Page MenuHome GnuPG
Feed Advanced Search

Sep 12 2017

werner committed rG7d15ee88980f: tools: New function mime_maker_add_body_data. (authored by werner).
tools: New function mime_maker_add_body_data.
Sep 12 2017, 2:47 PM
werner committed rGc65a7bba7331: wks: Use unencrypted draft-1 mode for posteo.de (authored by werner).
wks: Use unencrypted draft-1 mode for posteo.de
Sep 12 2017, 2:47 PM
werner committed rGa172759b5088: tests: Fix a test which specifies expiration date. (authored by gniibe).
tests: Fix a test which specifies expiration date.
Sep 12 2017, 2:39 PM
werner committed rG827abe01a72a: scd: Fix for large ECC keys. (authored by gniibe).
scd: Fix for large ECC keys.
Sep 12 2017, 2:39 PM
werner added a comment to T3278: explicit key expiration date/time is interpreted as UTC, is echoed back using local time, confusion ensues.

[copied from gnupg-devel@]

Sep 12 2017, 9:56 AM · gnupg24, gnupg (gpg23), Documentation, Bug Report
werner triaged T3398: fingerprint-based import screener is no defense against malice as Normal priority.
Sep 12 2017, 9:49 AM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T3405: GPA Key ring lists all Algorithms as rsa4096 as High priority.

I can replicate this even with master. Good catch.

Sep 12 2017, 9:48 AM · gpa, Bug Report
werner added projects to T3387: explorer context menu items do not start Kleopatra: gpg4win, gpgex.
Sep 12 2017, 9:46 AM · gpgex, gpg4win, Bug Report
werner triaged T3400: gpg-agent runtime option for s2k calibration time as Normal priority.
Sep 12 2017, 9:45 AM · gpgagent, Feature Request
werner edited projects for T3398: fingerprint-based import screener is no defense against malice, added: Feature Request, gnupg (gpg23); removed gnupg (gpg22), Bug Report.

I still consider the import screener (the term filter is used in a different way now) a big mess. Using the import feature to maintain the idea of a curated keyring is a bad idea because gpg has not been designed with this in mind. We spent so much time on this screener already and problems pop up again and again.

Sep 12 2017, 9:44 AM · gnupg24, gnupg (gpg23), Feature Request
werner added a project to T3388: Kleopatra does not offer ascii armor: gpg4win.
Sep 12 2017, 9:32 AM · gpg4win, Bug Report
werner triaged T3390: Showing complete OpenPGP key flags as Low priority.
Sep 12 2017, 9:31 AM · gnupg24, patch, Feature Request
werner triaged T3395: use swig to generate Perl bindings for gpgme as Normal priority.
Sep 12 2017, 9:31 AM · Feature Request, gpgme
werner triaged T3396: use swig to generate Ruby bindings for gpgme as Normal priority.
Sep 12 2017, 9:31 AM · Feature Request, gpgme
werner triaged T3397: gpg: --refresh-keys became extremely verbose and complaining as Low priority.
Sep 12 2017, 9:30 AM · gnupg (gpg22)
werner triaged T3394: "gpgconf --list-options gpg-agent" fails if bad option is present in ~/.gnupg/gpg-agent.conf as Normal priority.
Sep 12 2017, 9:30 AM · Documentation, Bug Report, gpgagent
werner triaged T3389: canonical OpenPGP certificate export as Normal priority.
Sep 12 2017, 9:29 AM · gnupg, Feature Request
werner added a project to T3401: GPGOL causes Outlook 2016 to hang when signing and Kleopatra is not yet open: gpg4win.
Sep 12 2017, 9:28 AM · gpgol, gpg4win, Bug Report
werner added a project to T3402: Kleopatra prompts for signing cert when sending signed email, even when told not to: gpg4win.
Sep 12 2017, 9:28 AM · gpg4win, Bug Report
werner added a project to T3403: Kleopatra cannot certify "for all to see" two times in a row: gpg4win.
Sep 12 2017, 9:27 AM · gpg4win, Bug Report
werner triaged T3404: gpgv warns about "--compliance=gnupg mode" but does not support --compliance=gnupg as an argument as Normal priority.
Sep 12 2017, 9:27 AM · gnupg (gpg22), gpgv, Bug Report

Sep 11 2017

werner committed rG384a3748d902: sm: Move qualified.txt from datadir into sysconfdir (authored by alonbl).
sm: Move qualified.txt from datadir into sysconfdir
Sep 11 2017, 12:54 PM
werner committed rG7089dcc54099: gpg: Fix key generation with only an email part. (authored by werner).
gpg: Fix key generation with only an email part.
Sep 11 2017, 11:33 AM

Sep 8 2017

werner added a comment to T3389: canonical OpenPGP certificate export.

But wait. Does my idea really help with comparing? I doubt it because a signature also includes a date and other variable stuff and thus they are already binary identical or it is a different signature.

Sep 8 2017, 11:38 AM · gnupg, Feature Request
werner added a comment to T3389: canonical OpenPGP certificate export.

Right we can't change the order of signature subpackets after they have been created. Given that we create subpackets by directly appending them to a memory buffer instead of keeping a list of subpackets to create, the least invasive method would be a function to shuffle that memory buffer right before the signature is computed.

Sep 8 2017, 11:32 AM · gnupg, Feature Request
werner triaged T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion as Normal priority.

Do you mean this?

Sep 8 2017, 8:18 AM · Too Old, Keyserver, Feature Request, dirmngr
werner added a comment to T3394: "gpgconf --list-options gpg-agent" fails if bad option is present in ~/.gnupg/gpg-agent.conf.

The only mitigation I can see for this is a better error message.

Sep 8 2017, 7:59 AM · Documentation, Bug Report, gpgagent
werner added a comment to T3389: canonical OpenPGP certificate export.

That is not required by the specs. Another way is to provide a tool to compare keys. That seems to be easier to me. Also consider the cases that there are new new packets or signature subpackets with unknown properties to the current implementations. What about different encodings in signed key material?

Sep 8 2017, 7:56 AM · gnupg, Feature Request

Sep 5 2017

werner committed rDcbd448822077: campaign: Also rename the translations of the main page (authored by werner).
campaign: Also rename the translations of the main page
Sep 5 2017, 6:52 PM
werner committed rD0df7691b59f6: web: Improve the new donation main page. (authored by werner).
web: Improve the new donation main page.
Sep 5 2017, 5:58 PM
werner committed rDfea357fc4052: web: Use a new bitcoin address. (authored by werner).
web: Use a new bitcoin address.
Sep 5 2017, 5:50 PM
werner committed rDfa2207d6fa76: campaign: Remove campaign page. (authored by werner).
campaign: Remove campaign page.
Sep 5 2017, 5:39 PM
werner committed rD306bf36fb3de: campaign: Create a copy of the campaign page to file away (authored by werner).
campaign: Create a copy of the campaign page to file away
Sep 5 2017, 4:05 PM
werner added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

So, this is VERIFY reset allows the host to implement the "force" flag we always had in the card for the first key. At least kind of, because malware can still suppress the VERIFY reset ;-). The integrated "force" flag requires the admin PIN, which is malware should have more problems to snoop.

Sep 5 2017, 10:24 AM · Feature Request
werner added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

The idea with the smartcard is that you can limit the time of exposure
of the key. Leaving the card accessible to the host is thus not a good
idea. Malware can simply snoop the PIN from the last operation and
then, at its own discretion, use the keys of the card. This can only be
avoided by using a smartcard reader equipped with a pinpad and able to
filter commands so that it is not possible to bypass the pinpad (which
is easy for the host).

Sep 5 2017, 8:48 AM · Feature Request

Sep 4 2017

werner committed rDbe360e160fc7: blog: Minor correction (authored by werner).
blog: Minor correction
Sep 4 2017, 12:36 PM
werner committed rDfe58e766af27: blog: Publish financial results for 2016 (authored by werner).
blog: Publish financial results for 2016
Sep 4 2017, 12:21 PM
werner added projects to T3381: dirmngr won't start on Windows 10 with admin level account: Windows, dirmngr.

dirmngr is meanwhile an integral part of GnuPG. The old 1.1 dirmngr is entire obsosolete and won't do what gpg expects from it. To better diagnose the problem you can do this:

Sep 4 2017, 8:30 AM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report

Sep 1 2017

werner raised a concern with rBOOK5f3fec20f0f0: Integrate Vincent Breitmoser's comments on the MUA chapter..

Please move this also to another branch.

Sep 1 2017, 11:17 AM
werner triaged T3380: Use exponential backoff when spawning agent and dirmngr as Normal priority.
Sep 1 2017, 11:14 AM · gnupg24 (gnupg-2.4.4), Feature Request

Aug 31 2017

werner committed rDd641749d033e: web: Adjust the menu of the campaign page (authored by werner).
web: Adjust the menu of the campaign page
Aug 31 2017, 7:26 PM
werner committed rDc4c57f90c345: web: Move the list of Videos of the day to the bottom of the page. (authored by werner).
web: Move the list of Videos of the day to the bottom of the page.
Aug 31 2017, 7:23 PM
werner committed rD0550ee5a2657: web: Remove Neal as employee of g10 code (authored by werner).
web: Remove Neal as employee of g10 code
Aug 31 2017, 7:17 PM
werner committed rD5f7892bc53e1: web: Remove the main campaign video (authored by werner).
web: Remove the main campaign video
Aug 31 2017, 7:12 PM
werner committed rDdca25cfbfa3e: web: Announce Libgcrypt 1.7.9 and 1.8.1 (authored by werner).
web: Announce Libgcrypt 1.7.9 and 1.8.1
Aug 31 2017, 4:18 PM
werner removed a member for g10code: neal.
Aug 31 2017, 12:32 PM
werner triaged T3378: gpg-agent.exe hanging after left to idle for a while as High priority.
Aug 31 2017, 12:28 PM · Windows, libassuan, gpgagent, Bug Report
werner triaged T3377: GPA updated Swedish translation as Normal priority.

Thanks. That reminds me again that a GPA release is due.

Aug 31 2017, 12:26 PM · gpa, i18n, patch, Bug Report

Aug 29 2017

werner triaged T3375: t-secmem test failure on ppc64le / musl c-library as Normal priority.

I recall something about this on our mailing list.

Aug 29 2017, 5:17 PM · libgcrypt, Bug Report
werner triaged T3376: gpgme: add missing getenv_r() support as Normal priority.

Do you have the specs for getenv_r? I can't find such a thing on FreeBSD or Debian

Aug 29 2017, 5:13 PM · patch, gpgme

Aug 28 2017

werner triaged T3374: gpg recv-keys fail if first dns server end up with "Connection refused" as Normal priority.
Aug 28 2017, 7:34 PM · dns, dirmngr, Bug Report
werner set the icon for dns to Tag.
Aug 28 2017, 7:33 PM
werner committed rD2d68f648fbe9: web: Announce 2.2.0 (authored by werner).
web: Announce 2.2.0
Aug 28 2017, 2:01 PM
werner committed rD4cd6b84cfef8: swdb: Release gnupg 2.2.0. (authored by werner).
swdb: Release gnupg 2.2.0.
Aug 28 2017, 12:26 PM
werner committed rG82d9a201dd7c: Post release updates (authored by werner).
Post release updates
Aug 28 2017, 12:10 PM
werner committed rG9e3d41bf727f: Post release updates (authored by werner).
Post release updates
Aug 28 2017, 12:10 PM
werner committed rG9d80fb8e0001: Release 2.2.0 (authored by werner).
Release 2.2.0
Aug 28 2017, 12:10 PM
werner committed rG24462fea508f: po: Auto update (authored by werner).
po: Auto update
Aug 28 2017, 12:10 PM
werner moved T2917: --locate-key should re-fetch key via WKD if it is expired from Blocker to Backlog on the gnupg (gpg22) board.
Aug 28 2017, 9:59 AM · gnupg (gpg22), Bug Report

Aug 27 2017

werner triaged T3373: Unusual incompatibility with PGP6 PhotoID's as Low priority.

IIRC, rfc2440 did not forbid partial length encoding for key-material so gpg could use that. rfc4880 limits partial length encoding to non-key-material which causes this error message.

Aug 27 2017, 9:04 PM · OpenPGP, gnupg, Bug Report
werner committed rG45d5f5800afe: scd: Convey the correct length for Le (authored by werner).
scd: Convey the correct length for Le
Aug 27 2017, 4:55 PM
werner added a comment to T3358: Curve specific field computation routines.

I prepared Libgcrypt for the 1.9 series, thus feel free to merge your patches to master anytime you like.

Aug 27 2017, 10:24 AM · libgcrypt
werner closed T3256: AIX: libgcrypt-1.7.8 compile errors as Resolved.
Aug 27 2017, 10:22 AM · AIX, Bug Report
werner committed rC52af575ae4d6: Also bump the LT Current value. (authored by werner).
Also bump the LT Current value.
Aug 27 2017, 10:17 AM
werner committed rC566c8efd585c: Prepare for the 1.9 branch (authored by werner).
Prepare for the 1.9 branch
Aug 27 2017, 10:12 AM
werner committed rC80fd8615048c: Release 1.8.1 (authored by werner).
Release 1.8.1
Aug 27 2017, 10:03 AM
werner committed rCbf76acbf0da6: ecc: Add input validation for X25519. (authored by gniibe).
ecc: Add input validation for X25519.
Aug 27 2017, 10:03 AM
werner committed rCeb8f35243916: Post release updates (authored by werner).
Post release updates
Aug 27 2017, 10:03 AM
werner committed rC5417a2933642: indent: Typo fix. (authored by werner).
indent: Typo fix.
Aug 27 2017, 10:03 AM
werner committed rC436fd3b91669: Release 1.7.9 (authored by werner).
Release 1.7.9
Aug 27 2017, 10:02 AM
werner committed rCe16a71c777b7: Post release updates (authored by werner).
Post release updates
Aug 27 2017, 10:02 AM
werner committed rCda780c8183cc: ecc: Add input validation for X25519. (authored by gniibe).
ecc: Add input validation for X25519.
Aug 27 2017, 10:02 AM

Aug 26 2017

werner triaged T3372: Long preference lists resetting each other as Normal priority.

The way the setpref command works is implementation specific and thus the OpenPGP standard is irrelevant here
.
Are you requesting a change in the behaviour of the setpref command? That would not be easy to implement for backward compatibility.

Aug 26 2017, 6:22 PM · OpenPGP, gnupg, Bug Report
werner added a comment to T3371: Ohhhh jeeee: ... this is a bug (getkey.c:3284:merge_selfsigs).

Can you please try 2.1.23 ? We might have fixed that already.

Aug 26 2017, 6:12 PM · Bug Report
werner triaged T3370: gpg --list-packets should show symmetric algorithm for PKESK (if decryptable) as Normal priority.
Aug 26 2017, 8:34 AM · Feature Request

Aug 25 2017

werner added a comment to T3206: npth-1.3 failed to build on NetBSD-7.

Nice talk, just watched it.

Aug 25 2017, 12:55 PM · npth, Bug Report
werner added a project to T3368: Jenkins should use standard make for OpenBSD: Jenkins.
Aug 25 2017, 10:50 AM · Jenkins
werner set the icon for Jenkins to Infrastructure.
Aug 25 2017, 10:49 AM
werner created T3368: Jenkins should use standard make for OpenBSD.
Aug 25 2017, 10:48 AM · Jenkins

Aug 24 2017

werner committed rG13821e15fb9b: gpg: Fix memory leak while running --check-trustdb. (authored by werner).
gpg: Fix memory leak while running --check-trustdb.
Aug 24 2017, 10:14 PM
werner committed rGb065a696344e: gpg: Fix memory leak in sig-check. (authored by werner).
gpg: Fix memory leak in sig-check.
Aug 24 2017, 8:30 PM
werner committed rG757302cc7a94: indent: Change comment style on two functions (authored by werner).
indent: Change comment style on two functions
Aug 24 2017, 8:30 PM
werner committed rG02a5df614a36: build: Remove obsolete option from autogen.rc (authored by werner).
build: Remove obsolete option from autogen.rc
Aug 24 2017, 5:48 PM
werner added a comment to T3367: GpgOL unsupported protocol.

Is that really the entire mail? I can see only the header of the mail but not the body. How did you copy the raw mail?

Aug 24 2017, 5:28 PM · gpgol, Bug Report
werner triaged T3348: gpgsm: should default to --disable-crl-checks as Normal priority.
Aug 24 2017, 5:23 PM · gpgme, gnupg, S/MIME
werner committed rM47f61df07044: core: New context flag "auto-key-retrieve" (authored by werner).
core: New context flag "auto-key-retrieve"
Aug 24 2017, 5:22 PM
werner committed rM6745eb69e27b: Set next version to 1.10.0 (authored by werner).
Set next version to 1.10.0
Aug 24 2017, 4:27 PM
werner committed rM9bde9144f0c2: core: New public enum gpgme_keyorg_t. (authored by werner).
core: New public enum gpgme_keyorg_t.
Aug 24 2017, 4:27 PM
werner added a comment to T3018: Assuan: No obvious way to connect to gpg-agent with non-standard homedir.

Please see my comments on rM9f24e6c9010e171fd11c5cdac797cb8ce2e501dd

Aug 24 2017, 8:30 AM · gpgme (gpgme 1.23.x), Bug Report
werner added a comment to rM9f24e6c9010e: gpgconf: Add access to --list-dirs for non-default engine..

It would also be good to explain the relation ship of this feature and the gpgme_get_dirinfo - if there is any

Aug 24 2017, 8:29 AM
werner reopened T3202: add support for illumos to our version of libtool as "Open".

I merely said, that we won't replace libtool by the upstream version because that lacks other important changes we need. Upstream was not willing to integrate our changes for Windows support and also introduced a lot of other regressions as well as dropping support for some platforms. Thus we need to maintain our version.

Aug 24 2017, 8:16 AM · Info Needed, gpgrt, Bug Report

Aug 23 2017

werner committed rG565e486b8028: gpgconf: Swap "auto-key-retrieve" and "no-auto-key-retrieve". (authored by werner).
gpgconf: Swap "auto-key-retrieve" and "no-auto-key-retrieve".
Aug 23 2017, 4:52 PM
werner added a reverting change for rG9bb13a0e8193: gpg: Make --no-auto-key-retrieve gpgconf-igurable.: rG565e486b8028: gpgconf: Swap "auto-key-retrieve" and "no-auto-key-retrieve"..
Aug 23 2017, 4:52 PM
werner committed rG008ae0bd868c: build: Change SWDB tag "gnupg21" to "gnupg22". (authored by werner).
build: Change SWDB tag "gnupg21" to "gnupg22".
Aug 23 2017, 4:14 PM
werner committed rGb917cb66b795: tests: Do not run trust-pgp-4.scm (authored by werner).
tests: Do not run trust-pgp-4.scm
Aug 23 2017, 4:14 PM
werner committed rDd2ac7df3fb9f: swdb: Rename some tags. (authored by werner).
swdb: Rename some tags.
Aug 23 2017, 3:52 PM
werner committed rGfd0e5b60bed1: po: Update Norwegian translation (authored by asikrom).
po: Update Norwegian translation
Aug 23 2017, 2:24 PM
werner added a project to T3348: gpgsm: should default to --disable-crl-checks: gpgme.

I would suggest that MUAs who care about privacy do no use S/MIME at all or at least direct GPGME to not consider CRLs during signature verification. We don't have such a feature in GPGME right now but I think that is the right place to add it. X.509 is way to complicated to avoid meta data leaks.

Aug 23 2017, 10:59 AM · gpgme, gnupg, S/MIME
werner triaged T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly as Wishlist priority.

Smartcards and on-disk keys are very different things and handled by different processes.

Aug 23 2017, 10:52 AM · Feature Request
werner triaged T3363: gpg2 fails to find secret key when content encrypted with throw-keyids option as Low priority.

Please try again with a recent version of GnuPG. We had a dozen more releases since 2.1.11 and we can't spend time on trying to replicate bugs which may have already been fixed in the last 18 month.

Aug 23 2017, 10:46 AM · Bug Report