[Gpg4win-users-en] Compatibility issue PGP / GPG

Bernhard Reiter bernhard at intevation.de
Mon Jun 18 09:02:29 CEST 2018


Dear Roberto,

Am Freitag 15 Juni 2018 18:29:58 schrieb Roberto Carna:
> Dear, generally when I encrypt files with GPGWin last version to
> recipients  with PGP public keys, they tell me they cannot decrypt the
> files.

in general GnuPG (the crypto engine of Gpg4win) is very compatible,
it also has many expert options.

So citing https://www.gnupg.org/faq/gnupg-faq.html#compatible
" Is it compatible with Symantec’s PGP?

Largely, yes. It can be made to interoperate with anything from PGP 5 and 
onwards, and has excellent interoperability with the most recent releases.
"

> For example, today I had a problem because one client uses PGP 6.5.8
> and he could not decrypt the file at all.

Gathering from a search engine, PGP 6.5.8 is from around year 2000,
which makes it 18 years old, you may need special and unsafe options
to be able to encrypt to it. "Modern" OpenPGP implementations will
use an integrity protection for encrypted contents (since 15 years)
a recent vulnerability in S/MIME shows that this integrity protection is 
really needed, see

https://nvd.nist.gov/vuln/detail/CVE-2017-17688
https://nvd.nist.gov/vuln/detail/CVE-2017-17689

> Is is true ?

I guess that the very old PGP 6.5.8 may not be able to cope with OpenPGP 
encryption like it is used for the last 15 years, which would explain the 
problems.

> What is the best way to use a universal GPG client in 
> order to encrypt/decrypt all PGP/GPG keys withouy any problem?

To my best knowledge GnuPG is very flexible, so I can recommend it
(Just so you know: I am with the GnuPG and Gpg4win teams for many years).
You'll find other Free Software implementations in an unsorted list at
  https://wiki.gnupg.org/OtherFreeSoftwareOpenPGP

My suggestion for your clients is to upgrade to a maintained version
of an OpenPGP implementation, because there have been a number of security 
issues in the last 18 years.

Best Regards,
Bernhard


-- 
www.intevation.de/~bernhard   +49 541 33 508 3-3
Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.wald.intevation.org/pipermail/gpg4win-users-en/attachments/20180618/65a2478f/attachment.asc>


More information about the Gpg4win-users-en mailing list