From lurker-index@localhost Fri Sep 23 08:06:17 2016
Return-Path: <owner-mutt-users-M24769@mutt.org>
Received: from lin16.mojsite.com (178.218.164.164:993) by g0n.xdwgrp with
  IMAP4-SSL; 23 Sep 2016 06:06:17 -0000
Envelope-to: miro.rovis@croatiafidelis.hr
Delivery-date: Thu, 22 Sep 2016 04:18:31 +0200
Received: from shtjevan.gbnet.net ([194.70.142.36]:44066 helo=gbnet.net)
	by lin16.mojsite.com with esmtps (TLSv1:DHE-RSA-AES256-SHA:256)
	(Exim 4.87)
	(envelope-from <owner-mutt-users-M24769@mutt.org>)
	id 1bmtaj-0000CJ-LR
	for miro.rovis@croatiafidelis.hr; Thu, 22 Sep 2016 04:18:25 +0200
Received: (qmail 14100 invoked by uid 611); 22 Sep 2016 02:15:20 -0000
Received: (qmail 14066 invoked from network); 22 Sep 2016 02:14:20 -0000
Received: from mail-1.fido.net (84.246.192.5)
  by shtjevan.gbnet.net with ESMTPS (DHE-RSA-AES256-SHA encrypted); 22 Sep 2016 02:14:20 -0000
Received: from disorder-1-pt.tunnel.tserv3.fmt2.ipv6.he.net ([2001:470:1f04:51a::2] helo=acedia.primate.net)
	by mail-1.fido.net with esmtps (TLSv1.2:ECDHE-RSA-AES256-SHA:256)
	(Exim 4.86)
	(envelope-from <itz@primate.net>)
	id 1bmtWf-0003kv-RO
	for mutt-users@mutt.org; Thu, 22 Sep 2016 03:14:20 +0100
Received: from acedia.primate.net (localhost [127.0.0.1])
	by acedia.primate.net (8.15.2/8.15.2/Debian-6) with ESMTPS id u8M2E75Y021900
	(version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT)
	for <mutt-users@mutt.org>; Wed, 21 Sep 2016 19:14:11 -0700
Received: (from itz@localhost)
	by acedia.primate.net (8.15.2/8.15.2/Submit) id u8M2E1BG021884
	for mutt-users@mutt.org; Wed, 21 Sep 2016 19:14:01 -0700
X-Authentication-Warning: acedia.primate.net: itz set sender to itz@primate.net using -f
Received: from [10.8.78.14] (helo=matica.foolinux.mooo.com)
	by ahiker.mooo.com with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.84_2)
	(envelope-from <itz@primate.net>)
	id 1bmtWR-0003U2-Q6
	for mutt-users@mutt.org; Wed, 21 Sep 2016 19:13:59 -0700
Received: from itz by matica.foolinux.mooo.com with local (Exim 4.87)
	(envelope-from <itz@matica.foolinux.mooo.com>)
	id 1bmtWR-0005aX-II
	for mutt-users@mutt.org; Wed, 21 Sep 2016 19:13:59 -0700
Date: Wed, 21 Sep 2016 19:13:59 -0700
From: Ian Zimmerman <itz@primate.net>
To: mutt-users@mutt.org
Subject: Re: PGP sigs fail verification
Message-ID: <20160922014629.20730.16A6B720@matica.foolinux.mooo.com>
Reply-To: mutt-users@mutt.org
Mail-Followup-To: mutt-users@mutt.org
References: <20160917232509.GK31239@g0n.xdwgrp>
 <20160918051503.GO31239@g0n.xdwgrp>
 <20160918061803.4077.03047CF5@matica.foolinux.mooo.com>
 <20160918064328.ts37vzdr6ehds6ln@lovelace.schplaf>
 <20160921104046.GD1147@adversary.org>
 <20160921213236.GD24944@dragontoe.org>
 <20160921214124.GA46901@aura.veggiechinese.net>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <20160921214124.GA46901@aura.veggiechinese.net>
User-Agent: Mutt/1.5.24 (2015-08-30)
Received-SPF: pass (mail-1.fido.net: domain of primate.net designates 2001:470:1f04:51a::2 as permitted sender) client-ip=2001:470:1f04:51a::2; envelope-from=itz@primate.net; helo=acedia.primate.net;
X-SPF-Result: mail-1.fido.net: domain of primate.net designates 2001:470:1f04:51a::2 as permitted sender
X-Filter-ID: s0sct1PQhAABKnZB5plbIYAKkrh5rwxlcg22BKDsrZOOCXPCA86NaNMUOKEdtvy1LIlSVjYxKd9o
 YFB5W5dM3eCU7hFHKMKhsTjn2LpSPx3rcxAODBZO2BOkcGk4nUtaCoFxbjkn4j2wmbuMZaTPtfvS
 HONLSNwM3hg96wTMCb7MuoF8+O4nOW1/LrNkEnp1u3gMPBoOkS/2keJj7H49E8qYe4reQDcpl+wi
 Tdhv5z3xffWm1k0B/LaC8r86TnQmUOiLkAoSZP7WW9QJS7iDUHLYM3A6BXfvel8OEFDbU51GGcS0
 5jgkiHUbDsEEOtjt+L+7RqYmIKy1pzAwQlJ/LOWBOXp8nHKe0R+FkIqN7hnvaGPfye0HD8TtnikE
 nytM9PxMY/zZGDe3cLPrK1e28YdMOxkGP0yM8z6aY72dVlGiAmsvxkPOxnV038SB0TJCttEXQn4A
 vqBFHAVy3LT9EYJM7yNZmUESMKRU0n44PBFP7iQrwXcopL7kWMF6SNzbBW6vVj4DtOtAs4OkWUdh
 3D2pC00DYqwsVH2I0H503SeAbPoHi/zvVGAK2jvr4TbuGb+l42SKJnTkU0Z1DfAjVdNUWr05IAz4
 /cTo+a/AbLE=
X-Report-Abuse-To: spam@master.fido.net
Authentication-Results: fido.net; spf=pass smtp.mailfrom=itz@primate.net
X-FidoGuard-Class: ham
X-FidoGuard-Evidence: Combined (0.15)
X-Recommended-Action: accept
List-Post: <mailto:mutt-users@mutt.org>
List-Unsubscribe: send mail to majordomo@mutt.org, body only "unsubscribe mutt-users"
Precedence: bulk
Sender: owner-mutt-users@mutt.org
X-PlusHosting-MailScanner-Information: Please contact the ISP for more information
X-PlusHosting-MailScanner-ID: 1bmtaj-0000CJ-LR
X-PlusHosting-MailScanner: Found to be clean
X-PlusHosting-MailScanner-SpamCheck: not spam, SpamAssassin (not cached,
	score=-6.299, required 5, autolearn=not spam, BAYES_00 -5.00,
	HEADER_FROM_DIFFERENT_DOMAINS 0.00, KAM_LAZY_DOMAIN_SECURITY 1.00,
	RCVD_IN_DNSWL_MED -2.30)
X-PlusHosting-MailScanner-From: owner-mutt-users-m24769@mutt.org
X-Spam-Status: No
X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?=

This post is mostly just to fix the subject :-P

But this may be a good time to give a very high-level view of the
problem.  There are two parts:

1. Some (apparently genuine) mails fail with "BAD signature", _both_
when reading through mutt and when verifying manually with gpg.  This is
a bug, not a flea.

It is very strange that in some of these cases, one mail from a person
checks out fine, and the next mail from the same person, sent with the
same MUA according to their X-Mailer header, fails.  This makes it less
likely that it is just a gpg version mismatch, but I really don't know
what else to blame.  Going through gpg changelogs between my version
(2.0.28) and current tip, nothing jumps out at me.

One special subcase of this so far can be squarely blamed on the sending
side.  My next step here is to catalogue the characteristics of the
sending systems, if available.

2. In _one_ case only so far, the same mail checks out with manual gpg,
but mutt gives "BAD signature".  This is clearly a flea, but I have no
idea where to look for it.  And again, other mails from the same person,
same sending system characteristics, check out fine in mutt as well as
with gpg.

My next step here is probably turning on mutt debug logs, and if nothing
jumps out, adding my own logs to the code.

-- 
Please *no* private Cc: on mailing lists and newsgroups
Why does the arrow on Hillary signs point to the right?
