X-Git-Url: https://git.notmuchmail.org/git?a=blobdiff_plain;ds=sidebyside;f=doc%2Fman1%2Fnotmuch-config.rst;h=773fd9da2cd735cbc38c5157c0ae158e3ded8012;hb=fccebbaeef1e4b6489425afb13f419543d53d285;hp=4835f897315b3e0373a5b8e3068dfb6db1f97165;hpb=e4890b5bf9e2260b36bcc36ddb77d8e97e2abe7d;p=notmuch diff --git a/doc/man1/notmuch-config.rst b/doc/man1/notmuch-config.rst index 4835f897..773fd9da 100644 --- a/doc/man1/notmuch-config.rst +++ b/doc/man1/notmuch-config.rst @@ -141,20 +141,29 @@ The available configuration items are described below. **index.decrypt** **[STORED IN DATABASE]** + + One of ``false``, ``auto``, ``nostash``, or ``true``. + When indexing an encrypted e-mail message, if this variable is set to ``true``, notmuch will try to decrypt the message and - index the cleartext. If ``auto``, it will try to index the - cleartext if a stashed session key is already known for the message, - but will not try to access your secret keys. Use ``false`` to - avoid decrypting even when a session key is already known. - - Be aware that the notmuch index is likely sufficient to - reconstruct the cleartext of the message itself, so please - ensure that the notmuch message index is adequately protected. - DO NOT USE ``index.decrypt=true`` without considering the - security of your index. - - Default: ``false``. + index the cleartext, stashing a copy of any discovered session + keys for the message. If ``auto``, it will try to index the + cleartext if a stashed session key is already known for the message + (e.g. from a previous copy), but will not try to access your + secret keys. Use ``false`` to avoid decrypting even when a + stashed session key is already present. + + ``nostash`` is the same as ``true`` except that it will not + stash newly-discovered session keys in the database. + + Be aware that the notmuch index is likely sufficient (and a + stashed session key is certainly sufficient) to reconstruct + the cleartext of the message itself, so please ensure that the + notmuch message index is adequately protected. DO NOT USE + ``index.decrypt=true`` or ``index.decrypt=nostash`` without + considering the security of your index. + + Default: ``auto``. **built_with.**