Consider adding hkps://mail-api.proton.me to the default key server list
Categories
(MailNews Core :: Security: OpenPGP, enhancement)
Tracking
(relnote-thunderbird +, thunderbird_esr140 wontfix, thunderbird152 wontfix, thunderbird153 fixed)
People
(Reporter: mkmelin, Assigned: mkmelin)
References
(Blocks 2 open bugs)
Details
Attachments
(2 files)
See https://proton.me/blog/address-verification-pgp-support
We should consider adding hkps://mail-api.proton.me to the default keyserver list
| Assignee | ||
Updated•19 days ago
|
Updated•19 days ago
|
| Assignee | ||
Comment 1•14 days ago
|
||
Comment 2•14 days ago
|
||
I think this is unnecessary, because Proton also hosts their keys on WKD, and we already query WKD.
Can you please check? Even without your patch, Thunderbird should already be able to find keys for proton mail users.
| Assignee | ||
Comment 3•13 days ago
|
||
Well, duplication of key source is not necessarily bad. There are some benefits:
- "Refresh Online" doesn't use WKD, so refreshing for a Proton user won't work atm. xref bug 1735033.
- you get multiple sources (for upcoming confidence work)
- for future "trust keyserver" that's not possible if I have to trust WKD, which would seem somewhat less safe
Actually seems our wkd for proton isn't really what it should be either... https://searchfox.org/comm-central/rev/99bc428ec6be3c5bad4b5986765655ecf5bc1e47/mail/extensions/openpgp/content/modules/wkdLookup.sys.mjs#305-324
| Assignee | ||
Updated•13 days ago
|
Comment 4•4 days ago
|
||
Besides bug 2047358 the new implementation works with all the example email addresses that I have tested.
Updated•3 days ago
|
| Assignee | ||
Updated•3 days ago
|
Pushed by martin@humanoids.be:
https://hg.mozilla.org/comm-central/rev/ffae2ca378aa
Add hkps://mail-api.proton.me to the default key server list. r=kaie
Comment 6•3 days ago
|
||
Is this relnote worthy? Or does the WKD stuff already mostly cover protonmail for recipients without custom domain?
Updated•3 days ago
|
Comment 7•3 days ago
|
||
Pushed by mkmelin@iki.fi:
https://hg.mozilla.org/comm-central/rev/d2a4124c10b6
Follow up to fix keyserver test. r=mkmelin
| Assignee | ||
Comment 10•1 day ago
|
||
Release Note Request (optional, but appreciated)
[Why is this notable]: Better interoperability with Proton mail users.
[Suggested wording]: Added the Proton Mail key server to the default keyserver list. Refreshing the key of a Proton Mail user will now work. We also removed an old, related workaround from before Proton had WKD support. As a consequence, keys for Proton hosted domains can now be found by Thunderbird using WKD.
Updated•1 day ago
|
Description
•