• [gentoo-user] Open PGP signatures on Thunderbird

    From Julien Roy@21:1/5 to All on Fri Jun 17 03:40:01 2022
    Hello list,

    I recently configured Thunderbird to digitally sign my emails using my
    GnuPG key. It seemed to be working fine with the tests I made to my
    other email address, however, I noticed an email I sent to this list was unreadable from the archive [0]. Therefore, I assume something is wrong
    with my setup since, from my understanding, nothing special is required
    from the receiver's side to read signed (and not encrypted) messages.

    Does anyone else on this list use Thunderbird with OpenPGP signatures
    that could help me figure out why this is happening? The configuration
    on Thunderbird is rather straight forward some I'm not sure what I
    could've done wrong.

    Do receivers have to accept/add my signature (which attaches itself to
    my emails by default) before they can view my messages?

    Strangely, the Gentoo User list archive has a small button at the button
    "Find on MARC"; when I click this, my email is readable just fine [1].
    This would indicate that perhaps the Gentoo archive isn't configured to
    handle signatures, however I am not the only one on this list who signs
    their emails, and other signed emails are readable just find on the
    Gentoo archive.

    Thanks,
    Julien


    [0] https://archives.gentoo.org/gentoo-user/message/1664f7907141dd782fc7f469baf7de83
    [1] https://marc.info/?l=gentoo-user&m=165525962832464

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Michael@21:1/5 to All on Fri Jun 17 09:22:24 2022
    On Friday, 17 June 2022 02:38:38 BST Julien Roy wrote:
    Hello list,

    I recently configured Thunderbird to digitally sign my emails using my
    GnuPG key. It seemed to be working fine with the tests I made to my
    other email address, however, I noticed an email I sent to this list was unreadable from the archive [0]. Therefore, I assume something is wrong
    with my setup since, from my understanding, nothing special is required
    from the receiver's side to read signed (and not encrypted) messages.

    I have been able to read your emails and signature, with Kmail, but the
    archive would use a different parser which it seems does not like the format of your signed message.


    Does anyone else on this list use Thunderbird with OpenPGP signatures
    that could help me figure out why this is happening? The configuration
    on Thunderbird is rather straight forward some I'm not sure what I
    could've done wrong.

    I don't have a signed message of yours available to examine its structure.
    You can check your Thunderbird's OpenPGP format to determine if the 'Content- Type' in the headers of the message is binary, or ASCII and if the signature
    is attached or embedded. I'm guessing the archive may have problems with binary. An attached ASCII signature works here.


    Do receivers have to accept/add my signature (which attaches itself to
    my emails by default) before they can view my messages?

    No, the receiving mail client application should deal with signature verification automatically and warn the receiver if the signature signing party's key is not trusted. The receiver would not normally manually alter
    the trust status of a sender's public key, unless the identity of the sender and his corresponding key fingerprint can be verified off-line.


    Strangely, the Gentoo User list archive has a small button at the button "Find on MARC"; when I click this, my email is readable just fine [1].
    This would indicate that perhaps the Gentoo archive isn't configured to handle signatures, however I am not the only one on this list who signs
    their emails, and other signed emails are readable just find on the
    Gentoo archive.

    Thanks,
    Julien


    [0] https://archives.gentoo.org/gentoo-user/message/1664f7907141dd782fc7f469baf7 de83 [1] https://marc.info/?l=gentoo-user&m=165525962832464

    I expect different mailing list managers use different parsing code and the archive discriminates against the format of the signed messages your T'bird is posting.

    If you prefer you can send me a message off list and I can check its structure at the receiving end.
    -----BEGIN PGP SIGNATURE-----

    iQIzBAABCAAdFiEEXqhvaVh2ERicA8Ceseqq9sKVZxkFAmKsOcAACgkQseqq9sKV ZxkT7A//e/Sw48gJbP+ubmToG8YAQfuBptmaILr16iaUC8D6hD8I2I/TskKIYhJL 59o5vrINgRl4Fi76bElLVIzdwUWiMKr0Uwk9p7ugqR1vKRySb/UxcLrXdF4LKPk1 mnB9dtJJDnSddaFBxm+g0C6QUIQGnqpFSUqWUDTFMgGGj9ysYkmwIzvfeHUfB4XT 1RPa6h0jJEJ5TDWkTL9+IeHylTLLeImodhMckLkid/v5SsOj6hEjl6RUpYj/1gfn gaSCMxe7c0gncrrc79EjsN2ZCPtlUcPAMskoYjY1D44Agzz/0cTkgx1g5KVQUgjC GEUV4wEaslA+IT+4lbcgPRHWamM6agozvLSNh45rT0h1cOXwpC61rHsk8Zm9iOr2 v7S4aopXm3saHCW09KscNls6oCxGv4cWBW7gq/7zl3MjmYl4+vJkYyFUu4aWCYtn 6duMvjH8WptgYIR0IhUeS+562bLNvYohuxzFpnZ+n7xqnB45apa10yZsFGJ+7lxc 34FFgOU7XUZCY4GTDhhaR/GUz+eoZtzg/q7mekQ43UkNA450OHcE89OS9V9xlciF 01umqacGqQrUXq4eWCjTzHW5/i+A0dN64+8SxhhSSGzv+op2EK5200BEsKvPU+LE WOESLcrQgwBPGp8jBGSQEHf/zGcRkSLAVt9XD73lWt43OS5v314=
    =zoyC
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)