From lurker-index@localhost Mon Sep 19 11:06:34 2016
Return-Path: <owner-mutt-users-M24736@mutt.org>
Received: from lin16.mojsite.com (178.218.164.164:993) by g0n.xdwgrp with
  IMAP4-SSL; 19 Sep 2016 09:06:34 -0000
Envelope-to: miro.rovis@croatiafidelis.hr
Delivery-date: Mon, 19 Sep 2016 07:54:20 +0200
Received: from shtjevan.gbnet.net ([194.70.142.36]:40092 helo=gbnet.net)
	by lin16.mojsite.com with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)
	(Exim 4.87)
	(envelope-from <owner-mutt-users-M24736@mutt.org>)
	id 1blrWn-0003MS-1F
	for miro.rovis@croatiafidelis.hr; Mon, 19 Sep 2016 07:54:05 +0200
Received: (qmail 22405 invoked by uid 611); 19 Sep 2016 05:51:05 -0000
Received: (qmail 22396 invoked from network); 19 Sep 2016 05:50:12 -0000
Received: from davin.gbnet.net (194.70.142.37)
  by shtjevan.gbnet.net with ESMTPS (DHE-RSA-AES256-SHA encrypted); 19 Sep 2016 05:50:12 -0000
Received: (qmail 21581 invoked from network); 19 Sep 2016 05:50:11 -0000
Received: from mail-1.fido.net (84.246.192.5)
  by davin.gbnet.net with ESMTPS (DHE-RSA-AES256-SHA encrypted); 19 Sep 2016 05:50:11 -0000
Received: from disorder-1-pt.tunnel.tserv3.fmt2.ipv6.he.net ([2001:470:1f04:51a::2] helo=acedia.primate.net)
	by mail-1.fido.net with esmtps (TLSv1.2:DHE-RSA-AES256-SHA:256)
	(Exim 4.85)
	(envelope-from <itz@primate.net>)
	id 1blrSv-00046N-Ro
	for mutt-users@mutt.org; Mon, 19 Sep 2016 06:50:11 +0100
Received: from acedia.primate.net (localhost [127.0.0.1])
	by acedia.primate.net (8.15.2/8.15.2/Debian-4) with ESMTPS id u8J5nvY6011400
	(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT)
	for <mutt-users@mutt.org>; Sun, 18 Sep 2016 22:50:01 -0700
Received: (from itz@localhost)
	by acedia.primate.net (8.15.2/8.15.2/Submit) id u8J5nphc011391
	for mutt-users@mutt.org; Sun, 18 Sep 2016 22:49:51 -0700
X-Authentication-Warning: acedia.primate.net: itz set sender to itz@primate.net using -f
Received: from [10.8.78.14] (helo=matica.foolinux.mooo.com)
	by ahiker.mooo.com with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.84_2)
	(envelope-from <itz@primate.net>)
	id 1blrSf-0003av-QB
	for mutt-users@mutt.org; Sun, 18 Sep 2016 22:49:49 -0700
Received: from itz by matica.foolinux.mooo.com with local (Exim 4.87)
	(envelope-from <itz@matica.foolinux.mooo.com>)
	id 1blrSf-0003cr-Kv
	for mutt-users@mutt.org; Sun, 18 Sep 2016 22:49:49 -0700
Date: Sun, 18 Sep 2016 22:49:49 -0700
From: Ian Zimmerman <itz@primate.net>
To: mutt-users@mutt.org
Subject: Re: OT: Miro's PGP signature [Was: urlview not listing the links
 right]
Message-ID: <20160919053542.13563.3494DAB5@matica.foolinux.mooo.com>
Reply-To: mutt-users@mutt.org
Mail-Followup-To: mutt-users@mutt.org
References: <20160917232509.GK31239@g0n.xdwgrp>
 <20160918051503.GO31239@g0n.xdwgrp>
 <20160918061803.4077.03047CF5@matica.foolinux.mooo.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20160918061803.4077.03047CF5@matica.foolinux.mooo.com>
User-Agent: Mutt/1.5.24 (2015-08-30)
Received-SPF: pass (mail-1.fido.net: domain of primate.net designates 2001:470:1f04:51a::2 as permitted sender) client-ip=2001:470:1f04:51a::2; envelope-from=itz@primate.net; helo=acedia.primate.net;
X-SPF-Result: mail-1.fido.net: domain of primate.net designates 2001:470:1f04:51a::2 as permitted sender
X-Filter-ID: s0sct1PQhAABKnZB5plbIYAKkrh5rwxlcg22BKDsrZOOCXPCA86NaNMUOKEdtvy1LIlSVjYxKd9o
 YFB5W5dM3eCU7hFHKMKhsTjn2LpSPx3rcxAODBZO2BOkcGk4nUtaCoFxbjkn4j2wmbuMZaTPtfvS
 HONLSNwM3hg96wTMCb7MuoF8+O4nOW1/LrNkEnp1u3gMPBoOkS/2keJj7H49E8qYe4reQDcpl+wi
 Tdhv5z0W/8V5CaVdLqp8F5ycFsv2V7Xg7d1AhNj10O/qt7vUUHLYM3A6BXfvel8OEFDbU51GGcS0
 5jgkiHUbDsEEOtjt+L+7RqYmIKy1pzAwQlJ/LOWBOXp8nHKe0R+FkIqN7hnvaGPfye0HD8TtnikE
 nytM9PxMY/zZGDe3cLPrK1e28YdMOxkGP0yM8z6aY72dVlGiAmsvxkPOxnV038SB0TJCttEXQn4A
 vqBFHAVy3LT9EYJM7yNZmUESMKRU0n44PBFP7iQrwXcopL7kWMF6SNzbBW6vVj4DtOtAs4OkWUdh
 3D2pC00DYqwsVH2I0H503SeAbPoHi/zvVGAK2jvr4TbuGb+l42SKJnTkU0Z1DfAjVdNUWr05IAz4
 /cTo+a/AbLE=
X-Report-Abuse-To: spam@master.fido.net
Authentication-Results: fido.net; spf=pass smtp.mailfrom=itz@primate.net
X-FidoGuard-Class: ham
X-FidoGuard-Evidence: Combined (0.15)
X-Recommended-Action: accept
List-Post: <mailto:mutt-users@mutt.org>
List-Unsubscribe: send mail to majordomo@mutt.org, body only "unsubscribe mutt-users"
Precedence: bulk
Sender: owner-mutt-users@mutt.org
X-PlusHosting-MailScanner-Information: Please contact the ISP for more information
X-PlusHosting-MailScanner-ID: 1blrWn-0003MS-1F
X-PlusHosting-MailScanner: Found to be clean
X-PlusHosting-MailScanner-SpamCheck: not spam, SpamAssassin (not cached,
	score=-3.199, required 5, BAYES_00 -1.90,
	HEADER_FROM_DIFFERENT_DOMAINS 0.00, KAM_LAZY_DOMAIN_SECURITY 1.00,
	RCVD_IN_DNSWL_MED -2.30)
X-PlusHosting-MailScanner-From: owner-mutt-users-m24736@mutt.org
X-Spam-Status: No
X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?=

On 2016-09-17 23:21, Ian Zimmerman wrote:

> Can anyone else verify Miro's signature?  I'm getting "BAD signature"
> both in mutt, and when I extract the signed part and try to verify it
> with gpg from the command line.
> 
> mutt 1.5.24, gpg 2.0.28, libgcrypt 1.7.3.

I switched to gpgme-1.5.5 (up until now I used the classic gpg spawning
interface).  Sadly, same results.

One thing I learned is that it makes no sense to just dump the signed
MIME part into a file and run gpg --verify; the signature is generated
over a highly massaged version of the data, as defined by RFC 3156.  For
one thing, line endings are supposed to be CRLF, and no trailing
whitespace.  Also, the MIME part headers _are_ covered by the sig
(although in the failing cases I see, there are no headers so it
shouldn't make a difference).

me (of mutt fame) is one of the authors of RFC 3156, and seems to lurk
here.  Care to comment?

-- 
Please *no* private Cc: on mailing lists and newsgroups
Why does the arrow on Hillary signs point to the right?
