Re: PGP sigs fail verification

Top Page
Attachments:
Message as email
+ (text/plain)
Delete this message
Author: Ian Zimmerman
Date:  
To: mutt-users
Old-Topics: [SPAM?] Re: [SPAM?] Re: OT: Miro's PGP signature [Was: urlview not listing the links right]
Subject: Re: PGP sigs fail verification
This post is mostly just to fix the subject :-P

But this may be a good time to give a very high-level view of the
problem. There are two parts:

1. Some (apparently genuine) mails fail with "BAD signature", _both_
when reading through mutt and when verifying manually with gpg. This is
a bug, not a flea.

It is very strange that in some of these cases, one mail from a person
checks out fine, and the next mail from the same person, sent with the
same MUA according to their X-Mailer header, fails. This makes it less
likely that it is just a gpg version mismatch, but I really don't know
what else to blame. Going through gpg changelogs between my version
(2.0.28) and current tip, nothing jumps out at me.

One special subcase of this so far can be squarely blamed on the sending
side. My next step here is to catalogue the characteristics of the
sending systems, if available.

2. In _one_ case only so far, the same mail checks out with manual gpg,
but mutt gives "BAD signature". This is clearly a flea, but I have no
idea where to look for it. And again, other mails from the same person,
same sending system characteristics, check out fine in mutt as well as
with gpg.

My next step here is probably turning on mutt debug logs, and if nothing
jumps out, adding my own logs to the code.

--
Please *no* private Cc: on mailing lists and newsgroups
Why does the arrow on Hillary signs point to the right?