Home GnuPG

Recent Activity

Today

tfry committed rOJ11cef65eb360: Properly close dialog on successful pairing (authored by tfry).
Properly close dialog on successful pairing
Wed, Jan 7, 4:59 PM
tfry committed rOJef0d2ed6b9d4: Proof of concept pairing mechanism (authored by tfry).
Proof of concept pairing mechanism
Wed, Jan 7, 4:55 PM
andrewgdotcom added a comment to T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks.

So why are there different grades of failure? Why is "invalid packet" a less scary error message than "WARNING: message was not integrity protected" when both are equally bad things?

Wed, Jan 7, 4:37 PM · Not A Bug, gnupg
ebo closed T7439: Kleopatra: DecryptVerifyFilesDialog crashes when output folder does not exist as Resolved.

In Gpg4win-5.0.0-beta479 the dialog no longer exists. Problem solved ;-)

Wed, Jan 7, 4:21 PM · gpd5x, kleopatra, Bug Report
ebo closed T7549: Kleopatra: crash on click in certificate extension dialog as Resolved.
Wed, Jan 7, 4:11 PM · gpd5x, kleopatra
ebo moved T7549: Kleopatra: crash on click in certificate extension dialog from QA to Done on the gpd5x board.

Gpg4win-5.0.0-beta479: works, no crash any more

Wed, Jan 7, 4:11 PM · gpd5x, kleopatra
ikloecker added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

I have verified (by looking at QTextEdit's code) that, on paste, QTextEdit splits the text for the internal representation into lines and discards any CR and LF characters.

Wed, Jan 7, 4:02 PM · gpd5x, vsd34, kleopatra
ikloecker added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

It turns out that Kleopatra's notepad converts the CR characters of the spoofed file to LF characters when pasting the text so that Kleopatra doesn't really verify the content of the spoofed file but different content. And this results in a bad signature. The confusing bit is that Kleopatra also says "Successfully verified the notepad" and that it shows the claimed-to-be-signed text although the signature is bad which could lead an inattentive user to the assumption that the signature of the displayed text was actually good (because "Successfully verified").

Wed, Jan 7, 3:33 PM · gpd5x, vsd34, kleopatra
ebo moved T7427: Kleopatra: Crash after decryption if files has an embedded file name from QA to Done on the gpd5x board.
Wed, Jan 7, 3:27 PM · gpd5x, kleopatra, Bug Report
ebo added a comment to T7427: Kleopatra: Crash after decryption if files has an embedded file name.

works, with Gpg4win-5.0.0-beta479 on Win11.
Now after hitting "save" a dialog is shown asking under which name the file shall be saved. Saving works with both options.

Wed, Jan 7, 3:26 PM · gpd5x, kleopatra, Bug Report
ikloecker renamed T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Kleopatra: Notepad should only show signed part to Kleopatra: Notepad should not show "signed" text if signature is bad.
Wed, Jan 7, 3:24 PM · gpd5x, vsd34, kleopatra
alexk lowered the priority of T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Unbreak Now! to Normal.

There is always a warning about bad signature.

Wed, Jan 7, 3:14 PM · gpd5x, vsd34, kleopatra
ebo added a comment to T8012: Missing error on first key search without keyserver.

It looks similar if the key is in a WKD: First search fails without error, only "no certificates found" is shown. Clicking "Search" again results then in the expected key being found and shown.

Wed, Jan 7, 3:14 PM · dirmngr, Bug Report, gnupg26
werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

I think we are all wrong here. We were tricked by the fact that regardless of the outcome of the signature verification the signed content is shown. That is surprising for a cleartext signature because that one can be viewed anyway. Thus I propose to not update the clipboard unless the signature checks out.

Wed, Jan 7, 3:08 PM · gpd5x, vsd34, kleopatra
werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

I originally uploaded a wrong copy of the file. Now fixed; the correct checksum is 8d830a2dd7e1e14ecbc47b8cdc61d393e9d3f62c

Wed, Jan 7, 2:32 PM · gpd5x, vsd34, kleopatra
ikloecker added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

On Linux, Kleopatra (master) with GnuPG 2.5 (master) shows a BAD signature. It shows the same output as running gpg --verify --output bla.txt in Konsole and pasting the file content (by maybe the copy paste changes some control characters). If I run gpg --verify --output bla.txt <payload.spoofed.asc then bla.txt also contains the same data.

Wed, Jan 7, 2:01 PM · gpd5x, vsd34, kleopatra
timegrid moved T7045: Kleopatra: Use "SCD DEVINFO --watch" also on Windows from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11.
Both without and with DeviceInfoWatcher (via configuration as shown in https://dev.gnupg.org/T7045#186162 ):

  • Removal of smart card -> smart card is removed in smart card view
  • Insertion of smart card + gpg-card -> smart card is added in smart card view
Wed, Jan 7, 1:27 PM · gpd5x, kleopatra
werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

is a spoofed file which verifies okay but shows the inserted and not signed final line. FWIW, gpa gets it right.

Wed, Jan 7, 1:25 PM · gpd5x, vsd34, kleopatra
timegrid closed T6688: Kleopatra GPGME: Reported assert on exit, a subtask of T7045: Kleopatra: Use "SCD DEVINFO --watch" also on Windows, as Resolved.
Wed, Jan 7, 1:18 PM · gpd5x, kleopatra
timegrid closed T6688: Kleopatra GPGME: Reported assert on exit as Resolved.

I'm not sure, how to reproduce this. On gpg4win-5.0.0-beta479 @ win11 I quit Kleopatra with a smartcard inserted, the process exits with code 0, so it looks fine and I'm setting this to resolved.

Wed, Jan 7, 1:18 PM · gpd5x, gpgme, kleopatra
timegrid changed the status of T6793: Cleanup temporary files / dirs with decrypted content, a subtask of T6199: Kleopatra: MIME viewer support, from Testing to Open.
Wed, Jan 7, 12:57 PM · mimetreeparser, Restricted Project, kleopatra
timegrid changed the status of T6793: Cleanup temporary files / dirs with decrypted content from Testing to Open.

Does not work on gpg4win-5.0.0-beta479 @ win11:

  • Open encrypted mail and open attachments in outlook + reboot
    • All temporary files in "C:\Users\g10\AppData\Local\Microsoft\Windows\INetCache\Content.Outlook\ODXPL3A9" are still present after reboot (files with 002 ending additionally opened)
    • Temporary files are still present after opening and closing Kleopatra and Outlook
  • Open encrypted attachment in kleopatra/mailviewer (via .eml file) + reboot
    • All temporary files in "C:\Users\g10\AppData\Local\Temp\kleopatra.XXXXXX" are still present after reboot (one folder per opened file)
    • Temporary files are still present after opening and closing Kleopatra
  • Decrypt archive in kleopatra + reboot during the success dialog with the save button
    • Temporary folder "C:\Users\g10\AppData\Local\Temp\kleopatra.XXXXXX" with extracted tarball still present after reboot
    • Temporary files are still present after opening and closing Kleopatra
Wed, Jan 7, 12:57 PM · gpd5x, vsd32 (vsd-3.2.0), kleopatra
anthumchris added a comment to T8021: Implement gpg key management API.

completed: draft all gpg key function names

Wed, Jan 7, 12:52 PM · gpgme, Feature Request
anthumchris updated the task description for T8021: Implement gpg key management API.
Wed, Jan 7, 12:47 PM · gpgme, Feature Request
anthumchris added a comment to T7975: Official GPGme interface/bindings for Nodejs (node).

I decided to prioritize developer experience and provide simplified, high-level functional abstractions instead of maintaining 1:1 parity with the underlying gpgme library functions. See example in T8021

Wed, Jan 7, 12:39 PM · gpgme, Feature Request
anthumchris updated the task description for T8021: Implement gpg key management API.
Wed, Jan 7, 12:35 PM · gpgme, Feature Request
anthumchris changed the status of T8005: TypeScript support, a subtask of T7975: Official GPGme interface/bindings for Nodejs (node), from Open to Testing.
Wed, Jan 7, 12:30 PM · gpgme, Feature Request
anthumchris changed the status of T8005: TypeScript support from Open to Testing.
Wed, Jan 7, 12:30 PM · gpgme, Feature Request
anthumchris changed the status of T8021: Implement gpg key management API from Open to Testing.
Wed, Jan 7, 12:29 PM · gpgme, Feature Request
alexk triaged T8020: Kleopatra: Notepad should not show "signed" text if signature is bad as Unbreak Now! priority.
Wed, Jan 7, 12:08 PM · gpd5x, vsd34, kleopatra
werner triaged T8017: Okular: Hang on signature with smime cert and distrusted root as High priority.
Wed, Jan 7, 12:06 PM · Bug Report, S/MIME, gpd5x, okular
werner triaged T8018: Okular: No error on signature with wrong passphrase as Normal priority.
Wed, Jan 7, 12:04 PM · Bug Report, gpd5x, okular
werner added a parent task for T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys: T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
werner added a subtask for T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification: T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.
Wed, Jan 7, 12:03 PM · gpd5x, kleopatra
werner triaged T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys as Normal priority.

Traditionally we have considered expired and revoked more or less similar. The idea is that an expired key might have been compromised but the owner did not found a way to revoke it. We may want to change this policy because some users don't care too much about expired keys (cf. T7990) .

Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
ikloecker added a comment to T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.

Verification results for a few more cases (to help with the correct implementation):

Wed, Jan 7, 12:00 PM · gpd5x, kleopatra
werner added a comment to T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks.

Right. And the MDC detects this and only if says okay you get a good decryption status back.

Wed, Jan 7, 11:57 AM · Not A Bug, gnupg
anthumchris closed T8004: Bindings for The GnuPG UI Server Protocol, a subtask of T7975: Official GPGme interface/bindings for Nodejs (node), as Invalid.
Wed, Jan 7, 11:52 AM · gpgme, Feature Request
anthumchris closed T8004: Bindings for The GnuPG UI Server Protocol as Invalid.

I may have misinterpreted what The GnuPG UI Server Protocol is. Instead, I will provide high-level functions to all of gpgme's underlying features

Wed, Jan 7, 11:52 AM · gpgme, Feature Request
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

to make sure we talk about the same thing, it's about the status column:

Wed, Jan 7, 11:51 AM · kleopatra, gpd5x
anthumchris added a subtask for T7975: Official GPGme interface/bindings for Nodejs (node): T8005: TypeScript support.
Wed, Jan 7, 11:46 AM · gpgme, Feature Request
anthumchris edited parent tasks for T8005: TypeScript support, added: T7975: Official GPGme interface/bindings for Nodejs (node); removed: T8004: Bindings for The GnuPG UI Server Protocol.
Wed, Jan 7, 11:46 AM · gpgme, Feature Request
anthumchris removed a subtask for T8004: Bindings for The GnuPG UI Server Protocol: T8005: TypeScript support.
Wed, Jan 7, 11:46 AM · gpgme, Feature Request
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

The imported cert was berta`s in this case.

Wed, Jan 7, 11:46 AM · kleopatra, gpd5x
ikloecker added a comment to T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.

Interestingly, gpg also prints the warning about the missing trusted key signature when verifying a signature made with a revoked key that has a valid certification by a trusted key. This could be intentional (because the revocation invalidates all certifications), but it's still a bit surprising.

Wed, Jan 7, 11:42 AM · Feature Request, S/MIME, OpenPGP, gnupg26
ikloecker created T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.
Wed, Jan 7, 11:20 AM · Feature Request, S/MIME, OpenPGP, gnupg26
andrewgdotcom added a comment to T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks.

This warning shall only show up if a message was really modified and not in case of

a simple truncation.

Wed, Jan 7, 10:42 AM · Not A Bug, gnupg
ikloecker added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Also: What happens if you cancel the ownership question and then change the owner trust of the key on the command line?

after gpg --lsign berta, the status value in kleopatra was updated automatically.

Wed, Jan 7, 10:28 AM · kleopatra, gpd5x
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.
>gpgsm -v --sign --local-user "Edward Tester" test.pdf > test.gpg.p7s
gpgsm: enabled compatibility flags:
gpgsm: looking up issuer from the Dirmngr cache
gpgsm: number of matching certificates: 0
gpgsm: dirmngr cache-only key lookup failed: No data
gpgsm: issuer certificate {04A0A7E932B29D43A9B6673139AF52C0A5FC467BF5A64D044D1AC33613ABBB73CA532569F5779999114C0118CD66FDF6E92B1B0EEE2A4D5A815DA7FD892DDDE9C1} not found using authorityKeyIdentifier
gpgsm: looking up issuer from the Dirmngr cache
gpgsm: number of matching certificates: 0
gpgsm: dirmngr cache-only key lookup failed: No data
gpgsm: certificate is good
gpgsm: root certificate is not marked trusted
gpgsm: fingerprint=D4:EC:A6:B4:69:AB:B5:44:08:27:CB:3F:C7:D7:91:08:3C:10:27:DB
gpgsm: DBG: BEGIN Certificate 'issuer':
gpgsm: DBG:      serial: 01
gpgsm: DBG:   notBefore: 2020-03-26 19:41:01
gpgsm: DBG:    notAfter: 2063-04-05 17:00:00
gpgsm: DBG:      issuer: CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE
gpgsm: DBG:     subject: CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE
gpgsm: DBG:   hash algo: 1.2.840.113549.1.1.11
gpgsm: DBG:   SHA1 Fingerprint: D4:EC:A6:B4:69:AB:B5:44:08:27:CB:3F:C7:D7:91:08:3C:10:27:DB
gpgsm: DBG: END Certificate
gpgsm: after checking the fingerprint, you may want to add it manually to the list of trusted certificates.
gpgsm: validation model used: shell
gpgsm: can't sign using 'Edward Tester': Not trusted
[GNUPG:] FAILURE gpgsm-exit 50331649
Wed, Jan 7, 9:33 AM · Bug Report, S/MIME, gpd5x, okular
svuorela added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

How does gpgsm react if you try to sign with the certificate?

Wed, Jan 7, 9:09 AM · Bug Report, S/MIME, gpd5x, okular
gniibe committed rE753f59cd2c7a: w32:spawn: Handle the case where ->hProcess has invalid handle. (authored by gniibe).
w32:spawn: Handle the case where ->hProcess has invalid handle.
Wed, Jan 7, 7:18 AM
l10n daemon script <scripty@kde.org> committed rMTP88260bb6b555: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 7, 4:21 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAdbcd94448380: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 7, 4:21 AM
l10n daemon script <scripty@kde.org> committed rMTPb71d3eda391d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 7, 2:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO5958c16f5c92: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 7, 2:49 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6228a72e7490: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 7, 2:47 AM

Yesterday

the13thletter added a comment to T8013: gpgconf does not support the --enable-win32-openssh-support option for gpg-agent.

Frankly, he OpenSSH support for Windows was experimental and I have never tested it. If it can be confirmed that this really works and is useful, it will be easy to add the opeion to gpgconf.

Tue, Jan 6, 10:04 PM · Feature Request, ssh, gnupg26, Windows
werner committed rD488a4777c9f7: web: Fix typo (authored by werner).
web: Fix typo
Tue, Jan 6, 5:51 PM
werner committed rD7ac55ef6c70b: web: Swap Mastodon icon wth Fernmeldegeheimnis (authored by werner).
web: Swap Mastodon icon wth Fernmeldegeheimnis
Tue, Jan 6, 5:43 PM
ikloecker added a comment to T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.

Oh, I just noticed that gpg doesn't say anything about the trust of the key if the key is expired. Compare this to the following output of gpg in case of a not-expired signing key without trusted certifications.

[GNUPG:] NEWSIG
gpg: Signature made Di 06 Jan 2026 16:35:20 CET
gpg:                using EDDSA key 98FB8E8F8E5F58FA653E17A6FC9B2EF2C62AC7BE
[GNUPG:] KEY_CONSIDERED 98FB8E8F8E5F58FA653E17A6FC9B2EF2C62AC7BE 0
[GNUPG:] SIG_ID mmuLNgiB0C7AfTaVYpNjZbcVQok 2026-01-06 1767713720
[GNUPG:] GOODSIG FC9B2EF2C62AC7BE t7790-expired
gpg: Good signature from "t7790-expired" [unknown]
[GNUPG:] VALIDSIG 98FB8E8F8E5F58FA653E17A6FC9B2EF2C62AC7BE 2026-01-06 1767713720 0 4 0 22 10 00 98FB8E8F8E5F58FA653E17A6FC9B2EF2C62AC7BE
[GNUPG:] TRUST_UNDEFINED 0 pgp
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
      98FB8E8F8E5F58FA653E17A6FC9B2EF2C62AC7BE
Tue, Jan 6, 5:23 PM · gpd5x, kleopatra
ikloecker added a comment to T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.

How I reproduced this:

  • Create new test key
  • Detached-sign some text with the new test key
  • Change trust of test key to "unknown"
  • Expire the test key (e.g. with gpg --quick-set-expire FPR seconds=1)
Tue, Jan 6, 5:10 PM · gpd5x, kleopatra
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Other observations:

  • after removing the smartcard reader again it's still not reproducible
  • after win restart it's not always reproducible
  • best chances to reproduce by killing all gpg related processes and deleting gnupghome and Gpg4Win folders first, then import
Tue, Jan 6, 5:05 PM · kleopatra, gpd5x
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

after attaching a smartcard reader with a smartcard, i can't reproduce this issue anymore

Tue, Jan 6, 4:50 PM · kleopatra, gpd5x
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Also: What happens if you cancel the ownership question and then change the owner trust of the key on the command line?

Tue, Jan 6, 4:47 PM · kleopatra, gpd5x
timegrid added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Interesting. I also wasn't able to reproduce this anymore, although I even created a new VM to make sure this is reproducible in a clean setup (and it was reproducible every time).
After restart of windows, it is reproducible again. This is the debugview output for an import without status update:

Tue, Jan 6, 4:42 PM · kleopatra, gpd5x
werner committed rD142e60f21764: web: Link to our mastodon account. (authored by werner).
web: Link to our mastodon account.
Tue, Jan 6, 4:27 PM
ikloecker claimed T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Tue, Jan 6, 4:05 PM · gpd5x, kleopatra
werner committed rD63dde190af01: web: New debian packages (authored by werner).
web: New debian packages
Tue, Jan 6, 4:01 PM
timegrid moved T7272: Kleopatra: Look up missing OpenPGP certificates for card keys from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11.

Tue, Jan 6, 3:55 PM · LDAP, gpd5x, kleopatra
ikloecker added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

I cannot reproduce this on Linux. Here I see that the file system watcher notices that trustdb.gpg was changed and triggers a keylisting.

Tue, Jan 6, 3:34 PM · kleopatra, gpd5x
ikloecker added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Also: What happens if you cancel the ownership question and then change the owner trust of the key on the command line?

Tue, Jan 6, 3:29 PM · kleopatra, gpd5x
ikloecker added a comment to T8015: Kleopatra: Status in certificate list not updated after import.

Please attach the log output of Kleopatra

Tue, Jan 6, 3:22 PM · kleopatra, gpd5x
timegrid moved T7937: Kleopatra: Screenreaders stay silent when smartcard window is opened from QA to Done on the gpd5x board.

Done

  • progress/busy indicator shown (probably also read, but loading was too fast, so it skipped the text)
alt+m
Manage Smart Cards - Kleopatra  window
Loading smart cards...
tab control
OpenPGP - 0005 00009D58  tab  Alt+  O
Tue, Jan 6, 3:02 PM · gpd5x, a11y, kleopatra
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

Maybe it would be better to just not offer S/MIME certs with distrusted root cert?

Tue, Jan 6, 2:42 PM · Bug Report, S/MIME, gpd5x, okular
svuorela added a comment to T6731: Default save dir in okular/windows is wrong.

Note: It does not seem to be possible to open a pdf from an URL, at least not via CLI okular.exe <URL> (it says Unknown protocol 'https').

Tue, Jan 6, 2:35 PM · gpd5x, okular
timegrid moved T7285: Okular: Improvement of error messages regarding signatures from QA to WIP on the gpd5x board.

I tried to get any error response but found those issues instead:

Tue, Jan 6, 2:33 PM · gpd5x, okular
timegrid created T8018: Okular: No error on signature with wrong passphrase.
Tue, Jan 6, 2:28 PM · Bug Report, gpd5x, okular
ikloecker changed the status of T8014: Kleopatra: Incorrect handling of unset keyserver in configuration dialog from Open to Testing.

Fixed.

Tue, Jan 6, 2:23 PM · gpd5x, kleopatra
ikloecker committed rKLEOPATRA429beeb20991: Explicitly set keyserver to "none" if usage of keyserver is disabled (authored by ikloecker).
Explicitly set keyserver to "none" if usage of keyserver is disabled
Tue, Jan 6, 2:20 PM
ikloecker committed rKLEOPATRA2a3e927f0ba3: Fix handling of unset keyserver and improve usability (authored by ikloecker).
Fix handling of unset keyserver and improve usability
Tue, Jan 6, 2:20 PM
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

If all processes are killed before okular is opened, i get an error:


Tue, Jan 6, 2:15 PM · Bug Report, S/MIME, gpd5x, okular
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

gpgsm.log (debug-all, whole process of signing)

Tue, Jan 6, 2:11 PM · Bug Report, S/MIME, gpd5x, okular
timegrid created T8017: Okular: Hang on signature with smime cert and distrusted root.
Tue, Jan 6, 2:03 PM · Bug Report, S/MIME, gpd5x, okular
timegrid moved T6731: Default save dir in okular/windows is wrong from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11. The default path is now the same as the path of the opened file:

Tue, Jan 6, 1:40 PM · gpd5x, okular
timegrid closed T1825: Add a re-encrypt to additional key as Resolved.
Tue, Jan 6, 12:57 PM · gpd5x, gnupg26, Feature Request
werner added a comment to T1825: Add a re-encrypt to additional key.

Regarding my comment T1825#191055 : The mane page has long been updated and gpgme support is also available. For the symmetric session key, see the feature request T8016

Tue, Jan 6, 12:53 PM · gpd5x, gnupg26, Feature Request
werner triaged T8016: Keep symmetric encryption keys with --add-recipients as Low priority.
Tue, Jan 6, 12:51 PM · gpd5x, gnupg26, Feature Request
timegrid created T8015: Kleopatra: Status in certificate list not updated after import.
Tue, Jan 6, 12:37 PM · kleopatra, gpd5x
timegrid moved T1825: Add a re-encrypt to additional key from QA to Done on the gnupg26 board.
Tue, Jan 6, 12:28 PM · gpd5x, gnupg26, Feature Request
timegrid moved T1825: Add a re-encrypt to additional key from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11:

  • gpg --show-only-session-key --decrypt FILE shows only the session key
  • gpg --add-recipients -r UID1 FILE adds recipients (tested with one or more uids)
  • gpg --change-recipients -r UID FILE changes the recipients (tested with one or more uids)
Tue, Jan 6, 12:28 PM · gpd5x, gnupg26, Feature Request
timegrid moved T7983: gpg: the validity of a secret key is changed by making a certification with it from QA to Done on the gnupg26 board.
Tue, Jan 6, 12:08 PM · keyboxd, Bug Report, gpd5x, gnupg26
timegrid moved T7983: gpg: the validity of a secret key is changed by making a certification with it from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11.
I can't reproduce ebo's nor pl13's issue.

Tue, Jan 6, 12:07 PM · keyboxd, Bug Report, gpd5x, gnupg26
ebo moved T6731: Default save dir in okular/windows is wrong from Backlog to QA on the gpd5x board.
Tue, Jan 6, 11:28 AM · gpd5x, okular
ebo moved T7285: Okular: Improvement of error messages regarding signatures from Backlog to QA on the gpd5x board.
Tue, Jan 6, 11:28 AM · gpd5x, okular
ebo moved T7983: gpg: the validity of a secret key is changed by making a certification with it from Backlog to QA on the gpd5x board.
Tue, Jan 6, 11:20 AM · keyboxd, Bug Report, gpd5x, gnupg26
ebo moved T7983: gpg: the validity of a secret key is changed by making a certification with it from Backlog to QA on the gnupg26 board.
Tue, Jan 6, 11:20 AM · keyboxd, Bug Report, gpd5x, gnupg26
ikloecker moved T8014: Kleopatra: Incorrect handling of unset keyserver in configuration dialog from Backlog to WIP on the gpd5x board.
Tue, Jan 6, 11:14 AM · gpd5x, kleopatra
ebo moved T7427: Kleopatra: Crash after decryption if files has an embedded file name from Backlog to QA on the gpd5x board.
Tue, Jan 6, 10:55 AM · gpd5x, kleopatra, Bug Report
ikloecker triaged T8014: Kleopatra: Incorrect handling of unset keyserver in configuration dialog as Normal priority.
Tue, Jan 6, 10:54 AM · gpd5x, kleopatra
ebo moved T7439: Kleopatra: DecryptVerifyFilesDialog crashes when output folder does not exist from Backlog to QA on the gpd5x board.
Tue, Jan 6, 10:54 AM · gpd5x, kleopatra, Bug Report