Home GnuPG

All Stories

Today

ikloecker renamed T8100: Kleopatra does not start on Windows Server 2016 from QT: SetThreadDescription not found in Qt6Core.dll to Kleopatra does not start on Windows Server 2016.
Wed, Feb 11, 12:06 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker committed rKLEOPATRAec79933401fa: Don't ask about "only user" when importing a shared secret team key (authored by ikloecker).
Don't ask about "only user" when importing a shared secret team key
Wed, Feb 11, 12:04 PM
pmgdeb added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Hi, the test is green with rG86baca6e62b3 for both 2038-01-01 and 2105-01-01. Thanks!

Wed, Feb 11, 11:19 AM · Bug Report
ikloecker claimed T8098: Kleopatra: Omit question about own key when importing a secret team key.
Wed, Feb 11, 11:01 AM · vsd34, gpd5x, kleopatra
ikloecker changed the status of T8056: Support config options RSAKeySizes and PGPKeyType for Kf6 from Open to Testing.

The settings should work again. They are described at https://docs.kde.org/trunk_kf6/en/kleopatra/kleopatra/admin.html#admin-certificate-request-wizard-keys , but note that the documentation is severely outdated. Note that those settings are not officially supported by GnuPG (VS-)Desktop (see https://gnupg.com/vsd/kleopatra-settings.html).

Wed, Feb 11, 10:51 AM · gpd5x, kleopatra
tfry committed rOJ7d33d36d907d: Rename manifest.po to avoid potential name clash (authored by tfry).
Rename manifest.po to avoid potential name clash
Wed, Feb 11, 10:43 AM
ikloecker committed rW05631bc0dd97: qtbase: Make it work on Windows Server 2016 (authored by ikloecker).
qtbase: Make it work on Windows Server 2016
Wed, Feb 11, 10:26 AM
ikloecker changed the status of T8100: Kleopatra does not start on Windows Server 2016 from Open to Testing.

Should work now.

Wed, Feb 11, 10:26 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ebo triaged T8100: Kleopatra does not start on Windows Server 2016 as Normal priority.
Wed, Feb 11, 9:52 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker claimed T8100: Kleopatra does not start on Windows Server 2016.
Wed, Feb 11, 9:49 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
ikloecker added a comment to T8100: Kleopatra does not start on Windows Server 2016.

This was fixed in Qt 6.10.0 by adding compatibility code that's "hidden" behind a compiler flag, i.e. we just need to enable this compiler flag. See https://codereview.qt-project.org/c/qt/qtbase/+/629255 for details.

Wed, Feb 11, 9:49 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt
uwi added a comment to T8101: Upgrade of local (portable) installation failed.

For the time being I "upgraded 5.0.1 to 4.4.1 (in the new directory), and then Kleopatra started again.
When upgrading that installation again to 5.0.1, Kleopatra does not start (same error message as before).

Wed, Feb 11, 9:03 AM · Bug Report, gpg4win
uwi added a comment to T8101: Upgrade of local (portable) installation failed.

Also: When I click "Abort" ("Abbrechen"), the dialog disappeared, but the main windows does not show any progress: Specifically it does not abort.
I had to press "Abort" ("Abbrechen") in the main window; then the upgrade aborted.
When retrying (and confirming that I don't want to install as Administrator (actually I cannot), the proposed target directory still is "C:\Program Files\Gpg4win".
When locating the previous installation directory (it seems it was a subdirectory of %USERPROFIL%\Downloads) the upgrade succeeded, but Kleopatra fails to start.
It want a bin\Qt6Core.dll, bit in the bin directory there is only a Qt5Corew.dll dated " 14. ‎Juli ‎2023, ‏‎13:23:40".
When retrying the installation/upgrade it announced to upgrade 5.0.1, but then did seemingly nothing (I guess as the version was estimated to "be current").
It seems some "reinstall/repair" option is missing.

Wed, Feb 11, 8:54 AM · Bug Report, gpg4win
tfry committed rOJ6a405eceb6bf: Localize manifest strings while generating the manifest (authored by tfry).
Localize manifest strings while generating the manifest
Wed, Feb 11, 8:39 AM
uwi created T8101: Upgrade of local (portable) installation failed.
Wed, Feb 11, 8:31 AM · Bug Report, gpg4win
l10n daemon script <scripty@kde.org> committed rLIBKLEO47ca63d019eb: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Wed, Feb 11, 4:18 AM
gniibe added a comment to T8094: libgcrypt: EC least leak failure on 32-bit machine.

No, OpenBSD's implementation of POSIX semaphore is different to NetBSD.
(It doesn't support PSHARED=1.)

Wed, Feb 11, 2:51 AM · libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO440b85a6f92e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Feb 11, 2:49 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6fa3b37b80a1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Feb 11, 2:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO96873e309146: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Wed, Feb 11, 2:41 AM
gniibe added a comment to T8094: libgcrypt: EC least leak failure on 32-bit machine.

Possibly, it is related to the NetBSD failure of T8065.
If importing the secret key fails (which invokes gpg-agent), decryption cannot be succeeded.
I will check OpenBSD implementation of POSIX semaphore, if it's similar to NetBSD one.

Wed, Feb 11, 2:41 AM · libgcrypt, Bug Report

Yesterday

ikloecker added a comment to T8099: Kleopatra: no default OpenPGP server configured.

We forgot to update the tooltip when the default keyserver was removed in gpg 2.5.3. This has already been fixed in the meantime. Sorry for the inconvenience!

Tue, Feb 10, 10:43 PM · Bug Report, gpg4win
ikloecker committed rKLEOPATRAb9fa02ba2216: Use extended helper to get compliant algorithms for CMS (authored by ikloecker).
Use extended helper to get compliant algorithms for CMS
Tue, Feb 10, 5:22 PM
ikloecker committed rLIBKLEO5e47a7ef6ce2: Bump library version (authored by ikloecker).
Bump library version
Tue, Feb 10, 5:17 PM
ikloecker committed rLIBKLEOa6c8962a9e1a: Re-add support for legacy settings PGPKeyType and RSAKeySizes (authored by ikloecker).
Re-add support for legacy settings PGPKeyType and RSAKeySizes
Tue, Feb 10, 5:17 PM
ikloecker committed rLIBKLEO2e1867d75546: Add support for CMS to algorithm helpers (authored by ikloecker).
Add support for CMS to algorithm helpers
Tue, Feb 10, 5:17 PM
ebo created T8100: Kleopatra does not start on Windows Server 2016.
Tue, Feb 10, 4:18 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
werner committed rG86baca6e62b3: gpgscm: New operator "*long-time-t?" to detect proper time_t systems. (authored by werner).
gpgscm: New operator "*long-time-t?" to detect proper time_t systems.
Tue, Feb 10, 3:40 PM
tfry committed rOJe61d386c0e4d: Do not activate window for RMB click on icon (authored by tfry).
Do not activate window for RMB click on icon
Tue, Feb 10, 3:17 PM
ebo closed T8097: AppImage ships Kleopatra icon in two different variants as Resolved.

Fixed for KF6 versions.

Tue, Feb 10, 3:11 PM · AppImage, Installer, kleopatra
ebo set Version to vsd 3.3.4 on T8097: AppImage ships Kleopatra icon in two different variants.
Tue, Feb 10, 3:11 PM · AppImage, Installer, kleopatra
ikloecker added a comment to T8097: AppImage ships Kleopatra icon in two different variants.

I'm pretty sure that this has already been fixed with the changes made for T8083: Kleopatra: Use blue icon for Gpg4win and GPD. build-appimage.sh now always replaces the Breeze icons shipped with the AppImage with the appropriate head icon.

Tue, Feb 10, 2:41 PM · AppImage, Installer, kleopatra
OliverL created T8099: Kleopatra: no default OpenPGP server configured.
Tue, Feb 10, 1:20 PM · Bug Report, gpg4win
werner triaged T8084: ctype(3) API use as Low priority.
Tue, Feb 10, 11:50 AM · NetBSD, gnupg, Bug Report
werner added a comment to T8097: AppImage ships Kleopatra icon in two different variants.

Won't fix for vsd3x

Tue, Feb 10, 11:50 AM · AppImage, Installer, kleopatra
werner triaged T8097: AppImage ships Kleopatra icon in two different variants as Normal priority.
Tue, Feb 10, 11:49 AM · AppImage, Installer, kleopatra
ebo moved T2227: Sign GpgOL to support group deployments from Backlog to Done on the gpgol board.
Tue, Feb 10, 11:48 AM · gpgol, Feature Request
ebo closed T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries as Resolved.

Meanwhile all executables are signed.

Tue, Feb 10, 11:48 AM · Feature Request, gpg4win
werner committed rW33707dbc0eab: Update libpng to 1.6.55 to due CVE-2026-25646. (authored by werner).
Update libpng to 1.6.55 to due CVE-2026-25646.
Tue, Feb 10, 11:46 AM
werner committed rWc739b47d05eb: msi: Yet another Perl syntax fix. (authored by werner).
msi: Yet another Perl syntax fix.
Tue, Feb 10, 11:33 AM
ebo triaged T8098: Kleopatra: Omit question about own key when importing a secret team key as Normal priority.
Tue, Feb 10, 11:00 AM · vsd34, gpd5x, kleopatra
ikloecker created T8098: Kleopatra: Omit question about own key when importing a secret team key.
Tue, Feb 10, 10:57 AM · vsd34, gpd5x, kleopatra
werner triaged T8094: libgcrypt: EC least leak failure on 32-bit machine as Low priority.

According to the ML @gniibe tried to replicate the problem without success.

Tue, Feb 10, 10:53 AM · libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO6adacdb8cabf: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Feb 10, 2:48 AM
gniibe added a comment to T8066: gpgrt: Static linking support.

Investigating GNU ld, I learned that there is no easy way (~= no way) to suppress the warnings (other than 2>/dev/null). It was implemented by the special section named gnu.warning.SYM where SYM is a symbol. I think that this is not-so-good for glibc to notify its users about possible static link problem, by gnu.warning.SYM.

Tue, Feb 10, 2:42 AM · Linux, Feature Request, gpgrt

Mon, Feb 9

ikloecker added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

I guess the test fails because one cannot create a key with an expiration date before the current date. And the test tries to create a key which expires on 2038-01-01 which will fail if the test is run on 2038-01-01 or later. The easiest fix would be to disable the test cases if the current date is past 2038-01-01.

Mon, Feb 9, 7:36 PM · Bug Report
ikloecker changed the status of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038 from Open to Testing.

Okay, then I set the ticket to Testing.

Mon, Feb 9, 7:24 PM · S/MIME, Bug Report, vsd34, kleopatra
pmgdeb added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Unfortunately, this was run on x86_64 and also other 64 bit archs.

Mon, Feb 9, 4:16 PM · Bug Report
werner added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Is that on a 32 bit machine or 64? The latter would be a problem for 32 bit with 32 bit time-t I'd say: we won't fix it.

Mon, Feb 9, 4:15 PM · Bug Report
tfry committed rOJ575c6ed275ee: Localize tooltip string while generating the manifest (authored by tfry).
Localize tooltip string while generating the manifest
Mon, Feb 9, 3:47 PM
werner added a comment to T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.

At least for an expired data signature I would suggest to have an info button to further expliah this. Maybe to a FAQ or KB article. The case is too rare that we should not discuss endlessly the pros and cons of expiring signatures. I hope that Kleo does not provide an option to crerate such a signature.

Mon, Feb 9, 3:30 PM · Bug Report, gpd5x, kleopatra
tfry created T8097: AppImage ships Kleopatra icon in two different variants.
Mon, Feb 9, 3:17 PM · AppImage, Installer, kleopatra
pmgdeb created T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.
Mon, Feb 9, 12:21 PM · Bug Report
tfry committed rOJ57c3796b85a8: Also save drafts in new common path (authored by tfry).
Also save drafts in new common path
Mon, Feb 9, 12:02 PM
tfry committed rOJc5bb528f7987: Explicitly share certain paths between client and server (authored by tfry).
Explicitly share certain paths between client and server
Mon, Feb 9, 12:02 PM
ebo added a parent task for T6869: Kleopatra: Improve verification results messages (esp. for invalid signature and multiple signatures): T8095: Kleopatra: parent ticket for improvements of verification result messages.
Mon, Feb 9, 11:51 AM · gpd5x (gpd-5.0.0), kleopatra
ebo added a parent task for T7786: Draft: Kleopatra: improvements of signature verification result messages: T8095: Kleopatra: parent ticket for improvements of verification result messages.
Mon, Feb 9, 11:51 AM · a11y, gpd5x, kleopatra
ebo added subtasks for T8095: Kleopatra: parent ticket for improvements of verification result messages: T6869: Kleopatra: Improve verification results messages (esp. for invalid signature and multiple signatures), T7786: Draft: Kleopatra: improvements of signature verification result messages.
Mon, Feb 9, 11:51 AM · kleopatra
ebo added a subtask for T8095: Kleopatra: parent ticket for improvements of verification result messages: T7701: Draft: Kleopatra: Add information for verification results.
Mon, Feb 9, 11:49 AM · kleopatra
ebo added a parent task for T7701: Draft: Kleopatra: Add information for verification results: T8095: Kleopatra: parent ticket for improvements of verification result messages.
Mon, Feb 9, 11:49 AM · gpd5x, kleopatra
ebo added a subtask for T8095: Kleopatra: parent ticket for improvements of verification result messages: T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Mon, Feb 9, 11:49 AM · kleopatra
ebo added a parent task for T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification: T8095: Kleopatra: parent ticket for improvements of verification result messages.
Mon, Feb 9, 11:49 AM · gpd5x, kleopatra
tfry committed rOJce86a52fdfde: Be less noisy about closing/opening the web client pane (authored by tfry).
Be less noisy about closing/opening the web client pane
Mon, Feb 9, 11:46 AM
timegrid added a comment to T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation.

Sorry for the ambiguity. The request was only about mentioning (bpX) for the first two choices, not to add more combinations.

Mon, Feb 9, 11:45 AM · Feature Request, PQC, gnupg26
tfry committed rOJ39728ef5e057: Do not repeat the same message (authored by tfry).
Do not repeat the same message
Mon, Feb 9, 11:33 AM
tfry committed rOJ22a3090cbf54: Better status indication in systray icon (authored by tfry).
Better status indication in systray icon
Mon, Feb 9, 11:33 AM
tfry committed rOJ290e027b5537: In single-user mode, pair clients, automatically (authored by tfry).
In single-user mode, pair clients, automatically
Mon, Feb 9, 11:28 AM
tfry committed rOJ71dbeb11abe1: Cleanup (authored by tfry).
Cleanup
Mon, Feb 9, 11:28 AM
tfry committed rOJ69c8d09a5c3a: Regenerate web files (authored by tfry).
Regenerate web files
Mon, Feb 9, 11:28 AM
tfry committed rOJ1c75ee2f94de: In single user-mode, ensure native client never connects to foreign proxy (authored by tfry).
In single user-mode, ensure native client never connects to foreign proxy
Mon, Feb 9, 11:28 AM
tfry committed rOJ45e6d11ddab2: Limit client connections to same origin IP (authored by tfry).
Limit client connections to same origin IP
Mon, Feb 9, 11:28 AM
ikloecker claimed T8056: Support config options RSAKeySizes and PGPKeyType for Kf6.
Mon, Feb 9, 11:27 AM · gpd5x, kleopatra
ebo added a subtask for T8095: Kleopatra: parent ticket for improvements of verification result messages: T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.
Mon, Feb 9, 11:27 AM · kleopatra
ebo added a parent task for T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked: T8095: Kleopatra: parent ticket for improvements of verification result messages.
Mon, Feb 9, 11:27 AM · Bug Report, gpd5x, kleopatra
ebo triaged T8095: Kleopatra: parent ticket for improvements of verification result messages as Normal priority.
Mon, Feb 9, 11:24 AM · kleopatra
werner added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

Your fix is okay.

Mon, Feb 9, 10:13 AM · S/MIME, Bug Report, vsd34, kleopatra
gniibe created T8094: libgcrypt: EC least leak failure on 32-bit machine.
Mon, Feb 9, 9:58 AM · libgcrypt, Bug Report
werner added a project to T8084: ctype(3) API use: NetBSD.

AFAICS all conditions are protected by isascii(3) which

Mon, Feb 9, 9:49 AM · NetBSD, gnupg, Bug Report
werner triaged T8091: Kleopatra: Add kyber choices for x25519/x448 as Low priority.

Physical experiment feature support should better not be widely used.

Mon, Feb 9, 9:41 AM · gpd5x, PQC, Feature Request, kleopatra
werner triaged T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation as Low priority.
Mon, Feb 9, 9:40 AM · Feature Request, PQC, gnupg26
werner added a comment to T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation.

Although it is technicall possible to use all combinations, we should limit in the menu them to those as listed above. Too many algorithms pose an interop problem. Thus we provide brainpool because it is required in Germany and the two IETF curves for the general internet (for those who are playing mitigation against against physical experiments).

Mon, Feb 9, 9:40 AM · Feature Request, PQC, gnupg26
tfry committed rOJc434063f80f3: Regenerate web files (authored by tfry).
Regenerate web files
Mon, Feb 9, 8:18 AM
tfry committed rOJ8a3622b0dad6: Clean up installation/pairing dialog page a bit (authored by tfry).
Clean up installation/pairing dialog page a bit
Mon, Feb 9, 8:18 AM
tfry committed rOJ15ce5888f848: Add mechanism to pair native and web client using temporary token (authored by tfry).
Add mechanism to pair native and web client using temporary token
Mon, Feb 9, 8:18 AM
tfry committed rOJa7926d188edb: Clean up protocol between native and web client, use ID as mapping (authored by tfry).
Clean up protocol between native and web client, use ID as mapping
Mon, Feb 9, 8:18 AM

Sun, Feb 8

giacomo added a comment to T8093: GPGME: inconsistent behavior on GPGME_KEYLIST_MODE_LOCATE from hkp server.

After serveral clever attempt, I've settled to this simple workaround that seems working despite being quite inefficient: if you don't find any key with gpgme_op_keylist_next and gpgme_err_code(err) == GPG_ERR_EOF on a ctx with keylist mode set to GPGME_KEYLIST_MODE_LOCATE, try again (even on the same context), after

Sun, Feb 8, 2:49 PM · Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA555a8c866cae: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Sun, Feb 8, 2:47 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOafed4d5f1ff6: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Sun, Feb 8, 2:38 AM

Sat, Feb 7

giacomo added a comment to T8093: GPGME: inconsistent behavior on GPGME_KEYLIST_MODE_LOCATE from hkp server.

Looking to workaround this issue, I've noticed something that might be useful during debug.

Sat, Feb 7, 7:28 PM · Bug Report
giacomo created T8093: GPGME: inconsistent behavior on GPGME_KEYLIST_MODE_LOCATE from hkp server.
Sat, Feb 7, 5:16 PM · Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO927b58adf4b9: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Sat, Feb 7, 2:39 AM

Fri, Feb 6

timegrid created T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation.
Fri, Feb 6, 2:31 PM · Feature Request, PQC, gnupg26
ebo added a project to T7502: Kleopatra: Import secret key dialog improvement: needs discussion.
Fri, Feb 6, 2:27 PM · needs discussion, vsd34, gpd5x, kleopatra
timegrid added a comment to T8091: Kleopatra: Add kyber choices for x25519/x448.

Note: In vsd it must be restricted to the bp algorithms then

Fri, Feb 6, 2:00 PM · gpd5x, PQC, Feature Request, kleopatra
timegrid created T8091: Kleopatra: Add kyber choices for x25519/x448.
Fri, Feb 6, 1:57 PM · gpd5x, PQC, Feature Request, kleopatra
mlaurent committed rMTP9d3f8fb523a6: GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it… (authored by mlaurent).
GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it…
Fri, Feb 6, 1:22 PM
mlaurent committed rKLEOPATRA6203af98caef: GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it… (authored by mlaurent).
GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it…
Fri, Feb 6, 1:21 PM
mlaurent committed rLIBKLEO4cd243e1611d: GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it… (authored by mlaurent).
GIT_SILENT: Bump kf ecm_set_disabled_deprecation_versions. Make sure that it…
Fri, Feb 6, 1:18 PM
ebo triaged T8059: Gpg4win: Change bug report address to a Gpg4win-specific address as Normal priority.
Fri, Feb 6, 10:13 AM · needs discussion, gpd5x, kleopatra, gpg4win
ebo triaged T8068: GpgOL: Restore original crypto settings when aborting sending as Normal priority.
Fri, Feb 6, 10:12 AM · gpd5x, gpgol