Which two actions can the recipient of a PGP email message perform to enable trust to be established between the sender and receiver?
PGP hybrid encryption encrypts the message with a symmetric session key and protects that session key with the recipient’s public-key encryption key. The recipient decrypts the symmetric session key using their private key, then uses the recovered symmetric key to decrypt the message. Sender authentication additionally depends on verification of a valid digital signature with the sender’s public key.
Community Discussion