One of the first feature requests was to not use GPG, but use PKI instead. One potential for this is to use PKCS#7 as it supports detached signatures. That being said, I haven't found an easy to use tool chain for generating these detached signatures. That being said, I'm really not chuffed on the idea of doing clearsign or encoded inline signatures along with the payload.
One of the first feature requests was to not use GPG, but use PKI instead. One potential for this is to use PKCS#7 as it supports detached signatures. That being said, I haven't found an easy to use tool chain for generating these detached signatures. That being said, I'm really not chuffed on the idea of doing clearsign or encoded inline signatures along with the payload.