Re: [Enigmail] Enigmail GNOME keyring handling

Patrick Brunschwig <[email protected]> Fri, 3 Jan 2020 09:21:35 +0100
Newsgroups gmane.comp.mozilla.enigmail.general
Message-ID <[email protected]>
[email protected] wrote on 02.01.2020 19:52:
> Am 02.01.20 um 17:36 schrieb Patrick Brunschwig:
>> Robert J. Hansen wrote on 02.01.2020 16:26:
>>>> Using Enigmail for some time now - thanks for your work!
>>> Patrick deserves all the credit; the rest of us just try to help him
>>> with the load of questions.  :)  Which is hard, given that he usually
>>> beats us to answering them!
>>>
>>>> As I understand, the GPG key for a specific email address is saved
>>>> inside the keyring, in my case the GNOME keyring. To decrypt an
>>>> encrypted email Enigmail needs to have access to that keyring. Which
>>>> means, the GNOME keyring needs to be unlocked so that Enigmail can
>>>> access it and read the according GPG key.
>>> Nope.  :)
>>>
>>> GnuPG is the one popping up those passphrase dialogs, not Enigmail. 
>>> We've got nothing to do with it.  We never touch your keyring.  Although
>>> I think your feature request is pretty reasonable, it's also beyond
>>> Enigmail's scope.  Perhaps ask on GnuPG-Users, or on a GNOME mailing list?
> Thanks for the clarification.
>> The above said, I assume that what happens is this: if GNOME keyring is
>> already running when gpg requires a password, it will connect to the
>> running instance of GNOME keyring and get the password from there. If
>> GNOME keyring is not already running, then gpg will need to start a
>> "keyring" tool on its own. And the only tool known to gpg is gpg-agent.
>>
>> -Patrick
>
> Thanks for pointing that out. So, just for my understanding: Are you
> happy - design-wise - with the fact that if the keyring is not unlocked
> a user is asked for the GPG key even it is already available in the
> keyring? What do you think would need to change on the GPG side if a
> user would like to have the keyring unlocked by Enigmail instead of
> requesting the GPG key?
This is clearly the fault of GNOME, or the way your distribution is
configured. GPG contains a component called gpg-agent that is designed
to deal with handling keys and passphrases. If GNOME decides to hijack
gpg-agent then that's entirely their decision, and you can't blame GPG
for working that.

-Patrick

_______________________________________________
enigmail-users mailing list
[email protected]
To unsubscribe or make changes to your subscription click here:
https://admin.hostpoint.ch/mailman/listinfo/enigmail-users_enigmail.net
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEET5+J9VBawdGiYGMc2xGHud1faTsFAl4O+ZAACgkQ2xGHud1f
aTuVKA//RnjAHCo1oIn0r9sN+91nBsxBtrheNz7bP+/HmNAtsbjZXKxecC//4PnM
7YAOcvpzvbQpVrFBBJA4EU7tXQU17UtKZU2McKEpGtbfZqgqFiX7NDp/HEvIuj//
Q0ezWZ9LkPCf05EmfubHKeauxqSzUsmdu3SdkQZrWkrDYbbcBfwJRCP923lr30Va
N1JCzI8VNCmTtKoSa5lWrfFcQXl8ZQZtbG/ABJ2A1e1qkptvXQYMortCZt+wpAGE
d+dAQXt06FlBpWKzKM2zXMVfIVTuwjK66lwQr2WYN54m3USnRNa3o8O5PiphUBcl
biWMdbLv1HnaQeYl9+DZKefLdFNTJrHxOF9TnbDprkHU2bAidBS9X2pZFIPFEwQF
e5QH2bteTPTqEcFbjgY4D0T9Qg08oBym3YutM6Lx6Y37ZwukRt0jWW1td1RwgPwt
RhBLVMLmuSP70LmoEQx6cWTEIdrXqGeHFyA4287Lz/bOs8UzlLC5e1A+WnYUJE6j
5ikX59C3bwJKSXSo0m8Ov/UemhUNe7APpW/XdYGgy9yT1cfp2MOaaE0+9FfswMyH
mO0HHd5G0hvTJfWbkNIb+dpUPNjJ8FGHfsPnHcE4YBCpaAUgIyS5QLdliIfK3Dfu
FaVfMEQTmiqpdgspRhYFWMDqHndbobyYbxD9YeY8/7o/jaL60h8=
=RFBa
-----END PGP SIGNATURE-----