Yesterday
Additionally to the issue Andre cited years ago, we also did some changes to fix other how signed/encrypted mails are shown, which are also relevant for the inbox. This should be fixed.
Tested on gpg4win-5.0.0-beta413 @ win11 with the following entries in dirmngr.conf:
This is a duplicate of T7833: GpgOL: Security level 2 shown for manually imported and certified cert
Ok, then this is only an issue in the VSD versions. (I confirmed with a quick test with Gpg4win-5.0.0-beta413)
Here is my proposal:
Wed, Nov 26
It would be possible as a workaround in Kleopatra to show any identical entries only once. Saving after that will not add any more entries.
Okay, forward porting that patch is the easiest solution. Actually this is not enough: Users of Libgcrypt also need to make sure that the new sysconfig dir has the right permissions. That's a part for the installer and concrete ACLs may differ.
Likely a bug in Qt. Accessibility Insights for Windows shows that the parent of all grid items is the tree view. It should probably be the parent item instead so that ATs can go up and count the level.
Good catch. My guess is that get_uid_for_sender returns the last matching UID without checking for revocations. The matching was done on the mailbox part only. For reference:
Still open in this ticket (see https://dev.gnupg.org/T6568#208755 ):
- Collapsible items in tree views can't be expanded/collapsed, at least not with space or arrow left/right
- Tab navigation in the Smartcard Dialog is broken
New tickets split from this:
- https://dev.gnupg.org/T7952 Make table column headings for other tables accessible
- https://dev.gnupg.org/T7953 Make table header column width accessible
- https://dev.gnupg.org/T7954 Highlight focused cell in tables
In gpg4win-5.0.0-beta413 @ win11 there's a failing patch for kcrash:
Here is my analysis.
Tue, Nov 25
I can't reproduce this on gpg4win-5.0.0-beta413 @ win11.
This seems to apply only for non vsd compliant algos. Importing and certifying a
- rsa/brainpool cert results in security level 4
- cv25519 cert results in security level 2
For our Okular, we should not use the standard file names (okularrc, …) as this would conflict with a regular Okular installation.
I rechecked: the revoked userid has to match the email address of the sender. Still there's another non revoked userid with the same email address:
Yubikeys allow that. See my mail to the mailing list.
Do you mean one of the user-ids has been revoked or the one matching the mail sender?
The extension .part is used by Mozilla/Firefox. Curl uses .tmp. Is that OK for Windows machine to use .part?
I examined the code of gnupg_sysconfdir in gnupg/common/homedir.c, if we could factor out things to gpgrt, so that something like gpgrt_fconcat with GPGRT_SYSCONFDIR can be implemented.
Mon, Nov 24
Seems like the OpenPGP Card Specification does not allow the change of retry counters.
That is a feature not a bug. Make also sense if your threat model is store-trafic-no-decrypt-later. If you can get the key you will also be abale to get the cleartext. Any nobody can remember a passphrase on par with the claimed Kyber security level.
yes, it seems to be caused by one of the patches. I'm trying to figure out which one...
Or Window activity (which is related to focus). I'm wondering if one of my patches is to blame.
I can reproduce. It's not that the Button itself needs to be pressed twice, *something* in the dialog needs to be pressed before the button reacts. So this looks like it's something about focus
I wonder if we should better open a new ticket with all the relevant data when we get a report giving more information and set this one to invalid.
Panel Used By
| Dashboard | kai's Dashboard |
