Page MenuHome GnuPG
Feed Advanced Search

Sep 30 2016

justus added a comment to T1338: Windows ldap_start_tls_sA has more parameters than used in keyserver/gpgkeys_ldap.c.

Fixed in 8d370180.

Sep 30 2016, 11:03 AM · gnupg, Feature Request
justus closed T1338: Windows ldap_start_tls_sA has more parameters than used in keyserver/gpgkeys_ldap.c as Resolved.
Sep 30 2016, 11:03 AM · gnupg, Feature Request
justus claimed T1338: Windows ldap_start_tls_sA has more parameters than used in keyserver/gpgkeys_ldap.c.
Sep 30 2016, 10:10 AM · gnupg, Feature Request

Sep 28 2016

werner removed a project from T1089: Please store requests in a cache to avoid sending out duplicate requests (mailto: interface): gnupg (gpg21).
Sep 28 2016, 9:55 AM · gnupg (gpg23), gnupg, Debian, Feature Request
werner removed Version on T1089: Please store requests in a cache to avoid sending out duplicate requests (mailto: interface).
Sep 28 2016, 9:55 AM · gnupg (gpg23), gnupg, Debian, Feature Request
werner added a project to T1089: Please store requests in a cache to avoid sending out duplicate requests (mailto: interface): gnupg (gpg23).
Sep 28 2016, 9:55 AM · gnupg (gpg23), gnupg, Debian, Feature Request
werner added a comment to T1089: Please store requests in a cache to avoid sending out duplicate requests (mailto: interface).

There are a couple of ideas on how to use mail for key retrieval. We won't be
able to implement them for 2.2 but we should consider this for 2.3.

There won't be any changes for 1.4, though.

Sep 28 2016, 9:55 AM · gnupg (gpg23), gnupg, Debian, Feature Request
werner added a comment to T2700: Clean up the command line interface (avoid abbreviated --long-options, consistency).

Please do that as soon as you have some spare time. Take care not to chnage
translated strings.

Sep 28 2016, 9:36 AM · gnupg, Feature Request, gnupg (gpg22)
werner raised the priority of T2701: Do not let users create keys without an expiration date from Wishlist to Normal.
Sep 28 2016, 9:35 AM · Feature Request, gnupg (gpg22)
werner added a comment to T2701: Do not let users create keys without an expiration date.

By renew you mean prolonging the expiration time?

To add this new default we should first add a --quick-set-expire command to make
it easier to change the expiration time. Or --quick-expire to match the name
used in --edit-key - I don't care. And of course gpgme needs a new API.

Sep 28 2016, 9:35 AM · Feature Request, gnupg (gpg22)
werner updated subscribers of T2359: Query which key will be used for a given mailbox.
Sep 28 2016, 9:29 AM · gnupg (gpg22), gnupg, Feature Request
werner added a comment to T2359: Query which key will be used for a given mailbox.

According to T1143 (aheinecke on Jun 08 2016, 07:15 PM / Roundup) the plan is that locate-key as well as -r uses a new
mechanism to figure oiut the appropriate key. aheinecke already implemented
this strategy in Kmail but we want to have it in gnupg proper.

If the given key is specified by a mail address the new scheme kicks in for
--locate-key and all keys given with -r. gpg finds all matching non-expired and
suitable keys and then computes the validity (WoT, TOFU, whatever). That is
list ordered and the top ranked key is used. Newer keys/subkeys are preferred
and thus in general there should never be an ambiguity. In case there is an
ambiguity, -r should return an error and --locate-key should return all those keys.

Sep 28 2016, 9:29 AM · gnupg (gpg22), gnupg, Feature Request
werner reassigned T2359: Query which key will be used for a given mailbox from werner to justus.
Sep 28 2016, 9:29 AM · gnupg (gpg22), gnupg, Feature Request
werner added a comment to T2359: Query which key will be used for a given mailbox.

This bug supersedes T1143 and T1232.

Sep 28 2016, 9:21 AM · gnupg (gpg22), gnupg, Feature Request
werner added a comment to T1143: better heuristic for choosing an encryption key based on a User ID.

Duplicate of T2359

Sep 28 2016, 9:17 AM · Duplicate, gnupg, Feature Request
werner closed T1143: better heuristic for choosing an encryption key based on a User ID as Resolved.
Sep 28 2016, 9:17 AM · Duplicate, gnupg, Feature Request
werner added a project to T1143: better heuristic for choosing an encryption key based on a User ID: Duplicate.
Sep 28 2016, 9:17 AM · Duplicate, gnupg, Feature Request

Sep 27 2016

werner removed a project from T2226: Add sha-256 checksums to swdb.lst: In Progress.
Sep 27 2016, 11:51 AM · gnupg, Feature Request
werner closed T2226: Add sha-256 checksums to swdb.lst as Resolved.
Sep 27 2016, 11:51 AM · gnupg, Feature Request
werner removed a project from T2280: Wish for a new keygen API: Restricted Project.
Sep 27 2016, 11:50 AM · gnupg, gnupg (gpg21), Feature Request
werner closed T2280: Wish for a new keygen API as Resolved.
Sep 27 2016, 11:50 AM · gnupg, gnupg (gpg21), Feature Request
werner added a comment to T2280: Wish for a new keygen API.

gpgme 1.7.0 has been released and thus I consider this bug solved.

Sep 27 2016, 11:50 AM · gnupg, gnupg (gpg21), Feature Request
werner raised the priority of T2703: provide option to ignore expiration date from Low to Normal.
Sep 27 2016, 11:49 AM · Feature Request, gnupg
werner added a project to T2703: provide option to ignore expiration date: Feature Request.
Sep 27 2016, 11:49 AM · Feature Request, gnupg

Sep 23 2016

justus added a comment to T2700: Clean up the command line interface (avoid abbreviated --long-options, consistency).

Also, most options join words with hyphens, but some don't.

Sep 23 2016, 2:44 PM · gnupg, Feature Request, gnupg (gpg22)
justus renamed T2700: Clean up the command line interface (avoid abbreviated --long-options, consistency) from Avoid abbreviated --long-options, e.g. --recv-keys to Clean up the command line interface (avoid abbreviated --long-options, consistency).
Sep 23 2016, 2:44 PM · gnupg, Feature Request, gnupg (gpg22)
justus assigned T1464: key signing in GPGME to werner.
Sep 23 2016, 12:28 PM · gpgme, Feature Request
justus added a comment to T1464: key signing in GPGME.

Fixed in 1.7 with gpgme_op_keysign.

Sep 23 2016, 12:28 PM · gpgme, Feature Request
justus closed T1464: key signing in GPGME as Resolved.
Sep 23 2016, 12:28 PM · gpgme, Feature Request
justus added projects to T2701: Do not let users create keys without an expiration date: gnupg (gpg22), Feature Request, gnupg.
Sep 23 2016, 11:51 AM · Feature Request, gnupg (gpg22)
justus added projects to T2700: Clean up the command line interface (avoid abbreviated --long-options, consistency): gnupg (gpg22), Feature Request, gnupg.
Sep 23 2016, 11:18 AM · gnupg, Feature Request, gnupg (gpg22)

Sep 22 2016

werner added a comment to T2694: insecure links on gnupg webpage (gnupg.org) that could be https.

All done except for some news entries which are actually about http. Two
changes for cvs.gnupg.org will go online with the next page rebuild.

Sep 22 2016, 9:53 AM · In Progress, Feature Request
werner closed T2694: insecure links on gnupg webpage (gnupg.org) that could be https as Resolved.
Sep 22 2016, 9:53 AM · In Progress, Feature Request

Sep 21 2016

werner added a comment to T2694: insecure links on gnupg webpage (gnupg.org) that could be https.

Yeah we recently had a lot of spam, thus the http trick.

Thanks for the list; I'll look at them.

Sep 21 2016, 9:54 PM · In Progress, Feature Request
werner added a comment to T2696: SETREPEAT support for pinentry-curses.

SETREPEAT is an optional feature - thus I changed this to a feature requests.

Sep 21 2016, 9:50 PM · pinentry, Feature Request
werner added a project to T2696: SETREPEAT support for pinentry-curses: Feature Request.
Sep 21 2016, 9:49 PM · pinentry, Feature Request

Sep 20 2016

hanno added a project to T2694: insecure links on gnupg webpage (gnupg.org) that could be https: Feature Request.
Sep 20 2016, 12:05 PM · In Progress, Feature Request

Sep 15 2016

p91 added a project to T2688: unlocking gpg-agent via pam?: Feature Request.
Sep 15 2016, 11:11 AM · gpgagent, Feature Request
bernhard added a comment to T2687: 98 chars limits on archived filenames for windows (gpgtar).

I'm unsure about the compatibility issues with using a higher filename-length
limit.

Sep 15 2016, 9:31 AM · gpgtar, gpg4win, Bug Report
bernhard added projects to T2687: 98 chars limits on archived filenames for windows (gpgtar): gpg4win, Feature Request, gpgtar.
Sep 15 2016, 9:30 AM · gpgtar, gpg4win, Bug Report
bernhard updated subscribers of T2687: 98 chars limits on archived filenames for windows (gpgtar).
Sep 15 2016, 9:30 AM · gpgtar, gpg4win, Bug Report

Sep 14 2016

werner added a comment to T2280: Wish for a new keygen API.

gpgme 1.7 will have gpgme_op_createkey which takes "default" and
"future-default" as algorithm parameters. There is also a bunch of user
functions to make creating a key easy with gpgme.

Sep 14 2016, 1:27 PM · gnupg, gnupg (gpg21), Feature Request
werner added a comment to T1814: Add option to output the signed text with --verify.

This has been implemented in the repo to be released with 2.1.16.

Sep 14 2016, 1:23 PM · gnupg, Feature Request
werner closed T1814: Add option to output the signed text with --verify as Resolved.
Sep 14 2016, 1:23 PM · gnupg, Feature Request
werner added a project to T1814: Add option to output the signed text with --verify: Unreleased.
Sep 14 2016, 1:23 PM · gnupg, Feature Request
werner added a comment to T2226: Add sha-256 checksums to swdb.lst.

This has meanwhile been done.

Sep 14 2016, 1:20 PM · gnupg, Feature Request
werner added a comment to T2364: gen-key --batch does not support certify only keys.

No bug, Use "cert" and not "certify".

Sep 14 2016, 1:19 PM · gnupg, Feature Request, KDE
werner closed T2364: gen-key --batch does not support certify only keys as Resolved.
Sep 14 2016, 1:19 PM · gnupg, Feature Request, KDE
uri set Version to 2.0.30 on T2683: Add config option to connect to HW token in non-exclusive (shared) mode.
Sep 14 2016, 3:32 AM · scd, Feature Request
uri added a project to T2683: Add config option to connect to HW token in non-exclusive (shared) mode: Feature Request.
Sep 14 2016, 3:32 AM · scd, Feature Request

Sep 12 2016

bernhard changed Version from 2.1.8 to 2.1.15 on T1804: HKPS scheme support for Windows Installer.
Sep 12 2016, 12:47 PM · Bug Report, gnupg, dirmngr
bernhard added a project to T1804: HKPS scheme support for Windows Installer: Bug Report.
Sep 12 2016, 12:47 PM · Bug Report, gnupg, dirmngr
bernhard updated subscribers of T1804: HKPS scheme support for Windows Installer.

@werner, if you prefer ntbtls over gnutls, okay. Can you add a link to ntblts
and outline the next steps. We'd probably need tls support for the web key
directory as well, so this needs a solution.

Sep 12 2016, 12:47 PM · Bug Report, gnupg, dirmngr

Sep 7 2016

werner added a comment to T2241: Encrypt to all encryption subkeys.

It is a hack in OpenKeychain to allow the use of several devices. Frankly, I am
not sure whether this is really a good idea: The security is limited by the key
for the least secure device.

Sep 7 2016, 11:20 AM · gnupg, OpenPGP, Feature Request

Aug 31 2016

werner removed a project from T2450: Add --terminate-after-idle to gpg-agent: Trash.
Aug 31 2016, 12:09 PM · gnupg, Feature Request
werner added a project to T2450: Add --terminate-after-idle to gpg-agent: gnupg.
Aug 31 2016, 12:09 PM · gnupg, Feature Request
Jan-Oliver_Wagner removed a project from T2450: Add --terminate-after-idle to gpg-agent: gnupg.
Aug 31 2016, 12:08 PM · gnupg, Feature Request
Jan-Oliver_Wagner added a project to T2450: Add --terminate-after-idle to gpg-agent: Trash.
Aug 31 2016, 12:08 PM · gnupg, Feature Request

Aug 29 2016

werner added projects to T2450: Add --terminate-after-idle to gpg-agent: Feature Request, gnupg.
Aug 29 2016, 12:08 PM · gnupg, Feature Request

Aug 18 2016

werner removed a project from T2437: please document forward-compatible expectations for machine-readable formats: Unreleased.
Aug 18 2016, 11:09 PM · gnupg, Feature Request
werner added a comment to T2437: please document forward-compatible expectations for machine-readable formats.

Done with commit d25db3c for 2.1.15

Aug 18 2016, 12:46 PM · gnupg, Feature Request
werner closed T2437: please document forward-compatible expectations for machine-readable formats as Resolved.
Aug 18 2016, 12:46 PM · gnupg, Feature Request
werner added a project to T2437: please document forward-compatible expectations for machine-readable formats: Unreleased.
Aug 18 2016, 12:46 PM · gnupg, Feature Request

Aug 16 2016

nwf added a comment to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.

Yeah, at the moment I shoot scdaemon with SIGTERM whenever I need to use the PIV
app, which is rare, and have carefully avoided any kind of automated invocation
of the smartcard through scdaemon (e.g. my statusbar polls via ykinfo directly,
rather than invoking gpg --card-status.)

I know essentially nothing about smart cards or PC/SC's design, but what goes
wrong holding the card open shared rather than exclusively? Can other shared
lock holders do drastic things like insert or remove keys, causing scdaemon's
cache to become stale? I would have (naively) guessed that shared holders could
only do things like cryptographic operations which won't pose an issue to
scdaemon's cache. (Admittedly, cryptography is not side-effect free; counters
get incremented, random numbers get generated, but none of that is the kind of
thing that scdaemon caches, right?)

Thanks for thinking about this. :)

Aug 16 2016, 3:36 AM · scd, gnupg, Feature Request
gniibe added a comment to T1756: gpg-agent doesn't accept ssh certificates.

FYI.

https://lists.gnupg.org/pipermail/gnupg-devel/2016-August/031479.html
^-- In this experiment, I tried another half of supporting OpenSSH certificates.

I found that it doesn't work as I had thought.

I think that the lower level support of gpg-agent is ready to add this feature
of accepting OpenSSH certificates, but modification of OpenSSH will be required
too, so that it works well.

Currently, the OpenSSH certificate file itself is still needed even if ssh-agent
supports OpenSSH certificates. When it returns a certificate to ssh client, ssh
client only uses the information of the key in the certificate. It is the file
which ssh client uses communicating to the server.

Aug 16 2016, 2:41 AM · gnupg, Feature Request
gniibe claimed T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.
Aug 16 2016, 2:29 AM · scd, gnupg, Feature Request
gniibe added a project to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't: gnupg.
Aug 16 2016, 2:29 AM · scd, gnupg, Feature Request
gniibe added a comment to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't.

Scdaemon grabs the device after its first use; it gets information on the
card/token and it operates (sign/decrypt) based on those information. If it
releases the device, it should get the info.
Current design of scdaemon is state-full: it caches the information on the card
so that operations can be soon done.
more state-less design could be possible, with the cost of each operation will
be heavy (by getting information each time).

I don't know the PIV app of Yubikey, but, in most cases, such an app can be
written stopping scdaemon beforehand (by a line of gpgconf --reload scdaemon, if
it's a script). It's a simple workaround for now.

Aug 16 2016, 2:29 AM · scd, gnupg, Feature Request

Aug 14 2016

nwf added a project to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't: Feature Request.
Aug 14 2016, 10:42 PM · scd, gnupg, Feature Request
nwf added a project to T2439: Optionally always prompt for key confirmation for requests from restricted sockets: Feature Request.
Aug 14 2016, 10:35 PM · gpgagent, Feature Request

Aug 12 2016

werner removed a project from T2359: Query which key will be used for a given mailbox: gnupg (gpg21).
Aug 12 2016, 11:16 AM · gnupg (gpg22), gnupg, Feature Request
werner added a project to T2359: Query which key will be used for a given mailbox: gnupg (gpg22).
Aug 12 2016, 11:16 AM · gnupg (gpg22), gnupg, Feature Request
werner removed a project from T2360: Add support for TOFU in GpgME: gnupg (gpg21).
Aug 12 2016, 11:14 AM · gnupg (gpg22), gpgme, Feature Request
werner added a project to T2360: Add support for TOFU in GpgME: gnupg (gpg22).
Aug 12 2016, 11:14 AM · gnupg (gpg22), gpgme, Feature Request

Aug 10 2016

werner added a comment to T2314: Improve detection of gpgme_data_identify.

PNGs are noe rejected.

Aug 10 2016, 3:38 PM · gpgme, Feature Request, gpg4win

Aug 9 2016

werner added a project to T2429: Allow Assuan flags to be set: Restricted Project.
Aug 9 2016, 3:49 PM · gpgme, Feature Request
werner added a comment to T2429: Allow Assuan flags to be set.

Fixed with commit b5e16b0

Aug 9 2016, 3:49 PM · gpgme, Feature Request
werner closed T1958: Use vfork/posix_spawn in gpgme as Resolved.
Aug 9 2016, 3:41 PM · Info Needed, gpgme, Feature Request
werner renamed T2385: support more than 1024 fds. from _gpgme_io_select crashes if fd > 1024 to support more than 1024 fds..
Aug 9 2016, 11:49 AM · gpgrt, Feature Request, gpgme
werner added a comment to T2385: support more than 1024 fds..

I changed this ussie to a feature request.

Aug 9 2016, 11:49 AM · gpgrt, Feature Request, gpgme
werner added a project to T2385: support more than 1024 fds.: Feature Request.
Aug 9 2016, 11:49 AM · gpgrt, Feature Request, gpgme

Aug 8 2016

werner added a comment to T2429: Allow Assuan flags to be set.

Debian's codesearch shows that gpgme_op_assuan_transact is only used by gpa and
a configure test in kdelibpim for its own copy of gpgme. In gpa it is harmless
to enable this. The only effect is that a status line callback will see a
status keyword "#" and status callbacks should always ignore unknown status lines.

Let's enable it by default.

Aug 8 2016, 4:55 PM · gpgme, Feature Request

Aug 6 2016

dkg added projects to T2437: please document forward-compatible expectations for machine-readable formats: Feature Request, gnupg.
Aug 6 2016, 6:20 PM · gnupg, Feature Request
dkg set Version to 2.1.14 on T2437: please document forward-compatible expectations for machine-readable formats.
Aug 6 2016, 6:20 PM · gnupg, Feature Request

Aug 5 2016

aheinecke added a project to T2420: TOFU Info for a Key: Duplicate.
Aug 5 2016, 10:49 AM · Duplicate, gpgme, gnupg (gpg21), Feature Request
aheinecke added a comment to T2420: TOFU Info for a Key.

This was already mentioned in T2360 so let's not clutter the tracker.
Resolved as duplicate.

Aug 5 2016, 10:49 AM · Duplicate, gpgme, gnupg (gpg21), Feature Request
aheinecke added a comment to T2420: TOFU Info for a Key.

Duplicate of T2360

Aug 5 2016, 10:49 AM · Duplicate, gpgme, gnupg (gpg21), Feature Request
aheinecke closed T2420: TOFU Info for a Key as Resolved.
Aug 5 2016, 10:49 AM · Duplicate, gpgme, gnupg (gpg21), Feature Request

Aug 3 2016

aheinecke added a comment to T2359: Query which key will be used for a given mailbox.

To piggyback something on this issue.

To quote T2359 (aheinecke on May 17 2016, 11:59 AM / Roundup):

e.g. an API to check which key: gpg -er aheinecke@intevation.de

I did not have groups on the radar for this. If a recipient is a group then
gnupg would use multiple keys in this command.

I think locate-keys would be a great mechanism to support this easily in MUAs.
When we change it that for a given mailbox only the single most valid Key is
returned we could also have the semantic that if then multiple Keys are returned
we have a group.

Aug 3 2016, 12:29 PM · gnupg (gpg22), gnupg, Feature Request

Aug 2 2016

aheinecke added projects to T2435: gpgsm combined sign and encrypt: Feature Request, kleopatra, gnupg.
Aug 2 2016, 3:57 PM · gnupg, kleopatra, Feature Request

Jul 28 2016

justus added projects to T2429: Allow Assuan flags to be set: Feature Request, gpgme.
Jul 28 2016, 2:12 PM · gpgme, Feature Request
justus set Version to master on T2428: Implement returning data from inquire callbacks.
Jul 28 2016, 2:07 PM · gpgme, Feature Request
justus added projects to T2428: Implement returning data from inquire callbacks: Feature Request, gpgme.
Jul 28 2016, 2:07 PM · gpgme, Feature Request

Jul 25 2016

justus added a comment to T1955: Prefer keys with no or cached passphrase..

I have a possible solution pushed to branch justus/issue1955. The idea is to try
to parse the message with PINENTRY_MODE_CANCEL first, and should that fail, we
retry with the configured pinentry mode. Not sure if that is too hacky, or what
side-effects parsing the message may have that we must not do twice. Werner,
what do you think?

Jul 25 2016, 10:52 AM · gnupg (gpg23), Feature Request

Jul 22 2016

aheinecke added a comment to T2314: Improve detection of gpgme_data_identify.

While the detection works now to distinguish between PGP and S/MIME data it
might be more robust if it would do some more sanity checking on the packet.

E.g. PNG Graphics are detected as PGP Signatures because they start with 0x89

But this is not super neccessary as for the use case of file extension support
valid data will be detected correctly.

Jul 22 2016, 2:28 PM · gpgme, Feature Request, gpg4win

Jul 20 2016

aheinecke added projects to T2420: TOFU Info for a Key: Feature Request, gnupg (gpg21), gpgme.
Jul 20 2016, 2:31 PM · Duplicate, gpgme, gnupg (gpg21), Feature Request
aheinecke set External Link to https://phabricator.kde.org/T2520 on T2420: TOFU Info for a Key.
Jul 20 2016, 2:31 PM · Duplicate, gpgme, gnupg (gpg21), Feature Request

Jul 14 2016

werner removed a project from T2402: New option to encrypt with a key taken from a file: Unreleased.
Jul 14 2016, 7:13 PM · gnupg, OpenPGP, Feature Request

Jul 7 2016

werner added a comment to T2314: Improve detection of gpgme_data_identify.

I think that the charset header in the armor is not a good idea. In fact gpg
does not consider it at all. The armor headers are not protected and thus they
should not not chnage the semantics of the encrypted message. There is also no
way to keep this information after removing the armor or to re-create the header
from a binary message.

I consider a new flag for the Literal Data Packet to indicate theat the content
is a MIME message to be better. Standard MIME methods can then be used to
describe the content. Right now we only have an 'u' flag to indicate UTF-8
encoding (which to some interpretation of OpenPGP is anyway the default).
An 'm' flag would make it explicit that the content is MIME encoded and there
would be no more need to derive that info from the context.

Jul 7 2016, 9:05 AM · gpgme, Feature Request, gpg4win
werner added a comment to T2314: Improve detection of gpgme_data_identify.

I also created a set of examples messages. They are in
gnupg/tests/openpgp/samplemsgs/

Jul 7 2016, 8:56 AM · gpgme, Feature Request, gpg4win