thunderbird / thunderbird/thunderbird-android

GPG/PGP signing key should be on identity not account

Open
#942 71 comments 26 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

type: enhancement
Dominant language
Kotlin
Stars
14k
Forks
2.8k
Avg merge
3d 3h
Merged PRs (30d)
57

Description

Currently the user has to set the signing key per account.
It should be that the signing key is set per identity instead.

As the identity and key are tied to an email address but the account is not,
this is the natural order of things.
It also allows the user to use multiple signing keys based on his current role
(answering private mails, company mail or customer mail from the same account).

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing where the current per-account GPG/PGP signing key is stored and selected, then inspect how identities and their email addresses are represented. Review the issue discussion before proposing a design, since the thread is extensive. Done means signing-key selection is associated with identities and supports multiple keys for different roles from one account.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
cryptography, mobile, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.