pgpenvelope-users Mailing List for pgpenvelope (Page 5)
Brought to you by:
ftobin
You can subscribe to this list here.
| 2000 |
Jan
(1) |
Feb
(22) |
Mar
(11) |
Apr
(9) |
May
(1) |
Jun
(9) |
Jul
(28) |
Aug
(9) |
Sep
(10) |
Oct
(26) |
Nov
|
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2001 |
Jan
(8) |
Feb
(2) |
Mar
|
Apr
(2) |
May
(6) |
Jun
|
Jul
(4) |
Aug
(8) |
Sep
(9) |
Oct
|
Nov
(2) |
Dec
(8) |
| 2002 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
(3) |
Oct
|
Nov
|
Dec
|
| 2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(2) |
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: L. S. <ra...@qu...> - 2000-08-22 21:21:26
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I've got an idea for pgpenvelope.
With pine's "roles" feature, one is able to set "on the fly" the
"From" address when replying to messages that match a regex.
It would be very useful for me if pgpenvelope could look at the
"From:" field, and determine the default signing key and default
encrypt-to key based on a "From:" match. I would, of course, want to be
required to explicitly define what keys are used when, but I think this
could be a beneficial feature.
- --Len.
__
L. Sassaman
Security Architect | "We all want many things,
Technology Consultant | but some of those are bottomly
| destructive of all desires."
http://sion.quickie.net | --Vernor Vinge
-----BEGIN PGP SIGNATURE-----
Comment: OpenPGP Encrypted Email Preferred.
iD8DBQE5ou7FPYrxsgmsCmoRAryBAKCfFxY0R5W6LsSKHtLjcIp0c8zs/ACfb4Bw
Tx8Iofwf1vM34rQ2XnabowI=
=w9iE
-----END PGP SIGNATURE-----
|
|
From: Frank T. <ft...@ui...> - 2000-08-03 15:19:15
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Some of you may not like using the procmail filter, haven't gotten around
to setting it up, etc, and don't like the delay of the display-filter when
viewing your message, because it pops up on every signed message.
One alternative way to use pgpenvelope is to first enable the unix
pipe-command in Pine's configuration:
[X] enable-unix-pipe-cmd
If you do this, you can then remove the pgpenvelope_decrypt
display-filter, and process signed messages using the pipe (|) command
selectively on messages you want to verify/decrypt. For the command to
pipe it to, you should enter "pgpenvelope_decrypt" if it is your $PATH, or
the complete path to it if not.
You don't want to change any of the 'default' subcommand options for the
pipe command when it prompts you for things like Raw Text.
- --
Frank Tobin http://www.uiuc.edu/~ftobin/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.2 (FreeBSD)
Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/
iEYEARECAAYFAjmJjWAACgkQVv/RCiYMT6OnUACgjbq/xtw6T/5Jnvtvp73Wz9J9
Y/gAnArhLDEdZNqm0spcyqmDLjmXv9Vj
=LSCp
-----END PGP SIGNATURE-----
|
|
From: Billy D. <bi...@da...> - 2000-08-02 15:02:55
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, 2 Aug 2000, Frank Tobin wrote: > Billy Donahue, at 12:26 -0400 on Tue, 1 Aug 2000, wrote: > > > The problem is killing it when pine dies. I guess pine > > would be the parent pid or something... > > Actually, it wouldn't be a problem; I'd simply have pgpenvelope call pine, > so it would wrapper around the pine session, exiting when pine exited. See, I hadn't thought of that... > BTW, hopefully you are using the procmail filter now; it certainly helps > on incoming mails :) Not yet.. (I know, I know). - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/ iD8DBQE5iDff+2VvpwIZdF0RAoR7AKCSMaecw4wPXauhoVEme9LLkjdu6QCfam4t R4Y2ScMBw/9HJ/Z/J/8WbJw= =dB95 -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-08-02 14:41:06
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Billy Donahue, at 12:26 -0400 on Tue, 1 Aug 2000, wrote: > I'm still thinking about the startup time of pgpenvelope. > It's all the perl compiling. It would be nice to have > a persistent perl process running 'hot' alongside pine, > The problem is killing it when pine dies. I guess pine > would be the parent pid or something... Actually, it wouldn't be a problem; I'd simply have pgpenvelope call pine, so it would wrapper around the pine session, exiting when pine exited. > So there would be this daemon running for you, and > there would be a short connector program which would be > the actual pine filter. Well, it's not easy, and I > haven't thought it out too well, but I thought I'd see > if anyone else is/was thinking about it. Yes, I've thought about it, and it is a good idea, and it can probably be implemented decently. This is an important issue (especially for me on a p200 :) ), but I have to research the issue. BTW, hopefully you are using the procmail filter now; it certainly helps on incoming mails :) - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.9.0 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjmIMv8ACgkQVv/RCiYMT6MS+wCdFxjQTqo3lAcKydDWHlnOfc6P lZ4Anj5fRDSpDfA3IIfZDOFlO8XujodO =Z19l -----END PGP SIGNATURE----- |
|
From: Billy D. <bi...@da...> - 2000-08-01 16:27:17
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'm still thinking about the startup time of pgpenvelope. It's all the perl compiling. It would be nice to have a persistent perl process running 'hot' alongside pine, The problem is killing it when pine dies. I guess pine would be the parent pid or something... So there would be this daemon running for you, and there would be a short connector program which would be the actual pine filter. Well, it's not easy, and I haven't thought it out too well, but I thought I'd see if anyone else is/was thinking about it. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.11 - http://pgpenvelope.sourceforge.net/ iD8DBQE5hvos+2VvpwIZdF0RAtjsAJ4lD01sURPcbElDuSgUdxb4IS1URACffXvN za6LADRoCc75+O7bQlXoOBs= =VzIp -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-24 02:32:36
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Billy Donahue, at 13:32 -0400 on Sun, 23 Jul 2000, wrote: > When you go to send a message, the cache is consulted (and possibly rebuilt). > If all recipient email addresses are matched, then you are allowed > the option to encrypt the message, otherwise, the best you can do > is to sign it. If a recipient address matches more than one key, > you have to choose which key you want to encrypt to. Interesting. I could do a similar thing with pgpenvelope, as I also use key structure that could lend itself to such processing. I'll think of what could be done similarly. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.11 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjl7qsEACgkQVv/RCiYMT6OoywCeOu1KvBpP0Gw+NG9rK4w/22ld 3RYAn3Vzp9BqnXbXuc8+DgRVSzS3ino1 =5B4/ -----END PGP SIGNATURE----- |
|
From: Billy D. <bi...@da...> - 2000-07-23 17:30:05
|
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
I've veen studying pgp4pine this morning.
It does an interesting caching with the keyring.
To determine whether to 'sign', or 'sign & encrypt', pgp4pine
checks whether a key exists for all of the recipients.
Figuring out which key to use for each recipient is sped up
by a cache database of the public keyring. The cache is built
by parsing the output of:
gpg --list-keys --with-colons --no-greeting 2>/dev/null
filling in a linked list of 'struct pkiKey' objects, where:
struct pkiKey {
char emailAddress[EMAIL_ADDRESS_MAX_LENGTH];
char displayName[EMAIL_ADDRESS_MAX_LENGTH];
char keyID[KEY_ID_LENGTH];
char keySize[KEY_SIZE_LENGTH];
char keyType[KEY_TYPE_LENGTH];
struct pkiKey *nextKey;
};
If a key has more than one 'uid', an additional copy of the struct pkiKey
is added to the database to accomodate the extra uid's emailAddress and
displayName fields. So all email addresses in the keyring are taken into
consideration.
When you go to send a message, the cache is consulted (and possibly rebuilt).
If all recipient email addresses are matched, then you are allowed
the option to encrypt the message, otherwise, the best you can do
is to sign it. If a recipient address matches more than one key,
you have to choose which key you want to encrypt to.
- --
"The Funk, the whole Funk, and nothing but the Funk."
Billy Donahue <mailto:bi...@da...>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.1 (GNU/Linux)
Comment: pgpenvelope 2.8.11 - http://pgpenvelope.sourceforge.net/
iD8DBQE5eyxH+2VvpwIZdF0RAuAeAJ9a6T7N1HTvqnQzcW5b9VU5rBZ2twCfdXQy
UOyrl7EC04gunEZUX2p2hkA=
=g0hC
-----END PGP SIGNATURE-----
|
|
From: Billy D. <bi...@da...> - 2000-07-23 03:37:21
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 22 Jul 2000, Frank Tobin wrote: > I've made some modifications to GnuPG::Interface so that some of the many > modules it uses aren't loaded unless they are needed (at least that's the > hope). If some of you who have problems with a slow pgpenvelope_decrypt > could cvs-checkout GnuPG::Interface and contrast runtimes before/after > installing the checked-out version, I'd appreciate it. I couldn't tell the difference.. It's still pretty slow to get going. I can't decide how to make a real benchmark. I'm just eyeballing it. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5emki+2VvpwIZdF0RAuX4AJ9qiuc17UxEEG3yWj1b5r+mW4pYwACePvi5 CTf9qmhDEjR7sx51imLQzMY= =10qk -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-23 02:45:58
|
Billy Donahue, at 22:20 -0400 on Sat, 22 Jul 2000, wrote: > Looks good.. You want to apply this patch, though. :) Whoops; thanks. -- Frank Tobin http://www.uiuc.edu/~ftobin/ |
|
From: Billy D. <bi...@da...> - 2000-07-23 02:18:09
|
Looks good.. You want to apply this patch, though. :)
Index: pgpenvelope_decrypt
===================================================================
RCS file: /cvsroot/pgpenvelope/pgpenvelope/pgpenvelope_decrypt,v
retrieving revision 1.16
diff -u -u -r1.16 pgpenvelope_decrypt
--- pgpenvelope_decrypt 2000/07/23 01:32:07 1.16
+++ pgpenvelope_decrypt 2000/07/23 02:16:37
@@ -242,7 +242,7 @@
{
my ( $signal_name ) = @_;
print "$FindBin::Script: Signal $signal_name caught. Cleaning up.\n";
- print STDOUT "-----UNPROCESSED MESSAGE BELOW-----";
+ print STDOUT "-----UNPROCESSED MESSAGE BELOW-----\n";
print STDOUT <STDIN>;
$terminal->cleanup() if $terminal;
print "Exiting.\n";
--
"The Funk, the whole Funk, and nothing but the Funk."
Billy Donahue <mailto:bi...@da...>
|
|
From: Frank T. <ft...@ui...> - 2000-07-23 01:57:07
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I've made some modifications to GnuPG::Interface so that some of the many modules it uses aren't loaded unless they are needed (at least that's the hope). If some of you who have problems with a slow pgpenvelope_decrypt could cvs-checkout GnuPG::Interface and contrast runtimes before/after installing the checked-out version, I'd appreciate it. Instructions on cvs-checking out GnuPG::Interface anonymously (which is what you will be doing) are available at: https://sourceforge.net/cvs/?group_id=4802 The "modulename" you'll need to use described in the instructions is "GnuPG-Interface". You can ignore any 'files missing' errors that you might get after running "perl Makefile.PL". Thanks in advance for any results! - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjl6UO8ACgkQVv/RCiYMT6O7HgCbBrY+gpVbwmhcB2gtrXAbBZYd WPEAn2JrbxU0bKY8JKatDbHmBFX4q+Qn =5V8B -----END PGP SIGNATURE----- |
|
From: Billy D. <bi...@da...> - 2000-07-23 01:20:04
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 22 Jul 2000, Frank Tobin wrote: > > Billy Donahue, at 20:41 -0400 on Sat, 22 Jul 2000, wrote: > > Maybe a recipient match should be run. > > pgp4pine has a stored cache of the uids in your > > keyring, so it can do this instantly. > > You can have encryption by-default selected via the prefs file. Could you > explain more about the recipient match pgp4pine does? Sure, when I've got some time to breathe, I'll look into it. > I highly recommend using the procmail filter described in the manpage to > pre-process signed messages. I'll have to give that a try.. I'm not using procmail at all right now, though. So I'll have to get around to it. I've been meaning to get it set up, so this is as good a reason as any. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5ekj1+2VvpwIZdF0RAj3qAKCDttotkwA6TB+ro/pVdoOxBhWHuQCeKBpG LsW2dHUajQw/oi94ZQx5NqQ= =U9iW -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-23 01:10:11
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Billy Donahue, at 20:41 -0400 on Sat, 22 Jul 2000, wrote: > With pgpenvelope, I have to manually select encrypting, and > signing is always checked by default. Maybe a recipient match > should be run. pgp4pine has a stored cache of the uids in your > keyring, so it can do this instantly. You can have encryption by-default selected via the prefs file. Could you explain more about the recipient match pgp4pine does? > Another point of comparison is startup speed. pgpenvelope is perl, and > takes a while to get going. This probably can't be helped much. > pgp4pine is a 'c' program, and it starts up _much_ faster... This is a > big deal when I'm quickly scanning my messages in Pine.. Yes, this can be a problem. The slowness is mainly due to GnuPG::Interface, the Perl module to access GnuPG behind pgpenvelope. I highly recommend using the procmail filter described in the manpage to pre-process signed messages. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjl6RfAACgkQVv/RCiYMT6NC5QCgm0bcr5fRIWelYKoCmz1AxOgk dPwAn188HMzYxnqVKBilLcr+k9N6XHid =8D+r -----END PGP SIGNATURE----- |
|
From: Billy D. <bi...@da...> - 2000-07-23 00:38:51
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sat, 22 Jul 2000, Frank Tobin wrote: > Billy Donahue, at 19:53 -0400 on Sat, 22 Jul 2000, wrote: > > I've definitely recently started considering having the problem solved in > two ways; first, having the procmail filter strip the key from the message > after trying to process it (you could still access it by the recommended > signed-backup) folder. > > Personally, I feel the people putting keys into BugTraq messages are being > quite silly and not showing a lot of gray matter. I agree, but I'm not talking about posting of public keys to bugtraq. I think it makes a LOT of sense to sign messages posted to buqtraq, to make it harder to forge security advisories. These signed messages trigger pgpenvelope_decrypt. > As a temporary workaround, there is a cofirm-decryption described in > ~/.pgpenvelope/prefs.default you may be interested in. I knew about that option, but I'm a keystroke monger, so I don't want to use it unless I really have to. > This is an interesting idea I've played around with; initially I thought > of pgpenvelope doing that, and then exiting with error; unfortunately, > Pine's behaviour is undefined when the filter exits with error. Just now > I thought of having pgpenvelope exit with success instead, and this would > solve the situation, so that's what I think I'll do. Yeah, that's certainly a reasonable way out of a sigint. > BTW, since I don't use pgp4pine, what points caused you to use > pgpenvelope, and are there any points of pgp4pine that you miss? The biggest thing that brought me over to pgp4pine was when I imported a friend's key and all of a sudden pgp4pine stopped working. :) I cleared the cache file, to no avail.. something was just wrong.. Rather than deal with it headfirst, I ran into the arms of pgpenvelope, and I'm pretty happy with it so far. Hmm.. pgp4pine took fewer keystrokes to send a signed message. I'd type (a) and that would 'sign' or 'sign and encrypt' depending on whether I had keys for all of the recipients. I got into the habit of typing 'a', $passphrase, '\n' (forgive my pseudoperl). With pgpenvelope, I have to manually select encrypting, and signing is always checked by default. Maybe a recipient match should be run. pgp4pine has a stored cache of the uids in your keyring, so it can do this instantly. Pgpenvelope is more flexible with key selection, which is cool. Another point of comparison is startup speed. pgpenvelope is perl, and takes a while to get going. This probably can't be helped much. pgp4pine is a 'c' program, and it starts up _much_ faster... This is a big deal when I'm quickly scanning my messages in Pine.. However, I remember that pgp4pine wasn't too sharp on keys with multiple uids. I think it would only get the first uid on the key. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5ej9K+2VvpwIZdF0RAjY9AJ9xSnkPpoGxMcq3sP9q7hBvzvqhmACgilGk GJpKz/M7+jjpAcrXMzvNrHA= =9Tgh -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-23 00:19:17
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Billy Donahue, at 19:53 -0400 on Sat, 22 Jul 2000, wrote: > I'm using pgpenvelope-2.8.10, gpg-1.0.1, on Linux-2.2.14, with Pine 4.20. > Okay. Now I get signed mail from people whose keys I don't have yet, > mostly from the Buqtraq list. PGPEnvelope will try to get their > keys from the keyserver, and it will hang doing this if the > key isn't to be found.. If I send a SIGINT, Pine (or pgpenvelope, I can't > tell) will tell me that the filter was interrupted or something. I've definitely recently started considering having the problem solved in two ways; first, having the procmail filter strip the key from the message after trying to process it (you could still access it by the recommended signed-backup) folder. Personally, I feel the people putting keys into BugTraq messages are being quite silly and not showing a lot of gray matter. > I can't actually read the message! > My point is that I may not care too much about the signature.. I might > want to abort the keyfetching after a second or two but still > see the message... Am I making sense? As a temporary workaround, there is a cofirm-decryption described in ~/.pgpenvelope/prefs.default you may be interested in. > My idea is to put a SIGINT handler into pgpenvelope that will spill > the original message out and die... What do you think? I believe this > is how pgp4pine worked, because I just switched from pgp4pine. This is an interesting idea I've played around with; initially I thought of pgpenvelope doing that, and then exiting with error; unfortunately, Pine's behaviour is undefined when the filter exits with error. Just now I thought of having pgpenvelope exit with success instead, and this would solve the situation, so that's what I think I'll do. BTW, since I don't use pgp4pine, what points caused you to use pgpenvelope, and are there any points of pgp4pine that you miss? - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjl6OgMACgkQVv/RCiYMT6NL2wCgorN6SZacksgO4Eqb94QvM/jO BAMAnj/AbgdWlzysUeVPpQxdUYILGerl =0IHP -----END PGP SIGNATURE----- |
|
From: Billy D. <bi...@da...> - 2000-07-22 23:50:50
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I'm using pgpenvelope-2.8.10, gpg-1.0.1, on Linux-2.2.14, with Pine 4.20. Okay. Now I get signed mail from people whose keys I don't have yet, mostly from the Buqtraq list. PGPEnvelope will try to get their keys from the keyserver, and it will hang doing this if the key isn't to be found.. If I send a SIGINT, Pine (or pgpenvelope, I can't tell) will tell me that the filter was interrupted or something. I can't actually read the message! My point is that I may not care too much about the signature.. I might want to abort the keyfetching after a second or two but still see the message... Am I making sense? My idea is to put a SIGINT handler into pgpenvelope that will spill the original message out and die... What do you think? I believe this is how pgp4pine worked, because I just switched from pgp4pine. - -- "The Funk, the whole Funk, and nothing but the Funk." Billy Donahue <mailto:bi...@da...> -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5ejQN+2VvpwIZdF0RAsaTAJ4qJoZhwxJ2hNNQnUDaxXdXvDR4jwCgk7vF 8r/giKkexaQgHgcx0Xqnp+I= =xixk -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-17 21:01:39
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Trevor Johnson, at 13:10 -0400 on Mon, 17 Jul 2000, wrote: > How can I use pgpenvelope with messages that use the RFC 2015 MIME types > (described at ftp://ftp.isi.edu/in-notes/rfc2015.txt)? My setup looks > like this: Unfortunately, Pine doesn't appear to support processing multi-part messages yet by its standard display-filtering mechanism. There is hope, however, to succeed by using Pine's pipe-filtering mechanism, or via procmail. > I've configured pine to use pgpenvelope according to the examples in the > man page. I tried editing a message I'd received, changing the MIME type > to text/plain, and pgpenvelope could decrypt it afterward (not > beforehand). I tried sending a message, and it was given a text/plain > MIME type. I'm told that for users of Mutt (an MUA for Unix--see > www.mutt.org), such messages are more difficult to decode than ones > constructed according to the RFC (the author of the RFC is also the author > of Mutt). Yes, Mutt does currently have PGP/MIME support. Pine does not support multi-part MIME's such as PGP/MIME yet. Something, unfortunately, is going to have to evolve in Pine, I feel, for pgpenvelope to get PGP/MIME supoprt. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlzdDEACgkQVv/RCiYMT6MleQCgjgVD36wZz/VfNEkOI+kWe8Iw v54AnA8lNuDvr0ez5NGYo7S6WgSb4h+A =f4bS -----END PGP SIGNATURE----- |
|
From: Trevor J. <tr...@jp...> - 2000-07-17 17:10:33
|
How can I use pgpenvelope with messages that use the RFC 2015 MIME types (described at ftp://ftp.isi.edu/in-notes/rfc2015.txt)? My setup looks like this: $ grep -i mime .pinerc|grep -v ^# mimetype-search-path=/usr/local/etc/apache/mime.types $ grep -i pgp /usr/local/etc/apache/mime.types application/pgp-encrypted application/pgp-keys application/pgp-signature I've configured pine to use pgpenvelope according to the examples in the man page. I tried editing a message I'd received, changing the MIME type to text/plain, and pgpenvelope could decrypt it afterward (not beforehand). I tried sending a message, and it was given a text/plain MIME type. I'm told that for users of Mutt (an MUA for Unix--see www.mutt.org), such messages are more difficult to decode than ones constructed according to the RFC (the author of the RFC is also the author of Mutt). -- Trevor Johnson http://jpj.net/~trevor/gpgkey.txt |
|
From: Frank T. <ft...@ui...> - 2000-07-17 07:09:38
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 00:04 -0700 on Mon, 17 Jul 2000, wrote: > BTW, minor bug here: in the index, select /open a message that is > encrypted, and immediately hit ^C (before the prompt to verifiy decryption > is offered) > SIGINT handler "die_signal_handler" not defined. I've noticed this also. This is due to pgpenvelope not being compiled yet by the time you hit Ctrl-C. I do not know of a workaround at this time. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlysTAACgkQVv/RCiYMT6NJQwCffhHtkJnMiE+pEaeQWK6q1eKB 0RYAn0feB6gB+EgIVdIUuBkt/XimJR8T =ljWc -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-07-17 07:04:16
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Fri, 14 Jul 2000, Frank Tobin wrote: > -----BEGIN PGPENVELOPE PROCESSED MESSAGE----- > > John A. Perry, at 21:34 -0500 on Fri, 14 Jul 2000, wrote: > > > When doing a "perl Makefile.PL" on the 2.8.10 version I get the following: > > > > Can't locate auto/ExtUtils/MakeMaker/autosplit.ix in @INC (@INC > > contains: /usr/lib/perl5/5.00503/i386-linux /usr/lib/perl5/5.00503 > > /usr/lib/perl5/site_perl/5.005/i386-linux /usr/lib/perl5/site_perl/5.005 > > .) at /usr/lib/perl5/5.00503/AutoLoader.pm line 127. > > at (eval 5) line 3 > > Writing Makefile for pgpenvelope > > This is a known issue, and is described in the INSTALL file. This error > started occuring once GnuPG::Interface started moving to using > Autoload. This warning/error does not seem to have any effects on > pgpenvelope or GnuPG::Interface. Note that I did RTFM in this case (because otherwise you would have definately heard from me... hehe. BTW, minor bug here: in the index, select /open a message that is encrypted, and immediately hit ^C (before the prompt to verifiy decryption is offered) Output: SIGINT handler "die_signal_handler" not defined. __ L. Sassaman System Administrator | "Every window on Alcatraz has Technology Consultant | a view of San Francisco." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Susanna Kaysen -----BEGIN PGP SIGNATURE----- Comment: OpenPGP Encrypted Email Preferred. iD8DBQE5cq/tPYrxsgmsCmoRAlqxAKCM8bJfKEJyduJgR1ScvGWefeZPMACeLrX4 1WsKRHWky1Lcr/lY4hpHX6k= =462U -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-17 07:03:43
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 This is a heads-up to pgpenvelope users about a passphrase-caching program that may be of interest. It supports passphrase-caching for GnuPG, which means pgpenvelope should be able to use it. To get pgpenvelope to call the right program (agpg in this case), simply configure your ~/.pgpenvelope/prefs to have the appropriate paths for the "encryption-program-call" and "decryption-program-call" settings. Note that these settings are not the same as the "encryption-program" and "decryption-program" settings, which only tell pgpenvelope overall what program is being called (instead of a path). - -- Frank Tobin http://www.uiuc.edu/~ftobin/ Forwarded message: - --------------------------------------------------- Date: 15 Jul 2000 22:15:32 +0200 From: Robert Bihlmeyer <ro...@or...> To: gnu...@gn... Subject: Announcing secret-agent 0.8 Resent-Date: Sat, 15 Jul 2000 22:47:02 +0200 Resent-From: gnu...@gn... I'd like to inform you of the release of secret-agent 0.8. It is a small utility to store secrets in memory. One of its main uses (and the reason I write to this list) is as a store for GPG passphrases for configurable time-span. An example session will probably go a long way of explaining it: $ eval `secret-agent` $ secret-client -t 600 put E6583EFB "Robert Bihlmeyer (GPG)" [here I enter the passphrase] $ agpg -ba a-file [a-file is signed without me having to enter the passphrase] $ agpg -ba b-file [ditto] $ sleep 600 $ agpg -ba c-file [this will fail, because the secret has timed out] This will also work with any application calling gpg (MUAs etc.) as long as you can make them call the agpg wrapper instead of the real thing. This mail was (hopefully <g>) signed with the help of secret-agent. secret-agent is GPL'd. The URL is <http://www.vibe.at/tools/secret-agent/> I hope you will find it as useful as I have. Bug reports and success stories should go to <ro...@or...>. - -- Robbe -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlyr80ACgkQVv/RCiYMT6PSfACdHdRn0Tb4uLXGt3eZwutoL1jA 27YAn3wDH3xC97Ba8OJ0k0RbSYIMVyKD =Gegq -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-16 00:19:58
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 14:09 -0700 on Fri, 14 Jul 2000, wrote: > > The just-released 2.8.10 addresses and fixes this bug. > > If only all software development had a turn-around time like that for > bug fixes. From the Glossary of Programming Perl: hubris -- Excessive pride, the soft of thing Zeus zaps you for. Also the quality that makes you write (and maintain) programs that other people won't want to say bad things about. Hence, the third great virtue of a programmer. See also "laziness" and "impatience". - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlw/6oACgkQVv/RCiYMT6M76ACfeKJ4LzVycG4LNvaqDgl6KIzK 1B0AnRnnQQ5QGAZDwf+CIPs0YdcPttlY =oWjr -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-15 03:01:41
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 John A. Perry, at 21:34 -0500 on Fri, 14 Jul 2000, wrote: > When doing a "perl Makefile.PL" on the 2.8.10 version I get the following: > > Can't locate auto/ExtUtils/MakeMaker/autosplit.ix in @INC (@INC > contains: /usr/lib/perl5/5.00503/i386-linux /usr/lib/perl5/5.00503 > /usr/lib/perl5/site_perl/5.005/i386-linux /usr/lib/perl5/site_perl/5.005 > .) at /usr/lib/perl5/5.00503/AutoLoader.pm line 127. > at (eval 5) line 3 > Writing Makefile for pgpenvelope This is a known issue, and is described in the INSTALL file. This error started occuring once GnuPG::Interface started moving to using Autoload. This warning/error does not seem to have any effects on pgpenvelope or GnuPG::Interface. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlv1BMACgkQVv/RCiYMT6MCDwCcD0ix7tmbLvfTta+mBx+0qxuO aeAAmwT3KdbsISeFd1/B7mxJ/qFzlXuz =Pcjr -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-07-15 02:59:34
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 John A. Perry, at 19:38 -0500 on Fri, 14 Jul 2000, wrote: > Too late now but I was going to report that 2.8.9 was working fine on my > system. What was the problem? It seemed an issue with what happens to dupped (dup(2)) filehandles upon a fork(2). On my system (FreeBSD) the original file's position indicator moved if the dupped one was written out, while that did not seem to happen on Len's system. The change I've is cleaner, anyways, from what I had before. - -- Frank Tobin http://www.uiuc.edu/~ftobin/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (FreeBSD) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iEYEARECAAYFAjlv05QACgkQVv/RCiYMT6PmLACgstkVtzaZ+OecenLqrct4VNXu dZ4AoK2ExPNPCqjbHAR8OSxrnt43ACt8 =mBNK -----END PGP SIGNATURE----- |
|
From: John A. P. <pe...@jp...> - 2000-07-15 02:34:59
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 When doing a "perl Makefile.PL" on the 2.8.10 version I get the following: Can't locate auto/ExtUtils/MakeMaker/autosplit.ix in @INC (@INC contains: /usr/lib/perl5/5.00503/i386-linux /usr/lib/perl5/5.00503 /usr/lib/perl5/site_perl/5.005/i386-linux /usr/lib/perl5/site_perl/5.005 .) at /usr/lib/perl5/5.00503/AutoLoader.pm line 127. at (eval 5) line 3 Writing Makefile for pgpenvelope - -- John Perry pe...@jp... PGP-encrypted e-mail welcome! PGP/GPG key 164BDBAE ICQ# 64823745 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: pgpenvelope 2.8.10 - http://pgpenvelope.sourceforge.net/ iD8DBQE5b83J7YSEAxZL264RAhdhAKDZjtbWv3eL/aJEtVx0Fh0c4cPs1QCfYBWr nfPWxI4pCsuNd8k7m3RVIOY= =vKqr -----END PGP SIGNATURE----- |