Page MenuHome GnuPG
Feed Advanced Search

Oct 11 2017

werner added a comment to T3438: Adding netzguerilla.net to the list of mailservers supporting WKD.

Thanks. I added you to the wiki page.

Oct 11 2017, 9:07 AM · Documentation, Feature Request, wkd

Oct 10 2017

hefee closed T3437: add more URL options for WKD as Resolved.

I think with the SRV entry, I can configure the server in the way I want to....

Oct 10 2017, 8:14 PM · Feature Request
hefee added a comment to T3437: add more URL options for WKD.

dirmngr has its own stub resolver to do DNS resolution via TCP so that it can be routed via Tor (to 8.8.8.8 which is a heavy traffic resolver and thus it will be hard to single out requests to other often used addresses.).

Oct 10 2017, 8:10 PM · Feature Request
hefee added a comment to T3438: Adding netzguerilla.net to the list of mailservers supporting WKD.

thanks for the links to documents.
we've setup submisson-address and policy links.

Oct 10 2017, 7:48 PM · Documentation, Feature Request, wkd
werner triaged T3438: Adding netzguerilla.net to the list of mailservers supporting WKD as High priority.
Oct 10 2017, 6:33 PM · Documentation, Feature Request, wkd
werner added a comment to T3406: GnuPG should adopt and maintain the bash completion for gpg.

I see that the completion script already uses --dump-options :-)

Oct 10 2017, 9:05 AM · Feature Request
werner triaged T3443: Install gpg 1.4 as gpg1 as High priority.
Oct 10 2017, 8:51 AM · Feature Request
werner created T3443: Install gpg 1.4 as gpg1.
Oct 10 2017, 8:50 AM · Feature Request

Oct 9 2017

werner added a comment to T3437: add more URL options for WKD.

dirmngr has its own stub resolver to do DNS resolution via TCP so that it can be routed via Tor (to 8.8.8.8 which is a heavy traffic resolver and thus it will be hard to single out requests to other often used addresses.).

Oct 9 2017, 3:32 PM · Feature Request
hefee added a comment to T3437: add more URL options for WKD.

okay, I see. Than I havn't found the documentation for this feature. This is enough for defining a different sever.

Oct 9 2017, 2:59 PM · Feature Request
werner added a comment to T3437: add more URL options for WKD.

The only requirement here is that you use a subdomain of gnupg.org (here wkd, but any will work). This was added for those providers who have outsourced the top level domain but can still add new DNS entries.

Oct 9 2017, 2:53 PM · Feature Request
werner added a comment to T3437: add more URL options for WKD.

Using a different server is actually supported:

Oct 9 2017, 2:44 PM · Feature Request
hefee added a comment to T3437: add more URL options for WKD.

I know, that I can't handle all WKD request under one domain for multiple once. But i could make sure, that autoconfig.<domain> would result under another IP adresse so I can handle all of the WKD request at another server. Add a own VirtualHost entry etc.

Oct 9 2017, 12:06 PM · Feature Request
werner added a comment to T3437: add more URL options for WKD.

FWIW, I plan to add a few features to gpg-wks-server to make the setup of a new domain and installation of keys easier.

Oct 9 2017, 11:58 AM · Feature Request
werner added a comment to T3437: add more URL options for WKD.

That does not work because a property of WKD is that the key you retrieve has only the requested mail address and no other mail address. Merging them all into one file, which you need to do with your proposal, removes that property.

Oct 9 2017, 11:57 AM · Feature Request

Oct 6 2017

hefee created T3437: add more URL options for WKD.
Oct 6 2017, 11:30 PM · Feature Request
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

Because of policy requirements I have.

Oct 6 2017, 6:43 PM · Restricted Project, Feature Request, gnupg
werner added a comment to T3431: Private key reported as public.

The import-show thing is new. What you see is different from the default action of gpg when it encounters a keyblock. In fact, that old output was never well defined and basically a debugging aid.

Oct 6 2017, 4:53 PM · Feature Request
vsajip added a comment to T3431: Private key reported as public.

Is this not a regression, rather than a new feature request? Earlier versions of GnuPG report sec rather than pub for such keys. The file itself is a private key - that it contains a public part is surely secondary in this context.

Oct 6 2017, 1:26 PM · Feature Request

Oct 5 2017

bernhard added a comment to T3435: Give an option during installation to fuse GnuPG executables with rest of executables from Gpg4win installation.

I agree that it is better to keep it in two directories.
(The potential advantages outweight the drawbacks.)

Oct 5 2017, 4:47 PM · gpg4win, Feature Request
werner triaged T3431: Private key reported as public as High priority.
Oct 5 2017, 9:28 AM · Feature Request
werner closed T3435: Give an option during installation to fuse GnuPG executables with rest of executables from Gpg4win installation as Wontfix.

I see.

Oct 5 2017, 9:27 AM · gpg4win, Feature Request
JochenSaalfeld added a comment to T3435: Give an option during installation to fuse GnuPG executables with rest of executables from Gpg4win installation.

With the GPG4Win 3.0 Release, the software is differently distributed to the System. In the 2.x releases it was one folder (usually C:\Programms\gpg4win), now it is distributed to two different folder (C:\Programms\gpg4win and C:\Programms\gnupg). So the complete GnuPG files have been rearranged to their complete own folder.

Oct 5 2017, 8:32 AM · gpg4win, Feature Request

Oct 4 2017

werner added a comment to T3435: Give an option during installation to fuse GnuPG executables with rest of executables from Gpg4win installation.

Sorry, I don't understand this. Can you please elaborate?

Oct 4 2017, 6:33 PM · gpg4win, Feature Request
JochenSaalfeld created T3435: Give an option during installation to fuse GnuPG executables with rest of executables from Gpg4win installation.
Oct 4 2017, 3:48 PM · gpg4win, Feature Request

Sep 29 2017

kousu added a comment to T2688: unlocking gpg-agent via pam?.

For context, here's what the wisdom of the crowd is rigging together around GPG to get this single-sign-on feature:

Sep 29 2017, 6:09 AM · gpgagent, Feature Request

Sep 28 2017

gniibe added a comment to T3429: defer use of new signing subkeys.

For workaround (master branch with rG0a7661129499), moving the private key file to *.key.bak can do that.

Sep 28 2017, 12:48 AM · gnupg24, gnupg (gpg23), Feature Request

Sep 27 2017

werner triaged T3428: pinentry-curses should be able to avoid showing *s when user enters passphrase as Normal priority.

Good idea.

Sep 27 2017, 10:22 AM · pinentry, Feature Request
werner triaged T3429: defer use of new signing subkeys as Normal priority.
Sep 27 2017, 10:06 AM · gnupg24, gnupg (gpg23), Feature Request

Sep 26 2017

dkg created T3429: defer use of new signing subkeys.
Sep 26 2017, 10:15 PM · gnupg24, gnupg (gpg23), Feature Request
dkg created T3428: pinentry-curses should be able to avoid showing *s when user enters passphrase.
Sep 26 2017, 8:59 PM · pinentry, Feature Request
gniibe closed T1967: GnuPG should select a key for signing without trying to use missing subkeys as Resolved.

Fixed in master, applying D297: 785_sign-fix.patch.
If needed, it will be in stable 2.2 branch, in future.

Sep 26 2017, 5:05 AM · gnupg (gpg22), Feature Request

Sep 25 2017

vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

What is the benefit of two subkeys?

Sep 25 2017, 10:51 PM · Restricted Project, Feature Request, gnupg

Sep 24 2017

werner added a project to T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion: Keyserver.
Sep 24 2017, 10:03 AM · Too Old, Keyserver, Feature Request, dirmngr

Sep 22 2017

kristianf added a comment to T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion.

Thanks, that is interesting info, I need to look into that.

Sep 22 2017, 7:45 PM · Too Old, Keyserver, Feature Request, dirmngr
dkg added a comment to T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion.

I spoke with the author of onionbalance, and they said:

Sep 22 2017, 7:35 PM · Too Old, Keyserver, Feature Request, dirmngr

Sep 21 2017

kristianf added a comment to T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion.

I'm not entirely sure whether it is due to low usage or little problems with the service, but it seems to work pretty OK. My primary concern is that as opposed to DNS based system, the onionbalance system requires my node to be running and available and as such constitutes a SPOF. Although I've cleaned up my scripts sufficiently, e.g network outage will make this service unavailable whereby the hkps pool will continue to function.

Sep 21 2017, 4:27 PM · Too Old, Keyserver, Feature Request, dirmngr
werner added a project to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't: scd.
Sep 21 2017, 3:46 PM · scd, Feature Request, gnupg
werner closed T3417: Can you add Lattice-based cryptography? as Resolved.

You need to raise this with the IETF OpenPGP WG. First we need it in the OpenPGP standard, then we can implement Something (tm).

Sep 21 2017, 3:32 PM · Feature Request
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

It is on the same machine, as I mentioned manually deleting ~/.gnupg/private-keys-v1.d/* is a workaround I have to use, but it is not very user friendly.

Sep 21 2017, 1:59 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Sorry previosly I asked for more slots for keys on token. But its not
needed one. I dont even know it is a valid request but

Sep 21 2017, 1:55 PM · Restricted Project, Feature Request, gnupg
mybowknot created T3417: Can you add Lattice-based cryptography? .
Sep 21 2017, 1:54 PM · Feature Request
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

GnuPG by design uses latest sub keys so in your setup office and home one
of them is latest.

Sep 21 2017, 1:50 PM · Restricted Project, Feature Request, gnupg
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

The use case is having 2 different hardware tokens - I have an opengpg card which supports 4096 rsa subkeys, and a yubikey which supports 2048 rsa subkeys. At work I need one, at home the other.

Sep 21 2017, 1:45 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

After reading PIV and using PIV token I understood how much simple and easy
GnuPG is by design. You guys rock.

Sep 21 2017, 1:43 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Is it you are moving to new sub keys? if yes do we still need outdated old
subkeys? Is it safe to cleanup old subkeys?

Sep 21 2017, 1:30 PM · Restricted Project, Feature Request, gnupg
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

Hi, currently to be able to use 2 different cards with 2 different sets of subkeys from the same primary key (home and work) I need to manually delete ~/.gnupg/private-keys-v1.d/* everytime I want to switch from the first card to the second.

Sep 21 2017, 12:14 PM · Restricted Project, Feature Request, gnupg
gniibe added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

@bluca I created a ticket for smartcard, so that this ticket can focus on the issue of available keys on host. If anything, please add comment to T3416: gpg should select available signing key on card (even with -u option).

Sep 21 2017, 2:10 AM · gnupg (gpg22), Feature Request
gniibe created T3416: gpg should select available signing key on card (even with -u option).
Sep 21 2017, 2:07 AM · Restricted Project, Feature Request, gnupg
gniibe updated the task description for T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).
Sep 21 2017, 2:03 AM · Restricted Project, Feature Request, gnupg
bluca added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

@gniibe yes, I can reproduce the problem using -u.
But why does picking a UID force the usage of the first known subkey? Is that expected behaviour? Is there a relationship between UIDs and subkeys?

Sep 21 2017, 12:04 AM · gnupg (gpg22), Feature Request

Sep 20 2017

gniibe added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

I have updated D297: 785_sign-fix.patch patch to minimize the impact only to secret key lookup.

Sep 20 2017, 12:08 PM · gnupg (gpg22), Feature Request
gniibe removed a project from T1967: GnuPG should select a key for signing without trying to use missing subkeys: Restricted Project.

My change only addressed the use case with smartcard. So, I removed [TESTING] tag.

Sep 20 2017, 7:55 AM · gnupg (gpg22), Feature Request
gniibe closed T1983: gpg2 prefers missing secret key to available key on card, a subtask of T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)), as Resolved.
Sep 20 2017, 7:49 AM · Restricted Project, Feature Request, gnupg

Sep 18 2017

werner edited projects for T2912: command line keytocard, added: gnupg (gpg23); removed gnupg (gpg22), gnupg.
Sep 18 2017, 4:30 PM · gnupg (gpg23), Feature Request

Sep 14 2017

werner triaged T3406: GnuPG should adopt and maintain the bash completion for gpg as Normal priority.

should be useful to create such completion stuff. No context specific completion but this is imho anyway a misfeature.

Sep 14 2017, 1:59 PM · Feature Request

Sep 13 2017

dkg renamed T3406: GnuPG should adopt and maintain the bash completion for gpg from GnuPG should adopt and maintain the bash completion to GnuPG should adopt and maintain the bash completion for gpg.
Sep 13 2017, 10:14 PM · Feature Request
dkg created T3406: GnuPG should adopt and maintain the bash completion for gpg.
Sep 13 2017, 9:42 PM · Feature Request

Sep 12 2017

dkg added a comment to T3398: fingerprint-based import screener is no defense against malice.

I've changed the text of this report from "filter" to "screener" to match the preferred terminology. thanks for the clarification.

Sep 12 2017, 2:16 PM · gnupg24, gnupg (gpg23), Feature Request
dkg renamed T3398: fingerprint-based import screener is no defense against malice from fingerprint-based import filters are no defense against malice to fingerprint-based import screener is no defense against malice.
Sep 12 2017, 2:13 PM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T3398: fingerprint-based import screener is no defense against malice as Normal priority.
Sep 12 2017, 9:49 AM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T3400: gpg-agent runtime option for s2k calibration time as Normal priority.
Sep 12 2017, 9:45 AM · gpgagent, Feature Request
werner edited projects for T3398: fingerprint-based import screener is no defense against malice, added: Feature Request, gnupg (gpg23); removed gnupg (gpg22), Bug Report.

I still consider the import screener (the term filter is used in a different way now) a big mess. Using the import feature to maintain the idea of a curated keyring is a bad idea because gpg has not been designed with this in mind. We spent so much time on this screener already and problems pop up again and again.

Sep 12 2017, 9:44 AM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T3390: Showing complete OpenPGP key flags as Low priority.
Sep 12 2017, 9:31 AM · gnupg24, patch, Feature Request
werner triaged T3395: use swig to generate Perl bindings for gpgme as Normal priority.
Sep 12 2017, 9:31 AM · Feature Request, gpgme
werner triaged T3396: use swig to generate Ruby bindings for gpgme as Normal priority.
Sep 12 2017, 9:31 AM · Feature Request, gpgme
werner triaged T3389: canonical OpenPGP certificate export as Normal priority.
Sep 12 2017, 9:29 AM · gnupg, Feature Request

Sep 9 2017

dkg closed T3399: gpg-agent: add a configure option for default calibration time for s2k as Resolved.
Sep 9 2017, 12:46 AM · gpgagent, Feature Request
dkg claimed T3399: gpg-agent: add a configure option for default calibration time for s2k.
Sep 9 2017, 12:46 AM · gpgagent, Feature Request
dkg added a comment to T3399: gpg-agent: add a configure option for default calibration time for s2k.

I think this is now resolved, as of rG926d07c5fa05

Sep 9 2017, 12:45 AM · gpgagent, Feature Request

Sep 8 2017

dkg created T3400: gpg-agent runtime option for s2k calibration time in the S1 Public space.
Sep 8 2017, 9:19 PM · gpgagent, Feature Request
dkg created T3399: gpg-agent: add a configure option for default calibration time for s2k.
Sep 8 2017, 9:17 PM · gpgagent, Feature Request
dkg added a comment to T3389: canonical OpenPGP certificate export.

I am not proposing changing the order of the *hashed* subpackets in a signature. I'm proposing removing/changing/canonicalizing the *unhashed* subpackets in a signature. Sorry if i didn't make that clear enough in the initial message.

Sep 8 2017, 4:22 PM · gnupg, Feature Request
werner added a comment to T3389: canonical OpenPGP certificate export.

But wait. Does my idea really help with comparing? I doubt it because a signature also includes a date and other variable stuff and thus they are already binary identical or it is a different signature.

Sep 8 2017, 11:38 AM · gnupg, Feature Request
werner added a comment to T3389: canonical OpenPGP certificate export.

Right we can't change the order of signature subpackets after they have been created. Given that we create subpackets by directly appending them to a memory buffer instead of keeping a list of subpackets to create, the least invasive method would be a function to shuffle that memory buffer right before the signature is computed.

Sep 8 2017, 11:32 AM · gnupg, Feature Request
dkg added a comment to T3389: canonical OpenPGP certificate export.

I thoroughly agree that this is not required by the specs.

Sep 8 2017, 8:30 AM · gnupg, Feature Request
werner triaged T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion as Normal priority.

Do you mean this?

Sep 8 2017, 8:18 AM · Too Old, Keyserver, Feature Request, dirmngr
werner added a comment to T3389: canonical OpenPGP certificate export.

That is not required by the specs. Another way is to provide a tool to compare keys. That seems to be easier to me. Also consider the cases that there are new new packets or signature subpackets with unknown properties to the current implementations. What about different encodings in signed key material?

Sep 8 2017, 7:56 AM · gnupg, Feature Request
dkg created T3396: use swig to generate Ruby bindings for gpgme in the S1 Public space.
Sep 8 2017, 6:02 AM · Feature Request, gpgme
dkg created T3395: use swig to generate Perl bindings for gpgme in the S1 Public space.
Sep 8 2017, 6:01 AM · Feature Request, gpgme
dkg added a comment to T3370: gpg --list-packets should show symmetric algorithm for PKESK (if decryptable).

The comment from aa above appears to be misdirected/spam.

Sep 8 2017, 2:18 AM · Feature Request
gniibe added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

@werner , I understand your poiont.

Sep 8 2017, 2:17 AM · Feature Request

Sep 7 2017

stm created T3390: Showing complete OpenPGP key flags.
Sep 7 2017, 9:57 AM · gnupg24, patch, Feature Request
dkg created T3389: canonical OpenPGP certificate export.
Sep 7 2017, 1:12 AM · gnupg, Feature Request

Sep 5 2017

werner added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

So, this is VERIFY reset allows the host to implement the "force" flag we always had in the card for the first key. At least kind of, because malware can still suppress the VERIFY reset ;-). The integrated "force" flag requires the admin PIN, which is malware should have more problems to snoop.

Sep 5 2017, 10:24 AM · Feature Request
gniibe added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

For the record, the authentication status reset by VERIFY command was introduced in OpenPGPcard specification V2.2.
I think V3 card supports that.
Gnuk 1.2 supports this reset feature.

Sep 5 2017, 8:58 AM · Feature Request
gniibe added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

Yes. For the use case of GnuPG, it is better to support disabling (unauthorize) use of keys.
On the other hand, IIUC, the original OpenPGPcard implementation is designed/implemented under the influence of other smartcard usages.

Sep 5 2017, 8:55 AM · Feature Request
werner added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

The idea with the smartcard is that you can limit the time of exposure
of the key. Leaving the card accessible to the host is thus not a good
idea. Malware can simply snoop the PIN from the last operation and
then, at its own discretion, use the keys of the card. This can only be
avoided by using a smartcard reader equipped with a pinpad and able to
filter commands so that it is not possible to bypass the pinpad (which
is easy for the host).

Sep 5 2017, 8:48 AM · Feature Request
gniibe added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

Unfortunately, not all OpenPGPcard implementations support command to unauthorize use of keys.

Sep 5 2017, 3:55 AM · Feature Request
gniibe added a subtask for T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly: T3383: scdaemon option 'card-timeout' does not have any effect.
Sep 5 2017, 3:50 AM · Feature Request

Sep 4 2017

nitroalex added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

Using a smartcard it should be possible to set a cache-ttl value so that not only on-disk keys but also the PIN used for unlocking the key on the smartcard is not cached longer than the given period in cache-ttl. Until now you have to plug out and in the card by yourself to get this working. Alternatively you theoretically could set a config in scdaemon to power off the card after some time ("card-timeout). It could be a solution to set this config automatically if cache-ttl option is used.

Sep 4 2017, 7:29 PM · Feature Request

Sep 1 2017

werner triaged T3380: Use exponential backoff when spawning agent and dirmngr as Normal priority.
Sep 1 2017, 11:14 AM · gnupg24 (gnupg-2.4.4), Feature Request

Aug 26 2017

aa added a comment to T3370: gpg --list-packets should show symmetric algorithm for PKESK (if decryptable).

Go ahead and type your message ...

Aug 26 2017, 12:16 PM · Feature Request
werner triaged T3370: gpg --list-packets should show symmetric algorithm for PKESK (if decryptable) as Normal priority.
Aug 26 2017, 8:34 AM · Feature Request

Aug 25 2017

dkg created T3370: gpg --list-packets should show symmetric algorithm for PKESK (if decryptable).
Aug 25 2017, 7:17 PM · Feature Request

Aug 23 2017

gouttegd added a comment to T2245: pinentry on wrong monitor.

Is this even something that we can control?

Aug 23 2017, 10:52 PM · Stalled, Feature Request, pinentry
werner triaged T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly as Wishlist priority.

Smartcards and on-disk keys are very different things and handled by different processes.

Aug 23 2017, 10:52 AM · Feature Request

Aug 21 2017

nitroalex created T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.
Aug 21 2017, 5:07 PM · Feature Request
justus triaged T3350: gpgv should emit a status line with full issuer fingerprint, if it is present in the key. as Wishlist priority.
Aug 21 2017, 11:33 AM · gpgv, Feature Request

Aug 19 2017

ouroboros added a comment to T2748: ssh-agent emulation should provide the primary User ID of any keys offered via ssh.

I would also like this feature. I currently use a pair of subkeys (one for work one for personal projects) and it would be much easier if I could configure gpg-agent to append comments to the keys rather than displaying (none). Perhaps a flag could be added to sshcontrol which allows you to specify and arbitrary comment?

Aug 19 2017, 10:25 PM · gnupg, Feature Request