[Gpg4win-devel] Putty and ECDSA support for gpg-agent in 2.0

Werner Koch wk at gnupg.org
Fri Jul 5 14:12:48 CEST 2013


On Fri,  5 Jul 2013 12:06, bernhard at intevation.de said:

> So the question is: How do we advertise this functionality, so that people 
> will try it? Could we come up with a question at first start in case putty is 
> installed or something like this? 

No.

Frankly, the use of public key authentication with ssh is still the
exception.  Most people I asked didn't known how to use public key
authentication with ssh.  Even server admins often don't know the
"PermitRootLogin without-password" clause of sshd and still allow
password authentication to root (or in a false sense of security via a
separate user and su).  Sending passwords over an encrypted ssh channel
is in general not a good idea.

It is not the duty of the Gpg4win installer to educate users on
(advanced) use of ssh.  This better done by a separate document.

And while we are at it: The need to click on the checkbox for the root
certificate readme in the installer is quite annoying.  May I remove
that checkbox?


Salam-Shalom,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.



More information about the Gpg4win-devel mailing list