pgpenvelope-users Mailing List for pgpenvelope (Page 8)
Brought to you by:
ftobin
You can subscribe to this list here.
| 2000 |
Jan
(1) |
Feb
(22) |
Mar
(11) |
Apr
(9) |
May
(1) |
Jun
(9) |
Jul
(28) |
Aug
(9) |
Sep
(10) |
Oct
(26) |
Nov
|
Dec
|
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2001 |
Jan
(8) |
Feb
(2) |
Mar
|
Apr
(2) |
May
(6) |
Jun
|
Jul
(4) |
Aug
(8) |
Sep
(9) |
Oct
|
Nov
(2) |
Dec
(8) |
| 2002 |
Jan
(1) |
Feb
|
Mar
(1) |
Apr
|
May
|
Jun
|
Jul
(1) |
Aug
|
Sep
(3) |
Oct
|
Nov
|
Dec
|
| 2003 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
(2) |
Aug
(2) |
Sep
|
Oct
|
Nov
|
Dec
|
|
From: Frank T. <ft...@ui...> - 2000-02-16 07:26:44
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 02:05 on Wed, 16 Feb 2000, wrote: > Are revoked. There should be a check against self-signature revokations on > UIDs, and this should be displayed as a warning (or they should simply not > appear in the list). If you sign an ordinary text file with your revoked key, does GnuPG warn you if you perform do a "gpg --verify"? How about "gpg --decrypt"? It might have been just me, but when I just tried to verify a file signed by my revoked RSA key, it didn't warn at first; however, I then set the trust level to full (was unset before), and then GnuPG did warn me. It seems I cannot re-set the trust to unset (represented by '-' in '--edit-key'). - -- Frank Tobin http://www.neverending.org/~ftobin/ "To learn what is good and what is to be valued, those truths which cannot be shaken or changed." Myst: The Book of Atrus OpenPGP: 4F86 3BBB A816 6F0A 340F 6003 56FF D10A 260C 4FA3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (FreeBSD) Comment: pgpenvelope - http://pgpenvelope.sourceforge.net iD8DBQE4qlCXVv/RCiYMT6MRAgUJAJ9z3NRYbxYsIF2Ei998izuQoumsLgCfZkEN A6AVTVmlPTuOBhTEZSilsYs= =vG4L -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-02-16 07:07:52
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 When I send mail to myself, signed, and run it through the PGPEnvelope filter, I notice this: - -----BEGIN PGPENVELOPE INFORMATION----- gpg: Signature made Wed Feb 16 01:57:33 2000 EST using DSA key ID 09AC0A6A gpg: Good signature from "L. Sassaman <ra...@qu...>" gpg: aka "L. Sassaman <lh...@in...>" gpg: aka "L. Sassaman <lh...@qu...>" gpg: aka "QuickieNet System Administrator <sys...@qu...>" gpg: aka "L. Sassaman <sys...@qu...>" gpg: aka "L. Sassaman <le...@de...>" gpg: aka "L. Sassaman <ra...@de...>" gpg: aka "Thawte Freemail Member <ra...@qu...>" gpg: aka "Leonard Harris Sassaman <ra...@qu...>" gpg: aka "L. Sassaman <lh...@ta...>" gpg: aka "L. Sassaman <ra...@ta...>" gpg: aka "L. Sassaman <LSa...@un...>" - -----END PGPENVELOPE INFORMATION----- Which looks fine. And that is the problem... These: gpg: aka "L. Sassaman <lh...@in...>" gpg: aka "L. Sassaman <lh...@ta...>" gpg: aka "L. Sassaman <ra...@ta...>" gpg: aka "L. Sassaman <LSa...@un...>" Are revoked. There should be a check against self-signature revokations on UIDs, and this should be displayed as a warning (or they should simply not appear in the list). I have a feeling, as I am writing this, that this is really a GnuPG flaw, and not a PGPEnvelope flaw, though possibly PGPEnvelope could compensate for it. - --Len. __ L. Sassaman System Administrator | "All of the chaos Technology Consultant | Makes perfect sense..." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Joe Diffie -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: OpenPGP Encrypted Email Preferred. iD8DBQE4qkwtPYrxsgmsCmoRAuiXAKCUcwf0S3oxJxD+xzv/9JC7IDfoPgCg81Po e46ScxLW2KfXlIH4wEBcTeg= =UPId -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-02-16 07:06:59
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 01:56 on Wed, 16 Feb 2000, wrote: > From what I can tell, it occurs when gpg tries to alter the file that is > locked (either keyring or trust.db). > > So basically, whenever GnuPG tries to verify sigs for which the signing > key is not on the keyring, this will occur. > > This is particularily troublesome with the procmail implementation. So, in summary, this only happens on received messages? - -- Frank Tobin http://www.neverending.org/~ftobin/ "To learn what is good and what is to be valued, those truths which cannot be shaken or changed." Myst: The Book of Atrus OpenPGP: 4F86 3BBB A816 6F0A 340F 6003 56FF D10A 260C 4FA3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (FreeBSD) Comment: pgpenvelope - http://pgpenvelope.sourceforge.net iD8DBQE4qkv3Vv/RCiYMT6MRAvhhAKChOiGTsxeT7jUDZxWJHUQJOhinZgCgjqaH ngp2qlnIxxuAzNRDEGyANMA= =U++x -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-02-16 06:59:27
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, 16 Feb 2000, Frank Tobin wrote: > -----BEGIN PGPENVELOPE PROCESSED MESSAGE----- > > L. Sassaman, at 00:36 on Wed, 16 Feb 2000, wrote: > > > The next invocation of GnuPG will cause it to sit and wait indefinately > > (although it gives the message "Waiting for lock file .. probably > > dead".) I am not quoting that exactly; I will cut/paste it next time I see > > it. When I see this, I then know I have to manually remove the lock file. > > > > However, this isn't visible when GnuPG is being called by PGPEnvelope. > > Could you provide me information on when this occurs? That is, is it > during sending (encryption/signing) or receiving (decryption/verifying). > I'm guessing verifying, because only then is GnuPG's stderr (error/logging > output) trapped. - From what I can tell, it occurs when gpg tries to alter the file that is locked (either keyring or trust.db). So basically, whenever GnuPG tries to verify sigs for which the signing key is not on the keyring, this will occur. This is particularily troublesome with the procmail implementation. __ L. Sassaman System Administrator | "All of the chaos Technology Consultant | Makes perfect sense..." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Joe Diffie -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: OpenPGP Encrypted Email Preferred. iD8DBQE4qkozPYrxsgmsCmoRAvbJAJ4hRXno/SMaSZygiZVCfhnt51n8fwCgtz3a YYeShFGfIL/DYRlPfsvTxps= =nEgb -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-02-16 06:48:48
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 00:36 on Wed, 16 Feb 2000, wrote: > The next invocation of GnuPG will cause it to sit and wait indefinately > (although it gives the message "Waiting for lock file .. probably > dead".) I am not quoting that exactly; I will cut/paste it next time I see > it. When I see this, I then know I have to manually remove the lock file. > > However, this isn't visible when GnuPG is being called by PGPEnvelope. Could you provide me information on when this occurs? That is, is it during sending (encryption/signing) or receiving (decryption/verifying). I'm guessing verifying, because only then is GnuPG's stderr (error/logging output) trapped. - -- Frank Tobin http://www.neverending.org/~ftobin/ "To learn what is good and what is to be valued, those truths which cannot be shaken or changed." Myst: The Book of Atrus OpenPGP: 4F86 3BBB A816 6F0A 340F 6003 56FF D10A 260C 4FA3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (FreeBSD) Comment: pgpenvelope - http://pgpenvelope.sourceforge.net iD8DBQE4qkeyVv/RCiYMT6MRAhmTAJ45Xo0iuP3uLt9vba376jQt8N1YBACfVfru W4lDHRvNHE0SlCPseO/pOK0= =VXHB -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-02-16 06:21:34
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi Frank, One annoyance I have found with PGPEnvelope/GnuPG is this: When GnuPG encounters a .lock file on the keyrings or trustdb, it will sit and wait for the lock to be released. Occasionally, the lock file becomes stale when procmail hiccups, or something else occurs to interrupt GnuPG. The next invocation of GnuPG will cause it to sit and wait indefinately (although it gives the message "Waiting for lock file .. probably dead".) I am not quoting that exactly; I will cut/paste it next time I see it. When I see this, I then know I have to manually remove the lock file. However, this isn't visible when GnuPG is being called by PGPEnvelope. Can we have PGPEnvelope look for GnuPG's lock file error messages, and terminate with an informative message telling the user to check the lock file and clear it if necessary? - --Len. __ L. Sassaman System Administrator | "All of the chaos Technology Consultant | Makes perfect sense..." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Joe Diffie -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: OpenPGP Encrypted Email Preferred. iD8DBQE4qjdxPYrxsgmsCmoRAnNmAJ9R1SvVz4q6WokYSOzGWCdtD4U+tgCg57vJ T/5AU5nU3G3s0G9BMJCzjZc= =ZEds -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-02-07 21:49:00
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Mon, 7 Feb 2000, Frank Tobin wrote: > Currently, the method pgpenvelope is using to get key information is very > blunt, to say the least; it is just capturing the output of "gpg > --list-keys". Using this method, there is no way to sense if a key has I figured as much. > been disabled. I've been putting it off, but given this scenario has > provided me with the 'push' to use the "--with-colons" options to grab the > data in a well-defined, parseable manner. This will require a major > rewrite of the key handling of pgpenvelope, so it will take some time. > Look to see for such a design in a near-future version of pgpenvelope. Great. As always, thanks for your wonderful work, Frank. __ L. Sassaman System Administrator | "All of the chaos Technology Consultant | Makes perfect sense..." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Joe Diffie -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: OpenPGP Encrypted Email Preferred. iD8DBQE4nz1XPYrxsgmsCmoRAlBBAJsGu/VEhP8p76BLx6vpkgeGK2wmQQCghPPJ uBgU2qQrBqqNk/x379jUmaA= =uf2G -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-02-07 07:54:30
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 L. Sassaman, at 23:38 on Sun, 6 Feb 2000, wrote: > I have two keys with the same uid on my keyring. The first one is > disabled... but when I try to encrypt mail to that address, PGPEnvelope > still offers me that key (then GPG chokes on it). Any way to check and see > if a key is disabled before presenting it in the list of possible > encryption keys? Currently, the method pgpenvelope is using to get key information is very blunt, to say the least; it is just capturing the output of "gpg - --list-keys". Using this method, there is no way to sense if a key has been disabled. I've been putting it off, but given this scenario has provided me with the 'push' to use the "--with-colons" options to grab the data in a well-defined, parseable manner. This will require a major rewrite of the key handling of pgpenvelope, so it will take some time. Look to see for such a design in a near-future version of pgpenvelope. - -- Frank Tobin http://www.neverending.org/~ftobin/ "To learn what is good and what is to be valued, those truths which cannot be shaken or changed." Myst: The Book of Atrus OpenPGP: 4F86 3BBB A816 6F0A 340F 6003 56FF D10A 260C 4FA3 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (FreeBSD) Comment: pgpenvelope - http://www.uiuc.edu/ph/www/ftobin/resources.html iEYEARECAAYFAjieebcACgkQVv/RCiYMT6P5RgCfajVc2GwllOrVtyJstfC7Lg7p bQsAoIUtnOet2SMio1WdbNkqpSC9yLNT =jcXZ -----END PGP SIGNATURE----- |
|
From: L. S. <ra...@qu...> - 2000-02-07 04:40:58
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Possible bug here... I have two keys with the same uid on my keyring. The first one is disabled... but when I try to encrypt mail to that address, PGPEnvelope still offers me that key (then GPG chokes on it). Any way to check and see if a key is disabled before presenting it in the list of possible encryption keys? __ L. Sassaman System Administrator | "All of the chaos Technology Consultant | Makes perfect sense..." icq.. 10735603 | pgp.. finger://ns.quickie.net/rabbi | --Joe Diffie -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.1 (GNU/Linux) Comment: OpenPGP Encrypted Email Preferred. iD8DBQE4nkxjPYrxsgmsCmoRAghAAJ96F+We/V3jLK0jdI3DDmf/0Yh8kgCfRJOn jIK1NtD4wPgjLTsy8dD4mh0= =4UbJ -----END PGP SIGNATURE----- |
|
From: Frank T. <ft...@ui...> - 2000-01-20 02:34:28
|
As you probably noticed by the welcome messages you got, I've decided to move developement, mailing lists, and the webpage of pgpenvelope over to sourceforge.net. They have an excellent setup, and definitely takes a load off of me. I've subscribed everyone who was on pgp...@ya... to: pgp...@li... pgp...@li... If you do not wish to be subscribed to these lists, feel free to visit the URL's described in the welcome message you got to configure your subscription or unsubscribe; SourceForge uses Mailman, a mailing list manager which has an excellent web-based interface. -- Frank Tobin http://www.neverending.org/~ftobin/ "To learn what is good and what is to be valued, those truths which cannot be shaken or changed." Myst: The Book of Atrus OpenPGP: 4F86 3BBB A816 6F0A 340F 6003 56FF D10A 260C 4FA3 |