Re: [PATCH v1] gpg-interface: Signatures by expired keys are fine
Uwe Kleine-König <ukleinek@kernel.org> writes:
> If a signature is done with a valid key and that key later expires, the
> signature should still be considered good.
>
> GnuPG exmits in this case something like:
Show 10 quoted lines
> diff --git a/gpg-interface.c b/gpg-interface.c
> index 47222bf31b6e..6635c6c8e16f 100644
> --- a/gpg-interface.c
> +++ b/gpg-interface.c
> @@ -382,7 +382,7 @@ static int verify_gpg_signed_buffer(struct signature_check *sigc,
>
> delete_tempfile(&temp);
>
> - ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ");
> + ret |= !strstr(gpg_stdout.buf, "\n[GNUPG:] GOODSIG ") && !strstr(gpg_stdout.buf, "\n[GNUPG:] EXPKEYSIG ");
Makes sense; I'll wrap this overlong line while queuing, though.
Show 14 quoted lines
> sigc->output = strbuf_detach(&gpg_stderr, NULL);
> sigc->gpg_status = strbuf_detach(&gpg_stdout, NULL);
>
> @@ -680,7 +680,7 @@ int check_signature(struct signature_check *sigc,
> if (status && !sigc->output)
> return !!status;
>
> - status |= sigc->result != 'G';
> + status |= sigc->result != 'G' && sigc->result != 'Y';
> status |= sigc->trust_level < configured_min_trust_level;
>
> return !!status;
>
> base-commit: b2826b52eb7caff9f4ed6e85ec45e338bf02ad09