Page MenuHome GnuPG
Feed All Stories

Mar 4 2015

cnd reopened T1857: broken SSL certificate in bug tracking system as "Open".
Mar 4 2015, 12:58 PM
cnd added a project to T1857: broken SSL certificate in bug tracking system: Bug Report.
Mar 4 2015, 12:58 PM
cnd added a comment to T1857: broken SSL certificate in bug tracking system.

You stated that you deliberately used a self-signed SSL cert instead of
buying one, because, in your own words, "The X.509 system is broken beyond
repair."

That is a political reason, and is has reduced user security. Using non-
working SSL reduces security - you do know that, don't you?

The *reason* security gets "broken beyond repair", is because too many
people change mistakes into "notbug" and never fix stuff.

Bite your tongue, swallow your pride, spend the $3.50 and just buy a
certificate mate.

This conversation is going to get read by other people in future, you decide
next what you want them to think about you.

Mar 4 2015, 12:58 PM
cnd raised the priority of T1857: broken SSL certificate in bug tracking system from Normal to Unbreak Now!.
Mar 4 2015, 12:58 PM
werner added a comment to T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf.

Some may want such an option, please discuss at gnupg-users and re-open this bug
if the conclusion is that there needs to be a way to ignore the preferred keyserver.

Mar 4 2015, 12:50 PM
werner added a comment to T1857: broken SSL certificate in bug tracking system.

Just a last remark: You have an encrypted connection which protects you from
passive easvesdropping of the password. Securing agains active attacks is much
harder and thus useless. The only thing we need to protect is the password
which in turn is only used as an anti-spam measure. All information in the
tracker are public anyway.

Mar 4 2015, 12:48 PM
werner added a comment to T1857: broken SSL certificate in bug tracking system.

I have not reduced the "security" of anything for political reasons.
This discussion does not belong into a bug tracker - please use gnupg-users
instead. Thanks.

Mar 4 2015, 12:44 PM
werner added a comment to T1862: Building static GnuPG 2.1.2 fails due to multiply defined symbols..

What platform? Did you run ldconfig after installing a library?

Mar 4 2015, 12:39 PM · Bug Report, gnupg
werner lowered the priority of T1862: Building static GnuPG 2.1.2 fails due to multiply defined symbols. from High to Normal.
Mar 4 2015, 12:39 PM · Bug Report, gnupg

Mar 3 2015

perske added a comment to T1644: Do not expect KeyIDs to be unique.

I really want to try, but I cannot compile 2.1.2 due to T1862.

Mar 3 2015, 7:38 PM · gnupg (gpg22), S/MIME, Bug Report
perske set Version to 2.1.2 on T1862: Building static GnuPG 2.1.2 fails due to multiply defined symbols..
Mar 3 2015, 7:36 PM · Bug Report, gnupg
perske added projects to T1862: Building static GnuPG 2.1.2 fails due to multiply defined symbols.: gnupg, Bug Report.
Mar 3 2015, 7:36 PM · Bug Report, gnupg
cnd renamed T1857: broken SSL certificate in bug tracking system from broken SSL certificate in bug tyracking system to broken SSL certificate in bug tracking system.
Mar 3 2015, 6:35 PM
cnd added a comment to T1857: broken SSL certificate in bug tracking system.

In what other ways have you "on purpose" reduced the security of your users
for tin-foil-hat political reasons I wonder?

Buy the cert. It's, like, $3.50 (comodo), or if you really want to splurge,
$49 for unlimited number of domains and SANs and wildcards and whatever else
tickles your fancy (startssl)

Mar 3 2015, 6:35 PM
perske added a comment to T1590: dirmngr with libgcrypt 1.6.0 forgets to initialize pth properly.

Compiling with latest npth instead of latest pth does not change anything.
Without patch = segfault, with patch = works.

Mar 3 2015, 4:54 PM · In Progress, dirmngr, Bug Report, gnupg (gpg20)
werner added a comment to T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey.

I do not think that such an option is useful. Please feel free to discuss at
gnupg-users to get other opinions.

Mar 3 2015, 2:48 PM · gnupg
werner added a project to T1861: gpgsm does not handle certificates with ambiguous name correctly: Duplicate.
Mar 3 2015, 2:46 PM · Duplicate, Bug Report, gnupg, gnupg (gpg20), S/MIME
werner added a comment to T1861: gpgsm does not handle certificates with ambiguous name correctly.

Duplicate of T1644

Mar 3 2015, 2:46 PM · Duplicate, Bug Report, gnupg, gnupg (gpg20), S/MIME
werner added a comment to T1861: gpgsm does not handle certificates with ambiguous name correctly.

Okay, I changed your role so that you can comment on T1644.

It is very unlikely that we are going to fix that in 2.0, thus be prepared to
move to 2.1.

Mar 3 2015, 2:46 PM · Duplicate, Bug Report, gnupg, gnupg (gpg20), S/MIME
werner closed T1857: broken SSL certificate in bug tracking system as Invalid.
Mar 3 2015, 2:43 PM
werner lowered the priority of T1857: broken SSL certificate in bug tracking system from Unbreak Now! to Normal.
Mar 3 2015, 2:43 PM
werner removed a project from T1857: broken SSL certificate in bug tracking system: Bug Report.
Mar 3 2015, 2:43 PM
werner added a comment to T1857: broken SSL certificate in bug tracking system.

That is actually on purpose. The X.509 system is broken beyond repair. It is
just not SECURE. The only thing you get is protection against passive
eavesdropping (if at all).

However, given all these complinats it might be easier to pay for a certificate.
I will consider this but first the tracker needs to be moved to another box.

Mar 3 2015, 2:43 PM
klada added projects to T1861: gpgsm does not handle certificates with ambiguous name correctly: S/MIME, gnupg (gpg20), gnupg, Bug Report.
Mar 3 2015, 1:43 PM · Duplicate, Bug Report, gnupg, gnupg (gpg20), S/MIME
klada set Version to 2.0.27 on T1861: gpgsm does not handle certificates with ambiguous name correctly.
Mar 3 2015, 1:43 PM · Duplicate, Bug Report, gnupg, gnupg (gpg20), S/MIME
jaymzh added a comment to T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf.

Wow. I didn't even know that was a thing. What's weirder is --keyserver doesn't
override it. Shouldn't the user be able to override it somehow?

Mar 3 2015, 10:30 AM
jaymzh added a comment to T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey.

Yes, I understand that keyids are not unique. However, when I ask for the
fingerprint of a key, I likely mean the primary key, not subkeys. People use
keyids (hopefully long, often short), or fingerprints as an identity... and they
always mean of their primary key, not their subkeys. There should be an option
to list only primary keys that match.

Mar 3 2015, 10:29 AM · gnupg
werner claimed T1847: Cannot read old keyring (issue 1793 related).
Mar 3 2015, 10:24 AM · Bug Report, gnupg
werner added a comment to T1847: Cannot read old keyring (issue 1793 related).

Thanks. It might be related to a left overPGP-2 key in the trustdb. I need to
investigate that closer.

Mar 3 2015, 10:24 AM · Bug Report, gnupg
werner removed a project from T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf: Bug Report.
Mar 3 2015, 10:17 AM
werner closed T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf as Invalid.
Mar 3 2015, 10:17 AM
werner added a comment to T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf.

gpg --check-sigs --list-options show-keyserver-urls BEB441496300CC3D
[...]
sig!3 BEB441496300CC3D 2011-02-15 Jeremy Kitchen (Systems

   Preferred keyserver: hkp://subkeys.pgp.net/

The key itself specifies preferred keyserver which overrides a standard keyserver.

Mar 3 2015, 10:17 AM
werner removed a project from T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey: Bug Report.
Mar 3 2015, 10:13 AM · gnupg
werner closed T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey as Invalid.
Mar 3 2015, 10:13 AM · gnupg
werner added a comment to T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey.

keyids are not unique. The short keyid of the subkey of the second key matches
the keyid of the first key and thus both are listed.

Mar 3 2015, 10:13 AM · gnupg
werner closed T1859: libgpg-error-1.18: e: WARNING: 'missing' script is too old or missing as Resolved.
Mar 3 2015, 10:10 AM · Bug Report, Not A Bug, gpgrt
werner added a project to T1859: libgpg-error-1.18: e: WARNING: 'missing' script is too old or missing: Not A Bug.
Mar 3 2015, 10:10 AM · Bug Report, Not A Bug, gpgrt
werner added a comment to T1859: libgpg-error-1.18: e: WARNING: 'missing' script is too old or missing.

It is just warning which does not matter if you are using a released tarball.
The next release will support newer autotools and has updated helper files.

Mar 3 2015, 10:10 AM · Bug Report, Not A Bug, gpgrt
werner removed a project from T1860: Can't verify signatures from command line using signer's public key block: Bug Report.
Mar 3 2015, 10:01 AM · Not A Bug, gnupg
werner closed T1860: Can't verify signatures from command line using signer's public key block as Invalid.
Mar 3 2015, 10:01 AM · Not A Bug, gnupg
werner added a comment to T1860: Can't verify signatures from command line using signer's public key block.

Download the page.
gpg -import the downloaded file.
Or copy and paste from the <bre> block.

I consider this a question and not a bug. Please post it again to the
gnupg-users@gnupg.org mailing-list. No need to subscribe; we have moderators to
let it through)

Mar 3 2015, 10:01 AM · Not A Bug, gnupg
werner lowered the priority of T1858: Wish for additional TLS access to GnuPG and Gpg4win binaries from Unbreak Now! to Normal.
Mar 3 2015, 9:56 AM · Feature Request, gpgweb
werner removed a project from T1858: Wish for additional TLS access to GnuPG and Gpg4win binaries: Bug Report.
Mar 3 2015, 9:56 AM · Feature Request, gpgweb
werner added a comment to T1858: Wish for additional TLS access to GnuPG and Gpg4win binaries.

Sorry, I do not understand yourt point.

Sure, FPT is clear and not authenticated. Instead of providing a not very
secure HTTPS access to the files we provide signatures for all source files
which are way more secure than the X.509 infrastructure.

It is in fact reasonsbale to ask to use an existing gpg to verify a signature.
gpg is a base tool for almost free OS distributions for about 15 years.

If you need to fallback to SHA-1 checksum, you may take them from the
announcement or from https://gnupg.org/download/integrity_check.html they are at
the bottom of the page. Only the current versions are listed, though.

Mar 3 2015, 9:56 AM · Feature Request, gpgweb
werner closed T1858: Wish for additional TLS access to GnuPG and Gpg4win binaries as Invalid.
Mar 3 2015, 9:56 AM · Feature Request, gpgweb
JW added a comment to T1860: Can't verify signatures from command line using signer's public key block.

Mar 3 2015, 8:40 AM · Not A Bug, gnupg
JW added projects to T1860: Can't verify signatures from command line using signer's public key block: gnupg, Bug Report.
Mar 3 2015, 8:40 AM · Not A Bug, gnupg
JW set Version to 1.4.16 on T1860: Can't verify signatures from command line using signer's public key block.
Mar 3 2015, 8:40 AM · Not A Bug, gnupg
JW set Version to 1.18 on T1859: libgpg-error-1.18: e: WARNING: 'missing' script is too old or missing.
Mar 3 2015, 7:59 AM · Bug Report, Not A Bug, gpgrt
JW added projects to T1859: libgpg-error-1.18: e: WARNING: 'missing' script is too old or missing: gpgrt, Bug Report.
Mar 3 2015, 7:59 AM · Bug Report, Not A Bug, gpgrt

Mar 1 2015

johnny added a comment to T1746: Bug report - GPG a folder to *.tar.gpg loss all files!.

I have verified that the bug have been solved in version 2.2.3. Thank you very much.

Mar 1 2015, 1:24 PM · Bug Report, gnupg, gpg4win
cnd added a project to T1858: Wish for additional TLS access to GnuPG and Gpg4win binaries: Bug Report.
Mar 1 2015, 4:13 AM · Feature Request, gpgweb
cnd added a comment to T1857: broken SSL certificate in bug tracking system.

Mar 1 2015, 4:00 AM
cnd added a project to T1857: broken SSL certificate in bug tracking system: Bug Report.
Mar 1 2015, 4:00 AM
jaymzh added a project to T1856: Requesting a fingerprint for a keyid will show fingerprints for different keys with matching subkey: Bug Report.
Mar 1 2015, 2:55 AM · gnupg
jaymzh added a project to T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf: Bug Report.
Mar 1 2015, 2:52 AM
jaymzh set Version to 1.4.18 on T1855: Some keyids make --refresh-keys ignore ~/.gnupg/gpg.conf.
Mar 1 2015, 2:52 AM

Feb 27 2015

andy_s added a comment to T1853: ecdh/ecdsa private key export, MPI encoding oddity.

Posted to the list, though not as a subscriber (so it'll need to be approved).

I apologize if I jumped the gun by posting here first - given that my question
was effectively "is this a bug?" (and that I was expecting the answer to be
"yes"), I was erring on the side of caution.

Feb 27 2015, 3:23 PM · Bug Report, gnupg, gnupg (gpg21)
nrickert added a comment to T1847: Cannot read old keyring (issue 1793 related).

Here's the output:


% gpg -K 1F38684E
% gpg -K 1F38684E
gpg: Oops: keyid_from_fingerprint: no pubkey
sec dsa1024/46B1EFE1 1999-07-05
uid [ultimate] Neil W Rickert <rickert@cs.niu.edu>
ssb elg2048/1F38684E 1999-07-05

% gpg --with-keygrip -k 1F38684E
gpg: Oops: keyid_from_fingerprint: no pubkey
pub dsa1024/46B1EFE1 1999-07-05

Keygrip = AD607F40378A7ADBC06212C08554174AB7A02B0D

uid [ultimate] Neil W Rickert <rickert@cs.niu.edu>
sub elg2048/1F38684E 1999-07-05

Keygrip = 007FC4C272831E165FDC61E9B078E566D7F472A3

Files exist for both keygrips in that output.

Feb 27 2015, 3:14 PM · Bug Report, gnupg
werner added a comment to T1852: Probable typo in sexp.c - mising parentheses.

You are right. Due to the first condition the second evaluates to (0==1). I
need to check whether thsi used inside libgcrypt.

What a pity that I released 1.6.3 without noticing this bug. ("typo" falsely
made be believe a doc problem). Sorry.

Feb 27 2015, 3:10 PM · Bug Report, libgcrypt
lorenz added projects to T1854: Problems with same encryption and signing key on smartcard: scd, Feature Request.
Feb 27 2015, 2:15 PM · gnupg, Feature Request, scd
werner added a comment to T1847: Cannot read old keyring (issue 1793 related).

Does

gpg -K  1F38684E

list this key? If not please do

gpg --with-keygrip -k 1F38684E

and check that there is a file named after the kegrip below
~/.gnupg/private-keys-v1.d/

Feb 27 2015, 1:52 PM · Bug Report, gnupg
werner added a comment to T1853: ecdh/ecdsa private key export, MPI encoding oddity.

Well, this sounds more like a question than a bug. Can you please post it to
gnupg-devel?

Feb 27 2015, 1:49 PM · Bug Report, gnupg, gnupg (gpg21)

Feb 26 2015

andy_s added projects to T1853: ecdh/ecdsa private key export, MPI encoding oddity: gnupg (gpg21), gnupg, Bug Report.
Feb 26 2015, 5:41 PM · Bug Report, gnupg, gnupg (gpg21)
andy_s set Version to 2.1.2 on T1853: ecdh/ecdsa private key export, MPI encoding oddity.
Feb 26 2015, 5:41 PM · Bug Report, gnupg, gnupg (gpg21)
nrickert added a comment to T1847: Cannot read old keyring (issue 1793 related).

With that patch:
gpg --list-keys rickert

that now works. However, I am still unable to decrypt. When attempting to open

kdewallet, I get the message:

Error when attempting to decrypt the wallet kdewallet using GPG. If you're using
a SmartCard, please ensure it's inserted then try again.

GPG error was Decryption failed

If I try to decrypt a file at the command line, I get:

gpg: encrypted with 2048-bit ELG key, ID 1F38684E, created 1999-07-05

"Neil W Rickert <rickert@cs.niu.edu>"
gpg: decryption failed: No secret key

However, using the same keyring, this all works with opensuse 13.2 (gpg 2.0.26),
so the secret key is there. The file uses the same key as kdewallet.

Feb 26 2015, 6:13 AM · Bug Report, gnupg

Feb 25 2015

t8m set Version to 1.6.2 on T1852: Probable typo in sexp.c - mising parentheses.
Feb 25 2015, 4:31 PM · Bug Report, libgcrypt
t8m added projects to T1852: Probable typo in sexp.c - mising parentheses: libgcrypt, Bug Report.
Feb 25 2015, 4:31 PM · Bug Report, libgcrypt

Feb 24 2015

donmez added projects to T1851: hkps support is broken: gnupg, Bug Report.
Feb 24 2015, 3:07 PM · Bug Report, gnupg
bevan added a comment to T1793: gnupg 2.1.1 regression: keyring_get_keyblock: read error: Invalid packet.

This issue seems to be gone with gnupg 2.1.2. Thanks for the fix :)

Feb 24 2015, 11:43 AM · Bug Report, gnupg, Arch
bevan closed T1793: gnupg 2.1.1 regression: keyring_get_keyblock: read error: Invalid packet as Resolved.
Feb 24 2015, 11:43 AM · Bug Report, gnupg, Arch

Feb 23 2015

dexolabs added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

I could attach some screen shots if that may be of any help.

Feb 23 2015, 5:40 PM · Bug Report, gnupg
werner added a comment to T1823: parse-packet.c DoS using badly encoded MPIs..

Back ported to 1.4 (commit 27d7addccf782d5cb0084cb17522d712d4a6d6b)

Feb 23 2015, 5:14 PM · Bug Report, gnupg
werner closed T1823: parse-packet.c DoS using badly encoded MPIs. as Resolved.
Feb 23 2015, 5:14 PM · Bug Report, gnupg
werner removed projects from T1823: parse-packet.c DoS using badly encoded MPIs.: backport, In Progress.
Feb 23 2015, 5:14 PM · Bug Report, gnupg
werner added a comment to T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7.

Fixed in all branches.

Feb 23 2015, 5:12 PM · Bug Report, gnupg
werner removed a project from T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7: In Progress.
Feb 23 2015, 5:12 PM · Bug Report, gnupg
werner closed T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7 as Resolved.
Feb 23 2015, 5:12 PM · Bug Report, gnupg
werner added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

Thank. I was not sure about this. Thus I need to re-use the passphrase for
subkey generation (this is a bit complicated but reuidred to remove this
regression).

Feb 23 2015, 4:46 PM · Bug Report, gnupg
werner added a comment to T1847: Cannot read old keyring (issue 1793 related).

D285: 559_0001-gpg-Skip-legacy-keys-while-searching-keyrings.patch

Feb 23 2015, 4:43 PM · Bug Report, gnupg
werner added a comment to T1847: Cannot read old keyring (issue 1793 related).

The code to skip the old keys is getting quite complex for the only reason to
allow reporting the use of such keys during import.

Please try the attached patch.

Feb 23 2015, 4:43 PM · Bug Report, gnupg
dexolabs added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

In the last non modern version (i downgraded) after the 2.1.2 problem, 2.0.27,
when i generated a new subkey, the only passphrase asked was to unlock the private
key, it never prompted me for another passphrase for the subkey.

Feb 23 2015, 3:49 PM · Bug Report, gnupg
werner added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

So you mean gpg should use the passphrase of the main key for the new subkey as
well, right?

This could be done but it won't allow to use a different passphrase for the
subkey. If that is a regression from 2.0 this should be considered a bug, else
a a "whish".

Feb 23 2015, 3:45 PM · Bug Report, gnupg
werner added a project to T1847: Cannot read old keyring (issue 1793 related): In Progress.
Feb 23 2015, 3:39 PM · Bug Report, gnupg
werner closed T1850: DNS CERT lookup fails in 2.1.2 as Resolved.
Feb 23 2015, 3:27 PM · Bug Report
werner added a comment to T1850: DNS CERT lookup fails in 2.1.2.

Fixed. Thanks.

Feb 23 2015, 3:27 PM · Bug Report
dexolabs added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

Yes it asks for the passphrase to unlock the keyring, nut when i want to generate
a key, it asks me for the passphrase to unlock the keyring which i provide, then
it follows up with a "enter a new passphrase" dialog. If i cancel said dialog then
it does not allow me to generate and add the key.

Feb 23 2015, 3:25 PM · Bug Report, gnupg
werner lowered the priority of T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys from Unbreak Now! to Normal.
Feb 23 2015, 3:20 PM · Bug Report, gnupg
werner added a comment to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.

Sure it asks for a passphrase when adding a subkey. The passphrase is required
to a) protect the passphrase and b) to create a key-binding signature.

I might have not fully understood your report. In that case please describe it
again step by step.

Feb 23 2015, 3:20 PM · Bug Report, gnupg
tot set Version to 2.1.2 on T1850: DNS CERT lookup fails in 2.1.2.
Feb 23 2015, 9:39 AM · Bug Report
tot added a comment to T1850: DNS CERT lookup fails in 2.1.2.

D286: 558_gnupg-2.1.2-dns-cert.patch

Feb 23 2015, 9:39 AM · Bug Report
tot added a project to T1850: DNS CERT lookup fails in 2.1.2: Bug Report.
Feb 23 2015, 9:39 AM · Bug Report

Feb 22 2015

rillig added a comment to T1849: Show revocation certificate details.

After trying some more, I found out some things.

I just have to run "gpg revoke.asc", without any options.

But then, the reason text that I entered when generating the revocation
certificate is not shown. Nor is the numeric reason.

gpg: standalone signature of class 0x20
gpg: Signature made 02/22/15 15:46:23 Eur using DSA key ID BACCF5EE
gpg: standalone revocation - use "gpg --import" to apply

And I dont understand what “class 0x20” means.

Feb 22 2015, 4:53 PM · gnupg, Feature Request
rillig added projects to T1849: Show revocation certificate details: Feature Request, gnupg.
Feb 22 2015, 4:40 PM · gnupg, Feature Request
rillig set Version to 1.4.18, 2.0.22 on T1849: Show revocation certificate details.
Feb 22 2015, 4:40 PM · gnupg, Feature Request

Feb 21 2015

dexolabs added projects to T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys: gnupg, Bug Report.
Feb 21 2015, 7:45 AM · Bug Report, gnupg
dexolabs set Version to 2.1.2 on T1848: gpg 2.1.2 with pinentry-curses prompts for passphrase when adding subkeys.
Feb 21 2015, 7:45 AM · Bug Report, gnupg

Feb 20 2015

nrickert added a comment to T1847: Cannot read old keyring (issue 1793 related).

Feb 20 2015, 6:17 PM · Bug Report, gnupg
nrickert set Version to gpg 2.1.2 on T1847: Cannot read old keyring (issue 1793 related).
Feb 20 2015, 6:17 PM · Bug Report, gnupg
nrickert added projects to T1847: Cannot read old keyring (issue 1793 related): gnupg, Bug Report.
Feb 20 2015, 6:17 PM · Bug Report, gnupg