DISQUS

ZeNiTHaR'z BLoG: gpgAuth - GnuPG Web Authentication

  • Christian Henz · 2 years ago
    It seems that gpgAuth development was abandoned in favor of Enigform? And last time I checked, Enigform was still insecure (open to replay attacks), so there might not be much sense in supporting it.

    Personally I'd like to see more support for TLS/OpenPGP.
  • Zenithar · 2 years ago
    And what about mod_openpgp, which the apache server module to support HTTP Signed protocol ?
  • Kyle L. Huff · 1 year ago
    gpgAuth auth has not been abandoned. The end goal is to work with the authors of Enigform/m_a_o to implement gpgAuth at the server level.. gpgAuth is a mechanism, not a product. It is a process to authenticate users to servers and server to users. gpgAuth is fully supported in the FireGPG firefox extension.

    Kyle L. Huff
    http://www.gpgauth.com
  • Buanzo · 1 year ago
    Regarding the replay attacks, I'm VERY aware of that, that's why I just finished implementing SESSION support for Enigform / mod_openpgp.

    Feel free to check out http://maotest.buanzo.org, and you're more than welcome to join me at the official forum:

    http://foros.buanzo.com.ar/viewforum.php?f=35