1 ;;; epa.el --- the EasyPG Assistant
2 ;; Copyright (C) 2006 Daiki Ueno
4 ;; Author: Daiki Ueno <ueno@unixuser.org>
5 ;; Keywords: PGP, GnuPG
7 ;; This file is part of EasyPG.
9 ;; This program is free software; you can redistribute it and/or modify
10 ;; it under the terms of the GNU General Public License as published by
11 ;; the Free Software Foundation; either version 2, or (at your option)
14 ;; This program is distributed in the hope that it will be useful,
15 ;; but WITHOUT ANY WARRANTY; without even the implied warranty of
16 ;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
17 ;; GNU General Public License for more details.
19 ;; You should have received a copy of the GNU General Public License
20 ;; along with GNU Emacs; see the file COPYING. If not, write to the
21 ;; Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor,
22 ;; Boston, MA 02110-1301, USA.
29 (eval-when-compile (require 'wid-edit))
32 "The EasyPG Assistant"
35 (defcustom epa-armor nil
36 "If non-nil, epa commands create ASCII armored output."
40 (defcustom epa-textmode nil
41 "If non-nil, epa commands treat input files as text."
45 (defcustom epa-popup-info-window nil
46 "If non-nil, status information from epa commands is displayed on
51 (defcustom epa-info-window-height 5
52 "Number of lines used to display status information."
56 (defgroup epa-faces nil
60 (defface epa-validity-high-face
61 '((((class color) (background dark))
62 (:foreground "PaleTurquoise" :bold t))
65 "Face used for displaying the high validity."
67 (defvar epa-validity-high-face 'epa-validity-high-face)
69 (defface epa-validity-medium-face
70 '((((class color) (background dark))
71 (:foreground "PaleTurquoise" :italic t))
74 "Face used for displaying the medium validity."
76 (defvar epa-validity-medium-face 'epa-validity-medium-face)
78 (defface epa-validity-low-face
81 "Face used for displaying the low validity."
83 (defvar epa-validity-low-face 'epa-validity-low-face)
85 (defface epa-validity-disabled-face
87 (:italic t :inverse-video t)))
88 "Face used for displaying the disabled validity."
90 (defvar epa-validity-disabled-face 'epa-validity-disabled-face)
92 (defface epa-string-face
95 (:foreground "lightyellow"))
98 (:foreground "blue4"))
101 "Face used for displaying the string."
103 (defvar epa-string-face 'epa-string-face)
105 (defface epa-mark-face
106 '((((class color) (background dark))
107 (:foreground "orange" :bold t))
109 (:foreground "red" :bold t)))
110 "Face used for displaying the high validity."
112 (defvar epa-mark-face 'epa-mark-face)
114 (defface epa-field-name-face
115 '((((class color) (background dark))
116 (:foreground "PaleTurquoise" :bold t))
118 "Face for the name of the attribute field."
120 (defvar epa-field-name-face 'epa-field-name-face)
122 (defface epa-field-body-face
123 '((((class color) (background dark))
124 (:foreground "turquoise" :italic t))
126 "Face for the body of the attribute field."
128 (defvar epa-field-body-face 'epa-field-body-face)
130 (defcustom epa-validity-face-alist
131 '((unknown . epa-validity-disabled-face)
132 (invalid . epa-validity-disabled-face)
133 (disabled . epa-validity-disabled-face)
134 (revoked . epa-validity-disabled-face)
135 (expired . epa-validity-disabled-face)
136 (none . epa-validity-low-face)
137 (undefined . epa-validity-low-face)
138 (never . epa-validity-low-face)
139 (marginal . epa-validity-medium-face)
140 (full . epa-validity-high-face)
141 (ultimate . epa-validity-high-face))
142 "An alist mapping validity values to faces."
146 (defcustom epa-font-lock-keywords
149 ("^\t\\([^\t:]+:\\)[ \t]*\\(.*\\)$"
150 (1 epa-field-name-face)
151 (2 epa-field-body-face)))
152 "Default expressions to addon in epa-mode."
153 :type '(repeat (list string))
156 (defconst epa-pubkey-algorithm-letter-alist
164 (defvar epa-keys-buffer nil)
165 (defvar epa-key-buffer-alist nil)
167 (defvar epa-list-keys-arguments nil)
168 (defvar epa-info-buffer nil)
170 (defvar epa-keys-mode-map
171 (let ((keymap (make-sparse-keymap)))
172 (define-key keymap "m" 'epa-mark)
173 (define-key keymap "u" 'epa-unmark)
174 (define-key keymap "d" 'epa-decrypt-file)
175 (define-key keymap "v" 'epa-verify-file)
176 (define-key keymap "s" 'epa-sign-file)
177 (define-key keymap "S" 'epa-sign-keys)
178 (define-key keymap "e" 'epa-encrypt-file)
179 (define-key keymap "r" 'epa-delete-keys)
180 (define-key keymap "i" 'epa-import-keys)
181 (define-key keymap "o" 'epa-export-keys)
182 (define-key keymap "g" 'epa-list-keys)
183 (define-key keymap "n" 'next-line)
184 (define-key keymap "p" 'previous-line)
185 (define-key keymap " " 'scroll-up)
186 (define-key keymap [delete] 'scroll-down)
187 (define-key keymap "q" 'epa-exit-buffer)
190 (defvar epa-key-mode-map
191 (let ((keymap (make-sparse-keymap)))
192 (define-key keymap "q" 'bury-buffer)
195 (defvar epa-info-mode-map
196 (let ((keymap (make-sparse-keymap)))
197 (define-key keymap "q" 'delete-window)
200 (defvar epa-exit-buffer-function #'bury-buffer)
202 (define-widget 'epa-key 'push-button
203 "Button for representing a epg-key object."
205 :button-face-get 'epa-key-widget-button-face-get
206 :value-create 'epa-key-widget-value-create
207 :action 'epa-key-widget-action
208 :help-echo 'epa-key-widget-help-echo)
210 (defun epa-key-widget-action (widget &optional event)
211 (epa-show-key (widget-get widget :value)))
213 (defun epa-key-widget-value-create (widget)
214 (let* ((key (widget-get widget :value))
215 (primary-sub-key (car (epg-key-sub-key-list key)))
216 (primary-user-id (car (epg-key-user-id-list key))))
217 (insert (format "%c "
218 (if (epg-sub-key-validity primary-sub-key)
219 (car (rassq (epg-sub-key-validity primary-sub-key)
220 epg-key-validity-alist))
222 (epg-sub-key-id primary-sub-key)
224 (if (stringp (epg-user-id-string primary-user-id))
225 (epg-user-id-string primary-user-id)
226 (epg-decode-dn (epg-user-id-string primary-user-id))))))
228 (defun epa-key-widget-button-face-get (widget)
229 (let ((validity (epg-sub-key-validity (car (epg-key-sub-key-list
230 (widget-get widget :value))))))
232 (cdr (assq validity epa-validity-face-alist))
235 (defun epa-key-widget-help-echo (widget)
237 (epg-sub-key-id (car (epg-key-sub-key-list
238 (widget-get widget :value))))))
240 (defun epa-keys-mode ()
241 "Major mode for `epa-list-keys'."
242 (kill-all-local-variables)
243 (buffer-disable-undo)
244 (setq major-mode 'epa-keys-mode
248 (use-local-map epa-keys-mode-map)
249 (set-keymap-parent (current-local-map) widget-keymap)
250 (make-local-variable 'font-lock-defaults)
251 (setq font-lock-defaults '(epa-font-lock-keywords t))
252 ;; In XEmacs, auto-initialization of font-lock is not effective
253 ;; if buffer-file-name is not set.
254 (font-lock-set-defaults)
256 (make-local-variable 'epa-exit-buffer-function)
257 (run-hooks 'epa-keys-mode-hook))
259 (defun epa-key-mode ()
260 "Major mode for `epa-show-key'."
261 (kill-all-local-variables)
262 (buffer-disable-undo)
263 (setq major-mode 'epa-key-mode
267 (use-local-map epa-key-mode-map)
268 (make-local-variable 'font-lock-defaults)
269 (setq font-lock-defaults '(epa-font-lock-keywords t))
270 ;; In XEmacs, auto-initialization of font-lock is not effective
271 ;; if buffer-file-name is not set.
272 (font-lock-set-defaults)
273 (make-local-variable 'epa-exit-buffer-function)
274 (run-hooks 'epa-key-mode-hook))
277 (defun epa-list-keys (&optional name mode protocol)
279 (if current-prefix-arg
280 (let ((name (read-string "Pattern: "
281 (if epa-list-keys-arguments
282 (car epa-list-keys-arguments)))))
283 (list (if (equal name "") nil name)
284 (y-or-n-p "Secret keys? ")
285 (intern (completing-read "Protocol? "
286 '(("OpenPGP") ("CMS"))
288 (or epa-list-keys-arguments (list nil nil nil))))
289 (unless (and epa-keys-buffer
290 (buffer-live-p epa-keys-buffer))
291 (setq epa-keys-buffer (generate-new-buffer "*Keys*")))
292 (set-buffer epa-keys-buffer)
293 (let ((inhibit-read-only t)
296 (context (epg-make-context protocol)))
297 (unless (get-text-property point 'epa-list-keys)
298 (setq point (next-single-property-change point 'epa-list-keys)))
301 (or (next-single-property-change point 'epa-list-keys)
304 (epa-insert-keys context name mode)
306 (make-local-variable 'epa-list-keys-arguments)
307 (setq epa-list-keys-arguments (list name mode protocol))
308 (goto-char (point-min))
309 (pop-to-buffer (current-buffer)))
311 (defun epa-insert-keys (context name mode)
314 (narrow-to-region (point) (point))
315 (let ((keys (epg-list-keys context name mode))
320 (add-text-properties point (point)
321 (list 'epa-key (car keys)
326 (widget-create 'epa-key :value (car keys))
328 (setq keys (cdr keys))))
329 (add-text-properties (point-min) (point-max)
330 (list 'epa-list-keys t
336 (defun epa-marked-keys ()
338 (set-buffer epa-keys-buffer)
339 (goto-char (point-min))
341 (while (re-search-forward "^\\*" nil t)
342 (if (setq key (get-text-property (match-beginning 0)
344 (setq keys (cons key keys))))
348 (let ((key (get-text-property (point) 'epa-key)))
353 (defun epa-select-keys (context prompt &optional names secret)
354 "Display a user's keyring and ask him to select keys.
355 CONTEXT is an epg-context.
356 PROMPT is a string to prompt with.
357 NAMES is a list of strings to be matched with keys. If it is nil, all
359 If SECRET is non-nil, list secret keys instead of public keys."
361 (unless (and epa-keys-buffer
362 (buffer-live-p epa-keys-buffer))
363 (setq epa-keys-buffer (generate-new-buffer "*Keys*")))
364 (let ((inhibit-read-only t)
366 (set-buffer epa-keys-buffer)
370 :notify (lambda (&rest ignore) (abort-recursive-edit))
372 (substitute-command-keys
373 "Click here or \\[abort-recursive-edit] to cancel")
376 :notify (lambda (&rest ignore) (exit-recursive-edit))
378 (substitute-command-keys
379 "Click here or \\[exit-recursive-edit] to finish")
384 (epa-insert-keys context (car names) secret)
385 (if (get-text-property (point) 'epa-list-keys)
387 (goto-char (point-max))
388 (setq names (cdr names)))
391 (epa-insert-keys context nil secret)
392 (if (get-text-property (point) 'epa-list-keys)
394 (epa-insert-keys context nil nil)))
396 (setq epa-exit-buffer-function #'abort-recursive-edit)
397 (goto-char (point-min))
398 (pop-to-buffer (current-buffer)))
403 (if (get-buffer-window epa-keys-buffer)
404 (delete-window (get-buffer-window epa-keys-buffer)))
405 (kill-buffer epa-keys-buffer))))
407 (defun epa-show-key (key)
408 (let* ((primary-sub-key (car (epg-key-sub-key-list key)))
409 (entry (assoc (epg-sub-key-id primary-sub-key)
410 epa-key-buffer-alist))
411 (inhibit-read-only t)
415 (setq entry (cons (epg-sub-key-id primary-sub-key) nil)
416 epa-key-buffer-alist (cons entry epa-key-buffer-alist)))
417 (unless (and (cdr entry)
418 (buffer-live-p (cdr entry)))
419 (setcdr entry (generate-new-buffer
420 (format "*Key*%s" (epg-sub-key-id primary-sub-key)))))
421 (set-buffer (cdr entry))
422 (make-local-variable 'epa-key)
425 (setq pointer (epg-key-user-id-list key))
428 (if (epg-user-id-validity (car pointer))
430 (car (rassq (epg-user-id-validity (car pointer))
431 epg-key-validity-alist)))
434 (if (stringp (epg-user-id-string (car pointer)))
435 (epg-user-id-string (car pointer))
436 (epg-decode-dn (epg-user-id-string (car pointer))))
438 (setq pointer (cdr pointer)))
439 (setq pointer (epg-key-sub-key-list key))
442 (if (epg-sub-key-validity (car pointer))
444 (car (rassq (epg-sub-key-validity (car pointer))
445 epg-key-validity-alist)))
448 (epg-sub-key-id (car pointer))
451 (epg-sub-key-length (car pointer)))
453 (cdr (assq (epg-sub-key-algorithm (car pointer))
454 epg-pubkey-algorithm-alist))
456 (format-time-string "%Y-%m-%d"
457 (epg-sub-key-creation-time (car pointer)))
458 (if (epg-sub-key-expiration-time (car pointer))
459 (format "\n\tExpires: %s"
460 (format-time-string "%Y-%m-%d"
461 (epg-sub-key-expiration-time
465 (mapconcat #'symbol-name
466 (epg-sub-key-capability (car pointer))
469 (epg-sub-key-fingerprint (car pointer))
471 (setq pointer (cdr pointer)))
472 (goto-char (point-min))
473 (pop-to-buffer (current-buffer))
476 (defun epa-show-key-notify (widget &rest ignore)
477 (epa-show-key (widget-get widget :value)))
479 (defun epa-mark (&optional arg)
480 "Mark the current line.
481 If ARG is non-nil, unmark the current line."
483 (let ((inhibit-read-only t)
487 (setq properties (text-properties-at (point)))
489 (insert (if arg " " "*"))
490 (set-text-properties (1- (point)) (point) properties)
493 (defun epa-unmark (&optional arg)
494 "Unmark the current line.
495 If ARG is non-nil, mark the current line."
497 (epa-mark (not arg)))
499 (defun epa-toggle-mark ()
500 "Toggle the mark the current line."
502 (epa-mark (eq (char-after (save-excursion (beginning-of-line) (point))) ?*)))
504 (defun epa-exit-buffer ()
505 "Exit the current buffer.
506 `epa-exit-buffer-function' is called if it is set."
508 (funcall epa-exit-buffer-function))
510 (defun epa-display-verify-result (verify-result)
511 (if epa-popup-info-window
513 (unless epa-info-buffer
514 (setq epa-info-buffer (generate-new-buffer "*Info*")))
516 (set-buffer epa-info-buffer)
517 (let ((inhibit-read-only t)
520 (insert (epg-verify-result-to-string verify-result)))
522 (pop-to-buffer epa-info-buffer)
523 (if (> (window-height) epa-info-window-height)
524 (shrink-window (- (window-height) epa-info-window-height)))
525 (goto-char (point-min)))
526 (message "%s" (epg-verify-result-to-string verify-result))))
528 (defun epa-info-mode ()
529 "Major mode for `epa-info-buffer'."
530 (kill-all-local-variables)
531 (buffer-disable-undo)
532 (setq major-mode 'epa-info-mode
536 (use-local-map epa-info-mode-map)
537 (run-hooks 'epa-info-mode-hook))
540 (defun epa-decrypt-file (file)
542 (interactive "fFile: ")
543 (let* ((default-name (file-name-sans-extension file))
544 (plain (expand-file-name
546 (concat "To file (default "
547 (file-name-nondirectory default-name)
549 (file-name-directory default-name)
551 (context (epg-make-context)))
552 (message "Decrypting %s..." (file-name-nondirectory file))
553 (epg-decrypt-file context file plain)
554 (message "Decrypting %s...done" (file-name-nondirectory file))
555 (if (epg-context-result-for context 'verify)
556 (epa-display-verify-result (epg-context-result-for context 'verify)))))
559 (defun epa-verify-file (file)
561 (interactive "fFile: ")
562 (let* ((context (epg-make-context))
563 (plain (if (equal (file-name-extension file) "sig")
564 (file-name-sans-extension file))))
565 (message "Verifying %s..." (file-name-nondirectory file))
566 (epg-verify-file context file plain)
567 (message "Verifying %s...done" (file-name-nondirectory file))
568 (if (epg-context-result-for context 'verify)
569 (epa-display-verify-result (epg-context-result-for context 'verify)))))
572 (defun epa-sign-file (file signers mode)
573 "Sign FILE by SIGNERS keys selected."
575 (list (expand-file-name (read-file-name "File: "))
576 (epa-select-keys (epg-make-context) "Select keys for signing.
577 If no one is selected, default secret key is used. "
579 (if (y-or-n-p "Make a detached signature? ")
581 (if (y-or-n-p "Make a cleartext signature? ")
583 (let ((signature (concat file
585 (not (memq mode '(nil t normal detached))))
587 (if (memq mode '(t detached))
590 (context (epg-make-context)))
591 (epg-context-set-armor context epa-armor)
592 (epg-context-set-textmode context epa-textmode)
593 (epg-context-set-signers context signers)
594 (message "Signing %s..." (file-name-nondirectory file))
595 (epg-sign-file context file signature mode)
596 (message "Signing %s...done" (file-name-nondirectory file))))
599 (defun epa-encrypt-file (file recipients)
600 "Encrypt FILE for RECIPIENTS."
602 (list (expand-file-name (read-file-name "File: "))
603 (epa-select-keys (epg-make-context) "Select recipients for encryption.
604 If no one is selected, symmetric encryption will be performed. ")))
605 (let ((cipher (concat file (if epa-armor ".asc" ".gpg")))
606 (context (epg-make-context)))
607 (epg-context-set-armor context epa-armor)
608 (epg-context-set-textmode context epa-textmode)
609 (message "Encrypting %s..." (file-name-nondirectory file))
610 (epg-encrypt-file context file recipients cipher)
611 (message "Encrypting %s...done" (file-name-nondirectory file))))
614 (defun epa-decrypt-region (start end)
615 "Decrypt the current region between START and END.
617 Don't use this command in Lisp programs!"
620 (let ((context (epg-make-context))
622 (message "Decrypting...")
623 (setq plain (epg-decrypt-string context (buffer-substring start end)))
624 (message "Decrypting...done")
625 (delete-region start end)
627 (insert (decode-coding-string plain coding-system-for-read))
628 (if (epg-context-result-for context 'verify)
629 (epa-display-verify-result (epg-context-result-for context 'verify))))))
632 (defun epa-decrypt-armor-in-region (start end)
633 "Decrypt OpenPGP armors in the current region between START and END.
635 Don't use this command in Lisp programs!"
639 (narrow-to-region start end)
641 (let (armor-start armor-end charset coding-system)
642 (while (re-search-forward "-----BEGIN PGP MESSAGE-----$" nil t)
643 (setq armor-start (match-beginning 0)
644 armor-end (re-search-forward "^-----END PGP MESSAGE-----$"
647 (error "No armor tail"))
648 (goto-char armor-start)
649 (if (re-search-forward "^Charset: \\(.*\\)" armor-end t)
650 (setq charset (match-string 1)))
651 (if coding-system-for-read
652 (setq coding-system coding-system-for-read)
654 (setq coding-system (intern (downcase charset)))
655 (setq coding-system 'utf-8)))
656 (let ((coding-system-for-read coding-system))
657 (epa-decrypt-region start end)))))))
660 (defun epa-verify-region (start end)
661 "Verify the current region between START and END.
663 Don't use this command in Lisp programs!"
665 (let ((context (epg-make-context)))
666 (epg-verify-string context
667 (encode-coding-string
668 (buffer-substring start end)
669 coding-system-for-write))
670 (if (epg-context-result-for context 'verify)
671 (epa-display-verify-result (epg-context-result-for context 'verify)))))
674 (defun epa-verify-armor-in-region (start end)
675 "Verify OpenPGP armors in the current region between START and END.
677 Don't use this command in Lisp programs!"
681 (narrow-to-region start end)
683 (let (armor-start armor-end)
684 (while (re-search-forward "-----BEGIN PGP\\( SIGNED\\)? MESSAGE-----$"
686 (setq armor-start (match-beginning 0))
687 (if (match-beginning 1) ;cleartext signed message
689 (unless (re-search-forward "^-----BEGIN PGP SIGNATURE-----$"
691 (error "Invalid cleartext signed message"))
692 (setq armor-end (re-search-forward
693 "^-----END PGP SIGNATURE-----$"
695 (setq armor-end (re-search-forward
696 "^-----END PGP MESSAGE-----$"
699 (error "No armor tail"))
700 (epa-verify-region armor-start armor-end))))))
703 (defun epa-sign-region (start end signers mode)
704 "Sign the current region between START and END by SIGNERS keys selected.
706 Don't use this command in Lisp programs!"
708 (list (region-beginning) (region-end)
709 (epa-select-keys (epg-make-context) "Select keys for signing.
710 If no one is selected, default secret key is used. "
712 (if (y-or-n-p "Make a detached signature? ")
714 (if (y-or-n-p "Make a cleartext signature? ")
717 (let ((context (epg-make-context))
719 (epg-context-set-armor context epa-armor)
720 (epg-context-set-textmode context epa-textmode)
721 (epg-context-set-signers context signers)
722 (message "Signing...")
723 (setq signature (epg-sign-string context
724 (encode-coding-string
725 (buffer-substring start end)
726 coding-system-for-write)
728 (message "Signing...done")
729 (delete-region start end)
730 (insert (decode-coding-string signature coding-system-for-read)))))
733 (defun epa-encrypt-region (start end recipients)
734 "Encrypt the current region between START and END for RECIPIENTS.
736 Don't use this command in Lisp programs!"
738 (list (region-beginning) (region-end)
739 (epa-select-keys (epg-make-context) "Select recipients for encryption.
740 If no one is selected, symmetric encryption will be performed. ")))
742 (let ((context (epg-make-context))
744 (epg-context-set-armor context epa-armor)
745 (epg-context-set-textmode context epa-textmode)
746 (message "Encrypting...")
747 (setq cipher (epg-encrypt-string context
748 (encode-coding-string
749 (buffer-substring start end)
750 coding-system-for-write)
752 (message "Encrypting...done")
753 (delete-region start end)
757 (defun epa-delete-keys (keys &optional allow-secret)
758 "Delete selected KEYS."
760 (let ((keys (epa-marked-keys)))
762 (error "No keys selected"))
764 (eq (nth 1 epa-list-keys-arguments) t))))
765 (let ((context (epg-make-context)))
766 (message "Deleting...")
767 (epg-delete-keys context keys allow-secret)
768 (message "Deleting...done")
769 (apply #'epa-list-keys epa-list-keys-arguments)))
772 (defun epa-import-keys (file)
773 "Import keys from FILE."
774 (interactive "fFile: ")
775 (let ((context (epg-make-context)))
776 (message "Importing %s..." (file-name-nondirectory file))
777 (epg-import-keys-from-file context (expand-file-name file))
778 (message "Importing %s...done" (file-name-nondirectory file))
779 (apply #'epa-list-keys epa-list-keys-arguments)))
782 (defun epa-export-keys (keys file)
783 "Export selected KEYS to FILE."
785 (let ((keys (epa-marked-keys))
788 (error "No keys selected"))
791 (concat (epg-sub-key-id (car (epg-key-sub-key-list (car keys))))
792 (if epa-armor ".asc" ".gpg"))
797 (concat "To file (default "
798 (file-name-nondirectory default-name)
800 (file-name-directory default-name)
802 (let ((context (epg-make-context)))
803 (epg-context-set-armor context epa-armor)
804 (message "Exporting to %s..." (file-name-nondirectory file))
805 (epg-export-keys-to-file context keys file)
806 (message "Exporting to %s...done" (file-name-nondirectory file))))
809 (defun epa-sign-keys (keys &optional local)
811 If LOCAL is non-nil, the signature is marked as non exportable."
813 (let ((keys (epa-marked-keys)))
815 (error "No keys selected"))
816 (list keys current-prefix-arg)))
817 (let ((context (epg-make-context)))
818 (message "Signing keys...")
819 (epg-sign-keys context keys local)
820 (message "Signing keys...done")))