Re: [Evolution] GPG Signature verification does not account for multiple UID's



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

I've created a bug report, any input is welcome.

https://bugzilla.gnome.org/show_bug.cgi?id=792610

Gijs

On Wed, 2018-01-17 at 02:44 +0100, Ángel wrote:
On 2018-01-15 at 10:44 +0100, Gijs Peskens wrote:
I have a GPG key containing multiple UID's for a few of my mail
adresses. 
In sending some test mails from the various accounts I notice that
Evolution seems to only regard the first UID for signature
verification
purposes, it seems that the mail is correctly signed as checking
with
another mail client (Thunderbird+Enigmail) does result in a
correctly
verified signature. 
Is this working as designed?

Gijs Peskens

No, it should take all the ids into account. I am seeing two things
here
(although I haven't tested with the latest version):

The first one is that evolution is not taking into account the value
of
the from: header (I made a copy of your email changing it to
"spoofer example com", and the GPG signature is shown the same).

The second one is that the bar states who signed it, but only shows
the
first UID (you can view the full GPG output, where all of them are
listed, clicking on the button).



I'm unsure how to treat it. On the one hand, it *is* showing you who
signed the message, and that should be enough data if properly taken
into account by the user. On the other hand, it seems wrong to ignore
such mismatch (even though it's not so uncommon that in the field
emailsl end up encrypted with the wrong key, mailing lists change the
From:, etc).

The second issue actually depends on the expected behavior regarding
the
first.

I looked at the available documentation for the feature, but it would
need some love:
https://help.gnome.org/users/evolution/stable/mail-encryption-gpg-dec
rypting.html.en


Regards

PS: you should revoke your 2014 key, that I assume you have replaced
with this one.

_______________________________________________
evolution-list mailing list
evolution-list gnome org
To change your list options or unsubscribe, visit ...
https://mail.gnome.org/mailman/listinfo/evolution-list
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEE39aOQY4w2je+JdDQi2ZEc9DzrPMFAlpfcesACgkQi2ZEc9Dz
rPPulw//Vl/bKcx9QjhORRzm7xTNIgMXumYT1O/fr/fDA/q9t1rc+W27Nl4VIfGk
kwqm/TV1Vg38cy16yVDYG9C03OGZfAk6YJHHuyP1vvs1IprKDsH+Z1sA69/HpWJW
BDlzXkVVKnxeuI9FBZ8cA0cTuaFWw+puswzf67CTOXPPXbIJdUkbl3QlFD03+xca
3BtnfuErHiHDG+cNk9GI/Os/k/JjAn3ba9Hj/5QJB++zs6rFktbj1B2HUyrnxqxP
BaHv3SvgCWviNNO1WmQFDK/lu4PDYHQju5NaDMCLXhLnRlj6RszXbzO9QxWI/sKI
mr9X+BjhdYTH3EGLxfHSEJZ4F3D3kzRlYmUgsfHrjrh+aXFwxOTipWZRPluaeC88
ztxOQ6SDTOl5aZycHkF7UofBlfPHRbE2nTD0Hvss+lCcLT6p6MTGXngLfjp+XZ46
pcWqpVkaDYZDynhpyBh7TuQu12L/pZyiSJPQiLcLS8N4Ltk9TH37NJ8VAXMB0Om5
ChZGmmh++xUIGN0G8wK9H2dFMqvsjr4Q27E170ba/im9IRHxDG1/e5H8itZ75zQo
fiVqlX7ENsOjPoXi4X4No1tJ57C5368Q+rZrs8dxf5ccaXAZ6oghcQ8EOjjWe8F5
IC4PbyebAjz/uv6UOkC6urPlWs/r+ncw3bRbT1gcGnDtvmj2x+E=
=a9ru
-----END PGP SIGNATURE-----



[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]