Page MenuHome GnuPG
Feed Advanced Search

May 11 2015

werner closed T672: option to restrict agent cache usage as Resolved.
May 11 2015, 8:46 PM · gnupg, Feature Request
werner added a comment to T672: option to restrict agent cache usage.

You can implemnnt something like this using 2.1 and the --extra-socket feature.
Give the extra socket appropriate permissions/ACLs

May 11 2015, 8:46 PM · gnupg, Feature Request
werner added a project to T1860: Can't verify signatures from command line using signer's public key block: Not A Bug.
May 11 2015, 8:45 PM · Not A Bug, gnupg
werner added a project to T1693: Spurious "Enter new filename" prompt: Not A Bug.
May 11 2015, 8:44 PM · Not A Bug, gnupg
werner added a comment to T1606: gpg --sign-key doesn't worth with --yes, --no-tty, or --batch.

FWIW, 2.1.4 will also bring a

gpg --quick-adduid USER_ID NEW_USER_ID

I close this bug because the new features won't be backported to 1.4 or 2.0.

May 11 2015, 8:43 PM · Won't Fix, gnupg (gpg20), gnupg (gpg14), gnupg
werner added projects to T1606: gpg --sign-key doesn't worth with --yes, --no-tty, or --batch: gnupg (gpg14), gnupg (gpg20), Won't Fix.
May 11 2015, 8:43 PM · Won't Fix, gnupg (gpg20), gnupg (gpg14), gnupg
werner added a comment to T1789: build-aux/missing is too old.

All updated in the meantime.

May 11 2015, 8:41 PM · gnupg
werner added a project to T1480: [patch] get rid of old ERR return values: Too Old.
May 11 2015, 8:40 PM · Too Old, gnupg
werner added a comment to T1964: make distclean forgets tests/crls.d and tests/S.dirmngr.

Actually "make distcheck" does such a check and thus I wonder how this can
aheppn. Well (make distcheck and me) we are always doint out-of-source builds
so this might be the reason.

May 11 2015, 8:39 PM · Bug Report, gnupg
werner closed T1209: Cherry ST-2000U USB card reader keypad not working on GNU/Linux as Resolved.
May 11 2015, 8:35 PM · scd, Bug Report, gnupg
werner added a comment to T1209: Cherry ST-2000U USB card reader keypad not working on GNU/Linux.

This bug report is quite old and a lot of code has been improved. Thus please
re-open it if it persists with 2.1.3.

May 11 2015, 8:35 PM · scd, Bug Report, gnupg
werner closed T1485: deluid deleting all exact copies from secret key as Resolved.
May 11 2015, 8:33 PM · Won't Fix, gnupg (gpg14), gnupg, Bug Report
werner added projects to T1485: deluid deleting all exact copies from secret key: gnupg (gpg14), Won't Fix.
May 11 2015, 8:33 PM · Won't Fix, gnupg (gpg14), gnupg, Bug Report
werner added a comment to T1485: deluid deleting all exact copies from secret key.

This won't happen in 2.1 anymore. We can't do much about it in 1.4. sorry.

May 11 2015, 8:33 PM · Won't Fix, gnupg (gpg14), gnupg, Bug Report
werner removed a project from T1546: Windows command line prepends homedir to --keyring= path specification: Restricted Project.
May 11 2015, 8:32 PM · Windows 32, Windows, Bug Report, gnupg
werner closed T1546: Windows command line prepends homedir to --keyring= path specification as Resolved.
May 11 2015, 8:32 PM · Windows 32, Windows, Bug Report, gnupg
werner closed T1596: GnuPG does not work correctly with OSX MS-DOS/FAT implementation. as Resolved.
May 11 2015, 8:31 PM · Not A Bug, Bug Report, MacOS, gnupg
werner removed a project from T1596: GnuPG does not work correctly with OSX MS-DOS/FAT implementation.: Stalled.
May 11 2015, 8:31 PM · Not A Bug, Bug Report, MacOS, gnupg
werner added a project to T1596: GnuPG does not work correctly with OSX MS-DOS/FAT implementation.: Not A Bug.
May 11 2015, 8:31 PM · Not A Bug, Bug Report, MacOS, gnupg
werner added a project to T1742: gpg --list-secret-keys may not show all UIDs when a UID has been revoked: Won't Fix.
May 11 2015, 8:28 PM · Won't Fix, Bug Report, gnupg
werner added a comment to T1742: gpg --list-secret-keys may not show all UIDs when a UID has been revoked.

Thanks.

May 11 2015, 8:28 PM · Won't Fix, Bug Report, gnupg
werner closed T1742: gpg --list-secret-keys may not show all UIDs when a UID has been revoked as Resolved.
May 11 2015, 8:28 PM · Won't Fix, Bug Report, gnupg
werner added a comment to T1762: gpg --homedir as root fails to convert old keyrings.

Can you please try with the latest version (2.1.4 will be released tomorrow)

May 11 2015, 8:27 PM · Bug Report, gnupg, Arch, Keyserver
werner added a project to T1763: gpg ... delete key failed: Unknown system error: gnupg (gpg20).
May 11 2015, 8:25 PM · gnupg (gpg20), Bug Report, gnupg
werner added a comment to T1763: gpg ... delete key failed: Unknown system error.

When updating a key gpg uses the keyring where it was found in the first place
and only this. Thus it is better to have only one copy.

May 11 2015, 8:25 PM · gnupg (gpg20), Bug Report, gnupg
werner added a comment to T1778: t-exechelp-posix get_max_fds returns MAX_INT32 rather than something sensible.

I am not sure whether this patch is the best for all platforms.

For now I install a fix that detects INT32_MAX and returns 256 then. May it be
that AIX does not use a fixed size structure? In this case it would be usable
to know whether there is a way to get information on the highest fd currently in
use.

May 11 2015, 8:22 PM · gnupg, Bug Report
werner closed T1792: hkps: Hostname verification uses the wrong hostname as Resolved.
May 11 2015, 7:55 PM · gnupg, Bug Report, Debian, dirmngr
werner removed a project from T1792: hkps: Hostname verification uses the wrong hostname: Restricted Project.
May 11 2015, 7:55 PM · gnupg, Bug Report, Debian, dirmngr
werner added a comment to T1799: GnuPG does not provide Host: header for proxy requests.

This report was for which version of GnuPG?

May 11 2015, 7:54 PM · Bug Report, gnupg
werner added a project to T1799: GnuPG does not provide Host: header for proxy requests: Info Needed.
May 11 2015, 7:54 PM · Bug Report, gnupg
werner renamed T1800: Allow s2k options for gpg --export-secret-key from Secret key s2k options ignored in GnuPG modern to Allow s2k options for gpg --export-secret-key.
May 11 2015, 7:52 PM · Feature Request, gnupg
werner removed a project from T1800: Allow s2k options for gpg --export-secret-key: Bug Report.
May 11 2015, 7:51 PM · Feature Request, gnupg
werner added a comment to T1800: Allow s2k options for gpg --export-secret-key.

Implement that for export.

May 11 2015, 7:51 PM · Feature Request, gnupg
werner added a project to T1800: Allow s2k options for gpg --export-secret-key: Feature Request.
May 11 2015, 7:51 PM · Feature Request, gnupg
werner closed T1802: broken keyring on 2.1.1 as Resolved.
May 11 2015, 7:50 PM · gnupg, Duplicate, Bug Report
werner added a comment to T1802: broken keyring on 2.1.1.

1793 has been fixed thus we can close this.

May 11 2015, 7:50 PM · gnupg, Duplicate, Bug Report
werner removed a project from T1802: broken keyring on 2.1.1: In Progress.
May 11 2015, 7:50 PM · gnupg, Duplicate, Bug Report
werner added a comment to T1811: Own key's validity gets set from ultimate to undef when signing a key that signed you.

May I assume this problem has been fixed?

(BTW, I sign my commits now)

May 11 2015, 7:48 PM · gnupg, Bug Report
werner added a project to T1819: "gpg --gen-key" failed on Windows: Info Needed.
May 11 2015, 7:46 PM · Duplicate, Windows 32, gnupg (gpg21), Windows, Bug Report, gnupg
werner added a comment to T1819: "gpg --gen-key" failed on Windows.

Please try 2.1.3 or the soon to be released 2.1.4

May 11 2015, 7:46 PM · Duplicate, Windows 32, gnupg (gpg21), Windows, Bug Report, gnupg
werner set External Link to https://bugs.debian.org/778480 on T1841: gpg-connect-agent: percent+ function doesn't encode '+'.
May 11 2015, 7:42 PM · Debian, Bug Report, gnupg
werner added a project to T1841: gpg-connect-agent: percent+ function doesn't encode '+': Restricted Project.
May 11 2015, 7:42 PM · Debian, Bug Report, gnupg
werner added a comment to T1841: gpg-connect-agent: percent+ function doesn't encode '+'.

I have fixed it for the gca functions percent and percent+ but won't do it in
the generic percent_exacpe C function. Changing the latter may introduce
regressions.

Fixed for 2.0 and 2.1.

May 11 2015, 7:42 PM · Debian, Bug Report, gnupg
werner added a comment to T1844: dirmngr-client should auto-detect when input is in PEM form.

You need to use --pem:

  dirmngr-client -v --pem ~/tmp/google.pem

There is no auto-detection in dirmngr-client. If you think this is useful
please change Priority to "feature " and adjust the title.

May 11 2015, 7:24 PM · Feature Request, gnupg, dirmngr
werner added a comment to T1851: hkps support is broken.

We fixed some things related to this in 2.1.3.
(2.1.4 will be released tomorrow)

May 11 2015, 7:10 PM · Bug Report, gnupg
werner closed T1853: ecdh/ecdsa private key export, MPI encoding oddity as Resolved.
May 11 2015, 7:08 PM · Bug Report, gnupg, gnupg (gpg21)
werner removed a project from T1853: ecdh/ecdsa private key export, MPI encoding oddity: Restricted Project.
May 11 2015, 7:08 PM · Bug Report, gnupg, gnupg (gpg21)
werner added a project to T1963: ldap keyserver communication error: Fedora.
May 11 2015, 7:06 PM · Fedora, gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1963: ldap keyserver communication error.

This looks more like a problem with the way that versionnhas been build in
Fedora. I suggest to take this problem to Fedora or the gnupg-users mailing list.

May 11 2015, 7:04 PM · Fedora, gnupg (gpg14), Bug Report, gnupg
werner added a project to T1963: ldap keyserver communication error: gnupg (gpg14).
May 11 2015, 7:01 PM · Fedora, gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm.

Okay that can be done. It won't be in 2.1., though.

May 11 2015, 7:00 PM · Bug Report, gnupg
werner added projects to T1973: Wrong line endings when decrypting to console: Windows, Windows 32.
May 11 2015, 6:28 PM · Windows 32, Windows, Bug Report, gnupg
aheinecke reopened T1921: Duplicated certificates in gpgsm pubring (2.1) as "Open".
May 11 2015, 3:46 PM · Bug Report, gnupg, dirmngr, S/MIME
aheinecke added a comment to T1921: Duplicated certificates in gpgsm pubring (2.1).

During deployment of gnupg 2.1.3 this bug was still noticed and I can still
reproduce it with git master. -> back to chatting

I must have messed up the test in T1921 (aheinecke on Apr 08 2015, 04:36 PM / Roundup). Probably by using a different
sysconfig dir for that test. Apologies for that.

May 11 2015, 3:46 PM · Bug Report, gnupg, dirmngr, S/MIME
werner added projects to T1259: pinentry should show fingerprint if certify a OpenPGP certificate: S/MIME, gnupg.
May 11 2015, 2:12 PM · gnupg, S/MIME, Feature Request
werner removed a project from T1259: pinentry should show fingerprint if certify a OpenPGP certificate: pinentry.
May 11 2015, 2:12 PM · gnupg, S/MIME, Feature Request

May 8 2015

werner closed T1956: adduid from command line option as Resolved.
May 8 2015, 4:11 PM · gnupg, Feature Request
werner set Version to 2.1 on T1956: adduid from command line option.
May 8 2015, 4:11 PM · gnupg, Feature Request
werner added a comment to T1956: adduid from command line option.

Fixed in master with commit 64e809b Will go into 2.1.4.

May 8 2015, 4:11 PM · gnupg, Feature Request
gp_ast added a comment to T1973: Wrong line endings when decrypting to console.

Missed to explain that this does not happen when using gnupg 2.0.* and this occured
on Windows. I did not try this on *nix.

May 8 2015, 3:14 PM · Windows 32, Windows, Bug Report, gnupg
gp_ast added projects to T1973: Wrong line endings when decrypting to console: gnupg, Bug Report.
May 8 2015, 3:02 PM · Windows 32, Windows, Bug Report, gnupg
iromanov added a comment to T1735: No NEED_PASSPHRASE in batch mode.

So maybe there is another correct way to say user that he must type passphrase?
It is need for QCA gnupg plugin. qca-gnupg plugins uses pipes to send/recieve
data with gpg. It was many time ago when I tried to fix problem. So now I can't
remember particularity problem. Seems it was gpg2 related.

I wrote this in my QCA TODO

  • New plugin qca-gpgme to replace current qca-gnupg. qca-gnupg requires to have gpg binary which can be any 1.4.x or 2.x. Them behaviour is different. gpg2 requires gpg-agent to ask user for passphrase. No correct way to check that key requires passphrase.
May 8 2015, 1:03 PM · Bug Report, gnupg
iromanov added a comment to T1735: No NEED_PASSPHRASE in batch mode.

Although the output timing of NEED_PASSPHRASE is different (than your

expectation), it is emitted after gpg reads passphrase string and it needs the
passphrase for signing.

It is nonsense. In this case status is such log file. Such behaviour is no
obviously and documentation says nothing about ths.
And user can't know must or no he provides passphrase.

May 8 2015, 12:52 PM · Bug Report, gnupg
werner added a project to T1972: gpg --search-keys doesn't indicate that results are truncated: gnupg.
May 8 2015, 9:00 AM · Bug Report, dirmngr, gnupg
werner changed Version from git to master on T1971: LDAP: --refresh-keys is not implemented.
May 8 2015, 9:00 AM · Bug Report, dirmngr, gnupg
werner added a project to T1971: LDAP: --refresh-keys is not implemented: gnupg.
May 8 2015, 8:59 AM · Bug Report, dirmngr, gnupg
gniibe added a comment to T1928: regression --passphrase-file ignored in gnupg 2.1.2.

I checked the code and the behavior. It is confirmed that the default of
gpg-agent disables loopback-pinentry mode and user needs to enable it.

Now, we need some fixes/improvements:
(1) gpg should automatically work with gpg-agent with the option of --passphrase
(-file, -fd).
In GnuPG 2.1.x, the secret keys are under control of gpg-agent and gpg frontend
should pass the passphrase to gpg-agent in some way.
When --passphrase (-file, -fd) option is supplied, gpg frontend could use
gpg-agent feature of either loopback-pinentry mode _OR_ preset_passphrase .
The latter requires specific key identification, so, loopback-pinentry mode
would be the solution for general.
(2) Both of loopback-pinentry mode and preset_passphrase are disabled as
default. We need to fix this default of gpg-agent _AND_ we need to fix gpg
frontend error handling of this case of disabled feature of gpg-agent. Well, I
don't know the reason this features need to be disabled...
(3) When it is gpg frontend which invokes gpg-agent, it would be natural to
enable loopback-pinentry (or preset_passphrase). But, there will be existing
gpg-agent even with --batch option. I don't know how it should work in this case.

May 8 2015, 3:34 AM · Bug Report, gnupg, Arch
gniibe added a comment to T1735: No NEED_PASSPHRASE in batch mode.

Thanks for your further experiment. I didn't read well about the part of
'mkfifo' in your first message.
I think that you expect some interactive behavior; gpg emits NEED_PASSPHRASE
when its needed, and your program writes to the fifo.

No, gpg doesn't work like that with --passphrase-file or --passphrase-fd.
gpg will read the passphrase string from a file or an fd at the start.

Although the output timing of NEED_PASSPHRASE is different (than your
expectation), it is emitted after gpg reads passphrase string and it needs the
passphrase for signing.

May 8 2015, 2:54 AM · Bug Report, gnupg

May 7 2015

iromanov added a comment to T1735: No NEED_PASSPHRASE in batch mode.

I just now tested it on my Fedora 20 with gpg 1.4.19 and 2.0.27. I tried to use
--no-use-agent no password request again.

May 7 2015, 1:24 PM · Bug Report, gnupg
perske removed a project from T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm: Feature Request.
May 7 2015, 11:27 AM · Bug Report, gnupg
perske added a project to T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm: Bug Report.
May 7 2015, 11:27 AM · Bug Report, gnupg
perske added a comment to T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm.

Background information:

With GnuPG 2.1, my webmailer does no longer work.

In principle, I use the following procedure e. g. for signing an e-mail:

  1. My GnuPG 2.0 is compiled with the option

--with-pinentry-pgm=/path/to/pinentrywrapper

  1. The user enters text and passphrase into the HTML form.
  1. I encrypt the passphrase with symmetric cryptography
  1. I set the environment variable PINENTRY_USER_DATA to the encrypted password

(see also T799)

  1. I set the environment variable GPG_TTY to "PINENTRY/pinentry-permail"
  1. I also set the environment variables HOME and GNUPGHOME.
  1. I launch /path/to/gpg-agent --daemon --sh --no-allow-mark-trusted
  1. I parse the output GPG_AGENT_INFO=/path/to/socket:process_number:version_number
  1. Then I sign, encrypt, decrypt, verify or whatever the user wants by
    • putting GPG_AGENT_INFO and all other needed variables into the environment
    • starting /path/to/gpgsm with all needed options for the respective transaction
  1. Then gpgsm contacts the just started gpg-agent which calls my

/path/to/pinentrywrapper which detects the "magic" GPG_TTY setting and does not
try to start a dialog on the (non-existent) terminal or desktop, but simply
responds with the decrypted content of PINENTRY_USER_DATA whenever a passphrase
input is requested.

  1. Finally I kill the gpg-agent using the process_number extracted above.

This procedure does no longer work with GnuPG 2.1 because I cannot start a new
agent for every transaction: gpg-agent of 2.1 uses the default socket, not a new
one, and does not write its process_number into GPG_AGENT_INFO, and, most
important, gpgsm disregards GPG_AGENT_INFO so that I cannot tell gpgsm which
running gpg-agent to contact. (There can be multiple transactions at the same
time; I trust in gpg-agent to properly lock files where necessary.)

As long as there is no way of passing the entered passphrase from my webmailer
to gpg-agent in any other way than by writing it into the environment when
starting gpg-agent and using a special pinentry that reads this environment, I
have to start a new gpg-agent for every transaction because different
transactions may need different passphrases.

That, of course, is only an ugly, ugly circumvention of a limitation of gpgsm.

gpg2 knows options --pinentry-mode loopback --passphrase-fd file_number, and
gpg-agent offers all support for using these options. Only gpgsm does not
support it.

If gpgsm would also offer these options, the whole hack with a magic GPG_TTY,
with the encrypted PINENTRY_USER_DATA, with using a pinentry wrapper, and with
using special options when compiling GnuPG 2.0 would be completely unnecessary.

So please please please copy the code that implements --pinentry-mode loopback
--passphrase-fd file_number from gpg2 to gpgsm.

Thank you very much!

May 7 2015, 11:27 AM · Bug Report, gnupg
exi added a comment to T1928: regression --passphrase-file ignored in gnupg 2.1.2.

It seems that the gpg-agent needs to be started with --allow-loopback-pinentry
for this to work.
Because I let gpg autostart the daemon for me, this does not get passed to
gpg-agent and therefore does not work when setting --pinentry-mode=loopback in gpg.

I don't know what is to do here.
Should gpg with --pinentry-mode=loopback autostart the gpg-agent with
--allow-loopback-pinentry ?
Or should I just add some documentation to the manpages to describe what is
necessary for --pinentry-mode=loopback and --passphrase-file to work?

May 7 2015, 10:51 AM · Bug Report, gnupg, Arch
gniibe added a comment to T1735: No NEED_PASSPHRASE in batch mode.

It doesn't reproducible for me with 2.0.26 in Debian.
For 1.4, you need --no-use-agent when you have use-agent option in your
configuration.

May 7 2015, 7:34 AM · Bug Report, gnupg
gniibe claimed T1735: No NEED_PASSPHRASE in batch mode.
May 7 2015, 7:34 AM · Bug Report, gnupg
gniibe claimed T1928: regression --passphrase-file ignored in gnupg 2.1.2.
May 7 2015, 5:14 AM · Bug Report, gnupg, Arch
gniibe added a comment to T1928: regression --passphrase-file ignored in gnupg 2.1.2.

It seems that your gpg-agent doesn't support loopback mode.
Either, your gpg-agent is from 2.0 or the socket is hijacked by gnome-keyring.
For the latter, please see http://wiki.gnupg.org/GnomeKeyring

May 7 2015, 5:14 AM · Bug Report, gnupg, Arch
gniibe claimed T1099: gnupg2 fails to handle multiple card readers.
May 7 2015, 4:59 AM · gnupg, Not A Bug, Bug Report
gniibe closed T1099: gnupg2 fails to handle multiple card readers as Resolved.
May 7 2015, 4:59 AM · gnupg, Not A Bug, Bug Report
gniibe added a project to T1099: gnupg2 fails to handle multiple card readers: gnupg.
May 7 2015, 4:59 AM · gnupg, Not A Bug, Bug Report
gniibe added a comment to T1099: gnupg2 fails to handle multiple card readers.

It can be specified by scdaemon's option. Now in 2.0.x and 2.1.x, it does
partial match for PC/SC.
So, this issue is now closed.

May 7 2015, 4:59 AM · gnupg, Not A Bug, Bug Report
gniibe closed T1311: Pinentry shows on incorrect terminal as Resolved.
May 7 2015, 4:54 AM · gnupg, gpgagent, Bug Report, Duplicate
gniibe added a comment to T1311: Pinentry shows on incorrect terminal.

It's fixed in 2.0.18 (as the T1203 was closed).

May 7 2015, 4:54 AM · gnupg, gpgagent, Bug Report, Duplicate
gniibe added a comment to T1402: [PATCH] gpg-protect-tool doesn't pass DISPLAY to agent.

Confirmed that this is fixed in GnuPG in 2.0.25. In the external reference (the
bugzilla at RedHat), it's also closed already.
In the SCM (http://pkgs.fedoraproject.org/cgit/gnupg2.git), it's
1f6281e091d124170238821e7b9150ab56ff1195 which
removed the patch.

May 7 2015, 4:20 AM · Fedora, Bug Report, gnupg
gniibe closed T1402: [PATCH] gpg-protect-tool doesn't pass DISPLAY to agent as Resolved.
May 7 2015, 4:20 AM · Fedora, Bug Report, gnupg

May 6 2015

perske set Version to 2.1.3 on T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm.
May 6 2015, 8:28 PM · Bug Report, gnupg
perske added projects to T1970: Implement --pinentry-mode loopback --passphrase-fd 9 also for gpgsm: Feature Request, gnupg.
May 6 2015, 8:28 PM · Bug Report, gnupg
werner added a project to T1969: gpg-agent stops working after OSX Upgrade to Yosemite: Won't Fix.
May 6 2015, 9:37 AM · patch, Bug Report, gpgagent, gnupg, gnupg (gpg20), Won't Fix, MacOS
werner added a comment to T1969: gpg-agent stops working after OSX Upgrade to Yosemite.

The patch is a work for problem somewhere in the PC/SC implementaion. I am also
not sure whether a pthread_cancel for a buggy PC/SC library is a good idea.
Terminating the process seems to be a better solution.

If gpgtools wants to apply this pacth, they might of course do so but I don't
want to apply it upstream in particular not to an older version (2.1 is current).

May 6 2015, 9:37 AM · patch, Bug Report, gpgagent, gnupg, gnupg (gpg20), Won't Fix, MacOS

May 5 2015

elosery added a comment to T1963: ldap keyserver communication error.

Hi Werner,

I am running Fedora 20 and here is some information regarding the the installed
packages

Name : gnupg
Arch : x86_64
Version : 1.4.19
Release : 2.fc20

Name : openldap
Arch : x86_64
Version : 2.4.39
Release : 4.fc20

I didn't compile any of them from source. I downgraded gnupg but for some reason
it went to 1.4.15

Name : gnupg
Arch : x86_64
Version : 1.4.15
Release : 1.fc20

This version works without a problem. Then upgrading again causes the problem to
come back.

Regarding the ldap setup, I followed the approach given in

http://justinmattock.blogspot.com/2013/03/openldap-gpg-keyserver-private.html

Please let me know if you need any further information.

Thanks

May 5 2015, 4:24 AM · Fedora, gnupg (gpg14), Bug Report, gnupg

May 4 2015

ahin added projects to T1969: gpg-agent stops working after OSX Upgrade to Yosemite: MacOS, gnupg (gpg20), gnupg, gpgagent, Bug Report, patch.
May 4 2015, 1:21 PM · patch, Bug Report, gpgagent, gnupg, gnupg (gpg20), Won't Fix, MacOS
werner added a comment to T1968: Bad signatures prevent user from signing a key.

Note that when using the --export option you are asked whether you want to add
another signature. This can be used as a workaround until the problem has been
fixed.

May 4 2015, 12:30 PM · Bug Report, gnupg
werner claimed T1968: Bad signatures prevent user from signing a key.
May 4 2015, 12:21 PM · Bug Report, gnupg
werner added a comment to T1963: ldap keyserver communication error.

We need a bit more information. What OS, how has 1.4.19 been build (attach
config.h) and what LDAP server you are using. Can you replicate the same after
downgrading to 1.4.18?

May 4 2015, 8:25 AM · Fedora, gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

I changed that to a feature but I agree that the subkey selection mechanism
should take smartcards into account.

It would be surpising that suddendly a different subkey will be used for signing
if a smartcard is not available. Right, most users with several subkeys are
experts and know what they are going but nevertheless this is a change in behaviour.

May 4 2015, 8:23 AM · gnupg (gpg22), Feature Request
werner added a project to T1967: GnuPG should select a key for signing without trying to use missing subkeys: Feature Request.
May 4 2015, 8:23 AM · gnupg (gpg22), Feature Request
werner removed a project from T1967: GnuPG should select a key for signing without trying to use missing subkeys: Bug Report.
May 4 2015, 8:23 AM · gnupg (gpg22), Feature Request

May 3 2015

diafygi added projects to T1968: Bad signatures prevent user from signing a key: gnupg, Bug Report.
May 3 2015, 12:42 AM · Bug Report, gnupg

May 2 2015

dkg set Version to 2.1.3 on T1967: GnuPG should select a key for signing without trying to use missing subkeys.
May 2 2015, 4:36 AM · gnupg (gpg22), Feature Request
dkg added projects to T1967: GnuPG should select a key for signing without trying to use missing subkeys: gnupg, Bug Report.
May 2 2015, 4:36 AM · gnupg (gpg22), Feature Request