In T8029#212310, @werner wrote:My actual plan is to rework the imp[ort/export of secret keys to gpg-agent. Right now gpg-agent has knowledge of OpenPGP for import/export. This is not good and the required conversion should be moved to a helper tools for easier testing and to have this out of the gpg-agent process. For Kyber we right now don't use any conversion mut store the secret keys in gpg-agent's native format. Thus the passphrase is not necessary. We need to figure out why we have this problem here.
Today
Today
Marian-Kechlibar added a comment to T8029: IPC error on batch import of secret kyber cert.
l10n daemon script <scripty@kde.org> committed rKLEOPATRA83ebdcd8cd79: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Yesterday
Yesterday
heirecka committed rKLEOPATRAd0afae5618b7: GIT_SILENT Upgrade release service version to 25.12.3. (authored by heirecka).
GIT_SILENT Upgrade release service version to 25.12.3.
heirecka committed rKLEOPATRA0c6d0b166e58: GIT_SILENT Update Appstream for new release (authored by heirecka).
GIT_SILENT Update Appstream for new release
heirecka committed rKLEOPATRA1a9403b4118a: GIT_SILENT Update Appstream for new release (authored by heirecka).
GIT_SILENT Update Appstream for new release
l10n daemon script <scripty@kde.org> committed rKLEOPATRA8790653f252d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rMTPc9741932ee29: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, Feb 27
Fri, Feb 27
• ebo added a project to T5707: Kleopatra: Use windows registry additionally to config files: needs discussion.
@werner said the reading order should be like on the page https://gnupg.com/vsd/kleopatra-settings.html:
• ebo added a comment to T5707: Kleopatra: Use windows registry additionally to config files.
Tested with Gpg4win 5.0.2 (Beta):
Registry settings SOFTWARE\Gpg4win\Kleopatra\<config group>\<config entry>
works (I used [CertificateCreationWizard] EMAIL_placeholder for testing)
• werner added a project to T8138: Kleopatra: Key generation fails with "unkown elliptic curve": RC.
• werner lowered the priority of T8138: Kleopatra: Key generation fails with "unkown elliptic curve" from Unbreak Now! to High.
This is not "Unbreak now" because we have not released the software yet. Unbreak now should be used for bugs in deployed software but not during development.
timegrid added a comment to T8141: Kleopatra: Many wrong registry keys created in HKCU\Software\Gpg4Win.
Note: This was fine on gpg4win-5.0.1
timegrid added a comment to T8140: Kleopatra: Segfault on start/import.
Regarding some broken "reg create" on some filepath: split into T8141: Kleopatra: Many wrong registry keys created in HKCU\Software\Gpg4Win
timegrid triaged T8141: Kleopatra: Many wrong registry keys created in HKCU\Software\Gpg4Win as High priority.
timegrid added a comment to T8140: Kleopatra: Segfault on start/import.
I rechecked the keyboxd locking of pubring.db. On crash via gdb the file was unlocked before, so this doesn't seem to be the problem:
• ebo added a comment to T7637: Kleopatra: certifications by available secret key which is *not* set to "ultimate" owner trust are disregarded .
Ok in Gpg4win 5.0.2. (Beta), in German:
• werner added a comment to T8138: Kleopatra: Key generation fails with "unkown elliptic curve".
Libkleo does not specify the curve in the parameter file becuase keyCurvve:isEmpty is asserted:
• werner added a comment to T8138: Kleopatra: Key generation fails with "unkown elliptic curve".
Works on the command line and adding a subkey later does also work.
• ebo triaged T8138: Kleopatra: Key generation fails with "unkown elliptic curve" as Unbreak Now! priority.
config file: Sorry, I got confused, it has to be %APPDATA%\GnuPG VS-Desktop\kleopatrarc in this case (VS-Desktop-4.0.90.1203-Beta), of course. And this one works.
Registry entry SOFTWARE\GnuPG VS-Desktop\Kleopatra\CMS\SaveCSRAsPEM does not work, though. But this is a separate issue, seems all Registry entries do not work in that build.
• werner committed rWc515c336d9af: msi: Tweak make-msi.pl for new VSD global conf dir. (authored by • werner).
msi: Tweak make-msi.pl for new VSD global conf dir.
Update GpgOL to 2.7.2
timegrid added a comment to T8115: Kleopatra: allow saving CSR in PEM format.
- config file: According to T7717: Location of qt-application config files %APPDATA%/Gpg4win/kleopatrarc should work.
- registry: According to T5707: Kleopatra: Use windows registry additionally to config files this should be SOFTWARE\Gpg4win\Kleopatra\CMS\SaveCSRAsPEM now
• gniibe committed rAe71eb3ec615e: Enable warnings for maintainer mode. Fix warnings. (authored by • gniibe).
Enable warnings for maintainer mode. Fix warnings.
• ebo added a comment to T8115: Kleopatra: allow saving CSR in PEM format.
Works with VS-Desktop-4.0.90.1203-Beta when putting this in C:\Program Files\GnuPG VS-Desktop\share\kleopatrarc
CSR is then saved as .pem file with ascii-armored content.
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTPb644af55c75a: In plain text mails, format any signature as fixed spaced (authored by Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net>).
In plain text mails, format any signature as fixed spaced
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTP50806e607128: In plain text mails, format any signature as fixed spaced (authored by Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net>).
In plain text mails, format any signature as fixed spaced
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTP4b3732043dbb: Do not overwrite specified encoding of signed parts (authored by tfry).
Do not overwrite specified encoding of signed parts
The new German tool tip is shown in Gpg4win 5.0.2 (Beta)
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTPcacc05459935: In plain text mails, format any signature as fixed spaced (authored by Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net>).
In plain text mails, format any signature as fixed spaced
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTP1ef743160afe: In plain text mails, format any signature as fixed spaced (authored by Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net>).
In plain text mails, format any signature as fixed spaced
Thomas Friedrichsmeier <thomas.friedrichsmeier@kdemail.net> committed rMTP47075737a984: Do not overwrite specified encoding of signed parts (authored by tfry).
Do not overwrite specified encoding of signed parts
• gniibe closed T7629: gcc 15 warns about -Wunterminated-string-initialization in gnupg as Resolved.
l10n daemon script <scripty@kde.org> committed rKLEOPATRAf5880a29259f: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
• gniibe added a comment to T8078: GpgAgent: trustlist.txt still requires LF on the last line.
I found that it's not that simple to accept the case of no newline at the end.
Because we need to handle the edge case where no newline occurs at the maximum buffer length, too.
It's something like the following.
l10n daemon script <scripty@kde.org> committed rLIBKLEOa9455d8270c9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rMTP17b11dbe47d8: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
l10n daemon script <scripty@kde.org> committed rKLEOPATRAc00b6050be1c: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Thu, Feb 26
Thu, Feb 26
• ikloecker changed the status of T7502: Kleopatra: Import secret key dialog improvement from Open to Testing.
Done and backported for VSD 3.4.
• ikloecker committed rKLEOPATRA7a7d2d68cefc: Show different "Certify new key?" dialog only for shared *secret* keys (authored by • ikloecker).
Show different "Certify new key?" dialog only for shared *secret* keys
• ikloecker committed rKLEOPATRAb00f29b16c18: Ask for certification of imported shared team key (authored by • ikloecker).
Ask for certification of imported shared team key
• ikloecker committed rKLEOPATRA1c92ce890d18: Show a different "Certify new key?" dialog for shared secret keys (authored by • ikloecker).
Show a different "Certify new key?" dialog for shared secret keys
• ikloecker committed rKLEOPATRAab65332a17bf: Reword question asked for imported secret keys (authored by • ikloecker).
Reword question asked for imported secret keys
• ikloecker committed rKLEOPATRA27a9404ae554: Show different "Certify new key?" dialog only for shared *secret* keys (authored by • ikloecker).
Show different "Certify new key?" dialog only for shared *secret* keys
• ikloecker committed rKLEOPATRA411c78f4307d: Show a different "Certify new key?" dialog for shared secret keys (authored by • ikloecker).
Show a different "Certify new key?" dialog for shared secret keys
• ebo added a project to T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures: test on hold.
Thanks for the info!
• ikloecker changed the status of T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures from Open to Testing.
This was fixed in Okular with https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2115 . The MR was merged 2026-02-05.
tfry committed rMTP3208713030e9: Do not overwrite specified encoding of signed parts (authored by tfry).
Do not overwrite specified encoding of signed parts
• ebo changed the status of T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures from Testing to Open.
Does not work in the latest Gpg4win builds (5.0.0. to 5.0.2).
I have no idea which commit would be needed, I see no commit with this bug-ID.
• ebo removed a project from T7885: Kleopatra: Unsupported backup of secret kyber key should be handled more gracefully: gpd5x.
• ebo moved T7989: GpgOL: Confusing message in dialog window "Conflicting crypto settings" from WIP to QA on the gpd5x board.
• ebo moved T7988: reencrypt: Better indication of progress / status from WIP to QA on the gpd5x board.
• ebo moved T8039: NSIS: Preselection of installed components on reinstall only works with browser integration installed from WIP to QA on the gpd5x board.
• ebo moved T8038: NSIS: Updating line omitted if browser integration is installed from WIP to QA on the gpd5x board.
• ebo moved T7040: Make it possible to install GnuPG VSD and GPD in parallel from WIP to QA on the gpd5x board.
• ebo moved T6568: Kleopatra: make table column headings accessible from WIP to QA on the gpd5x board.
• ebo moved T7528: Make it possible to run Kleopatra VSD and Kleopatra GPD in parallel from WIP to QA on the gpd5x board.
• ebo moved T7848: Kleopatra: Remove whitespace from suggested export filename from WIP to QA on the gpd5x board.
• ebo moved T7772: Kleopatra: Config option - only allow upload of certificates with private key to LDAP keyserver from WIP to QA on the gpd5x board.
• ebo moved T8014: Kleopatra: Incorrect handling of unset keyserver in configuration dialog from WIP to QA on the gpd5x board.
• ebo moved T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from WIP to QA on the gpd5x board.
• ebo moved T5707: Kleopatra: Use windows registry additionally to config files from WIP to QA on the gpd5x board.
• ebo moved T7831: Kleopatra: Configuration of the initial status of all checkboxes in the sign/encrypt dialog from WIP to QA on the gpd5x board.
• ebo moved T8030: Kleopatra: Add hint to filename of secret team key exports with signing key from WIP to QA on the gpd5x board.
• ebo moved T8027: Kleopatra: a secret team key should always include all public key information from WIP to QA on the gpd5x board.
• ebo moved T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked from WIP to QA on the gpd5x board.
• ebo moved T8015: Kleopatra: Status in certificate list not updated after import from WIP to QA on the gpd5x board.
• ebo moved T7789: Kleopatra: Wrong error message when choosing an expired certificate for encryption from WIP to QA on the gpd5x board.
• ebo moved T8042: Kleopatra: Add expired/revoked information to ldap search results from WIP to QA on the gpd5x board.
• ebo moved T7455: Improved Sign/Encrypt/Decrypt/Verify from clipboard from WIP to QA on the gpd5x board.
• ebo moved T8022: Kleopatra: Extract a tar.gpg archive consisting of only one folder directly into a given directory from WIP to QA on the gpd5x board.
• ebo moved T8051: Kleopatra: Tab navigation in smartcard table is broken from WIP to QA on the gpd5x board.
• ebo moved T7967: Kleopatra: User specific text on the welcome page. from WIP to QA on the gpd5x board.
• ebo moved T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong from WIP to QA on the gpd5x board.
• ebo moved T8056: Support config options RSAKeySizes and PGPKeyType for Kf6 from WIP to QA on the gpd5x board.
• ebo moved T8100: Kleopatra does not start on Windows Server 2016 from WIP to QA on the gpd5x board.
• ebo moved T8098: Kleopatra: Omit question about own key when importing a secret team key from WIP to QA on the gpd5x board.
• ebo moved T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key from WIP to QA on the gpd5x board.