Page MenuHome GnuPG
Feed All Stories

Today

dkg added a comment to T7527: Keyring/keybox denial of service.

Thank you @werner ! I can confirm that the patches that have landed on STABLE-BRANCH-2-4 do clear up the DoS i was seeing for signature verification.

Sat, Feb 22, 3:08 AM · OpenPGP, gnupg, Bug Report

Yesterday

dkg added a comment to T7106: Trailing newline trouble in clearsigned message generation and verification.

The patch below fixes the master branch to be compliant with the standards for CSF message generation and verification.

Fri, Feb 21, 8:00 PM · gnupg, Bug Report
fmg closed T7537: WKD key import denied due to false dirmngr caching as Resolved.

New Situation
Once I started testing in logging mode the problem had gone away already. There were some hints to HTTPS certificate issues, but nothing really to blame. Neither with nor without logging the problem could be reproduced after two days of questioning me.

Fri, Feb 21, 5:05 PM · dirmngr, wkd, Bug Report
werner committed rGfdcc69c29de2: dirmngr: Prepare for new command KS_DEL. (authored by werner).
dirmngr: Prepare for new command KS_DEL.
Fri, Feb 21, 2:43 PM
werner committed rGdb7141d462ed: dirmngr: Factor a common command parsing code out. (authored by werner).
dirmngr: Factor a common command parsing code out.
Fri, Feb 21, 2:43 PM
werner committed rG75667050dc34: build: Update autogen.sh to the current version. (authored by werner).
build: Update autogen.sh to the current version.
Fri, Feb 21, 12:59 PM
werner committed rGbec71fdbe57b: speedo: Do not build gpgme anymore. (authored by werner).
speedo: Do not build gpgme anymore.
Fri, Feb 21, 12:56 PM
werner closed T7527: Keyring/keybox denial of service as Resolved.

Also fixed for 2.4

Fri, Feb 21, 12:24 PM · OpenPGP, gnupg, Bug Report
werner committed rGda0164efc7f3: gpg: Fix a verification DoS due to a malicious subkey in the keyring. (authored by werner).
gpg: Fix a verification DoS due to a malicious subkey in the keyring.
Fri, Feb 21, 12:24 PM
werner committed rG9cd371b12d80: gpg: Remove a signature check function wrapper. (authored by werner).
gpg: Remove a signature check function wrapper.
Fri, Feb 21, 12:24 PM
werner lowered the priority of T7527: Keyring/keybox denial of service from High to Normal.

This has been fixed in master with rG48978ccb4e:

Fri, Feb 21, 12:18 PM · OpenPGP, gnupg, Bug Report
werner committed rG48978ccb4e20: gpg: Fix a verification DoS due to a malicious subkey in the keyring. (authored by werner).
gpg: Fix a verification DoS due to a malicious subkey in the keyring.
Fri, Feb 21, 12:15 PM
werner committed rG5e87e452e4e8: gpg: Remove a signature check function wrapper. (authored by werner).
gpg: Remove a signature check function wrapper.
Fri, Feb 21, 12:15 PM
werner committed rM6ad324752885: Update autogen.sh from gpgrt (authored by werner).
Update autogen.sh from gpgrt
Fri, Feb 21, 11:24 AM
werner committed rM7e6a65e66a96: Remove the long deprecated and never working trust list functions. (authored by werner).
Remove the long deprecated and never working trust list functions.
Fri, Feb 21, 11:24 AM
werner committed rM4139cbcdc244: Bump LT version to C45/A0/R0 (authored by werner).
Bump LT version to C45/A0/R0
Fri, Feb 21, 11:24 AM
werner committed rMd54d6eaa642b: Remove long deprecated functions. (authored by werner).
Remove long deprecated functions.
Fri, Feb 21, 11:24 AM
werner committed rWd7301355a8fb: Update autogen.sh from libgpg-error. (authored by werner).
Update autogen.sh from libgpg-error.
Fri, Feb 21, 11:13 AM
werner committed rE542b6fce1390: Fix logic for finding the beta version number (authored by ikloecker).
Fix logic for finding the beta version number
Fri, Feb 21, 11:13 AM
werner added a comment to T4834: gpgme library calls gpg with --list-trust-path.

Finally removed with gpgme 2.0

Fri, Feb 21, 10:57 AM · gpgme, Bug Report
werner closed T7294: keyboxd: Possible race conditions (and clean up), a subtask of T7224: Kleopatra: broken in Testversion beta-41, as Resolved.
Fri, Feb 21, 9:15 AM · Bug Report, kleopatra, Restricted Project
werner closed T7294: keyboxd: Possible race conditions (and clean up) as Resolved.

Closed after the release of 2.5.4

Fri, Feb 21, 9:15 AM · keyboxd, Bug Report, kleopatra, Restricted Project
werner triaged T7492: gpgconf failed to kill all gpgagent daemons on windows as Normal priority.
Fri, Feb 21, 9:11 AM · Windows, gnupg, Bug Report
werner triaged T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key as Normal priority.
Fri, Feb 21, 9:11 AM · gpd5x, kleopatra
werner added a comment to T7492: gpgconf failed to kill all gpgagent daemons on windows.

Right when you use a different homedir you also need to pass --homedir to gpgconf or set GNUPGHOME before invoking gpgconf. If you call gpgconf via GPGME the --homedir option is passed; afaics we don't have a kill option gpgme.

Fri, Feb 21, 9:09 AM · Windows, gnupg, Bug Report
werner triaged T7536: Key import dialog should come into foreground when import was triggered by file association as Normal priority.

This even happens with native Windows applications thus normal priority. Users need to watch the taskbar for blinking items.

Fri, Feb 21, 9:04 AM · UI, Bug Report, gpg4win
werner triaged T7537: WKD key import denied due to false dirmngr caching as Normal priority.

The caching works on the base of the requested domain, that is example.org and not openpgpkey.example.org - thus it should not make a difference when you change your setup. There is an initial test for a cached domain status before the resolving process starts. If you want to look yourself: gnupg/dirmngr/server.c:cmd_wkd_get() and domainfo.c.

Fri, Feb 21, 9:00 AM · dirmngr, wkd, Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA08f2f7493efc: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, Feb 21, 2:36 AM
fmg added a comment to T7537: WKD key import denied due to false dirmngr caching.

Reproducibility
The problem cannot be confirmed generic on domain level. I can reproduce the effect with keys shipped from my domain, i.e. email addresses @shimps.de, but the issue vanishes when I try to reproduce it with email addresses @gnupg.org as e.g. Werner's address.

Fri, Feb 21, 12:08 AM · dirmngr, wkd, Bug Report

Thu, Feb 20

ikloecker committed rKLEOPATRA4486a525fb07: Remove unused standalone mode of ResultListWidget (authored by ikloecker).
Remove unused standalone mode of ResultListWidget
Thu, Feb 20, 4:25 PM
ebo renamed T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key from Kleopatra: Do only ask for confirmation once when deleting a secret key to Kleopatra: Do only ask for confirmation twice when deleting a secret key.
Thu, Feb 20, 3:48 PM · gpd5x, kleopatra
ebo created T7538: Kleopatra: Do only ask for confirmation twice when deleting a secret key.
Thu, Feb 20, 3:46 PM · gpd5x, kleopatra
ebo edited projects for T7211: Kleopatra: configuration option to prohibit deletion of certificate with secret key, added: gpd5x; removed Restricted Project.
Thu, Feb 20, 3:33 PM · gpd5x, Feature Request, kleopatra
fmg created T7537: WKD key import denied due to false dirmngr caching.
Thu, Feb 20, 3:29 PM · dirmngr, wkd, Bug Report
werner added a member for Contributor: fmg.
Thu, Feb 20, 2:56 PM
ikloecker committed rWc5e792a1e045: Configure breeze-icons without icon generation and icon installation (authored by ikloecker).
Configure breeze-icons without icon generation and icon installation
Thu, Feb 20, 2:22 PM
ikloecker committed rWf198c565c659: Don't strip if there's nothing to strip (authored by ikloecker).
Don't strip if there's nothing to strip
Thu, Feb 20, 2:22 PM
ikloecker committed rWd3452493e665: Fix logic for finding the beta version number (authored by ikloecker).
Fix logic for finding the beta version number
Thu, Feb 20, 2:22 PM
ikloecker committed rWe8a371334064: Don't build the Breeze icons library in the native build (authored by ikloecker).
Don't build the Breeze icons library in the native build
Thu, Feb 20, 2:22 PM
ikloecker committed rW1895c375b157: Use blue app icon for Kleopatra in GnuPG Desktop (authored by ikloecker).
Use blue app icon for Kleopatra in GnuPG Desktop
Thu, Feb 20, 2:22 PM
ikloecker committed rWecb811904b5b: Perform a fresh configuration of the build tree (authored by ikloecker).
Perform a fresh configuration of the build tree
Thu, Feb 20, 2:22 PM
ebo renamed T7502: Kleopatra: Import secret key dialog improvement from Draft: Kleopatra: Import secret key dialog improvement to Kleopatra: Import secret key dialog improvement.
Thu, Feb 20, 1:59 PM · gpd5x, kleopatra
hej added a comment to T7502: Kleopatra: Import secret key dialog improvement.

You have imported a certificate with secret key.

Thu, Feb 20, 12:54 PM · gpd5x, kleopatra
ebo added a comment to T7502: Kleopatra: Import secret key dialog improvement.

You have imported a certificate with secret key.

Fingerprint: XXX
User ID: ABC
Thu, Feb 20, 12:07 PM · gpd5x, kleopatra
CarlSchwan committed rLIBKLEOa44f00198a45: keyparameters: Add support for control statements (authored by CarlSchwan).
keyparameters: Add support for control statements
Thu, Feb 20, 12:01 PM
ikloecker committed rKLEOPATRA60ec82b90511: Allow to use different icons for a customized build (authored by ikloecker).
Allow to use different icons for a customized build
Thu, Feb 20, 10:47 AM
ikloecker committed rKLEOPATRA58ff277d1111: On Windows, embed our app icon as Breeze icon (authored by ikloecker).
On Windows, embed our app icon as Breeze icon
Thu, Feb 20, 10:47 AM
ikloecker committed rKLEOPATRAfd41019730af: Make it possible to run different flavors of Kleopatra at the same time (authored by ikloecker).
Make it possible to run different flavors of Kleopatra at the same time
Thu, Feb 20, 10:47 AM
hej added a comment to T7502: Kleopatra: Import secret key dialog improvement.

Here are some ideas:

Thu, Feb 20, 10:22 AM · gpd5x, kleopatra
werner edited projects for T7527: Keyring/keybox denial of service, added: OpenPGP; removed keyboxd.

Well, the different outcome depends on the order of the certificates or the string comparision in keyboxd. So it is not a keyboxd vs. pubring.kbx thing.

Thu, Feb 20, 9:30 AM · OpenPGP, gnupg, Bug Report
werner added a comment to T7527: Keyring/keybox denial of service.

Okay, I can reproduce it when not using keyboxd.

Thu, Feb 20, 8:15 AM · OpenPGP, gnupg, Bug Report
gniibe committed rC88ae76d069c3: cipher,mpi: Expose some MPI helper functions by mpi.h. (authored by gniibe).
cipher,mpi: Expose some MPI helper functions by mpi.h.
Thu, Feb 20, 7:23 AM

Wed, Feb 19

ebo added a comment to T7502: Kleopatra: Import secret key dialog improvement.

Also, we should not forget the context of the whole dialog in the window. So we get the wording right, especially regarding key / certificate.

Wed, Feb 19, 5:00 PM · gpd5x, kleopatra
TobiasFella changed the status of T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work from Open to Testing.
Wed, Feb 19, 3:46 PM · Feature Request, kleopatra
TobiasFella added a comment to T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work.

Removed in https://invent.kde.org/pim/kleopatra/-/merge_requests/369

Wed, Feb 19, 3:46 PM · Feature Request, kleopatra
uwi added a comment to T5780: Kleopatra: Result dialog does not have focus after operation.

For me the change fixes the problem on Windows. (I haven't checked if there was a problem on Linux/X11, but I have verified that the change also works on Linux/X11.)

Wed, Feb 19, 2:48 PM · vsd33 (vsd-3.3.0), kleopatra, Restricted Project
TobiasFella committed rKLEOPATRA5968653af605: Remove "Decrypt/Verify all files in folder" (authored by TobiasFella).
Remove "Decrypt/Verify all files in folder"
Wed, Feb 19, 2:29 PM
TobiasFella committed rGPGPASS5135e42b4a23: Use placeholder component when password can't be decrypted (authored by TobiasFella).
Use placeholder component when password can't be decrypted
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS6c8f9fe1308b: Add "Retry Decryption" action (authored by TobiasFella).
Add "Retry Decryption" action
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS7b29cb58df24: Fix typo (authored by TobiasFella).
Fix typo
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS17e469b4d7be: Improve strings (authored by TobiasFella).
Improve strings
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASSa31ca003f082: Don't open Entry editor when double-clicking in tree (authored by TobiasFella).
Don't open Entry editor when double-clicking in tree
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS6b44138b51ae: Make appstream lint happier (authored by TobiasFella).
Make appstream lint happier
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS33472bd0328c: Fix passphrase wordlist loading (authored by TobiasFella).
Fix passphrase wordlist loading
Wed, Feb 19, 1:33 PM
TobiasFella committed rGPGPASS318c57520ae5: Port away from deprecated cmake command (authored by TobiasFella).
Port away from deprecated cmake command
Wed, Feb 19, 1:33 PM
ikloecker added a comment to T7536: Key import dialog should come into foreground when import was triggered by file association.

This is very similar to T5780 except that it concerns a different operation and thus a different window. The fix is likely the same as for T5780.

Wed, Feb 19, 1:26 PM · UI, Bug Report, gpg4win
ikloecker added a comment to T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work.

We do support "Decrypt & Verify" for multiple files (including the presentation of the status) so that it would be easy to do the same for all files in a folder (question is if this should even be recursive). Digging into the history I found that the desktop file was added shortly before Kleopatra 2.0.0-rc1, but that there wasn't any code for iterating a folder, i.e. this can never have worked.

Wed, Feb 19, 1:22 PM · Feature Request, kleopatra
werner triaged T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work as Low priority.
Wed, Feb 19, 12:06 PM · Feature Request, kleopatra
werner added a comment to T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work.

I can't remember that we ever had support this. It is also not easy to come up with the good way to present the status for all files in a folder. We would need to define a format similar to what sha1sum uses: A list of file with they signature file or so. Note that kleopatra has support for running sha256sum in such a way.

Wed, Feb 19, 12:05 PM · Feature Request, kleopatra
werner committed rG4c11359aecf2: doc: Declare --disable-http as legacy. (authored by werner).
doc: Declare --disable-http as legacy.
Wed, Feb 19, 11:56 AM
werner committed rG23913618953d: doc: Declare --disable-http as legacy. (authored by werner).
doc: Declare --disable-http as legacy.
Wed, Feb 19, 11:56 AM
werner added a comment to T7527: Keyring/keybox denial of service.

Sorry. I can't reproduce this. Neither with master nor with the 2.4 repo version.

Wed, Feb 19, 11:27 AM · OpenPGP, gnupg, Bug Report
TobiasFella added a comment to T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work.

We don't have this exact action on windows, but the normal "Decrypt & Verify" action shows up for folders there (and doesn't work either).

Wed, Feb 19, 11:26 AM · Feature Request, kleopatra
uwi updated the task description for T7536: Key import dialog should come into foreground when import was triggered by file association.
Wed, Feb 19, 9:22 AM · UI, Bug Report, gpg4win
uwi updated the task description for T7536: Key import dialog should come into foreground when import was triggered by file association.
Wed, Feb 19, 9:20 AM · UI, Bug Report, gpg4win
uwi created T7536: Key import dialog should come into foreground when import was triggered by file association.
Wed, Feb 19, 9:19 AM · UI, Bug Report, gpg4win
gniibe changed the status of T7519: libgcrypt: (EC)DSA signature generation should be constant-time from Open to Testing.

All changes are pushed to master.

Wed, Feb 19, 5:36 AM · libgcrypt, Bug Report
gniibe changed the status of T7490: libgcrypt: constant-time modular exponentiation, a subtask of T3264: Possible RSA improvement, from Open to Testing.
Wed, Feb 19, 5:35 AM · libgcrypt
gniibe changed the status of T7490: libgcrypt: constant-time modular exponentiation from Open to Testing.

Pushed the changes by the commit rC2039d93289db: mpi: Add MPI helper modular exponentiation, Least Leak Intended.

Wed, Feb 19, 5:35 AM · libgcrypt
gniibe committed rC58aca75a295d: mpi: Add a comment on _gcry_mpih_lookup_lli. (authored by gniibe).
mpi: Add a comment on _gcry_mpih_lookup_lli.
Wed, Feb 19, 3:02 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6676ebc81446: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Feb 19, 2:39 AM
gniibe committed rCbd53c51b0338: mpi: Fix _gcry_mpih_add_lli, as macro. (authored by gniibe).
mpi: Fix _gcry_mpih_add_lli, as macro.
Wed, Feb 19, 2:35 AM
gniibe committed rC8fd2aab881c7: mpi: Add MPH helper of table lookup, Least Leak Intended. (authored by gniibe).
mpi: Add MPH helper of table lookup, Least Leak Intended.
Wed, Feb 19, 1:03 AM
gniibe committed rC2039d93289db: mpi: Add MPI helper modular exponentiation, Least Leak Intended. (authored by gniibe).
mpi: Add MPI helper modular exponentiation, Least Leak Intended.
Wed, Feb 19, 1:03 AM

Tue, Feb 18

CarlSchwan committed rOJb2a73f805bd8: Fix building on Windows (authored by CarlSchwan).
Fix building on Windows
Tue, Feb 18, 11:40 PM
CarlSchwan committed rOJae20fc15268e: Remove dead code (authored by CarlSchwan).
Remove dead code
Tue, Feb 18, 11:40 PM
dkg added a comment to T7527: Keyring/keybox denial of service.

the reproducer is:

Tue, Feb 18, 10:42 PM · OpenPGP, gnupg, Bug Report
dkg reopened T7527: Keyring/keybox denial of service as "Open".

I don't think this is fixed. With this patch in place, if i import blocker.cert first, and then import distsigkey.gpg, it looks to me like i still can't verify signatures made from any of the GnuPG signing keys.

Tue, Feb 18, 10:40 PM · OpenPGP, gnupg, Bug Report
ikloecker created T7535: Kleopatra: "Decrypt/Verify all files in folder" doesn't work.
Tue, Feb 18, 7:18 PM · Feature Request, kleopatra
werner triaged T7462: gpg4win CLI installation ignores .ini configuration as Normal priority.
Tue, Feb 18, 4:51 PM · gpd5x, gpg4win
werner triaged T7534: GpgOL: Header info disappears when forwarding a HTML mail as Normal priority.
Tue, Feb 18, 4:50 PM · gpd5x, gpgol
ebo updated the task description for T7534: GpgOL: Header info disappears when forwarding a HTML mail.
Tue, Feb 18, 4:34 PM · gpd5x, gpgol
ebo created T7534: GpgOL: Header info disappears when forwarding a HTML mail.
Tue, Feb 18, 4:33 PM · gpd5x, gpgol
ebo moved T6559: GPGSM: "always trust like override" or "force" option from Backlog to Done on the gpgol board.
Tue, Feb 18, 2:46 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
werner committed rA9139b983278e: Post release updates (authored by werner).
Post release updates
Tue, Feb 18, 2:14 PM
werner committed rA0f84595a4bc7: Release 3.0.2 (authored by werner).
Release 3.0.2
Tue, Feb 18, 2:14 PM
werner committed rA27b58fd6674c: Put full commit id into VERSION. (authored by werner).
Put full commit id into VERSION.
Tue, Feb 18, 2:14 PM
werner committed rDfca69ef13b11: swdb: libassuan 3.0.2 (authored by werner).
swdb: libassuan 3.0.2
Tue, Feb 18, 2:03 PM
werner added a comment to T7434: Kleopatra: Initial keylisting hangs for ~60 seconds (gpg-agent: Socket ...S.gpg-agent cannot be bound).

Can now be tested after the release of libassuan 3.0.2 (T6163)

Tue, Feb 18, 1:53 PM · gnupg, kleopatra
werner closed T7456: libassuan: Windows: assuan_sock_bind error as Resolved.

Released with libassuan 3.0.2 (T7163)

Tue, Feb 18, 1:52 PM · libassuan, Windows