From: Xandy Johnson Date: 2002-11-07T20:07:31+09:00 Subject: Re: PGP signatures I can empathize with the frustration of dealing with PGP/MIME messages in a mail client that doesn't understand them; that frustration drove me to switch mail clients a couple months ago. (For the statistics gatherers, I'm now using Evolution , which sends signed or encrypted messages using PGP/MIME.) However, I believe the response to that frustration (if any) should be directed to the email client vendors/authors. The RFCs relating to this are 6 and 7 years old. Please refer to RFC 1847 "Security Multiparts for MIME: Multipart/Signed and Multipart/Encrypted" , RFC 1991 "PGP Message Exchange Formats" , and RFC 2015 "MIME Security with Pretty Good Privacy (PGP)" . Admittedly, there have been updates, such as RFC 3156 . Granted, it's probably easier to get an individual on the list to change his or her practices than to get an email client vendor to change its product, but in my opinion, the individual is doing something reasonable, and the vendor is not. Getting the vendor to change (or changing mail clients) is also more reliable. Like others have mentioned in this thread, I sign my messages as a standard practice. I'll try to refrain from doing so on this list, but I'll probably forget sometimes. Also, as the community grows, this issue will come up repeatedly, sparking threads of various lengths each time. Who knows; maybe the vendor is already considering it, and a cordial suggestion might sway them to raise the priority. I'll endeavor to abide by whatever the community decides, but I'd prefer to see the list policy be silent regarding PGP/GPG signatures. That is, "Sign your messages or don't, we don't really care as long as you're 'talking' about Ruby." Xandy