Page MenuHome GnuPG
Feed Advanced Search

Aug 23 2017

werner triaged T3361: Test keys for problem reporting (3072rsa) as Low priority.
Aug 23 2017, 10:42 AM

Aug 10 2017

werner committed rG2d6832aa83eb: po: Update Russian translation (authored by Ineiev <ineiev@gnu.org>).
po: Update Russian translation
Aug 10 2017, 12:45 PM

Aug 9 2017

werner committed rD077bca1a74fa: swdb: Release GnuPG 2.1.23 (authored by werner).
swdb: Release GnuPG 2.1.23
Aug 9 2017, 5:30 PM
werner committed rGd6b40a9c866a: Post release updates (authored by werner).
Post release updates
Aug 9 2017, 5:04 PM
werner committed rGe8ffa9a6ca5d: Release 2.1.23 (authored by werner).
Release 2.1.23
Aug 9 2017, 5:04 PM
werner committed rG31a99733639a: po: Auto-update (authored by werner).
po: Auto-update
Aug 9 2017, 3:51 PM
werner committed rG2059dbf20196: po: Update German translation (authored by werner).
po: Update German translation
Aug 9 2017, 12:57 PM

Aug 8 2017

werner added a comment to T1537: gpgv does not handle expired or revoked keys.

GPGME does not use gpgv. What Justus likely meant is that we would need to change the common code used by gpgv and gpg. That may give problems in GPGME.

Aug 8 2017, 9:09 PM · Feature Request, gnupg
werner triaged T3343: show-unusable-subkeys claims "expired: never" when primary key is expired as Normal priority.

Funny. We should make show-unusable-subkeys the default to detect such flaws ;-)

Aug 8 2017, 7:31 PM · gnupg, Bug Report
werner closed T3344: Installing GnuPG on Chromebook as Invalid.

With the exception of Windows, we only provide source code. Thus you need to compile it for your platform yourself or a find a distribution which comes with GnuPG.

Aug 8 2017, 7:26 PM · Bug Report
werner triaged T3345: import-export is noisy, even when i ask it to be --quiet as Low priority.
Aug 8 2017, 7:21 PM · Feature Request, gnupg
werner committed rGfb21aa8b5036: build: New configure option --enable-all-tests. (authored by werner).
build: New configure option --enable-all-tests.
Aug 8 2017, 5:56 PM
werner added a comment to T3043: Explore wiki options..

To avoid a single point of failure I would prefer to keep the wiki off from al-kindi and, if Intevation agrees, to keep it where it is.

Aug 8 2017, 3:39 PM · dev.gnupg.org
werner committed rG0bd19dae1161: gpgscm: Make the test summary stand out (authored by werner).
gpgscm: Make the test summary stand out
Aug 8 2017, 1:53 PM
werner committed rG0a8e20c4c639: sm: Always print the keygrip in colon mode. (authored by werner).
sm: Always print the keygrip in colon mode.
Aug 8 2017, 1:53 PM
werner lowered the priority of T2826: Clock skew screws up expiration and usage of keys from Normal to Wishlist.

Also note that --faked-system-time is a debugging aid and nothing you should use under production. A wrong system time is a security problem anyway because it invalidates assumptions gpg takes. A small clock skew is annoying but the way to avoid is is easy enough.

Aug 8 2017, 11:14 AM · gnupg, Bug Report
werner closed T3337: --daemon does not cause gpg-agent to run in the background. as Resolved.

In fact, on Windows you would need to have a system service. We did this in the past for the dirmngr but remove that feature due to possible security problems and problems during installation.

Aug 8 2017, 11:06 AM · gnupg (gpg22), Windows, gpgagent, Bug Report

Aug 7 2017

werner created T3335: Find a new Treasurer for the Verein.
Aug 7 2017, 4:09 PM · Verein
werner closed T3324: Activate Web Key Discovery by default as Resolved.
Aug 7 2017, 1:16 PM · g10code (gnupg-2.2)
werner edited projects for T2103: Improve the pinentry password quality indication, added: gnupg (gpg23); removed gnupg.
Aug 7 2017, 9:55 AM · gnupg (gpg23), Feature Request
werner triaged T3332: update the release notes page as Normal priority.
Aug 7 2017, 9:42 AM · gpgweb
werner created T3334: Option --disable-dirmngr for gpg.
Aug 7 2017, 9:41 AM · Feature Request, gnupg (gpg22)

Aug 5 2017

werner added a comment to T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6.

BTW, dirmngr has an option --disable-ipv4.

Aug 5 2017, 3:05 PM · gnupg (gpg22), dirmngr, Bug Report
werner triaged T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6 as Low priority.

If you don't have a TCP enabled OS, you can use configure --disable-dirmngr.

Aug 5 2017, 3:03 PM · gnupg (gpg22), dirmngr, Bug Report
werner lowered the priority of T3330: Install gpg as gpg and not anymore as gpg2 from High to Low.

Done with commit rGa69464b0b6da.

Aug 5 2017, 3:00 PM · gnupg (gpg14)
werner committed rGa69464b0b6da: gpg: Install gpg by default under the name gpg. (authored by werner).
gpg: Install gpg by default under the name gpg.
Aug 5 2017, 2:47 PM
werner committed rG69e97d909d58: gpg: gpgconf needs to support the now default --auto-key-retrieve. (authored by werner).
gpg: gpgconf needs to support the now default --auto-key-retrieve.
Aug 5 2017, 2:47 PM

Aug 4 2017

werner committed rGb70e86fd1050: gpg: Fix memory leak in parse_auto_key_locate. (authored by werner).
gpg: Fix memory leak in parse_auto_key_locate.
Aug 4 2017, 10:52 PM
werner committed rG0767eada1479: tests: Adjust tests for changed --auto-key-locate default. (authored by werner).
tests: Adjust tests for changed --auto-key-locate default.
Aug 4 2017, 10:35 PM
werner created T3330: Install gpg as gpg and not anymore as gpg2.
Aug 4 2017, 10:32 PM · gnupg (gpg14)
werner committed rG9bb13a0e8193: gpg: Make --no-auto-key-retrieve gpgconf-igurable. (authored by werner).
gpg: Make --no-auto-key-retrieve gpgconf-igurable.
Aug 4 2017, 10:25 PM
werner added a comment to T3324: Activate Web Key Discovery by default.

auto-key-locate now defaults to "local,wkd" and --auto-key-retrieve is also the default.

Aug 4 2017, 10:16 PM · g10code (gnupg-2.2)
werner committed rG7e1fe791d188: gpg: Default to --auto-key-locate "local,wkd" and --auto-key-retrieve. (authored by werner).
gpg: Default to --auto-key-locate "local,wkd" and --auto-key-retrieve.
Aug 4 2017, 10:14 PM
werner triaged T3329: only document --faked-system-time for gpg 2.1 and later as Normal priority.
Aug 4 2017, 6:51 PM · gnupg (gpg14), Bug Report
werner closed T3297: Pinentry-gtk2 may fail to grab the keyboard as Resolved.

Thanks for that. gpg-agent 2.1.23 or 2.2.0 will have a new default of --no-grab which can be reverted using the new --grab.

Aug 4 2017, 6:49 PM · pinentry
werner added a comment to T3279: Release pinentry 1.1.0.

I have changed gpg-agent to make --no-grab the default. The new option --grab can be used to revert this.

Aug 4 2017, 6:47 PM · pinentry
werner committed rG3d78ae4d3de0: agent: Make --no-grab the default. (authored by werner).
agent: Make --no-grab the default.
Aug 4 2017, 6:45 PM
kai awarded rGb54d75fb1dcf: gpg: Avoid double fingerprint printing with import-show. a Party Time token.
Aug 4 2017, 5:27 PM
werner committed rGb54d75fb1dcf: gpg: Avoid double fingerprint printing with import-show. (authored by werner).
gpg: Avoid double fingerprint printing with import-show.
Aug 4 2017, 5:17 PM
werner committed rGd9fabcc1989d: gpg: New import option show-only. (authored by werner).
gpg: New import option show-only.
Aug 4 2017, 5:17 PM
werner added a comment to D440: gtk: Disable tooltips in keyboard-grabbing mode..

Feel free to push it to the main repo at git.gnupg.org (similar to scrute). I granted you the required rights.

Aug 4 2017, 2:43 PM
werner added a comment to T3326: gpg --delete-secret-key silently leaves gpg1/gpg2.0 secret keys intact.

As said that is a distro thing and nothing we, as upstream authors, will decide for those who build gnupg on their own. Reading README and following migration instructions is a MUST for everyone installing a new version of a software.

Aug 4 2017, 11:09 AM · Documentation
werner closed T3314: libgcrypt-1.8.0 failed on solaris 10 as Invalid.

Please ask any Unix sysadmin for help. Paid support is available from the companies listed here: https://gnupg.org/service.html and there are lot of others.

Aug 4 2017, 11:03 AM · libgcrypt, Bug Report

Aug 3 2017

werner committed rG6cba56d436b5: wks: Allow gpg-wks-client --supported with just the domain name (authored by werner).
wks: Allow gpg-wks-client --supported with just the domain name
Aug 3 2017, 9:24 PM
werner committed rD196c591f4dd7: blog: Fix a typo in a link I introduced. (authored by werner).
blog: Fix a typo in a link I introduced.
Aug 3 2017, 9:02 PM
werner committed rDf6e5f1572ecb: blog: Okay, max-width attrib looked better. (authored by werner).
blog: Okay, max-width attrib looked better.
Aug 3 2017, 8:49 PM
werner committed rDcdad5f0bc9d0: tools: Also sync the img and data dirs of the blog (authored by werner).
tools: Also sync the img and data dirs of the blog
Aug 3 2017, 8:49 PM
werner committed rDac33d6f76550: blog: Remove images attributes and correct gpg version (authored by werner).
blog: Remove images attributes and correct gpg version
Aug 3 2017, 8:41 PM
werner added a comment to T3326: gpg --delete-secret-key silently leaves gpg1/gpg2.0 secret keys intact.

It is there for a purpose. If the distros want to enforce a certain policy, they can do that. But we can't do that.
Sure, we could print a warning note. But then we would need to print a lot of warning notes all over the place to the effect that nobody will care about that and ask for an option to silence them.

Aug 3 2017, 8:01 PM · Documentation
werner added a comment to T3324: Activate Web Key Discovery by default.

Yes, any auto-key-locate entry should disable the defaults.

Aug 3 2017, 7:54 PM · g10code (gnupg-2.2)
werner closed T3200: Fix sym cipher discrepancies in gpg4vsnfd evaluation documents., a subtask of T3191: Make sure only listed algorithms are used with --compliance=de-vs, as Resolved.
Aug 3 2017, 7:50 PM · gnupg (gpg22)
werner closed T3200: Fix sym cipher discrepancies in gpg4vsnfd evaluation documents. as Resolved.

Stephan released revised document which should fix this.

Aug 3 2017, 7:50 PM · Documentation, gnupg (gpg22)
werner placed T3075: Campaign 2017 up for grabs.

We should publish a status report about the campaign. I'd suggest to do this a few days before the 2.2 release.

Aug 3 2017, 7:49 PM · g10code, Verein
werner triaged T3326: gpg --delete-secret-key silently leaves gpg1/gpg2.0 secret keys intact as Normal priority.

I would not say that this remark is in a dark corner. Migration steps are actually important for, well, migration to a new version.

Aug 3 2017, 7:46 PM · Documentation
werner added a comment to T3279: Release pinentry 1.1.0.

Grabbing the keyboard is an important X feature and not related to gtk etc.
It has two purposes:

  • Make sure that the Pinentry has the focus
  • Avoid that other users can grab the keyboard and snoop on the input.

These days the latter is not so important anymore, given that most of us have only a single user on the systems.

Aug 3 2017, 7:43 PM · pinentry

Aug 2 2017

werner committed rCdf1e221b3012: tests: Fix a printf glitch for a Windows test. (authored by werner).
tests: Fix a printf glitch for a Windows test.
Aug 2 2017, 6:58 PM
werner committed rC21d0f068a721: tests: Add benchmarking option to tests/random. (authored by werner).
tests: Add benchmarking option to tests/random.
Aug 2 2017, 6:58 PM
werner committed rCeea36574f378: random: Add more bytes to the pool in addition to the seed file. (authored by werner).
random: Add more bytes to the pool in addition to the seed file.
Aug 2 2017, 6:58 PM
werner added a comment to T3314: libgcrypt-1.8.0 failed on solaris 10.

I don't know. We only provide binary packages for Windows.

Aug 2 2017, 5:47 PM · libgcrypt, Bug Report
werner triaged T3323: gpgme should be able to programmatically examine (and modify?) preferences on a key as Wishlist priority.
Aug 2 2017, 5:45 PM · gpgme
werner added a comment to rG9832a4bacfa5: debian: Remove packaging from upstream repository..

The reason for that cruft is that James originally suggested to have that even in the tarball but later reverted his idea.

Aug 2 2017, 4:25 PM
werner added a comment to T3301: Board meeting in July/August.

E194 started a bit too late but here we go:

Aug 2 2017, 4:03 PM · Verein
werner raised the priority of T3324: Activate Web Key Discovery by default from Normal to High.

So your suggestion is that

auto-key-retrieve
auto-key-locate local
auto-key-locate wkd
auto-key-locate dane

shall be the new default unless --disable-dirmngr is also used?

Aug 2 2017, 12:37 PM · g10code (gnupg-2.2)
werner created T3325: Allow encryption/signing in GPGME using a specified subkey .
Aug 2 2017, 11:43 AM · gpgme

Aug 1 2017

werner edited projects for T3316: test failures in gnupg 2.1.22 when using configure --disable-scdaemon, added: Tests; removed MacOS.
Aug 1 2017, 7:17 PM · Tests, Bug Report
werner added a comment to T3316: test failures in gnupg 2.1.22 when using configure --disable-scdaemon.

That's it. I can reproduce this on Debian.

Aug 1 2017, 7:16 PM · Tests, Bug Report
werner renamed T3316: test failures in gnupg 2.1.22 when using configure --disable-scdaemon from test failures in gnupg 2.1.22 on macOS to test failures in gnupg 2.1.22 when using configure --disable-scdaemon.
Aug 1 2017, 7:16 PM · Tests, Bug Report
werner reopened T3015: No rev cert saved if --gen-key in used with --output as "Open".

Patch breaks the tests.

Aug 1 2017, 7:05 PM · gnupg (gpg21), Bug Report
werner added a project to T3322: Set a policy for logo use: Verein.
Aug 1 2017, 6:58 PM · Verein, gpgweb
werner added a comment to rBOOK7fbef9167951: Third draft of MUA integration chapter..

Just a few comments while glancing on the text.

Aug 1 2017, 6:55 PM
werner reopened T3019: Provide small logos for use with fingerprints on websites etc. as "Open".

We can't close this bug because the main thing is to define a policy on how the GnuPG icons can be used. For example do we allow their use by proprietary software to indicate that they use GnuPG below the hood?

Aug 1 2017, 6:44 PM · gpgweb
werner raised a concern with rGebc65ff459e6: g10: Always save standard revocation certificate in file..

I don't like this patch because it is too large for what it achieves. The common way how we override global options is to save the old option, set that option, process, and the restore the option. In the revoke code we already do this for opt.armor.

Aug 1 2017, 6:37 PM
werner added a comment to T3321: Make it possible to combine GpgMEpp and QGpgme with MSVC compiled binaries.

I recall that we had the same problem back in 2010 and solved it. Please describe the ABI differences.

Aug 1 2017, 6:21 PM · Feature Request, gpgme
werner added a comment to rG4e117f206beb: gpg,sm: Error out on compliance mismatch while decrypting..

I had a long discussion with Stephan on this and he convinced me that this is the Right Thing to do. Anyway, in the last meeting with the customer we agreed on this behaviour There is a table in the minutes.

Aug 1 2017, 1:13 PM
werner committed rG4e117f206beb: gpg,sm: Error out on compliance mismatch while decrypting. (authored by werner).
gpg,sm: Error out on compliance mismatch while decrypting.
Aug 1 2017, 9:02 AM
werner committed rGa21ca77988ce: indent: Wrap overlong lines in argparse.c (authored by werner).
indent: Wrap overlong lines in argparse.c
Aug 1 2017, 9:02 AM
werner accepted rGfde9a8cc6c84: Simple typo fix..

The usual 'g' from triggering Gnus to get new News/mail. From time to time it happens that I hit g but having switched to the wrong buffer.

Aug 1 2017, 8:52 AM

Jul 31 2017

werner added a comment to T3317: dirmngr: Watching /etc/resolv.conf does not work on Mac OS X.

debug dns

log-file whateveryouwant
Jul 31 2017, 6:51 PM · MacOS, gnupg (gpg22), Bug Report
werner committed rDddb59c1fb16a: web: Fix links in last commit (authored by werner).
web: Fix links in last commit
Jul 31 2017, 5:15 PM
werner removed a project from T3318: Keyserver access on Windows broken (Resource Temporary Unavailable): In Progress.
Jul 31 2017, 5:12 PM · g10code (gnupg-2.2), gpg4win
werner closed T3318: Keyserver access on Windows broken (Resource Temporary Unavailable) as Resolved.

A new installer is now available:

Jul 31 2017, 5:10 PM · g10code (gnupg-2.2), gpg4win
werner committed rD713d1b397374: swdb: Uploaded a new 2.1.22 Windows installer (authored by werner).
swdb: Uploaded a new 2.1.22 Windows installer
Jul 31 2017, 5:09 PM
werner added a project to T3318: Keyserver access on Windows broken (Resource Temporary Unavailable): In Progress.
Jul 31 2017, 4:26 PM · g10code (gnupg-2.2), gpg4win
werner added a comment to T3318: Keyserver access on Windows broken (Resource Temporary Unavailable).

Patched installer is better. This is also a good test on whether the build works with custom patches.

Jul 31 2017, 2:10 PM · g10code (gnupg-2.2), gpg4win
werner added a comment to T3318: Keyserver access on Windows broken (Resource Temporary Unavailable).

How, shall we build just a new patched installer or do a full new release?

Jul 31 2017, 1:19 PM · g10code (gnupg-2.2), gpg4win
werner closed T3319: Fix connect with timeout on Windows, a subtask of T3318: Keyserver access on Windows broken (Resource Temporary Unavailable), as Resolved.
Jul 31 2017, 1:18 PM · g10code (gnupg-2.2), gpg4win
werner closed T3319: Fix connect with timeout on Windows as Resolved.

That was an easy one.

Jul 31 2017, 1:18 PM · g10code (gnupg-2.2), gpg4win
werner committed rG482fd5758c1b: dirmngr,w32: Fix http connection timeout problem. (authored by werner).
dirmngr,w32: Fix http connection timeout problem.
Jul 31 2017, 1:18 PM
werner added a comment to T3317: dirmngr: Watching /etc/resolv.conf does not work on Mac OS X.

According to POSIX stat(2) follows a symlink and thus /etc/resolv.conf is the right name to use. (To stat /etc/resolv.conf itself lstat(2) would need to be used. ). I just checked the macOS man page and it says nothing to the contrary.

Jul 31 2017, 12:30 PM · MacOS, gnupg (gpg22), Bug Report
werner triaged T3315: 5/7 tests failed installing libgpg-error-1.27 as Normal priority.
Jul 31 2017, 11:30 AM · gpgrt, Bug Report
werner triaged T3317: dirmngr: Watching /etc/resolv.conf does not work on Mac OS X as High priority.
Jul 31 2017, 11:28 AM · MacOS, gnupg (gpg22), Bug Report
werner committed rG4ad5bc1b6d72: Explain the "server is older than xxx warning". (authored by werner).
Explain the "server is older than xxx warning".
Jul 31 2017, 11:28 AM
werner closed T3117: improve warnings when daemons are older than gpg as Resolved.

Unless --quiet is used we now print

Jul 31 2017, 11:26 AM · gnupg (gpg22)
werner edited projects for T3193: --symmetric --multifile, added: gnupg (gpg23); removed gnupg (gpg22).
Jul 31 2017, 10:57 AM · gnupg24, gnupg (gpg23), Feature Request
werner closed T3088: document --no-use-tor and its interaction with --use-tor as Resolved.

Can now be found in the 2.1.22 man pages.

Jul 31 2017, 10:56 AM · gnupg (gpg22)
werner closed T3196: Use symmetric ESK packet as Wontfix.

It don't think it makes sense to put any work in this. rfc4880bis defines new cipher modes and a new ESK version which would be a good occasion to implement this for the new AEAD mode.

Jul 31 2017, 10:54 AM
werner moved T3200: Fix sym cipher discrepancies in gpg4vsnfd evaluation documents. from Blocker to Backlog on the gnupg (gpg22) board.
Jul 31 2017, 10:32 AM · Documentation, gnupg (gpg22)
werner moved T2423: configure: error: Sorry, the current implemenation requires mmap. due to empty CFLAGS (missing -fPIC) from Blocker to Backlog on the gnupg (gpg22) board.
Jul 31 2017, 10:32 AM · gnupg (gpg22), Bug Report, gnupg
werner moved T3252: Track the origin of a key from Blocker to Deferred on the gnupg (gpg22) board.
Jul 31 2017, 10:28 AM · gnupg (gpg22)
werner created T3319: Fix connect with timeout on Windows.
Jul 31 2017, 9:58 AM · g10code (gnupg-2.2), gpg4win