I've finally reproduced and reported that Mailman 2.1.x bug
that causes some signatures to break.
(Somebody said Ingo already nailed that bug, but I could
not find the Mailman bug report for it, so he might not have
reported it.)
On Tue, Sep 30, 2003 at 10:46:57AM -0700, SourceForge.net wrote:
> Bugs item #815297, was opened at 2003-09-30 19:42
> Message generated for change (Comment added) made by ber
> You can respond by visiting:
> https://sourceforge.net/tracker/?func=detail&atid=100103&aid=815297&group_id=103
>
> Initial Comment:
> Mailman _must_ not touch MIME-parts which are nested
> more deeply in the mail. As tested with Mailman 2.1.2,
> header lines will be sometimes reformatted in
> message/rfc822 attachments which will break the OpenPGP
> signature
> (also conforming to the PGP/MIME standard) on that part.
> This is an email security affecting bug, because if people
> start believing that a *BAD* signature does not mean much,
> because they get many broken by mailman, they will not
> react
> to a seriously manipulated email anymore!
that causes some signatures to break.
(Somebody said Ingo already nailed that bug, but I could
not find the Mailman bug report for it, so he might not have
reported it.)
On Tue, Sep 30, 2003 at 10:46:57AM -0700, SourceForge.net wrote:
> Bugs item #815297, was opened at 2003-09-30 19:42
> Message generated for change (Comment added) made by ber
> You can respond by visiting:
> https://sourceforge.net/tracker/?func=detail&atid=100103&aid=815297&group_id=103
>
> Initial Comment:
> Mailman _must_ not touch MIME-parts which are nested
> more deeply in the mail. As tested with Mailman 2.1.2,
> header lines will be sometimes reformatted in
> message/rfc822 attachments which will break the OpenPGP
> signature
> (also conforming to the PGP/MIME standard) on that part.
> This is an email security affecting bug, because if people
> start believing that a *BAD* signature does not mean much,
> because they get many broken by mailman, they will not
> react
> to a seriously manipulated email anymore!