GPG 1.04
========

$ gpg --symmetric --cipher-algo 3DES TT
gpg: Avertissement: l'utilisation de la mémoire n'est pas sûre !
Entrez le mot de passe: 1
Répétez le mot de passe: 1

There is no control on the key length when people enter a password in gpg.
They can enter only four character and even only one.
It's easier to test the software or good for the specialist who knows
crypto but it's not for end users.
May I suggest  you to add some robust control on the pass phrase (12 characters
long with a mix of uppercase, lower case, numeric and punct will be a minimum).


OPENSSL 0.9.6
=============

$ openssl des3 -in TT -out TT.3des
enter des-ede3-cbc encryption password: 1
Verifying password - enter des-ede3-cbc encryption password: 1

The same problem exist with openssl.

Thank's in advance.

Best regards.



-- 
Christian PELISSIER, ONERA GMT/DRIS , BP 72 92322 Chatillon France
Tel:   33 1 46 73 44 19                    Fax:   33 1 46 73 41 62
http://www.onera.fr                             ftp://ftp.onera.fr

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to