Passwords are unwillingly being saved throughout session

Holger Näther holger.naether at mac.com
Tue Nov 30 23:56:14 CET 2010


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi guys,

I have a feeling something is not working for me as I intend it to, or as it was probably planned by the programmer.

My system details:

Operating system: Mac OS X 10.6.5
GPG version: 2.0.16
libgcrypt version: 1.4.6
GPGMail version: 1.3.1

When I boot up the system and start a program using gpg for the first time (after reboot), ie. Mail.app or PSI.app, everything is normal. To sign or encrypt requires my pass-phrase, as I also need it to verify or to decrypt. But after that I am not asked for the pass-phrase again.

I can close the programs completely and restart them, pinentry does not show up anymore and the signing/encryption/verification/decryption is done without the necessity of my pass-phrase. I can even log out of my user session and back in, and the same situation. Only after a complete reboot of the computer, I am asked exactly once per program for my pass-phrase. It seems to be stored somewhere, but I have no idea where. I don't want it to be stored, I want to enter it, whenever needed.

I have checked within GPGMail, where the option to always ask for the phrase is set. I have checked the Keychain.app, but no phrase is stored there. I have checked the net, but am not getting any hits since ... well, I have to admit I'm not even sure how to pass my question on to google; what to search for.

I hope one of you might have experienced something like this before and can give me a short hint as to where to look.

Thanks and best regards,

Holger

-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.16 (Darwin)

iQIcBAEBAgAGBQJM9YEXAAoJENVOU/3eUfz6w/wP/iVE0zkAYv/sU9f4KsotC8aD
G9fwA33DfpRb+DJZIEvU6Kd5/EZC073+X+QdxpmMRaasZo5v/T54e/tNVgSUwHAp
6b2D69ix+2BnFCoh2Agj2ivm0QXu5j5CvbKMq4CYNuqZgVWx1KqZxWDmnrGJrDjC
RirOkV+jwqobBj/SeQqK3ElLzsrLO3svAfDHZ/uUQ0KW1OzFFMPxmZET3Cv9WYNl
oGnbdJu7+n9raGEuyYYF8V93XVZanCkdeWUY2paF7eX7nD247nRGpcEACD0fhOsq
ruDKEYjRLOTkwHCFEefLwS/9rzgsILtqHriBVy+ZHZZottqu7WDw9GqFy/0OXAwB
5t6UTlFVUBCLvjmttrFSfx18Np8f2QNsoPtblmG8PE94LSwMbLTNH3IWSdm3JWWu
UBX2am9IoK1KXaCYPjyoHXOd1wHpUWSx02PuDS/sgFjrzk8HjabPJIwACY5fjLXt
DEyTTONImkBbOoyM09Re62UJllFzj1keVMfYgJlwzIlEO4TWmUYWKM248HyGu2eZ
2JN/AYP9a9UhdfFKY7bmryKk0cc6aNzXGfnK1YtDsIADX4aTiXqwUQ2nSmh5+PBe
5SeDdXaqgB4SA2SzgPlAZNaNNA9phtWXhVQDba4dZ6FTWBSh7PYHFAwpNwoTKSwA
IIENi005e4o3nquUc8xM
=ZIiU
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list