Re: [BUG] Decryption fails if message was signed with an unknown key
authorDaniel Kahn Gillmor <dkg@fifthhorseman.net>
Tue, 24 Sep 2013 23:14:22 +0000 (19:14 +2000)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:57:12 +0000 (09:57 -0800)
81/e6255fb2cef96365ad730a4808ef56fb1465e1 [new file with mode: 0644]

diff --git a/81/e6255fb2cef96365ad730a4808ef56fb1465e1 b/81/e6255fb2cef96365ad730a4808ef56fb1465e1
new file mode 100644 (file)
index 0000000..4398caa
--- /dev/null
@@ -0,0 +1,105 @@
+Return-Path: <dkg@fifthhorseman.net>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 3BBC6431FBD\r
+       for <notmuch@notmuchmail.org>; Tue, 24 Sep 2013 16:14:34 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: 0\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=0 tagged_above=-999 required=5 tests=[none]\r
+       autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id qFuQviygHg22 for <notmuch@notmuchmail.org>;\r
+       Tue, 24 Sep 2013 16:14:28 -0700 (PDT)\r
+Received: from che.mayfirst.org (che.mayfirst.org [209.234.253.108])\r
+       by olra.theworths.org (Postfix) with ESMTP id 9F8CF431FBC\r
+       for <notmuch@notmuchmail.org>; Tue, 24 Sep 2013 16:14:28 -0700 (PDT)\r
+Received: from [192.168.13.183] (lair.fifthhorseman.net [108.58.6.98])\r
+       by che.mayfirst.org (Postfix) with ESMTPSA id F1D74F986;\r
+       Tue, 24 Sep 2013 19:14:22 -0400 (EDT)\r
+Message-ID: <52421CCE.6030006@fifthhorseman.net>\r
+Date: Tue, 24 Sep 2013 19:14:22 -0400\r
+From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>\r
+User-Agent: Mozilla/5.0 (X11; Linux x86_64;\r
+       rv:17.0) Gecko/20130821 Icedove/17.0.8\r
+MIME-Version: 1.0\r
+To: Simon Hirscher <public@simonhirscher.de>\r
+Subject: Re: [BUG] Decryption fails if message was signed with an unknown key\r
+References:\r
+ <CAEj42wtt9O1-k9hm9DNCh7En=b-eDYQWham5-FR-wzrt+sij+g@mail.gmail.com>\r
+       <52289D36.2060006@fifthhorseman.net>\r
+       <CAEj42wuNziY65Q=9cS7kJquNrmrsd91gp34b4=4xrsoBcYfZnQ@mail.gmail.com>\r
+In-Reply-To:\r
+ <CAEj42wuNziY65Q=9cS7kJquNrmrsd91gp34b4=4xrsoBcYfZnQ@mail.gmail.com>\r
+X-Enigmail-Version: 1.5.1\r
+Content-Type: multipart/signed; micalg=pgp-sha512;\r
+       protocol="application/pgp-signature";\r
+       boundary="----enig2MIIXRHDXVCQPLPPLEHDU"\r
+Cc: notmuch <notmuch@notmuchmail.org>\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Tue, 24 Sep 2013 23:14:34 -0000\r
+\r
+This is an OpenPGP/MIME signed message (RFC 4880 and 3156)\r
+------enig2MIIXRHDXVCQPLPPLEHDU\r
+Content-Type: text/plain; charset=UTF-8\r
+Content-Transfer-Encoding: quoted-printable\r
+\r
+On 09/23/2013 07:23 PM, Simon Hirscher wrote:\r
+> Now, in order for you to test that behavior I'm going to send you a\r
+> signed and encrypted message because that should exactly reproduce the\r
+> bug, as long as you don't import my key (id EBACABE5 /\r
+> http://simonhirscher.de/public_key.asc) for signature verification.\r
+\r
+message received and tested on debian jessie using notmuch 0.16-1, and i\r
+did not see this misbehavior.\r
+\r
+Simon, for future reference, you can also test this sort of thing\r
+yourself by making multiple (phony) gpg homedirectories and notmuch\r
+config files, and setting GNUPGHOME and NOTMUCH_CONFIG environment\r
+variables appropriately.  I find this a pretty handy diagnostic approach.=\r
+\r
+\r
+       --dkg\r
+\r
+\r
+------enig2MIIXRHDXVCQPLPPLEHDU\r
+Content-Type: application/pgp-signature; name="signature.asc"\r
+Content-Description: OpenPGP digital signature\r
+Content-Disposition: attachment; filename="signature.asc"\r
+\r
+-----BEGIN PGP SIGNATURE-----\r
+Version: GnuPG v1.4.14 (GNU/Linux)\r
+Comment: Using GnuPG with Icedove - http://www.enigmail.net/\r
+\r
+iQJ8BAEBCgBmBQJSQhzOXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w\r
+ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFQjk2OTEyODdBN0FEREUzNzU3RDkxMUVB\r
+NTI0MDFCMTFCRkRGQTVDAAoJEKUkAbEb/fpcTi0QANoDHh478VYEJWjqvjevmy3K\r
+igzofP1W0bGY2eekdD1CR/1B5t6nRBypaei19nrMNfDXLyjDz9VLCLnpIi/DF/K2\r
+PxXj4te1TCkzJs/Yoe3uGcFBk+NWQivO4DsXyqwVDa3fQogg1HU0/+ySRP8uW287\r
+A7bVyfA4izK41MyAvf1HxeEArFVgeHnEDo3tiq+dkwh617fHSBUaP+gikrYIrZI/\r
+gMEySHW2zrpFAzrLCtCVmoB3HBVklKYoYg9mP5evVLuhi5J4nyDrI1h8UEIB9/YF\r
+LXL/WZYXuYwu8W8kvctaChBr8ZskigKVoJxDRgXkMIhr2B6Wb8lZtNgJd7PZXODL\r
+ocHgmCBuyM4l8yYxI8xSgqCsisHdWolHK4G6b3VNNrYrLiOSL8mvy9FL8Z6AKVnV\r
+sjegRh+KOt98A6BEvPb+IgXjA4zRMqiJLdx0Am3Q1+6/WeR7RRb7nG8KknV+1vPB\r
+ADgPhPx6UqrAFdaQwvzD0dok1cexguWMW0aJhtX5rrbi8svtWbUviLkGWkoW/b/9\r
+hUAZakrwurjSmoGymxvudqwK9jC2WNUmAchVQwO+wswgOzNwHBXcEUk/q9SVYSQp\r
+IvPocH8LZVWPPLRZysx7d7NeVg2kQaWi8NhIeLhl4+Wfog26KNhJkTPdWUiIx0zB\r
+BFScyp/R6p1/TEIUhwhO\r
+=Gfji\r
+-----END PGP SIGNATURE-----\r
+\r
+------enig2MIIXRHDXVCQPLPPLEHDU--\r