Re: ignoring expired s/mime certificates for encryption

"Kevin J. McCarthy" <[email protected]> Wed, 1 Jul 2026 19:30:30 +0800
Newsgroups gmane.mail.mutt.user
Message-ID <[email protected]>
--fsaZGrv0pk/bo4lS
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Wed, Jul 01, 2026 at 10:36:11AM +0200, Robert J=C3=A4schke via Mutt-user=
s wrote:
>I am using gpgme (set crypt_use_gpgme) to encrypt and sign mails using
>s/mime. Several (own and others') certificates have been expired and
>are still in gpg's database. I do not want to remove them, since I can
>still use them to validate/decrypt old mails. Still, I find it
>confusing (if not to say annoying), to get these expired certificates
>presented whenever I want to send an encrypted mail, e.g.:

I'm sorry to say the news is not great.  The mutt GPGME code was written=20
quite a while ago.  It looks like, at that time, the concept of expired=20
was not included in the s/mime code when querying keys.

It looks quite deliberate, because the query code is shared with PGP but=20
has those parts only enabled for the PGP backend.  So perhaps at that=20
time the GPGME library didn't have support for that information.

I'm not sure if it does now.  I'll check with Werner and see if there=20
are updates.

--=20
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA

--fsaZGrv0pk/bo4lS
Content-Type: application/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEiXWpszqjeRA4XFMIre92hIAxa9oFAmpE+lYACgkQre92hIAx
a9qgzw/+Kj7DokOV3FMBDUgg313S5YfcewQoIEH6buiTp76n/kXpbgHPzg8SfG+z
fr0tY5kAOWlHSUXoxVV2Wrz2iq113btqDYZS1kYh2RPtT5ZLlx1vx6fvsXgDj7t9
95uk9X7DttKqw0EcWdVCNgd+994jxh868AABjYS1ihlO4NDqWfK51QvXpFCr36Rf
ygqBqyEJOAIJZJr/Fc3aB8XMYKylDxkvZFY5F2Quy3Z1X/kHeKzDd7qTXn1zbsez
hDfNADBjKavzXCO16CLYOkosVTMHP6DKrBDUOdoW5+XcyDdUr6+KDG5/77ktqvkv
fHvNJ7/tfRyLdwhRA6zyAUQUNjItB0tSxRg+j3Qn4nTvSUr3rXqtPGEsphvyxq1s
UFEMyD7ZLzbtTCCE85X9Bwy8Xwj1jCtg07gRkzcgU00wqAF79HqRmexMPYLQGxqT
Zo+Iareskf5TY4XKNeBrQ1H60zuZiwx3U+E4UHenMiM5QgPhbsphdKwG+f6ZLVqZ
qOudPtmiSaEmSl6eEyg+msQrSy442o+0ue16Xm6TGXLM9LuMPAfWzsTQlxbqUWWz
yJemL2sggc8bFSs1zX3Q8CPTv5Yk8fy9fXGm+Jaw5dAxly852YEiKYH/lAOuOxYI
secAz5OfgLwgY0b5hUIfDRC1zMp2QBvPj+lrO8biaWVA1hyvzfI=
=tK0L
-----END PGP SIGNATURE-----

--fsaZGrv0pk/bo4lS--