feat: allow to not sign asymmetrically encrypted multi-recipient messages

An unsigned message carries no intended recipient fingerprints,
so recipients of an encrypted unsigned message
learn nothing about other recipients from the PGP packets.
This commit is contained in:
holger krekel
2026-08-29 23:11:05 +02:00
parent 5176a9c633
commit 08b2374fcf
6 changed files with 98 additions and 57 deletions
+3 -7
View File
@@ -407,6 +407,8 @@ pub(crate) fn render_queued_mail(
}
}
let sign_key = if should_sign { Some(secret_key) } else { None };
let message = match encryption {
Encryption::No => raw_message,
Encryption::Asymmetric { encryption_pubkeys } => {
@@ -434,7 +436,7 @@ pub(crate) fn render_queued_mail(
let encrypted = crate::pgp::pk_encrypt(
full_raw_message,
encryption_keyring,
secret_key.clone(),
sign_key,
should_compress,
seipd_version,
)?;
@@ -446,12 +448,6 @@ pub(crate) fn render_queued_mail(
let mut full_raw_message = inner_headers.clone();
full_raw_message.extend(raw_message);
let sign_key = if should_sign {
Some(secret_key.clone())
} else {
None
};
let encrypted = crate::pgp::symm_encrypt_message(
full_raw_message,
sign_key,