Re: Kmail and smime

Sebastian Gödecke <[email protected]> Mon, 2 Mar 2026 08:22:39 +0100
Newsgroups gmane.comp.kde.users.pim
Message-ID <CAJRNCbaTzyOjX_bQqyRi_+op8E7JOt5=_4DPtVsHudHdjtTMjw@mail.gmail.com>
I send an email from my business account to the list with the
recommended settings.

Am Fr., 27. Feb. 2026 um 16:06 Uhr schrieb Ingo Kl=C3=B6cker <kloecker@kde.=
org>:
>
> On Freitag, 27. Februar 2026 14:58:11 Mitteleurop=C3=A4ische Normalzeit S=
ebastian
> G=C3=B6decke wrote:
> > Am Fr., 27. Feb. 2026 um 14:53 Uhr schrieb Ingo Kl=C3=B6cker <kloecker@=
kde.org>:
> > > On Freitag, 27. Februar 2026 12:49:10 Mitteleurop=C3=A4ische Normalze=
it
> > > Sebastian>
> > > G=C3=B6decke wrote:
> > > > Am Fr., 27. Feb. 2026 um 12:23 Uhr schrieb Ingo Kl=C3=B6cker
> <[email protected]>:
> > > > > On Freitag, 27. Februar 2026 11:46:12 Mitteleurop=C3=A4ische Norm=
alzeit
> > > > > Sebastian>
> > > > >
> > > > > G=C3=B6decke wrote:
> > > > > > Hi,
> > > > > > i've a smime cert and try to use it with Kontakt/Kmail. It is
> > > > > > imported
> > > > > > in Kleopatra and there is everything okay.
> > > > > > So i set it up in kmail to use this cert and when i try to writ=
e an
> > > > > > email, my email will be added with this smime.p7s and has the
> > > > > > signitar. So i send my mail, have to type my password for this =
cert
> > > > > > and then it will be sent. So i try it now to send it to me and =
then
> > > > > > it's a red sign, and it says: The signature is invalid: Incorre=
ct
> > > > > > signature
> > > > >
> > > > > I think it would be best if you could send a signed message to th=
is
> > > > > mailing list.
> > > >
> > > > Well, with my other (business) email i'm not here on the list!?
> > >
> > > That doesn't matter. Your message will be held for moderation, but I =
can
> > > approve it.
> >
> > okay i just send to the list.
>
> Thanks!
>
> The error "Bad signature" is misleading. The problem is that the certific=
ate of
> the root CA is not available. You can see this when you click on the
> certificate ID next to "Signature created with certificate". This should =
open
> Kleopatra. When you click on "Trust Chain Details" you can see that it sa=
ys
> "Issuer Certificate Not Found (CN=3DHARICA Client RSA Root CA 2021,O=3DHe=
llenic
> Academic and Research Institutions CA,C=3DGR)".
>
> By default, GnuPG doesn't include the root CA certificate in the signatur=
e. You
> can change this as follows:
> In Kleopatra open the configuration dialog (Settings->Configure Kleopatra=
...).
> Click on GnuPG System and then on S/MIME. For the option "Number of
> certificates to include" you should see the value "-2" (which means "incl=
ude
> all certificates except for the root certificate"). Change this value to =
"-1"
> (which means "include all certificates").
>
> This should fix the problem for all future emails that you sign with your
> certificate.
>
> Regards,
> Ingo



--=20
Mit freundlichen Gr=C3=BC=C3=9Fen
Sebastian G=C3=B6decke