Bug 136205 - Kwallet and KGPG, revisited
Summary: Kwallet and KGPG, revisited
Status: RESOLVED FIXED
Alias: None
Product: kdelibs
Classification: Frameworks and Libraries
Component: kwallet (show other bugs)
Version: 1.1
Platform: Debian testing Linux
: NOR wishlist
Target Milestone: ---
Assignee: kdelibs bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2006-10-23 22:15 UTC by Sidney N Kahn
Modified: 2014-01-18 14:10 UTC (History)
2 users (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sidney N Kahn 2006-10-23 22:15:53 UTC
Version:           1.1 (using KDE KDE 3.5.5)
Installed from:    Debian testing/unstable Packages
OS:                Linux

I would like to re-examine the idea of using the kwallet system with KGPG.  This issue has been touched on in the bugs:
Bug 75693: kwallet should be used to store passphrases
Bug 81067: using kwallet as an ssh-agent

As of the writing of this report the second bug was still open, while the first had been closed as WONTFIX.  Bug 75693 was closed not by the package's maintainer but by another developer who works primarily on kmail, not kgpg or kwallet.  As for this developer's reasoning behind his decision, I see no factual argument against the addition of this feature in kwallet*.  This developer claims the use of kwallet to supply the gpg-agent passphrase as a security risk, yet it is not clear how this is so, considering the entire purpose of the kwallet system is to securely store such data and provide them to applications upon request.
An option that may satisfy all parties might be the use of a separate "kgpg" wallet used and opened exclusively by kgpg, as opposed to the default "kdewallet", so that the compromise of the main wallet does not expose gpg key passphrases or secret keys.
If possible, I request that the maintainers of kgpg and/or kwallet consider the addition of the capability to store passphrases and/or keys using the kwallet system.

*For the record, my wallets do not contain eggs of any kind, nor do I seem to have the option of inserting them.
Comment 1 Mathias Homann 2007-01-09 17:13:40 UTC
i think the idea in #75693 was the other way around, encrypt wallets with gpg before storing them on disk... which i would want as well.