Closed Bug 1698391 Opened 5 years ago Closed 4 years ago

OpenPGP lacks UI to refresh keys

Categories

(MailNews Core :: Security: OpenPGP, defect, P2)

defect

Tracking

(thunderbird_esr91 wontfix, thunderbird101 fixed)

RESOLVED FIXED
102 Branch
Tracking Status
thunderbird_esr91 --- wontfix
thunderbird101 --- fixed

People

(Reporter: krakonos, Assigned: KaiE)

Details

(Whiteboard: [nf-89])

Attachments

(1 file)

User Agent: Mozilla/5.0 (X11; Linux x86_64; rv:86.0) Gecko/20100101 Firefox/86.0

Steps to reproduce:

TB does not support refreshing expired OpenPGP keys (or I have not found any reasonable way in OpenPGP Key Manager dialog). Even discovering my own key again (by manually typing email address/fingerprint) only displays the dialog of the key stored in TB, not the updated one. Deleting and discovering the key again works, but is cumbersome for my own private key (that I have extended on another machine through gnupg).

Expected results:

  1. The UI should have a "Refresh key" option.
  2. Re-discovering a key manually should allow me to import a new signatures to extend the expiration date.
Component: Security → Security: OpenPGP
Product: Thunderbird → MailNews Core

Agreed. Refreshing will be improved in bug 1751885.
Let's use this bug to track a refresh UI.

Status: UNCONFIRMED → NEW
Ever confirmed: true

I think this needs a high priority and is also simple to do.

I suggest two places:
(1) in the key properties dialog, add a button "refresh", which searches online for an updated copy of this particular key, (by fingerprint)

(2) in the openpgp key manager, the same action should be triggered from a menu item, for the selected single or multiple keys.

I suggest to get this done within the next few weeks.

Severity: -- → S3
Priority: -- → P2
Assignee: nobody → kaie
Whiteboard: [nf-89]

Also, if a key was refreshed and imported, we should give feedback.
Currently, if we use OpenPGP key manager, discover keys online, and enter the ID of a key that we already have, and we find an update and merge it, we don't get any UI feedback.

I thought I'd briefly add strings, as an advance preparation...

But then I decided I need to check what feedback we currently give.
And I found inconsistencies.
And I decided to quickly fix them.
In the end I spent more hours on this as I wanted, but I think it's worth it, this is an important feature to have.
Patch upcoming.

In line 103 should not be it if (keyList && keyList.length > 1) analog to line 55 if (keyList && keyList.length == 1) ?
(Sorry I do not have permission to make inline comments in Phabricator)

(In reply to Arvidt from comment #6)

In line 103 should not be it if (keyList && keyList.length > 1) analog to line 55 if (keyList && keyList.length == 1) ?
(Sorry I do not have permission to make inline comments in Phabricator)

No this code only works verifying keyservers that return either zero or exactly one match.

Whiteboard: [nf-89]

(adding back nf-89 whiteboard , for posterity, if one ever goes through the list)

Whiteboard: [nf-89]

Pushed by kaie@kuix.de:
https://hg.mozilla.org/comm-central/rev/25de6d52888b
Allowing refreshing an OpenPGP key. r=mkmelin

Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → FIXED

Comment on attachment 9274849 [details]
Bug 1698391 - Allowing refreshing an OpenPGP key. r=mkmelin

let's test functionality intended for 102 in beta

Attachment #9274849 - Flags: approval-comm-beta?

Comment on attachment 9274849 [details]
Bug 1698391 - Allowing refreshing an OpenPGP key. r=mkmelin

[Triage Comment]
Approved for beta

Attachment #9274849 - Flags: approval-comm-beta? → approval-comm-beta+
Target Milestone: --- → 102 Branch
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: