[pkg-gnupg-maint] Bug#907234: gnupg warns that an email was signed by a key that expired... in 2018

Nicolas Braud-Santoni nicolas at braud-santoni.eu
Sat Aug 25 02:37:14 BST 2018


Package: gnupg
Version: 2.2.9-2
Severity: normal
Tags: upstream

Hi,

I noticed that gnupg reports that a particularly mail was signed by a key
that is expired... since 2019 :

> Problem signature from: Alexandre Viau <alexandre at alexandreviau.net>
>                    aka: Alexandre Viau (ReAzem) <reazem at reazem.net>
>                    aka: Alexandre Viau <aviau at debian.org>
>                created: Tue 21 Aug 2018 04:23:44 PM BST
> Warning: The key used to create the signature expired at: Mon 15 Jul 2019 10:54:58 PM BST

My current time is set to the correct date, and here is the output of `gpg -k`:

> $ date
> Sat Aug 25 02:32:43 BST 2018
> 
> $ gpg -k aviau
> gpg: please do a --check-trustdb
> pub   rsa4096/0xDA82830E3CCC3A3A 2014-04-01 [SC] [expires: 2019-07-15]
>       Key fingerprint = E301 54F5 429F FBB9 B22E  49C2 DA82 830E 3CCC 3A3A
> uid                   [  full  ] Alexandre Viau <alexandre at alexandreviau.net>
> uid                   [  full  ] Alexandre Viau (ReAzem) <reazem at reazem.net>
> uid                   [  full  ] Alexandre Viau <aviau at debian.org>
> 
> pub   rsa4096/0xDA82830E3CCC3A3A 2014-04-01 [SC] [expires: 2020-07-14]
>       Key fingerprint = E301 54F5 429F FBB9 B22E  49C2 DA82 830E 3CCC 3A3A
> uid                   [  full  ] Alexandre Viau <alexandre at alexandreviau.net>
> uid                   [  full  ] Alexandre Viau (ReAzem) <reazem at reazem.net>
> uid                   [  full  ] Alexandre Viau <aviau at debian.org>
> sub   rsa4096/0xD8FF317310159602 2016-06-02 [E] [expires: 2020-07-14]
> sub   rsa4096/0xA760A90DE6594708 2016-07-13 [A] [expires: 2020-07-14]
> sub   rsa4096/0x8F2B113C6535C5A7 2016-07-15 [S] [expires: 2020-07-14]


Please find attached the mail that exposed the bug.
I am using neomutt as a mail reader, in cast that's relevant.


Best,

  nicoo

-- System Information:
Debian Release: buster/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 4.17.0-3-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) (ignored: LC_ALL set to en_US.UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8) (ignored: LC_ALL set to en_US.UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages gnupg depends on:
ii  dirmngr         2.2.9-2
ii  gnupg-l10n      2.2.9-2
ii  gnupg-utils     2.2.9-2
ii  gpg             2.2.9-2
ii  gpg-agent       2.2.9-2
ii  gpg-wks-client  2.2.9-2
ii  gpg-wks-server  2.2.9-2
ii  gpgsm           2.2.9-2
ii  gpgv            2.2.9-2

gnupg recommends no packages.

Versions of packages gnupg suggests:
pn  parcimonie  <none>
pn  xloadimage  <none>

-- no debconf information



More information about the pkg-gnupg-maint mailing list