Import of unprotected ECDH secret keys broken in gnupg 2.5.24
Testing, Unbreak Now!Public

Assigned To
None
Authored By
• werner
Mon, Sep 28, 2:43 PM
Subscribers

Description

This was reported by Thomas Klausner on gnupg-devel. The configure script failed when updating gnupg from 2.5.22 to 2.5.24. I can replicate this: the import of the sample key results in a broken private key file and thus a different keygrip so that the key can't be found when decryption (and it would not work anyway).

The broken key is:

Key: (private-key (ecc (curve "1.3.6.1.4.1.3029.1.5.1")(flags
  djb-tweak)(q #03010807#)(d #5A1EFA9E63363344E65123E324E96230B109E0BDF
 0CA256E2032D3263BE76EB0#)))

And the correct key (here imported with gnupg 2.2 using the 2.5 gpg-agent):

Created: 20220907T100823
Key: (private-key (ecc (curve Curve25519)(flags djb-tweak)(q
  #40439DDC4C820F9AA8E3E42E1F3D25AEE08654CEA7E9123876D021DDC5FDB87C22#)
 (d #5A1EFA9E63363344E65123E324E96230B109E0BDF0CA256E2032D3263BE76EB0#)
 ))

Revisions and Commits

Event Timeline

• werner triaged this task as Unbreak Now! priority.Mon, Sep 28, 2:43 PM
• werner created this task.
• werner renamed this task from Import of ECDH secret keys broken in gnupg 2.5.24 to Import of unprotected ECDH secret keys broken in gnupg 2.5.24.Mon, Sep 28, 4:50 PM
• werner moved this task from Backlog to WIP on the gnupg26 board.
• werner changed the task status from Open to Testing.Mon, Sep 28, 4:53 PM