Bug 343703 - Cannot set the trust level of a signature to ultimate
Summary: Cannot set the trust level of a signature to ultimate
Status: REPORTED
Alias: None
Product: kleopatra
Classification: Applications
Component: general (show other bugs)
Version: unspecified
Platform: Other Other
: NOR normal
Target Milestone: ---
Assignee: kdepim bugs
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-02-02 17:02 UTC by Martin Häcker
Modified: 2021-09-02 14:39 UTC (History)
3 users (show)

See Also:
Latest Commit:
Version Fixed In:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Häcker 2015-02-02 17:02:24 UTC
This bites when using Enigmail together with cleopatra, as Enigmail only shows incoming mail signatures as correct if they are ultimately trusted  - and only allows sending emails to them if they are ultimately trusted.

I noticed this when explaining gpg to a new crypto user who immediately stumbled over this - later on it took quite some time to find the cause and get it working while he thought that GPG is just broken and doesn't work.

I would expect that this is an enigma problem, but then again, I have no clue of the internals, and maybe really Kleopatra should change.

See gpg4win bug at: https://sourceforge.net/p/enigmail/bugs/399/

Reproducible: Always

Steps to Reproduce:
1. Install fresh copy of gpg4win
2. Get my signature to someone
3. Import it in cleopatra and set the trust level after verifying it
4. Try to check the signature in Enigma.

Actual Results:  
Borken

Expected Results:  
Should work
Comment 1 Robert Buchholz 2015-02-02 17:17:16 UTC
Ironically, Gnome's "Passwords and Keys" has the same problem.
Comment 2 Justin Zobel 2021-03-10 00:15:33 UTC
Thank you for the bug report.

As this report hasn't seen any changes in 5 years or more, we ask if you can please confirm that the issue still persists.

If this bug is no longer persisting or relevant please change the status to resolved.
Comment 3 Leonardo 2021-09-02 14:39:29 UTC
Hello everybody,

I use an Actalis S/MIME free e-mail certificate for corporate purposes with Mozilla Thunderbird. I recently launched Kleopatra to check details of this certificate by double-checking my e-mail address as shown in the certificate trust levels shown below:

>Actalis Authentication Root CA
 >Actalis Client Authentication CA G3
  >mycorporatelogin@myserver.com

Whenever I do this a pop-up Windows shows the signature details as expected, and it shows 3 columns with my corporate e-mail address, my name and its corresponding trust level. Here comes my concern, though, because Kleopatra shows this certificate as invalid, and I wonder why this happens.
I know this is not a Kleopatra bug, but I'd like to know what it means and how to change this "invalid" status to a "trusted" status, if possible.

Thank you all,

Leonardo.