pgpdump
Kazu Yamamoto
pgpdump is a PGP packet visualizer which displays the packet format of OpenPGP (RFC 9580 and RFC 4880), including the post-quantum algorithms of RFC 9980, and PGP version 2 (RFC 1991). It also displays the LibrePGP extensions generated by GnuPG (draft-koch-librepgp).
How does pgpdump work?
PGP produces binary files or files encoded with ASCII armor (which is identical to the MIME Base64 encoding). An example of ASCII armor file is as follows (say “sig.pgp”). This is the sample inline-signed message of RFC 9580 (Appendix A.7):
% cat sig.pgp
-----BEGIN PGP MESSAGE-----
xEYGAQobIHZJX1AhiJD39eLuPBgiUU9wUA9VHYblySHkBONKU/usyxhsTwYJppfk
1S36bHIrDB8eJ8GKVnCPZSXsJ7rZrMkBy0p1AAAAAABXaGF0IHdlIG5lZWQgZnJv
bSB0aGUgZ3JvY2VyeSBzdG9yZToKCi0gdG9mdQotIHZlZ2V0YWJsZXMKLSBub29k
bGVzCsKYBgEbCgAAACkFgmOYo2MiIQbLGGxPBgmml+TVLfpscisMHx4nwYpWcI9l
JewnutmsyQAAAABpNiB2SV9QIYiQ9/Xi7jwYIlFPcFAPVR2G5ckh5ATjSlP7rCfQ
b7gKqPxbyxbhljGygHQPnqau1eBzrQD5QVplPEDnemrnfmkrpx0GmhCfokxYz9jj
FtCgazStmsuOXF9SFQE=
-----END PGP MESSAGE-----
It’s very hard to understand the data structure inside this. Pgpdump visualizes this example as follows:
% pgpdump sig.pgp
New: One-Pass Signature Packet(tag 4)(70 bytes)
Latest version(6)
Sig type - Signature of a canonical text document(0x01).
Hash alg - SHA512(hash 10)
Pub alg - Ed25519(pub 27)
Salt - 76 49 5f 50 21 88 90 f7 f5 e2 ee 3c 18 22 51 4f 70 50 0f 55 1d 86 e5 c9 21 e4 04 e3 4a 53 fb ac
Fingerprint - cb 18 6c 4f 06 09 a6 97 e4 d5 2d fa 6c 72 2b 0c 1f 1e 27 c1 8a 56 70 8f 65 25 ec 27 ba d9 ac c9
Next packet - other than one pass signature
New: Literal Data Packet(tag 11)(74 bytes)
Packet data format - UTF-8 text
Filename -
Creation time - Thu Jan 1 09:00:00 JST 1970
Literal - ...
New: Signature Packet(tag 2)(152 bytes)
Ver 6 - latest
Sig type - Signature of a canonical text document(0x01).
Pub alg - Ed25519(pub 27)
Hash alg - SHA512(hash 10)
Hashed Sub: signature creation time(sub 2)(critical)(4 bytes)
Time - Wed Dec 14 01:08:03 JST 2022
Hashed Sub: issuer fingerprint(sub 33)(33 bytes)
v6 - Fingerprint - cb 18 6c 4f 06 09 a6 97 e4 d5 2d fa 6c 72 2b 0c 1f 1e 27 c1 8a 56 70 8f 65 25 ec 27 ba d9 ac c9
Hash left 2 bytes - 69 36
Salt - 76 49 5f 50 21 88 90 f7 f5 e2 ee 3c 18 22 51 4f 70 50 0f 55 1d 86 e5 c9 21 e4 04 e3 4a 53 fb ac
Ed25519 signature(64 bytes) - ...
Availability
- The first release of pgpdump was December 1998.
- The current version is 0.38 (25 Sep 2026). Download the source.
- Git repository is available on github.
History of PGP format
- The comprehensive book about PGP written by Simson Garfinkel (O’Reilly) says:
- “First Zimmermann wrote a paper describing standards and data structures for representing encryption keys, encrypted text, and signatures. The paper was eventually published in IEEE Computer”.
- I guess the following is the one:
- Philip Zimmermann, “A Proposed Standard Format for RSA Cryptosystems”, IEEE Computer 19(9), pp 21-34 (1986).
- The first description of the PGP 2 format was written in “doc/pgformat.doc”.
- RFC 1991, the PGP 2 format, was published in August 1996.
- RFC 2440, the OpenPGP format was published in November 1998.
- RFC 2440 has been revised by the RFC 4880 in November 2007.
- RFC 4880 has been revised by the RFC 9580 in July 2024.
- RFC 9980, post-quantum cryptography in OpenPGP, was published in June 2026.