Page MenuHome GnuPG

Kleopatra: Indicate CRL check failure when validating certificates
Open, NormalPublic

Description

A common problem with S/MIME is that CRL checks fail. While we have a very good status indicator of this in the verification result of Kleopatras file decryption dialog (HTML Audit log) there is no such indication in the keylist. Not even in the certificate details. This makes support a bit more difficult.

It would be great if we could somehow indicate instead of "Invalid" for an S/MIME intermediate or Leaf certificate "CRL Error" or something like that to point users in the right direction.

Event Timeline

aheinecke triaged this task as Normal priority.Jun 2 2023, 10:06 AM
aheinecke created this task.

I had a brief look at this. I don't think there's a way currently to convey "CRL Error" via a keylist result to gpgme. The --with-colons format would probably need to be extended.