Details
Fri, Jul 17
I also tested a mail with mixed related/unrelated images, looks fine:
I talked with @mmontkowski:
- the description of the current state above is intended
- the display of the attachment, when the mail is opened the first time, can't be fixed
- the above mentioned issue of a partially unresponsive interface on mails with many/big mail attachments should still be checked, so i create another ticket for it
A pgp signed/encrypted message with drag&drop attachments (no CID i guess) will contain the attachments in an multipart/mixed part:
Looks good to me on gpg4win-5.1.0-beta658 / gpgol-2.7.3-beta11_dd853c7 @ win11:
Looks good to me on gpg4win-5.1.0-beta658 / gpgol-2.7.3-beta11_dd853c7 @ win11:
- The same errors are displayed
- Outlook does not freeze anymore
I assume, it's due to the difference in the mail structure (as displayed in outlook web):
Ok, I think, my tests above might be not valid, as new mails behave differently.
Some comment about what is to be expected would be nice, the last comment T7843: GpgOL: Empty OpenPGP mails with "Read as plain" activated is probably outdated.
Thu, Jul 16
Tested on gpg4win-5.1.0-beta658 / gpgol-2.7.3-beta11_dd853c7 @ win11.
Note: The fix will only apply to new mails, so I consider the old mails invalid now.
I'm retesting with newly created mails, maybe something changed
The original task should be tested with a VSD version but I did a quick check with Gpg4win-5.1.0-beta658 because of:
No change in gpg4win-5.1.0-beta658 / gpgol-2.7.3-beta11_dd853c7 @ win11:
In the keyboxd.log, the key is identified with e (ephemeral) flag and with no revoke flag (-).
2026-07-15 17:26:14 keyboxd[9452] DBG: chan_0x000000000000027c -> S PUBKEY_INFO 2 8D1B205094CF17E0ACB90DFBAA7CAA1F3303534E e- 0 0
@timegrid Thank you for the log. It helps me to identify the bug.
Here is the bug:
https://dev.gnupg.org/source/gnupg/browse/master/sm/keydb.c;0be940905d70125866622c6f53b8d25bde87c21b$1080?as=source&blame=off
Wed, Jul 15
Looks good to me on gpg4win-5.1.0-beta658 @ win11.
Looks good to me on gpg4win-5.1.0-beta658 @ win11
- certificate details (context menu item added, tooltip enhanced)
- certificate list (tooltip enhanced)
Looks good to me on gpg4win-5.1.0-beta658 @ win11:
Without keyboxd, in both versions gpg4win-5.0.2 @ win11 and gpg4win-5.1.0-beta658 / gpg 2.5.21 @ win11, the import works (without the autoimport issue on search).
Debugview output for gpg4win-5.0.2 (with auto import bug):
Issue found on gpg4win-5.1.0-beta658 @ win11:
In short, it looks like the icon change was only applied to separate mail windows, not to mails in the preview pane
We explicitly don't want potentially disastrous low-level card operations like a factory reset to be possible from within Kleopatra.
Instead of disallowing the creation of S/MIME signed archives Kleopatra disallows problematic combinations of the creation of signed and encrypted archives. Reasoning: If one tries to create an OpenPGP-signed and S/MIME-only encrypted archive then one also ends up with an opaquely signed unencrypted archive.
But I wonder anyway if we could a) sometime in the future implement a heuristic to insert a break before an error message if there is not enough space for it or b) only give the filename in these kinds of messages. The path is not important in this case, at least. I'm not sure if the path is important in other cases, too, though.
Allright, set to Wontfix.
@ebo already tested this and the automatic import seems to suppress the import certificate dialog.
All other cases are fine, I'm quite sure the smartcard case would also work as intended.
I'll consider this resolved.
I don't expect it, but it should still be decided, if (some of) the changes should be backported, so I'll leave this issue open.
Summary of this ticket
I suggest to close this ticket. There will always be situations where the layout is suboptimal.
I don't think that Kleopatra can influence that gpg/gpgsm/gpg-agent shows a second pinentry if on the first try a wrong passphrase was entered. Therefore I think the "retry" has to be implemented in GnuPG.
@ikloecker I guess, this issue is not specific to smartcard errors?

