Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #209532 > unrolled thread

how to integrate ca-certificates with gpgsm (for email s/mime signature verification)

Started byGregor Zattler <telegraph@gmx.net>
First post2019-06-02 19:40 +0200
Last post2019-06-03 08:20 +0200
Articles 4 — 2 participants

Back to article view | Back to linux.debian.user


Contents

  how to integrate ca-certificates with gpgsm (for email s/mime signature verification) Gregor Zattler <telegraph@gmx.net> - 2019-06-02 19:40 +0200
    Re: how to integrate ca-certificates with gpgsm (for email s/mime signature verification) deloptes <deloptes@gmail.com> - 2019-06-02 22:10 +0200
      Re: how to integrate ca-certificates with gpgsm (for email s/mime signature verification) Gregor Zattler <telegraph@gmx.net> - 2019-06-03 00:00 +0200
        Re: how to integrate ca-certificates with gpgsm (for email s/mime signature verification) deloptes <deloptes@gmail.com> - 2019-06-03 08:20 +0200

#209532 — how to integrate ca-certificates with gpgsm (for email s/mime signature verification)

FromGregor Zattler <telegraph@gmx.net>
Date2019-06-02 19:40 +0200
Subjecthow to integrate ca-certificates with gpgsm (for email s/mime signature verification)
Message-ID<y4CCC-9W-5@gated-at.bofh.it>
Hi,

I use notmuch-emacs to read my email and sometimes do use GnuPG,
therefore notmuch-emacs is configured to verify signatures but
does so also for S/MIME  signatures.  When displaying such emails
I'm asked if I trust the respective Root CAs Cert.  That's tedious.

Therefore I would like to integrate certificates provided by
debians ca-certificates package with gpgsm, but the only way I
found to do so, would be to manually import all those
certificates.

Isn't there an option to read in those certs from /etc/ssl... at
start-up?


Ciao; Gregor
--
 -... --- .-. . -.. ..--.. ...-.-

[toc] | [next] | [standalone]


#209537

Fromdeloptes <deloptes@gmail.com>
Date2019-06-02 22:10 +0200
Message-ID<y4EXL-1KA-5@gated-at.bofh.it>
In reply to#209532
Gregor Zattler wrote:

> I use notmuch-emacs to read my email and sometimes do use GnuPG,
> therefore notmuch-emacs is configured to verify signatures but
> does so also for S/MIME  signatures.  When displaying such emails
> I'm asked if I trust the respective Root CAs Cert.  That's tedious.
> 
> Therefore I would like to integrate certificates provided by
> debians ca-certificates package with gpgsm, but the only way I
> found to do so, would be to manually import all those
> certificates.
> 
> Isn't there an option to read in those certs from /etc/ssl... at
> start-up?

Why don't you ask at the GPG mailing list?

[toc] | [prev] | [next] | [standalone]


#209539

FromGregor Zattler <telegraph@gmx.net>
Date2019-06-03 00:00 +0200
Message-ID<y4GGd-2Dw-7@gated-at.bofh.it>
In reply to#209537
Hi,
* deloptes <deloptes@gmail.com> [2019-06-02; 22:01]:
> Gregor Zattler wrote:
>> I use notmuch-emacs to read my email and sometimes do use GnuPG,
>> therefore notmuch-emacs is configured to verify signatures but
>> does so also for S/MIME  signatures.  When displaying such emails
>> I'm asked if I trust the respective Root CAs Cert.  That's tedious.
>> 
>> Therefore I would like to integrate certificates provided by
>> debians ca-certificates package with gpgsm, but the only way I
>> found to do so, would be to manually import all those
>> certificates.
>> 
>> Isn't there an option to read in those certs from /etc/ssl... at
>> start-up?
>
> Why don't you ask at the GPG mailing list?

I thought the location of the certs might be debian specific.


Ciao; Gregor
-- 
 -... --- .-. . -.. ..--.. ...-.-

[toc] | [prev] | [next] | [standalone]


#209545

Fromdeloptes <deloptes@gmail.com>
Date2019-06-03 08:20 +0200
Message-ID<y4Ou5-7IW-1@gated-at.bofh.it>
In reply to#209539
Gregor Zattler wrote:

> I thought the location of the certs might be debian specific.

Hi,
sorry but I do not know anything about S/MIME - I tend to recall, it is
insecure and meaningless.
Another option would be to ask on the debian dev list or to address the
debian maintainer or wait here someone to answer.

regards

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web