GpgOL is an Outlook Add-In for Outlook 2010 and later. However, it won't work with the future Outlook which will come without MAPI support. We are going to replace that Add-In by the new gpgol2 .
Details
Thu, Nov 27
Additionally to the issue Andre cited years ago, we also did some changes to fix other how signed/encrypted mails are shown, which are also relevant for the inbox. This should be fixed.
This is a duplicate of T7833: GpgOL: Security level 2 shown for manually imported and certified cert
Ok, then this is only an issue in the VSD versions. (I confirmed with a quick test with Gpg4win-5.0.0-beta413)
Wed, Nov 26
Good catch. My guess is that get_uid_for_sender returns the last matching UID without checking for revocations. The matching was done on the mailbox part only. For reference:
Tue, Nov 25
I can't reproduce this on gpg4win-5.0.0-beta413 @ win11.
This seems to apply only for non vsd compliant algos. Importing and certifying a
- rsa/brainpool cert results in security level 4
- cv25519 cert results in security level 2
I rechecked: the revoked userid has to match the email address of the sender. Still there's another non revoked userid with the same email address:
Do you mean one of the user-ids has been revoked or the one matching the mail sender?
Mon, Nov 24
I wonder if we should better open a new ticket with all the relevant data when we get a report giving more information and set this one to invalid.
And meanwhile I have tested this a bit with VSD3.3.3 and in the case that the sender has a valid and *VS-compliant* key the automatic switching works.
Fri, Nov 21
Looks good to me on gpg4win-5.0.0-beta413 @ win11
Looks good to me on gpg4win-5.0.0-beta413 @ win11

