How to find someone else?s public key ?

Answer Posted / ramkumar

Suppose Alice wants to find Bob's public key. There are
several possible ways of doing this. She could call him up
and ask him to send his public key via e-mail. She could
request it via e-mail, exchange it in person, as well as
many other ways. Since the public key is public knowledge,
there is no need to encrypt it while transferring it,
though one should verify the authenticity of a public key.
A mischievous third party could intercept the transmission,
replace Bob's key with his or her own and thereby be able
intercept and decrypt messages that are sent from Alice to
Bob and encrypted using the ``fake'' public key. For this
reason one should personally verify the key (for example,
this can be done by computing a hash of the key and
verifying it with Bob over the phone) or rely on certifying
authorities (see Question 4.1.3.12 for more information on
certifying authorities). Certifying authorities may provide
directory services; if Bob works for company Z, Alice could
look in the directory kept by Z's certifying authority.

Today, full-fledged directories are emerging, serving as on-
line white or yellow pages. Along with ITU-T X.509
standards (see Question 5.3.2), most directories contain
certificates as well as public keys; the presence of
certificates lower the directories' security needs.

Is This Answer Correct ?    0 Yes 0 No



Post New Answer       View All Answers


Please Help Members By Posting Answers For Below Questions

What is probabilistic encryption?

516


What is an algorithm?

1878


what is pretty good privacy?

1486


What are the ecb and cbc modes?

505


How Encoding is different from Encryption?

486






What are some other public key cryptosystems ?

1619


How to change the location of the Kryptel (Silver Key) program group?

1509


How to I prevent other users from using Kryptel (Silver Key)?

1542


What is multiple encryption?

486


Do encrypted files contain password in some form?

1694


How is an s-box value of AES can be modified? How is it done?

1391


What are knapsack cryptosystems?

504


What is merkles tree signature scheme?

494


What is are "proprietary" and "public" cryptographic algorithms?

1568


Do digital signatures help detect altered documents and transmission errors?

599