Page MenuHome GnuPG
Feed Advanced Search

Aug 20 2016

bsiegert set External Link to https://mail-index.netbsd.org/pkgsrc-users/2016/08/15/msg023624.html on T2445: gpgscm needs to link against libintl on Mac OS.
Aug 20 2016, 6:01 PM · Bug Report, gnupg
bsiegert set Version to 2.1.14 on T2445: gpgscm needs to link against libintl on Mac OS.
Aug 20 2016, 6:01 PM · Bug Report, gnupg
bsiegert added projects to T2445: gpgscm needs to link against libintl on Mac OS: gnupg, Bug Report.
Aug 20 2016, 6:01 PM · Bug Report, gnupg

Aug 18 2016

werner added a comment to T2443: gpg2 --use-agent gives "gpg: decryption failed: No secret key".

--use-agent is a dummy option in GnUPG 2.1 - it has no effect.

Aug 18 2016, 11:15 PM · Bug Report, gnupg
werner added a comment to T2238: When generating a DSA or Elgamal key with --expert GPG claims that keys smaller than 1024 bits are supported when they are not..

1.4 has been released - waiting for 2.0

Aug 18 2016, 11:13 PM · gnupg (gpg20), Unreleased, gnupg (gpg14), Bug Report, gnupg
werner removed a project from T2246: Regression: home dir no longer automatically created: Unreleased.
Aug 18 2016, 11:10 PM · Bug Report, gnupg
werner removed a project from T2437: please document forward-compatible expectations for machine-readable formats: Unreleased.
Aug 18 2016, 11:09 PM · gnupg, Feature Request
werner removed a project from T2442: homedir: Libgcrypt warning: missing initialization: Unreleased.
Aug 18 2016, 11:08 PM · Bug Report, gnupg
werner added a project to T2389: segfault after importing key, corrupting trustdb: Restricted Project.
Aug 18 2016, 11:08 PM · gnupg, MacOS, Bug Report
cri added a comment to T2389: segfault after importing key, corrupting trustdb.

I used your workaround and haven't been running into problems since. Unfortunately, I
don't currently have the time at hand to give it a thorough test run. If I do, I will
keep you updated.

Aug 18 2016, 6:21 PM · gnupg, MacOS, Bug Report
tuxick added a comment to T2443: gpg2 --use-agent gives "gpg: decryption failed: No secret key".

gpg2 --use-agent --decrypt encrypted.asc
...
gpg: decryption failed: No secret key
FAIL

--use-agent --decrypt encrypted.asc
..
You need a passphrase to unlock the secret key for
...SUCCESS

This for example makes enigmail fail, and to make things worse: enigmail refuses
to work with gpg1

Using:
gpg (GnuPG) 2.1.11
libgcrypt 1.6.5
on Ubuntu 16.04.1 LTS

I have multiple keys in .gnupg, this might be triggering the problem.

Aug 18 2016, 2:24 PM · Bug Report, gnupg
tuxick added projects to T2443: gpg2 --use-agent gives "gpg: decryption failed: No secret key": gnupg, Bug Report.
Aug 18 2016, 2:13 PM · Bug Report, gnupg
werner assigned T2270: gpg caches bad symmetric passwords to neal.
Aug 18 2016, 1:01 PM · Bug Report, gnupg
werner assigned T2054: All of max-cache-ttl, default-cache-ttl, and no-allow-external-cache are ignored to neal.
Aug 18 2016, 12:59 PM · Bug Report, gnupg
werner closed T2066: Wrong BLOB Type/keytable.c:150 as Resolved.
Aug 18 2016, 12:58 PM · Not A Bug, gnupg, Bug Report, gpg4win
werner added a project to T2066: Wrong BLOB Type/keytable.c:150: Not A Bug.
Aug 18 2016, 12:58 PM · Not A Bug, gnupg, Bug Report, gpg4win
werner added a comment to T2066: Wrong BLOB Type/keytable.c:150.

Indeed; this look like a corrupted file. Please restrore from abckup.

Aug 18 2016, 12:58 PM · Not A Bug, gnupg, Bug Report, gpg4win
werner renamed T2024: "Unknown IPC command" in many situations (gpg4win/gnupg conflict?) from "Unknown IPC command" in many situations to "Unknown IPC command" in many situations (gpg4win/gnupg conflict?).
Aug 18 2016, 12:56 PM · Windows 32, Windows, Bug Report, gnupg
werner closed T2080: no status output when trying to sign data with revoked private key as Resolved.
Aug 18 2016, 12:54 PM · Won't Fix, Bug Report, gnupg, gnupg (gpg14)
werner added a project to T2080: no status output when trying to sign data with revoked private key: Won't Fix.
Aug 18 2016, 12:54 PM · Won't Fix, Bug Report, gnupg, gnupg (gpg14)
werner closed T2225: gpg2 send keys failed ,because 'invalid argument'.And why? as Resolved.
Aug 18 2016, 12:53 PM · Bug Report, gnupg, Info Needed
werner added a comment to T2390: gpg-agent not expiring passphrase.

ping

Aug 18 2016, 12:52 PM · Info Needed, Bug Report, gnupg
werner added a project to T2390: gpg-agent not expiring passphrase: Info Needed.
Aug 18 2016, 12:52 PM · Info Needed, Bug Report, gnupg
werner added a project to T2400: GnuPG 2.1 regression in unattended key generation: gnupg (gpg22).
Aug 18 2016, 12:51 PM · gnupg (gpg22), Bug Report, gnupg
werner added a comment to T2389: segfault after importing key, corrupting trustdb.

Could you verify that the problem has been solved (in 2.1.14)?

Aug 18 2016, 12:49 PM · gnupg, MacOS, Bug Report
werner set Version to 2.0.22 on T2354: Deleted secure key not quite deleted?.
Aug 18 2016, 12:47 PM · gnupg, Bug Report
werner added a comment to T2437: please document forward-compatible expectations for machine-readable formats.

Done with commit d25db3c for 2.1.15

Aug 18 2016, 12:46 PM · gnupg, Feature Request
werner closed T2437: please document forward-compatible expectations for machine-readable formats as Resolved.
Aug 18 2016, 12:46 PM · gnupg, Feature Request
werner added a project to T2437: please document forward-compatible expectations for machine-readable formats: Unreleased.
Aug 18 2016, 12:46 PM · gnupg, Feature Request
werner closed T2442: homedir: Libgcrypt warning: missing initialization as Resolved.
Aug 18 2016, 12:33 PM · Bug Report, gnupg
werner added a project to T2442: homedir: Libgcrypt warning: missing initialization: Unreleased.
Aug 18 2016, 12:33 PM · Bug Report, gnupg
werner added a comment to T2442: homedir: Libgcrypt warning: missing initialization.

Already fixed in the repo. It is only a warning and harmless in this case.
Thanks.

Aug 18 2016, 12:33 PM · Bug Report, gnupg
nfnty set Version to 2.1.13 on T2442: homedir: Libgcrypt warning: missing initialization.
Aug 18 2016, 12:49 AM · Bug Report, gnupg
nfnty added projects to T2442: homedir: Libgcrypt warning: missing initialization: gnupg, Bug Report.
Aug 18 2016, 12:49 AM · Bug Report, gnupg

Aug 16 2016

werner added a project to T2441: Issue during decrypting - Secret Key not found: Support.
Aug 16 2016, 7:35 PM · gnupg, Support
werner lowered the priority of T2441: Issue during decrypting - Secret Key not found from Unbreak Now! to Normal.
Aug 16 2016, 7:35 PM · gnupg, Support
werner closed T2441: Issue during decrypting - Secret Key not found as Invalid.
Aug 16 2016, 7:35 PM · gnupg, Support
werner removed a project from T2441: Issue during decrypting - Secret Key not found: Bug Report.
Aug 16 2016, 7:35 PM · gnupg, Support
werner added a comment to T2441: Issue during decrypting - Secret Key not found.

This seems to be a general question on how to use the software. Please read the
HOWTOS at gnupg.org and if you still have questions ask at the gnupg-users
mailing list.

Aug 16 2016, 7:35 PM · gnupg, Support
shweta_hari set Version to 2.0.30 on T2441: Issue during decrypting - Secret Key not found.
Aug 16 2016, 10:30 AM · gnupg, Support
shweta_hari added projects to T2441: Issue during decrypting - Secret Key not found: gnupg, Bug Report.
Aug 16 2016, 10:30 AM · gnupg, Support
nwf added a comment to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.

Yeah, at the moment I shoot scdaemon with SIGTERM whenever I need to use the PIV
app, which is rare, and have carefully avoided any kind of automated invocation
of the smartcard through scdaemon (e.g. my statusbar polls via ykinfo directly,
rather than invoking gpg --card-status.)

I know essentially nothing about smart cards or PC/SC's design, but what goes
wrong holding the card open shared rather than exclusively? Can other shared
lock holders do drastic things like insert or remove keys, causing scdaemon's
cache to become stale? I would have (naively) guessed that shared holders could
only do things like cryptographic operations which won't pose an issue to
scdaemon's cache. (Admittedly, cryptography is not side-effect free; counters
get incremented, random numbers get generated, but none of that is the kind of
thing that scdaemon caches, right?)

Thanks for thinking about this. :)

Aug 16 2016, 3:36 AM · scd, Feature Request, gnupg
gniibe added a comment to T1756: gpg-agent doesn't accept ssh certificates.

FYI.

https://lists.gnupg.org/pipermail/gnupg-devel/2016-August/031479.html
^-- In this experiment, I tried another half of supporting OpenSSH certificates.

I found that it doesn't work as I had thought.

I think that the lower level support of gpg-agent is ready to add this feature
of accepting OpenSSH certificates, but modification of OpenSSH will be required
too, so that it works well.

Currently, the OpenSSH certificate file itself is still needed even if ssh-agent
supports OpenSSH certificates. When it returns a certificate to ssh client, ssh
client only uses the information of the key in the certificate. It is the file
which ssh client uses communicating to the server.

Aug 16 2016, 2:41 AM · gnupg, Feature Request
gniibe claimed T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.
Aug 16 2016, 2:29 AM · scd, Feature Request, gnupg
gniibe added a project to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't: gnupg.
Aug 16 2016, 2:29 AM · scd, Feature Request, gnupg
gniibe added a comment to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.

Scdaemon grabs the device after its first use; it gets information on the
card/token and it operates (sign/decrypt) based on those information. If it
releases the device, it should get the info.
Current design of scdaemon is state-full: it caches the information on the card
so that operations can be soon done.
more state-less design could be possible, with the cost of each operation will
be heavy (by getting information each time).

I don't know the PIV app of Yubikey, but, in most cases, such an app can be
written stopping scdaemon beforehand (by a line of gpgconf --reload scdaemon, if
it's a script). It's a simple workaround for now.

Aug 16 2016, 2:29 AM · scd, Feature Request, gnupg

Aug 12 2016

werner removed a project from T2359: Query which key will be used for a given mailbox: gnupg (gpg21).
Aug 12 2016, 11:16 AM · gnupg (gpg22), gnupg, Feature Request
werner added a project to T2359: Query which key will be used for a given mailbox: gnupg (gpg22).
Aug 12 2016, 11:16 AM · gnupg (gpg22), gnupg, Feature Request

Aug 11 2016

justus closed T2408: implicit declaration of function ‘gpg_err_set_errno’ in common/w32-afunix.c:65 as Resolved.
Aug 11 2016, 1:49 PM · Bug Report, gnupg
justus added a comment to T2408: implicit declaration of function ‘gpg_err_set_errno’ in common/w32-afunix.c:65.

Fixed in 72fa314b.

Aug 11 2016, 1:49 PM · Bug Report, gnupg
justus claimed T2408: implicit declaration of function ‘gpg_err_set_errno’ in common/w32-afunix.c:65.
Aug 11 2016, 9:56 AM · Bug Report, gnupg

Aug 10 2016

justus added a comment to T2417: gnupg doesn't like empty trustdb file.

Actually, I'd argue that tdbio_set_dbname did not handle this case correctly. In
any case, if you must create some temporary gnupghomes, deleting the whole
directory might be both easier and more robust.

Fixed in a27410a2.

Aug 10 2016, 4:54 PM · gnupg, Bug Report
justus closed T2417: gnupg doesn't like empty trustdb file as Resolved.
Aug 10 2016, 4:54 PM · gnupg, Bug Report

Aug 6 2016

dkg added projects to T2437: please document forward-compatible expectations for machine-readable formats: Feature Request, gnupg.
Aug 6 2016, 6:20 PM · gnupg, Feature Request
dkg set Version to 2.1.14 on T2437: please document forward-compatible expectations for machine-readable formats.
Aug 6 2016, 6:20 PM · gnupg, Feature Request

Aug 5 2016

werner added projects to T2427: Allow universal --batch more, with STDIN reads: Not A Bug, Won't Fix.
Aug 5 2016, 7:55 PM · Won't Fix, Not A Bug, Bug Report, gnupg
werner added a comment to T2427: Allow universal --batch more, with STDIN reads.

I explained this already on the mailing list: gpg takes data from stdin but
sometimes need to ask on the tty for a passphrase or confirmation. If you do
not want this use --batch and --with-colons.

The --edit-key interface cannot be operated via stdin because this is a human
only interface. To automate --edit-key you need to use --status-fd and
--command-fd and apply an FSM for processing. This is required to keep the API
stable and to allow extending the --edit-key interface.

GnuPG 2.1 also has a bunch of new commands (--quick-foo) which can be used to do
the most common operations directly from the command line.

Aug 5 2016, 7:55 PM · Won't Fix, Not A Bug, Bug Report, gnupg
werner added a comment to T2436: --yes sometimes doesn't work without --batch, but this is not well-documented.

Well, the man page states

  --yes  Assume "yes" on most questions.

Note the "most" ;-)

I agree that there is no clear pattern. I tried to make use of --yes in way to
minimizes surprising loss of data. Can certainly be improved.

Aug 5 2016, 7:47 PM · Bug Report, gnupg
justus added projects to T2259: --key-gen failing on Solaris 10: gnupg (gpg14), gnupg.
Aug 5 2016, 9:01 AM · gnupg, gnupg (gpg14), Bug Report
justus added a project to T2354: Deleted secure key not quite deleted?: gnupg.
Aug 5 2016, 9:00 AM · gnupg, Bug Report
justus added a project to T2417: gnupg doesn't like empty trustdb file: gnupg.
Aug 5 2016, 8:59 AM · gnupg, Bug Report
dkg added projects to T2436: --yes sometimes doesn't work without --batch, but this is not well-documented: gnupg, Bug Report.
Aug 5 2016, 6:30 AM · Bug Report, gnupg

Aug 4 2016

justus added a comment to T2425: 2.1.14 intermittent `make check` failure on gpgtar.scm.

Can you please tell us what version of ssh you are using (ssh -V)?

Aug 4 2016, 11:58 AM · MacOS, gnupg, Bug Report, gnupg (gpg22)

Aug 3 2016

aheinecke added a comment to T2359: Query which key will be used for a given mailbox.

To piggyback something on this issue.

To quote T2359 (aheinecke on May 17 2016, 11:59 AM / Roundup):

e.g. an API to check which key: gpg -er aheinecke@intevation.de

I did not have groups on the radar for this. If a recipient is a group then
gnupg would use multiple keys in this command.

I think locate-keys would be a great mechanism to support this easily in MUAs.
When we change it that for a given mailbox only the single most valid Key is
returned we could also have the semantic that if then multiple Keys are returned
we have a group.

Aug 3 2016, 12:29 PM · gnupg (gpg22), gnupg, Feature Request

Aug 2 2016

werner added a comment to T2423: configure: error: Sorry, the current implemenation requires mmap. due to empty CFLAGS (missing -fPIC).

Please describe the bug and your patch here. A long title is not a sufficient
description. tia.

Aug 2 2016, 7:04 PM · gnupg (gpg22), Bug Report, gnupg
justus added a comment to T767: gpg2 ignores gpgme_set_passphrase_cb.

https://pagure.io/pygpgme/c/6648b075fb3d434c599d7e1793bd1f0bbe85dfe3?branch=master says:

T767 indicates that

gpgme_set_passphrase_cb is a deprecated corner of the API and that
developers using gpgme should really rely on the gpg-agent to handle
this stuff.

That is not correct. gpgme_set_passphrase_cb is not deprecated, and gpg21 does honor the flag.
In fact, allow-loopback-pinentry is the default since GnuPG 2.1.12.

Aug 2 2016, 6:28 PM · gnupg
justus claimed T767: gpg2 ignores gpgme_set_passphrase_cb.
Aug 2 2016, 6:28 PM · gnupg
aheinecke added projects to T2435: gpgsm combined sign and encrypt: Feature Request, kleopatra, gnupg.
Aug 2 2016, 3:57 PM · gnupg, kleopatra, Feature Request
aixtools added a comment to T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org.

Aug 2 2016, 8:57 AM · gnupg, Bug Report
aixtools added a comment to T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org.

Will be a week or so. Had to power off my server due to "flooding" nearby.

Aug 2 2016, 8:57 AM · gnupg, Bug Report

Aug 1 2016

justus added a comment to T2432: gpgsm --with-colons --list-keys writes an excessive colon, causing --with-secret to write to the wrong column.

Indeed, thanks for the analysis!

Fixed in 40365b28.

Aug 1 2016, 12:36 PM · Bug Report, gnupg
justus closed T2432: gpgsm --with-colons --list-keys writes an excessive colon, causing --with-secret to write to the wrong column as Resolved.
Aug 1 2016, 12:36 PM · Bug Report, gnupg
justus claimed T2432: gpgsm --with-colons --list-keys writes an excessive colon, causing --with-secret to write to the wrong column.
Aug 1 2016, 12:36 PM · Bug Report, gnupg
justus claimed T2431: tests/openpgp/run-test.scm not shipped in tarball.
Aug 1 2016, 11:20 AM · Bug Report, gnupg
justus closed T2431: tests/openpgp/run-test.scm not shipped in tarball as Resolved.
Aug 1 2016, 11:20 AM · Bug Report, gnupg
justus added a comment to T2431: tests/openpgp/run-test.scm not shipped in tarball.

Fixed in c971ff08.

Aug 1 2016, 11:20 AM · Bug Report, gnupg
bernhard updated subscribers of T2118: Command --quick-gen-key ignores --default-cert-expire, --edit-key ignores --default-sig-expire.
Aug 1 2016, 10:22 AM · Won't Fix, gnupg (gpg21), Bug Report, gnupg
perske added projects to T2432: gpgsm --with-colons --list-keys writes an excessive colon, causing --with-secret to write to the wrong column: gnupg, Bug Report.
Aug 1 2016, 1:57 AM · Bug Report, gnupg
perske set Version to 2.1.14 on T2432: gpgsm --with-colons --list-keys writes an excessive colon, causing --with-secret to write to the wrong column.
Aug 1 2016, 1:57 AM · Bug Report, gnupg

Jul 31 2016

perske added a comment to T1644: Do not expect KeyIDs to be unique.

D198: 866_gnupg-2.1.14.diff

Jul 31 2016, 10:00 PM · gnupg (gpg22), S/MIME, Bug Report
perske added a comment to T1644: Do not expect KeyIDs to be unique.

With T1590 irrelevant, issues 1862, 1970, and 2336 resolved (very special
thanks to everyone who helped in fixing them!), this is the only problem left in
version 2.1.14 that forces me to use a patched version of gpgsm for my webmailer.

My patch from 2014-04-30 works, but by mistake ("if (cmp < 0)" in place of "if
(cmp > 0)" it selects not the newest but the oldest one of the ambiguous
certificates what is bad in the DFN PKI because an older one of the certificates
is revoked, so I attach a new patch against 2.1.14.

Jul 31 2016, 10:00 PM · gnupg (gpg22), S/MIME, Bug Report

Jul 30 2016

dkg set Version to 2.1.14 on T2431: tests/openpgp/run-test.scm not shipped in tarball.
Jul 30 2016, 7:24 PM · Bug Report, gnupg
dkg added projects to T2431: tests/openpgp/run-test.scm not shipped in tarball: gnupg, Bug Report.
Jul 30 2016, 7:24 PM · Bug Report, gnupg

Jul 29 2016

languitar added a comment to T2298: Unblocking a smartcard PIN not possible in 2.1.

Ok, I can record such files. Will there be any confidential information contained in
these logs?

Jul 29 2016, 8:24 PM · Info Needed, gnupg, scd, Bug Report
gniibe added a project to T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org: Restricted Project.
Jul 29 2016, 9:56 AM · gnupg, Bug Report
gniibe removed a project from T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org: Info Needed.
Jul 29 2016, 9:56 AM · gnupg, Bug Report
gniibe claimed T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org.
Jul 29 2016, 9:56 AM · gnupg, Bug Report
gniibe added a comment to T1779: AIX & GCC 4.7.4: 27 of 30 tests failed Please report to http://bugs.gnupg.org.

AIX required a patch for Npth library for fork.
Please test again with npth 1.3 when it will be released.
I tested with 2.1.14, all go well successfully (make check no errors) with
patched version of Npth library.

Jul 29 2016, 9:56 AM · gnupg, Bug Report
gniibe removed a project from T2403: make check failed for t-stringhelp (AIX 7.1): Info Needed.
Jul 29 2016, 9:51 AM · Bug Report, gnupg
gniibe added a project to T2403: make check failed for t-stringhelp (AIX 7.1): Restricted Project.
Jul 29 2016, 9:51 AM · Bug Report, gnupg
gniibe added a comment to T2403: make check failed for t-stringhelp (AIX 7.1).

I confirmed that with patched npth, 2.1.14 with
c49c43d7e4229fd9f1bc55e17fa32fdc334dbef6 builds well and "make check" goes
successfully (on AIX 7.1 with gcc 4.8.1).

Please test again when npth 1.3 will be released.

Jul 29 2016, 9:51 AM · Bug Report, gnupg
gniibe added a comment to T2298: Unblocking a smartcard PIN not possible in 2.1.

You can have a configuration file like:

.gnupg/gpg-agent.conf

enable-ssh-support
debug-level guru
debug-all

log-file /run/user/1000/gpg-agent.log

and

.gnupg/scdaemon.conf

debug-level guru
debug-all
debug-ccid-driver

log-file /run/user/1000/scd.log

so that the interactions can be recorded with debug information.

Jul 29 2016, 2:53 AM · Info Needed, gnupg, scd, Bug Report

Jul 28 2016

JohnDB added a comment to T2427: Allow universal --batch more, with STDIN reads.

An option like --stdout-as-tty may also be needed,
for completeness, to avoid /dev/tty writes.

Jul 28 2016, 1:28 AM · Won't Fix, Not A Bug, Bug Report, gnupg

Jul 27 2016

JohnDB added projects to T2427: Allow universal --batch more, with STDIN reads: gnupg, Bug Report.
Jul 27 2016, 9:20 PM · Won't Fix, Not A Bug, Bug Report, gnupg
justus added a comment to T2401: import-clean and export-clean do not have the documented effect.

import-clean does call the same code, but it behaves differently for the key you
mention. I created a test key that does get cleaned up upon import.

Jul 27 2016, 4:22 PM · Bug Report, gnupg
justus changed Version from 2.1.13 to 2.1.13,master on T2401: import-clean and export-clean do not have the documented effect.
Jul 27 2016, 4:22 PM · Bug Report, gnupg
justus added a comment to T2401: import-clean and export-clean do not have the documented effect.

Jul 27 2016, 4:22 PM · Bug Report, gnupg
justus closed T2418: Wrong check for Android in configure.ac as Resolved.
Jul 27 2016, 12:40 PM · Bug Report, gnupg
justus added a comment to T2418: Wrong check for Android in configure.ac.

Merged in 583a464c, thanks!

Note that we prefer contributions sent to the mailinglist using git send-email.

Jul 27 2016, 12:40 PM · Bug Report, gnupg
justus claimed T2418: Wrong check for Android in configure.ac.
Jul 27 2016, 12:40 PM · Bug Report, gnupg