Can't sign or encrypt Yosemite and received signed emails are marked as invalid
Hi,
I've installed GPGTools due to keybase.io requiring it.
I've installed GPG Suite 2015.03-b6 and am on Yosemite (10.10.3), All up to date as of 2015-04-18.
After installing nothing appears to have failed, I have keys in the GPG Keychain and the Mail plugin has loaded in Mail.app.
However the new email dialog doesn't allow me to press either the signed or encrypt buttons, even if I'm addressing it to someone who's key I have in the keychain. I've tried changing between S/MIME and PGP formats.
And emails I have received are highlighted as having invalid signatures. After uninstalling GPGTools they are marked as signed (I'm not sure where Mail.app is getting the key from in this case though, it doesn't show up in Keychain Access.app and it's not in my contacts)
-
after-uninstall-signed.png
20.1 KB
-
invalid-signature.png
31.7 KB
-
new-email-disabled.png
28.2 KB
Comments are currently closed for this discussion. You can start a new one.
Keyboard shortcuts
Generic
| ? | Show this help |
|---|---|
| ESC | Blurs the current field |
Comment Form
| r | Focus the comment reply box |
|---|---|
| ^ + ↩ | Submit the comment |
You can use Command ⌘ instead of Control ^ on Mac
Support Staff 1 Posted by Steve on 23 Apr, 2015 08:48 PM
Hi Adam,
could you provide another screenshot for the invalid signature (click on details to show more information about why the signature is invalid).
In GPG Keychain how many keys with type "sec/pub" do you see?
All the best,
steve
2 Posted by adam on 23 Apr, 2015 08:56 PM
Hi Steve,
In GPG Keychain there is one sec/pub keypair which is my keybase.io one and everything else is just pub.
Clicking details pops up this box which doesn't have much more info
Support Staff 3 Posted by Steve on 23 Apr, 2015 09:12 PM
Ok, so what happens if you send yourself a testmail encrypted and signed? Does that arrive as expected?
Is there any exchange server involved in your mail setup?
To have a closer look at the signed mail and if that signed mail does not contain sensitive information, please export the received message.
To export, simply select a message and press CMD + SHIFT + S, select "Raw Message Source" as type and save it. Then attach the resulting file to this discussion here.
So there are several issues here:
there is an S/MIME signed mail which has a valid signature when GPGMail is uninstalled. That same signature becomes invalid after GPGMail is installed. Is that correct?
You cannot create a signed or encrypted mail yourself.
Did I understand correctly that you created a key pair on keybase.io, then exported sec and pub key and imported both to GPG Keychain? I never tried that, since I dislike the idea of sharing my secret key with an online service. But I am aware they offer this feature. So before diving deeper into this, could you please double check, that mail.app > Accounts your account in question absolutely matches the mail address used in your sec / pub key.
4 Posted by adam on 23 Apr, 2015 09:29 PM
Ah so the email on the keypair doesn't match my email address. It's been given my [email blocked].
There's no exchange server involved. My email account is an imap gmail account.
Yes 1 is correct, I'm not sure if it's S/MIME or PGP though, the content type is multipart/signed but the signature is application/pgp-signature not application/pkcs7-signature.
The only examples of signed emails I have are from a work colleague so I'd rather not post them on the web, is there a way I can send you a copy instead.
Thanks,
Adam
5 Posted by adam on 27 Apr, 2015 09:20 AM
Oh I didn't think it would block email addresses, the one my key has been given has my keybase username at keybase.io as the address.
Support Staff 6 Posted by Steve on 27 Apr, 2015 09:26 AM
Hey Adam,
so that is the issue then. If you key does not include the email address used, GPGMail won't be able to encrypt or sign.
You could add the email address you use in mail.app as UserID to your existing keybase key. But again, I don't think it's a good idea to share your secret key with an online service. So it might be a good idea to just create a second key for that email address. But since I am not familiar with your use case scenario with keybase one or the other might be preferable.
All the best,
steve
7 Posted by adam on 27 Apr, 2015 10:28 AM
Thanks, that fixes the signature/encryption feature.
I'm just testing out keybase and it's not a important key so i'm not worried about that issue.
The invalid signature thing is still happening though, I don't think that's related to my key being tied to the wrong email.
Support Staff 8 Posted by Steve on 02 May, 2015 05:19 PM
Hi Adam,
that is correct. To really test this and probably fix the issues with the signed status, we'd need a test case.
I'm setting this discussion to "private". That means only our core-team and the company hosting this support platform are able to access this discussion.
If you still prefer to send a test case mail our way directly, please make sure to do that as eml file: To export, simply select a message and press CMD + SHIFT + S, select "Raw Message Source" as type and save it.
Then send that to [email blocked] and make sure to include a link to this discussion here.
All the best,
steve
Support Staff 9 Posted by Steve on 14 Aug, 2015 01:40 PM
Closing, since no further user feedback was received. Should your problem persist, feel free to re-open this discussion any time.
All the best, steve
Steve closed this discussion on 14 Aug, 2015 01:40 PM.