close
Comments you submit will be routed for moderation. If you have an account, please log in first.
Modify

Opened 4 years ago

Closed 21 months ago

#5 closed bug (fixed)

YAM fail to check signed e-mails from User-Agent: IceDove

Reported by: amigasurfer@… Owned by: somebody
Priority: normal Milestone: YAM 2.8
Component: PGP/GPG encryption Version: 2.5
Severity: major Keywords: SF
Cc: OS Platform:
Blocked By: Blocking:
Release Notes:

Description (last modified by damato)

If I try to check the signatur of an e-mail mit quoted printable and the signatur inside the textbody, e.g. generated with User-Agent: IceDove 1.5.0.14pre (X11/20071018), YAM allways says invalid signatur.

The problem is, YAM gives the file directly to PGP without converting the quoted printable back first.

Attached you will find an example e-mail.

If I copy this e-mail and convert all quoted printable by hand and doesn't makes a mistake in doing this, then PGP does check the signatur good.

PS: The required pgp-key 0x16AC66D9 can be found at the common keyservers. Same for my key needed for the other bugreport.


Moved from SF:
https://sourceforge.net/tracker/?func=detail&aid=1879345&group_id=13560&atid=113560

Attachments (1)

OIt++AAGW6Q=.001,RA (4.8 KB) - added by damato 4 years ago.
signed e-mail with quoted printable and the sig inside the textbody - Moved from SF. Original author: amigasurfer

Download all attachments as: .zip

Change History (10)

comment:1 Changed 4 years ago by damato

  • Description modified (diff)

Changed 4 years ago by damato

signed e-mail with quoted printable and the sig inside the textbody - Moved from SF. Original author: amigasurfer

comment:2 Changed 4 years ago by damato

For me PGP also fails if I pass it the decoded message part from T:.

I think the mail itself is broken. It contains the usual "-----BEGIN PGP
SIGNED MESSAGE-----" line, but no "-----END PGP SIGNED MESSAGE-----". The
signature seems to be complete.

If I strip everything but the signature PGP tells me that a newer version
is needed to check this signature. I used PGP 2.6.3i.


Moved from SF. Original poster: thboeckel

comment:3 Changed 4 years ago by damato

Yesterday I read somewhere that "-----END PGP SIGNED MESSAGE-----" isn't
explicit needed, if the signature seamless follows the signed text with
"-----BEGIN PGP SIGNATURE-----". This line is then equal to "-----END PGP
SIGNED MESSAGE-----". But I read yesterday so many forums and google
results. I can't remember where I read this and can't find it again.

I'm astonished that you could add the public key 0x16AC66D9 to your
keyring with PGP 2.6.3i. The key is a DSS/Diffie-Hellman key. You need PGP
5.1 for this. PGP 2.6.3i can only handle RSA keys.


Moved from SF. Original poster: amigasurfer

comment:4 Changed 4 years ago by damato

  • Priority changed from major to undecided
  • Severity set to major

comment:5 Changed 4 years ago by damato

  • Component changed from nightly build to undefined

comment:6 Changed 4 years ago by damato

  • Cc yamos-svn@… removed

comment:7 Changed 4 years ago by damato

  • Component changed from undefined to PGP/GPG encryption
  • Milestone set to YAM 2.7
  • Priority changed from undecided to normal
  • Status changed from new to accepted

comment:8 Changed 3 years ago by damato

  • Description modified (diff)
  • Milestone changed from YAM 2.7 to YAM 2.8

comment:9 Changed 21 months ago by tboeckel

  • Resolution set to fixed
  • Status changed from accepted to closed

This should finally be fixed by the next nightly build (see r6350 to r6359).

Add Comment

Modify Ticket

Action
as closed .
The resolution will be deleted. Next status will be 'reopened'.
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.

This list contains all users that will be notified about changes made to this ticket.

These roles will be notified: Reporter, Owner, Subscriber

  • amigasurfer@…(Reporter)