Problems using OpenPGP that has a name-only user ID (and separate user IDs for email addresses)
Categories
(MailNews Core :: Security: OpenPGP, defect)
Tracking
(Not tracked)
People
(Reporter: KaiE, Unassigned)
Details
I'm moving over a report from bug 1718627 into this new bug.
In bug 1718627 comment 4, 5, 6, dkg reported that the provided key has multiple user IDs, two of them being email addresses, and that it isn't possible to use them all. (Please read those comments for the full details.)
I don't want to mix the discussions, so I'll respond in this new bug.
| Reporter | ||
Comment 1•4 years ago
|
||
(In reply to Daniel Kahn Gillmor from comment #5)
Looking at the
openpgp.sqlitedatabase in the thunderbird profile directory, i'm a little bit surprised to see thatacceptance_decisionjust maps OpenPGP fingerprints to decision levels, butacceptance_emailmaps fingerprints to e-mail addresses. Shouldn't the acceptance decisions map to (fingerprint, e-mail address) tuples instead? I don't understand the data model.
The idea is based on the intention to use a simplified user interface.
We only offer to accept the key with an overall decision.
We don't offer separate acceptance decisions per user ID.
To avoid that we accept the key for an email address that the user wasn't aware of, we remember which email address the user has seen, at the time we asked for acceptance.
This means, should we later receive an updated version of the key with an additional email address, the additional email address won't be accepted (but ignored), because there is no acceptance_email record yet. (Currently, the only way to fix that is to mark the key as not accepted, then mark it as accepted again.)
This currently leads to a discrepancy in the user interface (the user has no way to see which email addresses are ignored). I'd like to fix that in the near future in bug 1755281).
| Reporter | ||
Comment 2•4 years ago
|
||
(In reply to Daniel Kahn Gillmor from comment #4)
I'm seeing similar behavior with the attached
dkg.gpgpublic key, running thunderbird on debian, version 1:91.7.0-2.This OpenPGP certificate contains three identities with the User ID "split out":
Daniel Kahn Gillmor(my human-friendly name)<dkg@fifthhorseman.net>(one e-mail address i use)<dkg@debian.org>(another e-mail address i also use)
I cannot reproduce the failure you're describing.
You said that you are using a fresh profile, importing the attached public key, mark it as verified, and then fail to send the email.
In a fresh profile, you cannot send encrypted email until you have configured an email account, and configured a personal/private key for that email account. Did you do that?
| Reporter | ||
Comment 3•4 years ago
|
||
Here is what I did test:
- used 91.7.0 on linux
- fresh profile
- setup email account
- created new key in account settings
- opened key manager
- file import public key, selected your dkg.gpg attachment
- get prompted to import your key, both email addresses shown
- selected "not accepted", ok
- in key manager, found your key listed, double clicked, in the details I selected "yes, verified", ok
- compose email to first email, encrypt, send later -> works
- compose email to second email, encrypt, send later -> works
| Reporter | ||
Comment 4•4 years ago
|
||
Daniel, can you still reproduce with Thunderbird 91.8.1 ?
Comment 5•4 years ago
|
||
I can confirm that the specific steps from comment 3 allowed me to send two encrypted messages, one to each e-mail address from the dkg.gpg key file, using thunderbird 91.8.1 in debian's 1:91.8.1-1 package.
I can't say that i actually understand why as a user I would click "not accepted" and then dig up the same key in the key manager and click "yes, verified". I don't even understand the distinction between those choices. are those necessary steps to use the key?
What am i supposed to do if i find a key that has two e-mail addresses on it and i have only verified one of them?
| Reporter | ||
Comment 6•4 years ago
|
||
(In reply to Daniel Kahn Gillmor from comment #5)
I can't say that i actually understand why as a user I would click "not accepted" and then dig up the same key in the key manager and click "yes, verified".
You don't have to click "not accepted". It should work fine, too, if you immediately click on "accept" during import.
If you do this, you aren't required to dig up the key in key manager afterwards. Only if you want to verify them. Also, immediately after import we should the old Enigmail prompt that lists all the imported keys, that's another place where you can immediately go to the details of the imported keys and change acceptance, if desired.
I don't even understand the distinction between those choices. are those necessary steps to use the key?
If you select "accept" in the initial import screen, you are immediately able to use the key.
What am i supposed to do if i find a key that has two e-mail addresses on it and i have only verified one of them?
Thunderbird 102 release will have new UI for that, bug 1755281.
Description
•