[Bug 128784] RIPEMD160 hash signed messages send incorrect header with OpenPGP/MIME

Julian Mehnle julian at mehnle.net
Thu Jul 2 22:47:58 BST 2009


https://bugs.kde.org/show_bug.cgi?id=128784





--- Comment #7 from Julian Mehnle <julian mehnle net>  2009-07-02 23:47:56 ---
I can confirm that KMail inappropriately generates "micalg=pgp-sha1" even when
actually using a different digest algorithm to sign the message (here: SHA-512
or SHA-256).

Given that by now, SHA-1 has been seriously compromised, using SHA-1 simply
isn't an acceptable alternative anymore.  What will it take to get this fixed
in KMail?

-- 
Configure bugmail: https://bugs.kde.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the Kdepim-bugs mailing list