From: Jure Varlec <exzombie@exzombie.homeip.net>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] OpenSSL certificates and Kmail
Date: Mon, 21 May 2007 15:25:20 +0200 [thread overview]
Message-ID: <200705211525.25113.exzombie@exzombie.homeip.net> (raw)
In-Reply-To: <200705201916.53234.michaelkintzios@gmail.com>
[-- Attachment #1: Type: text/plain, Size: 2990 bytes --]
On Sunday 20 of May 2007 20:16:43 Mick wrote:
> OK, I also tried Validate with CRL and I am now getting a CRL related
> error: =============================================================
> 5 - 2007-05-20 19:09:00 gpg-agent[7251]: handler 0x80c8820 for fd 0
> terminated 7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- ISVALID
> CDECFDC58640B7262B39CCB59B61E8EEFF2ED4D0.0380C6
> 7 - 2007-05-20 19:09:01 dirmngr[9532]: no CRL available for issuer id
> CDECFDC58640B7262B39CCB59B61E8EEFF2ED4D0
> 7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: -> INQUIRE SENDCERT
> 7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- [ 44 20 30 82 05
> 42 30 82 03 2a a0 03 02 01 02 02 03 03 80 c6 30 25 30 44 06 09 2a [snip ] 7
> - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- [ 44 20 1c 45 de 3e
> 49 63 5f 1f 65 58 03 4f 5c 08 82 ef cd b0 15 bd a7 2b 3e 58 76 [snip ] 7 -
> 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: <- END
> 7 - 2007-05-20 19:09:01 dirmngr[9532]: crl_fetch via issuer failed:
> Configuration error
> 7 - 2007-05-20 19:09:01 dirmngr[9532]: command ISVALID failed:
> Configuration error
> 7 - 2007-05-20 19:09:01 dirmngr[9532.0x8080078] DBG: -> ERR 167772275
> Configuration error
> 6 - 2007-05-20 19:09:01 gpgsm[9531]: response of dirmngr: ec=10.115
> 6 - 2007-05-20 19:09:01 gpgsm[9531]: checking the CRL failed:
> Configuration error
> 6 - 2007-05-20 19:09:01 gpgsm[9531.0x80806a0] DBG: -> S INV_RECP 0
> 9964FAAE960AD708013D03A5CC3E6023CDC3E990
> 6 - 2007-05-20 19:09:01 gpgsm[9531.0x80806a0] DBG: -> ERR 167772275
> Configuration error
> 6 - 2007-05-20 19:09:04 gpgsm[9531.0x80806a0] DBG: <- BYE
> 6 - 2007-05-20 19:09:05 gpgsm[9531.0x80806a0] DBG: -> OK closing
> connection 7 - 2007-05-20 19:09:05 dirmngr[9532.0x8080078] DBG: <- [EOF]
> =============================================================
>
> What should I use OCP or CRL and if the latter how am I supposed to
> configure this?
Ugh. Well, they say a picture is worth a thousand words:
http://imgs.xkcd.com/comics/unspeakable_pun.jpg
Now that I checked with some random signed mails on this list, it turns out my
setup shows exactly the same symptoms as yours, i.e. it can't download
certain CRLs and cacert's OCP doesn't work. To be frank, what I really needed
S/MIME to work for are the bills my telco issues through e-mail. After
installing dimngr and the relevant certificate, kmail recognizes signature in
their bills correctly.
Funny thing is, kleopatra can and does download certain CRLs correctly using
URLs embedded in a certificate, but can't do so for some others. And even if
it can download a CRL, it then can't download the issuer certificate which
makes it a bit useless. I haven't a clue how to proceed, as documentation
seems a bit scarce.
As there are people on this list who use S/MIME signatures I guess it can be
made to work. Perhaps someone could chime in?
Regards
Jure
[-- Attachment #2: This is a digitally signed message part. --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
next prev parent reply other threads:[~2007-05-21 13:35 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2007-05-20 11:24 [gentoo-user] OpenSSL certificates and Kmail Mick
2007-05-20 12:53 ` Jure Varlec
2007-05-20 14:47 ` Mick
2007-05-20 15:54 ` Jure Varlec
2007-05-20 17:10 ` Mick
2007-05-20 18:16 ` Mick
2007-05-21 13:25 ` Jure Varlec [this message]
2007-05-23 21:57 ` Mick
2007-05-20 17:20 ` Elias Probst
2007-05-21 13:30 ` Jure Varlec
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200705211525.25113.exzombie@exzombie.homeip.net \
--to=exzombie@exzombie.homeip.net \
--cc=gentoo-user@lists.gentoo.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox