Signing a blank message

Forum for misc bugs and other questions. If it doesn't seem to work properly or if you have any questions, post them here. Do not post questions regarding nightly builds here.

Signing a blank message

Postby ilurista » 9th Oct 2009 20:53

Hi @ all,

I am new here in the forum, my english is not the best cause I´m from germany, but I hope you can understand it. :)
Like in the subject mentioned I tested to sign a blank message and send it to my own mail address.
The mail arrives but it isn´t signed why?
Isn´t it possible to send a signed blank mail to certify the senders address only?

Thanks for all answers!

Have a nice day, ilurista
ilurista
New user
New user
 
Posts: 1
Joined: 9th Oct 2009 05:38

Re: Signing a blank message

Postby dan » 9th Oct 2009 23:22

Hi and welcome,

Your English is fine. :wink:

When you send a blank email it will not be signed, even if you ask Enigmail to do so, because signing applies to the email payload only, therefore in a blank email there's nothing to sign. All email headers e.g. the Subject, Date, all Received headers, the "name" part of the From, etc. are not included in the signature and could therefore be forged. (This is obvious when you think that the headers are added to the message by the email client after the Enigmail processing; some headers are even added by MTAs in the path from sender to receiver.)

The sender's email address is mentioned in the user ID of the public key, so it's strictly bound to the key that was used to sign the message.
This does not suffice to "certify" the sender, though: when you receive a new public key you should check that it was really given to you by the intended owner. You can do that by checking the key fingerprint with the owner.
User avatar
dan
Experienced user
Experienced user
 
Posts: 104
Joined: 3rd Sep 2008 13:25
Location: Geneva, Switzerland


Return to General Discussions