#156 ✓released
steve

when signing + encrpyting a file, and then canceling pinentry, an encrypted and unsigned file is produced

Reported by steve | June 16th, 2017 @ 03:57 PM | in 0.8 (closed)

Tim Wilson-Brown (teor) reported this. Copying his description. He's using a Yubikey, but the issue is reproducing using gpg 2.1.21 in macOS 10.12.6b3 (no yubikey).

When I encrypt and sign a message using GPG Services, using a Yubikey,
it's easy to accidentally generate an unsigned, encrypted file without
any UI feedback.

Steps to reproduce:

Using a Yubikey (I assume any key that requires a PIN has the same
issue, but I haven't checked).

  1. Encrypt a file, so the encryption PIN has been entered already.

  2. Select a file in the finder

  3. Select Services -> OpenPGP: Encrypt File

  4. Select Sign and leave "Add To Recipients" selected

  5. When the signing PIN entry dialog comes up, click Cancel

Expected Results:

No file is produced.
An error dialog pops up with the "PIN entry failed" message.

Actual Results:

An encrypted but unsigned file is produced.
The normal "encryption succeeded" dialog does not appear.
(This is quite subtle, and easy to miss.)

Comments and changes to this ticket

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.

New-ticket Create new ticket

Create your profile

Help contribute to this project by taking a few moments to create your personal profile. Create your profile ยป

Shared Ticket Bins

People watching this ticket

Pages