GpgOL: Mark level 2 and 3 in a clearly different way
Closed, ResolvedPublic

Assigned To
Authored By
• ebo
Apr 9 2024, 9:27 AM
Tags

Description

The presentation of security levels 2 and 3 is very similar at present. This should be improved in a way which is easy to perceive at a glance.

Level 2 should get a different color, like yellow.
And a different icon would be good, too. I propose to only change the background of the check mark icon to yellow, too.

Edit 2020-03-21: it was decided to show level 3 by an additional check mark only.

Revisions and Commits

Event Timeline

• ebo triaged this task as High priority.Apr 9 2024, 9:27 AM
• ebo created this task.
• aheinecke lowered the priority of this task from High to Normal.Apr 9 2024, 9:47 AM
• aheinecke removed a project: vsd33.
• aheinecke removed Version.

For VSD I somewhat agree since this is the difference between a VD Compliant signature. For the community edition though level 2 is usually enough and should also be indicated as trustworthy. So I am currently in two minds about this.

Yellow indicates a warning. In the old days we used yellow in too many cases and people barely got a green. This raised more user questioned than it was helpful. There is also a problem with accessibility if we overload colors too much.

I can imagine a double check mark for level 3 for a large icon or even in the text line (similar to what is used by Conversations et al.)

• werner mentioned this in Unknown Object (Phriction Wiki Document).Sep 26 2024, 3:35 PM
mmontkowski changed the task status from Open to Testing.Mar 20 2025, 2:09 PM
mmontkowski added a project: vsd33.
mmontkowski moved this task from Backlog to WiP on the vsd33 board.
• ebo moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.

In version Version VS-Desktop-3.3.0.0 a certificate imported via WKD is correctly shown as level 2 security:

After certification with one of my own keys it should be shown als level 3 AFAIK but it stays level 2. Even after restarting Kleopatra, its background processes and Outlook.

I'll have to check this with a VS-NfD compliant certificate, too, the one I used here is not.

And I'll have to check whether the fix for the icon is really included in this build and this might be a new bug introduced by it or what else causes this / triage when this might have been introduced.

with Version VS-Desktop-3.3.90.6-Beta:

The new Icon is included but I only saw it for a few seconds, now the security level is displayed wrong again as level 4, after I clicked on an other Mail an then back again.

The setup where a certificate should be shown as level 3 is:

  • mail signed by certificate A
  • certificate A is certified by certificate B, which has ownertrust full. It *is not* certified by any of the secret keys in the testkeyring.
• ebo moved this task from Backlog to Done on the gpgol board.
• ebo edited projects, added vsd33 (vsd-3.3.1); removed vsd33.

After further testing:
The new level 3 icon is shown for most test cases. This ticket here is only for the new icon, therefore I'm setting this to done. I'll make a new ticket for the cases where the level is not detected correctly.

• ebo moved this task from Restricted Project Column to Restricted Project Column on the Restricted Project board.Apr 7 2025, 11:57 AM
• ebo mentioned this in Unknown Object (Maniphest Task).Apr 15 2025, 5:07 PM