Kleopatra: invalid S/MIME certificates are offered for encryption
Closed, ResolvedPublic

Assigned To
Authored By
• ebo
Sep 22 2022, 9:29 AM
Tags

Description

Invaild S/MIME certificates are offered for encryption in Kleopatra. This then correctly results in an error message when trying to encrypt.

Expected: That the invalid certificate is not offered in the first place, since encryption with t is not possible anyway.

Details

Version
VSD 3.1.24

Event Timeline

• aheinecke triaged this task as Wishlist priority.Sep 26 2022, 9:36 AM
• aheinecke added a subscriber: • aheinecke.

This is because Kleopatra does not differentiate between invalid S/MIME and unverified OpenPGP certificates and we want to be able to encrypt to unverified OpenPGP certificates.

Still this should be changed. I am setting it as wishlist because it was never different.

• ikloecker changed the task status from Open to Testing.Nov 14 2022, 1:54 PM
• ikloecker moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.
• ikloecker added a subscriber: • ikloecker.

It should no longer be possible to choose invalid S/MIME certificates as signing or encryption keys via the drop-down boxes or the input field. (The key selection dialog still offers all certificates.)

• ebo claimed this task.

yes, confirmed. And if I insist on choosing this certificate via the selection dialog I can not encrypt to this certificate, as sign/encrypt is grayed out. (As long as there is no valid key chosen additionally.)

• ebo moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.Apr 5 2023, 2:59 PM