Re: Kmail and smime

Ingo Klöcker <[email protected]> Fri, 27 Feb 2026 16:06:02 +0100
Newsgroups gmane.comp.kde.users.pim
Message-ID <16418286.Emhk5qWAgF@daneel>
--nextPart2334711.t9SDvczpPo
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"; protected-headers="v1"
From: Ingo =?UTF-8?B?S2zDtmNrZXI=?= <[email protected]>
To: [email protected]
Reply-To: [email protected]
Subject: Re: Kmail and smime
Date: Fri, 27 Feb 2026 16:06:02 +0100
Message-ID: <16418286.Emhk5qWAgF@daneel>
MIME-Version: 1.0

On Freitag, 27. Februar 2026 14:58:11 Mitteleurop=C3=A4ische Normalzeit Seb=
astian=20
G=C3=B6decke wrote:
> Am Fr., 27. Feb. 2026 um 14:53 Uhr schrieb Ingo Kl=C3=B6cker <kloecker@kd=
e.org>:
> > On Freitag, 27. Februar 2026 12:49:10 Mitteleurop=C3=A4ische Normalzeit
> > Sebastian>=20
> > G=C3=B6decke wrote:
> > > Am Fr., 27. Feb. 2026 um 12:23 Uhr schrieb Ingo Kl=C3=B6cker=20
<[email protected]>:
> > > > On Freitag, 27. Februar 2026 11:46:12 Mitteleurop=C3=A4ische Normal=
zeit
> > > > Sebastian>
> > > >=20
> > > > G=C3=B6decke wrote:
> > > > > Hi,
> > > > > i've a smime cert and try to use it with Kontakt/Kmail. It is
> > > > > imported
> > > > > in Kleopatra and there is everything okay.
> > > > > So i set it up in kmail to use this cert and when i try to write =
an
> > > > > email, my email will be added with this smime.p7s and has the
> > > > > signitar. So i send my mail, have to type my password for this ce=
rt
> > > > > and then it will be sent. So i try it now to send it to me and th=
en
> > > > > it's a red sign, and it says: The signature is invalid: Incorrect
> > > > > signature
> > > >=20
> > > > I think it would be best if you could send a signed message to this
> > > > mailing list.
> > >=20
> > > Well, with my other (business) email i'm not here on the list!?
> >=20
> > That doesn't matter. Your message will be held for moderation, but I can
> > approve it.
>
> okay i just send to the list.

Thanks!

The error "Bad signature" is misleading. The problem is that the certificat=
e of=20
the root CA is not available. You can see this when you click on the=20
certificate ID next to "Signature created with certificate". This should op=
en=20
Kleopatra. When you click on "Trust Chain Details" you can see that it says=
=20
"Issuer Certificate Not Found (CN=3DHARICA Client RSA Root CA 2021,O=3DHell=
enic=20
Academic and Research Institutions CA,C=3DGR)".

By default, GnuPG doesn't include the root CA certificate in the signature.=
 You=20
can change this as follows:
In Kleopatra open the configuration dialog (Settings->Configure Kleopatra..=
=2E).=20
Click on GnuPG System and then on S/MIME. For the option "Number of=20
certificates to include" you should see the value "-2" (which means "includ=
e=20
all certificates except for the root certificate"). Change this value to "-=
1"=20
(which means "include all certificates").

This should fix the problem for all future emails that you sign with your=20
certificate.

Regards,
Ingo

--nextPart2334711.t9SDvczpPo
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part.
Content-Transfer-Encoding: 7Bit

-----BEGIN PGP SIGNATURE-----

iJEEABYKADkWIQTbjgIOMowwlCBgvyGxb1mVFkdKugUCaaGy2hsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDIACgkQsW9ZlRZHSro9VAD+N9pYbbvfH/242FvGxycS
jmHSR93VmmTqfADeV/m+grcA/2Bf79XyV04+PtFhD44Yg0u1PZjgyRE1GRUl620s
0usN
=iVb/
-----END PGP SIGNATURE-----

--nextPart2334711.t9SDvczpPo--