--- /dev/null
+Return-Path: <jani@nikula.org>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id 22C2B431FBC\r
+ for <notmuch@notmuchmail.org>; Sat, 30 Aug 2014 00:37:53 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -0.7\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-0.7 tagged_above=-999 required=5\r
+ tests=[RCVD_IN_DNSWL_LOW=-0.7] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id szU4BsqmIMFp for <notmuch@notmuchmail.org>;\r
+ Sat, 30 Aug 2014 00:37:48 -0700 (PDT)\r
+Received: from mail-wg0-f41.google.com (mail-wg0-f41.google.com\r
+ [74.125.82.41]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (No client\r
+ certificate requested) by olra.theworths.org (Postfix) with ESMTPS id\r
+ 8E743431FB6 for <notmuch@notmuchmail.org>; Sat, 30 Aug 2014 00:37:48 -0700\r
+ (PDT)\r
+Received: by mail-wg0-f41.google.com with SMTP id l18so3031607wgh.0\r
+ for <notmuch@notmuchmail.org>; Sat, 30 Aug 2014 00:37:46 -0700 (PDT)\r
+X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;\r
+ d=1e100.net; s=20130820;\r
+ h=x-gm-message-state:from:to:subject:in-reply-to:references\r
+ :user-agent:date:message-id:mime-version:content-type;\r
+ bh=MNet3gcTnl36g+oeRCo0FQmVoD8Ut7RYLMd/dQsgrwQ=;\r
+ b=jcLnt5wmCo1ZbsGsnjxQQrVdVS4eSjsAGB1Oenprphw9LTJZAY9YM7iWC3oXZbWi1c\r
+ VCDX30xhPlySxo+3MYhlNTwnFA4owabxI0zKO9bKtBTNrdOldyfbmKFqEHt7S4cft9gQ\r
+ NhVW98ix12ha4Y9LZGMTnBBQ5FiWsN52DoNuiafg91IF/j7TM/vT2VDyThnwkqzcrm5T\r
+ qZtPOCnbtXfvHWHlmBfKfByX/EMlyfleMexEp1439RyJnMOpaWauFjxsWX0TPkCggCTu\r
+ tbTNwwL1yMDTqz6EgTEZ4CoxpiSV7jtBTZjoHRDugduux183K3Qou+5bQxZT+23rNYqQ\r
+ xvlQ==\r
+X-Gm-Message-State:\r
+ ALoCoQky1g6DsF+GAHKZtbyEfKflskGF8oR7w/DRf22rD9xhXYBzpZKi2/ShSWneTCFEiueIOekh\r
+X-Received: by 10.194.63.205 with SMTP id i13mr18828746wjs.74.1409384265928;\r
+ Sat, 30 Aug 2014 00:37:45 -0700 (PDT)\r
+Received: from localhost (dsl-hkibrasgw2-58c374-75.dhcp.inet.fi.\r
+ [88.195.116.75])\r
+ by mx.google.com with ESMTPSA id dh7sm3258459wib.18.2014.08.30.00.37.44\r
+ for <multiple recipients>\r
+ (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);\r
+ Sat, 30 Aug 2014 00:37:45 -0700 (PDT)\r
+From: Jani Nikula <jani@nikula.org>\r
+To: David Bremner <david@tethera.net>, notmuch@notmuchmail.org\r
+Subject: Re: [Vagrant Cascadian] Bug#759646: notmuch-emacs: switching mode=\r
+ to invalid value sends unencrypted mail\r
+In-Reply-To: <87lhq7npcw.fsf@maritornes.cs.unb.ca>\r
+References: <87lhq7npcw.fsf@maritornes.cs.unb.ca>\r
+User-Agent: Notmuch/0.18.1+65~g9f0f30f (http://notmuchmail.org) Emacs/24.3.1\r
+ (x86_64-pc-linux-gnu)\r
+Date: Sat, 30 Aug 2014 10:37:43 +0300\r
+Message-ID: <87k35q2zso.fsf@nikula.org>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Sat, 30 Aug 2014 07:37:53 -0000\r
+\r
+On Thu, 28 Aug 2014, Vagrant Cascadian <vagrant@debian.org> wrote:\r
+> When sending mail from notmuch-emacs interface, I usually use pgpmine\r
+> signatures, but sometimes I want to send a signed encrypted message, so\r
+> I manually edit the mode=sign to mode=signencrypt ... but if I make a\r
+> typo, i.e. mode=signinvalidencrypt, notmuch happily and without warning\r
+> sends the mail unencrypted.\r
+> \r
+> i.e. #secure method=pgpmime mode=signinvalidencrypt will end up\r
+> sending an encrypted message (with the <>, of course).\r
+> \r
+> It seems like it should error out if the mode= is set to an invalid or\r
+> unknown value, rather than sending mail in the clear.\r
+> \r
+> I've got this set up in ~/.emacs, not sure what all else might be coming\r
+> into play:\r
+> \r
+> '(message-setup-hook (quote (mml-secure-message-sign)))\r
+> '(notmuch-crypto-process-mime t)\r
+\r
+I'm inclined to think this is a bug in message-mode. But we should\r
+probably try to see what we could do to mitigate this.\r
+\r
+As a workaround of sorts, I'd suggest not messing with the #secure tag\r
+manually. Instead, you can use mml-secure-message-sign and\r
+mml-secure-message-sign-encrypt to change the mode.\r
+\r
+BR,\r
+Jani.\r