Can't sign or encrypt Yosemite and received signed emails are marked as invalid

adam's Avatar

adam

20 Apr, 2015 05:19 PM

Hi,

I've installed GPGTools due to keybase.io requiring it.

I've installed GPG Suite 2015.03-b6 and am on Yosemite (10.10.3), All up to date as of 2015-04-18.

After installing nothing appears to have failed, I have keys in the GPG Keychain and the Mail plugin has loaded in Mail.app.

However the new email dialog doesn't allow me to press either the signed or encrypt buttons, even if I'm addressing it to someone who's key I have in the keychain. I've tried changing between S/MIME and PGP formats.

And emails I have received are highlighted as having invalid signatures. After uninstalling GPGTools they are marked as signed (I'm not sure where Mail.app is getting the key from in this case though, it doesn't show up in Keychain Access.app and it's not in my contacts)

  1. Support Staff 1 Posted by Steve on 23 Apr, 2015 08:48 PM

    Steve's Avatar

    Hi Adam,

    could you provide another screenshot for the invalid signature (click on details to show more information about why the signature is invalid).

    In GPG Keychain how many keys with type "sec/pub" do you see?

    All the best,
    steve

  2. 2 Posted by adam on 23 Apr, 2015 08:56 PM

    adam's Avatar

    Hi Steve,

    In GPG Keychain there is one sec/pub keypair which is my keybase.io one and everything else is just pub.

    Clicking details pops up this box which doesn't have much more info

  3. Support Staff 3 Posted by Steve on 23 Apr, 2015 09:12 PM

    Steve's Avatar

    Ok, so what happens if you send yourself a testmail encrypted and signed? Does that arrive as expected?

    Is there any exchange server involved in your mail setup?

    To have a closer look at the signed mail and if that signed mail does not contain sensitive information, please export the received message.

    To export, simply select a message and press CMD + SHIFT + S, select "Raw Message Source" as type and save it. Then attach the resulting file to this discussion here.

    So there are several issues here:

    1. there is an S/MIME signed mail which has a valid signature when GPGMail is uninstalled. That same signature becomes invalid after GPGMail is installed. Is that correct?

    2. You cannot create a signed or encrypted mail yourself.

    Did I understand correctly that you created a key pair on keybase.io, then exported sec and pub key and imported both to GPG Keychain? I never tried that, since I dislike the idea of sharing my secret key with an online service. But I am aware they offer this feature. So before diving deeper into this, could you please double check, that mail.app > Accounts your account in question absolutely matches the mail address used in your sec / pub key.

  4. 4 Posted by adam on 23 Apr, 2015 09:29 PM

    adam's Avatar

    Ah so the email on the keypair doesn't match my email address. It's been given my [email blocked].

    There's no exchange server involved. My email account is an imap gmail account.

    Yes 1 is correct, I'm not sure if it's S/MIME or PGP though, the content type is multipart/signed but the signature is application/pgp-signature not application/pkcs7-signature.

    1. Correct both the sign and encrypt buttons are disabled so I can't send a test encrypted email.

    The only examples of signed emails I have are from a work colleague so I'd rather not post them on the web, is there a way I can send you a copy instead.

    Thanks,
    Adam

  5. 5 Posted by adam on 27 Apr, 2015 09:20 AM

    adam's Avatar

    Oh I didn't think it would block email addresses, the one my key has been given has my keybase username at keybase.io as the address.

  6. Support Staff 6 Posted by Steve on 27 Apr, 2015 09:26 AM

    Steve's Avatar

    Hey Adam,

    so that is the issue then. If you key does not include the email address used, GPGMail won't be able to encrypt or sign.

    You could add the email address you use in mail.app as UserID to your existing keybase key. But again, I don't think it's a good idea to share your secret key with an online service. So it might be a good idea to just create a second key for that email address. But since I am not familiar with your use case scenario with keybase one or the other might be preferable.

    All the best,
    steve

  7. 7 Posted by adam on 27 Apr, 2015 10:28 AM

    adam's Avatar

    Thanks, that fixes the signature/encryption feature.

    I'm just testing out keybase and it's not a important key so i'm not worried about that issue.

    The invalid signature thing is still happening though, I don't think that's related to my key being tied to the wrong email.

  8. Support Staff 8 Posted by Steve on 02 May, 2015 05:19 PM

    Steve's Avatar

    Hi Adam,

    that is correct. To really test this and probably fix the issues with the signed status, we'd need a test case.

    I'm setting this discussion to "private". That means only our core-team and the company hosting this support platform are able to access this discussion.

    If you still prefer to send a test case mail our way directly, please make sure to do that as eml file: To export, simply select a message and press CMD + SHIFT + S, select "Raw Message Source" as type and save it.

    Then send that to [email blocked] and make sure to include a link to this discussion here.

    All the best,
    steve

  9. Support Staff 9 Posted by Steve on 14 Aug, 2015 01:40 PM

    Steve's Avatar

    Closing, since no further user feedback was received. Should your problem persist, feel free to re-open this discussion any time.

    All the best, steve

  10. Steve closed this discussion on 14 Aug, 2015 01:40 PM.

Comments are currently closed for this discussion. You can start a new one.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac