public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Jure Varlec <exzombie@exzombie.homeip.net>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] OpenSSL certificates and Kmail
Date: Mon, 21 May 2007 15:25:20 +0200	[thread overview]
Message-ID: <200705211525.25113.exzombie@exzombie.homeip.net> (raw)
In-Reply-To: <200705201916.53234.michaelkintzios@gmail.com>

[-- Attachment #1: Type: text/plain, Size: 2990 bytes --]

On Sunday 20 of May 2007 20:16:43 Mick wrote:
> OK, I also tried Validate with CRL and I am now getting a CRL related
> error: =============================================================
> 5 - 2007-05-20 19:09:00 gpg-agent[7251]: handler 0x80c8820 for fd 0
> terminated 7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- ISVALID
> CDECFDC58640B7262B39CCB59B61E8EEFF2ED4D0.0380C6
>   7 - 2007-05-20 19:09:01 dirmngr[9532]: no CRL available for issuer id
> CDECFDC58640B7262B39CCB59B61E8EEFF2ED4D0
>   7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: -> INQUIRE SENDCERT
>   7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- [ 44 20 30 82 05
> 42 30 82 03 2a a0 03 02 01 02 02 03 03 80 c6 30 25 30 44 06 09 2a [snip ] 7
> - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- [ 44 20 1c 45 de 3e
> 49 63 5f 1f 65 58 03 4f 5c 08 82 ef cd b0 15 bd a7 2b 3e 58 76 [snip ] 7 -
> 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- END
>   7 - 2007-05-20 19:09:01 dirmngr[9532]: crl_fetch via issuer failed:
> Configuration error
>   7 - 2007-05-20 19:09:01 dirmngr[9532]: command ISVALID failed:
> Configuration error
>   7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: -> ERR 167772275
> Configuration error
>   6 - 2007-05-20 19:09:01 gpgsm[9531]: response of dirmngr: ec=10.115
>   6 - 2007-05-20 19:09:01 gpgsm[9531]: checking the CRL failed:
> Configuration error
>   6 - 2007-05-20 19:09:01 gpgsm[9531.0x80806a0] DBG: -> S INV_RECP 0
> 9964FAAE960AD708013D03A5CC3E6023CDC3E990
>   6 - 2007-05-20 19:09:01 gpgsm[9531.0x80806a0] DBG: -> ERR 167772275
> Configuration error
>   6 - 2007-05-20 19:09:04 gpgsm[9531.0x80806a0] DBG: <- BYE
>   6 - 2007-05-20 19:09:05 gpgsm[9531.0x80806a0] DBG: -> OK closing
> connection 7 - 2007-05-20 19:09:05 dirmngr[9532.0x8080078] DBG: <- [EOF]
> =============================================================
>
> What should I use OCP or CRL and if the latter how am I supposed to
> configure this?


Ugh. Well, they say a picture is worth a thousand words:
http://imgs.xkcd.com/comics/unspeakable_pun.jpg

Now that I checked with some random signed mails on this list, it turns out my 
setup shows exactly the same symptoms as yours, i.e. it can't download 
certain CRLs and cacert's OCP doesn't work. To be frank, what I really needed 
S/MIME to work for are the bills my telco issues through e-mail. After 
installing dimngr and the relevant certificate, kmail recognizes signature in 
their bills correctly.

Funny thing is, kleopatra can and does download certain CRLs correctly using 
URLs embedded in a certificate, but can't do so for some others. And even if 
it can download a CRL, it then can't download the issuer certificate which 
makes it a bit useless. I haven't a clue how to proceed, as documentation 
seems a bit scarce.

As there are people on this list who use S/MIME signatures I guess it can be 
made to work. Perhaps someone could chime in?

Regards
Jure

[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

  reply	other threads:[~2007-05-21 13:35 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-05-20 11:24 [gentoo-user] OpenSSL certificates and Kmail Mick
2007-05-20 12:53 ` Jure Varlec
2007-05-20 14:47   ` Mick
2007-05-20 15:54     ` Jure Varlec
2007-05-20 17:10       ` Mick
2007-05-20 18:16         ` Mick
2007-05-21 13:25           ` Jure Varlec [this message]
2007-05-23 21:57             ` Mick
2007-05-20 17:20   ` Elias Probst
2007-05-21 13:30     ` Jure Varlec

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200705211525.25113.exzombie@exzombie.homeip.net \
    --to=exzombie@exzombie.homeip.net \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox