Page MenuHome GnuPG

Kleopatra: invalid S/MIME certificates are offered for encryption
Closed, ResolvedPublic

Description

Invaild S/MIME certificates are offered for encryption in Kleopatra. This then correctly results in an error message when trying to encrypt.

Expected: That the invalid certificate is not offered in the first place, since encryption with t is not possible anyway.

Details

Version
VSD 3.1.24

Event Timeline

aheinecke triaged this task as Wishlist priority.Sep 26 2022, 9:36 AM
aheinecke added a subscriber: aheinecke.

This is because Kleopatra does not differentiate between invalid S/MIME and unverified OpenPGP certificates and we want to be able to encrypt to unverified OpenPGP certificates.

Still this should be changed. I am setting it as wishlist because it was never different.

ikloecker changed the task status from Open to Testing.Nov 14 2022, 1:54 PM
ikloecker moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.
ikloecker added a subscriber: ikloecker.

It should no longer be possible to choose invalid S/MIME certificates as signing or encryption keys via the drop-down boxes or the input field. (The key selection dialog still offers all certificates.)

ebo claimed this task.

yes, confirmed. And if I insist on choosing this certificate via the selection dialog I can not encrypt to this certificate, as sign/encrypt is grayed out. (As long as there is no valid key chosen additionally.)

ebo moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.Apr 5 2023, 2:59 PM