"The EasyPG Assistant"
:group 'epg)
+(defcustom epa-armor nil
+ "If non-nil, epa commands create ASCII armored output."
+ :type 'boolean
+ :group 'epa)
+
+(defcustom epa-textmode nil
+ "If non-nil, epa commands treat input files as text."
+ :type 'boolean
+ :group 'epa)
+
(defgroup epa-faces nil
"Faces for epa-mode."
:group 'epa)
(define-key keymap "d" 'epa-decrypt-file)
(define-key keymap "v" 'epa-verify-file)
(define-key keymap "s" 'epa-sign-file)
+ (define-key keymap "S" 'epa-sign-keys)
(define-key keymap "e" 'epa-encrypt-file)
- (define-key keymap "r" 'epa-delete-key)
+ (define-key keymap "r" 'epa-delete-keys)
+ (define-key keymap "i" 'epa-import-keys)
+ (define-key keymap "o" 'epa-export-keys)
+ (define-key keymap "g" 'epa-list-keys)
(define-key keymap "n" 'next-line)
(define-key keymap "p" 'previous-line)
(define-key keymap " " 'scroll-up)
(define-key keymap [delete] 'scroll-down)
- (define-key keymap "q" 'bury-buffer)
+ (define-key keymap "q" 'epa-exit-buffer)
keymap))
+(defvar epa-exit-buffer-function #'bury-buffer)
+
(define-widget 'epa-key 'push-button
"Button for representing a epg-key object."
:format "%[%v%]"
? ))
(epg-sub-key-id primary-sub-key)
" "
- (epg-user-id-name primary-user-id))))
+ (if (stringp (epg-user-id-string primary-user-id))
+ (epg-user-id-string primary-user-id)
+ (epg-decode-dn (epg-user-id-string primary-user-id))))))
(defun epa-key-widget-button-face-get (widget)
(let ((validity (epg-sub-key-validity (car (epg-key-sub-key-list
;; if buffer-file-name is not set.
(font-lock-set-defaults)
(widget-setup)
+ (make-local-variable 'epa-exit-buffer-function)
(run-hooks 'epa-keys-mode-hook))
(defvar epa-key-mode-map
;; In XEmacs, auto-initialization of font-lock is not effective
;; if buffer-file-name is not set.
(font-lock-set-defaults)
+ (make-local-variable 'epa-exit-buffer-function)
(run-hooks 'epa-key-mode-hook))
;;;###autoload
-(defun epa-list-keys (&optional name mode)
+(defun epa-list-keys (&optional name mode protocol)
(interactive
- (let ((name (read-string "Pattern: ")))
- (list (if (equal name "") nil name)
- current-prefix-arg)))
+ (if current-prefix-arg
+ (let ((name (read-string "Pattern: "
+ (if epa-list-keys-arguments
+ (car epa-list-keys-arguments)))))
+ (list (if (equal name "") nil name)
+ (y-or-n-p "Secret keys? ")
+ (intern (completing-read "Protocol? "
+ '(("OpenPGP") ("CMS"))
+ nil t))))
+ (or epa-list-keys-arguments (list nil nil nil))))
(unless (and epa-keys-buffer
(buffer-live-p epa-keys-buffer))
(setq epa-keys-buffer (generate-new-buffer "*Keys*")))
(set-buffer epa-keys-buffer)
(let ((inhibit-read-only t)
- buffer-read-only)
- (erase-buffer)
- (epa-list-keys-1 name mode)
+ buffer-read-only
+ (point (point-min))
+ (context (epg-make-context protocol)))
+ (unless (get-text-property point 'epa-list-keys)
+ (setq point (next-single-property-change point 'epa-list-keys)))
+ (when point
+ (delete-region point
+ (or (next-single-property-change point 'epa-list-keys)
+ (point-max)))
+ (goto-char point))
+ (epa-list-keys-1 context name mode)
(epa-keys-mode))
(make-local-variable 'epa-list-keys-arguments)
- (setq epa-list-keys-arguments (list name mode))
+ (setq epa-list-keys-arguments (list name mode protocol))
(goto-char (point-min))
(pop-to-buffer (current-buffer)))
-(defun epa-list-keys-1 (name mode)
- (let ((inhibit-read-only t)
- buffer-read-only
- (keys (epg-list-keys name mode))
- point)
- (while keys
- (setq point (point))
- (insert " ")
- (put-text-property point (point) 'epa-key (car keys))
- (widget-create 'epa-key :value (car keys))
- (insert "\n")
- (setq keys (cdr keys)))))
-
-(defun epa-select-keys (prompt &optional names)
+(defun epa-list-keys-1 (context name mode)
+ (save-restriction
+ (narrow-to-region (point) (point))
+ (let ((inhibit-read-only t)
+ buffer-read-only
+ (keys (epg-list-keys context name mode))
+ point)
+ (while keys
+ (setq point (point))
+ (insert " ")
+ (put-text-property point (point) 'epa-key (car keys))
+ (widget-create 'epa-key :value (car keys))
+ (insert "\n")
+ (setq keys (cdr keys))))
+ (put-text-property (point-min) (point-max) 'epa-list-keys t)))
+
+(defun epa-marked-keys ()
+ (or (save-excursion
+ (set-buffer epa-keys-buffer)
+ (goto-char (point-min))
+ (let (keys key)
+ (while (re-search-forward "^\\*" nil t)
+ (if (setq key (get-text-property (match-beginning 0)
+ 'epa-key))
+ (setq keys (cons key keys))))
+ (nreverse keys)))
+ (save-excursion
+ (beginning-of-line)
+ (let ((key (get-text-property (point) 'epa-key)))
+ (if key
+ (list key))))))
+
+;;;###autoload
+(defun epa-select-keys (context prompt &optional names secret)
+ "Display a user's keyring and ask him to select keys.
+CONTEXT is an epg-context.
+PROMPT is a string to prompt with.
+NAMES is a list of strings to be matched with keys. If it is nil, all
+the keys are listed.
+If SECRET is non-nil, list secret keys instead of public keys."
(save-excursion
(unless (and epa-keys-buffer
(buffer-live-p epa-keys-buffer))
(erase-buffer)
(insert prompt "\n")
(widget-create 'link
+ :notify (lambda (&rest ignore) (abort-recursive-edit))
+ :help-echo
+ (substitute-command-keys
+ "Click here or \\[abort-recursive-edit] to cancel")
+ "Cancel")
+ (widget-create 'link
:notify (lambda (&rest ignore) (exit-recursive-edit))
:help-echo
(substitute-command-keys
(if names
(while names
(setq point (point))
- (epa-list-keys-1 (car names) nil)
+ (epa-list-keys-1 context (car names) secret)
(goto-char point)
(epa-mark)
(goto-char (point-max))
(setq names (cdr names)))
- (epa-list-keys-1 nil nil))
+ (epa-list-keys-1 context nil secret))
(epa-keys-mode)
+ (setq epa-exit-buffer-function #'abort-recursive-edit)
(goto-char (point-min))
- (pop-to-buffer (current-buffer))
- (unwind-protect
+ (pop-to-buffer (current-buffer)))
+ (unwind-protect
(progn
(recursive-edit)
- (save-excursion
- (set-buffer epa-keys-buffer)
- (goto-char (point-min))
- (let (keys key)
- (while (re-search-forward "^\\*" nil t)
- (if (setq key (get-text-property (match-beginning 0)
- 'epa-key))
- (setq keys (cons key keys))))
- (nreverse keys))))
+ (epa-marked-keys))
(if (get-buffer-window epa-keys-buffer)
(delete-window (get-buffer-window epa-keys-buffer)))
- (kill-buffer epa-keys-buffer)))))
+ (kill-buffer epa-keys-buffer))))
(defun epa-show-key (key)
(let* ((primary-sub-key (car (epg-key-sub-key-list key)))
epg-key-validity-alist)))
" ")
" "
- (epg-user-id-name (car pointer))
+ (if (stringp (epg-user-id-string (car pointer)))
+ (epg-user-id-string (car pointer))
+ (epg-decode-dn (epg-user-id-string (car pointer))))
"\n")
(setq pointer (cdr pointer)))
(setq pointer (epg-key-sub-key-list key))
(epa-show-key (widget-get widget :value)))
(defun epa-mark (&optional arg)
- "Mark the current line."
+ "Mark the current line.
+If ARG is non-nil, unmark the current line."
(interactive "P")
(let ((inhibit-read-only t)
buffer-read-only
(forward-line)))
(defun epa-unmark (&optional arg)
- "Unmark the current line."
+ "Unmark the current line.
+If ARG is non-nil, mark the current line."
(interactive "P")
(epa-mark (not arg)))
+(defun epa-exit-buffer ()
+ "Exit the current buffer.
+`epa-exit-buffer-function' is called if it is set."
+ (interactive)
+ (funcall epa-exit-buffer-function))
+
+;;;###autoload
(defun epa-decrypt-file (file)
+ "Decrypt FILE."
(interactive "fFile: ")
(let* ((default-name (file-name-sans-extension file))
(plain (expand-file-name
(context (epg-make-context)))
(message "Decrypting %s..." (file-name-nondirectory file))
(epg-decrypt-file context file plain)
- (message "Decrypting %s...done" (file-name-nondirectory file))))
+ (message "Decrypting %s...done" (file-name-nondirectory file))
+ (if (epg-context-result-for context 'verify)
+ (message "%s"
+ (epg-verify-result-to-string
+ (epg-context-result-for context 'verify))))))
+;;;###autoload
(defun epa-verify-file (file)
+ "Verify FILE."
(interactive "fFile: ")
(let* ((context (epg-make-context))
(plain (if (equal (file-name-extension file) "sig")
- (file-name-sans-extension file)))
- signature)
+ (file-name-sans-extension file))))
(message "Verifying %s..." (file-name-nondirectory file))
(epg-verify-file context file plain)
- (setq signature (reverse (epg-context-result-for context 'verify)))
- (with-output-to-temp-buffer "*epa-verify-file*"
- (set-buffer standard-output)
- (while signature
- (insert (format "%s: %s %s %s\n"
- (epg-signature-status (car signature))
- (epg-signature-key-id (car signature))
- (epg-signature-user-id (car signature))
- (epg-signature-validity (car signature))))
- (setq signature (cdr signature))))
- (shrink-window-if-larger-than-buffer
- (get-buffer-window "*epa-verify-file*"))
- (message "Verifying %s...done" (file-name-nondirectory file))))
-
-(defun epa-sign-file (file detached)
+ (message "Verifying %s...done" (file-name-nondirectory file))
+ (message "%s"
+ (epg-verify-result-to-string
+ (epg-context-result-for context 'verify)))))
+
+;;;###autoload
+(defun epa-sign-file (file signers mode)
+ "Sign FILE by SIGNERS keys selected."
(interactive
(list (expand-file-name (read-file-name "File: "))
- (y-or-n-p "Make a detached signature? ")))
- (let ((signature (concat file (if detached ".sig" ".gpg")))
+ (epa-select-keys (epg-make-context) "Select keys for signing.
+If no one is selected, default secret key is used. "
+ nil t)
+ (if (y-or-n-p "Make a detached signature? ")
+ 'detached
+ (if (y-or-n-p "Make a cleartext signature? ")
+ 'clear))))
+ (let ((signature (concat file
+ (if (or epa-armor
+ (not (memq mode '(nil t normal detached))))
+ ".asc"
+ (if (memq mode '(t detached))
+ ".sig"
+ ".gpg"))))
(context (epg-make-context)))
+ (epg-context-set-armor context epa-armor)
+ (epg-context-set-textmode context epa-textmode)
+ (epg-context-set-signers context signers)
(message "Signing %s..." (file-name-nondirectory file))
- (epg-sign-file context file signature (not (null detached)))
+ (epg-sign-file context file signature mode)
(message "Signing %s...done" (file-name-nondirectory file))))
+;;;###autoload
(defun epa-encrypt-file (file recipients)
+ "Encrypt FILE for RECIPIENTS."
(interactive
(list (expand-file-name (read-file-name "File: "))
- (mapcar (lambda (key)
- (epg-sub-key-id
- (car (epg-key-sub-key-list key))))
- (epa-select-keys "Select recipents for encryption.
-If no one is selected, symmetric encryption will be performed. "))))
- (let ((cipher (concat file ".gpg"))
+ (epa-select-keys (epg-make-context) "Select recipents for encryption.
+If no one is selected, symmetric encryption will be performed. ")))
+ (let ((cipher (concat file (if epa-armor ".asc" ".gpg")))
(context (epg-make-context)))
+ (epg-context-set-armor context epa-armor)
+ (epg-context-set-textmode context epa-textmode)
(message "Encrypting %s..." (file-name-nondirectory file))
- (epg-encrypt-file context
- file
- recipients
- cipher)
+ (epg-encrypt-file context file recipients cipher)
(message "Encrypting %s...done" (file-name-nondirectory file))))
-(defun epa-delete-key (key)
+;;;###autoload
+(defun epa-decrypt-region (start end)
+ "Decrypt the current region between START and END."
+ (interactive "r")
+ (save-excursion
+ (let ((context (epg-make-context))
+ charset plain coding-system)
+ (message "Decrypting...")
+ (setq plain (epg-decrypt-string context (buffer-substring start end)))
+ (message "Decrypting...done")
+ (delete-region start end)
+ (goto-char start)
+ (insert (decode-coding-string plain coding-system-for-read))
+ (if (epg-context-result-for context 'verify)
+ (message "%s"
+ (epg-verify-result-to-string
+ (epg-context-result-for context 'verify)))))))
+
+;;;###autoload
+(defun epa-decrypt-armor-in-region (start end)
+ "Decrypt OpenPGP armors in the current region between START and END."
+ (interactive "r")
+ (save-excursion
+ (save-restriction
+ (narrow-to-region start end)
+ (goto-char start)
+ (let (armor-start armor-end charset plain coding-system)
+ (while (re-search-forward "-----BEGIN PGP MESSAGE-----$" nil t)
+ (setq armor-start (match-beginning 0)
+ armor-end (re-search-forward "^-----END PGP MESSAGE-----$"
+ nil t))
+ (unless armor-end
+ (error "No armor tail"))
+ (goto-char armor-start)
+ (if (re-search-forward "^Charset: \\(.*\\)" armor-end t)
+ (setq charset (match-string 1)))
+ (if coding-system-for-read
+ (setq coding-system coding-system-for-read)
+ (if charset
+ (setq coding-system (intern (downcase charset)))
+ (setq coding-system 'utf-8)))
+ (let ((coding-system-for-read coding-system))
+ (epa-decrypt-region start end)))))))
+
+;;;###autoload
+(defun epa-verify-region (start end)
+ "Verify the current region between START and END."
+ (interactive "r")
+ (let ((context (epg-make-context)))
+ (epg-verify-string context
+ (encode-coding-string
+ (buffer-substring start end)
+ coding-system-for-write))
+ (message "%s"
+ (epg-verify-result-to-string
+ (epg-context-result-for context 'verify)))))
+
+;;;###autoload
+(defun epa-verify-armor-in-region (start end)
+ "Verify OpenPGP armors in the current region between START and END."
+ (interactive "r")
+ (save-excursion
+ (save-restriction
+ (narrow-to-region start end)
+ (goto-char start)
+ (let (armor-start armor-end)
+ (while (re-search-forward "-----BEGIN PGP\\( SIGNED\\)? MESSAGE-----$"
+ nil t)
+ (setq armor-start (match-beginning 0))
+ (if (match-beginning 1) ;cleartext signed message
+ (progn
+ (unless (re-search-forward "^-----BEGIN PGP SIGNATURE-----$"
+ nil t)
+ (error "Invalid cleartext signed message"))
+ (setq armor-end (re-search-forward
+ "^-----END PGP SIGNATURE-----$"
+ nil t)))
+ (setq armor-end (re-search-forward
+ "^-----END PGP MESSAGE-----$"
+ nil t)))
+ (unless armor-end
+ (error "No armor tail"))
+ (epa-verify-region armor-start armor-end))))))
+
+;;;###autoload
+(defun epa-sign-region (start end signers mode)
+ "Sign the current region between START and END by SIGNERS keys selected."
+ (interactive
+ (list (region-beginning) (region-end)
+ (epa-select-keys (epg-make-context) "Select keys for signing.
+If no one is selected, default secret key is used. "
+ nil t)
+ (if (y-or-n-p "Make a detached signature? ")
+ 'detached
+ (if (y-or-n-p "Make a cleartext signature? ")
+ 'clear))))
+ (save-excursion
+ (let ((context (epg-make-context))
+ signature)
+ (epg-context-set-armor context epa-armor)
+ (epg-context-set-textmode context epa-textmode)
+ (epg-context-set-signers context signers)
+ (message "Signing...")
+ (setq signature (epg-sign-string context
+ (encode-coding-string
+ (buffer-substring start end)
+ coding-system-for-write)
+ mode))
+ (message "Signing...done")
+ (delete-region start end)
+ (insert (decode-coding-string signature coding-system-for-read)))))
+
+;;;###autoload
+(defun epa-encrypt-region (start end recipients)
+ "Encrypt the current region between START and END for RECIPIENTS."
+ (interactive
+ (list (region-beginning) (region-end)
+ (epa-select-keys (epg-make-context) "Select recipents for encryption.
+If no one is selected, symmetric encryption will be performed. ")))
+ (save-excursion
+ (let ((context (epg-make-context))
+ cipher)
+ (epg-context-set-armor context epa-armor)
+ (epg-context-set-textmode context epa-textmode)
+ (message "Encrypting...")
+ (setq cipher (epg-encrypt-string context
+ (encode-coding-string
+ (buffer-substring start end)
+ coding-system-for-write)
+ recipients))
+ (message "Encrypting...done")
+ (delete-region start end)
+ (insert cipher))))
+
+;;;###autoload
+(defun epa-delete-keys (keys &optional allow-secret)
+ "Delete selected KEYS."
+ (interactive
+ (let ((keys (epa-marked-keys)))
+ (unless keys
+ (error "No keys selected"))
+ (list keys
+ (eq (nth 1 epa-list-keys-arguments) t))))
+ (let ((context (epg-make-context)))
+ (message "Deleting...")
+ (epg-delete-keys context keys allow-secret)
+ (message "Deleting...done")
+ (apply #'epa-list-keys epa-list-keys-arguments)))
+
+;;;###autoload
+(defun epa-import-keys (file)
+ "Import keys from FILE."
+ (interactive "fFile: ")
+ (let ((context (epg-make-context)))
+ (message "Importing %s..." (file-name-nondirectory file))
+ (epg-import-keys-from-file context (expand-file-name file))
+ (message "Importing %s...done" (file-name-nondirectory file))
+ (apply #'epa-list-keys epa-list-keys-arguments)))
+
+;;;###autoload
+(defun epa-export-keys (keys file)
+ "Export selected KEYS to FILE."
+ (interactive
+ (let ((keys (epa-marked-keys))
+ default-name)
+ (unless keys
+ (error "No keys selected"))
+ (setq default-name
+ (expand-file-name
+ (concat (epg-sub-key-id (car (epg-key-sub-key-list (car keys))))
+ (if epa-armor ".asc" ".gpg"))
+ default-directory))
+ (list keys
+ (expand-file-name
+ (read-file-name
+ (concat "To file (default "
+ (file-name-nondirectory default-name)
+ ") ")
+ (file-name-directory default-name)
+ default-name)))))
+ (let ((context (epg-make-context)))
+ (epg-context-set-armor context epa-armor)
+ (message "Exporting to %s..." (file-name-nondirectory file))
+ (epg-export-keys-to-file context keys file)
+ (message "Exporting to %s...done" (file-name-nondirectory file))))
+
+;;;###autoload
+(defun epa-sign-keys (keys &optional local)
+ "Sign selected KEYS.
+If LOCAL is non-nil, the signature is marked as non exportable."
(interactive
- (list
- (save-excursion
- (beginning-of-line)
- (get-text-property (point) 'epa-key))))
+ (let ((keys (epa-marked-keys)))
+ (unless keys
+ (error "No keys selected"))
+ (list keys current-prefix-arg)))
(let ((context (epg-make-context)))
- (message "Deleting %s..."
- (epg-sub-key-id (car (epg-key-sub-key-list key))))
- (epg-delete-key context key)
- (apply #'epa-list-keys epa-list-keys-arguments)
- (message "Deleting %s...done"
- (epg-sub-key-id (car (epg-key-sub-key-list key))))))
+ (message "Signing keys...")
+ (epg-sign-keys context keys local)
+ (message "Signing keys...done")))
(provide 'epa)