1
0
mirror of git://git.gnupg.org/gnupg.git synced 2025-01-09 12:54:23 +01:00
Damien Goutte-Gattat via Gnupg-devel 72e3fddbfe
gpg: Force the use of AES-256 in some cases
* g10/encrypt.c (create_dek_with_warnings): Forcefully use AES-256 if
PQC encryption was required or if all recipient keys are Kyber keys.
--

If --require-pqc-encryption was set, then it should be safe to always
force AES-256, without even checking if we are encrypting to Kyber keys
(if some recipients do not have Kyber keys, --require-pqc-encryption
will fail elsewhere).

Otherwise, we force AES-256 if we encrypt *only* to Kyber keys -- unless
the user explicitly requested another algo, in which case we assume they
know what they are doing.

GnuPG-bug-id: 7472
Signed-off-by: Damien Goutte-Gattat <dgouttegattat@incenp.org>

Man page entry extended

Signed-off-by: Werner Koch <wk@gnupg.org>
2025-01-06 18:17:07 +01:00
..
2024-09-11 13:51:16 +09:00
2024-08-09 09:31:54 +02:00
2023-06-20 09:08:29 +09:00
2024-08-08 17:31:26 +02:00
2020-11-11 09:13:13 +09:00
2021-11-13 21:03:02 +01:00
2022-11-09 10:37:58 +09:00
2022-11-09 10:37:58 +09:00
2015-02-04 09:15:34 +01:00
2017-03-07 20:25:54 +09:00
2017-03-07 20:25:54 +09:00
2024-05-31 12:28:32 +02:00
2024-12-04 11:04:41 +01:00
2024-08-09 09:31:54 +02:00
2024-04-15 13:25:07 +02:00
2020-02-18 18:07:46 -05:00
2019-07-11 12:32:44 +09:00
2024-08-23 11:28:30 +02:00
2019-07-23 12:04:21 +09:00
2017-01-23 19:16:55 +01:00
2017-03-07 20:32:09 +09:00
2024-05-31 12:28:32 +02:00
2024-05-31 12:28:32 +02:00
2016-03-08 14:08:49 +01:00
2024-03-12 16:00:55 +01:00
2024-02-10 14:26:55 +01:00
2016-12-06 12:16:56 +01:00
2023-02-16 18:10:03 +01:00
2024-03-12 16:00:55 +01:00