Keyboxd: S/MIME certificate is imported on ldap search
Open, NormalPublic

Assigned To
Authored By
timegrid
Jan 20 2026, 1:56 PM

Description

A ldap search for an email will directly import S/MIME certificates.

To reproduce:

  1. Ensure, some smime certificate is available on the ldap
  2. Search for the associated email -> the entry is found, but directly imported

Details

Version
gpg4win-5.0.0 @ win11

Related Objects

Event Timeline

timegrid created this object with edit policy "Contributor (Project)".

Note: This does not happen on vsd-3.3.4

I have not checked but I guess that the certificate is marked as ephemeal and kleopatra either lists ephemeral certificates or the ephemeral flag got removed to to a validation process,

gpgme logs (also of vsd-3.3.4) will be useful.

  • gpg4win 5.0.0 @ win11

  • vsd 3.3.4 @ win10

Gpg4win 5.0.0

Result of LISTKEYS with keylist mode 0x2 (= remote; i.e. lookup on server)

crt::4096:1:E9D11C94DCC1BAE5:20260120T102434:20270120T102434:02::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::esES::::::23:
fpr:::::::::34AFBE6C696E65D763413FA1E9D11C94DCC1BAE5:::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:
fp2:::::::::2BA723F68B44981210B2CE74BB42D957192DDC0F43EAB2BFD18A5CFF925F9DC9::::
grp:::::::::36D2569F4543378959A7B4D63B6FD4817F3695F0:
uid:::::::::CN=Bob,1.2.840.113549.1.9.1=#626F6240676E7570672E74657374,O=QA,L=Erkrath,ST=NRW,C=DE:::
uid:::::::::<bob@gnupg.test>::

Result of LISTKEYS with keylist mode 0x111 (= local, with secret, validate)

crt:f:4096:1:E9D11C94DCC1BAE5:20260120T102434:20270120T102434:02::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::esES::::::23:
fpr:::::::::34AFBE6C696E65D763413FA1E9D11C94DCC1BAE5:::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:
fp2:::::::::2BA723F68B44981210B2CE74BB42D957192DDC0F43EAB2BFD18A5CFF925F9DC9::::
grp:::::::::36D2569F4543378959A7B4D63B6FD4817F3695F0:
uid:f::::::::CN=Bob,1.2.840.113549.1.9.1=#626F6240676E7570672E74657374,O=QA,L=Erkrath,ST=NRW,C=DE:::
uid:f::::::::<bob@gnupg.test>::

crs:f:3072:1:F7ED85B98C7DDFC5:20230313T180701:20630405T170000:4D9528785EE3E701::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE::eE:::+:::23:
fpr:::::::::54DCF69AD0C25D777CB4B73EF7ED85B98C7DDFC5:::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:
fp2:::::::::AE250DD11730E08EA7D78F996A0BAFBD9668348E78F3465003A47009DC9D8D29::::
grp:::::::::10EA99B65693AD207A4081C6DFF465E44DFD49BF:
uid:f::::::::CN=Test Tester,OU=demo,O=g10 Code GmbH,C=DE:::
uid:f::::::::<ted.tester@demo.gnupg.com>::

crt:u:4096:1:BAD0BBA151F462ED:20260120T102433:20270120T102433:165AC17CC2D9EDB0F1E9AA86503AB62B20EEB012::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::cC::::::23:
fpr:::::::::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:
fp2:::::::::A5E46E01789497B72E647743135A40747B05901F7198471A3839BFB9588D5691::::
grp:::::::::D22D8490F5087FD647E514BC38EE7FBA6A9AD906:
uid:u::::::::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE:::
uid:u::::::::<ca@gnupg.test>::

crs:f:3072:1:67F99891C2311DD2:20230313T180555:20630405T170000:3CE06BDCCCDB7E03::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE::sS:::+:::23:
fpr:::::::::7C6A4442C88AA009D1B82BD267F99891C2311DD2:::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:
fp2:::::::::EAF07D4C6FE531C37D8460A41F504A507BA4B5BFAF048D5ED5B25A14FE03BCDE::::
grp:::::::::FA53C09B98FC771C31A96B05CE04FDCE84B1013D:
uid:f::::::::CN=Test Tester,OU=demo,O=g10 Code GmbH,C=DE:::
uid:f::::::::<ted.tester@demo.gnupg.com>::

crt:f:3072:1:72A2E3036291C878:20230313T181741:20630405T170000:3D0FAB26F82C740D::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE::esES::::::23:
fpr:::::::::A8363E8C52A262B04E8B2FC772A2E3036291C878:::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:
fp2:::::::::11F249A37CFB8D10199B31150AA53045188646C0272A3D0902E76CC416213206::::
grp:::::::::36513EAA2DB9BF6CF835CEF1DBDC155728089965:
uid:f::::::::CN=Berta Boss,OU=demo,O=g10 Code GmbH,C=DE:::
uid:f::::::::<berta.boss@demo.gnupg.com>::

crt:u:3072:1:C7D791083C1027DB:20200326T194101:20630405T170000:01::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE::cC::::::23:
fpr:::::::::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:
fp2:::::::::8BA71E53C0AF36F73EE6041E54800ECFA74EA61E08004734F35AF7579B76E2C5::::
grp:::::::::184977136DA4D5C90C202F22E3812012ABCD7174:
uid:u::::::::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE:::
uid:u::::::::<root-ca-2020@gnupg.com>::

crs:f:256:18:C7FD4C0193216FA6:20230313T183140:20630405T170000:281B974B684B7934::CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE::esES:::+::brainpoolP256r1:23:
fpr:::::::::FF810B9281A43C394AA138E9C7FD4C0193216FA6:::D4ECA6B469ABB5440827CB3FC7D791083C1027DB:
fp2:::::::::FCAEE9A63060E168A7AC2C21BFC1D5FEAE8C9A87613847F016A3B3173597E5C6::::
grp:::::::::0D260BD2025388018FA914A59C941060259E7360:
uid:f::::::::CN=Edward Tester,OU=demo,O=g10 Code GmbH,C=DE:::
uid:f::::::::<edward.tester@demo.gnupg.com>::

VSD 3.3.4

Result of LISTKEYS with keylist mode 0x2 (= remote; i.e. lookup on server)

crt::4096:1:E9D11C94DCC1BAE5:20260120T102434:20270120T102434:02::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::esES::::::23:
fpr:::::::::34AFBE6C696E65D763413FA1E9D11C94DCC1BAE5:::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:
fp2:::::::::2BA723F68B44981210B2CE74BB42D957192DDC0F43EAB2BFD18A5CFF925F9DC9::::
grp:::::::::36D2569F4543378959A7B4D63B6FD4817F3695F0:
uid:::::::::CN=Bob,1.2.840.113549.1.9.1=#626F6240676E7570672E74657374,O=QA,L=Erkrath,ST=NRW,C=DE::
uid:::::::::<bob@gnupg.test>::

Result of LISTKEYS with keylist mode 0x111 (= local, with secret, validate)

crt:u:4096:1:BAD0BBA151F462ED:20260120T102433:20270120T102433:165AC17CC2D9EDB0F1E9AA86503AB62B20EEB012::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::cC::::::23:
fpr:::::::::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:::5F2B39FFEF377DAF7C2DF50CBAD0BBA151F462ED:
fp2:::::::::A5E46E01789497B72E647743135A40747B05901F7198471A3839BFB9588D5691::::
grp:::::::::D22D8490F5087FD647E514BC38EE7FBA6A9AD906:
uid:u::::::::1.2.840.113549.1.9.1=#636140676E7570672E74657374,CN=CA,OU=QA,O=g10code,L=Erkrath,ST=NRW,C=DE::
uid:u::::::::<ca@gnupg.test>::

With Gpg4win 5.0.0 the LISTKEYS after the server lookup lists the (ephemeral?) ca@gnupg.test certificate and (!) the bob@gnupg.test certificate (and some other certificates, but I guess those are from other tests).

With VSD 3.3.4 the LISTKEYS after the server lookup lists the (ephemeral?) ca@gnupg.test certificate and nothing else.

Note that the GPGME_KEYLIST_MODE_EPHEMERAL flag (0x80) is NOT set in any LISTKEYS commands, i.e. ephemeral certificates should not be listed by gpgsm.

My usual question: What happens if the keyboxd is disabled in Gpg4win 5?

Second question: Does Kleopatra VSD 3.3.4 show the ca@gnupg.test certificate in the certificate list?

It also happens on CLI:

Gpg4Win 5.0.0

PS C:\Users\g10> gpgsm -k bob

PS C:\Users\g10> gpgsm -v --list-external-keys bob@gnupg.test
gpgsm: enabled compatibility flags:
[external keys]
---------------
           ID: 0xDCC1BAE5
          S/N: 02
        (dec): 2
       Issuer: /CN=CA/OU=QA/O=g10code/L=Erkrath/ST=NRW/C=DE/EMail=ca@gnupg.test
      Subject: /CN=Bob/O=QA/L=Erkrath/ST=NRW/C=DE/EMail=bob@gnupg.test
     validity: 2026-01-20 10:24:34 through 2027-01-20 10:24:34
     key type: rsa4096
    key usage: digitalSignature nonRepudiation keyEncipherment dataEncipherment
     sha1 fpr: 34:AF:BE:6C:69:6E:65:D7:63:41:3F:A1:E9:D1:1C:94:DC:C1:BA:E5
     sha2 fpr: 2B:A7:23:F6:8B:44:98:12:10:B2:CE:74:BB:42:D9:57:19:2D:DC:0F:43:EA:B2:BF:D1:8A:5C:FF:92:5F:9D:C9

PS C:\Users\g10> gpgsm -k bob
[keyboxd]
---------
           ID: 0xDCC1BAE5
          S/N: 02
        (dec): 2
       Issuer: /CN=CA/OU=QA/O=g10code/L=Erkrath/ST=NRW/C=DE/EMail=ca@gnupg.test
      Subject: /CN=Bob/O=QA/L=Erkrath/ST=NRW/C=DE/EMail=bob@gnupg.test
     validity: 2026-01-20 10:24:34 through 2027-01-20 10:24:34
     key type: rsa4096
    key usage: digitalSignature nonRepudiation keyEncipherment dataEncipherment
     sha1 fpr: 34:AF:BE:6C:69:6E:65:D7:63:41:3F:A1:E9:D1:1C:94:DC:C1:BA:E5
     sha2 fpr: 2B:A7:23:F6:8B:44:98:12:10:B2:CE:74:BB:42:D9:57:19:2D:DC:0F:43:EA:B2:BF:D1:8A:5C:FF:92:5F:9D:C9

VSD 3.3.4

C:\Users\g10>gpgsm -k bob

C:\Users\g10>gpgsm -v --list-external-keys bob@gnupg.test
gpgsm: enabled compatibility flags: de-vs-trustlist
[external keys]
---------------
           ID: 0xDCC1BAE5
          S/N: 02
        (dec): 2
       Issuer: /CN=CA/OU=QA/O=g10code/L=Erkrath/ST=NRW/C=DE/EMail=ca@gnupg.test
      Subject: /CN=Bob/O=QA/L=Erkrath/ST=NRW/C=DE/EMail=bob@gnupg.test
     validity: 2026-01-20 10:24:34 through 2027-01-20 10:24:34
     key type: rsa4096
    key usage: digitalSignature nonRepudiation keyEncipherment dataEncipherment
  fingerprint: 34:AF:BE:6C:69:6E:65:D7:63:41:3F:A1:E9:D1:1C:94:DC:C1:BA:E5
     sha2 fpr: 2B:A7:23:F6:8B:44:98:12:10:B2:CE:74:BB:42:D9:57:19:2D:DC:0F:43:EA:B2:BF:D1:8A:5C:FF:92:5F:9D:C9


C:\Users\g10>gpgsm -k bob
timegrid renamed this task from Kleopatra: S/MIME certificate is imported on ldap search to GnuPG: S/MIME certificate is imported on ldap search.Jan 21 2026, 10:00 AM
timegrid edited projects, added gnupg26; removed kleopatra.
timegrid added a project: Bug Report.

some other certificates, but I guess those are from other tests

Yes

Does Kleopatra VSD 3.3.4 show the ca@gnupg.test certificate in the certificate list?

The "ca" root cert was imported manually before via Kleopatra and is shown.

What happens if the keyboxd is disabled in Gpg4win 5?

Without keyboxd, the certificate is not imported.

timegrid renamed this task from GnuPG: S/MIME certificate is imported on ldap search to Keyboxd: S/MIME certificate is imported on ldap search.Jan 21 2026, 10:13 AM
timegrid added a project: keyboxd.

The "ca" root cert is not on the ldap, if that matters

I looked at sm/keydb.c:keydb_set_ephemeral function. It says:

if (hd->use_keyboxd)
  return 0; /* FIXME: No support yet.  */

keyboxd has not yet supported ephemeral mode, thus, the external one is stored as normal one.

gniibe mentioned this in Unknown Object (Maniphest Task).Mar 23 2026, 3:43 AM

Here is an attempt to fix the client side:

The idea is keyboxd can be enhanced by modifying STORE and SEARCH command with the use of ctrl->ephemeral.

I applied the keyboxd part for SETEPHEMERAL command, as it doesn't break anything.

My plan is now:

  • Enhance keyboxd to have new command for what keybox_set_flags does.
  • Enhance keyboxd to support ctrl->ephemeral state for STORE and SEARCH.
  • Use SETEPHEMERAL and PUTKEYFLAG in gpgsm.
gniibe mentioned this in Unknown Object (Maniphest Task).Mar 30 2026, 2:35 AM
gniibe mentioned this in Unknown Object (Maniphest Task).Apr 13 2026, 6:35 AM

Enhance keyboxd to have new command for what keybox_set_flags does.

Here is the change:

I created a branch https://dev.gnupg.org/source/gnupg/history/gniibe%252Ft8048 and pushed all changes (including keyboxd-patch-2026-04-23).

gniibe changed the task status from Open to Testing.Apr 27 2026, 6:48 AM

Applied to master.

gniibe mentioned this in Unknown Object (Maniphest Task).Apr 27 2026, 6:53 AM
gniibe mentioned this in Unknown Object (Maniphest Task).May 4 2026, 6:15 AM

Issue found on gpg4win-5.1.0-beta658 / gpg 2.5.21 @ win11:

The import itself does not work anymore in Kleopatra.

To reproduce

  1. Given
    • clean gnupg home directory
    • one key in keyring (to skip the welcome screen)
    • dirmngr.conf with ldapserver set (I use ldapserver ldap.gnupg.test:389:uid=LordPrivySeal,ou=GnuPG Users,dc=gnupg,dc=test:pass:dc=gnupg,dc=test:)
    • ldap server containing a smime certificate (e.g. for bob)
  2. Open Kleopatra and search for bob -> entry is found, but not imported (ok)
  3. Import => not imported (unchanged)

Logs

debuglog
### search ###
1	0.000000	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - file changed: "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d/pubring.db"
2	0.005052	11260	kleopatra.exe	org.kde.pim.kleopatra: slotNextKey got key GpgME::Key("Bob <bob@gnupg.test> (not checked, S/MIME, created: 15.07.2026)", fpr: 8D1B205094CF17E0ACB90DFBAA7CAA1F3303534E)
3	1.018874	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache(0x224c51edcf0) reload option: 0
4	1.019016	11260	kleopatra.exe	org.kde.pim.libkleo: KeyCache::RefreshKeysJob start
5	1.093753	11260	kleopatra.exe	org.kde.pim.kleopatra: Cannot find: "1B7724C95351B75394303415C2577F23F8E93418" anymore in cache
6	1.093807	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache::RefreshKeysJob(0x224c7b33900) RefreshKeysJob::done
7	1.094710	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg"
8	1.095154	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/private-keys-v1.d"
9	1.095379	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d"
10	1.095742	11260	kleopatra.exe	org.kde.pim.libkleo: readGroups Reading groups

### import ###
11	45.421974	11260	kleopatra.exe	org.kde.pim.libkleo: KeyCacheAutoRefreshSuspension
12	45.424025	11260	kleopatra.exe	org.kde.pim.kleopatra: increaseProgressMaximum progress: 0 / 2
13	45.424064	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) tryToFinish
14	45.424463	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) tryToFinish There are unfinished jobs -> keep going
15	45.487535	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) onImportResult QGpgME::QGpgMEImportFromKeyserverJob(0x224c7b4a750)
16	45.487621	11260	kleopatra.exe	org.kde.pim.kleopatra: increaseProgressValue progress: 1 / 2
17	45.487775	11260	kleopatra.exe	org.kde.pim.libkleo: errorAsString gettext_use_utf8(-1) returns 1
18	45.487832	11260	kleopatra.exe	org.kde.pim.libkleo: errorAsString error: "Success"
19	45.487847	11260	kleopatra.exe	org.kde.pim.libkleo: errorAsString error (percent-encoded): "Success"
20	45.487878	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) addImportResult "" Result: "Success"
21	45.487902	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) tryToFinish
22	45.487938	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache(0x224c51edcf0) reload option: 0
23	45.487976	11260	kleopatra.exe	org.kde.pim.libkleo: KeyCache::RefreshKeysJob start
24	45.578396	11260	kleopatra.exe	org.kde.pim.kleopatra: Cannot find: "FADC4675146CFAF3D86F137E1D3C5E6E3DB3C71D" anymore in cache
25	45.578421	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache::RefreshKeysJob(0x224c7b34540) RefreshKeysJob::done
26	45.579253	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg"
27	45.579684	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/private-keys-v1.d"
28	45.579890	11260	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x224c4999a50) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d"
29	45.580192	11260	kleopatra.exe	org.kde.pim.libkleo: readGroups Reading groups
30	45.580688	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x224c7ad38e0) keyCacheUpdated
31	45.580722	11260	kleopatra.exe	org.kde.pim.libkleo: ~KeyCacheAutoRefreshSuspension
32	45.580886	11260	kleopatra.exe	org.kde.pim.kleopatra: validateImportedCertificate Certificate with fingerprint 8D1B205094CF17E0ACB90DFBAA7CAA1F3303534E not found
33	45.580913	11260	kleopatra.exe	org.kde.pim.kleopatra: setProgressToMaximum
34	45.580967	11260	kleopatra.exe	org.kde.pim.kleopatra: handleOwnerTrust Skipping non-OpenPGP import
35	45.581003	11260	kleopatra.exe	org.kde.pim.kleopatra: getSingleOpenPGPImport returns null because no import result is import of a single OpenPGP key
36	45.592869	11260	kleopatra.exe	org.kde.pim.kleopatra: 0x224c7ad38e0
37	45.597430	11260	kleopatra.exe	org.kde.pim.kleopatra: 
38	45.597444	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Command(0x224c7ad38e0) ~Command
39	45.597467	11260	kleopatra.exe	org.kde.pim.kleopatra: 
40	45.597545	11260	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Command(0x224c7ad38e0) ~Private
41	45.597566	11260	kleopatra.exe	org.kde.pim.kleopatra: 0x224c7ad38e0

Lookup via dirmngr looks fine i guess:

cli
C:\Users\g10>gpg-connect-agent --dirmngr
> /hex
> lookup bob
D[0000]  30 82 04 E3 30 82 03 CB  A0 03 02 01 02 02 01 09   0...0...........
D[0010]  30 25 30 44 06 09 2A 86  48 86 F7 25 30 44 01 01   0%0D..*.H..%0D..
[...]
D[0110]  48 86 F7 25 30 44 01 09  01 16 0E 62 6F 62 40 67   H..%0D.....bob@g
D[0120]  6E 75 70 67 2E 74 65 73  74 31 0C 30 25 30 41 06   nupg.test1.0%0A.
D[0130]  03 55 04 03 0C 03 42 6F  62 30 82 02 22 30 25 30   .U....Bob0.."0%0
[...]
D[0100]  99 78 07 00 E6 82 21 C0  78 53 C1 E7 B9 43 DC 10   .x....!.xS...C..
D[0110]  9C 69 6A 79 D9 14 10 21  54 A3 9C 74 CF A0 B5 4E   .ijy...!T..t...N
D[0120]  74 6D 55 FD 53 25 30 41  BA E9 7A 8D 9D 41 77 90   tmU.S%0A..z..Aw.
D[0130]  1D                                                 .
END
OK

Note: The automatic import on search is prevented now (ok):

cmd
C:\Users\g10>gpgsm -v --list-external-keys bob@gnupg.test
[...]
[external keys]
---------------
           ID: 0x3303534E
          S/N: 09
        (dec): 9
       Issuer: /CN=CA/OU=QA/O=g10code/L=Erkrath/ST=NRW/C=DE/EMail=ca@gnupg.test
      Subject: /CN=Bob/O=QA/L=Erkrath/ST=NRW/C=DE/EMail=bob@gnupg.test
     validity: 2026-07-15 12:24:57 through 2027-07-15 12:24:57
     key type: rsa4096
    key usage: digitalSignature nonRepudiation keyEncipherment dataEncipherment
     sha1 fpr: 8D:1B:20:50:94:CF:17:E0:AC:B9:0D:FB:AA:7C:AA:1F:33:03:53:4E
     sha2 fpr: B0:7B:68:C0:BB:55:64:05:42:9E:9F:69:D0:0B:62:FA:2F:FA:03:17:FF:60:ED:43:11:9E:D6:B5:66:3D:F2:47


C:\Users\g10>gpgsm -k bob

C:\Users\g10>
timegrid changed the task status from Testing to Open.Wed, Jul 15, 4:08 PM

Debugview output for gpg4win-5.0.2 (with auto import bug):

debugview
1	0.000000	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - file changed: "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d/pubring.db"
2	0.059131	4232	kleopatra.exe	org.kde.pim.kleopatra: slotNextKey got key GpgME::Key("Bob <bob@gnupg.test> (not checked, S/MIME, created: 15.07.2026)", fpr: 8D1B205094CF17E0ACB90DFBAA7CAA1F3303534E)
3	1.037601	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache(0x262143320d0) reload option: 0
4	1.041891	4232	kleopatra.exe	org.kde.pim.libkleo: KeyCache::RefreshKeysJob start
5	1.727426	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache::RefreshKeysJob(0x26218d597c0) RefreshKeysJob::done
6	1.733727	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg"
7	1.737147	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/private-keys-v1.d"
8	1.738665	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d"
9	1.741044	4232	kleopatra.exe	org.kde.pim.libkleo: readGroups Reading groups
10	8.671575	4232	kleopatra.exe	org.kde.pim.libkleo: KeyCacheAutoRefreshSuspension
11	8.676695	4232	kleopatra.exe	org.kde.pim.kleopatra: increaseProgressMaximum progress: 0 / 2
12	8.676988	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) tryToFinish
13	8.677261	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) tryToFinish There are unfinished jobs -> keep going
14	8.972434	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) onImportResult QGpgME::QGpgMEImportFromKeyserverJob(0x26218d6f350)
15	8.973290	4232	kleopatra.exe	org.kde.pim.kleopatra: increaseProgressValue progress: 1 / 2
16	8.973623	4232	kleopatra.exe	org.kde.pim.libkleo: errorAsString gettext_use_utf8(-1) returns 1
17	8.973697	4232	kleopatra.exe	org.kde.pim.libkleo: errorAsString error: "Success"
18	8.973951	4232	kleopatra.exe	org.kde.pim.libkleo: errorAsString error (percent-encoded): "Success"
19	8.974034	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) addImportResult "S/MIME Certificate Server" Result: "Success"
20	8.974209	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) tryToFinish
21	8.974362	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache(0x262143320d0) reload option: 0
22	8.974517	4232	kleopatra.exe	org.kde.pim.libkleo: KeyCache::RefreshKeysJob start
23	9.341114	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::KeyCache::RefreshKeysJob(0x26218d5ae60) RefreshKeysJob::done
24	9.345326	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg"
25	9.347659	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/private-keys-v1.d"
26	9.348893	4232	kleopatra.exe	org.kde.pim.libkleo: Kleo::FileSystemWatcher(0x2621437eaf0) - checking for new files in "C:/Users/g10/AppData/Roaming/gnupg/public-keys.d"
27	9.350766	4232	kleopatra.exe	org.kde.pim.libkleo: readGroups Reading groups
28	9.353108	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Commands::LookupCertificatesCommand(0x26218c59290) keyCacheUpdated
29	9.353419	4232	kleopatra.exe	org.kde.pim.libkleo: ~KeyCacheAutoRefreshSuspension
30	9.703606	4232	kleopatra.exe	org.kde.pim.kleopatra: setProgressToMaximum
31	9.785380	4232	kleopatra.exe	org.kde.pim.kleopatra: handleOwnerTrust Skipping non-OpenPGP import
32	9.790357	4232	kleopatra.exe	org.kde.pim.kleopatra: getSingleOpenPGPImport returns null because no import result is import of a single OpenPGP key
33	9.893677	4232	kleopatra.exe	org.kde.pim.kleopatra: 0x26218c59290
34	9.985217	4232	kleopatra.exe	org.kde.pim.kleopatra: 
35	9.986211	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Command(0x26218c59290) ~Command
36	9.986374	4232	kleopatra.exe	org.kde.pim.kleopatra: 
37	9.987092	4232	kleopatra.exe	org.kde.pim.kleopatra: Kleo::Command(0x26218c59290) ~Private
38	9.987308	4232	kleopatra.exe	org.kde.pim.kleopatra: 0x26218c59290

Without keyboxd, in both versions gpg4win-5.0.2 @ win11 and gpg4win-5.1.0-beta658 / gpg 2.5.21 @ win11, the import works (without the autoimport issue on search).

Further logs (for gpg4win-5.1.0-beta658 / gpg 2.5.21 @ win11 with keyboxd, for search and import)

  • 17:26:01 - search
  • 17:26:13 - import

@timegrid Thank you for the log. It helps me to identify the bug.
Here is the bug:
https://dev.gnupg.org/source/gnupg/browse/master/sm/keydb.c;0be940905d70125866622c6f53b8d25bde87c21b$1080?as=source&blame=off

I'm going to implement keydb_get_flags with keyboxd.

In the keyboxd.log, the key is identified with e (ephemeral) flag and with no revoke flag (-).

2026-07-15 17:26:14 keyboxd[9452] DBG: chan_0x000000000000027c -> S PUBKEY_INFO 2 8D1B205094CF17E0ACB90DFBAA7CAA1F3303534E e- 0 0

So, all that we need to do is to keep these information and return when asked by keydb_get_flags function.

gniibe mentioned this in Unknown Object (Maniphest Task).Mon, Jul 20, 6:39 AM

keydb_get_flags is fixed (with keyboxd). It now works well, or we can see some progress at least.

gniibe mentioned this in Unknown Object (Maniphest Task).Mon, Jul 27, 8:16 AM