After discussion various other wordings like:
Since the signing certificate is not marked as verified, the data cannot be trusted to originate from the right source, either. Technically, signature and data match.
I found this hard to read. Suggestion: "Technically, signature and data match, but the signing certificate is not marked as verified. The data cannot be trusted to originate from the stated source."
It occurred to me that users may find the wording "evaluated FILE with signature" strange, because if you have a paper document you check the signature and not the content of the file.
Opinions?
Remove standalone root CA generator
Centralize path handling, remove duplicate files
Simplify installation code
Start server process from same directory
Test results with the same files as in my last comment and the updated patch:
In cases 2 and 4 where no compression and no was used, and a
later tag was modified the output file still remains.
In all other cases no output file (with or without ) remains.
There was no veto for the removal of the color. I'll update the description.
gpgoljs: Add dependency on kdsingleapplication
Update GnuPG to 2.5.20 and Libgcrypt 1.12.2
Noteworthy changes in Version 5.0.2 (2026-03-16)
Thanks again for further testing of yours.
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAee52f240dbdf: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAdee8839c734d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rMTP019d361ed8a0: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rLIBKLEO5cf8bedf2501: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA3583c926674d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rLIBKLEOba3bffb8a92f: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
l10n daemon script <scripty@kde.org> committed
rMTP73f5566c8d29: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAb6bc0fe57c40: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rLIBKLEOcf780f4eb46a: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rLIBKLEO1066f66c55b3: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
GIT_SILENT: time to increase version
GIT_SILENT: time to increase version
GIT_SILENT: time to increase version
GIT_SILENT: prepare 6.7.3
l10n daemon script <scripty@kde.org> committed
rLIBKLEO5eadaac28b14: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAd35166aedb04: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rLIBKLEOd10b531eb537: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA0d20afabe00c: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
I tested following cases with a 100~mb file (GnuPG 2.5.20 on linux):
Clarify description of crypotographically invalid signature
Cleanup unused redundant code
Move web install files to qrc
GIT_SILENT: prepare 6.7.3
cipher:kem: Validate input length.
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAf81a9be2c8b2: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA297293bada01: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA8074154476ac: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
I'd like to push the changes above for gpg, even if it's not exactly same as what Kleo does (not perfect enough: when signature check fails, output file remains;).
l10n daemon script <scripty@kde.org> committed
rKLEOPATRAe16abe6ba054: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Add reuse lint in pre-commit CI support
I found that for a signed+encrypted file, when AEAD failure occurs in the stream of signature part (after literal data part), output file remains.
It's also the case when signature (which comes after literal data packet) is wrong.
sexp: Add length check DATALEN when parsing SEXP.
cipher:gcm: Silence GCC 15 warning.
Tested on Linux with GnuPG 2.5.20.
Testing with a small file (160~byte) did not leave a broken file. If I
understand Werner correctly it is due to libgpg-error/estream.c:
fcancel emptying the buffer if the file fits in the buffer.
Thus I tested with a 1GB file.
modified bigfile.txt
Output before patch:
A broken file remains.
Additional patch for gpg:
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA8fa8c4002abb: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA6e6155430bbf: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA327016f9d4d3: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed
rKLEOPATRA9f62adc37d10: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
In the comment of mine {T7873#218499}, I was wrong. The place I explained for a breakpoint was for symmetric encryption.
For public key encryption, it is:
For gpg, we need to check (and possibly fix) the cases with:
Remove reference to removed patch
Update libkleo and kleopatra
Move web install files to qrc
m <meik.michalke@gnupg.com> committed
rW6837be0e1621: updated GpgOL/Web (authored by m <meik.michalke@gnupg.com>).
updated GpgOL/Web
Ensure that key filters are listed in correct order
Actually this means that the BER encoding is broken. I would propose to not return an error in this case only if a new flag is passed to libksba.
Ensure that key filters read from config are sorted correctly
Add test case for sender UID in prettyFormatSignature()
Actually display specified sender in prettyFormatSignature()
Update libkleo and kleopatra
Update libkleo and kleopatra
Update kmime, kmbox, mimetreeparser to 26.04.1
gen-qt.sh: Fix update of packages.list
gen-qt.sh: Add support for Qt 5 packages
• ebo edited projects for
T6333: GpgOL: Improve handling of HTML Only mails, added:
gpd5x; removed
Restricted Project.
Allow to fetch messages from shared mailboxes
Detect, offer to import OpenPGP keys in attachments / headers
Detect, offer to import OpenPGP keys in attachments / headers