Re: Emacs not finding keys to verify signatures
authorDaniel Kahn Gillmor <dkg@fifthhorseman.net>
Fri, 28 Jun 2013 15:13:14 +0000 (11:13 +2000)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:55:46 +0000 (09:55 -0800)
ac/609b2734a9d73c39c9eed9c348376634a505b8 [new file with mode: 0644]

diff --git a/ac/609b2734a9d73c39c9eed9c348376634a505b8 b/ac/609b2734a9d73c39c9eed9c348376634a505b8
new file mode 100644 (file)
index 0000000..e7871f4
--- /dev/null
@@ -0,0 +1,129 @@
+Return-Path: <dkg@fifthhorseman.net>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 17FF7431FBD\r
+       for <notmuch@notmuchmail.org>; Fri, 28 Jun 2013 08:13:27 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: 0\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=0 tagged_above=-999 required=5 tests=[none]\r
+       autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id 8cg-SO+y2RnT for <notmuch@notmuchmail.org>;\r
+       Fri, 28 Jun 2013 08:13:19 -0700 (PDT)\r
+Received: from che.mayfirst.org (che.mayfirst.org [209.234.253.108])\r
+       by olra.theworths.org (Postfix) with ESMTP id E6FE6431FB6\r
+       for <notmuch@notmuchmail.org>; Fri, 28 Jun 2013 08:13:18 -0700 (PDT)\r
+Received: from [192.168.23.229] (dsl254-070-154.nyc1.dsl.speakeasy.net\r
+       [216.254.70.154])\r
+       by che.mayfirst.org (Postfix) with ESMTPSA id B6901F979;\r
+       Fri, 28 Jun 2013 11:13:16 -0400 (EDT)\r
+Message-ID: <51CDA80A.9050700@fifthhorseman.net>\r
+Date: Fri, 28 Jun 2013 11:13:14 -0400\r
+From: Daniel Kahn Gillmor <dkg@fifthhorseman.net>\r
+User-Agent: Mozilla/5.0 (X11; Linux x86_64;\r
+       rv:17.0) Gecko/20130518 Icedove/17.0.5\r
+MIME-Version: 1.0\r
+To: David Bremner <david@tethera.net>\r
+Subject: Re: Emacs not finding keys to verify signatures\r
+References:\r
+ <87sj07a72g.fsf@thinkpad.i-did-not-set--mail-host-address--so-tickle-me>\r
+       <87sj028ovv.fsf@zancas.localnet> <87ehbmpeg5.fsf@mbp.dbpmail.net>\r
+       <87zjua9sxi.fsf@convex-new.cs.unb.ca>\r
+In-Reply-To: <87zjua9sxi.fsf@convex-new.cs.unb.ca>\r
+X-Enigmail-Version: 1.5.1\r
+Content-Type: multipart/signed; micalg=pgp-sha512;\r
+       protocol="application/pgp-signature";\r
+       boundary="----enig2OHGJQORHRDAFGBXAMMAP"\r
+Cc: notmuch@notmuchmail.org\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Fri, 28 Jun 2013 15:13:27 -0000\r
+\r
+This is an OpenPGP/MIME signed message (RFC 4880 and 3156)\r
+------enig2OHGJQORHRDAFGBXAMMAP\r
+Content-Type: text/plain; charset=UTF-8\r
+Content-Transfer-Encoding: quoted-printable\r
+\r
+On 06/28/2013 11:05 AM, David Bremner wrote:\r
+> Daniel Patterson <dbp@dbpmail.net> writes:\r
+>=20\r
+>> One thing I forgot to mention - I have notmuch running on a remote\r
+>> server through ssh. I don't really imagine this would be an issue, but=\r
+\r
+>> maybe? (I also have the library installed locally, for emacs).\r
+>=20\r
+> The verification of the message happens in the notmuch CLI, so on the\r
+> the remote host. I guess the downloading is happening on the local host=\r
+,\r
+> so that is quite possibly the problem.\r
+\r
+i'm quite sure this is the problem, that was a relevant bit of info to\r
+include :)\r
+\r
+Daniel: on your remote host, have you tried fetching the relevant keys\r
+into your gpg keyring?  you don't need to create any secret key material\r
+on the remote host, just fetch the keys as you normally would any other\r
+user's public key material; then you'll want to mark your own key as\r
+"ultimately" trusted on the remote host.\r
+\r
+So, for example, on the remote host:\r
+\r
+ gpg --keyserver ha.pool.sks-keyservers.net --recv\r
+0x36EEAD9EA53D20B79C383EED2747EC48A98D4AF0\r
+\r
+ gpg --edit-key 0x36EEAD9EA53D20B79C383EED2747EC48A98D4AF0 trust\r
+\r
+you'll want to maintain this public keyring on that host to be able to\r
+verify the messages, but you don't need to do anything else with it.\r
+\r
+this makes me wonder if the actions that get triggered on those\r
+"unverified" crypto buttons in the display interface need to be\r
+customizable to send the commands to a remote gpg as well, instead of\r
+assuming that they are local.\r
+\r
+please report back with how that works for you!\r
+\r
+       --dkg\r
+\r
+\r
+------enig2OHGJQORHRDAFGBXAMMAP\r
+Content-Type: application/pgp-signature; name="signature.asc"\r
+Content-Description: OpenPGP digital signature\r
+Content-Disposition: attachment; filename="signature.asc"\r
+\r
+-----BEGIN PGP SIGNATURE-----\r
+Version: GnuPG v1.4.12 (GNU/Linux)\r
+Comment: Using GnuPG with Icedove - http://www.enigmail.net/\r
+\r
+iQJ8BAEBCgBmBQJRzagMXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w\r
+ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFQjk2OTEyODdBN0FEREUzNzU3RDkxMUVB\r
+NTI0MDFCMTFCRkRGQTVDAAoJEKUkAbEb/fpc//MP/RaS0FTtnfPoMxc97/4gUJq2\r
+QmJC7RK/uES6Vdmg+/LrykkU3a6085u5QwWM3ZzdUJYLUgveCb/bMHAGS3tKTxoy\r
+P2lHBwv5K+OQc+yoiciWQhq6DT0YsvQEM3v51QI+43MQmomqIN2UU7x2L7wveAfX\r
+hV1DtKy7WkWV11GKn7c28LoiUQTcWJPHkTBxuHddgwf1SEpWu+YJ8rAg60DqIJzZ\r
+CDPhHzO1Rk96drTvXll5KFGOIl7deEOWd4N5bmiwnfSvoxf56B2aGoIbaQ8M1NWS\r
+h4SWVIYIvPbO6CwbIJw9wlEZZtTEGtKqjQBmoq47gLqSNmFO6whdlUm1OeqZz+Qe\r
+ElY9UZeEk17ipWi9L1YkwHArxPKrZ0w4ctbfwTc7Ja3O5GgF9EcGMWNlamWhCi7X\r
+34dGjthCJExVkIo7uBDyjI+HkQCIOl0+at4Oc88aRF6hCz3hETxYl6G/RKAzawd+\r
+OOVfkKGefUYyJ1z1VGUyCp/m3MVd7V+U7h4RTKVo/OV1PubNdZUGDfpR60i0PYeB\r
+bnQNyDnlqdxfjLBBbxzrhr/MojmDDftAEHxH7dqfq7w/cwo5wy85fK8HGdvill9f\r
+22sOJpo0pW/l1LXwVYfQ7LDYHvAewouEugczqcucOnPqu4g7JlY+aiAcbDwrvCt9\r
+2QpktiEAWTQvYcPI488V\r
+=ZtS/\r
+-----END PGP SIGNATURE-----\r
+\r
+------enig2OHGJQORHRDAFGBXAMMAP--\r