Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upSplit GPG with Thunderbird+Enigmail - frequent qubes.Gpg dialog prompts #3470
Comments
andrewdavidwong
added
bug
C: other
labels
Jan 17, 2018
andrewdavidwong
added this to the Release 4.0 milestone
Jan 17, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
tasket
Jan 18, 2018
Discussion - https://groups.google.com/d/msgid/qubes-users/8e8080b9-8422-0dc3-eff5-097deb995be4%40posteo.net
I'd like to emphasize that merely browsing signed messages triggers multiple dialog prompts for each message. This makes Enigmail unbearable in its intended capacity as an overall guard against forgery.
Of course, you can enable it just for signing, but if other people similarly don't enable it for general reading then the utility of signing is diminished.
tasket
commented
Jan 18, 2018
|
Discussion - https://groups.google.com/d/msgid/qubes-users/8e8080b9-8422-0dc3-eff5-097deb995be4%40posteo.net I'd like to emphasize that merely browsing signed messages triggers multiple dialog prompts for each message. This makes Enigmail unbearable in its intended capacity as an overall guard against forgery. Of course, you can enable it just for signing, but if other people similarly don't enable it for general reading then the utility of signing is diminished. |
andrewdavidwong
added
the
P: major
label
Jan 19, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
mossy-nw
Jan 19, 2018
not yet able to confirm but think this could be fixed in R4.0 using appropriate qrexec policy. See #3251 and https://www.qubes-os.org/news/2017/10/03/core3/
mossy-nw
commented
Jan 19, 2018
|
not yet able to confirm but think this could be fixed in R4.0 using appropriate qrexec policy. See #3251 and https://www.qubes-os.org/news/2017/10/03/core3/ |
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
mossy-nw
Jan 19, 2018
OK this fixes it! Edit the file /etc/qubes-rpc/policy/qubes.Gpg to:
clientVM keysVM allow
$anyvm $anyvm ask
where client is your thunderbird+enigmail VM and keys is where your GPG private keys live. I'll update the docs and then close this issue.
mossy-nw
commented
Jan 19, 2018
•
|
OK this fixes it! Edit the file
where |
mossy-nw
closed this
Jan 19, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
mossy-nw
Jan 19, 2018
mossy-nw
commented
Jan 19, 2018
|
tasket:
Discussion - https://groups.google.com/d/msgid/qubes-users/8e8080b9-8422-0dc3-eff5-097deb995be4%40posteo.net
---
I'd like to emphasize that merely browsing signed messages triggers multiple dialog prompts for _each_ message. This makes Enigmail unbearable in its intended capacity as an overall guard against forgery.
Of course, you can enable it just for _signing_, but if other people similarly don't enable it for general _reading_ then the utility of signing is diminished.
To restore R3.2 split-gpg behavior to R4.0, edit the file
/etc/qubes-rpc/policy/qubes.Gpg to:
clientVM keysVM allow
$anyvm $anyvm ask
where client is your thunderbird+enigmail VM and keys is where your GPG
private keys live. I added this to the split-gpg documentation.
HTH,
…-m0ssy
|
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
tasket
commented
Jan 19, 2018
|
@mossy-nw OK, thanks! |
andrewdavidwong
added
the
resolved
label
Jan 20, 2018
This comment has been minimized.
Show comment
Hide comment
This comment has been minimized.
mfc
Jul 9, 2018
Member
created pull request moving this content to appropriate section of documentation: QubesOS/qubes-doc#676
|
created pull request moving this content to appropriate section of documentation: QubesOS/qubes-doc#676 |
mossy-nw commentedJan 17, 2018
Qubes OS version:
R4.0_rc3
Affected TemplateVMs:
fedora-26
debian-9
probably any others used with split-gpg
Steps to reproduce the behavior:
Expected behavior:
Actual behavior:
General notes:
Related issues:
possibly related to recent deprecation of qvm-copy-to-vm/qvm-move-to-vm tools (now requiring entering destination VM in dom0 dialog)?