close
Comments you submit will be routed for moderation. If you have an account, please log in first.
Modify

Opened 5 years ago

Closed 2 years ago

#5 closed bug (fixed)

YAM fail to check signed e-mails from User-Agent: IceDove

Reported by: amigasurfer@… Owned by: somebody
Priority: normal Milestone: YAM 2.8
Component: PGP/GPG encryption Version: 2.5
Severity: major Keywords: SF
Cc: OS Platform:
Blocked By: Blocking:
Release Notes:

Description (last modified by damato)

If I try to check the signatur of an e-mail mit quoted printable and the signatur inside the textbody, e.g. generated with User-Agent: IceDove 1.5.0.14pre (X11/20071018), YAM allways says invalid signatur.

The problem is, YAM gives the file directly to PGP without converting the quoted printable back first.

Attached you will find an example e-mail.

If I copy this e-mail and convert all quoted printable by hand and doesn't makes a mistake in doing this, then PGP does check the signatur good.

PS: The required pgp-key 0x16AC66D9 can be found at the common keyservers. Same for my key needed for the other bugreport.


Moved from SF:
https://sourceforge.net/tracker/?func=detail&aid=1879345&group_id=13560&atid=113560

Attachments (1)

OIt++AAGW6Q=.001,RA (4.8 KB) - added by damato 5 years ago.
signed e-mail with quoted printable and the sig inside the textbody - Moved from SF. Original author: amigasurfer

Download all attachments as: .zip

Change History (10)

comment:1 Changed 5 years ago by damato

  • Description modified (diff)

Changed 5 years ago by damato

signed e-mail with quoted printable and the sig inside the textbody - Moved from SF. Original author: amigasurfer

comment:2 Changed 5 years ago by damato

For me PGP also fails if I pass it the decoded message part from T:.

I think the mail itself is broken. It contains the usual "-----BEGIN PGP
SIGNED MESSAGE-----" line, but no "-----END PGP SIGNED MESSAGE-----". The
signature seems to be complete.

If I strip everything but the signature PGP tells me that a newer version
is needed to check this signature. I used PGP 2.6.3i.


Moved from SF. Original poster: thboeckel

comment:3 Changed 5 years ago by damato

Yesterday I read somewhere that "-----END PGP SIGNED MESSAGE-----" isn't
explicit needed, if the signature seamless follows the signed text with
"-----BEGIN PGP SIGNATURE-----". This line is then equal to "-----END PGP
SIGNED MESSAGE-----". But I read yesterday so many forums and google
results. I can't remember where I read this and can't find it again.

I'm astonished that you could add the public key 0x16AC66D9 to your
keyring with PGP 2.6.3i. The key is a DSS/Diffie-Hellman key. You need PGP
5.1 for this. PGP 2.6.3i can only handle RSA keys.


Moved from SF. Original poster: amigasurfer

comment:4 Changed 5 years ago by damato

  • Priority changed from major to undecided
  • Severity set to major

comment:5 Changed 5 years ago by damato

  • Component changed from nightly build to undefined

comment:6 Changed 5 years ago by damato

  • Cc yamos-svn@… removed

comment:7 Changed 5 years ago by damato

  • Component changed from undefined to PGP/GPG encryption
  • Milestone set to YAM 2.7
  • Priority changed from undecided to normal
  • Status changed from new to accepted

comment:8 Changed 3 years ago by damato

  • Description modified (diff)
  • Milestone changed from YAM 2.7 to YAM 2.8

comment:9 Changed 2 years ago by tboeckel

  • Resolution set to fixed
  • Status changed from accepted to closed

This should finally be fixed by the next nightly build (see r6350 to r6359).

Add Comment

Modify Ticket

Action
as closed The owner will remain somebody.
The resolution will be deleted. Next status will be 'reopened'.
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.

This list contains all users that will be notified about changes made to this ticket.

These roles will be notified: Reporter, Owner, Subscriber

  • amigasurfer@…(Reporter)