Opened 11 years ago

#222 new enhancement

Warn on weak zcrypt keys

Reported by: adehnert@mit.edu Owned by:
Priority: major Milestone:
Component: zephyr Keywords:
Cc:

Description

Given the difficulties in #221 and a recently-discovered weak key, I suspect there are a bunch of weak zcrypt keys. We should supply something to help detect and fix weak zcrypt keys. Some possibilities:

  • Warn when you send and/or receive a zephyr encrypted with a weak key
  • On startup, parse ~/.crypt-table, read the referenced keys, and warn on any weak keys
  • Supply a script that parses ~/.crypt-table, reads the referenced keys, and warns on any weak keys

Change History (0)

Note: See TracTickets for help on using tickets.