<?xml version="1.0" encoding="UTF-8"?> 
<?xml-stylesheet href="https://dev.horde.org/themes/horde//default/feed-rss.xsl" type="text/xsl"?> 
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"> 
 <channel> 
  <title>gpg keys pair</title> 
  <pubDate>Fri, 10 Apr 2026 03:14:11 +0000</pubDate> 
  <link>https://bugs.horde.org/ticket/6872</link> 
  <atom:link rel="self" type="application/rss+xml" title="gpg keys pair" href="https://bugs.horde.org/ticket/6872/rss" /> 
  <description>gpg keys pair</description> 
 
   
   
  <item> 
   <title>i think that it&#039;s a high security risk to save private key i</title> 
   <description>i think that it&#039;s a high security risk to save private key into the database



i think that horde/imp must use keys (and keyrings) contained into the private/hidden directory .gnupg of every user; horde/imp must use gnupg command line (sudo&#039;ed as spamassassin) for every operation</description> 
   <pubDate>Mon, 09 Jun 2008 16:30:17 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46128</link> 
  </item> 
   
  <item> 
   <title>&gt; i think that it&#039;s a high security risk to save private key</title> 
   <description>&gt; i think that it&#039;s a high security risk to save private key into the database



Then don&#039;t use PGP on Horde if you find this not acceptable.



&gt; i think that horde/imp must use keys (and keyrings) contained into 

&gt; the private/hidden directory .gnupg of every user; horde/imp must use 

&gt; gnupg command line (sudo&#039;ed as spamassassin) for every operation



What user directory?  Horde/IMP has no access to a user&#039;s home directory.</description> 
   <pubDate>Mon, 09 Jun 2008 16:44:42 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46130</link> 
  </item> 
   
  <item> 
   <title>&gt;&gt; i think that it&#039;s a high security risk to save private ke</title> 
   <description>&gt;&gt; i think that it&#039;s a high security risk to save private key into the database

&gt;

&gt; Then don&#039;t use PGP on Horde if you find this not acceptable.



Indeed, for now I can not use it; but I like to use it in the future



&gt;&gt; i think that horde/imp must use keys (and keyrings) contained into

&gt;&gt; the private/hidden directory .gnupg of every user; horde/imp must use

&gt;&gt; gnupg command line (sudo&#039;ed as spamassassin) for every operation

&gt;

&gt; What user directory?  Horde/IMP has no access to a user&#039;s home directory.



not horde, but gnupg yes



if you run gnugp sudo&#039;ed with the logged user, i think it can access the user&#039;s home

</description> 
   <pubDate>Tue, 10 Jun 2008 06:58:31 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46165</link> 
  </item> 
   
  <item> 
   <title>&gt;&gt;&gt; i think that horde/imp must use keys (and keyrings) cont</title> 
   <description>&gt;&gt;&gt; i think that horde/imp must use keys (and keyrings) contained into

&gt;&gt;&gt; the private/hidden directory .gnupg of every user; horde/imp must use

&gt;&gt;&gt; gnupg command line (sudo&#039;ed as spamassassin) for every operation

&gt;&gt;

&gt;&gt; What user directory?  Horde/IMP has no access to a user&#039;s home directory.

&gt;

&gt; not horde, but gnupg yes

&gt;

&gt; if you run gnugp sudo&#039;ed with the logged user, i think it can access 

&gt; the user&#039;s home



There is absolutely no requirement that users have accounts on the server running Horde. Not to mention that a web process having sudo powers is likely opening up a *way* bigger security hole than any security shortcomings you are trying to mask.</description> 
   <pubDate>Tue, 10 Jun 2008 07:04:16 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46167</link> 
  </item> 
   
  <item> 
   <title>&gt;&gt;&gt;&gt; i think that horde/imp must use keys (and keyrings) con</title> 
   <description>&gt;&gt;&gt;&gt; i think that horde/imp must use keys (and keyrings) contained into

&gt;&gt;&gt;&gt; the private/hidden directory .gnupg of every user; horde/imp must use

&gt;&gt;&gt;&gt; gnupg command line (sudo&#039;ed as spamassassin) for every operation

&gt;&gt;&gt;

&gt;&gt;&gt; What user directory?  Horde/IMP has no access to a user&#039;s home directory.

&gt;&gt;

&gt;&gt; not horde, but gnupg yes

&gt;&gt;

&gt;&gt; if you run gnugp sudo&#039;ed with the logged user, i think it can access

&gt;&gt; the user&#039;s home

&gt;

&gt; There is absolutely no requirement that users have accounts on the 

&gt; server running Horde. 



but it can; and it can have his .gnupg directory with his public/private keys and his keyrings already full



&gt;Not to mention that a web process having sudo 

&gt; powers is likely opening up a *way* bigger security hole than any 

&gt; security shortcomings you are trying to mask.



i don&#039;t know... i&#039;m not very expert... but i think that is easier to &quot;crack&quot; a db that a process ran with sudo</description> 
   <pubDate>Tue, 10 Jun 2008 07:29:13 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46170</link> 
  </item> 
   
  <item> 
   <title>&gt;[...]

&gt;

&gt;&gt; Not to mention that a web process having sudo
</title> 
   <description>&gt;[...]

&gt;

&gt;&gt; Not to mention that a web process having sudo

&gt;&gt; powers is likely opening up a *way* bigger security hole than any

&gt;&gt; security shortcomings you are trying to mask.

&gt;

&gt; i don&#039;t know... i&#039;m not very expert... but i think that is easier to 

&gt; &quot;crack&quot; a db that a process ran with sudo



if you don&#039;t want to use sudo, i think you can use the gnupg&#039;s parameter --homedir (which value can be saved on user&#039;s preferences)</description> 
   <pubDate>Tue, 10 Jun 2008 11:45:44 +0000</pubDate> 
   <link>https://bugs.horde.org/ticket/6872#t46186</link> 
  </item> 
   
   
 
 </channel> 
</rss> 
