#278706 evolution: Signatures from revoked keys should not be trusted

Package:
evolution
Source:
evolution
Description:
groupware suite with mail client and organizer
Submitter:
Moray Allan
Date:
2010-06-22 16:18:06 UTC
Severity:
normal
#278706#5
Date:
2004-10-28 20:39:59 UTC
From:
To:
Evolution shows "Valid signature, cannot verify sender" for a message
signed by a revoked key. It would be better to make it more obvious
that the key has been revoked -- it may be that the key was compromised
and that signatures from it should definitely *not* be trusted.

In this case, clicking on the 'seal' icon shows warnings from GPG,
including
"gpg: WARNING: This key has been revoked by its owner!
 gpg:          This could mean that the signature is forgery.
 gpg: reason for revocation: Key has been compromised"

#278706#8
Date:
2005-02-05 03:02:54 UTC
From:
To:
Hi!

Some time ago you submitted a bug related to evolution:
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=278706

Can you still reproduce this bug with version 2.0.3 (latest in Sarge and
Sid) ?

Thanks!

#278706#13
Date:
2005-02-08 23:47:58 UTC
From:
To:
Yes, the behaviour hasn't changed from what I originally described.

Thanks,

#278706#20
Date:
2007-02-27 14:16:30 UTC
From:
To:
Hi,

I can still reproduce this in 2.8.2.1.


Thijs

#278706#25
Date:
2010-06-22 16:16:41 UTC
From:
To:
Hey,

I don't have a revoked key handy for now, would you mind reporting if
this one still exists in current evolution?

Cheers,