RE: S/MIME support
authorJameson Graef Rollins <jrollins@finestructure.net>
Tue, 10 Jul 2012 07:40:03 +0000 (00:40 +1700)
committerW. Trevor King <wking@tremily.us>
Fri, 7 Nov 2014 17:48:07 +0000 (09:48 -0800)
9d/859a1c7eddeeda795e26e48279e7640038ef55 [new file with mode: 0644]

diff --git a/9d/859a1c7eddeeda795e26e48279e7640038ef55 b/9d/859a1c7eddeeda795e26e48279e7640038ef55
new file mode 100644 (file)
index 0000000..458732b
--- /dev/null
@@ -0,0 +1,144 @@
+Return-Path: <jrollins@finestructure.net>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+       by olra.theworths.org (Postfix) with ESMTP id 294AB431E64\r
+       for <notmuch@notmuchmail.org>; Tue, 10 Jul 2012 00:40:18 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -2.29\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-2.29 tagged_above=-999 required=5\r
+       tests=[RCVD_IN_DNSWL_MED=-2.3, T_MIME_NO_TEXT=0.01] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+       by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+       with ESMTP id UW7-ylViczRq for <notmuch@notmuchmail.org>;\r
+       Tue, 10 Jul 2012 00:40:16 -0700 (PDT)\r
+Received: from outgoing-mail.its.caltech.edu (outgoing-mail.its.caltech.edu\r
+       [131.215.239.19])\r
+       by olra.theworths.org (Postfix) with ESMTP id 48C61431FBF\r
+       for <notmuch@notmuchmail.org>; Tue, 10 Jul 2012 00:40:16 -0700 (PDT)\r
+Received: from fire-doxen.imss.caltech.edu (localhost [127.0.0.1])\r
+       by fire-doxen-postvirus (Postfix) with ESMTP id AF55C2E50C9D;\r
+       Tue, 10 Jul 2012 00:40:13 -0700 (PDT)\r
+X-Spam-Scanned: at Caltech-IMSS on fire-doxen by amavisd-new\r
+Received: from finestructure.net (unknown [76.89.192.57])\r
+       (Authenticated sender: jrollins)\r
+       by fire-doxen-submit (Postfix) with ESMTP id 6A7F42E50BDA;\r
+       Tue, 10 Jul 2012 00:40:06 -0700 (PDT)\r
+Received: by finestructure.net (Postfix, from userid 1000)\r
+       id 18F87868; Tue, 10 Jul 2012 00:40:06 -0700 (PDT)\r
+From: Jameson Graef Rollins <jrollins@finestructure.net>\r
+To: "Bryant\, Daniel B." <Dan.Bryant@jhuapl.edu>,\r
+       Notmuch Mail <notmuch@notmuchmail.org>\r
+Subject: RE: S/MIME support\r
+In-Reply-To:\r
+ <24CAA033F4DBCD4DB53CBFB11AEF037C1044F0566F@aplesrepublic.dom1.jhuapl.edu>\r
+References: <1340995101-9616-1-git-send-email-jrollins@finestructure.net>\r
+       <24CAA033F4DBCD4DB53CBFB11AEF037C1044F0566F@aplesrepublic.dom1.jhuapl.edu>\r
+User-Agent: Notmuch/0.13.2+54~ga0426dc (http://notmuchmail.org) Emacs/23.4.1\r
+       (x86_64-pc-linux-gnu)\r
+Date: Tue, 10 Jul 2012 00:40:03 -0700\r
+Message-ID: <87hatgysh8.fsf@servo.finestructure.net>\r
+MIME-Version: 1.0\r
+Content-Type: multipart/signed; boundary="=-=-=";\r
+       micalg=pgp-sha256; protocol="application/pgp-signature"\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+       <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+       <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Tue, 10 Jul 2012 07:40:18 -0000\r
+\r
+--=-=-=\r
+Content-Transfer-Encoding: quoted-printable\r
+\r
+On Mon, Jul 09 2012, "Bryant, Daniel B." <Dan.Bryant@jhuapl.edu> wrote:\r
+> I was able to get signature verification working with your patchset\r
+> (with a caveat) but not decryption.\r
+\r
+Hi, Daniel.  I guess I'm only partially happy to hear that!  I\r
+definitely do appreciate the feedback, though.\r
+\r
+> The caveat is that GMime is still borked with handling signatures with\r
+> content type application/x-pkcs7-signature\r
+> (vs. application/pkcs7-signature, which works fine). This is upstream\r
+> GNOME bug #674032 that was supposed to have been fixed in GMime 2.6.9,\r
+> but that original fix is also broken.\r
+\r
+Ah, I didn't notice that:\r
+\r
+https://bugzilla.gnome.org/show_bug.cgi?id=3D674032\r
+\r
+Encouragingly, it sounds like Jeffery is working on it.\r
+\r
+> One possible workaround is to twiddle the content-type of the\r
+> signature part (and the corresponding protocol in the multipart/signed\r
+> part). I implemented this by looping over each message part in\r
+> mime_node_open() and modifying as necessary using the following logic:\r
+>\r
+>\r
+>     GMimeContentType *content_type =3D g_mime_object_get_content_type (pa=\r
+rt);\r
+>\r
+>     const char *subtype =3D g_mime_content_type_get_media_subtype (conten=\r
+t_type);\r
+>     const char *protocol =3D g_mime_content_type_get_parameter (content_t=\r
+ype, "protocol");\r
+>\r
+>     if (!strcmp(subtype, "x-pkcs7-signature")) {\r
+>         g_mime_content_type_set_media_subtype (content_type, "pkcs7-signa=\r
+ture");\r
+>     }\r
+>\r
+>     if (protocol && !strcmp(protocol, "application/x-pkcs7-signature")) {\r
+>         g_mime_content_type_set_parameter (content_type, "protocol","appl=\r
+ication/pkcs7-signature");\r
+>     }=20=20=20=20\r
+\r
+We could do this, but I would certainly prefer that we fix gmime to\r
+handle both types properly.\r
+\r
+> All of my S/MIME encrypted mail consists of single part messages with\r
+> content-type "application/x-pkcs7-mime". These conform to RFC3851,\r
+> section 3.3/3.4. (sample messages are included in the RFC as\r
+> well). This fails to be decrypted by notmuch because the mime node\r
+> traversal code assumes that every encrypted message is\r
+> multipart/encrypted, which appears to only be true for PGP/MIME.\r
+\r
+Thanks for the great example of why we need tests!\r
+\r
+Would you (or anyone) be willing to start putting together some tests\r
+that include messages encrypted according to this RFC?  I think adding\r
+some tests to the test/crypto script would be a great place to start.\r
+\r
+jamie.\r
+\r
+--=-=-=\r
+Content-Type: application/pgp-signature\r
+\r
+-----BEGIN PGP SIGNATURE-----\r
+Version: GnuPG v1.4.12 (GNU/Linux)\r
+\r
+iQIcBAEBCAAGBQJP+9xTAAoJEO00zqvie6q8V+EP/jhoBnmPDq9Y9ZdFjaB2dUoz\r
+8ywPcDyBsWHOKTMqlhoh2j9POOJkHR6lMQEekAjfJxpfTTqBvVDtGKXH5fzWZKwT\r
+giVaS6aCZeeFxjZU0y7iKHRsbjemeSv/9dv0FpHxMt4hEcNsduRLx89+xfARhRmg\r
+jcLwTjAAaSVTIJagElvImZLxLr3URUptRDN+x590PylA3ZeM0mLf5mlMdem72cT9\r
+jepcYQLxg4p1v/d2Tz68n9JmqOqH0bX/Aq5A0NJ9aKP1rxyJsSM3cXPqGNRccK8Q\r
+RUVmCVTTgmOCFvI17cLTSd8gP9ikJ6P5ZZmsL5PmuyfjbctY5m6Y8mYEO636s62J\r
+RrEuPoZV1UjrmIVR9dmsASfB/j8wKkMvlRzaMrdmcOl2wHzI47VdCVT51lf2Tpib\r
+J3LqwIvcqqHN+qhVkvBlCtX4xz+cwwZxJMapg9W3Q53QKh/RowH4dzxCe+Catudg\r
+G3hMBkaBOGNe2tEGEvxgDTyE2pmFCNkkM9eAKyvn2wqtsX3ACEajvkFsyC4y6A0c\r
+wapKavsimz3AKpYypFcqHsSoGbFKghqzEitqIjXXZRDWkxTa6Kohk9Newlwj9nW0\r
+arejsCUrYkPeHeOkFVVKapKczfOdVOaaNLApOnd6jefy0aZh7ce8wHQjiMyzW81P\r
+bvU7UZ/zFWSkdsU4sHIM\r
+=35NF\r
+-----END PGP SIGNATURE-----\r
+--=-=-=--\r