1
0
mirror of git://git.gnupg.org/gnupg.git synced 2025-01-10 13:04:23 +01:00
Damien Goutte-Gattat via Gnupg-devel 72e3fddbfe
gpg: Force the use of AES-256 in some cases
* g10/encrypt.c (create_dek_with_warnings): Forcefully use AES-256 if
PQC encryption was required or if all recipient keys are Kyber keys.
--

If --require-pqc-encryption was set, then it should be safe to always
force AES-256, without even checking if we are encrypting to Kyber keys
(if some recipients do not have Kyber keys, --require-pqc-encryption
will fail elsewhere).

Otherwise, we force AES-256 if we encrypt *only* to Kyber keys -- unless
the user explicitly requested another algo, in which case we assume they
know what they are doing.

GnuPG-bug-id: 7472
Signed-off-by: Damien Goutte-Gattat <dgouttegattat@incenp.org>

Man page entry extended

Signed-off-by: Werner Koch <wk@gnupg.org>
2025-01-06 18:17:07 +01:00
..
2024-05-31 12:28:32 +02:00
2014-12-14 12:15:21 +01:00
sm/
2006-11-14 10:23:21 +00:00
2016-09-20 09:32:25 +09:00
DCO
2013-04-17 11:26:27 +02:00
2023-10-05 14:00:46 +09:00
2024-05-31 12:28:32 +02:00
2003-01-09 13:24:01 +00:00
2016-09-20 09:56:22 +09:00
2007-07-04 19:49:40 +00:00
2007-03-08 18:31:56 +00:00
2014-07-03 11:03:22 +02:00
2024-05-31 12:28:32 +02:00
2024-05-31 12:28:32 +02:00
2024-05-31 12:28:32 +02:00
2023-12-01 15:23:49 +09:00
2024-05-31 12:28:32 +02:00
2007-05-08 13:59:41 +00:00
2024-04-11 08:27:53 +02:00
2006-08-21 20:20:23 +00:00
2020-02-18 18:07:46 -05:00
2012-11-30 12:47:49 -05:00
2023-10-05 14:00:46 +09:00
2011-08-12 14:40:47 +02:00
2017-02-21 13:11:46 -05:00
2006-12-06 16:38:34 +00:00
2020-02-18 18:07:46 -05:00
2024-03-12 16:00:55 +01:00