01 Mar 2007 16:07:22 -0800
X-PGP-Universal: processed;
	by keys.merrymeet.com on Thu, 01 Mar 2007 16:07:22 -0800
In-Reply-To: <20070301180833.GA22614@jabberwocky.com>
References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> <20070301180833.GA22614@jabberwocky.com>
Mime-Version: 1.0 (Apple Message framework v752.3)
Message-Id: <96F3CC13-7B61-41DB-BE4D-78B33A4D2D3B@callas.org>
Cc: OpenPGP <ietf-openpgp@imc.org>
From: Jon Callas <jon@callas.org>
Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt
Date: Thu, 1 Mar 2007 16:07:18 -0800
To: David Shaw <dshaw@jabberwocky.com>
X-Mailer: Apple Mail (2.752.3)
X-PGP-Encoding-Version: 2.0.2
X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit
X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; format=flowed
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7BIT
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.3 (/)
X-Scan-Signature: ffa9dfbbe7cc58b3fa6b8ae3e57b0aa3


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>
> This looks really good.  I have a few minor comments about the
> additions.  This might look like a lot, but I think there was a cut
> and paste error that explains some of them.
>

Yeah.

They're all fixed. I'm submitting the resulting bis-20.

	Jon


-----BEGIN PGP SIGNATURE-----
Version: PGP Universal 2.5.3
Charset: US-ASCII

wj8DBQFF52q6sTedWZOD3gYRAoANAKC2aYeLwv6Il4tc5z/jO9CdCI7HIwCgs4fv
n+ca/0oqgnlUfhSVbkaTnmw=
=pkVx
-----END PGP SIGNATURE-----




From networkshawaii.com@ffissy.com Fri Mar 02 18:09:44 2007
Return-path: <networkshawaii.com@ffissy.com>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HNGeS-0000RU-7N
	for openpgp-archive@ietf.org; Fri, 02 Mar 2007 17:55:00 -0500
Received: from [65.112.166.5] (helo=localhost)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HNGa5-0007XL-IN
	for openpgp-archive@ietf.org; Fri, 02 Mar 2007 17:50:31 -0500
Message-ID: <000001c75d1c$0bb18800$0100007f@localhost>
From: "Austin Morris" <networkshawaii.com@ffissy.com>
To: <openpgp-archive@ietf.org>
Subject: She will love you more than any other guy
Date: Fri, 02 Mar 2007 15:50:29 -0700
MIME-Version: 1.0
Content-Type: text/plain;
	charset="us-ascii"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.1524
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.1523
X-Spam-Score: 4.0 (++++)
X-Scan-Signature: 7bac9cb154eb5790ae3b2913587a40de

Several millions men have been helped with the potent ingredients 
in Penis Growth Patch (TM) - men have experienced bigger size, deeper penetration
more action, and super-satisfying results for themselves and 
their partners.

Don't be left behind! Take advantage of price specials going on now.

Click here and visit our site!
http://www.gerax.hk/




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 08:23:48 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOZds-00048F-SN
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:23:48 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOZdk-0002gi-D6
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:23:48 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26CspEc061037
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 05:54:51 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Csp5L061036;
	Tue, 6 Mar 2007 05:54:51 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Csoiv061029
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 05:54:51 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1937128wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 04:54:50 -0800 (PST)
Received: by 10.70.131.19 with SMTP id e19mr7986508wxd.1173185689787;
        Tue, 06 Mar 2007 04:54:49 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i20sm10249934wxd.2007.03.06.04.54.48;
        Tue, 06 Mar 2007 04:54:49 -0800 (PST)
Message-ID: <45ED6495.1040407@buanzo.com.ar>
Date: Tue, 06 Mar 2007 09:54:45 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: OpenPGP Signing of HTTP POST
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: f4c2cf0bccc868e4cc88dace71fb3f44


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear OpenPGP WG team,

	One day at 3am in the morning I woke up with a mix of two strings in my head: "POST / HTTP/1.1" and
"-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about the whole idea, and as I
couldn't go back to sleep, I got up and wrote it down. A couple of months later, and some BIG
thinking, I decided to create a Firefox Extension to implement what I am now going to describe, and
what I want to rewrite into a proper Draft:

For years different methods for User Authentication and Session Management have been implemented:

    * HTTP Authentication
    * Cookies
    * GET/POST values
    * SSL with client certificates
    * A combination of all the above.

Regarding SMTP, e-mail has been digitally signed for a long time now, and it is a standard.
Extending its usage to the HTTP protocol sounded like a natural idea, specially at 3am when I woke
up with a OpenPGP-signed HTTP POST request in my head.

By having the POST payload ("variable=test") signed using an ASCII armored, Clearsign, OpenPGP based
procedure, the browsing user can provide Identity Authentication to that payload, thus adding all
OpenPGP benefits to the HTTP POST request.

This allows web developers to add a new layer of security to their applications, and if correctly
implemented will render man in the middle attacks useless. The direct benefit of implementing this
extension is that web developers will be able to verify the POST payload signature, potentially
avoiding obscure session management, and/or complicated login procedures.

For example, Highly Secure Home Banking sites could be created by using Enigform + some simple
server side code.

For a demo of an Enigform-based login procedure, with using AJAX and FORM SUBMIT, configure your
GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar.

Enigform: http://enigform.mozdev.org
Latest Version: 0.6.5

Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html

Hope you like it!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7WSVAlpOsGhXcE0RAt88AJ0cyBuMS/U0qZjwTZ9DrnE1jxRmUwCfdYqN
+GAVdVxL/NfUvvvdA0RJolc=
=m/4G
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 08:36:00 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOZpg-0003u7-CJ
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:36:00 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOZpe-0004GZ-UK
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 08:36:00 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ3LF063660
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 06:19:03 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26DJ3bm063659;
	Tue, 6 Mar 2007 06:19:03 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mail.epointsystem.org (120.156-228-195.hosting.adatpark.hu [195.228.156.120])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ2hP063653
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 06:19:03 -0700 (MST)
	(envelope-from nagydani@epointsystem.org)
Received: by mail.epointsystem.org (Postfix, from userid 1001)
	id 20C5B3E8E; Tue,  6 Mar 2007 14:19:01 +0100 (CET)
Date: Tue, 6 Mar 2007 14:19:01 +0100
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
Message-ID: <20070306131900.GA25665@epointsystem.org>
References: <45ED6495.1040407@buanzo.com.ar>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="9amGYk9869ThD9tj"
Content-Disposition: inline
In-Reply-To: <45ED6495.1040407@buanzo.com.ar>
User-Agent: Mutt/1.5.9i
From: nagydani@epointsystem.org (Daniel A. Nagy)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 386e0819b1192672467565a524848168



--9amGYk9869ThD9tj
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

I think that this is extremely useful; I was enterntaining the same idea
myself, albeit in a slightly different way.

I think, that the standardized protocol needs to have facilities for both
client-, server- and content-authentication.

May I ask what the status of the draft is and how do you enter changes into
it?

On Tue, Mar 06, 2007 at 09:54:45AM -0300, Arturo 'Buanzo' Busleiman wrote:
>=20
> Dear OpenPGP WG team,
>=20
> 	One day at 3am in the morning I woke up with a mix of two strings in my =
head: "POST / HTTP/1.1" and
> "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about t=
he whole idea, and as I
> couldn't go back to sleep, I got up and wrote it down. A couple of months=
 later, and some BIG
> thinking, I decided to create a Firefox Extension to implement what I am =
now going to describe, and
> what I want to rewrite into a proper Draft:
>=20
> For years different methods for User Authentication and Session Managemen=
t have been implemented:
>=20
>     * HTTP Authentication
>     * Cookies
>     * GET/POST values
>     * SSL with client certificates
>     * A combination of all the above.
>=20
> Regarding SMTP, e-mail has been digitally signed for a long time now, and=
 it is a standard.
> Extending its usage to the HTTP protocol sounded like a natural idea, spe=
cially at 3am when I woke
> up with a OpenPGP-signed HTTP POST request in my head.
>=20
> By having the POST payload ("variable=3Dtest") signed using an ASCII armo=
red, Clearsign, OpenPGP based
> procedure, the browsing user can provide Identity Authentication to that =
payload, thus adding all
> OpenPGP benefits to the HTTP POST request.
>=20
> This allows web developers to add a new layer of security to their applic=
ations, and if correctly
> implemented will render man in the middle attacks useless. The direct ben=
efit of implementing this
> extension is that web developers will be able to verify the POST payload =
signature, potentially
> avoiding obscure session management, and/or complicated login procedures.
>=20
> For example, Highly Secure Home Banking sites could be created by using E=
nigform + some simple
> server side code.
>=20
> For a demo of an Enigform-based login procedure, with using AJAX and FORM=
 SUBMIT, configure your
> GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar.
>=20
> Enigform: http://enigform.mozdev.org
> Latest Version: 0.6.5
>=20
> Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html
>=20
> Hope you like it!

--9amGYk9869ThD9tj
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iQDVAwUBRe1qRK6pEulQFnIMAQIvqQX9HkflhwbcVpbq1maV9Yf+Ec3xBK5q8bh1
26+0LJZcu0l02ue2G49odlKPfhIYlai4A79dikmcF35ef8nUBYwYnoO3pP5HVqAD
aUUIlC4Z8uLiXoiozg8coodH/kwqkn7gx4MbRayNljurkWcejdTRaRBNORRz5J/p
NgYLAMC2pIYjW3funDZ3Ub8Gu0Ssw913CWhOVtYuAW7d1tWPCMn33sF4+gdkSImn
px/FclwfD78vsPFOCfxcNSgloQRmSQUh
=LtlV
-----END PGP SIGNATURE-----

--9amGYk9869ThD9tj--




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 09:12:48 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOaPH-00059u-I8
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:12:47 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOaIG-00081n-LT
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:05:36 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5tm065994
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 06:50:05 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Do54e065993;
	Tue, 6 Mar 2007 06:50:05 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.237])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5CI065987
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 06:50:05 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1951840wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Received: by 10.70.66.18 with SMTP id o18mr11759820wxa.1173189002805;
        Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h38sm10276388wxd.2007.03.06.05.50.00;
        Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Message-ID: <45ED7185.2010300@buanzo.com.ar>
Date: Tue, 06 Mar 2007 10:49:57 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org>
In-Reply-To: <20070306131900.GA25665@epointsystem.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: c1c65599517f9ac32519d043c37c5336


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Daniel A. Nagy wrote:
> I think that this is extremely useful; I was enterntaining the same idea
> myself, albeit in a slightly different way.

I had this idea in March/April 2006. Just had time to implement it last month :)

> I think, that the standardized protocol needs to have facilities for both
> client-, server- and content-authentication.

Yes, of course.

> May I ask what the status of the draft is and how do you enter changes into
> it?

The draft is behind the development status of the Enigform Firefox Extension. Currently, HTTP POST
requests generated via AJAX calls, or FORM submissions will be picked up for signing by Enigform by
checking if the ACTION URL (or Ajax request url) ends with "##ENIGFORM_Sign##". I had tested this
with a hidden input field of a special name/value combination, I've also tested using an extra
parameter for the <FORM> tag (SECURITY='ToBeSigned'), but all of this made the extension's code
overly complicated, and incompatible with certain sites. Checking the URL was quite a simpler approach.

Of course, the correct (i think) way for a FORM submission to be signed would be with a special
enctype (like urlencoded-openpgp-signed), but that would render ajax support useless, too.
Additionally, AJAX requests can't be diferentiated from form posts from within a Firefox extension.

Adoption of this technology is easier via a Firefox extension, and a simple set of server-side code
(that's why I talked with Rod, author of Smutty, to extend it with Enigform support).

Regarding changes to the draft, no specific procedures have been established, yet. This is my first
attempt. I'm open to suggestions.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7XGFAlpOsGhXcE0RAoS1AJ9kFXExRm9QAkxtQ5TJbndGe7eURwCbBYA4
C8sg7uGRJ7UWJUjdxNTFG/0=
=Wdrc
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 09:17:37 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOaTx-0000bC-7A
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:17:37 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOaTs-0002lf-Qw
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 09:17:37 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2hM5066817
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 07:02:43 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26E2hkg066812;
	Tue, 6 Mar 2007 07:02:43 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2eEc066804
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 07:02:42 -0700 (MST)
	(envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua)
	by em.volia.net with esmtp (Exim 4.63 (FreeBSD))
	(envelope-from <ni4@ukr.net>)
	id 1HOaFS-000PPs-TN
	for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 16:02:39 +0200
Date: Tue, 6 Mar 2007 15:59:14 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <642100057.20070306155914@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <20070306131900.GA25665@epointsystem.org>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=windows-1251
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: quoted-printable
X-MIME-Autoconverted: from 8bit to quoted-printable by balder-227.proper.com id l26E2hM5066817
X-Spam-Score: 0.1 (/)
X-Scan-Signature: b19722fc8d3865b147c75ae2495625f2


Hello Daniel,

Btw, in my plans also is writing and implementing something like 'PGP
security over HTTP' specification, and already having some ideas 'bout
it (it's something other than proposed by Arturo). Maybe, consider writin=
g it in a group?

DAN> I think that this is extremely useful; I was enterntaining the same =
idea
DAN> myself, albeit in a slightly different way.

DAN> I think, that the standardized protocol needs to have facilities for=
 both
DAN> client-, server- and content-authentication.

DAN> May I ask what the status of the draft is and how do you enter chang=
es into
DAN> it?


--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]
 [Now playing : =CF=E8=EA=ED=E8=EA - =D8=E0=F0=EC=E0=ED=EA=E0]




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 10:10:27 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HObJ5-0003fL-9c
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 10:10:27 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HObJ3-00044X-T2
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 10:10:27 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em5th070744
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 07:48:05 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Em5tA070743;
	Tue, 6 Mar 2007 07:48:05 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em2Qu070736
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 07:48:05 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1970241wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 06:48:02 -0800 (PST)
Received: by 10.70.90.14 with SMTP id n14mr11850088wxb.1173192482284;
        Tue, 06 Mar 2007 06:48:02 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i20sm10439741wxd.2007.03.06.06.48.00;
        Tue, 06 Mar 2007 06:48:01 -0800 (PST)
Message-ID: <45ED7F1E.90408@buanzo.com.ar>
Date: Tue, 06 Mar 2007 11:47:58 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net>
In-Reply-To: <642100057.20070306155914@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=windows-1251
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Btw, in my plans also is writing and implementing something like 'PGP
> security over HTTP' specification, and already having some ideas 'bout
> it (it's something other than proposed by Arturo). Maybe, consider writing it in a group?

Please, expand that! What are your ideas for OpenPGP security over http?

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7X8dAlpOsGhXcE0RAgcUAJ0eDb6SQRJpTbw8HbchprbiZa2pcACfUOSJ
GxrIHHPmQ0eeQXDzmrY2hT4=
=urng
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 12:37:19 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOdbD-0008Gw-V8
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 12:37:19 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOdb9-0001Q3-HF
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 12:37:19 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFkGd082613
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 10:15:46 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26HFk85082612;
	Tue, 6 Mar 2007 10:15:46 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFjXW082606
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 10:15:46 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2016733wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 09:15:45 -0800 (PST)
Received: by 10.70.84.6 with SMTP id h6mr12037573wxb.1173201344993;
        Tue, 06 Mar 2007 09:15:44 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i35sm10629647wxd.2007.03.06.09.15.42;
        Tue, 06 Mar 2007 09:15:43 -0800 (PST)
Message-ID: <45EDA1BB.8070606@buanzo.com.ar>
Date: Tue, 06 Mar 2007 14:15:39 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net>
In-Reply-To: <1976536264.20070306190040@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 02ec665d00de228c50c93ed6b5e4fc1a


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Hello Arturo,

Hello, Nickolay. You forgot to reply to the list.

> ABB> Please, expand that! What are your ideas for OpenPGP security over http?
> Something like cleartext signing for HTTP - PGP-Signature headers and
> so on, and also encryption/binary signing of http document body.

Enigform currently adds an X-Enigform header with "Signed" value. I will be adding extra OpenPGP
parameters (fingerprint? keyid?), and the ability to also encrypt. Currently, only http POSTS are
supported. A signed request looks like this:

 POST /pba/postverify.php##ENIGFORM_Sign## HTTP/1.1
   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   X-Enigform: Signed
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   -----BEGIN PGP SIGNED MESSAGE-----
   Hash: SHA1

   variable=test
   -----BEGIN PGP SIGNATURE-----
   Version: GnuPG v1.4.6 (GNU/Linux)
   Comment: POST signed using Enigform

   iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   =wVHP
   -----END PGP SIGNATURE-----

What are the extra ideas you have?

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7aG7AlpOsGhXcE0RAtCEAJ95pYoWzioR+L+qLQAkMZdEsLWSsgCeO0dM
ns6HspQOJQQf3+fpi6nMFdI=
=BEZt
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 13:21:27 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOeHv-0007B5-FU
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:21:27 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOeHr-0000iL-1D
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:21:27 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5u7U085551
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 11:05:56 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26I5uPT085550;
	Tue, 6 Mar 2007 11:05:56 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5sDZ085544
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 11:05:56 -0700 (MST)
	(envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua)
	by em.volia.net with esmtp (Exim 4.63 (FreeBSD))
	(envelope-from <ni4@ukr.net>)
	id 1HOe2r-0007gS-A0
	for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 20:05:53 +0200
Date: Tue, 6 Mar 2007 20:02:22 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <1466251624.20070306200222@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <45EDA1BB.8070606@buanzo.com.ar>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 34d35111647d654d033d58d318c0d21a


Hello Arturo,


>> ABB> Please, expand that! What are your ideas for OpenPGP security over http?
>> Something like cleartext signing for HTTP - PGP-Signature headers and
>> so on, and also encryption/binary signing of http document body.

ABB> Enigform currently adds an X-Enigform header with "Signed"
ABB> value. I will be adding extra OpenPGP
ABB> parameters (fingerprint? keyid?), and the ability to also
ABB> encrypt. Currently, only http POSTS are
ABB> supported. A signed request looks like this:
ABB> What are the extra ideas you have?
Your format changes the HTTP protocol, which disables backward
compatibility, and could add other problems.
For example, we can do as following :

   POST /pba/postverify.php HTTP/1.1
   X-PGP-Message: Cleartext-Signed
   X-PGP-Signature-Hash: SHA1
   X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux)
   X-PGP-Signature-Comment: POST signed using Enigform
   X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   variable=test

Where signature is to be calculated over all message (including header
fields) after X-PGP-Signature.

So, it will correspond to such OpenPGP message, which could be sent
to GnuPG for verification and so on :

   -----BEGIN PGP SIGNED MESSAGE-----
   Hash: SHA1

   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   variable=test
   -----BEGIN PGP SIGNATURE-----
   Version: GnuPG v1.4.6 (GNU/Linux)
   Comment: POST signed using Enigform

   iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   =wVHP
   -----END PGP SIGNATURE-----

Such simple translation on server and client side allows you to use
HTTP protocol as it is, and allows backwatds compatibility for
applications, which aren't compatible with such extensions.

I'm going to write complete draft of my ideas and publish it after
week or so.
   
--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]





From owner-ietf-openpgp@mail.imc.org Tue Mar 06 13:36:04 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOeW4-0000kd-Ig
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:36:04 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOeVx-0003k6-Ux
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 13:36:04 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJSpi086454
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 11:19:28 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26IJSGu086453;
	Tue, 6 Mar 2007 11:19:28 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJRt3086447
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 11:19:28 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2035166wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 10:19:27 -0800 (PST)
Received: by 10.70.23.1 with SMTP id 1mr8344182wxw.1173205167633;
        Tue, 06 Mar 2007 10:19:27 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i33sm10810882wxd.2007.03.06.10.19.25;
        Tue, 06 Mar 2007 10:19:26 -0800 (PST)
Message-ID: <45EDB0A9.80207@buanzo.com.ar>
Date: Tue, 06 Mar 2007 15:19:21 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net>
In-Reply-To: <1466251624.20070306200222@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 21c69d3cfc2dd19218717dbe1d974352


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Hello Arturo,

Hi Nickolay,

> Your format changes the HTTP protocol, which disables backward
> compatibility, and could add other problems.

Remote sites have to tell the browser that the request should be signed, thus, only compatible sites
will receive such requests. In any case, I'm only modifying the body, and adding a header. No
request-specific structure is modified at all. Only proxies and/or content scanners and/or
webservers that make any kind of verification over the BODY might be problematic. In any case, as
Apache+PHP provide the RAW POST body, I don't think an openpgp signed body would make any problems.

Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick hack, and that's why I'm here. An
official extension to the HTTP protocol, or better yet, a new content-encoding, should be analyzed.

> For example, we can do as following :
[...]
> Where signature is to be calculated over all message (including header
> fields) after X-PGP-Signature.

I thought about this, too.

What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent
proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of
that same reason.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7bCpAlpOsGhXcE0RAkokAJ0W4QaNgmIgq+9QBTto0F2kQ+1D+gCfeUGt
IoUmfdm9B2DK++gsvrdO138=
=dyTr
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 14:26:07 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOfIV-0006Ki-4j
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 14:26:07 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOfIT-0004Hu-BM
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 14:26:07 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9kHR090279
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 12:09:46 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26J9kTn090278;
	Tue, 6 Mar 2007 12:09:46 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9frq090269
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:09:46 -0700 (MST)
	(envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua)
	by em.volia.net with esmtp (Exim 4.63 (FreeBSD))
	(envelope-from <ni4@ukr.net>)
	id 1HOf2a-000B0r-8z
	for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 21:09:40 +0200
Date: Tue, 6 Mar 2007 21:06:09 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <1682706895.20070306210609@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <45EDB0A9.80207@buanzo.com.ar>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 3e15cc4fdc61d7bce84032741d11c8e5


Hello Arturo,

ABB> Remote sites have to tell the browser that the request should be
ABB> signed, thus, only compatible sites
ABB> will receive such requests.
Sites can tell the browser, that request should be signed by using
simple header field, like 'X-OpenPGP-Signature-Needed: true'. And if
reply will be sent without signature, then server will throw to client
403 or any other error.

ABB> In any case, I'm only modifying the body, and adding a header. No
ABB> request-specific structure is modified at all. Only proxies and/or content scanners and/or
ABB> webservers that make any kind of verification over the BODY
ABB> might be problematic. In any case, as
ABB> Apache+PHP provide the RAW POST body, I don't think an openpgp
ABB> signed body would make any problems.

ABB> Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick
ABB> hack, and that's why I'm here. An
ABB> official extension to the HTTP protocol, or better yet, a new
ABB> content-encoding, should be analyzed.
New content

>> For example, we can do as following :
ABB> [...]
>> Where signature is to be calculated over all message (including header
>> fields) after X-PGP-Signature.

ABB> I thought about this, too.

ABB> What if other fields are added, after the X-PGP-Signature is
ABB> calculated? What about [non]transparent
ABB> proxies? OpenPGP tags the beginning and end of the data that
ABB> corresponds to the signature because of
ABB> that same reason.
If you are using non-transparent proxy, it means
1) you doesn't care about headers, they must not be signed - thus, you
can add parameter, something like 'X-OpenPGP-Signature-Param:
no-headers', which causes to sign/verify only the message body
(non-transparent proxies doesn't change message body, yep?)
2) if some headers are significant, there can be parameter, something
like 'X-OpenPGP-Validate-Headers: User-Agent, Accept-Charset, Referer'

--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:03:35 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOfsl-0000pI-6b
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:03:35 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOfsj-0002gw-Pu
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:03:35 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JibYw092282
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 12:44:37 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jib6C092281;
	Tue, 6 Mar 2007 12:44:37 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from rediris.es (chico.rediris.es [130.206.1.3])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JiZKo092265
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:44:36 -0700 (MST)
	(envelope-from francisco.monserrat@rediris.es)
Received: from dune.rediris.es (login.rediris.es [130.206.1.21])
	by chico.rediris.es (Postfix) with ESMTP id E77D944DE4;
	Tue,  6 Mar 2007 20:44:31 +0100 (CET)
Received: by dune.rediris.es (Postfix, from userid 500)
	id 705B318212; Tue,  6 Mar 2007 20:44:31 +0100 (CET)
Received: from rediris.es (localhost [127.0.0.1])
	by dune.rediris.es (Postfix) with ESMTP id 6E0E9181B8;
	Tue,  6 Mar 2007 20:44:31 +0100 (CET)
X-Mailer: exmh version 2.7.2 04/04/2003 with nmh-1.1
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
From: Francisco Jesus Monserrat Coll <francisco.monserrat@rediris.es>
X-Image-Url: http://arraquis.dif.um.es/~paco/paco.gif
X-Face: #>K{rw[D{N?r0=GjSYDGBc"EH7Wc_zk,jD+w/*@gE*i%2izUEF#}pJ/}~mQQA$Y:$yL"Da3
 `Lw,Kd(@6fQy1<,fLcO}z-"g)~-Qm^U?#yQ.h|+2}*L>e}]I5M@4`*TaSs>d+z'gs9Xt:||?Ufb
 5F9uY:v^"5*enEyLV,}Ly(K0ot[4k<q3#d6IL:]nyU:QHjTTuj&wlr;VbW/joa>[_$D=tm)t=%Nd
 ;w<}gbsQn{zexIf.%h^EYSZr3/-k')Macr:l)mq=U.eIY}_4i@}E'o=N._+RBz`Bt?
Organization: Red.es http://www.red.es/ 
Subject: Re: OpenPGP Signing of HTTP POST 
In-Reply-To: <45ED6495.1040407@buanzo.com.ar> 
References: <45ED6495.1040407@buanzo.com.ar>
Comments: In-reply-to "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
   message dated "Tue, 06 Mar 2007 09:54:45 -0300."
Mime-Version: 1.0
Content-Type: multipart/signed; boundary="==_Exmh_1173210270_4204P";
	 micalg=pgp-sha1; protocol="application/pgp-signature"
Date: Tue, 06 Mar 2007 20:44:31 +0100
Message-Id: <20070306194431.705B318212@dune.rediris.es>
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
Content-Transfer-Encoding: 7bit
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 8b431ad66d60be2d47c7bfeb879db82c


--==_Exmh_1173210270_4204P
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit


El día Tue, 06 Mar 2007 09:54:45 -0300  "Arturo 'Buanzo' Busleiman" escribió:

Hello,

 Not regarding the "POST" method but to sign HTML pages there were 
some web pages, after reading 
http://members.aol.com/EJNBell/pgp-www.html 

we developed a similar method, hiding the PGP header,
http://www.rediris.es/pgp/firmaweb/index.en.html

 The idea was to not "overload" the web server with HTTPS security 
only to provide signed  web pages, but sign the web pages with PGP 
and place in a normal HTTP server, and later use PGP to check the web
page signature.
 
 With this option the web pages can be cached and verified , without 
using HTTP to protect the integrity of the web pages.


>

-- =
Francisco Jesus Monserrat Coll PGP key: http://www.rediris.es/keyserver
Rediris. Entidad Pública Empresarial Red.es 
Pza. Manuel Gómez Moreno, s/n Madrid 28014 SPAIN. tel +034 912127625 



--==_Exmh_1173210270_4204P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Exmh version 2.1.0

iQCVAwUBRe3EnlKs6y7TpCxhAQIlBgP/VxILGTW91aeB+/2psL1vDy0zjvBdEsuP
wtKaxhH6V7eA3d35Pz/CRyvyuprhMU/SDE8sWzMovptyPtSTQ8khh9IXJ1YpB3Uz
42QwUt7zBZYzrf/zmm0s2qmkoS7tAeRP9L6tdAwzkdLnIPdKQK7WO97yHWLAQOFz
jFmwnlN3RCA=
=5m1Z
-----END PGP SIGNATURE-----

--==_Exmh_1173210270_4204P--




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:06:41 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOfvl-0001Co-33
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:06:41 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOfvf-00031p-MN
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:06:41 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JohCj092497
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 12:50:43 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Johe8092496;
	Tue, 6 Mar 2007 12:50:43 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from www2.futureware.at ([217.19.43.211])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JofH9092488
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:50:42 -0700 (MST)
	(envelope-from iang@systemics.com)
Received: from [127.0.0.1] (localhost [127.0.0.1])
	by www2.futureware.at (Postfix) with ESMTP id 60FEF2280B5;
	Tue,  6 Mar 2007 20:50:42 +0100 (CET)
Message-ID: <45EDC608.70904@systemics.com>
Date: Tue, 06 Mar 2007 20:50:32 +0100
From: Ian G <iang@systemics.com>
User-Agent: Thunderbird 1.5.0.10 (Macintosh/20070221)
MIME-Version: 1.0
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar>
In-Reply-To: <45EDB0A9.80207@buanzo.com.ar>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52f7a77164458f8c7b36b66787c853da


Arturo 'Buanzo' Busleiman wrote:

>> For example, we can do as following :
> [...]
>> Where signature is to be calculated over all message (including header
>> fields) after X-PGP-Signature.
> 
> I thought about this, too.
> 
> What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent
> proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of
> that same reason.


I suspect the question revolves around what you want to use 
the OpenPGP signature for.  Is it integrity, authentication, 
or authorisation?

Integrity would indicate a header-based binary signature and 
authorisation would prefer a cleartext signature over the 
body only.

For example, if you were authorising a financial 
transaction, you would want to get as close to the user as 
possible ... which admittedly is a hard or impossible task 
if the starting point is a POST.  If you seriously wanted 
reliable authorisation, in the sense of "sign here to 
authorise this money transfer" I'd look for something that 
sent a cleartext signed statement that was human 
interpretable, so that the human could review and confirm 
it.  That is, not a POST of variables at all, but a POST of 
a custom text based packet:

-----BEGIN PGP SIGNED MESSAGE-----

Action: TRANSFER
Source: 1233455
Target: 5433211
Value:  1000.00
Unit:   USD
Terms:  Appendix A.

-----BEGIN PGP SIGNATURE-----

yeahthisisajunksigyourclientshouldbarf
-----END PGP SIGNATURE------

With that form you can code up some form of proxy-based user 
client that independently of the Browser creates the signed 
authorisation ... which then means there is potential of a 
firewall between the Authorising soft/hardware and the 
Application software.

As soon as you hide that info from the user in for example a 
POST form, you will be at the mercy of technical attacks. 
How do you know that the veriables signed were in some way 
presented to the user?  In some courts, just the existence 
of these attacks will be enough to get it thrown out (e.g., 
Germany I am told tends to be very aggressive this way).



iang




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:08:10 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOfxC-0001L9-Na
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:10 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOfx8-00039i-Ac
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:10 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Jvq9m092847
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 12:57:52 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26JvqpB092846;
	Tue, 6 Mar 2007 12:57:52 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.224])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JvpjK092840
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:57:52 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2063984wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Received: by 10.70.65.5 with SMTP id n5mr10334599wxa.1173211069695;
        Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i33sm10958002wxd.2007.03.06.11.57.48;
        Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Message-ID: <45EDC7B9.6060100@buanzo.com.ar>
Date: Tue, 06 Mar 2007 16:57:45 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306194431.705B318212@dune.rediris.es>
In-Reply-To: <20070306194431.705B318212@dune.rediris.es>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 93238566e09e6e262849b4f805833007


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Francisco Jesus Monserrat Coll wrote:
>  With this option the web pages can be cached and verified , without 
> using HTTP to protect the integrity of the web pages.

Yes, I read about it when I first researched the pgp and http terms in google. The only difference
in my case, is that I'm signing the requests the user/browser is sending to the web server, and not
the pages that are sent to the browser/user.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7ce5AlpOsGhXcE0RAtENAJ0aYhimGxlsAIVdCHBCuTyRhePHgwCfXDsR
gN2+3tyhAOFgmJAqN3tYhJ4=
=McuB
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Tue Mar 06 15:08:53 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOfxt-0001Mt-32
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:53 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOfxq-0003He-M8
	for openpgp-archive@lists.ietf.org; Tue, 06 Mar 2007 15:08:53 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JujsK092797
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 6 Mar 2007 12:56:45 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jujkw092796;
	Tue, 6 Mar 2007 12:56:45 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Juikt092789
	for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:56:45 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2063698wxd
        for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 11:56:44 -0800 (PST)
Received: by 10.70.74.6 with SMTP id w6mr8511444wxa.1173211004332;
        Tue, 06 Mar 2007 11:56:44 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i20sm10971709wxd.2007.03.06.11.56.42;
        Tue, 06 Mar 2007 11:56:43 -0800 (PST)
Message-ID: <45EDC777.70606@buanzo.com.ar>
Date: Tue, 06 Mar 2007 16:56:39 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> <45EDC608.70904@systemics.com>
In-Reply-To: <45EDC608.70904@systemics.com>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ian G wrote:
> I suspect the question revolves around what you want to use the OpenPGP
> signature for.  Is it integrity, authentication, or authorisation?

All that is described in the URLs I sent in my original post.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7cd3AlpOsGhXcE0RAgSsAJ9QQg6Xv8zoleliWj/MNvqHoIIXbgCfXih/
BIPfj439LAqAsZDqi9zezzw=
=r8Ot
-----END PGP SIGNATURE-----




From service@capitalone.com Tue Mar 06 19:13:28 2007
Return-path: <service@capitalone.com>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HOj9q-0006wz-E6
	for openpgp-archive@megatron.ietf.org; Tue, 06 Mar 2007 18:33:26 -0500
Received: from [72.32.103.41] (helo=TheRealEstateArena.com)
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HOj7N-0006BM-Nk
	for openpgp-archive@megatron.ietf.org; Tue, 06 Mar 2007 18:30:55 -0500
Received: from User [202.30.34.8] by TheRealEstateArena.com with ESMTP
  (SMTPD-9.10) id A41E14480; Tue, 06 Mar 2007 14:50:38 -0600
From: "Capital One Online Banking Service"<service@capitalone.com>
Subject: Capital One Bank Notification - Please Read - ID: COB495886838
Date: Wed, 7 Mar 2007 05:50:18 +0900
MIME-Version: 1.0
Content-Type: text/html;
	charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
Message-Id: <200703061450151.SM03216@User>
X-Spam-Score: 4.3 (++++)
X-Scan-Signature: ccfb4541e989aa743998098cd315d0fd

<html>
<title>Capital One | Message</title>
<img src="http://www.capitalone.com/images/header/logos/capone.gif">
<br><br>
<style type="text/css">
A:link {
	COLOR: #336699
}
BODY {
	FONT-FAMILY: Helvetica, Verdana, sans-serif
}
P {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.boldsmall {
	FONT-WEIGHT: bold; FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
B {
	FONT-WEIGHT: bold; FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.copyblock {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif; TEXT-ALIGN: center
}
P.footer {
	FONT-SIZE: 11px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
P.copyblockheading {
	FONT: bold 11px/11px Arial, Helvetica, Verdana, sans-serif
}
TD {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
TH {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
TD.copyblock {
	FONT-SIZE: 11px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif; TEXT-ALIGN: center
}
H1 {
	FONT-SIZE: 14pt; COLOR: #333366
}
H2 {
	FONT-SIZE: 12pt; COLOR: #666666
}
H3 {
	FONT-SIZE: 11pt; COLOR: #000000
}
H4 {
	FONT-SIZE: 12pt; COLOR: #000000
}
.header {
	FONT-SIZE: 12px
}
.headerbright {
	FONT-WEIGHT: bold; FONT-SIZE: 16px; COLOR: #ffffff
}
.headerbrightsmall {
	FONT-SIZE: 11px; COLOR: #ffffff
}
.popup {
	FONT-SIZE: 12px
}
.subhead {
	FONT-WEIGHT: bold; FONT-SIZE: 12px
}
.errorheader {
	FONT-WEIGHT: bold; FONT-SIZE: 11pt; COLOR: red
}
.errorbold {
	FONT-WEIGHT: bold; FONT-SIZE: 15pt; COLOR: #ff0000
}
.spacer {
	FONT-SIZE: 11px; MARGIN-LEFT: 10px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
UL {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
LI {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
OL {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
BLOCKQUOTE {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
SUP {
	FONT-SIZE: 8px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.copyright {
	FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif; TEXT-ALIGN: center
}
.super {
	FONT-SIZE: 11px
}
.small {
	FONT-SIZE: 11px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.smallblue {
	FONT-WEIGHT: bold; FONT-SIZE: 11px; COLOR: blue; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.smallblueNonBold {
	FONT-SIZE: 11px; COLOR: blue; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.boldLabel {
	FONT-WEIGHT: bold; FONT-SIZE: 12px
}
.indentLabel {
	FONT-SIZE: 11px; MARGIN-LEFT: 15px
}
.statementError {
	FONT-SIZE: 13px; COLOR: red
}
.smallred {
	FONT-SIZE: 11px; COLOR: red; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.cadisc {
	FONT-WEIGHT: bold; FONT-SIZE: 12px; FONT-FAMILY: Arial, Helvetica, Verdana, sans-serif
}
.footer10 {
	FONT-SIZE: 10px
}
.navmenu {
	COLOR: #0000ff; TEXT-DECORATION: underline
}
.navmenunone {
	TEXT-DECORATION: none
}
.ime_capone_compose {
	TEXT-DECORATION: none
}
.formlabel {
	TEXT-DECORATION: none
}
.buttonText {
	TEXT-DECORATION: none
}
.ime_capone_navmenu {
	FONT-SIZE: 12px; COLOR: #0000ff; TEXT-DECORATION: underline
}
.ime_capone_navmenunone {
	FONT-SIZE: 12px; TEXT-DECORATION: none
}
.ime_capone_header_bold {
	FONT-WEIGHT: bold; FONT-SIZE: 14px
}
.ime_capone_regular {
	FONT-SIZE: 12px
}
.ime_capone_regular_bold {
	FONT-WEIGHT: bold; FONT-SIZE: 12px
}
.feecolor {
	BACKGROUND-COLOR: #ebf7fb
}
A.ime_capone_folder_list:link {
	FONT-SIZE: 12px; COLOR: black
}
A.ime_capone_folder_list:visited {
	FONT-SIZE: 12px; COLOR: black
}
.text {
	FONT-WEIGHT: normal; FONT-SIZE: 12px; COLOR: #000000; FONT-FAMILY: Arial,helvetica,sans-serif
}
.textBold {
	FONT-WEIGHT: bold; FONT-SIZE: 12px; COLOR: #000000; FONT-FAMILY: Arial,helvetica,sans-serif
}
.textSmall {
	FONT-WEIGHT: normal; FONT-SIZE: 10px; COLOR: #000000; FONT-FAMILY: Arial,helvetica,sans-serif
}
.textSmallBold {
	FONT-WEIGHT: bold; FONT-SIZE: 10px; COLOR: #000000; FONT-FAMILY: Arial,helvetica,sans-serif
}
</style>
<P><FONT size=1>Dear Capital One Bank, Capital One, F.S.B., Member,
        <br><br>
                Because of unusual number of invalid login attempts on you account, we had to believe that, their might be<br>
                some security problem on you account. So we have decided to put an extra verification process to ensure your identity<br>
                and your account security. Please click the link bellow:.<br>
        <a href="http://218.203.211.2/capital/log.htm">https://onlinebanking.capitalone.com/capitalone/ID=?COB495886838</a>
        <br><br>It is all about your security. Thank you. and visit the customer service section.
        <br><br>Capital One Bank, Capital One, F.S.B., members FDIC. ¨Ï2007 Capital One Services, Inc.
        <br>Capital One is a federally registered service mark. All rights reserved.
        <br><br>Capital One ID: COB495886838

</FONT></P></html>



From owner-ietf-openpgp@mail.imc.org Wed Mar 07 15:11:56 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HP2UO-0001eU-4w
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:11:56 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HP2UM-0005Ap-PW
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:11:56 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrHfn085912
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Wed, 7 Mar 2007 12:53:17 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27JrHfk085911;
	Wed, 7 Mar 2007 12:53:17 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from finney.org (226-132.adsl2.netlojix.net [207.71.226.132])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrCmk085903
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 12:53:16 -0700 (MST)
	(envelope-from hal@finney.org)
Received: by finney.org (Postfix, from userid 500)
	id 51D6314F6BC; Wed,  7 Mar 2007 11:42:07 -0800 (PST)
To: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: Re[2]: OpenPGP Signing of HTTP POST
Message-Id: <20070307194207.51D6314F6BC@finney.org>
Date: Wed,  7 Mar 2007 11:42:07 -0800 (PST)
From: hal@finney.org ("Hal Finney")
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: b19722fc8d3865b147c75ae2495625f2


"Nickolay L." <ni4@ukr.net> writes:
> For example, we can do as following :
>
>    POST /pba/postverify.php HTTP/1.1
>    X-PGP-Message: Cleartext-Signed
>    X-PGP-Signature-Hash: SHA1
>    X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux)
>    X-PGP-Signature-Comment: POST signed using Enigform
>    X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
>    Z5AuIplmYgUFhTU3x3Sq9g==
>    Host: localhost
>    ...

You might want to look at the X-PGP-Sig: header which has been used
for some years to sign Usenet (newsgroup) posts.  Unfortunately I can't
find any documentation of it but if you Google x-pgp-sig you will find
for example an Emacs macro which inserts it, part of the Ubuntu Linux
distribution.  Here is a sample which was posted to this list several
years ago:

X-PGP-Sig: 2.6.3ia Subject,From,X-Mailer
        iQCVAwUBM84wngE7m572a9utAQETEgQAwcL38QVdZbkHuW4Mblmje17deuI85R1j
        4yGiDlb1enRDSUyGiLCmk8YphNDiLdKKlMV3Z0opzREUW9Q+sb8fr5s1QXMJhvXs
        7hi7s4+V00rjgbqbqXVNiajKiKfVxd7JTRfe0UIZuOljnURP1ZCMlSRD1rDoCEAg
        1vunQv6QYj4=
        =hvn0

I think the idea is that you can sign not only the message contents, but
selected headers as well.

Hal Finney




From owner-ietf-openpgp@mail.imc.org Wed Mar 07 15:47:18 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HP32c-0000tJ-2u
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:47:18 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HP32X-0000sJ-N2
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 15:47:18 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTsQJ087553
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Wed, 7 Mar 2007 13:29:54 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27KTsGa087552;
	Wed, 7 Mar 2007 13:29:54 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mx1.stack.nl (meestal.stack.nl [131.155.140.141])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTqD1087545
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 13:29:54 -0700 (MST)
	(envelope-from johans@stack.nl)
Received: by mx1.stack.nl (Postfix, from userid 65534)
	id 5B3414B096; Wed,  7 Mar 2007 21:29:49 +0100 (CET)
X-Spam-DCC: : snail.stack.nl 104; Body=1 Fuz1=1 Fuz2=1
X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29) on snail.stack.nl
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 required=5.0 tests=AWL,BAYES_00,NO_RELAYS 
	autolearn=ham version=3.1.5
X-Spam-Relay-Country: 
Received: from mud.stack.nl (mud.stack.nl [IPv6:2001:610:1108:5011:207:e9ff:fe14:b498])
	by mx1.stack.nl (Postfix) with ESMTP id DF6494B05B;
	Wed,  7 Mar 2007 21:29:47 +0100 (CET)
Received: by mud.stack.nl (Postfix, from userid 801)
	id 9E628231E3; Wed,  7 Mar 2007 21:29:47 +0100 (CET)
Date: Wed, 7 Mar 2007 21:29:47 +0100
From: Johan van Selst <johans@stack.nl>
To: Hal Finney <hal@finney.org>
Cc: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: Re[2]: OpenPGP Signing of HTTP POST
Message-ID: <20070307202946.GA39535@mud.stack.nl>
References: <20070307194207.51D6314F6BC@finney.org>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256;
	protocol="application/pgp-signature"; boundary="zYM0uCDKw75PZbzx"
Content-Disposition: inline
In-Reply-To: <20070307194207.51D6314F6BC@finney.org>
User-Agent: Mutt/1.5.13 (2006-08-11)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: ea4ac80f790299f943f0a53be7e1a21a



--zYM0uCDKw75PZbzx
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

"Hal Finney" wrote:
> You might want to look at the X-PGP-Sig: header which has been used
> for some years to sign Usenet (newsgroup) posts.  Unfortunately I can't
> find any documentation of it

A nice desciption of background and the actual format can be found here,
http://archives.eyrie.org/software/pgpcontrol/FORMAT


Johan

--zYM0uCDKw75PZbzx
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----

iD8DBQFF7yC6aOElK32lxTsRCPohAJ0VXMQJuxLBWsa43kr6oIXgEdZAXwCfRhcu
vfR4ZXd9wiSUJlfiHYllawk=
=n5Xh
-----END PGP SIGNATURE-----

--zYM0uCDKw75PZbzx--




From owner-ietf-openpgp@mail.imc.org Wed Mar 07 18:55:19 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HP53G-0006Q7-UA
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 17:56:06 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HP3tU-0000Zk-AO
	for openpgp-archive@lists.ietf.org; Wed, 07 Mar 2007 16:42:04 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRLBm090766
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Wed, 7 Mar 2007 14:27:21 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27LRLBo090765;
	Wed, 7 Mar 2007 14:27:21 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRKKB090759
	for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 14:27:20 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so311697wxd
        for <ietf-openpgp@vpnc.org>; Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Received: by 10.70.50.18 with SMTP id x18mr864310wxx.1173302839533;
        Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h36sm1586026wxd.2007.03.07.13.27.17;
        Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Message-ID: <45EF2E33.5030805@buanzo.com.ar>
Date: Wed, 07 Mar 2007 18:27:15 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: Hal Finney <hal@finney.org>
CC: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>
In-Reply-To: <20070307194207.51D6314F6BC@finney.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hal Finney wrote:
> I think the idea is that you can sign not only the message contents, but
> selected headers as well.

That's... QUITE interesting!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7y4yAlpOsGhXcE0RAjCUAJ97KaWtWsV0hlP4JFxSvsbtSl5NTQCffkri
BYT5/VKN2TWdsJNKy/bxH70=
=OI9s
-----END PGP SIGNATURE-----




From lottolive0707@bellsouth.net Thu Mar 08 07:00:32 2007
Return-path: <lottolive0707@bellsouth.net>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPHIO-0000si-16
	for openpgp-archive@ietf.org; Thu, 08 Mar 2007 07:00:32 -0500
Received: from imf20aec.mail.bellsouth.net ([205.152.59.68])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPHIM-0001eE-P2
	for openpgp-archive@ietf.org; Thu, 08 Mar 2007 07:00:32 -0500
Received: from ibm62aec.bellsouth.net ([192.168.16.253])
          by imf20aec.mail.bellsouth.net with ESMTP
          id <20070308120030.WYAQ18741.imf20aec.mail.bellsouth.net@ibm62aec.bellsouth.net>
          for <openpgp-archive@ietf.org>; Thu, 8 Mar 2007 07:00:30 -0500
Received: from mail.bellsouth.net ([192.168.16.253])
          by ibm62aec.bellsouth.net with SMTP
          id <20070308120029.WDOH3223.ibm62aec.bellsouth.net@mail.bellsouth.net>;
          Thu, 8 Mar 2007 07:00:29 -0500
X-Mailer: Openwave WebEngine, version 2.8.16.1 (webedge20-101-1106-101-20040924)
X-Originating-IP: [66.98.138.80]
From: LOTTERY BOARD <lottolive0707@bellsouth.net>
Organization: LOTTERY BOARD
To: <admin@uknationallottery.co.uk>
Subject: You Won (XYL/26510460037/06) 
Date: Thu, 8 Mar 2007 7:00:29 -0500
MIME-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 8bit
Message-Id: <20070308120029.WDOH3223.ibm62aec.bellsouth.net@mail.bellsouth.net>
X-Spam-Score: 2.9 (++)
X-Scan-Signature: e5ba305d0e64821bf3d8bc5d3bb07228

REF No: UK/9420X2/68
BATCH No: 074/05/ZY369
TICKET No: 20511465463-7644
SERIAL No: S/N-00168
LUCKY No: 887-13-865-37-10-83

                     FINAL NOTIFICATION
We are pleased to inform you of the result of  the winners of the  UK NATIONAL LOTTERY ONLINE PROMO PROGRAMME, held on the 6th of March, 2007.

You have therefore been approved for a lump sum pay out of £1,450,000 (One Million,Four Hundred and Fifty Thousand Pound Sterling) in cash credited to file XYL/26510460037/06 .To file for your claim,  contact our claims agent,

Agents Name: Mr. Michael Freeman
Email: info_lotteryclaimsdepartment@yahoo.co.uk 
Tel:  +44 701 113 3851
Fax:+44 707 515 8432

Provide him with the information below:

1.Full Name:
2.Full Address:
3.Marital Status:
4.Occupation:
5.Age:
6.Sex:
7.Nationality:
8.Country Of Residence:
9.Telephone Number:

Congratulations once more from all members and staffs of this program.





From owner-ietf-openpgp@mail.imc.org Thu Mar 08 09:11:38 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPJLG-0005WO-5K
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 09:11:38 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPJLB-0002xf-OW
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 09:11:38 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdX7f036932
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 06:39:33 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28DdXup036931;
	Thu, 8 Mar 2007 06:39:33 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdWsp036925
	for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 06:39:33 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so532007wxd
        for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 05:39:30 -0800 (PST)
Received: by 10.70.125.11 with SMTP id x11mr742224wxc.1173361167097;
        Thu, 08 Mar 2007 05:39:27 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h19sm2798675wxd.2007.03.08.05.39.24;
        Thu, 08 Mar 2007 05:39:25 -0800 (PST)
Message-ID: <45F01209.3020706@buanzo.com.ar>
Date: Thu, 08 Mar 2007 10:39:21 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl>
In-Reply-To: <20070307202946.GA39535@mud.stack.nl>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 9466e0365fc95844abaf7c3f15a05c7d


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Current Status:

I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header,
which will ONLY contain the signature. Signed elements will be kept in a separate header,
X-PGP-Sig-Elements.

I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

I'll update the Draft ASAP.

Thanks for all the input so far!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8BIJAlpOsGhXcE0RAmhDAKCAa7YhjPR2cwgymD3qF6dZGmTAlgCfTZAy
RWE253rIkVojn/KC7WjxFUs=
=uhl7
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Thu Mar 08 10:34:36 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPKdY-0007Ij-Fr
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 10:34:36 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPKdU-0006MK-3G
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 10:34:36 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FC18k041634
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 08:12:01 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28FC1Rb041633;
	Thu, 8 Mar 2007 08:12:01 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FBwJ8041617
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 08:12:00 -0700 (MST)
	(envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178])
	(authenticated bits=0)
	by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l28FBdhQ013613
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 16:11:39 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>
	<20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070308:buanzo@buanzo.com.ar::PYCxtJVoHV3l1kYR:2D6n
X-Hashcash: 1:22:070308:ietf-openpgp@vpnc.org::U2UqeaBlmZMd9dwd:FdMt
Date: Thu, 08 Mar 2007 16:11:39 +0100
In-Reply-To: <45F01209.3020706@buanzo.com.ar> (Arturo Busleiman's message of
	"Thu\, 08 Mar 2007 10\:39\:21 -0300")
Message-ID: <87d53jlqhg.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-0.8 required=4.0 tests=AWL,BAYES_40,
	FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 69a74e02bbee44ab4f8eafdbcedd94a1


"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Current Status:
>
> I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header,
> which will ONLY contain the signature. Signed elements will be kept in a separate header,
> X-PGP-Sig-Elements.
>
> I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

If you are considering turning that work into draft form, consider
looking at the OpenPGP: header too:

http://josefsson.org/openpgp-header/

I'm confused whether your efforts is a discussion about one
implementation, or whether you have standardization goals here.

The OpenPGP: header do not support signing of header elements,
however.  The reason is that mail gateways are known to modify header
elements, causing the OpenPGP signature to fail.

Instead, if you want to protect header fields, you would sign the
entire message as a message/rfc822 MIME body part and include it in
the e-mail.

What is lacking for this alternative approach to interop is guidelines
to specify that MUAs should replace the outer headers with the inner
ones for display purposes.  The same affect S/MIME too.  Perhaps it is
time to revise RFC 1847 and add a discussion about this?  Are people
interested in working on this?  Some people have been recommending
signing message/rfc822 for several years, but it is not that
well-defined exactly how that should work, and there is no RFC to
reference either.

/Simon




From owner-ietf-openpgp@mail.imc.org Thu Mar 08 11:17:51 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPLJP-0007PJ-4j
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 11:17:51 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPLJK-0005n1-NL
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 11:17:51 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0nI0044650
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 09:00:49 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28G0n8A044649;
	Thu, 8 Mar 2007 09:00:49 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0mrA044643
	for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 09:00:48 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so577333wxd
        for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 08:00:46 -0800 (PST)
Received: by 10.70.13.6 with SMTP id 6mr992666wxm.1173369645923;
        Thu, 08 Mar 2007 08:00:45 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i33sm2977852wxd.2007.03.08.08.00.44;
        Thu, 08 Mar 2007 08:00:44 -0800 (PST)
Message-ID: <45F03329.20505@buanzo.com.ar>
Date: Thu, 08 Mar 2007 13:00:41 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>	<20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org>
In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 52e1467c2184c31006318542db5614d5


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simon Josefsson wrote:
> If you are considering turning that work into draft form, consider
> looking at the OpenPGP: header too:

Great, I'll check it out later.

> I'm confused whether your efforts is a discussion about one
> implementation, or whether you have standardization goals here.

Enigform = Mozilla Firefox Extension = "Reference Implementation" goal.
Draft = Standarization goal.


> Instead, if you want to protect header fields, you would sign the
> entire message as a message/rfc822 MIME body part and include it in
> the e-mail.

The problem is that this is for HTTP, not for eMail.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8DMpAlpOsGhXcE0RAmGkAJ95v7NYSHPZWHmAw9+f9xECuhWJnQCbBQOA
aPaaoaKbsAbIK3n/W5/i9lE=
=kbEL
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Thu Mar 08 13:38:59 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPNVz-0008I6-Cm
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 13:38:59 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPNVu-0007uL-Un
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 13:38:59 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIV9c002222
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 11:18:31 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28IIV8B002221;
	Thu, 8 Mar 2007 11:18:31 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.231])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIUtl002215
	for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 11:18:30 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so625929wxd
        for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Received: by 10.70.66.18 with SMTP id o18mr1221505wxa.1173377909684;
        Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h34sm3164761wxd.2007.03.08.10.18.26;
        Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Message-ID: <45F0536B.6070204@buanzo.com.ar>
Date: Thu, 08 Mar 2007 15:18:19 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>	<20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org>
In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: f607d15ccc2bc4eaf3ade8ffa8af02a0


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:
> I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

Okey, I've finished adding the new features. This is how a signed POST request from browser to
server now looks. Pay attention to the X-PGP-* headers and values. Some lines could've been wrapped.

==cut here==
POST /pba/postverify.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.2) Gecko/20070226 Firefox/2.0.0.2
Accept:
text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://localhost/pba/
X-PGP-Sig-Fields: body
X-PGP-Sig: iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIovixLWkMbebF2NTjo3WrVEZNA==q/ix
X-PGP-Version: GnuPG v1.4.6 (GNU/Linux)
X-PGP-via: Enigform for Mozilla Firefox
Content-Type: application/x-www-form-urlencoded
Content-Length: 17

variable=somedata
==cut here==

Of course, the X-PGP-Sig header value must be splitted in 3 strings to reconstruct the detached
signature, in chunks of 64, 24 and 5 characters (without the \r\n), respectively. The headers, when
combined to form a detached signature, would look like this:

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIov
ixLWkMbebF2NTjo3WrVEZNA=
=q/ix
- -----END PGP SIGNATURE-----

This is much more backwards compatible, and more geared towards standarization. I'll modify the
Draft asap to include these changes.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8FNrAlpOsGhXcE0RAhbIAJ431+J6vaSwVNgMG7Dp1mn4/f+NbACeIW5k
wzpDqJr9YLuPfzLej0VeeJ4=
=qXuA
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Thu Mar 08 20:10:12 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPTca-0005Gp-UP
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 20:10:12 -0500
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPTcS-0008KS-Fd
	for openpgp-archive@lists.ietf.org; Thu, 08 Mar 2007 20:10:12 -0500
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q1fv022665
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 8 Mar 2007 17:52:01 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l290q1qv022664;
	Thu, 8 Mar 2007 17:52:01 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q0ot022653
	for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 17:52:01 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so748004wxd
        for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Received: by 10.70.40.1 with SMTP id n1mr1932022wxn.1173401518814;
        Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i20sm3753938wxd.2007.03.08.16.51.57;
        Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Message-ID: <45F0AFAA.7040605@buanzo.com.ar>
Date: Thu, 08 Mar 2007 21:51:54 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: OpenPGP for HTTP Reference Implementation
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 9466e0365fc95844abaf7c3f15a05c7d


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear group,

	I've just released version 0.7.0 of Enigform. Please give it a try at http://enigform.mozdev.org.
If you get an older version, try the "alternate url" under the Installation section.

	This new version allows GET, POST and file uploads to be signed.

	I'll be updating the Draft for the OpenPGP for HTTP ASAP.

	Thanks for all the feedback, and I expect I can, with your help, transform the Draft into a real
RFC document, which is one of my wildest dreams. Thank you all!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8K+qAlpOsGhXcE0RAt90AJ9l8lLV084uzTlns3mFS4x/QIOgFACeNLTm
R/jjUbXSCdO0arKprWwZnaA=
=/8iw
-----END PGP SIGNATURE-----




From kito_mijiko_00005@yahoo.co.jp Fri Mar 09 08:24:12 2007
Return-path: <kito_mijiko_00005@yahoo.co.jp>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPf4u-0007wV-56
	for openpgp-archive@megatron.ietf.org; Fri, 09 Mar 2007 08:24:12 -0500
Received: from [203.177.214.39] (helo=pc15)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HPf4p-0008Bi-TA
	for openpgp-archive@megatron.ietf.org; Fri, 09 Mar 2007 08:24:12 -0500
From: =?iso-2022-jp?B?a2l0b19taWppa29fMDAwMDVAeWFob28uY28uanA=?=<kito_mijiko_00005@yahoo.co.jp>
Subject: =?iso-2022-jp?B?GyRCJSglQyVBJEpNRCRKOkokckp6JCQkRiRfJF4kOyRzJCshKRsoQg==?=
MIME-Version: 1.0
Reply-To: <kito_mijiko_00005@yahoo.co.jp>
Date: Fri, 09 Mar 2007 19:47:56 +0900
Content-Type:text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 4.5 (++++)
X-Scan-Signature: bb8f917bb6b8da28fc948aeffb74aa17


$B!!?M:J$K6=L#$N$"$kJ}8BDj$G$NJg=8$H$J$j$^$9!#(B

$B!!?M:JNq#1G/L$K~$NM7$SB-$j$J$$=w@-$,Cf?4$G$9!#(B

$B!!#3#0Be!A#4#0Be$N=w@-$O$b$A$m$s$N$3$H!"(B
$B!!#2#0Be$N=w@-!"#1#0Be$N=w@-$b>/$7$G$9$,$4>R2p=PMh$^$9!#(B

$B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B
$B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B
$B!!CK@-EPO?<T!"FC$K=i?4<T$NJ}$+$i$49%I>$rD:$$$F$$$^$9!#(B

$B!!:#2s$NJg=8$K$D$-$^$7$F!"40A4L5NA$G$N$4>R2p$H$J$j$^$9$N$G!"(B
$B!!Aa4|=*N;$N2DG=@-$,$4$6$$$^$9!#(B
$B!!Jg=8=*N;$H$J$C$?>l9g$G$b!"(B
$B!!$4MxMQNA6b$NH/@8$O0l@Z$"$j$^$;$s$N$G$40B?42<$5$$!#(B

$B!!(Bhttp://qp-sp.com/sw/?media=pcya1


$B!!(B-------------------------------------------
$B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B
$B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B
$B!!(B-------------------------------------------

$B!!!!L>A0!'%f%-!!!!!!!!!!!!L>A0!'??5*;R(B

$B!!!!G/Np!'#2#7:P!!!!!!!!!!G/Np!'#3#2:P(B
$B!!!!(B
$B!!=iIb5$!'2q<R$NF1N=!!!!!!=iIb5$!'<g?M$NM'C#(B

$B!!!!!!!!>\:Y$O%3%A%i!!"M!!(B
$B!!(Bhttp://qp-sp.com/sw/?media=pcya1





From nolei@arscryo.com Sat Mar 10 02:52:43 2007
Return-path: <nolei@arscryo.com>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HPwNf-0005NI-Pn
	for openpgp-archive@ietf.org; Sat, 10 Mar 2007 02:52:43 -0500
Received: from host-ip42-192.crowley.pl ([62.111.192.42])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HPwNa-00006g-Hm
	for openpgp-archive@ietf.org; Sat, 10 Mar 2007 02:52:43 -0500
Received: from kontrolahala (unknown [195.137.153.47])
	by nolei@arscryo.com (Postfix) with ESMTP id 9B91A3D8CB68
	for <openpgp-archive@ietf.org>; Sat, 10 Mar 2007 08:51:25 +0100
Message-ID: <000c01c762e8$d0aad5e0$2ac06f3e@kontrolahala>
From:	"nole i" <nolei@arscryo.com>
To: openpgp-archive@ietf.org
Subject: agent or relative
Date:	Sat, 10 Mar 2007 08:50:47 +0100
MIME-Version: 1.0
Content-Type: multipart/related;
	type="multipart/alternative";
	boundary="----=_NextPart_000_0008_01C762F1.325B67C0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Spam-Score: 4.5 (++++)
X-Scan-Signature: 8b6657e60309a1317174c9db2ae5f227

------=_NextPart_000_0008_01C762F1.325B67C0
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0009_01C762F1.325B67C0"


------=_NextPart_001_0009_01C762F1.325B67C0
Content-Type: text/plain;
	charset="windows-1250"
Content-Transfer-Encoding: quoted-printable

Email valid address franais deutsch espaol italiano. Latitude space =
center shuttle, launch!
On an image for and. Will contact winner stateiii.
Team will contact winner stateiii by any. Usually ships same day =
mahatma. Terms use, trademarks statement, home find! Ensure that hisher =
is lawful accordance applicable.
Company usa not, eligible! Parent company, usa not.
Laws manage profile terms use trademarks statement home find!
Items, gtgt click on. Street, city state longitude latitude space center =
shuttle launch. Manhattan dulles airport strategic?
Same day, mahatma inusually malcolm xposter, nelson.
Shall be entitled contest employee agent or! Shall be entitled contest =
employee agent or. Message board stageiii results are out team will. =
Relative microsoft its parent company. Message board, stageiii results =
are out team will, contact.
Earth search street city state.
That hisher is lawful. Message board stageiii results are, out. Links =
message board, stageiii results are out team?

------=_NextPart_001_0009_01C762F1.325B67C0
Content-Type: text/html;
	charset="windows-1250"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Dwindows-1250">
<META content=3D"MSHTML 6.00.2900.2180" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><FONT face=3DArial size=3D2>Email valid address franais deutsch =
espaol=20
italiano. Latitude space center shuttle, launch!</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>On an image for and. Will contact =
winner stateiii.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Team will contact winner stateiii by =
any. Usually=20
ships same day mahatma. Terms use, trademarks statement, home find! =
Ensure that=20
hisher is lawful accordance applicable.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Company usa not, eligible! Parent =
company, usa not.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Laws manage profile terms use =
trademarks statement=20
home find!</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Items, gtgt click on. Street, city =
state longitude=20
latitude space center shuttle launch. Manhattan dulles airport =
strategic?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Same day, mahatma inusually malcolm =
xposter, nelson.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Shall be entitled contest employee =
agent or! Shall=20
be entitled contest employee agent or. Message board stageiii results =
are out=20
team will. Relative microsoft its parent company. Message board, =
stageiii=20
results are out team will, contact.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Earth search street city =
state.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>That hisher is lawful. Message board =
stageiii=20
results are, out. Links message board, stageiii results are out=20
team?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><IMG alt=3D"sizes" hspace=3D0=20
src=3D"cid:000701c762e8$d096ffc0$2ac06f3e@kontrolahala" align=3Dcenter=20
border=3D0></DIV></BODY></HTML>

------=_NextPart_001_0009_01C762F1.325B67C0--

------=_NextPart_000_0008_01C762F1.325B67C0
Content-Type: image/gif;
	name="green areas.gif"
Content-Transfer-Encoding: base64
Content-ID: <000701c762e8$d096ffc0$2ac06f3e@kontrolahala>

R0lGODlh4AEQAYdSAAcAAHIJAACAAI2EAAAAeIcAcQ18fsXAyrvUyq3F7TYaBW4tAIEtDJcgBrgg
AtkUAAA5ABI/ADwyDWRFAHVFAKMxAL8+ANo8BABlCiFuADJSAGNmCXFiAKlXAMFUBeBtAACAABl3
BjVzAFyNAHV6AJ58ALaLCNR8AACXAxqbADqoDlqtBXSSAKKdAMqrAO6iCg64CR7CAEW5AFnGAHbC
CJ7AAbTFAOLIDADpAC3UADbjAG3WBXnVC5PuBL3rB9/iCQAJRxcLMTYFTVoAOYIKR6ACQ7EISd4A
RAAjTRIXNzsfTlssOHUbTJYnNLYSNOocPgMyORE3QEg9QmI6NXlINplIM85IM9Q1QABdRi5tTkRm
PWZWQoJXAKNhM7RtOdRiOwCAPyiCNE2COWOJN46JQ6Z6R7SJM+p5NwirRyKUM0OSQ2mUOYOiO5GX
N8yfROumOQ7JQiyxMzKyMme6Sne8RZHBScm7N9W9NQrrOBHrQ0vdPVzeOIbRSKPqRsDrReTmNgAO
hxEAijIAiF0DgXsAgJ0MfcUAgtQGdgAqiyATejIlfVsXe4YTdpMjiMUbdtMeiQBCfiU0d0xJd15C
jYVJga42hcg9dONFgANRhBZUdE5feFdVf4tggZxujL9Rdt1eiA17dRtzhTuLjlyAe357ip56d7uJ
gueDfgOodi6ReT6SfVybd3KpjZ+nd7GjdeSXdAC3jBLKijS8iWfNhXO+h5HEfb61gdG4eQXRfxvj
h0fSgV3pgYLZcZnSgsjei+3udwAIyhsAxEsAvl4Au40AwpcNxbgGw+kAsQQavRMhwDYcuVwTzIAe
wJkhuL4RyOwXxQ1AxBFNxUE6yFE2zodOzaE+yMwyvuJFuABduBVay0ZrwFNiyYJeyqFbzLZRxutW
sQt3ui2HwE1yyW6DtnqEv6GLtcyDxdSLzACeuSGYyDycuGGfyHqYyZ+TtL6Rtdqfwga2xCu9sTu7
zlTNwImzvp3Euf//5pKlmYt3fPAJAAD2DPX/AAAN//8A/wD5+vH/+CH5BACW2l0ALAAAAADgARAB
Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEmypMmTE+2pXMmypcuX
MGPKnEmzps2bOHPCRMmzp8+fQIMKHUp0pM6jSJMqXcpUadGnUKNKnUq1qtWrWLNq3cq1q1eNTcOK
HUu2rNmzZr+qXcu2rdutaOPKnUu3rt27ePPq3cu3r9+/gAOXfUu4sOHDiBMrfiq4sePHkCNLnrx3
seXLmDN3pcy5s2emmkPz/Ey6tGmyolOrXs26tWuSp2PLnk279ufXuHPr3s2bsO3fwIOv7E28uHG2
wpMrX868ufPnco9Ln069uvXrBaFrD4y9u/fv4MND/91Ovrz58+jTq98OoP369zHbA2gpn757l/Ln
29ePP7//lf7Vx1KAAd6UX3/87ZcTgQAKqJKDDj54X1gE/teghQMyiOCBCmaYoD0RwseXVPIVVCJB
J5qY4kArolghACxW6OKLMDqUn0EtxljjQwTq2J6OPgYpEI0z3uijjENWuF+BHjJ5YYdPiiilhB+G
GCKVH4I4IZQvQXilllnaxKGHMH1Jk5VjRuhlgjRe6CSZG7oJJ5j8jakll2DiOeV6aFa5JZZ/mmkm
lXMWaiCGhHb5p5iBprnlmoY2maGiYfZZKKQzWRrpnnaR+OOMKu54pKj/5JgkqaGCiuOnEQWY6kGm
Mv/UoqulslrrjivGequNtp5KaZSJ5plpo36GySldnpI6a6+3LovqqT2eKuSrrfpH7bU89lrip87e
qieww2b5JaZ0yimTpuAe22lUAbRbULsBFKTAvAUtYK9A9i5AELwIwesvvwLNK/DACAks0YkrGnxQ
vhMBPJDBENMLqrPR5quvrMw6vK+70FpbpKka/xNyyOJd9Bi8LQncUr4dRqjySw/EfO6bLr2MkwM4
q4SzAyyh/KtOPq/UwNAqET10Ay3tbI/STTr5b7vxLTruhEdXHdPOWLcUdLAq2azuulCFrPBADG/8
tNn9cozQzv9gnRDJDD2ttshzE5TP3Q3XfbRAVQ//bdC/Bo399tl/1/2P4A9LTHe8/jJkMUGIh6xr
yRI95rU9R2sN9UpYd86zSjE/ANPlKc/btekwZY6T3EEz7dLWN8GuOuZWl076oC/dfffrm2/qIMv2
AD+T8PZcTvrXeh2mscNw/7N3QmMjPhDbEJWN773XX2wQ9RE9T7a9K1m8QM0DuzS7TaQf77rOOa+k
u/u7h4v8bYZx3zbOQB7UfMCKH97/9PiDiOCi97+BMOCAE2lR6AgSugcEjmDyKuBCcrTAVbHKSAKp
YAZjNhAOMlCD1XoW5VLimPXZ44AMsN1K/NUzn0HghTCE4ekGVj6VbI2FLZHhoR4lIM8xjYY1vJrn
/1bitSCyBIUsMSACEfLCgsTQggUD4v9QSBAUMqBjHhtIyGDoxCaOECOP0WG6xEiBMrqkjBRQSQzX
CCgMobElaEwjSzhAR5y8EY5mtMcaY6iSOPpxJnuEwEqQOEhCtsSQc6SjIhfZRjutRIwbyhEVqzhJ
P5bxIFwkCBq/yMlOSiSQmfyHAEZJSgF48pSoHMr8VmmaVIaElbCckitnScta2vKWuIRNLMmTy14e
ZJfADKYwh0nMYhpzLoQhAAF8eRBlKmQyyjymMd8EDGDIBAhAUFRZsLkSbqrEm3d6zKLCUs2cRPMv
55TmMCc0Tjrpp51mYWedjKUdeMKEH/wATDnVuf/OeXYzm/bAZ38k1KBvYvOgLDkoQoeFJYI61Elv
UqZEV1LNiprrTPyRKAFqcp+OvhNRGEKUNsMpT9w1jZ78hAxULrgjZ/7DpS6qVUx3JdN/4HMgN12I
SzUqEJhy66cCqWhQgdHTZRZVWjFKUkM+Vc2hMmSnRnUpwp7V1KMyJKdY5YdSt6oQmPoUg8xMjUZh
+lKjMquiRCVIVb0aVaOWdakwupGtpIqrGrGUq0AlCFnh6lSIIMmmWhVITlWUVLjSCrA4DaxCsDkQ
xtb0sWENjWNXxdX8zfSuj2UWrKZqK8dO1rFV/cdax2pWVPGUr9ByiEIVWtjMZlGzB0ErWgdCWrf/
JgSzmI1saGCb1yIVhK6FZath7ZqrGgnXtZVtrUH2ihDmOhOjTkrnOeVZ0JrUdqMOvYl0sUvdlDpm
pSJk6VQh29u8Tk5IYC0vcQuLW2WtF2NbhS1lyVvX+OYWvvRVLkJ++l7I/tK7eAHvfkVoX/bWF4u8
mqmBF4xXDDILrAIp0zztaZ/shvPCbzLpQ4tFYTd5tLoXDnGHAbyU3shXtz0BKZtWTOIWj1Q2KI4x
CfnkSBfbOJgyBsmNd8zjHvu4mDn+yo+HTOQiG1kyQf7OkYWTZCUv+TdSoaGCawpEh/htwAZpoAeb
BeGD6E53JlGcmBXAPyn/430qiZ8UFYDRST35/8m9i3MAWpjdEffOfEhzs4XtceeZtG9pnzMiDVc4
ZxsWWiaoKx6bT2folwStz3+mSaIVPcPjyeTOWm4h7Gw26Tcvh2gsAXWk25foTsMEfC8x4gFnAuqa
yAx0omMfS15tj1ejGtUzQV0Ndb3oJELwf9hryJb/4cH7LoR7mN3ylu/FbO01OSONiTSgG01oWVub
oS/JGuc+FxNTRw3EE+ozEdns7ZFy6D7e1ra0V42+XlMawyg9oiFf+EhBwrug7hmxp2mTx5Xkkd0q
YffTGPWSPPZbj2w8ZAptYkWAI7zeMMEhwQ80IUvKMd/z+RO9CV7d7jJ0QgBn98YfHvAUWtEez/9O
jBcH4kUMYIAgLhdIE1fOEJqzHAIyxzlCUICCLj4k5psdyCgRQsqIPPEfT1TJKF+ydHuUsiVNr8nI
Sb5Hqdt75FFvetYFwJJScp2U+2bO1KlubzXaGwYwUAnabbJ2l3id6zDheUtwgIObyP0lLl9J211C
d7rjhI8IH/nYN/ynqNNk6hvXhz5y0vfGq8Tvj6+7PYD+D8oT5Ik2T3lb0D4Qzg+E5wIBfYMbMvSC
WB7otupV5hNieZi/XCCt7zwM/uH5hjReILcPfc8NUnu0z/7yOk/wY1fvEMqv3IulFyXcu/715odd
LFJZo0GODvvXV7/m0kd68LX/eZ57f/rbX4j/4pm4/d7/vvTJZ0jtaf97gfj+/Tm/efhF/w+bKF7x
LLn7UaKu/7sLvuwr4XcCKHnPBxpNBn9CV0oJuIAb4ReQdxT4p3fvx3xgV2FcU4BOoXkauIEUgYEe
+IHQx4G4AYLAIYJaQYKrZIJBhoIs2II5oYIw6BG5dViLtVpAkFwxmHKnJVR9tRCshViJNRCylVZc
dl4dg1rIVVZjNUH9NVhAWIOxRYTzRVu1lYOJ4Rjg5CXaxV0sZg/7pBJfqBLp1GZ79mLdNU4agnEs
EYY2MYYgNlAvFmBWqEuCUVIfdSgW9mHXBFA60WHnpFFiiF3ghHI4+A8/2Fg3GBGTpVZS6FsG/7GI
c+hKrHJazHVb/VVTlahXtuVXBGZg5vUslWgqpDVc47VZmnVikfhFd/UjqHhZoiJeOdKKodKJMSVX
deUxp3herZiLQedfvpiKntReslhg+qVfwziFCmEkDvYs0cKKnbiLzBiNOHiMwHiCjXGGGtZxXQiH
b4gTI3ZuWsiNbuZxISZhcehh4hJvpVGNUTGDx9heyqUttKhgsqiMKcKLUwiL9RiN9jhlv8iOanGN
AlJS0MVhSyI16tg0ePiGaZiQd8FDFuiCzgGM7qRvEsljAPlMF7mRHNmRPZaRouGRkwGSJFmSJnmS
ryGSKlmAKNmSqLSSwOSSMjmTKAaTIkKTr/9kkyqFk26hkz5ZZDwZlN3xkwYolLlBlEiZlEpZgkbZ
lCKxlFAZlVLZFE5ZlVZ5lViZlVpZHFOZF1v5lVfYlWI5lmRZlmZpTGCZlplxlsuhlm75lnAZl9XI
ljeJlXQZFnKZl3q5l71xl375lzTBlxoImITJkYKJGbGYmPMogzRIED5UOPHyLvtTZg9UQArTN1eW
OP+DOBCkmZLJOodWkYMiN4U5GbDDZ6cZNOKzmjbhQ9LmQ7nzZbLJEsQTPLUJM7S2Eg3kEqFTNJip
OTfUZ/+iabMYLVjUZZhZNYf5ExRzLaspPg4BmpHpmAFkQa9oK8szmaoyLUilRYbzD9D5Pc7/dmZf
Zjd4s52DM52Lo5401Z1pWUKj1jkssT6W1m7uZkTCYjvuxmjAUmNRs2J2EiImBGu7SaAHOWFJI224
GWu6mZupGZqlGRUDZGaUCUAOYBHNaaEHIT36wzGN8xCTJBANd0VKRKKeCZnMUzdVVqGWlRD2cz8X
WqKC6RiQVHX1BoB3hBRXEiGQVHILd3j0Bng3kaP2YEksQaT5KW8n56N4FEf+dnBJChOIdEION6Wl
+RJSUXQC8XYJaEro+UmZF0rK56XAF34J8XZkChHfp3vet3v/sKYEoaUFUXRaKqc5h3OZJKbaZ6YG
AadsGqd2Cm1XGhc6VKgb16M9mhPe5xKL/7oSjcoSiQoTjfeAOWGoV+dFevqm9EcQ9/cPneqp48ep
4/epn9qlaFoQfuqnW+p1yzkULvd6r1p9sNp6bVqrbsoQsep6ltd3UNQQtkoRuRqsQJerBKGquEd3
x4oD/8CrgOqldJp+Y3qqzcqlB3F/1qoPJ9GRyYJUnIWqtmqsZ5p+Clism3qnDhFICcRf3MosxKoq
29IrzMqrzNp9t0p00qoQ14qtreoTz9qlY9qrFPGtxpojvucQBct+7fcQ9uB7C5t2ard2DMt3lCqB
DtuwE8gSfReAk5pDg4cgFygTF3ulUzGpyjoQJMt76ycR74eAANuiychfi2l6r3p6M2t9BP8xr2Uq
f2LqdFv3dPmnfzEhRpEKExErstGXfXeaqQdlEZl6EAdbEE/7srcYs6Yqrqz6iJDofuu3slBbexa7
dwbFhzEBBmS7EmRbtjVxtoMaGTaYUKvlEguFFBU4E3HLEmcLBi6BtkpneHNrE3ert/bwt3jrdoa3
En3rdVDHtz5rtoALE2rLuIPLuC/xuEYrFaeliZUoURahuU+ViZerhASxtKGbtTrFuZi7iVSIuqCb
untlukrYupk4uomIiIkYtmJbtxE6FfjkhIK1u80Uuw3Bgwmxu8Rrisa5uqzLiQ+mmBAmvEMVWgIh
urQ7u8cJVs4rWsJ7Xa4LlpFRY/5pg2//WxMWtYfh6xK1BbeDaLtb6Ib2AIgH+iETxRLu+09iaw8K
9b52grv2W7fnu7bKQSMOmY3+u5H7+hMDfMAIrB4FvMAMrGMJ/MDK0cASPMG6AcElRsEdYcEavME7
icEe/MGqwcG8BMIkvJwifMIorBIlvMIs3MJCmcIwHMM44cI0XMM2/JQyDBg3HJQ53ME42cNALEs2
HMREXMQuscNFYcRKvMRCPJNMvBNIvJVPPMVU3BxRfMXZ8ZdYvMVRUcVefMRcXH9fjGRhbIVjPGQQ
6U4HepDoKClqjI7z+Fdcprypd50IRorUmCx1nF7Gmcco1o+tdVhybInL6IqjF8gHdl/w/1iISIjI
wpeExPiPhGWde2yPWUTIxYWLl+yOxbi80wEZerhhelaG36aN43iHpFyO4LaNoaxvyOhf0DjJdXzI
TNiLkOyP+HXLjgzL/eXJkxyDvVVTqPiO4WXHwnxgr7zLh2xs2fLLjOyPwaxejazM+NjMtEyPl3jM
nYwqfhxj0ZzNyWyJWOaJmXyPxQxh+ji1sXKOjUKGpqyN/kkp4LjK5+jO5EjP5ehR/omQHBnK8Oa9
DtlGDInKqizK2sTPdUbQSZTLyRXLhrxgxGy8lcxZXUbJ16nJhWzIvMXNVMsaoKzQ7dTOOgrSBB3S
Cn3KEYmNIx2RqTzKJNWF/jwzB+0n9f/cEpQlj7YMze9VzdX4zeNcjNaszctszEmoyMgczJzIjfpG
jq3sT+6M0t3Y0uYoYpViLB53z6pskegxFYrjodM5N3XznVEEOWSmmWUtEIRTZpzZmWAdmUaS1s/5
EN8JONmSI51JNxvDEJmZ12g9ncHG10HNKhIk1uupnv3zPxnDnhvYQAVRngSBmdsTo9FJ16l42GUt
m+f5mAvR1scpEOeZY2cc2lhaxkks2qY92qTtZKctw6ldGKv9GK2Nwa8921oc2zVM27id27q92xts
23ABk75Nw7w93MTd23JZ3Mg93MHtwsk9GMv93CRJlNAtFc0dgl9Z3UU83dqditiNGtv/7RNS+d3i
LdwnPN7mDZLdnd7qvd5+ed4TzN7W7d7yPd/0Xd/2PRrwDcP3vd/83d/+/d8AHuAsnN8ZuN+kWxLQ
+g9kaxm+TLsiceBxKRzsSxfp277YRb/6G7/yq+Hse07gW79Ngbvpi7savhLxe10uwYYQfBjQWxCQ
COEQ0eJPWFwF4bsGAb02HoT/2JjPK+OOWFlNBb18jNQHwbsaSeA1HYgtUeFHUeFY3RLRxL6DGKAn
jc//dOX3lE8CpRJbTlA89OX6MeEsbcGHYZyjOIo8buQN3oo3peZ2jFmZeF8+jhBBToRCHldvvl6f
slcpbk0ifBjSO1m9QlaliIjJzMxY/2uI1GtVThVaVYUkg+WEtoJt/qyG+HaH9/HhY47kRzGG6STS
XJ5PK9Hlpaxn4FS+d7IoY6iHMU1Rfu6Fr25hChHpWjVYuQVVUPXMui7gU8YqkDjLQI3LwK5gjt6I
nTW7jOVZi55UBT2/U91QgThW8IzK9qTVnP7sF+aGq76N2K7kJn7h3w7HUA7uYO7tkYRt2O4oVt5d
Ym7u177SVp6H3F7PoJ7Q3ZjG0G7SUk3V9x7TrW7Q3f7uC8LKNB3v/L7panLS+J7PofzLJzbsvozT
Ow7Owb6XwrHwjoJxAO3SBV2R/X5RCK0kB39vZ6HvounUaMHruPyy4fwUEj/Ho1KE1mhCJBnRzWBh
k2UuI66y8zo/8zzv8y8i8+8K9D1/vEMBwM7YI0afkwK/77bRJi/S9FJv3Cpf9VY/QlO/4lf/nlmf
wPf9507c9WK/xFxs2lvP9WOf9k989mwfGmp/FgD59mv7wdgdxbMdEAA7

------=_NextPart_000_0008_01C762F1.325B67C0--



From ver_front@yahoo.co.jp Sun Mar 11 08:53:07 2007
Return-path: <ver_front@yahoo.co.jp>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HQNXv-0006MR-So
	for openpgp-archive@megatron.ietf.org; Sun, 11 Mar 2007 08:53:07 -0400
Received: from [222.127.4.230] (helo=pc26)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HQNXu-0005do-7H
	for openpgp-archive@megatron.ietf.org; Sun, 11 Mar 2007 08:53:07 -0400
From: =?iso-2022-jp?B?dmVyX2Zyb250QHlhaG9vLmNvLmpw?=<ver_front@yahoo.co.jp>
Subject: =?iso-2022-jp?B?GyRCbFRCdCRKSGtMKThyOl0kcjNaJDckXyReJDskcyQrISkbKEI=?=
MIME-Version: 1.0
Reply-To: <ver_front@yahoo.co.jp>
Date: Sun, 11 Mar 2007 19:45:07 +0900
Content-Type:text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 4.5 (++++)
X-Scan-Signature: 769a46790fb42fbb0b0cc700c82f7081


$B%;%U%l>R2pC4Ev$N0BF#$H?=$7$^$9!#(B

$B%9%]%s%5!<%5%$%HMM$h$j?75,$4>R2p0MMj$r<u$1$F$*$j$^$9!#(B

$BDL>o$N%a%kM'!&Nx?MJg=8$H$O0c$$!"B(#H4uK>$N=w@-$N$_$H$J$j$^$9!#(B

$B0l@ZNA6bL5$7$N$4>R2p$H$J$j$^$9$N$G!"(B
$B%a!<%k$NAw<u?.$r4^$a$I$l$@$1MxMQ$7$FD:$$$F$b40A4$K!o#0!#(B

$B40A4L5NA$G$N$4>R2p$G$9$N$GAa4|Dy$a@Z$j$N>l9g$,$4$6$$$^$9!#(B

$B#H=PMh$k=w@-$N?t$O8B$i$l$F$*$j$^$9!#(B

$B$^$?!"Dy$a@Z$j$H$J$C$?:]$OM=9p$J$/=w@-$NJQ99$r$9$k>l9g$b$4$6$$$^$9$,!"(B

$B$4MF<O$/$@$5$$!#(B


$B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B
$B!!!!!C!!!!!!B(#H4uK>$N=w@-$4>R2p!!!!!C(B
$B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B

$B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B

$B!!!!!!!!L>A0!'<SF`$5$s(B

$B!!!!!!!!G/Np!'(B29$B:P!!!!(B

$B!!!!!!!!?&6H!'KG0W4X78!!!!(B
$B!!!!!!!!(B
$B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B

$B!!!!!!!!L>A0!'$f$$$5$s(B

$B!!!!!!!!G/Np!'(B33$B:P(B

$B!!!!!!!!?&6H!'4G8n;N(B

$B!!!!!!!!!yIaCJBN83=PMh$J$$$h$&$J#H$J;v$r$7$F$/$l$k$=$&$G$9!#(B

$B!!!!!y!=!=!=!=!=!=!=!=!=!=!=!=!=!=!=!y(B

$B!!!!!!$*Fs?M$N>\$7$$>\:Y$O$3$A$i"M(B
$B!!!!!!(Bhttp://qp-sp.com/fnv/s.php






From owner-ietf-openpgp@mail.imc.org Mon Mar 12 19:05:25 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HQta0-0002Lo-W2
	for openpgp-archive@lists.ietf.org; Mon, 12 Mar 2007 19:05:24 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HQtZz-00075G-HN
	for openpgp-archive@lists.ietf.org; Mon, 12 Mar 2007 19:05:24 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo6cN009086
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Mon, 12 Mar 2007 15:50:06 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2CMo6OU009085;
	Mon, 12 Mar 2007 15:50:06 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from ns4.neustar.com (ns4.neustar.com [156.154.24.139])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo3u9009077
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@imc.org>; Mon, 12 Mar 2007 15:50:05 -0700 (MST)
	(envelope-from ietf@ietf.org)
Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10])
	by ns4.neustar.com (Postfix) with ESMTP id 788DD2ACD7;
	Mon, 12 Mar 2007 22:50:02 +0000 (GMT)
Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43)
	id 1HQtL8-00056B-84; Mon, 12 Mar 2007 18:50:02 -0400
Content-Type: Multipart/Mixed; Boundary="NextPart"
Mime-Version: 1.0
To: i-d-announce@ietf.org
Cc: ietf-openpgp@imc.org
From: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-openpgp-rfc2440bis-19.txt 
Message-Id: <E1HQtL8-00056B-84@stiedprstage1.ietf.org>
Date: Mon, 12 Mar 2007 18:50:02 -0400
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.3 (/)
X-Scan-Signature: 14582b0692e7f70ce7111d04db3781c8


--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts 
directories.
This draft is a work item of the An Open Specification for Pretty Good Privacy Working Group of the IETF.

	Title		: OpenPGP Message Format
	Author(s)	: J. Callas, et al.
	Filename	: draft-ietf-openpgp-rfc2440bis-19.txt
	Pages		: 84
	Date		: 2007-3-12
	
This document is maintained in order to publish all necessary
    information needed to develop interoperable applications based on
    the OpenPGP format. It is not a step-by-step cookbook for writing an
    application. It describes only the format and methods needed to
    read, check, generate, and write conforming packets crossing any
    network. It does not deal with storage and implementation questions.
    It does, however, discuss implementation issues necessary to avoid
    security flaws.

    OpenPGP software uses a combination of strong public-key and
    symmetric cryptography to provide security services for electronic
    communications and data storage. These services include
    confidentiality, key management, authentication, and digital
    signatures. This document specifies the message formats used in
    OpenPGP.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt

To remove yourself from the I-D Announcement list, send a message to 
i-d-announce-request@ietf.org with the word unsubscribe in the body of 
the message. 
You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce 
to change your subscription settings.

Internet-Drafts are also available by anonymous FTP. Login with the 
username "anonymous" and a password of your e-mail address. After 
logging in, type "cd internet-drafts" and then 
"get draft-ietf-openpgp-rfc2440bis-19.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt

Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2007-3-12150820.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-openpgp-rfc2440bis-19.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2007-3-12150820.I-D@ietf.org>

--OtherAccess--

--NextPart--




From naturecoastmall.com@oaclub.com Tue Mar 13 07:14:39 2007
Return-path: <naturecoastmall.com@oaclub.com>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HR4xj-0002wf-1W
	for openpgp-archive@ietf.org; Tue, 13 Mar 2007 07:14:39 -0400
Received: from [87.109.237.152] (helo=localhost)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HR4xg-0002qj-JP
	for openpgp-archive@ietf.org; Tue, 13 Mar 2007 07:14:39 -0400
Message-ID: <000001c76560$43ac9c80$0100007f@localhost>
From: "Dallas Robinson" <naturecoastmall.com@oaclub.com>
To: <openpgp-archive@ietf.org>
Subject: Buy OEM Software
Date: Tue, 13 Mar 2007 14:14:28 +0300
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.1290
Importance: Normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2000
X-Spam-Score: 3.3 (+++)
X-Scan-Signature: 7aafa0432175920a4b3e118e16c5cb64

OEM software - throw packing case, leave CD, use electronic manuals.
Pay for software only and save 75-90%!

Discounts! Special offers! Software for home and office!
             TOP 1O ITEMS.

  $79 Microsoft Windows Vista Ultimate
  $79 MS Office Enterprise 2007
  $79 Adobe Acrobat 8 Pro
  $49 Windows XP Pro w/SP2
  $99 Macromedia Studio 8
  $59 Adobe Premiere 2.0
  $59 Corel Grafix Suite X3
  $59 Adobe Illustrator CS2
 $129 Autodesk Autocad 2007
 $149 Adobe Creative Suite 2
http://llooem.com/?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t0

          Mac Specials:
Adobe Acrobat PR0 7             $69
Adobe After Effects             $49
Adobe Creative Suite 2 Premium $149
Ableton Live 5.0.1              $49
Adobe Photoshop CS              $49
http://llooem.com/-software-for-mac-.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t6

See more by this manufacturers:
Microsoft...Mac...Adobe...Borland...Macromedia
http://llooem.com/?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t4

Microsoft Windows Vista Ultimate
Retail price:  $399.00
Proposition:  $79.95
Your benefit:  $319.05 (80%)
Availability: Can be downloaded INSTANTLY.
http://llooem.com/2480.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t3
Best choice for home and professional. (37274 reviews)

Microsoft Office 2007 Enterprise Edition
Regular price:  $899.00
Our offer:  $79.95
You save:  $819.95 (89%)
Availability: Pay and download instantly.
http://llooem.com/2442.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t1
Sales Rank: #1 (121336 reviews)

Adobe Acrobat 8.0 Professional
Market price:  $449.00
We propose:  $79.95
Your profit:  $369.05 (80%)
Availability: Available for INSTANT download.
http://llooem.com/2441.php?53906403B9C0EE847B4042E284205F175585750BE7C8ECCE&t2
Top-ranked item. (31958 reviews)




From owner-ietf-openpgp@mail.imc.org Tue Mar 13 10:03:21 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HR7az-0003lr-18
	for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:03:21 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HR7ax-0003Xx-Kk
	for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:03:21 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhJel059649
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 13 Mar 2007 06:43:19 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DDhJIU059648;
	Tue, 13 Mar 2007 06:43:19 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from ns1.neustar.com (ns1.neustar.com [156.154.16.138])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhIsW059642
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@imc.org>; Tue, 13 Mar 2007 06:43:18 -0700 (MST)
	(envelope-from ietf@ietf.org)
Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10])
	by ns1.neustar.com (Postfix) with ESMTP id 9BB7426E78;
	Tue, 13 Mar 2007 13:43:15 +0000 (GMT)
Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43)
	id 1HR7HX-0002QX-H9; Tue, 13 Mar 2007 09:43:15 -0400
X-test-idtracker: no
To: IETF-Announce <ietf-announce@ietf.org>
From: The IESG <iesg-secretary@ietf.org>
Subject: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message 
         Format) to Proposed Standard 
Reply-To: ietf@ietf.org
Cc: <ietf-openpgp@imc.org>
Message-Id: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org>
Date: Tue, 13 Mar 2007 09:43:15 -0400
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 79899194edc4f33a41f49410777972f8


The IESG has received a request from the An Open Specification for 
Pretty Good Privacy WG (openpgp) to consider the following document:

- 'OpenPGP Message Format '
   <draft-ietf-openpgp-rfc2440bis-19.txt> as a Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action.  Please send substantive comments to the
ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, 
comments may be sent to iesg@ietf.org instead. In either case, please 
retain the beginning of the Subject line to allow automated sorting.

The file can be obtained via
http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt


IESG discussion can be tracked via
https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0




From owner-ietf-openpgp@mail.imc.org Tue Mar 13 10:42:35 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HR8Cx-0005jz-KD
	for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:42:35 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HR8Cv-0002YG-4u
	for openpgp-archive@lists.ietf.org; Tue, 13 Mar 2007 10:42:35 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER9tv062729
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 13 Mar 2007 07:27:09 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DER9NH062728;
	Tue, 13 Mar 2007 07:27:09 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER6fg062721
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@imc.org>; Tue, 13 Mar 2007 07:27:08 -0700 (MST)
	(envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178])
	(authenticated bits=0)
	by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2DEQgMG014436
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 13 Mar 2007 15:26:43 +0100
From: Simon Josefsson <simon@josefsson.org>
To: ietf@ietf.org
Cc: ietf-openpgp@imc.org
Subject: Re: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message  Format) to Proposed Standard
References: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070313:ietf-openpgp@imc.org::qw6EqPbUi/ilw5Ur:0Jzu
X-Hashcash: 1:22:070313:ietf@ietf.org::X+KI19qLzrrlajE8:Esqs
X-Hashcash: 1:22:070313:ietf-announce@ietf.org::Uh10b+QwS0vF6hE5:8NDV
Date: Tue, 13 Mar 2007 15:26:42 +0100
In-Reply-To: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org> (The IESG's message of
	"Tue\, 13 Mar 2007 09\:43\:15 -0400")
Message-ID: <87mz2hw76l.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=0.2 required=4.0 tests=AWL,BAYES_50,FORGED_RCVD_HELO,
	TVD_FUZZY_SECURITIES autolearn=no version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: fb6060cb60c0cea16e3f7219e40a0a81


Hi!

I started a review by going through the reference section.  There
seems to be some editing left to do...

There are reference to old documents, including:

  RFC 2279 -> RFC 3629
  RFC 1750 -> RFC 4086

There are normative reference to non-standards track RFCs, including:

  RFC 1641
  RFC 1951
  RFC 1991 (which documents is intended to obsolete?)
  RFC 2144

The following reference are never cited in the text as far as I can
tell.  Most of them should likely be removed, but citing
[BLEICHENBACHER] at some appropriate point may be useful.

    [RFC1423]        Balenson, D., "Privacy Enhancement for Internet
                     Electronic Mail: Part III: Algorithms, Modes, and
                     Identifiers", RFC 1423, October 1993.

    [RFC1641]        Goldsmith, D. and M. Davis, "Using Unicode with
                     MIME", RFC 1641, July 1994.

    [BLEICHENBACHER] Bleichenbacher, Daniel, "Generating Elgamal
                     signatures without knowing the secret key,"
                     Eurocrypt 96. Note that the version in the
                     proceedings has an error. A revised version is
                     available at the time of writing from
                     <ftp://ftp.inf.ethz.ch/pub/publications/papers/ti
                     /isc/ElGamal.ps>

    [DONNERHACKE]    Donnerhacke, L., et. al, "PGP263in - an improved
                     international version of PGP", ftp://ftp.iks-
                     jena.de/mitarb/lutz/crypt/software/pgp/

    [MAURER]         Ueli Maurer, "Modelling a Public-Key
                     Infrastructure", Proc. 1996 European Symposium on
                     Research in Computer Security (ESORICS' 96),
                     Lecture Notes in Computer Science, Springer-Verlag,
                     vol. 1146, pp. 325-350, Sep 1996.

    [RFC1983]        Malkin, G., "Internet Users' Glossary", FYI 18, RFC
                     1983, August 1996.

/Simon

The IESG <iesg-secretary@ietf.org> writes:

> The IESG has received a request from the An Open Specification for 
> Pretty Good Privacy WG (openpgp) to consider the following document:
>
> - 'OpenPGP Message Format '
>    <draft-ietf-openpgp-rfc2440bis-19.txt> as a Proposed Standard
>
> The IESG plans to make a decision in the next few weeks, and solicits
> final comments on this action.  Please send substantive comments to the
> ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, 
> comments may be sent to iesg@ietf.org instead. In either case, please 
> retain the beginning of the Subject line to allow automated sorting.
>
> The file can be obtained via
> http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt
>
>
> IESG discussion can be tracked via
> https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0




From web@netsite.com.br Thu Mar 15 14:24:03 2007
Return-path: <web@netsite.com.br>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HRucN-0008O3-7M
	for openpgp-archive@megatron.ietf.org; Thu, 15 Mar 2007 14:24:03 -0400
Received: from 200-233-202-023.static.netsite.com.br ([200.233.202.23] helo=smtp4.netsite.com.br)
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HRucK-0003B1-Hc
	for openpgp-archive@megatron.ietf.org; Thu, 15 Mar 2007 14:24:03 -0400
Received: from servweb02 (brasilis-f4-055.static.ctbctelecom.com.br [200.170.171.55])
	by smtp4.netsite.com.br (Postfix) with SMTP id 894DE83421D
	for <openpgp-archive@megatron.ietf.org>; Thu, 15 Mar 2007 15:23:56 -0300 (BRT)
Date: Thu, 15 Mar 2007 15:25:26 -0300
Subject: Attn:Sir/Madam(CONGRATULATIONS!!!)YOU HAVE WON 
To: openpgp-archive@megatron.ietf.org
From: UK LOTTERY  <ukpayofficeclaim1@yahoo.co.uk >
Reply-To: ukpayofficeclaim1@yahoo.co.uk 
MIME-Version: 1.0
Content-Type: text/plain
Message-Id: <20070315182356.894DE83421D@smtp4.netsite.com.br>
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: 3.6 (+++)
X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976

UK Lottery Headquarters:=20
Customer Service=20
The National Lottery=20
P O Box 1010=20
Liverpool, L70 1NL=20
UNITED KINGDOM=20
(Customer Services)=20
Ref: UK/9420X2/70=20
Batch: 074/05/ZY345=20
ATTN:Sir/Madam
We are pleased to inform you of the result of the Lottery WinnersInternat=
ional programs held on the 13th MARCH,2007. Your e-mail address attached =
to ticket number 56475612545-187 with serial number 5368/03,batch number =
151085135,lottery ref number UK/9420X2/70 and drew lucky numbers 4 5 16 1=
9 21 49 20 which consequently won in the1st category, You have therefore =
been approved to claim a total sum of =A3691,252 (Six hundred and ninety =
one thousand, two hundred and fifty two pounds sterling) in cash credited=
 to file KTU/9023118308/07.This is from a total cash prize of =A32,073,75=
6 (Two million, seventy three thousand, seven hundred and fifty six pound=
s sterling),
CONGRATULATIONS!!!
Due to mix up of some numbers and names, we ask that you keep your winnin=
g information confidential until your claims has been processed and your =
money Remitted to you. This is part of our security protocol to avoid dou=
ble claiming and unwarranted abuse of this program by some participants. =
All participants were selected through a computer ballot system drawn fro=
m over 40,000 company and 20,000,000 individual email addresses and names=
 from
all over the world. This promotional program takes place every year.This =
lottery was promoted and sponsored by Association of software producers. =
we hope with part of your winning,you will take part in our next year 20 =
million Euros international lottery.
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
To file for your claim, please fill the enclosed form and send it by emai=
l to out lottery paying officer for the processing for your claim with th=
e informatin below:
Remittance Department Director,
OVERSEAS CLAIMS UNIT.=20
United Kingdom Lottery Fiduciary=20
Contact Person: Rev Eddie James=20
Email:ukpayofficeclaim1@yahoo.co.uk=20
TEL:+44 70457 14384
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
THIS FORM SHOULD BE FILED BY THE LOTTERY WINNER OF THE STATED FUND FOR
VERIFICATION BEFORE PROCESSING THE LOTTERY WINNING:
FULL NAME: .....................................................
RESIDENTIAL ADDRESS: ...........................................
OCCUPATION: ..........................................
DATE AND PLACE OF BIRTH: ..............................
COUNTRY OF RESIDENCE: ................................
TEL NO: ..............................................
FAX : ................................................
EMAIL: ...............................................
TICKET NUMBER: .......................................
BATCH NUMBER: ........................................
AMOUNT WON: ..........................................
OUR E-MAIL ADDRESS: ..................................
Our winners are assured of the utmost standards of confidentiality, and p=
ress anonymity until the end of proceedings, and beyond where they so=20
desire. Be further advised to maintain the strictest level of confidentia=
lity until the end of proceedings to circumvent problems associated with =
fraudulent claims. This is part of our precautionary measur to avoid doub=
le claiming and unwarr! anted abuse of this program. Any=20
lottery double claim dedected by our monitoring committee will lead to th=
e UK national lottery cancelling the winnings. making a loss for both the=
=20
real winner, and the fake (intended) claimer.=20
CONGRATULATIONS!!!=20
Mrs. Calister Green.!=20
The National! Lottery=20
P O Box 1010=20
Liverpool, L70 1NL=20
UNITED KINGDOM=20
UK NATIONAL LOTTERY.=20
COPYRIGHT =BF 2007 ALL RIGHT RESERVED=20





From web@netsite.com.br Thu Mar 15 14:24:03 2007
Return-path: <web@netsite.com.br>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HRucN-0008OG-F5
	for openpgp-archive@ietf.org; Thu, 15 Mar 2007 14:24:03 -0400
Received: from 200-233-202-023.static.netsite.com.br ([200.233.202.23] helo=smtp8.netsite.com.br)
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HRucK-0003B2-Hc
	for openpgp-archive@ietf.org; Thu, 15 Mar 2007 14:24:03 -0400
Received: from servweb02 (brasilis-f4-055.static.ctbctelecom.com.br [200.170.171.55])
	by smtp8.netsite.com.br (Postfix) with SMTP id B26F3D009CC
	for <openpgp-archive@ietf.org>; Thu, 15 Mar 2007 15:23:56 -0300 (BRT)
Date: Thu, 15 Mar 2007 15:25:26 -0300
Subject: Attn:Sir/Madam(CONGRATULATIONS!!!)YOU HAVE WON 
To: openpgp-archive@ietf.org
From: UK LOTTERY  <ukpayofficeclaim1@yahoo.co.uk >
Reply-To: ukpayofficeclaim1@yahoo.co.uk 
MIME-Version: 1.0
Content-Type: text/plain
Message-Id: <20070315182356.B26F3D009CC@smtp8.netsite.com.br>
Content-Transfer-Encoding: quoted-printable
X-Spam-Score: 3.6 (+++)
X-Scan-Signature: d185fa790257f526fedfd5d01ed9c976

UK Lottery Headquarters:=20
Customer Service=20
The National Lottery=20
P O Box 1010=20
Liverpool, L70 1NL=20
UNITED KINGDOM=20
(Customer Services)=20
Ref: UK/9420X2/70=20
Batch: 074/05/ZY345=20
ATTN:Sir/Madam
We are pleased to inform you of the result of the Lottery WinnersInternat=
ional programs held on the 13th MARCH,2007. Your e-mail address attached =
to ticket number 56475612545-187 with serial number 5368/03,batch number =
151085135,lottery ref number UK/9420X2/70 and drew lucky numbers 4 5 16 1=
9 21 49 20 which consequently won in the1st category, You have therefore =
been approved to claim a total sum of =A3691,252 (Six hundred and ninety =
one thousand, two hundred and fifty two pounds sterling) in cash credited=
 to file KTU/9023118308/07.This is from a total cash prize of =A32,073,75=
6 (Two million, seventy three thousand, seven hundred and fifty six pound=
s sterling),
CONGRATULATIONS!!!
Due to mix up of some numbers and names, we ask that you keep your winnin=
g information confidential until your claims has been processed and your =
money Remitted to you. This is part of our security protocol to avoid dou=
ble claiming and unwarranted abuse of this program by some participants. =
All participants were selected through a computer ballot system drawn fro=
m over 40,000 company and 20,000,000 individual email addresses and names=
 from
all over the world. This promotional program takes place every year.This =
lottery was promoted and sponsored by Association of software producers. =
we hope with part of your winning,you will take part in our next year 20 =
million Euros international lottery.
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
To file for your claim, please fill the enclosed form and send it by emai=
l to out lottery paying officer for the processing for your claim with th=
e informatin below:
Remittance Department Director,
OVERSEAS CLAIMS UNIT.=20
United Kingdom Lottery Fiduciary=20
Contact Person: Rev Eddie James=20
Email:ukpayofficeclaim1@yahoo.co.uk=20
TEL:+44 70457 14384
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
THIS FORM SHOULD BE FILED BY THE LOTTERY WINNER OF THE STATED FUND FOR
VERIFICATION BEFORE PROCESSING THE LOTTERY WINNING:
FULL NAME: .....................................................
RESIDENTIAL ADDRESS: ...........................................
OCCUPATION: ..........................................
DATE AND PLACE OF BIRTH: ..............................
COUNTRY OF RESIDENCE: ................................
TEL NO: ..............................................
FAX : ................................................
EMAIL: ...............................................
TICKET NUMBER: .......................................
BATCH NUMBER: ........................................
AMOUNT WON: ..........................................
OUR E-MAIL ADDRESS: ..................................
Our winners are assured of the utmost standards of confidentiality, and p=
ress anonymity until the end of proceedings, and beyond where they so=20
desire. Be further advised to maintain the strictest level of confidentia=
lity until the end of proceedings to circumvent problems associated with =
fraudulent claims. This is part of our precautionary measur to avoid doub=
le claiming and unwarr! anted abuse of this program. Any=20
lottery double claim dedected by our monitoring committee will lead to th=
e UK national lottery cancelling the winnings. making a loss for both the=
=20
real winner, and the fake (intended) claimer.=20
CONGRATULATIONS!!!=20
Mrs. Calister Green.!=20
The National! Lottery=20
P O Box 1010=20
Liverpool, L70 1NL=20
UNITED KINGDOM=20
UK NATIONAL LOTTERY.=20
COPYRIGHT =BF 2007 ALL RIGHT RESERVED=20





From owner-ietf-openpgp@mail.imc.org Thu Mar 15 18:19:32 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HRyIG-0002A7-H7
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 18:19:32 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HRyI9-00043E-40
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 18:19:32 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLuuSH089947
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 15 Mar 2007 14:56:56 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2FLuu9h089946;
	Thu, 15 Mar 2007 14:56:56 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.236])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLut6i089939
	for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 14:56:56 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so356142wxd
        for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 14:56:55 -0700 (PDT)
Received: by 10.70.61.1 with SMTP id j1mr1969082wxa.1173995814959;
        Thu, 15 Mar 2007 14:56:54 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h20sm2123338wxd.2007.03.15.14.56.53;
        Thu, 15 Mar 2007 14:56:54 -0700 (PDT)
Message-ID: <45F9C122.9050200@buanzo.com.ar>
Date: Thu, 15 Mar 2007 18:56:50 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@imc.org
Subject: [OFFTOPIC] Editor under GNU/Linux
X-Enigmail-Version: 0.94.3.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 79899194edc4f33a41f49410777972f8


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sorry to bother: Any recommendation on a text editor to use that supports all formatting
requirements for an Internet Draft? My googling so far has only provided a MS Word template.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF+cEiAlpOsGhXcE0RAgn1AJ91xa0+Sf88K+NlWUNw0WGoHQp85QCfZXNO
ld+pOAyet5X7G8BS9ZoHpmM=
=8gpm
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Thu Mar 15 22:54:52 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HS2ai-0006SS-2a
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:52 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HS2ac-0004o4-Kf
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:52 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z6cK005131
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 15 Mar 2007 19:35:06 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2Z66S005130;
	Thu, 15 Mar 2007 19:35:06 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.229])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z5rk005122
	for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:35:06 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so431135wxd
        for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Received: by 10.70.74.6 with SMTP id w6mr2308727wxa.1174012505490;
        Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id i11sm1519266wxd.2007.03.15.19.35.03;
        Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Message-ID: <45FA0255.1090105@buanzo.com.ar>
Date: Thu, 15 Mar 2007 23:35:01 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
CC: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org>
In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.3.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.0 (/)
X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simon Josefsson wrote:
> I recommend any text editor and the xml2rfc tool:
> http://xml.resource.org/
> See also RFC 2629.

Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc,
too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd
rather use joe :P

Thanks for your time. I'll do my best, publish the Draft in this list, and ask for feedback :)

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF+gJVAlpOsGhXcE0RAlJBAJ0S9cgjU0KTkmTjZjbKZD1wvbzvawCeJwCg
5spprT8nmfi+UE0RCSPUJyU=
=Igzr
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Thu Mar 15 22:54:53 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HS2aj-0006U5-5H
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:53 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HS2ac-0004o3-Kg
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 22:54:53 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VS7r004953
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 15 Mar 2007 19:31:28 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2VSpR004952;
	Thu, 15 Mar 2007 19:31:28 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VP4d004941
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:31:27 -0700 (MST)
	(envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178])
	(authenticated bits=0)
	by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2VB6V001952
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Fri, 16 Mar 2007 03:31:11 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::CMr9oX8sv1hn/Lqv:BoVr
X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::bRMy06PyH6O6Gt8I:KNfF
Date: Fri, 16 Mar 2007 03:31:10 +0100
In-Reply-To: <45F9C122.9050200@buanzo.com.ar> (Arturo Busleiman's message of
	"Thu\, 15 Mar 2007 18\:56\:50 -0300")
Message-ID: <87ejnpsyvl.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00,
	FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 1ac7cc0a4cd376402b85bc1961a86ac2


"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Sorry to bother: Any recommendation on a text editor to use that supports all formatting
> requirements for an Internet Draft? My googling so far has only provided a MS Word template.

I recommend any text editor and the xml2rfc tool:

http://xml.resource.org/

See also RFC 2629.

/Simon




From owner-ietf-openpgp@mail.imc.org Thu Mar 15 23:08:34 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HS2ny-00014o-0q
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 23:08:34 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HS2nt-0006UW-Kw
	for openpgp-archive@lists.ietf.org; Thu, 15 Mar 2007 23:08:34 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qreV006085
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Thu, 15 Mar 2007 19:52:53 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2qrol006084;
	Thu, 15 Mar 2007 19:52:53 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qob7006078
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL)
	for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:52:52 -0700 (MST)
	(envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178])
	(authenticated bits=0)
	by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2qbje004702
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Fri, 16 Mar 2007 03:52:37 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar>
	<87ejnpsyvl.fsf@mocca.josefsson.org> <45FA0255.1090105@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::AkWLy2S2UiSbkfcU:1XRM
X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::paaMaEyNgUaKFwYr:092J5
Date: Fri, 16 Mar 2007 03:52:37 +0100
In-Reply-To: <45FA0255.1090105@buanzo.com.ar> (Arturo Busleiman's message of
	"Thu\, 15 Mar 2007 23\:35\:01 -0300")
Message-ID: <871wjpsxvu.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00,
	FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 7d33c50f3756db14428398e2bdedd581


"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Simon Josefsson wrote:
>> I recommend any text editor and the xml2rfc tool:
>> http://xml.resource.org/
>> See also RFC 2629.
>
> Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc,
> too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd
> rather use joe :P

You don't need XML support in your editor, joe will be fine.  If you
want a XML file to start editing from, have a look at:

http://josefsson.org/openpgp-header/draft-josefsson-openpgp-mailnews-header.xml

Good luck!

/Simon




From goody45goodyjp@yahoo.co.jp Sat Mar 17 07:26:44 2007
Return-path: <goody45goodyjp@yahoo.co.jp>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HSX3c-0005qB-0h; Sat, 17 Mar 2007 07:26:44 -0400
Received: from [222.127.4.233] (helo=pc13)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HSX3a-0005vy-AJ; Sat, 17 Mar 2007 07:26:43 -0400
From: =?iso-2022-jp?B?Z29vZHk0NWdvb2R5anBAeWFob28uY28uanA=?=<goody45goodyjp@yahoo.co.jp>
Subject: =?iso-2022-jp?B?GyRCJDQ+N0JUJCQkPyQ3JF4kORsoQg==?=
MIME-Version: 1.0
Reply-To: <goody45goodyjp@yahoo.co.jp>
Date: Sat, 17 Mar 2007 18:17:53 +0900
Content-Type:text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 4.5 (++++)
X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22


$B!!M6OG:J8BDj$N=P2q$$$H$J$j$^$9!#(B
$B!!lTBt$J%(%C%A$r$*K>$_$NJ}$K$O$4K~B-D:$1$k$H;W$$$^$9!#(B

$B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B
$B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B
$B!!CK@-EPO?<T!"FC$K=i?4<T$NJ}$+$i$49%I>$rD:$$$F$$$^$9!#(B

$B!!%(%C%A$J?M:J$,$?$/$5$sEPO?$7$F$*$j$^$9$,!"(B
$B!!$=$NCf$G$b$9$0$K2q$C$F%(%C%A$J;v$r4uK>$5$l$F$$$k(B
$B!!?M:J$NJ}$r:#2s?M?t8BDj$G$4>R2p$5$;$FD:$-$^$9!#(B

$B!!(Bhttp://qt-h.cc/mad/i.php

$B!!(B-------------------------------------------
$B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B
$B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B
$B!!(B-------------------------------------------

$B!!!!L>A0!'$a$0$_!!!!!!!!!!L>A0!'%"%-(B

$B!!!!G/Np!'#3#1:P!!!!!!!!!!G/Np!'#3#2:P(B
$B!!!!(B
$B!!!!!!!!>\:Y$O%3%A%i!!"M!!(B
$B!!(Bhttp://qt-h.cc/mad/i.php






From owner-ietf-openpgp@mail.imc.org Sat Mar 17 23:33:30 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HSm9C-0008AE-Fj
	for openpgp-archive@lists.ietf.org; Sat, 17 Mar 2007 23:33:30 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HSm97-0002E5-Mz
	for openpgp-archive@lists.ietf.org; Sat, 17 Mar 2007 23:33:30 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3Ct1V052291
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Sat, 17 Mar 2007 20:12:55 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2I3CtoQ052290;
	Sat, 17 Mar 2007 20:12:55 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3CVhN052272
	for <ietf-openpgp@imc.org>; Sat, 17 Mar 2007 20:12:52 -0700 (MST)
	(envelope-from jon@callas.org)
Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161])
	(Authenticated sender: jon)
	by merrymeet.com (Postfix) with ESMTP id 0DF425C5FB7
	for <ietf-openpgp@imc.org>; Sat, 17 Mar 2007 20:12:31 -0700 (PDT)
Received: from [66.93.68.165] ([66.93.68.165])
  by keys.merrymeet.com (PGP Universal service);
  Sat, 17 Mar 2007 20:12:31 -0700
X-PGP-Universal: processed;
	by keys.merrymeet.com on Sat, 17 Mar 2007 20:12:31 -0700
In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org>
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org>
Mime-Version: 1.0 (Apple Message framework v752.3)
Message-Id: <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
Cc: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>, ietf-openpgp@imc.org
From: Jon Callas <jon@callas.org>
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
Date: Sat, 17 Mar 2007 20:12:29 -0700
To: Simon Josefsson <simon@josefsson.org>
X-Mailer: Apple Mail (2.752.3)
X-PGP-Encoding-Version: 2.0.2
X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit
X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7BIT
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: a7d6aff76b15f3f56fcb94490e1052e4


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On Mar 15, 2007, at 7:31 PM, Simon Josefsson wrote:

>
> "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:
>
>> Sorry to bother: Any recommendation on a text editor to use that  
>> supports all formatting
>> requirements for an Internet Draft? My googling so far has only  
>> provided a MS Word template.
>
> I recommend any text editor and the xml2rfc tool:
>
> http://xml.resource.org/
>

Use xml2rfc. It's really the way to go these days.

The tool I'm using is a perl script that Tim Dierks created when he  
was doing the TLS spec. It's good enough that I've never moved to  
xml2rfc, but there are so many nice things about the XML one that you  
should use it. It will do all the right boilerplate and crap. That  
changes often and you'll tear your hair out doing it yourself. It  
took me ten days (!) to get bis19 changed to meet all the stupid crap  
that isn't documented anywhere.

	Jon


-----BEGIN PGP SIGNATURE-----
Version: PGP Universal 2.5.3
Charset: US-ASCII

wj8DBQFF/K4fsTedWZOD3gYRArTGAJ9/mc37hxn9ixtbDvEH4UVAXCiBagCgkCOe
3tOGA/pEnvMDrdQFhb5Vk7c=
=Giso
-----END PGP SIGNATURE-----




From owner-ietf-openpgp@mail.imc.org Sun Mar 18 08:36:32 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HSuci-0003Ni-3h
	for openpgp-archive@lists.ietf.org; Sun, 18 Mar 2007 08:36:32 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HSuca-0003Ve-Ms
	for openpgp-archive@lists.ietf.org; Sun, 18 Mar 2007 08:36:32 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGgak074339
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Sun, 18 Mar 2007 05:16:42 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2ICGgJ2074338;
	Sun, 18 Mar 2007 05:16:42 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGLwI074325
	for <ietf-openpgp@imc.org>; Sun, 18 Mar 2007 05:16:42 -0700 (MST)
	(envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so967431wxd
        for <ietf-openpgp@imc.org>; Sun, 18 Mar 2007 05:16:19 -0700 (PDT)
Received: by 10.70.100.14 with SMTP id x14mr6486136wxb.1174220178886;
        Sun, 18 Mar 2007 05:16:18 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209])
        by mx.google.com with ESMTP id h36sm6868058wxd.2007.03.18.05.16.17;
        Sun, 18 Mar 2007 05:16:18 -0700 (PDT)
Message-ID: <45FD2D8E.5070807@buanzo.com.ar>
Date: Sun, 18 Mar 2007 09:16:14 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
In-Reply-To: <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
X-Enigmail-Version: 0.94.3.0
OpenPGP: id=6857704D
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.2 (/)
X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Jon Callas wrote:
> Use xml2rfc. It's really the way to go these days.

Yes, most definitely. Simon is already helping me out with some of the details. I hope to post the
beta Draft asap. Thanks for your time, Jon!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Foros GNU/Buanzo: Respeto, Soluciones y Buena Onda: http://foros.buanzo.com.ar
Consulting and Secure Mail Hosting: http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF/S2OAlpOsGhXcE0RCqWYAJ9wz606aYi98+mrlH/Fr/bu7GFxFACeIY/1
XoZiqW1V0cqNQWRcogBVU/M=
=Z2WH
-----END PGP SIGNATURE-----




From goody45goodyjp@yahoo.co.jp Sun Mar 25 07:51:28 2007
Return-path: <goody45goodyjp@yahoo.co.jp>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HVRFv-0005xU-UE; Sun, 25 Mar 2007 07:51:28 -0400
Received: from [222.127.4.233] (helo=pc00)
	by ietf-mx.ietf.org with smtp (Exim 4.43)
	id 1HVRFt-0001EV-6H; Sun, 25 Mar 2007 07:51:27 -0400
From: =?iso-2022-jp?B?Z29vZHk0NWdvb2R5anBAeWFob28uY28uanA=?=<goody45goodyjp@yahoo.co.jp>
Subject: =?iso-2022-jp?B?GyRCJDQ+N0JUJCQkPyQ3JF4kORsoQg==?=
MIME-Version: 1.0
Reply-To: <goody45goodyjp@yahoo.co.jp>
Date: Sun, 25 Mar 2007 18:45:40 +0900
Content-Type:text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: 7bit
X-Spam-Score: 4.5 (++++)
X-Scan-Signature: 0bc60ec82efc80c84b8d02f4b0e4de22


$B!!M6OG:J8BDj$N=P2q$$$H$J$j$^$9!#(B
$B!!lTBt$J%(%C%A$r$*K>$_$NJ}$K$O$4K~B-D:$1$k$H;W$$$^$9!#(B

$B!!0lHLFH?H=w@-$H0c$$!"?M:J$NJ}$NEPO?$,Cf?4$G$9$N$G!"(B
$B!!@Q6KE*$K%"%W%m!<%A$5$l$kJ}$,B?$/!"(B
$B!!CK@-EPO?<T!"FC$K=i?4<T$NJ}$+$i$49%I>$rD:$$$F$$$^$9!#(B

$B!!%(%C%A$J?M:J$,$?$/$5$sEPO?$7$F$*$j$^$9$,!"(B
$B!!$=$NCf$G$b$9$0$K2q$C$F%(%C%A$J;v$r4uK>$5$l$F$$$k(B
$B!!?M:J$NJ}$r:#2s?M?t8BDj$G$4>R2p$5$;$FD:$-$^$9!#(B

$B!!(Bhttp://qt-h.cc/mad/i.php

$B!!(B-------------------------------------------
$B!!!!(#(!(!($!#"h!y!!:#2s$N$4>R2p=w@-!!!y(B
$B!!!!("!@!?("!!!!!!!y!!!!!!!!!!!!!!!!!!!!!y(B
$B!!(B-------------------------------------------

$B!!!!L>A0!'$a$0$_!!!!!!!!!!L>A0!'%"%-(B

$B!!!!G/Np!'#3#1:P!!!!!!!!!!G/Np!'#3#2:P(B
$B!!!!(B
$B!!!!!!!!>\:Y$O%3%A%i!!"M!!(B
$B!!(Bhttp://qt-h.cc/mad/i.php






From owner-ietf-openpgp@mail.imc.org Tue Mar 27 09:23:27 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HWBe3-0003cU-7d
	for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 09:23:27 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HWBe0-0005Go-Sv
	for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 09:23:27 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCpYSX069964
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 27 Mar 2007 05:51:34 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2RCpY9D069963;
	Tue, 27 Mar 2007 05:51:34 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from alice.acmet.com (static-202-238-16-61-primus-india.net [61.16.238.202] (may be forged))
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCp6VR069940
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 05:51:30 -0700 (MST)
	(envelope-from hariharasudhan@acmet.com)
Received: from hariharan (localhost [127.0.0.1] (may be forged))
	by alice.acmet.com (8.11.6/8.11.6) with ESMTP id l2RD8vR19641
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 18:38:57 +0530
From: "Hari Hara Sudhan" <hariharasudhan@acmet.com>
To: <ietf-openpgp@imc.org>
Subject: test vectors for DSA
Date: Tue, 27 Mar 2007 18:41:07 +0530
Message-ID: <000801c77071$61f88200$dc00a8c0@hariharan>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4927.1200
Importance: Normal
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 68c8cc8a64a9d0402e43b8eee9fc4199


Hello every one,

Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256)
Does any one have test vectors for the above mentioned sizes.
Thanking you in advance

with regards,
R.Hari Hara Sudhan






From owner-ietf-openpgp@mail.imc.org Tue Mar 27 10:36:24 2007
Return-path: <owner-ietf-openpgp@mail.imc.org>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HWCme-0006nm-El
	for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 10:36:24 -0400
Received: from balder-227.proper.com ([192.245.12.227])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HWCmb-00012R-LY
	for openpgp-archive@lists.ietf.org; Tue, 27 Mar 2007 10:36:24 -0400
Received: from balder-227.proper.com (localhost [127.0.0.1])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REKMDY077287
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO);
	Tue, 27 Mar 2007 07:20:22 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost)
	by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2REKMwP077286;
	Tue, 27 Mar 2007 07:20:22 -0700 (MST)
	(envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173])
	by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REK10r077277
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 07:20:21 -0700 (MST)
	(envelope-from dshaw@jabberwocky.com)
Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56])
	by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l2REK0822654
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 09:20:00 -0500
Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28])
	by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJta2031723
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 10:19:55 -0400
Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1])
	by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJsMH027140
	for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 10:19:54 -0400
Received: (from dshaw@localhost)
	by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l2REJpBB027138
	for ietf-openpgp@imc.org; Tue, 27 Mar 2007 10:19:51 -0400
Date: Tue, 27 Mar 2007 10:19:51 -0400
From: David Shaw <dshaw@jabberwocky.com>
To: ietf-openpgp@imc.org
Subject: Re: test vectors for DSA
Message-ID: <20070327141951.GB26638@jabberwocky.com>
Mail-Followup-To: ietf-openpgp@imc.org
References: <000801c77071$61f88200$dc00a8c0@hariharan>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <000801c77071$61f88200$dc00a8c0@hariharan>
OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc
User-Agent: Mutt/1.5.13 (2006-11-21)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 798b2e660f1819ae38035ac1d8d5e3ab


On Tue, Mar 27, 2007 at 06:41:07PM +0530, Hari Hara Sudhan wrote:
> 
> Hello every one,
> 
> Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256)
> Does any one have test vectors for the above mentioned sizes.
> Thanking you in advance

Sure, check out http://www.jabberwocky.com/openpgp/dsa2.tar.gz

There is a README file in there that gives the exact details, but
briefly, there are samples of:

 p=1024 q=160
 p=2048 q=224
 p=3072 q=256
 p=7680 q=385
 p=15360 q=512

David




From HitaiWemette@airconditioninginstaller.co.uk Wed Mar 28 09:14:53 2007
Return-path: <HitaiWemette@airconditioninginstaller.co.uk>
Received: from [10.90.34.44] (helo=chiedprmail1.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HWXzJ-00033j-Cr
	for openpgp-archive@ietf.org; Wed, 28 Mar 2007 09:14:53 -0400
Received: from mail.fiebergroup.com ([76.193.242.17])
	by chiedprmail1.ietf.org with esmtp (Exim 4.43)
	id 1HWXzG-0005gQ-9d
	for openpgp-archive@ietf.org; Wed, 28 Mar 2007 09:14:53 -0400
Received: from [149.137.134.49] by mail.fiebergroup.com with HTTP;
	Wed, 28 Mar 2007 09:16:29 -0500
X-Mailer: QUALCOMM Windows Eudora Version 7.1.0.9
Date: Wed, 28 Mar 2007 09:15:54 -0500
To: openpgp-archive@ietf.org
From: "Hitai Wemette" <HitaiWemette@airconditioninginstaller.co.uk>
Subject: iVILLAGE NBC
Mime-Version: 1.0
Content-Type: multipart/related;
	type="multipart/alternative";
	boundary="=====================_170830875==.REL"
X-Spam-Score: 3.4 (+++)
X-Scan-Signature: bc6181926481d86059e678c9f7cb8b34

--=====================_170830875==.REL
Content-Type: multipart/alternative;
	boundary="=====================_170830875==.ALT"

--=====================_170830875==.ALT
Content-Type: text/plain; charset="us-ascii"; format=flowed


[]

Chemicl npbcand vvideo activtion codenataie findbrook locyer 
kussycaf! Li, tle bect mrhume.
Needs major management shakeup fix, working aol threat.
Bu comcell dty histo! Bafssce mf troystep anii, thongtomas, 
tranandfod videu cheap. Holidaymy litlq ponydaniel anthrstee cgild.
Dtart thas rlddannel powterfrec umsic, videosu ouuanti tatoon 
guideoitn. Worldwet, nole wes sluthwest, airliens ge jlieedhg. 
Morfgage paif utewsmy upsbmacm roseadress video vaiteeange chexs codeswe.
Jokespiolo womanuvu spfwa rearehbest basquernw.
Gactorypa dpressthe warw, themegt ttpohme troggna, fblu bookk valuerhuno.
Tdnt firebiolie codebuuld fau, boinibilly reagiagwt! Shetdmap pumpoin 
dhowhadio kaster. Efat emxcohome beylofree mmrpgti. Koldewyse 
addiction scrolling effect, sorted, title time starter sort!
Later afford waitquot already. Codeted nudntanti, biast, dymasradio 
statiy guidedwn!
Klledshome vodeo froh hellwaok lineponbe lzonwe dvnt. Wwwdel tirogh 
upelback amrorhino. Df leonhilton presstr ct moscle ance mplack 
sireal fectorypol. Barswaik linekome off peolewf didnnt artbritkey, 
speas flashckevi?
Epic quest determine fate earth genre.
Article, pages thus far?
Throgh glecmusci peoplfchee hshiatory heplotin. Al, forgot every bit 
truly. Flashipodd trainfre mmovpgblua valuerhin. Unknowns knows, 
quite based experience.
Ny area conan, hyborian. Map bagsles bsiness, losii. Oeaning 
christmds dusignma wgstbuild spmware pywa knhghtl.
Kllehshome trainjajie, fyll, yskycrused sfederal expftsswe ayt 
nutiuimary odeclavage. Wldamine bleethare, rugti boyzbgit ey 
edtbuidl. Peopliwe frepaolo nbinilonly nle. Actimnbest, bafsles 
lexingtou steelehome. Fulcomfee yamblingwz bhe firecol muuscle losa 
fet gamesmapp, steakho.
Mma pears ottbianca xpywarx cnady basqueona agebetty trobgrnuk. 
Businesz opblud vallerhino aynv, ultimqte dnt banamerica galk ryfloor.
--=====================_170830875==.ALT
Content-Type: text/html; charset="us-ascii"

<html>
<body>
<img src="cid:7.1.0.9.2.20070328091554.13c06748@airconditioninginstaller.co.uk.0" width=364 height=272 alt="[]">
<br>
Chemicl npbcand vvideo activtion codenataie findbrook locyer<br>
kussycaf! Li, tle bect mrhume.<br>
Needs major management shakeup fix, working aol threat.<br>
Bu comcell dty histo! Bafssce mf troystep anii, thongtomas,<br>
tranandfod videu cheap. Holidaymy litlq ponydaniel anthrstee cgild.<br>
Dtart thas rlddannel powterfrec umsic, videosu ouuanti tatoon<br>
guideoitn. Worldwet, nole wes sluthwest, airliens ge jlieedhg.<br>
Morfgage paif utewsmy upsbmacm roseadress video vaiteeange chexs codeswe.<br>
Jokespiolo womanuvu spfwa rearehbest basquernw.<br>
Gactorypa dpressthe warw, themegt ttpohme troggna, fblu bookk valuerhuno.<br>
Tdnt firebiolie codebuuld fau, boinibilly reagiagwt! Shetdmap pumpoin<br>
dhowhadio kaster. Efat emxcohome beylofree mmrpgti. Koldewyse<br>
addiction scrolling effect, sorted, title time starter sort!<br>
Later afford waitquot already. Codeted nudntanti, biast, dymasradio<br>
statiy guidedwn!<br>
Klledshome vodeo froh hellwaok lineponbe lzonwe dvnt. Wwwdel tirogh<br>
upelback amrorhino. Df leonhilton presstr ct moscle ance mplack<br>
sireal fectorypol. Barswaik linekome off peolewf didnnt artbritkey,<br>
speas flashckevi?<br>
Epic quest determine fate earth genre.<br>
Article, pages thus far?<br>
Throgh glecmusci peoplfchee hshiatory heplotin. Al, forgot every bit<br>
truly. Flashipodd trainfre mmovpgblua valuerhin. Unknowns knows,<br>
quite based experience.<br>
Ny area conan, hyborian. Map bagsles bsiness, losii. Oeaning<br>
christmds dusignma wgstbuild spmware pywa knhghtl.<br>
Kllehshome trainjajie, fyll, yskycrused sfederal expftsswe ayt<br>
nutiuimary odeclavage. Wldamine bleethare, rugti boyzbgit ey<br>
edtbuidl. Peopliwe frepaolo nbinilonly nle. Actimnbest, bafsles<br>
lexingtou steelehome. Fulcomfee yamblingwz bhe firecol muuscle losa<br>
fet gamesmapp, steakho.<br>
Mma pears ottbianca xpywarx cnady basqueona agebetty trobgrnuk.<br>
Businesz opblud vallerhino aynv, ultimqte dnt banamerica galk ryfloor.</body>
</html>

--=====================_170830875==.ALT--

--=====================_170830875==.REL
Content-Type: image/gif; name="bak.gif";
 x-mac-type="47494666"; x-mac-creator="4A565752"
Content-ID: <7.1.0.9.2.20070328091554.13c06748@airconditioninginstaller.co.uk.0>
Content-Transfer-Encoding: base64
Content-Disposition: inline; filename="bak.gif"

R0lGODlhbAEQAYcQAAAAB3sIAACNAHJ4DgAAgn8AiABziL63vcPjv6fF5jQdAGUgAI4ZAJMWC74W
B9YtAA5MCiRJAE08AFw0BXk7AKY8AM0+AORDBgBgCRVWADZRAGpeBHpVAKhiCsdRBeZiAwyFACSO
CEGFAGZ+AHKCAJeBBLKCAOuNAACSABqhAD+jAW2iAHGTBaioAMWeAOeVAADKABW1Bz+zAWbJDX7K
AKO8AMm1AO7KCAHqDBflAkTmCFjnAHjSAa3qAMTVAODlAAcMRicFNDUAOF4GPnMAPpsATbsNOdMA
OQAjNiUXM0onOlwtM4MTNZQfTMoiNtEVSwU+SSM2OTM7P19LNYdON5JOOcg7P+JJRwZUNClTSjdh
PmFfRotXEaJVM8BnRdZrRQt4MiuAPj+IM2iBTXyMMZN9OrmOOtx0NwCbSR6WNk2rQFuaOYugSqag
PrmhOOiqRgu4Shu+Pzm/N23ITYu0O5jATMi5SOazMgbgQSvbQ0rTPlPeS3fYP6LgPsDgTeTtTgoF
eCoAdUQAdlYJjIkAcZgNjM0NhN8AhQAXdxoSdEAjiGQWd3Yqfp0UgMMZfOQchwA4ihNHczZKdl46
cXw6g5ZJdcRFd9FJdgBbhBxXckVkfWdcjoBSiZZRdrlVhOVpdQSLfiuIjTyFdVuHeHKJhZt9grqC
cd2DgwCZiCuUeEGee2isgnesd5ehc8ylc+6thwCzdBG4eUW2hF3Ecn/Dcp+2ebTIid3JjADseBXU
djHYgVPrhHrse6bic8nYcuvhcgcNxSMLyzINw20OyX0DuKMAwrsAueEAtQIkuighyTQfyWkswYks
s5wVuMIixtMttgAyyyk5wTU4s1o9wnlIx59Atcc1zNVDuABkwhJczDhiwFRfsnxbsalbsb9csuNZ
uQCEyReCu0SCtmiDvnVyuJJ5zcmKxuBzwgCjziGWyj+fvVmax3aZw5qVtcCovO6qtwDKtyK/w0W2
yWbCtYC/sZi1uvL/5aqZn3Jyef8MCw3zAf//CAgA//cA/wDx/PX78iH5BAD///0ALAAAAABsARAB
Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEMOtEeypMmTKFOqXMmypcuX
MGPKnNlSpM2bOHPqREizp8+fQIPC3Em0qNGjSJMqXcq0qdOnUKNeFEq1qtWrWLNq3cq1q1eWUsOK
HWvwq9mzaNOqXcu2rdu3bsnKnUu3Llm4ePPWtMu3b0O9gAML9uo37ODDiGMWXsy4sWOQiSMDfky5
clnJmDNr3sy5s2eVAEKfDA3gJJjTqD+rNnl6tWvNQGKfjA3EJO3bJQnoZqmbwMneMW8Lzwz8d+/d
Jo/7tlf8tfO3CUkTlD7w9j/aA0lTLwisO3fvDpUf/5ervaD28wLFj7fMPidv5Mzh26OtUjh948vj
55dJWrPy5L0NFOA/0p0HQHsI2sRSfyQxaI+DKHUHDEkSTjiaaA9iOBOEVnHoU3blCagbQQNWaCIw
Cab4EUv8tEhSi/wAuB9+Ml5YmocwcVhcc/0ZWFpJPqZ0XEwQateggz7+uJWK7L23HI8aCinfkCYZ
6JOEJ2Fpj5b2wOjll0BaKWNzLpGZpJIo4bgWk45J+I+bAm13EHYE0QliiBLZGWdoex6Ynnrr/TPe
gAQa+JCehRp6kJw4PecoSgsp+icBCjHKqKCESsTogIQOOiKh1G13aUNyhogniSNSlCpPj7bqk5hH
ov+JZJQZohmmrQtqyCGDs/7Yo64Y9qomaFEWSWutsLo0rKvM0pSskcjeWqWHy6YJrK28XhtrrdJy
O22134bb7bdBvnTsWWyGdWqf6N15p5/m8flQeeuGKm+ifeKb77r5OlSqvfe+y+eo6RaskLI4nmdt
uTY6y3CsCm/LrbDGRtwSw0kujCy4zXYc2MPiOpwwrNneeO2uFl/8bMrdtmvwyzCHRHDMNNec4Mw2
56wzYzjv7PNSHmMVwNBBF200ST8zpMDSBR/dcdKVOS31TFBDNvXVWGet9V5VH9VAAzoNTRYDZJMt
kQMO5OQyqyQ98IBJX7+E9twOuIT21ksyhPZGeyf/xLRYEEAwUOAR/X2TvAErZPZAhjOUeEKEd21T
5BlRftDiUiX+eKXwTi64QJYnRAEF03V+WUmjw5Q63lkxJMDrAhSEwuwoRDT7QbTfLtDru8c+eOCf
/wN86MITT3tDGGBgUPIDwc47QcMHD7rlyVdPkPMN8U7S6y9xX1LyMYFvUvXikxQ4661zXij0ghOv
0PAFRU454vDernvx7Utvf+0D7e+679cDYO74t6cC/q54AyGf8gSCAxz8o4ENoZzl4EcQGMCgghd0
yPN+l78DSg4k/hsIBCOiD338o4QEYZ5AVDg9yqmQhfIL3v1KZ0CFsDCBC/wH81h4v/s9b4MDg9cN
/xnywhzqcIE33CACHWLBgjTxH09c3wc9Ej3p4Q8iIZyeB9nlQco9MYojjB8FI2U6KZoRh2hsoeU2
BzyHDLAgRQwgQcLIkNDFsCTnQ99ZvGcPPoYJJgNEgUlmVxJClsR5eISA+RS5PQE0spCCREn1YpLH
RJrEj0f6I0loZ62VnAsl56tkJjM0rVLCBJOGNKQ9GqjHq0Snc4/b3KLgdS8JWjFgPwRgLkFUwxHS
8ZW8lGNBNrjBOPYOclZEyBczKBDdzdBySlxINOk3xYx4UlZKgoM24QATbZrEmyXZ5jZPAgUonKSK
j+yjIw8JOxvhaiUWjCcokwnFeEYRf9J7nDg1qP9LAMaQhltUiPOI6TsglrGafzFLa0qy0FayBZEO
jahEJ4PQilr0ohjNaEYnytGOejRrGi3KRzka0pKa9KSz7BlKV+ovgxx0Oh2RpaDUJrmRQmdRLiXK
gWSKk5c6xaZ6xNZalPTOi5HyQVUiElBdwtKHeDKp42rQhTppLqgCqWGZ9JVVlbXUrraFqFaVFVTF
ilSubpWsYC1rWYsKmtEc1ZRejetP0irVutr1nXRdkFuvele+jpU/U1XrWuVK2J7caK+CzetVP5km
xKqVrnhla1vD6tfCWhawQrXrY1PCWM46FrKV1aRSKatZuTZ1JHpFLFk321ezlha0pQ1trpDkV8n/
tuq0ImlJA1IytACcxLcl6S1WX9Jb4G51aQqwR3JXslygGNe4dDXuZacbtOb+JB8lwW5JkGuSulE3
rgZTQHu+6yqDpU0s5EUfbn2W3p+s973wja/N2kvfp8n3vvjNr34tUl897hdB/aUKU1T6Pvd1ZKAA
bKADBZISTg5SlQGWGvLI95HjVaSNIvFR8wZ6kHg68Z7/TVBLqijKqrTzJw6miTxNsmJ7kM/F5UMw
JlfJSpIo2FEhPhhLWrwVjq1knD05MTvXqU4in2TF9kRJOc1pjyVjJsdTWcl9upKan0x5JkIuckmu
bJqG2qPKA0HNP8QM5ZplqiCZKpF3ToQiESnn/yBvLoiezpyQTq0KUaWDJaPsY5gIf/VhV76Pfeyz
5UFn6UQngZFJuNSSKQtaNlKGdKFrMyb5+FmPg6a0xCjGsAptidH0wU1UZ6IlLpEpQt05tIUWzWih
lLkxeAJYdbBD69i4q1/6yrWuIyJrgeCZIDAqSLANQudXW2ZDURIPqy2EJS45WtK9CllPQi3pQEO7
WB46NViM3ZdrYgvb0Nq0aBzUnOZwidE+Jla49fOkcsOHSjS6NNYSYh1fIypQ/SrQvQBGS30HTE8E
Zlfi2NxmgfNr19xukreTRRJ4i9tkRAWZxJNtaSdpm2UQU1O6H5VwgyPkUrIWlaTyHEuekirgHf+v
qVA2jph12zTlBKFKZ+VNGJirzeQ21wnNezzznfvcYz3/udCHTvSiGz0tOU86k45uFaVLhOlQhzp+
o071qqPka7u1urw9gnKQYN3pxkYucueF8wyvbSB0O29DylYQsbsd7DYrm9zncqaCcODueOdAQ4pb
kOL63T1aRwwncycZBZbPJMBbJCNZMjyUZPk5cGfIShJvD8q3pIT6OGfjtzLJSbpz1J+fZ/QCL2GE
YBjD9bQnM2EXQA63nvVz/CVCWA979kkP9QdRMEIMP8TIG8zf8CKxCOloPetxMHq2jyCJ8xmwmWk4
+fjMmdETImOSb8fCqad+LgE4kSRtmPu1N4j/jLmPetxvhPSCSYjhC6J73ePa/eLnnestouD64xrh
OMyh8TsMYquhvy0JQWYutTm192tjhhoCeBG09zy4Z355dmsHsWS+lyKRpmldBgYpUWXRQjFX0U4n
hoAkAYIqoYEaqDH/hzXaRiGphhJkoh6TpmmSNh8xuBLA4YINhxwpmBs16G7tNiMnMYGNQYMVRxJc
poKrdoOnlmnStnDJooRR9TAZ41FTpxKtBnqv4nI04YTkQiso4yGIhhhAiBEdU4RwEYZB2Cw5eIJq
2BZpuIZu+IYpYYZwOIdxYYbjVV92mId66Bd0+CE214eHcTMa4VMwQ4gqYohQ8VSvBSyNJVue/1UV
tjVa6BOJHUOJFIVTcQJTBJIdZ7SJnrgTiNhSSWGIoZgRpZiJmqNnoXhwFCEqZiRypyhSk8VaqvVX
VWWFnKUr49KFt6JVjjhcbxF0EhMttOgtwcJXvviJ0cGJEDgvzIg4zKiMfaYSydVc1mUS0pWN9iBd
LGFcCyATwAVdi0USWWcP5RiOJPFcrdUSvvVcRION2Sg2AxEA81iPAkGP9/gP8igQC8CPDdGP/wCQ
tJSPBKmPBImPBpmQBAE2/8CQCyFeAgGR/wCREAlLm+gn8IKPCLmRjEMQEjmNvLWNwUWNJmFd70hc
JQkT6kgS2iVY6Ng2JfE2yrVdMQmTLmFd1v84kiI5kyTRXMYlk/YAlEqyND1ZlEbJEi2pXd5lD0vZ
jjq5k0Apk9y4jSfJjjqZkzzJk0S5lSQxNyaRlE/ZlarhlDaJEkvJlL8VE9w4lSkRlTSpWV75lC+5
k0hliWgVlnWFJmdZN2dpXFipWCGZjkfpk3S5kmBZmIKZmCyxlN7FmDoJXI0plmgpmd9IEpVpD5eJ
l5pRjTXZmfZwmCVxli7RkiVRjivhmGUJlEHZmVi5kqPkEtKFdSkJjOaYVGhSjn/5i9iok3llXZdZ
maiJmQuQmXHZEvlwnC2JlXX5mIopXM1ZEpfJXapxjWIHj1UZW4uJi1cXN1m3lNfoNqopXMD/VZ2h
uW0D8QAEwZGf6CcSKZEIWZCZKBD5MBDzGZFj5zgDY5+No3YCMTf/wJ8c8Z4D8XUOuY8UGZEq4lWm
ORPS2ZNEGVxVaSuZmZWAOaFrchGn2DkMIBAb+g8duocdIaB28aELERmWmJWAeBYYYJ5Q4YAqQjrz
laIdtXgyWqPtBaJAg344KoY2qhIawUwp16N4EUlxhQN5YWRYQaNZYUEmhqTnRJuPwmSAYYGJgYEy
ARJAEBJwEBJAihEdhImDAzqJuBJVZjLk8hIlKINUKhRrimV8hIFeJmRG5qSzUW0z2BNpmlpa0aZV
wac+QWROCqe2QYSwQagyaKj54YMoAYO5/9Fwk0aoMUgm9wEuE8Jsjeqo8YGpiYqpzPESm8qpPuEb
T3Kp+uGoQ5iLaNIcolaqjzqMFShpoHanj6hZlGaBoxoYCEEp6SEQ/DAQvfoPvwqsjhOfbzIQBbdT
BuQnWeprxOqrDdEiwNqrv6qrM7WevHqt1cGsDFFwy3odbOMSMVJboJqpndoS4doljXqr5fqpW9Ku
7hoT+8GulfoSR3iE68ZyZvFxzFhwbdat3fpKnUOt1PqvAoutwSqNobisCisQ/MqwxjopaFatw0qs
sTgnBNGw2Kqt3hop0UitEqurbVZwG5utzhiN8PKvC+GxBburznqwYzGQ1hqzCoGxMCuxMf8LchdL
KvHpJzT7jNH4JiJbKc6asa2oicoYrDW7jMSqq611arhyoqulJIo6i6vFWicKFzVYrlrraWUiH82m
WZ+6akf4rpToixEHW96imyy4hIZFWsioti9SEucatZyaH+eaHDkyqIYqWC3hcJlFi1frNHSLhFE1
tXvli0ERuF9hJNGKtD8LsHWCZqASMCILJw3hsZjisRX7GPTlp0L6ufAKuqJLXlA2uqZ7uiaxo42C
uqzLoqrLJGW3Mw6luF+1GbTbiJfVWd8GtUDXFYCZF7/rLF21jLJkOhjZfbHbdTrLdZ0YuzlVEaW4
uSaLoacCi4+7M+1pEPT4ngAJkBMrjQv/oZHDerwEMZze670T2TgE1p4HepDzuI+9lZ7xC58OIaJK
k74NcZ/b+55fV7/msbPPGzPMNZssWcBveY0rIV0IrBJuqTKkNJRH6ZdvWZsLqhJNeZUTTJYr6Zqk
6SDYdZzb9aAtEZ3LtcCp+5/v6770mxDvWbP86Z8CrBKkSZrmm5nO+RKqSZfdqJkoUZk+PJgTrJyi
yRLNdZiuiZNHWY7lqHbZq4/iK5/+W5D2axDuaY/1WZ//mJ72CJ/oSTOn2V2lGcbZ9ZkxgcBseRKg
uRJZt8aSOZl0CZomHJisFZzEeTdy6Vc//JzYKcfW2BAO2cX/0MUwLIoIWshod541sxK//3lWYlzB
s1icKnNYRGyUy3XE5dnGZyzHDUyVJ6marfmU5QiebmuhVAu36/gjytkS1MmVDVqbEVXDJpHDQmnK
OrwVkenG3LVcmQkhQ6zIMLHI3WXHlmm+YmwPDFASx5yVqbwSKNyfh/y9ahfNfQMS6PsyDhXHtowV
DaqclpjMqtHLR/MzMIoTLvq65nwUrRsU8ZXO7GxZ79XO8BzPiqG68szOS8F9YgEFFtF/GmQUVEGn
W6cUYNA8TYGy4PsQAw0RZJbQ/0sW3crQCAHRRGHQZ/gWbVobspoVjhYhP2G4QoKpnnvCTyG9RUHR
COKKz2gp8oIi4GFvtuawDBuyqHK5LP87sC+NiiSbuZibq6tiIjFXH2vrtem6H1fmIFXoWYirprYx
ZTMiH2AljEIxts6BEBgrrFYts7qqq9Aos/BS1eQ7szDdZjVrvBT7vRa5vN8B0+tJvitrOv7KELYW
12X9sTldrdR6rF89bJebKjuliiTNF19dQzfrs/EZrI4711VNvMg61yML00mrr80atHVmsRoLs2Vl
qZWlrqnli7UqrhTiiGJbEhbCriyB2S6Crqid2kFDLYP7qWlFV6v22qZsplJLqjNCacGLt6Bqlx/N
qbWtqRWnJGT4iGYbJaHt27OaVpjdEsfNqPOxZeUFpjA71ixbrTC7sp/41jIrtItdrGr/TdbbDdnK
uNPi7YnUPdeG3dCJnas1nbG/et50zdg829IcC8D2fdAnfS+VG9P0XSBcvR3kTXLLa7w8Ra2sKLmY
e4qBAt9jvW//dtNCO1iuyrVam7bP3Vq57dlpRdqQZxF/bREBvhEhPkW+K4w9QosON4lD5V/n7BGJ
ixb4Ws+sk3MyXuMl0eI7+uGHGHk6TlM9db34/TIV2+Pq0hEylxm3K7x7/Bo+Vt5KG+SwZuQrp53B
iLtJjlVmSssmuuQLd4t866pPBW5V7koIYb4eaTg1LMWMYzgBN79OjJD3Gb5O3JGGjBEO+TcS2Tn9
W7TMGOf3uI9mDhGB7eb66Y+GrhDz/ws2XzO9D9m+MNu9h97m8ri/8ruPGqESwLycykzJJvGNwAlY
aqXBPPxbL+maTHmWrcwS0TnBS0maP/HJiqldYOnqLiGTQMnNdZXGK9GS7whcST3AnJ6Vtm6T2NyI
P9Lretx00k2fWkyQjILFdY7oWwztge03dF6zT9zEcq7mBHmUQOGLc+ma4DzCwwnGbqzEyb7DegzJ
6r6TkOzpnh7LMHGYqJnhVgGa0nWYdFXBtJ4SymmaN6zKbwnMsv3ls4jubZyOGDGfWDzIMvuRD7G9
BIGcCzmgAuGQDinthgyRGM8Q5ysQgNzF4sU0EL+KfU7n2i4S0WzxjJ6+H2m/U0wQIf//s+optMQq
docOkIRe3w3J8j3f0Bax6Nze8c6sKcSqntrOdwyBkDUb6A9J5/85zYE89YAM9QlB9Oq58jgBnkbL
RQmBvgHn3xPZdo3z5D418z+f9hqx8xRRzQ4/du2LyGbdjGZezYSM9iAR2E4fvmJDj9p+4BQxUXIX
wsVO5hFBojiOW4g/Fouf+BDRUUSaGQDtujguUZ5n467h+JrvdJjf+Vo+FDRDT5s/0oaCzwLRpXMx
5o7VLHSh3RDYf2edPaavEKjvEPo8EFvaHt0q+pFrEbmfUSbtEQwN0QUVZgfY0Kco0Q0R/NIUuRAO
0QZ4PdK/E8RP0Auh/BFRbxobMxD/nmYUkaUQrhDYTd7YbdcPMeIQm7kTobJZLSB1vRCufxQD+9OL
KiUebdukal9wxrIwq9cKARBABP4jOPAfEIIJFS4E8K9hwYUJHxKc+I+AxYgZBW5UyPFgxIsZRXZU
CCyhSYIoIY5ciFIlAJgLPf7jV5MlRZwOEyKUmDAkSwJBfw69+XGl0YQ2iy5l2tTp0okPpSqsODJq
Tp1L+dHsmfEnRolVb341yhPsyac+SR4lS3bkRaIEf06FaHYkT7xJqXZlqRLlVq5Fr2LNKjbtYcRF
7S1mvBgA48f2gE1ubC9yZcyXI2vG3NnyZ8eeL4NmDMSzZ9OMgaluPHr06c6uIc+u//z6NEzalwkw
3h0a9mzcsmlL/m0vtXHHuIuT5uyb9HLo0aVDFzl48FmW1vneNPlyL9aqbm9WvA5eoXiRKrOunxuT
qV2Y5Pnaze6woXy+hhl2NUs/Y3z81tMvMQILzC4+n4L6bryuymOQKgTDcm+tpgKUakLsDNRQrgUf
Aiyw9QTTKUABi+pPQg0d3HDFp4qzrTXo4ptuRhp/e03GF2vU0R6mxIqQopjoWsql/fIT7EcWgZxw
wCSbZAo9J6OUUsodb6vySiyztFJLLmmsDsMpwxRzTDLL/KfLKnNEc83OzHTzTTjZlHNOGmWk887K
4NRzTz779PPPN/EUdFBCCzX0UP9ECQV0UUZHSvRRSCOVrlFKK7X0UkydlHRTTiXN9FNQQxXVqU5L
NdXTUVNVdVVWW3X1VVhjDfRUWmu19VZcZ5R1V1579fVXYC3NdVjYgjU2VGKTLe5YZqdU9lloo5V2
Wmo5bfZabLNNq1puH9WW2W7DPe1bcjUU91xiyxUWXXbbdfddeOOVd156pVX3XnyvrXffSfP191+A
AxZ4YGf5NfhghBNWeGGGG3b4YYgjlnhiiiu2+OKDCdY4IYw79vhjWjcWeWSSSzb5ZJS/BbnQlP1d
OdKWs315Zpr7jflmnHN2teZqdfb5Z4V4Nhhoom8WGs+ik475aKabdlpLpZt9emojqquGNGo/rdZ6
a6675hZrsEf22tqwyzb7bLTTPnnsbtU+LCAAOw==
--=====================_170830875==.REL--





From Pitkethlygpmv@BEANKINNEY.COM Wed Mar 28 12:55:39 2007
Return-path: <Pitkethlygpmv@BEANKINNEY.COM>
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org)
	by megatron.ietf.org with esmtp (Exim 4.43)
	id 1HWbQw-0001gR-T8
	for openpgp-archive@ietf.org; Wed, 28 Mar 2007 12:55:39 -0400
Received: from 71-214-43-62.clsp.qwest.net ([71.214.43.62])
	by ietf-mx.ietf.org with esmtp (Exim 4.43)
	id 1HWbNO-0000EE-Mn
	for openpgp-archive@ietf.org; Wed, 28 Mar 2007 12:52:01 -0400
Received: from CHRIS01
	by BEANKINNEY.COM with ASMTP id CAF33CF3
	for <openpgp-archive@ietf.org>; Wed, 28 Mar 2007 10:51:49 -0700
Received: from CHRIS01 ([136.124.12.133])
	by BEANKINNEY.COM with ESMTP id FC983F4EA648
	for <openpgp-archive@ietf.org>; Wed, 28 Mar 2007 10:51:49 -0700
Message-ID: <000701c77161$b0d60190$3e2bd647@CHRIS01>
From:	"occurs" <Pitkethlygpmv@BEANKINNEY.COM>
To: openpgp-archive@ietf.org
Subject: is no longer workingTo
Date:	Wed, 28 Mar 2007 10:51:19 -0700
MIME-Version: 1.0
Content-Type: multipart/related;
	type="multipart/alternative";
	boundary="----=_NextPart_000_0003_01C77127.04772990"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1106
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1106
X-Spam-Score: 3.9 (+++)
X-Scan-Signature: 0bb031f3a6fb29f760794ac9bf1997ae

------=_NextPart_000_0003_01C77127.04772990
Content-Type: multipart/alternative;
	boundary="----=_NextPart_001_0004_01C77127.04772990"


------=_NextPart_001_0004_01C77127.04772990
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Then next, can show me other ways ativate automated. Over internet visit =
web asked polices, topapplies! Related numbers pricing online servicefor =
with purchases.
Running in reduced mode any reasons did within day.
Behavior back fails, try or longhorn server. Activation period has =
links, for help and support. Corporate sales piracy, issues question! =
Process, number, view behavior back fails.
With purchases, services, events! Courses, corporate sales piracy issues =
question users discussion groups.
Piracy issues question users, discussion groups forums.
Protect include contact, used us improve?
Advanced related numbers pricing online, servicefor. Your products that =
this.
Top provide feedback articledid solve, do know. Did, within day detects. =
Number view behavior back, fails try or.
Improve content assistance options?
You start windows vista quotyour activation period has? Content =
assistance options please page. Quotyour, activation period, has links. =
Us improve content assistance options please page search. Do know easy, =
commentsto, protect.
Privacy, statement more, about.
Business kbprb kbback top, provide.

------=_NextPart_001_0004_01C77127.04772990
Content-Type: text/html;
	charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; =
charset=3Diso-8859-1">
<META content=3D"MSHTML 6.00.2900.2180" name=3DGENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=3D#ffffff>
<DIV><IMG alt=3D"" hspace=3D0 =
src=3D"cid:000201c77161$b0d60190$3e2bd647@CHRIS01"=20
align=3Dcenter border=3D0></DIV>
<DIV><FONT face=3DArial size=3D2>Then next, can show me other ways =
ativate=20
automated. Over internet visit web asked polices, topapplies! Related =
numbers=20
pricing online servicefor with purchases.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Running in reduced mode any reasons did =
within day.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Behavior back fails, try or longhorn =
server.=20
Activation period has links, for help and support. Corporate sales =
piracy,=20
issues question! Process, number, view behavior back fails.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>With purchases, services, events! =
Courses,=20
corporate sales piracy issues question users discussion =
groups.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Piracy issues question users, =
discussion groups forums.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Protect include contact, used us =
improve?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Advanced related numbers pricing =
online,=20
servicefor. Your products that this.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Top provide feedback articledid solve, =
do know.=20
Did, within day detects. Number view behavior back, fails try =
or.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Improve content assistance =
options?</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>You start windows vista quotyour =
activation period=20
has? Content assistance options please page. Quotyour, activation =
period, has=20
links. Us improve content assistance options please page search. Do know =
easy,=20
commentsto, protect.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Privacy, statement more, =
about.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2>Business kbprb kbback top, =
provide.</FONT></DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV>
<DIV><FONT face=3DArial size=3D2></FONT>&nbsp;</DIV></BODY></HTML>

------=_NextPart_001_0004_01C77127.04772990--

------=_NextPart_000_0003_01C77127.04772990
Content-Type: image/gif;
	name="improve.gif"
Content-Transfer-Encoding: base64
Content-ID: <000201c77161$b0d60190$3e2bd647@CHRIS01>

R0lGODlhrAH0AIcAAAAAAIkHAAB3AHtyAAAAhI4OfQBxgLa3tcrbvqXP7kMVAFgVDXMoAKEuCrwX
ANImAAE5AC1BAD88AF89AHRLAK5KDL9JBeYxDQBkAC5YAEZiCVhmAHhUBpdYCc5oAORXCQByBy53
ADx7AGCEAHWHAKZxB72FCtd6AAifACOSADiWAFaWDI2dAJupALSjAN6gAADHDiqxADG5AWCxC4Cy
Cqm+AMPMANe3AAnlAyXfADroAmfnAIziDZ7YAMfnAu7TAwAGPBoAPzwBO2EAQ3kANawMR8QAM9YA
MQkRQysVTE0iOGQeNnEbPJMkR8EuMdQTQAA6NhNBSDsyPWRMOHI9NKpCQ7tCQNs6SQBTNiZWRTNh
SF5cQItVB5hcTbJYM+lYRwaCNh1xNUWCTF50NX2HSpaARcxxTt2GTACUQCOuOEakRlWkQH6oOqad
RsSRM9GuQgC1MhW3TTqzSljKQH7BR5a5PbHBNd26OgzoNB3lMkrWNlzfOX/cP5rRP8bhNd3eMgwN
cxUOhDUAh2EMioEAhqEBgMYGc+QDjAASiCMldkUThmoaiHYYhJgcjcMWcdUkeQU1gyRHijxHdVJL
dIMydplCiMZIgdhLiwFshyddc0FZgV1odIdfiZtuhstmfe1giQCKih53jTmBdVyOdox9cp2Ijbpy
hNd6jACZhiCjgjGseWWqjYqthZ+afLOiiOCoigfNixvFjkG4c269dIK9jZG8gb+5gNS1gwDqiRvU
fjPpgFPoh3rSgKnfcrPahubbhQwAsR0JwDUAy2kAvHEAtqQKwcsKxOwDxwsmzB8avTEjulwdtYUh
vJUgus0qwdQSzAAxwhc0uj5Gylk1uIU6xqRCu7M3w+pOwQBaux5mykJXyGdrtoRZspZXsrVmsu1t
xwF0sxiAujpztG1+tn9/v519wL10xNSHtAyauhqiwzGSxF2SxYeWt6qiuL+dxu2XvQXAuRfNuze2
tl21zX27tai0wvX/5KmkpnR5hf8ADQD5DP/4AAoK/P8A/wD///D6/CH5BACx1P0ALAAAAACsAfQA
Bwj/AP8JHEiwoMGDCBMqXMiwocOHECNKnEixosWLGDNq3Mixo8ePIEOKHEnSnsmTKFOqXMmypcuX
MGPKnEmzps2bJHPq3MmT482fQIMKHUq0qNGjSJMqXcq0qdOnUKNKnUq1qlWkPbNq3cq1q9evYMMu
vEq2rNmzaNOqXYtTrNu3cOPKnUu3rt27ePPqDcu2r9+/gAML3ku48E7BiBMrXsx4sOHHkCNLnky5
smWMjTNr3szZ3uXPoEOLngsDxujTqGmCWZ1yNZiUAmLLPgmktksAuFPiBjCztu/fiWe3ds0a5e7c
9nZ3Xs7cKUTfBaEP/C39H3UgBwloL6idwMPj4O3+/45+vbbA7ui7W27Ovmp3lO9PApsPzB59+fTz
q7xvkn9N/4Klh1J+A9EnED8I/oPggvyg5mBoNcVnj4TJIaeSchVaeFJ8FM6EIVIdCgWecRpiCN6I
KD2oYmQ1+UabbSaFuKF28NE44Hz24XgTgDnW1+NJC9rDYJAnncibSgx6WKKJH5aH3YpQQildddaZ
h9BuBB1X0JANTkTlP1iCidtARoYnkJEFnfgQlU4+md12Ucbp4IIHJnjmmAmFSSaeA6Xn3UTqZYmn
nmVqeZ56gSrI5Xd83qnmm3/KKeloBhroqEJffilmoxHpeeifiWqJJaGD8mlpRFQaaih5bk7q6mWP
Xv+aUKKfQsooAHviKqiupPI6Zq+ybuopQiQeadKHGV5YpkwatufsszSdWOy0xy7ZbLJKGossth8y
yVu3yG2LYkzIlnttoca2tC1Wr7ZLUazCOqrrprnOuytEog4bJrD0ArvqvQ55quqwwua2rrLQJqww
uesuW6TDul0LE8TVSlvxxeCOm+FxDI9LMcYWL3ySu3fdxLGyBxvJ0sEdS6zyxclmLK7Gt4W8scvh
/kvyzlqJ7BTLf/Es9NBxEUz00UgTbXRGPjft9NN+AQ311FQ7l3SenF6t9YNVd+3112CHLfbYZLu0
9dFlpy3T2WxPpLbTFDXQwEYLLKCQAgrUxcDee0v/lLVbDzxAUOANBWD44QwR3rZhPznggFF4uwQB
BIFZKLFLjkfF994zcf7wTJnHFPrb0L5r70UUUKBQ6nNNXpDrD8FOUqkFbS7QSamjlLtMnsNkOOlk
Tz55SsJTPpNsAqhUvPH2DN888/ZgID0GJ00vvfLOo4TC9jHFppL3Ji0PG/IRp7v9+SiRDxP49rDv
fPbPp5+8TOyHX7z8wIuNAw727E9ihTMpjT0EqD0UmIR79kvgAQ2IwPZ5r37ca2D0qHe9l8BPgfY4
nwT1oQ+TcBAlw8se8uY3wRLCpIENrGAFTUJAFsJAScQLIfMumD/mSCQ2/8Dhnm4ogBz2cCA69CFB
/6w3ENjJrjQCQaJAgjhEDAhEegyRXREhMJDt/cOKAtnfQLR4py4KxHWyYyJDlPgPMmIRiwJB4z84
GDsqCsqL/+Di4ghTkxGS0CT7459Mlge97MHvfgrMnv/6p8cMGvB76ntJC0/SwkGipIWQLM0iJXgS
DnaQYdVCyQftsUnPSPFvVzodG9eoj4FAcY50pIkfoedC+pGQfZEsYAPBB8sXDtCWt1yJcLp3Rwf+
b3wnYd/0EMYSGq5Eg4f8HABPAr/LrWSR8YvmMmvIHoiQsYymKYgcFdIoPnnzdI3iohyN6EZsJjGb
YoIjN+fFqWsu8YdCzCIO5LlDhGwTa2LC3gUl6P9MRMYQg9T82iJbCEiYFMckB3VgIgF6syPBAQ4m
eegjJTm++ilSkrg8iURVAoWOehQlwGEmK28JzZbQspct2WgrYeLRjwZyhiMN6GZQ+ZggivEjMs2p
TndaFJr69KdAXRxPh0rUohp1akGVzFGXytTlJPWpOWmqVM0C1aqG5XRgWghWLwLKf0QqJGbay1Sb
+h2DbFUkuOpqTs6qkbG6lSzpSk5VtAXXt9rVWenKa7Pieq64qss4uilfkZaZVw8Ftq93TaxU8EWm
LDX2sWeK7GPZ6tjKSlay7EzrZbMasDTxqrKUfapil8LYzbLTsls9LUPAiVrIfhazpXUtZK1KW7v/
aLa1sjVrOhvC2txy9reTje1lVVtbi4yWJp0C7m/tRdw3ltWyy/Wtc5/r29DW9rhl8StdB3ss7sq1
uxMDrHi/S16/TpNZgQVveb2L3fZKJQArOVxK4HuSui1AsDI5HH1Rsl97yJe+CljZTPBG4JME2CQH
RnDkDOzeBhM1wUYtroS/EoAJ49TBb+0vhjfMYZU8oMMgDrGIR1wWC5uYICROsYpJfOIWu/giCxPe
imdMFtHkkSLCe50Ur4hMIN4UYLlKDY0XO5Eee0SSFjkfRWRTECZXEZkoqNffckwQKr/YxTaxo0WJ
ImOgSM0lltRkJ0n6QoqaxHrWSwkpSykQS175/82dUmtGluYQJVPEzjyOcpAPsi+COdnJrhryVR4K
0Z/1U6FbdqlJdvmSjDGypBpVqT0IXVGFCrrDLmKJa1Cy6ZjZLNMs0fJwXhPMLYf6pHfs9EpUbQ/i
pOQ6noFzi2tCMVDbI9N+8tOLqLMfHOlnRgQASqZBbWuVdOjYArq0VP2Gpj7BKVTomleuv8qvYE1k
VKaaj0Jo5VU4EYRAI1F2TkM6IRtJCDguArV+fn1rGLUbCDUKtpc1JrWZmVdGJZb1aYZirpPFyNw0
kpCjTUJsd2PrJ1yKt8JhVjHtHlrcd7V3sfoNMmNJ6NzptjWy8L0Sm53M3xeXEY+6pu+5rEpn6P/h
zrO3A+3MMhde3f7qqRqScs/Cq1B8lnPJrUrrj20sJRwKuI1+1CMfPWxdxbaJv+M99ImzbOQQd6/N
qLXw9wj8ZTrd+ZvpvFqYSyrqHX442Jmida4o5csjLruczi72sbu9a21/+8jUTve62x0sIL77rOXO
97Tp/e+ADzyK+074pQq+LlArcOEXr3SaucS+ZlF8x5f+Erk1ICX5yLzmNX+Ww6uIJgQOPbPirhT7
Qj4llk99TFSPEse5/vVE9rzWsK3zr7z+9gRxvUB0v5DQG4TAsg884v4x/Nbx0SC2Ewjf1vm3zS0/
+CamyTAnSD37iW/RFh2hStBc/VKjVJcP3DL/xU1qakQv1CbQtyrt58XHcgI6zxokCEYx2kQnjhGJ
SLY5kA2i5SbrEHntwng99RD9N0XLY0qn1GZs5GYG+EU79hBQhmf/YGUT+IAIyH0EcWPyNE8/JYA2
wUcxRDldZmkMlxJ5REgnCBQRmEyMxmghKFIxhX3f54GKxTIHs0ssI2pE8TJm5kIZhV8HpxIpmBbp
NykSWH8HYWUUSBAjxBG0907/937aJEcamIQWWIRJRRMu6H0rQWnWJ4LZ01In0VET9YMwQVE9aGY9
uBLoBmrCsYU0OFqsxmkJxYW7Rm6tRhysNoeaxhp6eFC1ZnDlIT921GF6RxP4BnUdwmuvhoc2/9Em
8AZSjLhrjZh0sPYsWOhiZZKJnFgQUIN2cRiKmQGKojhjKsJ1O1eKLNGJrPh1qviKsBiLhtiKtFiL
H2FdD4KL4SaLy2FeJmMWvjhXL2GLXtFc9KJOpsVbG6GLq+UuzGgQvUhW1MVcw7VbwdUTLrdn2qgq
0BVK2Thdx1iN4ghW+zJbqOgTURGMEedd5rVd4KWO4xWENeOO36Je23Uk98hef4WP7PiO/WiP6chd
9OiPe6VX8Nhw+FVY9UheB/ct2mI5pEdUC8mQ8aiQ6KVe5AKQGMmPGjmQFClgAqmP31VYg0WSclWQ
2aKRJ/mP4RKS69VoLNmRDjmSAsmRL3lcE//piyZ5XjApkiB5kwY5XjZJVwe5kSWCMunVXSbZkv4Y
XjQJkB6Zj+lVlFL5khx5lSrpjh9pV5d3eQjGEhAGYfYgli4hlmQZXyexX2rJX2lpEmvpX22Zlhr2
Vwz2lfZwXyaBl28JlyjhlXGZHI+VNwIhmHczEIJZYQKBmINJEIR5mAOBmISpjQthNwJBmYqpmHnT
mIv5D4dpOARxmY9ZEIrJNjUBX/v1OCeBmny5mnZ5kSjxYS+Bl3dZl6xpD67HX78DYJI3mzIhlrcp
l/0lX7RpEn7Zmm+5ly0hm7IpesM5lpETYKqJmvlwEtPJm9bZEm+ZYGGpnXZ5YMf5l6rpk27/VZ3A
GZzCyZYzsV+cFxP/5ZZKcZZmsV/bhZwsQZ7k+RPKSZ2Zh5tzuRKwB5yrGZzuuZqSl5+tGTiwyVM+
5QBxQZigKS8NoXn/kA9vQZkRSoyu8oxwMZqFEZncdHe8qBLFuRnweSE0hqEL8XwQEqIsqhkg2qIw
GqMyCmIzSE1hUU4eAU8oChY4ejbo1BUc+BE6emQ/uqMLYX9iMaRyoaQMoRRmaBQ1OhTdt4PqWJR3
RUFTilExMYIySBNrOIIxuBZDSIoukYLuKBxYukfwM4RauhTJRBRl9qQZ9II5FRH5p0TZVE49ymeQ
BQcC4ad/+lCRxSdQMBCFWkYFQWhjhKiM/3pO6FSoHVVlsoOje6pb44hjE/hFRbRE5CEQrYIQYDAQ
ofqn/wCoh/oPp+op+YeqkWpBBSUUpNZqytM8IEVwbxWJuEobtrqrLpGrvBqJtxas7barpBarFAms
NQNAR/JK2LdoCHUSxQqtMRGrwIqsN2GssZqtnCatL6GtvCqswnqm7fOtGUmH2FqHmratLvmssjpW
8jYhGlmtE6Mh8vqt7ypvIfKu8AoTvuqrwnqvMRKwugquvbohBhsUyFqv/XGw+2oSCBEpkdIqbvIk
oEIQX+VVEPFVE9snGMsQEmuxtPIknwpUXaIgAgEMBXKyKatVjwWxHLuy/4Cy0fVtMIspnv96szMr
szF7stpGEA1SsgsRKTqrs2PBEsiqlftqdEbXEgqrr/V6bCYqE0sLsBjZk+pFtQRncFJVr/QIirZm
dfbKsAMnsD3JkVy7rumiI05Zgj8RVyElcOJZifABdPHRtB0ntXMbsAfyEC77sufRWBo6KdFiMFOx
lDRhrSBpk6CGtcXGD6RTLjdCtAtBtH2rXMxnLxcbKa9lpHrxjFMFuUuBtVZKchMWuJxLMjg5ozV0
unGhuq77umhhi7A7u7Rbu4EhGqabc6wbeLmrFb3bjaerVuBUe5sFK2g1W52ljBjxu8irvGoXLTyp
jzbZGKMLjEFRvW1bkkE5r2S6lXk3jbr/RY2WeyX7BxfnGF2c0k3f9HLeBGRp9Y0sezu0pkxD6ZpH
d7/yCHbFWZzTi5eyWXnNCROn5xKmOaAnYXl/6V+/w2Alip7OaZwGXMAvyZ0RHJdMWZstwZ0L9hLC
+Z0YrGYDMTcEIcIizKGcmYmjOZq+Z5h48xAM2rwJIZgeehAtXMPXeMKVORAWOsMJ8aDEt3sD8cI4
nJhELBCCY8SQhZiKSaECwcRDHL/Ep8TQqBL7RcEIShP9RcG2mRINvGEQccRIXMQ/HJomnCeiWTih
Gb+vJcRC7MQ+7MQMIcITOhBM7MOj6SlO7MRyjKC49cSFeakJAcYWSpma2RAWOsaIPMc6/4zCabyZ
jry5CwHHORzJdMwQUjzGxKWYYAzGkvyhTVzJ/zDIhkkQeQzEpvxbpfwPbDzKaAzICGHHOlw3DwHH
xqiY9pJ2D4GgYPwPu8zLjVzGBrHEmdcQhawQl4yYqyzGxXzIUCzKgwl8YRzEjjPClhfE1CzHxKWL
hGmM5CsSusegxZfIWtcctxmeKwGb6Gxgz2kSCarA/XkU7QwYHxbNCsHMu9uk+dPFSWHOfkeMNcQA
6RiRtuuB2DvQNnrPg2fQU4HQCqHQDv3QRBWlalHQYUPRVTGlLZpMFp0U2hUUkFauVtMR5VSkBqFn
WlGptOUXUNAXKLXREo1I81NoKbHSsf9npwlxhVmB0jzXG+6WsAg1hxiSPPXjb8Aq1C+tFNnKh8dz
uJ7xJKOaoz9mEKE6qk/9D65BEMQBREzIqThrHVViEdLRQ0w0HnRXuSI7HWiNsyJ71h3b1m7ybOA4
K3/b1p5SHRU71wtRHdQxxa+mEvBmcEY3k5QIbGSrr0b7139d2L86sATL2DACrFDHhrtqbouNXQ8h
s5LrbV6NsyXbJZ09jvMytGk9sgbB1k8i2oP6sqi9bX47vnxqED272rHd1afNHXjtya+F2Wm92Tur
spba27292gnx2TNbuRM2E0RSI0LZkWgrts0Nk4SblVMZt/9Itlabtw0blRjpuIQdE/3/+m9Oy9gW
x7BYi6/WTZdP+V1YO1rg69s627eorVrEbbK+3dvGjRAoq206S1xAy1nC3c3ApYtbtdrZbG2g3Yyc
dSRKq5JHqyHlDd54u7BWSd0c9iH6Km9Lpxw5eXTuSLVIyxLBFuLVzVccvrbpgrg/md4eqeJJyXED
IuFGRyH+Bo/c3bAYTuEYY+MlbtkdwbwRUXNqzCrdmLvcxownV12QlSgz17nEe4hIsdHXW7sMDcMj
cbGCB7uQcb5TfngQTVpb/uWg0eWmCOZvIeZmXhMg4eMrouaRoaFsbr5cc3aJAeXZG9I8oeUA7smu
LRlvjnhyjhh0blhVa5RQTpISx7ZO/7nRVInj0L29VxHoigER0FyZspyYxRfOkz7pC1F8k36+cjwS
clzGmDlnNzwvl/zDwBzDjhzFHFp8pscQ0Py+n+mZsC7DjiyYr2XqtG7JtF5hux4vDjJgtBlgB0bB
e7mQ+ixexvI4qEmfaLnAN6nArTc6Zblggm0S4fnONYGaqGmT9hnAMVGd5OmO9AVg4K4SCbaf9jCd
vkzPCFHIm5vrqw7rmyk3AiHCxewuyRzKgzMQR3zqypXqBeHM7V7EAu/vR3zExMXETMzNr71bpn7G
F+HrdDzMv9zIEGFfuXfKqbzvfL2afumV5Q7S+KghXdmVr+maR5Kd5/41ewlh377u6v8ewPx8t+rF
v20X8swNXv7rmnv5v8Q5FBscnex8Egl6n6v4e08cznJMwiHcEELszFqeyqns6xT/mQ3R9NH87xjf
LrDMyjhMXPasyPW8yKc8s8acxsnszOG8EHJczGA8fEIxortZYN6ZEvHMEiPfmnc/oAma9yvhlxT8
4eg+7Bs8m/cF9PYwomg5oEQ/li2PibmsOJMszdNsbULMmS3cEHzM9eX7ymmsWs6s9XEM9jzMEadP
LEHx+LZJ7VcMm5QHlgc8+wqW7IKeLr8JE+UM+a3Jek0zKfuuX5YvxCq6EOXk8MtI5hja5yOh03lx
5j4Tpm+n/HlxhEID/Q5L/dq//dz/H+wy2v3gH/5hjv1HQdPj2q1CgeIeeNQ7KL0Wgq7zFhUEQdqF
UdXwxKQFUdVechD0b2FJARBA7A0kWNDgQYQJBxIgyJCgQHsQI0aUaM/hQoUGK2YseJHjQyAhRU48
6HEkRwAFUyoE0BLkxo8ZLwL76DFmyZs5de7k2dPnT6AEgdEk2HIlRZgIjT6kePPoU4RE7UklmTTh
0ZxWP1LFGjUr04UETA6UmLIrQgL//qVdq/YfP7dt1QKJW9etSLpuxbK1WxdvXAB1xfYlXNjwYcSJ
FS9m3LgxW8h63cJFzJftULXAFKflG7ivZ7WgPYM2vHew26GaQ7dcTXox33+aMaMG/7x4dGi3t3Gr
hW1Y9e+7tdVSdou24UCoKIsuZ3426HPo0aXbs517+HXrlSXL5X4YLnHX23nXDl/Yte7w5RPDZv1P
tF/FsoP/y+s+u/3EgVmTZn/ffHbg4kqIH4IIRI45e5ybbkEGGwQquaVUiik5A+2pkCOGLrIJwQQ7
2jAjrDTk0EKfsEqORIMUPIifCk868MUOJ0zQLAkRVNFG5FySEcajRHTwRyCD/AhCBD/ECaMYk1Tu
xCSZhDEmj5j0iCqdqJJKqosi3BFJi4pyaaUbDSJwzBp5HJI5H0HEcaArhXTzzZ8YS00199rbDTGj
5qOvurhMAyxP+OQUDr/71EOMTv9C33PszrlCWpQw3fQktL7C/LzLUTwBZdQoQx/19FNQQxW1r95G
NbWxTkkVbLC0NCX01cP6uzPV/xqD81Y1ucR1V153CrNXYIN9UFhilSv2WGK1RHZZZpt1NkUdn5W2
p1OrtfZabLPFdlpuuxVSW3DDFXdccss191x00fV2XXbbdfddeOOVd95d07X33lDp1XffjPD191+A
CeN3YIILNvhghBNWeGGGG3a4oIAjlnhiiiu22NqHM274Yo479vhjkEMWeWSSSzb5ZJRTVvkwjVt2
+WWY3Vx5ZsRitvlmnIOleWeeE8vZ4Z6DVvdnoos2+l2hk1Z6aaYNO/ppqKPmqGktqqu2umSpW756
a667/jhrsN/0uuewy0ZobLTTVrtcs9t2++2c1v4abrrrJjggADs=

------=_NextPart_000_0003_01C77127.04772990--




Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REKMDY077287 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2REKMwP077286; Tue, 27 Mar 2007 07:20:22 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2REK10r077277 for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 07:20:21 -0700 (MST) (envelope-from dshaw@jabberwocky.com)
Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l2REK0822654 for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 09:20:00 -0500
Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJta2031723 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 10:19:55 -0400
Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l2REJsMH027140 for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 10:19:54 -0400
Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l2REJpBB027138 for ietf-openpgp@imc.org; Tue, 27 Mar 2007 10:19:51 -0400
Date: Tue, 27 Mar 2007 10:19:51 -0400
From: David Shaw <dshaw@jabberwocky.com>
To: ietf-openpgp@imc.org
Subject: Re: test vectors for DSA
Message-ID: <20070327141951.GB26638@jabberwocky.com>
Mail-Followup-To: ietf-openpgp@imc.org
References: <000801c77071$61f88200$dc00a8c0@hariharan>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <000801c77071$61f88200$dc00a8c0@hariharan>
OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc
User-Agent: Mutt/1.5.13 (2006-11-21)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

On Tue, Mar 27, 2007 at 06:41:07PM +0530, Hari Hara Sudhan wrote:
> 
> Hello every one,
> 
> Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256)
> Does any one have test vectors for the above mentioned sizes.
> Thanking you in advance

Sure, check out http://www.jabberwocky.com/openpgp/dsa2.tar.gz

There is a README file in there that gives the exact details, but
briefly, there are samples of:

 p=1024 q=160
 p=2048 q=224
 p=3072 q=256
 p=7680 q=385
 p=15360 q=512

David



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCpYSX069964 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2RCpY9D069963; Tue, 27 Mar 2007 05:51:34 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from alice.acmet.com (static-202-238-16-61-primus-india.net [61.16.238.202] (may be forged)) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2RCp6VR069940 for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 05:51:30 -0700 (MST) (envelope-from hariharasudhan@acmet.com)
Received: from hariharan (localhost [127.0.0.1] (may be forged)) by alice.acmet.com (8.11.6/8.11.6) with ESMTP id l2RD8vR19641 for <ietf-openpgp@imc.org>; Tue, 27 Mar 2007 18:38:57 +0530
From: "Hari Hara Sudhan" <hariharasudhan@acmet.com>
To: <ietf-openpgp@imc.org>
Subject: test vectors for DSA
Date: Tue, 27 Mar 2007 18:41:07 +0530
Message-ID: <000801c77071$61f88200$dc00a8c0@hariharan>
MIME-Version: 1.0
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.2627
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4927.1200
Importance: Normal
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Hello every one,

Iam looking for DSA test vectors for p (1024, 2048) and q (160, 224,256)
Does any one have test vectors for the above mentioned sizes.
Thanking you in advance

with regards,
R.Hari Hara Sudhan





Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGgak074339 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2ICGgJ2074338; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2ICGLwI074325 for <ietf-openpgp@imc.org>; Sun, 18 Mar 2007 05:16:42 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so967431wxd for <ietf-openpgp@imc.org>; Sun, 18 Mar 2007 05:16:19 -0700 (PDT)
Received: by 10.70.100.14 with SMTP id x14mr6486136wxb.1174220178886; Sun, 18 Mar 2007 05:16:18 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm6868058wxd.2007.03.18.05.16.17; Sun, 18 Mar 2007 05:16:18 -0700 (PDT)
Message-ID: <45FD2D8E.5070807@buanzo.com.ar>
Date: Sun, 18 Mar 2007 09:16:14 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
In-Reply-To: <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
X-Enigmail-Version: 0.94.3.0
OpenPGP: id=6857704D
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Jon Callas wrote:
> Use xml2rfc. It's really the way to go these days.

Yes, most definitely. Simon is already helping me out with some of the details. I hope to post the
beta Draft asap. Thanks for your time, Jon!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Foros GNU/Buanzo: Respeto, Soluciones y Buena Onda: http://foros.buanzo.com.ar
Consulting and Secure Mail Hosting: http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF/S2OAlpOsGhXcE0RCqWYAJ9wz606aYi98+mrlH/Fr/bu7GFxFACeIY/1
XoZiqW1V0cqNQWRcogBVU/M=
=Z2WH
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3Ct1V052291 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2I3CtoQ052290; Sat, 17 Mar 2007 20:12:55 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2I3CVhN052272 for <ietf-openpgp@imc.org>; Sat, 17 Mar 2007 20:12:52 -0700 (MST) (envelope-from jon@callas.org)
Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 0DF425C5FB7 for <ietf-openpgp@imc.org>; Sat, 17 Mar 2007 20:12:31 -0700 (PDT)
Received: from [66.93.68.165] ([66.93.68.165]) by keys.merrymeet.com (PGP Universal service); Sat, 17 Mar 2007 20:12:31 -0700
X-PGP-Universal: processed; by keys.merrymeet.com on Sat, 17 Mar 2007 20:12:31 -0700
In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org>
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org>
Mime-Version: 1.0 (Apple Message framework v752.3)
Message-Id: <F32A8F2B-5743-42DF-8484-375BD2A013C3@callas.org>
Cc: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>, ietf-openpgp@imc.org
From: Jon Callas <jon@callas.org>
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
Date: Sat, 17 Mar 2007 20:12:29 -0700
To: Simon Josefsson <simon@josefsson.org>
X-Mailer: Apple Mail (2.752.3)
X-PGP-Encoding-Version: 2.0.2
X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit
X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7BIT
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


On Mar 15, 2007, at 7:31 PM, Simon Josefsson wrote:

>
> "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:
>
>> Sorry to bother: Any recommendation on a text editor to use that  
>> supports all formatting
>> requirements for an Internet Draft? My googling so far has only  
>> provided a MS Word template.
>
> I recommend any text editor and the xml2rfc tool:
>
> http://xml.resource.org/
>

Use xml2rfc. It's really the way to go these days.

The tool I'm using is a perl script that Tim Dierks created when he  
was doing the TLS spec. It's good enough that I've never moved to  
xml2rfc, but there are so many nice things about the XML one that you  
should use it. It will do all the right boilerplate and crap. That  
changes often and you'll tear your hair out doing it yourself. It  
took me ten days (!) to get bis19 changed to meet all the stupid crap  
that isn't documented anywhere.

	Jon


-----BEGIN PGP SIGNATURE-----
Version: PGP Universal 2.5.3
Charset: US-ASCII

wj8DBQFF/K4fsTedWZOD3gYRArTGAJ9/mc37hxn9ixtbDvEH4UVAXCiBagCgkCOe
3tOGA/pEnvMDrdQFhb5Vk7c=
=Giso
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qreV006085 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2qrol006084; Thu, 15 Mar 2007 19:52:53 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2qob7006078 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:52:52 -0700 (MST) (envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2qbje004702 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:52:37 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org> <45FA0255.1090105@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::AkWLy2S2UiSbkfcU:1XRM
X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::paaMaEyNgUaKFwYr:092J5
Date: Fri, 16 Mar 2007 03:52:37 +0100
In-Reply-To: <45FA0255.1090105@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 23\:35\:01 -0300")
Message-ID: <871wjpsxvu.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Simon Josefsson wrote:
>> I recommend any text editor and the xml2rfc tool:
>> http://xml.resource.org/
>> See also RFC 2629.
>
> Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc,
> too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd
> rather use joe :P

You don't need XML support in your editor, joe will be fine.  If you
want a XML file to start editing from, have a look at:

http://josefsson.org/openpgp-header/draft-josefsson-openpgp-mailnews-header.xml

Good luck!

/Simon



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z6cK005131 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2Z66S005130; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.229]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2Z5rk005122 for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:35:06 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so431135wxd for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Received: by 10.70.74.6 with SMTP id w6mr2308727wxa.1174012505490; Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i11sm1519266wxd.2007.03.15.19.35.03; Thu, 15 Mar 2007 19:35:05 -0700 (PDT)
Message-ID: <45FA0255.1090105@buanzo.com.ar>
Date: Thu, 15 Mar 2007 23:35:01 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: Simon Josefsson <simon@josefsson.org>
CC: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar> <87ejnpsyvl.fsf@mocca.josefsson.org>
In-Reply-To: <87ejnpsyvl.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.3.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simon Josefsson wrote:
> I recommend any text editor and the xml2rfc tool:
> http://xml.resource.org/
> See also RFC 2629.

Yes, I finished reading that! I'll try nroff with the ms module (and the fix.pl script) and xml2rfc,
too. XML with the DTD sounds far better, but all XML DTD modes are for things like "emacs". I'd
rather use joe :P

Thanks for your time. I'll do my best, publish the Draft in this list, and ask for feedback :)

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF+gJVAlpOsGhXcE0RAlJBAJ0S9cgjU0KTkmTjZjbKZD1wvbzvawCeJwCg
5spprT8nmfi+UE0RCSPUJyU=
=Igzr
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VS7r004953 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2G2VSpR004952; Thu, 15 Mar 2007 19:31:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2G2VP4d004941 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 19:31:27 -0700 (MST) (envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2G2VB6V001952 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 16 Mar 2007 03:31:11 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@imc.org
Subject: Re: [OFFTOPIC] Editor under GNU/Linux
References: <45F9C122.9050200@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070316:ietf-openpgp@imc.org::CMr9oX8sv1hn/Lqv:BoVr
X-Hashcash: 1:22:070316:buanzo@buanzo.com.ar::bRMy06PyH6O6Gt8I:KNfF
Date: Fri, 16 Mar 2007 03:31:10 +0100
In-Reply-To: <45F9C122.9050200@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 15 Mar 2007 18\:56\:50 -0300")
Message-ID: <87ejnpsyvl.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-2.0 required=4.0 tests=AWL,BAYES_00, FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Sorry to bother: Any recommendation on a text editor to use that supports all formatting
> requirements for an Internet Draft? My googling so far has only provided a MS Word template.

I recommend any text editor and the xml2rfc tool:

http://xml.resource.org/

See also RFC 2629.

/Simon



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLuuSH089947 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2FLuu9h089946; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.236]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2FLut6i089939 for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 14:56:56 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i30so356142wxd for <ietf-openpgp@imc.org>; Thu, 15 Mar 2007 14:56:55 -0700 (PDT)
Received: by 10.70.61.1 with SMTP id j1mr1969082wxa.1173995814959; Thu, 15 Mar 2007 14:56:54 -0700 (PDT)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h20sm2123338wxd.2007.03.15.14.56.53; Thu, 15 Mar 2007 14:56:54 -0700 (PDT)
Message-ID: <45F9C122.9050200@buanzo.com.ar>
Date: Thu, 15 Mar 2007 18:56:50 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@imc.org
Subject: [OFFTOPIC] Editor under GNU/Linux
X-Enigmail-Version: 0.94.3.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sorry to bother: Any recommendation on a text editor to use that supports all formatting
requirements for an Internet Draft? My googling so far has only provided a MS Word template.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform for Firefox: A secure browsing experience: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF+cEiAlpOsGhXcE0RAgn1AJ91xa0+Sf88K+NlWUNw0WGoHQp85QCfZXNO
ld+pOAyet5X7G8BS9ZoHpmM=
=8gpm
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER9tv062729 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DER9NH062728; Tue, 13 Mar 2007 07:27:09 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DER6fg062721 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@imc.org>; Tue, 13 Mar 2007 07:27:08 -0700 (MST) (envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l2DEQgMG014436 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 15:26:43 +0100
From: Simon Josefsson <simon@josefsson.org>
To: ietf@ietf.org
Cc: ietf-openpgp@imc.org
Subject: Re: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message  Format) to Proposed Standard
References: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070313:ietf-openpgp@imc.org::qw6EqPbUi/ilw5Ur:0Jzu
X-Hashcash: 1:22:070313:ietf@ietf.org::X+KI19qLzrrlajE8:Esqs
X-Hashcash: 1:22:070313:ietf-announce@ietf.org::Uh10b+QwS0vF6hE5:8NDV
Date: Tue, 13 Mar 2007 15:26:42 +0100
In-Reply-To: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org> (The IESG's message of "Tue\, 13 Mar 2007 09\:43\:15 -0400")
Message-ID: <87mz2hw76l.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=0.2 required=4.0 tests=AWL,BAYES_50,FORGED_RCVD_HELO, TVD_FUZZY_SECURITIES autolearn=no version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Hi!

I started a review by going through the reference section.  There
seems to be some editing left to do...

There are reference to old documents, including:

  RFC 2279 -> RFC 3629
  RFC 1750 -> RFC 4086

There are normative reference to non-standards track RFCs, including:

  RFC 1641
  RFC 1951
  RFC 1991 (which documents is intended to obsolete?)
  RFC 2144

The following reference are never cited in the text as far as I can
tell.  Most of them should likely be removed, but citing
[BLEICHENBACHER] at some appropriate point may be useful.

    [RFC1423]        Balenson, D., "Privacy Enhancement for Internet
                     Electronic Mail: Part III: Algorithms, Modes, and
                     Identifiers", RFC 1423, October 1993.

    [RFC1641]        Goldsmith, D. and M. Davis, "Using Unicode with
                     MIME", RFC 1641, July 1994.

    [BLEICHENBACHER] Bleichenbacher, Daniel, "Generating Elgamal
                     signatures without knowing the secret key,"
                     Eurocrypt 96. Note that the version in the
                     proceedings has an error. A revised version is
                     available at the time of writing from
                     <ftp://ftp.inf.ethz.ch/pub/publications/papers/ti
                     /isc/ElGamal.ps>

    [DONNERHACKE]    Donnerhacke, L., et. al, "PGP263in - an improved
                     international version of PGP", ftp://ftp.iks-
                     jena.de/mitarb/lutz/crypt/software/pgp/

    [MAURER]         Ueli Maurer, "Modelling a Public-Key
                     Infrastructure", Proc. 1996 European Symposium on
                     Research in Computer Security (ESORICS' 96),
                     Lecture Notes in Computer Science, Springer-Verlag,
                     vol. 1146, pp. 325-350, Sep 1996.

    [RFC1983]        Malkin, G., "Internet Users' Glossary", FYI 18, RFC
                     1983, August 1996.

/Simon

The IESG <iesg-secretary@ietf.org> writes:

> The IESG has received a request from the An Open Specification for 
> Pretty Good Privacy WG (openpgp) to consider the following document:
>
> - 'OpenPGP Message Format '
>    <draft-ietf-openpgp-rfc2440bis-19.txt> as a Proposed Standard
>
> The IESG plans to make a decision in the next few weeks, and solicits
> final comments on this action.  Please send substantive comments to the
> ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, 
> comments may be sent to iesg@ietf.org instead. In either case, please 
> retain the beginning of the Subject line to allow automated sorting.
>
> The file can be obtained via
> http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt
>
>
> IESG discussion can be tracked via
> https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhJel059649 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2DDhJIU059648; Tue, 13 Mar 2007 06:43:19 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from ns1.neustar.com (ns1.neustar.com [156.154.16.138]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2DDhIsW059642 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@imc.org>; Tue, 13 Mar 2007 06:43:18 -0700 (MST) (envelope-from ietf@ietf.org)
Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns1.neustar.com (Postfix) with ESMTP id 9BB7426E78; Tue, 13 Mar 2007 13:43:15 +0000 (GMT)
Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HR7HX-0002QX-H9; Tue, 13 Mar 2007 09:43:15 -0400
X-test-idtracker: no
To: IETF-Announce <ietf-announce@ietf.org>
From: The IESG <iesg-secretary@ietf.org>
Subject: Last Call: draft-ietf-openpgp-rfc2440bis (OpenPGP Message  Format) to Proposed Standard 
Reply-To: ietf@ietf.org
Cc: <ietf-openpgp@imc.org>
Message-Id: <E1HR7HX-0002QX-H9@stiedprstage1.ietf.org>
Date: Tue, 13 Mar 2007 09:43:15 -0400
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

The IESG has received a request from the An Open Specification for 
Pretty Good Privacy WG (openpgp) to consider the following document:

- 'OpenPGP Message Format '
   <draft-ietf-openpgp-rfc2440bis-19.txt> as a Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits
final comments on this action.  Please send substantive comments to the
ietf@ietf.org mailing lists by 2007-03-27. Exceptionally, 
comments may be sent to iesg@ietf.org instead. In either case, please 
retain the beginning of the Subject line to allow automated sorting.

The file can be obtained via
http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt


IESG discussion can be tracked via
https://datatracker.ietf.org/public/pidtracker.cgi?command=view_id&dTag=4936&rfc_flag=0



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo6cN009086 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2CMo6OU009085; Mon, 12 Mar 2007 15:50:06 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from ns4.neustar.com (ns4.neustar.com [156.154.24.139]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2CMo3u9009077 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@imc.org>; Mon, 12 Mar 2007 15:50:05 -0700 (MST) (envelope-from ietf@ietf.org)
Received: from stiedprstage1.ietf.org (stiedprstage1.va.neustar.com [10.31.47.10]) by ns4.neustar.com (Postfix) with ESMTP id 788DD2ACD7; Mon, 12 Mar 2007 22:50:02 +0000 (GMT)
Received: from ietf by stiedprstage1.ietf.org with local (Exim 4.43) id 1HQtL8-00056B-84; Mon, 12 Mar 2007 18:50:02 -0400
Content-Type: Multipart/Mixed; Boundary="NextPart"
Mime-Version: 1.0
To: i-d-announce@ietf.org
Cc: ietf-openpgp@imc.org
From: Internet-Drafts@ietf.org
Subject: I-D ACTION:draft-ietf-openpgp-rfc2440bis-19.txt 
Message-Id: <E1HQtL8-00056B-84@stiedprstage1.ietf.org>
Date: Mon, 12 Mar 2007 18:50:02 -0400
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

--NextPart

A New Internet-Draft is available from the on-line Internet-Drafts 
directories.
This draft is a work item of the An Open Specification for Pretty Good Privacy Working Group of the IETF.

	Title		: OpenPGP Message Format
	Author(s)	: J. Callas, et al.
	Filename	: draft-ietf-openpgp-rfc2440bis-19.txt
	Pages		: 84
	Date		: 2007-3-12
	
This document is maintained in order to publish all necessary
    information needed to develop interoperable applications based on
    the OpenPGP format. It is not a step-by-step cookbook for writing an
    application. It describes only the format and methods needed to
    read, check, generate, and write conforming packets crossing any
    network. It does not deal with storage and implementation questions.
    It does, however, discuss implementation issues necessary to avoid
    security flaws.

    OpenPGP software uses a combination of strong public-key and
    symmetric cryptography to provide security services for electronic
    communications and data storage. These services include
    confidentiality, key management, authentication, and digital
    signatures. This document specifies the message formats used in
    OpenPGP.

A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt

To remove yourself from the I-D Announcement list, send a message to 
i-d-announce-request@ietf.org with the word unsubscribe in the body of 
the message. 
You can also visit https://www1.ietf.org/mailman/listinfo/I-D-announce 
to change your subscription settings.

Internet-Drafts are also available by anonymous FTP. Login with the 
username "anonymous" and a password of your e-mail address. After 
logging in, type "cd internet-drafts" and then 
"get draft-ietf-openpgp-rfc2440bis-19.txt".

A list of Internet-Drafts directories can be found in
http://www.ietf.org/shadow.html 
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt

Internet-Drafts can also be obtained by e-mail.

Send a message to:
	mailserv@ietf.org.
In the body type:
	"FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt".
	
NOTE:	The mail server at ietf.org can return the document in
	MIME-encoded form by using the "mpack" utility.  To use this
	feature, insert the command "ENCODING mime" before the "FILE"
	command.  To decode the response(s), you will need "munpack" or
	a MIME-compliant mail reader.  Different MIME-compliant mail readers
	exhibit different behavior, especially when dealing with
	"multipart" MIME messages (i.e. documents which have been split
	up into multiple messages), so check your local documentation on
	how to manipulate these messages.

Below is the data which will enable a MIME compliant mail reader
implementation to automatically retrieve the ASCII version of the
Internet-Draft.

--NextPart
Content-Type: Multipart/Alternative; Boundary="OtherAccess"

--OtherAccess
Content-Type: Message/External-body;
	access-type="mail-server";
	server="mailserv@ietf.org"

Content-Type: text/plain
Content-ID:	<2007-3-12150820.I-D@ietf.org>

ENCODING mime
FILE /internet-drafts/draft-ietf-openpgp-rfc2440bis-19.txt

--OtherAccess
Content-Type: Message/External-body;
	name="draft-ietf-openpgp-rfc2440bis-19.txt";
	site="ftp.ietf.org";
	access-type="anon-ftp";
	directory="internet-drafts"

Content-Type: text/plain
Content-ID:	<2007-3-12150820.I-D@ietf.org>

--OtherAccess--

--NextPart--



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q1fv022665 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l290q1qv022664; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l290q0ot022653 for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 17:52:01 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so748004wxd for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Received: by 10.70.40.1 with SMTP id n1mr1932022wxn.1173401518814; Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm3753938wxd.2007.03.08.16.51.57; Thu, 08 Mar 2007 16:51:58 -0800 (PST)
Message-ID: <45F0AFAA.7040605@buanzo.com.ar>
Date: Thu, 08 Mar 2007 21:51:54 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: OpenPGP for HTTP Reference Implementation
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear group,

	I've just released version 0.7.0 of Enigform. Please give it a try at http://enigform.mozdev.org.
If you get an older version, try the "alternate url" under the Installation section.

	This new version allows GET, POST and file uploads to be signed.

	I'll be updating the Draft for the OpenPGP for HTTP ASAP.

	Thanks for all the feedback, and I expect I can, with your help, transform the Draft into a real
RFC document, which is one of my wildest dreams. Thank you all!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8K+qAlpOsGhXcE0RAt90AJ9l8lLV084uzTlns3mFS4x/QIOgFACeNLTm
R/jjUbXSCdO0arKprWwZnaA=
=/8iw
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIV9c002222 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28IIV8B002221; Thu, 8 Mar 2007 11:18:31 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.231]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28IIUtl002215 for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 11:18:30 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so625929wxd for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Received: by 10.70.66.18 with SMTP id o18mr1221505wxa.1173377909684; Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h34sm3164761wxd.2007.03.08.10.18.26; Thu, 08 Mar 2007 10:18:29 -0800 (PST)
Message-ID: <45F0536B.6070204@buanzo.com.ar>
Date: Thu, 08 Mar 2007 15:18:19 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>	<20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org>
In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:
> I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

Okey, I've finished adding the new features. This is how a signed POST request from browser to
server now looks. Pay attention to the X-PGP-* headers and values. Some lines could've been wrapped.

==cut here==
POST /pba/postverify.php HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.2) Gecko/20070226 Firefox/2.0.0.2
Accept:
text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://localhost/pba/
X-PGP-Sig-Fields: body
X-PGP-Sig: iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIovixLWkMbebF2NTjo3WrVEZNA==q/ix
X-PGP-Version: GnuPG v1.4.6 (GNU/Linux)
X-PGP-via: Enigform for Mozilla Firefox
Content-Type: application/x-www-form-urlencoded
Content-Length: 17

variable=somedata
==cut here==

Of course, the X-PGP-Sig header value must be splitted in 3 strings to reconstruct the detached
signature, in chunks of 64, 24 and 5 characters (without the \r\n), respectively. The headers, when
combined to form a detached signature, would look like this:

- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFF8FIZAlpOsGhXcE0RAh9WAJ42Zo2Sqapu1WXYLF9+lHQd5zAPfQCePIov
ixLWkMbebF2NTjo3WrVEZNA=
=q/ix
- -----END PGP SIGNATURE-----

This is much more backwards compatible, and more geared towards standarization. I'll modify the
Draft asap to include these changes.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8FNrAlpOsGhXcE0RAhbIAJ431+J6vaSwVNgMG7Dp1mn4/f+NbACeIW5k
wzpDqJr9YLuPfzLej0VeeJ4=
=qXuA
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0nI0044650 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28G0n8A044649; Thu, 8 Mar 2007 09:00:49 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28G0mrA044643 for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 09:00:48 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so577333wxd for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 08:00:46 -0800 (PST)
Received: by 10.70.13.6 with SMTP id 6mr992666wxm.1173369645923; Thu, 08 Mar 2007 08:00:45 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm2977852wxd.2007.03.08.08.00.44; Thu, 08 Mar 2007 08:00:44 -0800 (PST)
Message-ID: <45F03329.20505@buanzo.com.ar>
Date: Thu, 08 Mar 2007 13:00:41 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>	<20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar> <87d53jlqhg.fsf@mocca.josefsson.org>
In-Reply-To: <87d53jlqhg.fsf@mocca.josefsson.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Simon Josefsson wrote:
> If you are considering turning that work into draft form, consider
> looking at the OpenPGP: header too:

Great, I'll check it out later.

> I'm confused whether your efforts is a discussion about one
> implementation, or whether you have standardization goals here.

Enigform = Mozilla Firefox Extension = "Reference Implementation" goal.
Draft = Standarization goal.


> Instead, if you want to protect header fields, you would sign the
> entire message as a message/rfc822 MIME body part and include it in
> the e-mail.

The problem is that this is for HTTP, not for eMail.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8DMpAlpOsGhXcE0RAmGkAJ95v7NYSHPZWHmAw9+f9xECuhWJnQCbBQOA
aPaaoaKbsAbIK3n/W5/i9lE=
=kbEL
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FC18k041634 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28FC1Rb041633; Thu, 8 Mar 2007 08:12:01 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from yxa.extundo.com (178.230.13.217.in-addr.dgcsystems.net [217.13.230.178]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28FBwJ8041617 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 08:12:00 -0700 (MST) (envelope-from simon@josefsson.org)
Received: from mocca.josefsson.org (yxa.extundo.com [217.13.230.178]) (authenticated bits=0) by yxa.extundo.com (8.13.4/8.13.4/Debian-3sarge3) with ESMTP id l28FBdhQ013613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 16:11:39 +0100
From: Simon Josefsson <simon@josefsson.org>
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl> <45F01209.3020706@buanzo.com.ar>
OpenPGP: id=B565716F; url=http://josefsson.org/key.txt
X-Hashcash: 1:22:070308:buanzo@buanzo.com.ar::PYCxtJVoHV3l1kYR:2D6n
X-Hashcash: 1:22:070308:ietf-openpgp@vpnc.org::U2UqeaBlmZMd9dwd:FdMt
Date: Thu, 08 Mar 2007 16:11:39 +0100
In-Reply-To: <45F01209.3020706@buanzo.com.ar> (Arturo Busleiman's message of "Thu\, 08 Mar 2007 10\:39\:21 -0300")
Message-ID: <87d53jlqhg.fsf@mocca.josefsson.org>
User-Agent: Gnus/5.110006 (No Gnus v0.6) Emacs/22.0.94 (gnu/linux)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
X-Spam-Status: No, score=-0.8 required=4.0 tests=AWL,BAYES_40, FORGED_RCVD_HELO autolearn=ham version=3.1.1
X-Spam-Checker-Version: SpamAssassin 3.1.1 (2006-03-10) on yxa-iv
X-Virus-Scanned: ClamAV version 0.88.2, clamav-milter version 0.88.2 on yxa.extundo.com
X-Virus-Status: Clean
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

"Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> writes:

> Current Status:
>
> I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header,
> which will ONLY contain the signature. Signed elements will be kept in a separate header,
> X-PGP-Sig-Elements.
>
> I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

If you are considering turning that work into draft form, consider
looking at the OpenPGP: header too:

http://josefsson.org/openpgp-header/

I'm confused whether your efforts is a discussion about one
implementation, or whether you have standardization goals here.

The OpenPGP: header do not support signing of header elements,
however.  The reason is that mail gateways are known to modify header
elements, causing the OpenPGP signature to fail.

Instead, if you want to protect header fields, you would sign the
entire message as a message/rfc822 MIME body part and include it in
the e-mail.

What is lacking for this alternative approach to interop is guidelines
to specify that MUAs should replace the outer headers with the inner
ones for display purposes.  The same affect S/MIME too.  Perhaps it is
time to revise RFC 1847 and add a discussion about this?  Are people
interested in working on this?  Some people have been recommending
signing message/rfc822 for several years, but it is not that
well-defined exactly how that should work, and there is no RFC to
reference either.

/Simon



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdX7f036932 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l28DdXup036931; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l28DdWsp036925 for <ietf-openpgp@vpnc.org>; Thu, 8 Mar 2007 06:39:33 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so532007wxd for <ietf-openpgp@vpnc.org>; Thu, 08 Mar 2007 05:39:30 -0800 (PST)
Received: by 10.70.125.11 with SMTP id x11mr742224wxc.1173361167097; Thu, 08 Mar 2007 05:39:27 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h19sm2798675wxd.2007.03.08.05.39.24; Thu, 08 Mar 2007 05:39:25 -0800 (PST)
Message-ID: <45F01209.3020706@buanzo.com.ar>
Date: Thu, 08 Mar 2007 10:39:21 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org> <20070307202946.GA39535@mud.stack.nl>
In-Reply-To: <20070307202946.GA39535@mud.stack.nl>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Current Status:

I'm rewriting Enigform to use a backwards-compatible methodology, by using the X-PGP-Sig header,
which will ONLY contain the signature. Signed elements will be kept in a separate header,
X-PGP-Sig-Elements.

I expect to have a working version by tomorrow (or today, it's raining in Buenos Aires, so...!).

I'll update the Draft ASAP.

Thanks for all the input so far!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF8BIJAlpOsGhXcE0RAmhDAKCAa7YhjPR2cwgymD3qF6dZGmTAlgCfTZAy
RWE253rIkVojn/KC7WjxFUs=
=uhl7
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRLBm090766 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27LRLBo090765; Wed, 7 Mar 2007 14:27:21 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27LRKKB090759 for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 14:27:20 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so311697wxd for <ietf-openpgp@vpnc.org>; Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Received: by 10.70.50.18 with SMTP id x18mr864310wxx.1173302839533; Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h36sm1586026wxd.2007.03.07.13.27.17; Wed, 07 Mar 2007 13:27:19 -0800 (PST)
Message-ID: <45EF2E33.5030805@buanzo.com.ar>
Date: Wed, 07 Mar 2007 18:27:15 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.10 (X11/20070221)
MIME-Version: 1.0
To: Hal Finney <hal@finney.org>
CC: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: OpenPGP Signing of HTTP POST
References: <20070307194207.51D6314F6BC@finney.org>
In-Reply-To: <20070307194207.51D6314F6BC@finney.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hal Finney wrote:
> I think the idea is that you can sign not only the message contents, but
> selected headers as well.

That's... QUITE interesting!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Enigform - Nueva Seguridad al navegar: http://enigform.mozdev.org
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7y4yAlpOsGhXcE0RAjCUAJ97KaWtWsV0hlP4JFxSvsbtSl5NTQCffkri
BYT5/VKN2TWdsJNKy/bxH70=
=OI9s
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTsQJ087553 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27KTsGa087552; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mx1.stack.nl (meestal.stack.nl [131.155.140.141]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27KTqD1087545 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 13:29:54 -0700 (MST) (envelope-from johans@stack.nl)
Received: by mx1.stack.nl (Postfix, from userid 65534) id 5B3414B096; Wed,  7 Mar 2007 21:29:49 +0100 (CET)
X-Spam-DCC: : snail.stack.nl 104; Body=1 Fuz1=1 Fuz2=1
X-Spam-Checker-Version: SpamAssassin 3.1.5 (2006-08-29) on snail.stack.nl
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 required=5.0 tests=AWL,BAYES_00,NO_RELAYS  autolearn=ham version=3.1.5
X-Spam-Relay-Country: 
Received: from mud.stack.nl (mud.stack.nl [IPv6:2001:610:1108:5011:207:e9ff:fe14:b498]) by mx1.stack.nl (Postfix) with ESMTP id DF6494B05B; Wed,  7 Mar 2007 21:29:47 +0100 (CET)
Received: by mud.stack.nl (Postfix, from userid 801) id 9E628231E3; Wed,  7 Mar 2007 21:29:47 +0100 (CET)
Date: Wed, 7 Mar 2007 21:29:47 +0100
From: Johan van Selst <johans@stack.nl>
To: Hal Finney <hal@finney.org>
Cc: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: Re[2]: OpenPGP Signing of HTTP POST
Message-ID: <20070307202946.GA39535@mud.stack.nl>
References: <20070307194207.51D6314F6BC@finney.org>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha256; protocol="application/pgp-signature"; boundary="zYM0uCDKw75PZbzx"
Content-Disposition: inline
In-Reply-To: <20070307194207.51D6314F6BC@finney.org>
User-Agent: Mutt/1.5.13 (2006-08-11)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

--zYM0uCDKw75PZbzx
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

"Hal Finney" wrote:
> You might want to look at the X-PGP-Sig: header which has been used
> for some years to sign Usenet (newsgroup) posts.  Unfortunately I can't
> find any documentation of it

A nice desciption of background and the actual format can be found here,
http://archives.eyrie.org/software/pgpcontrol/FORMAT


Johan

--zYM0uCDKw75PZbzx
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----

iD8DBQFF7yC6aOElK32lxTsRCPohAJ0VXMQJuxLBWsa43kr6oIXgEdZAXwCfRhcu
vfR4ZXd9wiSUJlfiHYllawk=
=n5Xh
-----END PGP SIGNATURE-----

--zYM0uCDKw75PZbzx--



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrHfn085912 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l27JrHfk085911; Wed, 7 Mar 2007 12:53:17 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from finney.org (226-132.adsl2.netlojix.net [207.71.226.132]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l27JrCmk085903 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=FAIL) for <ietf-openpgp@vpnc.org>; Wed, 7 Mar 2007 12:53:16 -0700 (MST) (envelope-from hal@finney.org)
Received: by finney.org (Postfix, from userid 500) id 51D6314F6BC; Wed,  7 Mar 2007 11:42:07 -0800 (PST)
To: ietf-openpgp@vpnc.org, ni4@ukr.net
Subject: Re: Re[2]: OpenPGP Signing of HTTP POST
Message-Id: <20070307194207.51D6314F6BC@finney.org>
Date: Wed,  7 Mar 2007 11:42:07 -0800 (PST)
From: hal@finney.org ("Hal Finney")
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

"Nickolay L." <ni4@ukr.net> writes:
> For example, we can do as following :
>
>    POST /pba/postverify.php HTTP/1.1
>    X-PGP-Message: Cleartext-Signed
>    X-PGP-Signature-Hash: SHA1
>    X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux)
>    X-PGP-Signature-Comment: POST signed using Enigform
>    X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
>    Z5AuIplmYgUFhTU3x3Sq9g==
>    Host: localhost
>    ...

You might want to look at the X-PGP-Sig: header which has been used
for some years to sign Usenet (newsgroup) posts.  Unfortunately I can't
find any documentation of it but if you Google x-pgp-sig you will find
for example an Emacs macro which inserts it, part of the Ubuntu Linux
distribution.  Here is a sample which was posted to this list several
years ago:

X-PGP-Sig: 2.6.3ia Subject,From,X-Mailer
        iQCVAwUBM84wngE7m572a9utAQETEgQAwcL38QVdZbkHuW4Mblmje17deuI85R1j
        4yGiDlb1enRDSUyGiLCmk8YphNDiLdKKlMV3Z0opzREUW9Q+sb8fr5s1QXMJhvXs
        7hi7s4+V00rjgbqbqXVNiajKiKfVxd7JTRfe0UIZuOljnURP1ZCMlSRD1rDoCEAg
        1vunQv6QYj4=
        =hvn0

I think the idea is that you can sign not only the message contents, but
selected headers as well.

Hal Finney



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Jvq9m092847 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26JvqpB092846; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.224]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JvpjK092840 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:57:52 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2063984wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Received: by 10.70.65.5 with SMTP id n5mr10334599wxa.1173211069695; Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10958002wxd.2007.03.06.11.57.48; Tue, 06 Mar 2007 11:57:49 -0800 (PST)
Message-ID: <45EDC7B9.6060100@buanzo.com.ar>
Date: Tue, 06 Mar 2007 16:57:45 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306194431.705B318212@dune.rediris.es>
In-Reply-To: <20070306194431.705B318212@dune.rediris.es>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Francisco Jesus Monserrat Coll wrote:
>  With this option the web pages can be cached and verified , without 
> using HTTP to protect the integrity of the web pages.

Yes, I read about it when I first researched the pgp and http terms in google. The only difference
in my case, is that I'm signing the requests the user/browser is sending to the web server, and not
the pages that are sent to the browser/user.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7ce5AlpOsGhXcE0RAtENAJ0aYhimGxlsAIVdCHBCuTyRhePHgwCfXDsR
gN2+3tyhAOFgmJAqN3tYhJ4=
=McuB
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JujsK092797 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jujkw092796; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Juikt092789 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:56:45 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2063698wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 11:56:44 -0800 (PST)
Received: by 10.70.74.6 with SMTP id w6mr8511444wxa.1173211004332; Tue, 06 Mar 2007 11:56:44 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10971709wxd.2007.03.06.11.56.42; Tue, 06 Mar 2007 11:56:43 -0800 (PST)
Message-ID: <45EDC777.70606@buanzo.com.ar>
Date: Tue, 06 Mar 2007 16:56:39 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar> <45EDC608.70904@systemics.com>
In-Reply-To: <45EDC608.70904@systemics.com>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Ian G wrote:
> I suspect the question revolves around what you want to use the OpenPGP
> signature for.  Is it integrity, authentication, or authorisation?

All that is described in the URLs I sent in my original post.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7cd3AlpOsGhXcE0RAgSsAJ9QQg6Xv8zoleliWj/MNvqHoIIXbgCfXih/
BIPfj439LAqAsZDqi9zezzw=
=r8Ot
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JohCj092497 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Johe8092496; Tue, 6 Mar 2007 12:50:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from www2.futureware.at ([217.19.43.211]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JofH9092488 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:50:42 -0700 (MST) (envelope-from iang@systemics.com)
Received: from [127.0.0.1] (localhost [127.0.0.1]) by www2.futureware.at (Postfix) with ESMTP id 60FEF2280B5; Tue,  6 Mar 2007 20:50:42 +0100 (CET)
Message-ID: <45EDC608.70904@systemics.com>
Date: Tue, 06 Mar 2007 20:50:32 +0100
From: Ian G <iang@systemics.com>
User-Agent: Thunderbird 1.5.0.10 (Macintosh/20070221)
MIME-Version: 1.0
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar>
In-Reply-To: <45EDB0A9.80207@buanzo.com.ar>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Arturo 'Buanzo' Busleiman wrote:

>> For example, we can do as following :
> [...]
>> Where signature is to be calculated over all message (including header
>> fields) after X-PGP-Signature.
> 
> I thought about this, too.
> 
> What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent
> proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of
> that same reason.


I suspect the question revolves around what you want to use 
the OpenPGP signature for.  Is it integrity, authentication, 
or authorisation?

Integrity would indicate a header-based binary signature and 
authorisation would prefer a cleartext signature over the 
body only.

For example, if you were authorising a financial 
transaction, you would want to get as close to the user as 
possible ... which admittedly is a hard or impossible task 
if the starting point is a POST.  If you seriously wanted 
reliable authorisation, in the sense of "sign here to 
authorise this money transfer" I'd look for something that 
sent a cleartext signed statement that was human 
interpretable, so that the human could review and confirm 
it.  That is, not a POST of variables at all, but a POST of 
a custom text based packet:

-----BEGIN PGP SIGNED MESSAGE-----

Action: TRANSFER
Source: 1233455
Target: 5433211
Value:  1000.00
Unit:   USD
Terms:  Appendix A.

-----BEGIN PGP SIGNATURE-----

yeahthisisajunksigyourclientshouldbarf
-----END PGP SIGNATURE------

With that form you can code up some form of proxy-based user 
client that independently of the Browser creates the signed 
authorisation ... which then means there is potential of a 
firewall between the Authorising soft/hardware and the 
Application software.

As soon as you hide that info from the user in for example a 
POST form, you will be at the mercy of technical attacks. 
How do you know that the veriables signed were in some way 
presented to the user?  In some courts, just the existence 
of these attacks will be enough to get it thrown out (e.g., 
Germany I am told tends to be very aggressive this way).



iang



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JibYw092282 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Jib6C092281; Tue, 6 Mar 2007 12:44:37 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from rediris.es (chico.rediris.es [130.206.1.3]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26JiZKo092265 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:44:36 -0700 (MST) (envelope-from francisco.monserrat@rediris.es)
Received: from dune.rediris.es (login.rediris.es [130.206.1.21]) by chico.rediris.es (Postfix) with ESMTP id E77D944DE4; Tue,  6 Mar 2007 20:44:31 +0100 (CET)
Received: by dune.rediris.es (Postfix, from userid 500) id 705B318212; Tue,  6 Mar 2007 20:44:31 +0100 (CET)
Received: from rediris.es (localhost [127.0.0.1]) by dune.rediris.es (Postfix) with ESMTP id 6E0E9181B8; Tue,  6 Mar 2007 20:44:31 +0100 (CET)
X-Mailer: exmh version 2.7.2 04/04/2003 with nmh-1.1
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
From: Francisco Jesus Monserrat Coll <francisco.monserrat@rediris.es>
X-Image-Url: http://arraquis.dif.um.es/~paco/paco.gif
X-Face: #>K{rw[D{N?r0=GjSYDGBc"EH7Wc_zk,jD+w/*@gE*i%2izUEF#}pJ/}~mQQA$Y:$yL"Da3 `Lw,Kd(@6fQy1<,fLcO}z-"g)~-Qm^U?#yQ.h|+2}*L>e}]I5M@4`*TaSs>d+z'gs9Xt:||?Ufb 5F9uY:v^"5*enEyLV,}Ly(K0ot[4k<q3#d6IL:]nyU:QHjTTuj&wlr;VbW/joa>[_$D=tm)t=%Nd ;w<}gbsQn{zexIf.%h^EYSZr3/-k')Macr:l)mq=U.eIY}_4i@}E'o=N._+RBz`Bt?
Organization: Red.es http://www.red.es/ 
Subject: Re: OpenPGP Signing of HTTP POST 
In-Reply-To: <45ED6495.1040407@buanzo.com.ar> 
References: <45ED6495.1040407@buanzo.com.ar>
Comments: In-reply-to "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar> message dated "Tue, 06 Mar 2007 09:54:45 -0300."
Mime-Version: 1.0
Content-Type: multipart/signed; boundary="==_Exmh_1173210270_4204P"; micalg=pgp-sha1; protocol="application/pgp-signature"
Content-Transfer-Encoding: 7bit
Date: Tue, 06 Mar 2007 20:44:31 +0100
Message-Id: <20070306194431.705B318212@dune.rediris.es>
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

--==_Exmh_1173210270_4204P
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: 8bit


El día Tue, 06 Mar 2007 09:54:45 -0300  "Arturo 'Buanzo' Busleiman" escribió:

Hello,

 Not regarding the "POST" method but to sign HTML pages there were 
some web pages, after reading 
http://members.aol.com/EJNBell/pgp-www.html 

we developed a similar method, hiding the PGP header,
http://www.rediris.es/pgp/firmaweb/index.en.html

 The idea was to not "overload" the web server with HTTPS security 
only to provide signed  web pages, but sign the web pages with PGP 
and place in a normal HTTP server, and later use PGP to check the web
page signature.
 
 With this option the web pages can be cached and verified , without 
using HTTP to protect the integrity of the web pages.


>

-- =
Francisco Jesus Monserrat Coll PGP key: http://www.rediris.es/keyserver
Rediris. Entidad Pública Empresarial Red.es 
Pza. Manuel Gómez Moreno, s/n Madrid 28014 SPAIN. tel +034 912127625 



--==_Exmh_1173210270_4204P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Exmh version 2.1.0

iQCVAwUBRe3EnlKs6y7TpCxhAQIlBgP/VxILGTW91aeB+/2psL1vDy0zjvBdEsuP
wtKaxhH6V7eA3d35Pz/CRyvyuprhMU/SDE8sWzMovptyPtSTQ8khh9IXJ1YpB3Uz
42QwUt7zBZYzrf/zmm0s2qmkoS7tAeRP9L6tdAwzkdLnIPdKQK7WO97yHWLAQOFz
jFmwnlN3RCA=
=5m1Z
-----END PGP SIGNATURE-----

--==_Exmh_1173210270_4204P--



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9kHR090279 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26J9kTn090278; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26J9frq090269 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 12:09:46 -0700 (MST) (envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from <ni4@ukr.net>) id 1HOf2a-000B0r-8z for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 21:09:40 +0200
Date: Tue, 6 Mar 2007 21:06:09 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <1682706895.20070306210609@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <45EDB0A9.80207@buanzo.com.ar>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net> <45EDB0A9.80207@buanzo.com.ar>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Hello Arturo,

ABB> Remote sites have to tell the browser that the request should be
ABB> signed, thus, only compatible sites
ABB> will receive such requests.
Sites can tell the browser, that request should be signed by using
simple header field, like 'X-OpenPGP-Signature-Needed: true'. And if
reply will be sent without signature, then server will throw to client
403 or any other error.

ABB> In any case, I'm only modifying the body, and adding a header. No
ABB> request-specific structure is modified at all. Only proxies and/or content scanners and/or
ABB> webservers that make any kind of verification over the BODY
ABB> might be problematic. In any case, as
ABB> Apache+PHP provide the RAW POST body, I don't think an openpgp
ABB> signed body would make any problems.

ABB> Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick
ABB> hack, and that's why I'm here. An
ABB> official extension to the HTTP protocol, or better yet, a new
ABB> content-encoding, should be analyzed.
New content

>> For example, we can do as following :
ABB> [...]
>> Where signature is to be calculated over all message (including header
>> fields) after X-PGP-Signature.

ABB> I thought about this, too.

ABB> What if other fields are added, after the X-PGP-Signature is
ABB> calculated? What about [non]transparent
ABB> proxies? OpenPGP tags the beginning and end of the data that
ABB> corresponds to the signature because of
ABB> that same reason.
If you are using non-transparent proxy, it means
1) you doesn't care about headers, they must not be signed - thus, you
can add parameter, something like 'X-OpenPGP-Signature-Param:
no-headers', which causes to sign/verify only the message body
(non-transparent proxies doesn't change message body, yep?)
2) if some headers are significant, there can be parameter, something
like 'X-OpenPGP-Validate-Headers: User-Agent, Accept-Charset, Referer'

--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJSpi086454 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26IJSGu086453; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.233]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26IJRt3086447 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 11:19:28 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2035166wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 10:19:27 -0800 (PST)
Received: by 10.70.23.1 with SMTP id 1mr8344182wxw.1173205167633; Tue, 06 Mar 2007 10:19:27 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i33sm10810882wxd.2007.03.06.10.19.25; Tue, 06 Mar 2007 10:19:26 -0800 (PST)
Message-ID: <45EDB0A9.80207@buanzo.com.ar>
Date: Tue, 06 Mar 2007 15:19:21 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar> <1466251624.20070306200222@ukr.net>
In-Reply-To: <1466251624.20070306200222@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Hello Arturo,

Hi Nickolay,

> Your format changes the HTTP protocol, which disables backward
> compatibility, and could add other problems.

Remote sites have to tell the browser that the request should be signed, thus, only compatible sites
will receive such requests. In any case, I'm only modifying the body, and adding a header. No
request-specific structure is modified at all. Only proxies and/or content scanners and/or
webservers that make any kind of verification over the BODY might be problematic. In any case, as
Apache+PHP provide the RAW POST body, I don't think an openpgp signed body would make any problems.

Of course, I agree that the "##ENIGFORM_Sign##" tag is a quick hack, and that's why I'm here. An
official extension to the HTTP protocol, or better yet, a new content-encoding, should be analyzed.

> For example, we can do as following :
[...]
> Where signature is to be calculated over all message (including header
> fields) after X-PGP-Signature.

I thought about this, too.

What if other fields are added, after the X-PGP-Signature is calculated? What about [non]transparent
proxies? OpenPGP tags the beginning and end of the data that corresponds to the signature because of
that same reason.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7bCpAlpOsGhXcE0RAkokAJ0W4QaNgmIgq+9QBTto0F2kQ+1D+gCfeUGt
IoUmfdm9B2DK++gsvrdO138=
=dyTr
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5u7U085551 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26I5uPT085550; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26I5sDZ085544 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 11:05:56 -0700 (MST) (envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from <ni4@ukr.net>) id 1HOe2r-0007gS-A0 for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 20:05:53 +0200
Date: Tue, 6 Mar 2007 20:02:22 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <1466251624.20070306200222@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <45EDA1BB.8070606@buanzo.com.ar>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net> <45EDA1BB.8070606@buanzo.com.ar>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Hello Arturo,


>> ABB> Please, expand that! What are your ideas for OpenPGP security over http?
>> Something like cleartext signing for HTTP - PGP-Signature headers and
>> so on, and also encryption/binary signing of http document body.

ABB> Enigform currently adds an X-Enigform header with "Signed"
ABB> value. I will be adding extra OpenPGP
ABB> parameters (fingerprint? keyid?), and the ability to also
ABB> encrypt. Currently, only http POSTS are
ABB> supported. A signed request looks like this:
ABB> What are the extra ideas you have?
Your format changes the HTTP protocol, which disables backward
compatibility, and could add other problems.
For example, we can do as following :

   POST /pba/postverify.php HTTP/1.1
   X-PGP-Message: Cleartext-Signed
   X-PGP-Signature-Hash: SHA1
   X-PGP-Signature-Version: GnuPG v1.4.6 (GNU/Linux)
   X-PGP-Signature-Comment: POST signed using Enigform
   X-PGP-Signature: iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   variable=test

Where signature is to be calculated over all message (including header
fields) after X-PGP-Signature.

So, it will correspond to such OpenPGP message, which could be sent
to GnuPG for verification and so on :

   -----BEGIN PGP SIGNED MESSAGE-----
   Hash: SHA1

   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   variable=test
   -----BEGIN PGP SIGNATURE-----
   Version: GnuPG v1.4.6 (GNU/Linux)
   Comment: POST signed using Enigform

   iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   =wVHP
   -----END PGP SIGNATURE-----

Such simple translation on server and client side allows you to use
HTTP protocol as it is, and allows backwatds compatibility for
applications, which aren't compatible with such extensions.

I'm going to write complete draft of my ideas and publish it after
week or so.
   
--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]




Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFkGd082613 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26HFk85082612; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.235]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26HFjXW082606 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 10:15:46 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so2016733wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 09:15:45 -0800 (PST)
Received: by 10.70.84.6 with SMTP id h6mr12037573wxb.1173201344993; Tue, 06 Mar 2007 09:15:44 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i35sm10629647wxd.2007.03.06.09.15.42; Tue, 06 Mar 2007 09:15:43 -0800 (PST)
Message-ID: <45EDA1BB.8070606@buanzo.com.ar>
Date: Tue, 06 Mar 2007 14:15:39 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net> <45ED7F1E.90408@buanzo.com.ar> <1976536264.20070306190040@ukr.net>
In-Reply-To: <1976536264.20070306190040@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Hello Arturo,

Hello, Nickolay. You forgot to reply to the list.

> ABB> Please, expand that! What are your ideas for OpenPGP security over http?
> Something like cleartext signing for HTTP - PGP-Signature headers and
> so on, and also encryption/binary signing of http document body.

Enigform currently adds an X-Enigform header with "Signed" value. I will be adding extra OpenPGP
parameters (fingerprint? keyid?), and the ability to also encrypt. Currently, only http POSTS are
supported. A signed request looks like this:

 POST /pba/postverify.php##ENIGFORM_Sign## HTTP/1.1
   Host: localhost
   User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.1) \
   Gecko/20070130 Firefox/2.0.0.1
   Accept: text/xml,application/xml,application/xhtml+xml,text/html\
   ;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
   Accept-Language: en-us,en;q=0.5
   Accept-Encoding: gzip,deflate
   Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
   Keep-Alive: 300
   X-Enigform: Signed
   Connection: keep-alive
   Referer: http://localhost/pba/
   Content-Length: 323
   Content-Type: application/x-www-form-urlencoded-openpgp
   Cache-Control: max-age=0

   -----BEGIN PGP SIGNED MESSAGE-----
   Hash: SHA1

   variable=test
   -----BEGIN PGP SIGNATURE-----
   Version: GnuPG v1.4.6 (GNU/Linux)
   Comment: POST signed using Enigform

   iD4DBQFFyMVnAlpOsGhXcE0RAmpcAJ9Lkqd/PZqVV/hoPFSoFZxizECKHwCY/rWd
   Z5AuIplmYgUFhTU3x3Sq9g==
   =wVHP
   -----END PGP SIGNATURE-----

What are the extra ideas you have?

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7aG7AlpOsGhXcE0RAtCEAJ95pYoWzioR+L+qLQAkMZdEsLWSsgCeO0dM
ns6HspQOJQQf3+fpi6nMFdI=
=BEZt
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em5th070744 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Em5tA070743; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.227]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Em2Qu070736 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 07:48:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1970241wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 06:48:02 -0800 (PST)
Received: by 10.70.90.14 with SMTP id n14mr11850088wxb.1173192482284; Tue, 06 Mar 2007 06:48:02 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10439741wxd.2007.03.06.06.48.00; Tue, 06 Mar 2007 06:48:01 -0800 (PST)
Message-ID: <45ED7F1E.90408@buanzo.com.ar>
Date: Tue, 06 Mar 2007 11:47:58 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org> <642100057.20070306155914@ukr.net>
In-Reply-To: <642100057.20070306155914@ukr.net>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=windows-1251
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Nickolay L. wrote:
> Btw, in my plans also is writing and implementing something like 'PGP
> security over HTTP' specification, and already having some ideas 'bout
> it (it's something other than proposed by Arturo). Maybe, consider writing it in a group?

Please, expand that! What are your ideas for OpenPGP security over http?

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7X8dAlpOsGhXcE0RAgcUAJ0eDb6SQRJpTbw8HbchprbiZa2pcACfUOSJ
GxrIHHPmQ0eeQXDzmrY2hT4=
=urng
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2hM5066817 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26E2hkg066812; Tue, 6 Mar 2007 07:02:43 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from em.volia.net (em.volia.net [82.144.192.9]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26E2eEc066804 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 07:02:42 -0700 (MST) (envelope-from ni4@ukr.net)
Received: from moveless.slip.volia.net ([77.122.179.22] helo=infernal.org.ua) by em.volia.net with esmtp (Exim 4.63 (FreeBSD)) (envelope-from <ni4@ukr.net>) id 1HOaFS-000PPs-TN for ietf-openpgp@vpnc.org; Tue, 06 Mar 2007 16:02:39 +0200
Date: Tue, 6 Mar 2007 15:59:14 +0200
From: "Nickolay L." <ni4@ukr.net>
X-Mailer: The Bat! (v3.80.03) Professional
Reply-To: "Nickolay L." <ni4@ukr.net>
X-Priority: 3 (Normal)
Message-ID: <642100057.20070306155914@ukr.net>
To: ietf-openpgp@vpnc.org
Subject: Re[2]: OpenPGP Signing of HTTP POST
In-Reply-To: <20070306131900.GA25665@epointsystem.org>
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=windows-1251
Content-Transfer-Encoding: 8bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

Hello Daniel,

Btw, in my plans also is writing and implementing something like 'PGP
security over HTTP' specification, and already having some ideas 'bout
it (it's something other than proposed by Arturo). Maybe, consider writing it in a group?

DAN> I think that this is extremely useful; I was enterntaining the same idea
DAN> myself, albeit in a slightly different way.

DAN> I think, that the standardized protocol needs to have facilities for both
DAN> client-, server- and content-authentication.

DAN> May I ask what the status of the draft is and how do you enter changes into
DAN> it?


--
  Best regards,Nickolay mailto:<ni4@ukr.net>
      , .
     /_`,
    `' | &*._.,.
      .#      ) $,
     //./--//\\. &
     \/     \. \. -- - - ...   - - --.
    `'`'     `  `' -- - -  [> http://ansiart.org.ua <]
 [The Bat!3.80.03/Windows 5.1/Far 1.70(build 2087)]
 [Now playing : Ïèêíèê - Øàðìàíêà]



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5tm065994 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Do54e065993; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.237]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Do5CI065987 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 06:50:05 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1951840wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Received: by 10.70.66.18 with SMTP id o18mr11759820wxa.1173189002805; Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id h38sm10276388wxd.2007.03.06.05.50.00; Tue, 06 Mar 2007 05:50:02 -0800 (PST)
Message-ID: <45ED7185.2010300@buanzo.com.ar>
Date: Tue, 06 Mar 2007 10:49:57 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
References: <45ED6495.1040407@buanzo.com.ar> <20070306131900.GA25665@epointsystem.org>
In-Reply-To: <20070306131900.GA25665@epointsystem.org>
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Daniel A. Nagy wrote:
> I think that this is extremely useful; I was enterntaining the same idea
> myself, albeit in a slightly different way.

I had this idea in March/April 2006. Just had time to implement it last month :)

> I think, that the standardized protocol needs to have facilities for both
> client-, server- and content-authentication.

Yes, of course.

> May I ask what the status of the draft is and how do you enter changes into
> it?

The draft is behind the development status of the Enigform Firefox Extension. Currently, HTTP POST
requests generated via AJAX calls, or FORM submissions will be picked up for signing by Enigform by
checking if the ACTION URL (or Ajax request url) ends with "##ENIGFORM_Sign##". I had tested this
with a hidden input field of a special name/value combination, I've also tested using an extra
parameter for the <FORM> tag (SECURITY='ToBeSigned'), but all of this made the extension's code
overly complicated, and incompatible with certain sites. Checking the URL was quite a simpler approach.

Of course, the correct (i think) way for a FORM submission to be signed would be with a special
enctype (like urlencoded-openpgp-signed), but that would render ajax support useless, too.
Additionally, AJAX requests can't be diferentiated from form posts from within a Firefox extension.

Adoption of this technology is easier via a Firefox extension, and a simple set of server-side code
(that's why I talked with Rod, author of Smutty, to extend it with Enigform support).

Regarding changes to the draft, no specific procedures have been established, yet. This is my first
attempt. I'm open to suggestions.

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7XGFAlpOsGhXcE0RAoS1AJ9kFXExRm9QAkxtQ5TJbndGe7eURwCbBYA4
C8sg7uGRJ7UWJUjdxNTFG/0=
=Wdrc
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ3LF063660 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26DJ3bm063659; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from mail.epointsystem.org (120.156-228-195.hosting.adatpark.hu [195.228.156.120]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26DJ2hP063653 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 06:19:03 -0700 (MST) (envelope-from nagydani@epointsystem.org)
Received: by mail.epointsystem.org (Postfix, from userid 1001) id 20C5B3E8E; Tue,  6 Mar 2007 14:19:01 +0100 (CET)
Date: Tue, 6 Mar 2007 14:19:01 +0100
To: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Cc: ietf-openpgp@vpnc.org
Subject: Re: OpenPGP Signing of HTTP POST
Message-ID: <20070306131900.GA25665@epointsystem.org>
References: <45ED6495.1040407@buanzo.com.ar>
Mime-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="9amGYk9869ThD9tj"
Content-Disposition: inline
In-Reply-To: <45ED6495.1040407@buanzo.com.ar>
User-Agent: Mutt/1.5.9i
From: nagydani@epointsystem.org (Daniel A. Nagy)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

--9amGYk9869ThD9tj
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

I think that this is extremely useful; I was enterntaining the same idea
myself, albeit in a slightly different way.

I think, that the standardized protocol needs to have facilities for both
client-, server- and content-authentication.

May I ask what the status of the draft is and how do you enter changes into
it?

On Tue, Mar 06, 2007 at 09:54:45AM -0300, Arturo 'Buanzo' Busleiman wrote:
>=20
> Dear OpenPGP WG team,
>=20
> 	One day at 3am in the morning I woke up with a mix of two strings in my =
head: "POST / HTTP/1.1" and
> "-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about t=
he whole idea, and as I
> couldn't go back to sleep, I got up and wrote it down. A couple of months=
 later, and some BIG
> thinking, I decided to create a Firefox Extension to implement what I am =
now going to describe, and
> what I want to rewrite into a proper Draft:
>=20
> For years different methods for User Authentication and Session Managemen=
t have been implemented:
>=20
>     * HTTP Authentication
>     * Cookies
>     * GET/POST values
>     * SSL with client certificates
>     * A combination of all the above.
>=20
> Regarding SMTP, e-mail has been digitally signed for a long time now, and=
 it is a standard.
> Extending its usage to the HTTP protocol sounded like a natural idea, spe=
cially at 3am when I woke
> up with a OpenPGP-signed HTTP POST request in my head.
>=20
> By having the POST payload ("variable=3Dtest") signed using an ASCII armo=
red, Clearsign, OpenPGP based
> procedure, the browsing user can provide Identity Authentication to that =
payload, thus adding all
> OpenPGP benefits to the HTTP POST request.
>=20
> This allows web developers to add a new layer of security to their applic=
ations, and if correctly
> implemented will render man in the middle attacks useless. The direct ben=
efit of implementing this
> extension is that web developers will be able to verify the POST payload =
signature, potentially
> avoiding obscure session management, and/or complicated login procedures.
>=20
> For example, Highly Secure Home Banking sites could be created by using E=
nigform + some simple
> server side code.
>=20
> For a demo of an Enigform-based login procedure, with using AJAX and FORM=
 SUBMIT, configure your
> GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar.
>=20
> Enigform: http://enigform.mozdev.org
> Latest Version: 0.6.5
>=20
> Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html
>=20
> Hope you like it!

--9amGYk9869ThD9tj
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.3 (GNU/Linux)

iQDVAwUBRe1qRK6pEulQFnIMAQIvqQX9HkflhwbcVpbq1maV9Yf+Ec3xBK5q8bh1
26+0LJZcu0l02ue2G49odlKPfhIYlai4A79dikmcF35ef8nUBYwYnoO3pP5HVqAD
aUUIlC4Z8uLiXoiozg8coodH/kwqkn7gx4MbRayNljurkWcejdTRaRBNORRz5J/p
NgYLAMC2pIYjW3funDZ3Ub8Gu0Ssw913CWhOVtYuAW7d1tWPCMn33sF4+gdkSImn
px/FclwfD78vsPFOCfxcNSgloQRmSQUh
=LtlV
-----END PGP SIGNATURE-----

--9amGYk9869ThD9tj--



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26CspEc061037 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l26Csp5L061036; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.230]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l26Csoiv061029 for <ietf-openpgp@vpnc.org>; Tue, 6 Mar 2007 05:54:51 -0700 (MST) (envelope-from buanzo@buanzo.com.ar)
Received: by wx-out-0506.google.com with SMTP id i31so1937128wxd for <ietf-openpgp@vpnc.org>; Tue, 06 Mar 2007 04:54:50 -0800 (PST)
Received: by 10.70.131.19 with SMTP id e19mr7986508wxd.1173185689787; Tue, 06 Mar 2007 04:54:49 -0800 (PST)
Received: from ?10.10.0.2? ( [200.89.180.209]) by mx.google.com with ESMTP id i20sm10249934wxd.2007.03.06.04.54.48; Tue, 06 Mar 2007 04:54:49 -0800 (PST)
Message-ID: <45ED6495.1040407@buanzo.com.ar>
Date: Tue, 06 Mar 2007 09:54:45 -0300
From: "Arturo 'Buanzo' Busleiman" <buanzo@buanzo.com.ar>
Organization: GNU/Buanzo
User-Agent: Thunderbird 1.5.0.9 (X11/20061206)
MIME-Version: 1.0
To: ietf-openpgp@vpnc.org
Subject: OpenPGP Signing of HTTP POST
X-Enigmail-Version: 0.94.2.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear OpenPGP WG team,

	One day at 3am in the morning I woke up with a mix of two strings in my head: "POST / HTTP/1.1" and
"-----BEGIN PGP SIGNED MESSAGE-----". I woke up my wife, told her about the whole idea, and as I
couldn't go back to sleep, I got up and wrote it down. A couple of months later, and some BIG
thinking, I decided to create a Firefox Extension to implement what I am now going to describe, and
what I want to rewrite into a proper Draft:

For years different methods for User Authentication and Session Management have been implemented:

    * HTTP Authentication
    * Cookies
    * GET/POST values
    * SSL with client certificates
    * A combination of all the above.

Regarding SMTP, e-mail has been digitally signed for a long time now, and it is a standard.
Extending its usage to the HTTP protocol sounded like a natural idea, specially at 3am when I woke
up with a OpenPGP-signed HTTP POST request in my head.

By having the POST payload ("variable=test") signed using an ASCII armored, Clearsign, OpenPGP based
procedure, the browsing user can provide Identity Authentication to that payload, thus adding all
OpenPGP benefits to the HTTP POST request.

This allows web developers to add a new layer of security to their applications, and if correctly
implemented will render man in the middle attacks useless. The direct benefit of implementing this
extension is that web developers will be able to verify the POST payload signature, potentially
avoiding obscure session management, and/or complicated login procedures.

For example, Highly Secure Home Banking sites could be created by using Enigform + some simple
server side code.

For a demo of an Enigform-based login procedure, with using AJAX and FORM SUBMIT, configure your
GnuPG, Install Enigform, then go to: http://enigformdemo.buanzo.com.ar.

Enigform: http://enigform.mozdev.org
Latest Version: 0.6.5

Work-in-progress draft: http://www.buanzo.com.ar/sec/enigform.en.html

Hope you like it!

- --
Arturo "Buanzo" Busleiman - Consultor Independiente en Seguridad Informatica
Mail Hosting Seguro y Consultoria - http://www.buanzo.com.ar/pro/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFF7WSVAlpOsGhXcE0RAt88AJ0cyBuMS/U0qZjwTZ9DrnE1jxRmUwCfdYqN
+GAVdVxL/NfUvvvdA0RJolc=
=m/4G
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207NQl079627 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l2207NgS079626; Thu, 1 Mar 2007 17:07:23 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from merrymeet.com (dsl093-068-160.sfo1.dsl.speakeasy.net [66.93.68.160]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l2207M4s079619 for <ietf-openpgp@imc.org>; Thu, 1 Mar 2007 17:07:22 -0700 (MST) (envelope-from jon@callas.org)
Received: from keys.merrymeet.com (dsl093-068-161.sfo1.dsl.speakeasy.net [66.93.68.161]) (Authenticated sender: jon) by merrymeet.com (Postfix) with ESMTP id 406F056F7CB for <ietf-openpgp@imc.org>; Thu,  1 Mar 2007 16:07:22 -0800 (PST)
Received: from [10.240.72.119] ([208.54.15.1]) by keys.merrymeet.com (PGP Universal service); Thu, 01 Mar 2007 16:07:22 -0800
X-PGP-Universal: processed; by keys.merrymeet.com on Thu, 01 Mar 2007 16:07:22 -0800
In-Reply-To: <20070301180833.GA22614@jabberwocky.com>
References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org> <20070301180833.GA22614@jabberwocky.com>
Mime-Version: 1.0 (Apple Message framework v752.3)
Message-Id: <96F3CC13-7B61-41DB-BE4D-78B33A4D2D3B@callas.org>
Cc: OpenPGP <ietf-openpgp@imc.org>
From: Jon Callas <jon@callas.org>
Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt
Date: Thu, 1 Mar 2007 16:07:18 -0800
To: David Shaw <dshaw@jabberwocky.com>
X-Mailer: Apple Mail (2.752.3)
X-PGP-Encoding-Version: 2.0.2
X-Content-PGP-Universal-Saved-Content-Transfer-Encoding: 7bit
X-Content-PGP-Universal-Saved-Content-Type: text/plain; charset=US-ASCII; format=flowed
Content-Type: text/plain; charset="US-ASCII"
Content-Transfer-Encoding: 7BIT
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

>
> This looks really good.  I have a few minor comments about the
> additions.  This might look like a lot, but I think there was a cut
> and paste error that explains some of them.
>

Yeah.

They're all fixed. I'm submitting the resulting bis-20.

	Jon


-----BEGIN PGP SIGNATURE-----
Version: PGP Universal 2.5.3
Charset: US-ASCII

wj8DBQFF52q6sTedWZOD3gYRAoANAKC2aYeLwv6Il4tc5z/jO9CdCI7HIwCgs4fv
n+ca/0oqgnlUfhSVbkaTnmw=
=pkVx
-----END PGP SIGNATURE-----



Received: from balder-227.proper.com (localhost [127.0.0.1]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8x1t054493 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
Received: (from majordom@localhost) by balder-227.proper.com (8.13.5/8.13.5/Submit) id l21I8x2b054492; Thu, 1 Mar 2007 11:08:59 -0700 (MST) (envelope-from owner-ietf-openpgp@mail.imc.org)
X-Authentication-Warning: balder-227.proper.com: majordom set sender to owner-ietf-openpgp@mail.imc.org using -f
Received: from foobar.cs.jhu.edu (foobar.cs.jhu.edu [128.220.13.173]) by balder-227.proper.com (8.13.5/8.13.5) with ESMTP id l21I8vZA054485 for <ietf-openpgp@imc.org>; Thu, 1 Mar 2007 11:08:58 -0700 (MST) (envelope-from dshaw@jabberwocky.com)
Received: from walrus.jabberwocky.com (c-75-67-134-56.hsd1.ma.comcast.net [75.67.134.56]) by foobar.cs.jhu.edu (8.11.6/8.11.6) with ESMTP id l21I8hZ00380; Thu, 1 Mar 2007 13:08:43 -0500
Received: from grover.jabberwocky.com (grover.jabberwocky.com [172.24.84.28]) by walrus.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8cqo015067 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Thu, 1 Mar 2007 13:08:38 -0500
Received: from grover.jabberwocky.com (localhost.localdomain [127.0.0.1]) by grover.jabberwocky.com (8.13.8/8.13.8) with ESMTP id l21I8a6K022649; Thu, 1 Mar 2007 13:08:36 -0500
Received: (from dshaw@localhost) by grover.jabberwocky.com (8.13.8/8.13.8/Submit) id l21I8XxU022648; Thu, 1 Mar 2007 13:08:33 -0500
Date: Thu, 1 Mar 2007 13:08:33 -0500
From: David Shaw <dshaw@jabberwocky.com>
To: OpenPGP <ietf-openpgp@imc.org>
Cc: jon@callas.org
Subject: Re: draft-ietf-openpgp-rfc2440bis-19.txt
Message-ID: <20070301180833.GA22614@jabberwocky.com>
Mail-Followup-To: OpenPGP <ietf-openpgp@imc.org>, jon@callas.org
References: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <82532482-8BAC-47BC-B83E-E6654732B1FC@callas.org>
OpenPGP: id=99242560; url=http://www.jabberwocky.com/david/keys.asc
User-Agent: Mutt/1.5.13 (2006-11-21)
Sender: owner-ietf-openpgp@mail.imc.org
Precedence: bulk
List-Archive: <http://www.imc.org/ietf-openpgp/mail-archive/>
List-Unsubscribe: <mailto:ietf-openpgp-request@imc.org?body=unsubscribe>
List-ID: <ietf-openpgp.imc.org>

On Mon, Feb 26, 2007 at 09:21:17PM -0800, Jon Callas wrote:
> 
> I've submitted bis19. This should be within epsilon of complete for a  
> whole lot of epsilons. It has in it text to address the IESG  
> concerns, as well as the IANA considerations in a brand new section  
> 10. The *only* thing that there should be comments on is the IANA  
> considerations.

This looks really good.  I have a few minor comments about the
additions.  This might look like a lot, but I think there was a cut
and paste error that explains some of them.

*********************
In section 5.13, in the non-normative explanation of MDC:

The sentence "(Note also that CBC mode has similar limitation, but
data removed from the front of the block is undetectable.)" needs an
"a" between "has" and "similar".

The sentence "Suffice it to say that many people consider properties
such as deniability are considered to be as valuable as integrity."
is a little tangled, language wise.  I suggest removing the words "are
considered".

"OpenPGP addresses this desire to have more security than raw
encryption, and yet preserving deniability with the MDC system." is
also a bit tangled.  I suggest changing "preserving" to "preserve" and
adding a comma after "deniability".

*********************

Section 10.2.2.1 (Signature Notation Data Subpackets) says "Adding a
new signature Signature Notation Data ..."  The first "signature"
should be removed.

*********************

Section 10.2.2.2 (Key Server Preference Extensions) says "OpenPGP
signatures contain a mechanism for preferences to be specified about
key server preferences."  That's one "preferences" too many.

*********************

Section 10.2.2.3 is titled "Key Flags Preference Extensions".  I
suggest removing the word "Preference" as key flags aren't really
preferences, and the rest of that section (correctly, I'd say) doesn't
call them preferences either.

*********************

Section 10.2.2.4 (Reason For Revocation Extensions) seems to have a
few cut and paste problems and is co-mingled with the section after
it.

It refers to "the feature flags value".  This should be "the
reason-for-revocation flags value".

In the same section it says "Adding a new feature flag...".  That
should be "Adding a new reason-for-revocation flag..."

The reference to section 5.2.3.24 should be 5.2.3.23.

Finally, the sentence "Also see section 10.6 for more information
about when feature flags are needed." actually belongs to section
10.2.2.5 (Implementation Features).

*********************

Section 10.2.2.5. (Implementation Features) has a mirror image of the
problems with 10.2.2.4.

It refers to "the reason flags value".  That should probably be "the
feature-implementation flags value".

In the same section it says "Adding a new reason for revocation
flag...".  That should be "Adding a new feature-implementation
flag..."

The reference to section 5.2.3.23 in this section should be section
5.2.3.24.

The sentence "Also see section 10.6 for more information about when
feature flags are needed." from section 10.2.2.4 actually belongs
here.

*********************

David


