Page MenuHome GnuPG
Feed Advanced Search

Dec 7 2017

theirix added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

Could we please merge it to the stable branch (2.2.3 does not have this patch yet) or it is not tested enough? Existing subkey sellection strategy doesn't play well with mail signing and affects GPGTools/GPGMail users as well as any other users with multiple signing subkeys. Thanks!

Dec 7 2017, 8:05 PM · gnupg (gpg22), Feature Request

Dec 6 2017

gniibe merged task T2285: decryption fails with "Missing item in object" even though private key is available into T3576: Open PGP SmartCard V2.1 - decryption error: ERR 100663364 Missing item in object <SCD>.
Dec 6 2017, 1:14 AM · Info Needed, Bug Report, gnupg, scd

Dec 4 2017

werner added a parent task for T1756: gpg-agent doesn't accept ssh certificates: T3574: gpg-agent doesn't pick up ssh certificates.
Dec 4 2017, 8:05 PM · gnupg, Feature Request
jordan added a comment to T1756: gpg-agent doesn't accept ssh certificates.
Dec 4 2017, 5:17 PM · gnupg, Feature Request

Dec 2 2017

mkkcmlk created T3567: At&T Internet Service Number (1844_375_4111) At&T Wireless Customer Service Number in the S1 Public space.
Dec 2 2017, 2:42 PM · gnupg
mkkcmlk created T3566: At&T Internet Service Number (1844_375_4111) At&T Wireless Customer Service in the S1 Public space.
Dec 2 2017, 2:35 PM · gnupg
mkkcmlk created T3565: At&T Internet Service Number (1844_375_4111) At&T Customer Service Phone Number in the S1 Public space.
Dec 2 2017, 2:22 PM · gnupg
mkkcmlk created T3564: Asus Customer Care Number™ 1+-844_375_4111♝♝"^Asus Laptop Customer Service Number in the S1 Public space.
Dec 2 2017, 1:37 PM · gnupg
mkkcmlk created T3563: Asus Customer Service Review™ @@(1844)375)4111)Asus Laptop Support Phone Number in the S1 Public space.
Dec 2 2017, 1:35 PM · gnupg
mkkcmlk created T3562: Contact Asus Support™ +1⌥844⌥375⌥4111Asus Customer Care Number in the S1 Public space.
Dec 2 2017, 1:25 PM · gnupg
mkkcmlk created T3561: Asus Laptop Help™ 1(844)375-4111Asus Customer Service Review in the S1 Public space.
Dec 2 2017, 1:22 PM · gnupg
mkkcmlk created T3559: Asus Router Support Number™ (1844)375)4111)Asus Router Technical Support Phone Number in the S1 Public space.
Dec 2 2017, 1:07 PM · gnupg
mkkcmlk created T3558: Asus Product Support™ V!! (844)3754*111 Asus Laptop Technical Support Number in the S1 Public space.
Dec 2 2017, 1:05 PM · gnupg
mkkcmlk created T3557: Asus Com Service™ +@1844+375+(4111)@ Asus Computer Service Center in the S1 Public space.
Dec 2 2017, 12:49 PM · gnupg
mkkcmlk created T3556: Asus Router Support™ $$$1=844~(375)~4111 Asus Router Tech Support Phone Number in the S1 Public space.
Dec 2 2017, 12:46 PM · gnupg
mkkcmlk created T3555: Asus Laptop Customer Service USA™ 1++844+375+(4111)@Asus Laptop Tech Support Phone Number in the S1 Public space.
Dec 2 2017, 12:44 PM · gnupg
mkkcmlk created T3554: Asus Customer Care (1844_375_4111) Asus Router Customer Support Phone Number in the S1 Public space.
Dec 2 2017, 12:43 PM · gnupg

Nov 23 2017

werner closed T3533: Some Build Warnings for gnupg-2.2.3 on Ubuntu 17.10 as Resolved.

Please do not post warning. They are called warnings for a reason.

Nov 23 2017, 12:59 PM · gnupg, Bug Report
utkonos created T3533: Some Build Warnings for gnupg-2.2.3 on Ubuntu 17.10.
Nov 23 2017, 11:27 AM · gnupg, Bug Report

Nov 22 2017

drrossum closed T2868: Cannot remove passphrase as Resolved.

Nevermind, I did not realize that passwd does not only operate on the selected key but on all keys (subkeys) in sequence.

Nov 22 2017, 1:37 PM · Bug Report, gnupg
drrossum reopened T2868: Cannot remove passphrase as "Open".

I tried to remove the passphrase on my authentication subkey but the same issue seems to still be present in version 2.2.2.

Nov 22 2017, 1:08 PM · Bug Report, gnupg

Nov 20 2017

gniibe abandoned D452: Build: FreeBSD make.

Applied to 2.2 branch.

Nov 20 2017, 4:04 AM · gnupg
musteresel added a project to T3513: Change of trust of new uid not immediately reflected in user interface: gnupg.
Nov 20 2017, 12:57 AM · gnupg24, OpenPGP, Feature Request

Nov 15 2017

werner closed T2902: dimrngr over tor fails obscurely on IPv6 records when NoIPv6Traffic flag is set as Resolved.

This has been fixed a while ago my having dirmngr print a hint on the possible problem. gpg will then print a warning about a problem with the Tor configuration and with --verbose print the hint on solving this as well.

Nov 15 2017, 6:56 PM · Debian, Bug Report, gnupg, dirmngr

Nov 14 2017

werner merged task T3066: wks should automatically refresh keys into T2917: --locate-key should re-fetch key via WKD if it is expired.
Nov 14 2017, 4:32 PM · gnupg
werner merged T3066: wks should automatically refresh keys into T2917: --locate-key should re-fetch key via WKD if it is expired.
Nov 14 2017, 4:32 PM · gnupg (gpg22), Bug Report
werner merged T3497: mnemonic phrase based backup for OpenPGP / GnuPG / gpg keys into T169: Add a way to generate keypairs from a passphrase.
Nov 14 2017, 11:26 AM · gnupg, Feature Request

Nov 13 2017

aheinecke added a comment to T3498: GPG: Batch keygen has no default expiry date.

Ok for me to just have it in master. It should be fixed but is not super important imo.

Nov 13 2017, 12:19 PM · gnupg
werner added a comment to T3498: GPG: Batch keygen has no default expiry date.

Hmm. I am fine changing this for master. But for 2.2 I am nut sure. Asking on gnupg-devel?

Nov 13 2017, 12:18 PM · gnupg
aheinecke created T3498: GPG: Batch keygen has no default expiry date.
Nov 13 2017, 11:20 AM · gnupg

Nov 9 2017

gniibe merged task T2284: tsign behavior does not achieve what dkg says it should into T2923: trust signature domain restrictions don't work.
Nov 9 2017, 7:44 AM · Bug Report, gnupg
gniibe merged T2923: trust signature domain restrictions don't work into T2284: tsign behavior does not achieve what dkg says it should.
Nov 9 2017, 7:41 AM · Bug Report, gnupg
gniibe added a comment to T2284: tsign behavior does not achieve what dkg says it should.

I confirmed this is same bug in T2923: trust signature domain restrictions don't work, I am closing this one as duplicate.

Nov 9 2017, 7:41 AM · Bug Report, gnupg

Nov 7 2017

gniibe created D452: Build: FreeBSD make.
Nov 7 2017, 5:19 AM · gnupg

Nov 6 2017

werner closed T3478: Subkey-Grip support for unattended key generation, a subtask of T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only, as Resolved.
Nov 6 2017, 3:09 PM · gnupg, Feature Request

Nov 1 2017

gniibe closed T1818: gnupg fails (buffer overflow detected) to encrypt archive when called from duplicity as Resolved.

OK, closed.

Nov 1 2017, 7:17 AM · Info Needed, gnupg, gnupg (gpg14), Bug Report, Debian
gniibe added a subtask for T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only: T3478: Subkey-Grip support for unattended key generation.
Nov 1 2017, 12:37 AM · gnupg, Feature Request

Oct 26 2017

werner closed T2423: configure: error: Sorry, the current implemenation requires mmap. due to empty CFLAGS (missing -fPIC) as Resolved.

I close this for now. If you run into problems with 2.2.2 again, please re-open this bug.

Oct 26 2017, 1:09 PM · gnupg (gpg22), Bug Report, gnupg

Oct 24 2017

homolkao added a comment to T3465: --pinentry-mode loopback with --delete-secret-keys.

Unfortunately --batch option doesn't help, it only suppresses user input.

$ gpg2 --pinentry-mode loopback --batch --delete-secret-keys F4433F96910C9AC1FEF65A7299A5538C769B6150
gpg: deleting secret key failed: No pinentry
gpg: deleting secret subkey failed: No pinentry
gpg: F4433F96910C9AC1FEF65A7299A5538C769B6150: delete key failed: No pinentry

GPG pinentry works well on my Gnome desktop (wellformated form appear) but I have a problem when I need remove secret key (enter passphrase) on remote machine via SSH.
It can be handled with --export why not with --delete-secret-keys?
Is there some fix already? Or roadmap this will be fixed? Or some workaround how can I remove secret key remotely via SSH?

Oct 24 2017, 5:00 PM · gnupg, Bug Report
werner triaged T3456: GPG does not import secret subkeys from --export-secret-subkeys output if subkey stubs existed before as Normal priority.
Oct 24 2017, 3:09 PM · gnupg22 (gnupg-2.2.42), Restricted Project
werner triaged T3465: --pinentry-mode loopback with --delete-secret-keys as Normal priority.

gpg-agent sometimes pops up confirmation dialogs. This can't yet be handled with the loopback pinentry. Try gpg option --batch.

Oct 24 2017, 3:07 PM · gnupg, Bug Report
homolkao created T3465: --pinentry-mode loopback with --delete-secret-keys.
Oct 24 2017, 3:04 PM · gnupg, Bug Report

Oct 22 2017

jcross added a comment to T2289: UI says “Secret key is available.” in gpg when it is not.

Same issue exists in 2.2:

Oct 22 2017, 3:39 PM · Bug Report, gnupg, gnupg (gpg20), gnupg (gpg14)

Oct 20 2017

werner changed the status of T2746: ssh keys not deduplicated, cannot configure card auth keys using sshcontrol from Resolved to Wontfix.
Oct 20 2017, 1:53 PM · Bug Report, gnupg, gnupg (gpg21)
werner closed T2746: ssh keys not deduplicated, cannot configure card auth keys using sshcontrol as Resolved.

The long term goal is to replace sshcontrol by aflag in the extended private key format. This would instantly solve the bug. Thus closing.

Oct 20 2017, 1:53 PM · Bug Report, gnupg, gnupg (gpg21)
werner edited projects for T3296: When --detach-sign is given, but a detached signature is not created, gpg should at least emit a warning, added: gnupg; removed gnupg (gpg21).
Oct 20 2017, 1:40 PM · gnupg, Bug Report
werner closed T2939: Should not be required to manually `killagent` on card removal as Resolved.

A backport to 2.0 does not make anymore sense given EOF in 2 months.

Oct 20 2017, 1:34 PM · gnupg (gpg20), Bug Report, gnupg
werner removed projects from T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon: gnupg (gpg20), gnupg (gpg21).

gniibe: Can you check the status?

Oct 20 2017, 1:28 PM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
werner closed T2289: UI says “Secret key is available.” in gpg when it is not as Wontfix.

Won't be fixed for 1.4.

Oct 20 2017, 1:25 PM · Bug Report, gnupg, gnupg (gpg20), gnupg (gpg14)
werner closed T2071: Processes invoking gpgme_op_decrypt() should not incur a delay due to the invocation of gpg-agent as Resolved.

2.0 reached eol in 2 months so need to check it. For 1.4 I assume it has been fixed ;-)

Oct 20 2017, 1:21 PM · Restricted Project, gnupg, Bug Report
werner added a comment to T1644: Do not expect KeyIDs to be unique.

@perske, may I ask you to send a DCO and an possible updated patch against 2.2 to gnupg-devel@ ? I would like to add it to 2.2.2. Sorry for the delays.

Oct 20 2017, 1:14 PM · gnupg (gpg22), S/MIME, Bug Report
werner added a comment to T2822: gnupg 1.4 sometimes truncates pubring.gpg on SIGINT.

There should be a backup file in these cases.

Oct 20 2017, 1:06 PM · gnupg (gpg14), Bug Report, gnupg
werner closed T2736: gnupg 1.4 fixed-list-mode fails to take effect when listing keys as Wontfix.

In 2.2 we implemented --import-option show-only which dies the right thing, that is to use the reguarl key-listing code. Backporting this to 1.4 does not make sense - people should move on and use gpg 2.2.

Oct 20 2017, 12:54 PM · gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1818: gnupg fails (buffer overflow detected) to encrypt archive when called from duplicity.

Given that we received no info after nearly two years, shouldn't we simply assume that this bug as been fixed?

Oct 20 2017, 12:51 PM · Info Needed, gnupg, gnupg (gpg14), Bug Report, Debian

Oct 19 2017

werner added a comment to T3456: GPG does not import secret subkeys from --export-secret-subkeys output if subkey stubs existed before.

gnupg 2.1.11 is pretty old and has quite some bugs. Please try at least the Debian version which is 2.1.18 plus a couple of backported fixes. Or yet better, the current stable 2.2.x

Oct 19 2017, 3:16 PM · gnupg22 (gnupg-2.2.42), Restricted Project
werner closed T3446: Possible key duplication when using auto-key-retrieve? as Resolved.

Backport to 2.2 done.

Oct 19 2017, 3:11 PM · gnupg
werner added a comment to T3446: Possible key duplication when using auto-key-retrieve?.

Fixed in master. Backport to 2.2 pending.

Oct 19 2017, 11:56 AM · gnupg

Oct 17 2017

nh2 added a comment to T3456: GPG does not import secret subkeys from --export-secret-subkeys output if subkey stubs existed before.

Potentially useful to know: This is how the import looks like into an empty ~/.gnupg directory:

Oct 17 2017, 7:24 PM · gnupg22 (gnupg-2.2.42), Restricted Project
nh2 created T3456: GPG does not import secret subkeys from --export-secret-subkeys output if subkey stubs existed before in the S1 Public space.
Oct 17 2017, 7:17 PM · gnupg22 (gnupg-2.2.42), Restricted Project

Oct 16 2017

werner raised the priority of T3446: Possible key duplication when using auto-key-retrieve? from Normal to Unbreak Now!.

Looking again at this case I assume this problem is seen more often today because 2.1 started to clean keys during import. That enlarges the time span for the race condition. We clearly need to do something about this in gnupg 2.2.

Oct 16 2017, 11:40 AM · gnupg

Oct 14 2017

werner triaged T3447: delkey removes only public part of a subkey as Wishlist priority.

We need a way to delete a secret subkey.

Oct 14 2017, 12:35 PM · Debian, gnupg
werner added a comment to T3447: delkey removes only public part of a subkey.

No direct way. You can do this:

Oct 14 2017, 12:34 PM · Debian, gnupg
werner added a comment to T3447: delkey removes only public part of a subkey.

Ooops. you meant a subkey - let me check...

Oct 14 2017, 12:30 PM · Debian, gnupg
werner added a comment to T3447: delkey removes only public part of a subkey.

Sure: --delete-secret-and-public-key FINGERPRINT

Oct 14 2017, 12:29 PM · Debian, gnupg

Oct 13 2017

prudemar added a comment to T3447: delkey removes only public part of a subkey.

OK, sorry. Forgive me to ask here.. but is there a way how to remove both - the public and the private part? - and only of a specific subkey?

Oct 13 2017, 2:44 PM · Debian, gnupg
werner removed a project from T3447: delkey removes only public part of a subkey: Bug Report.

That is intended.

Oct 13 2017, 2:34 PM · Debian, gnupg
prudemar updated the task description for T3447: delkey removes only public part of a subkey.
Oct 13 2017, 12:36 PM · Debian, gnupg
prudemar updated the task description for T3447: delkey removes only public part of a subkey.
Oct 13 2017, 12:10 PM · Debian, gnupg
patrick added a comment to T3446: Possible key duplication when using auto-key-retrieve?.

Werner, so what do you suggest? Does Enigmail (and any other tool using gpg, and actually also across tools) need to make sure that there are no concurrent calls to gpg of the type that could lead to adding a new key in the keyring?

Oct 13 2017, 11:39 AM · gnupg
prudemar added projects to T3447: delkey removes only public part of a subkey: gnupg, Debian.
Oct 13 2017, 11:25 AM · Debian, gnupg

Oct 12 2017

gp_ast added a comment to T3446: Possible key duplication when using auto-key-retrieve?.

Ok, thanks for the explanation.

Oct 12 2017, 2:36 PM · gnupg
werner triaged T3446: Possible key duplication when using auto-key-retrieve? as Normal priority.

When Enigmail is running several operations at the same time it is possible that this happens. We would need to take a read lock for the entire time it takes to fetch the key or use other complicated methods to avoid a test/insert race. That would be very inconvenient. The proposed solution is to have just one process to update the keyring.

Oct 12 2017, 10:18 AM · gnupg

Oct 11 2017

gp_ast created T3446: Possible key duplication when using auto-key-retrieve? in the S1 Public space.
Oct 11 2017, 5:42 PM · gnupg

Oct 6 2017

bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

Because of policy requirements I have.

Oct 6 2017, 6:43 PM · Restricted Project, Feature Request, gnupg

Sep 26 2017

gniibe closed T1967: GnuPG should select a key for signing without trying to use missing subkeys as Resolved.

Fixed in master, applying D297: 785_sign-fix.patch.
If needed, it will be in stable 2.2 branch, in future.

Sep 26 2017, 5:05 AM · gnupg (gpg22), Feature Request

Sep 25 2017

vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

What is the benefit of two subkeys?

Sep 25 2017, 10:51 PM · Restricted Project, Feature Request, gnupg

Sep 21 2017

werner added a project to T2440: scdaemon grabs card exclusively; it'd be nice if it didn't: scd.
Sep 21 2017, 3:46 PM · scd, Feature Request, gnupg
werner closed T1928: regression --passphrase-file ignored in gnupg 2.1.2 as Resolved.
Sep 21 2017, 3:40 PM · Bug Report, gnupg, Arch
werner closed T2813: gnupg v2 does not allow for parallel processing any more as Invalid.

No info received and thus assuming that the caching was disabled.

Sep 21 2017, 3:37 PM · gnupg, Info Needed
werner lowered the priority of T1675: gpg --verify has race conditions when used concurrently from Normal to Low.
Sep 21 2017, 3:34 PM · gnupg, Bug Report
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

It is on the same machine, as I mentioned manually deleting ~/.gnupg/private-keys-v1.d/* is a workaround I have to use, but it is not very user friendly.

Sep 21 2017, 1:59 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Sorry previosly I asked for more slots for keys on token. But its not
needed one. I dont even know it is a valid request but

Sep 21 2017, 1:55 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

GnuPG by design uses latest sub keys so in your setup office and home one
of them is latest.

Sep 21 2017, 1:50 PM · Restricted Project, Feature Request, gnupg
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

The use case is having 2 different hardware tokens - I have an opengpg card which supports 4096 rsa subkeys, and a yubikey which supports 2048 rsa subkeys. At work I need one, at home the other.

Sep 21 2017, 1:45 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

After reading PIV and using PIV token I understood how much simple and easy
GnuPG is by design. You guys rock.

Sep 21 2017, 1:43 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Is it you are moving to new sub keys? if yes do we still need outdated old
subkeys? Is it safe to cleanup old subkeys?

Sep 21 2017, 1:30 PM · Restricted Project, Feature Request, gnupg
bluca added a comment to T3416: gpg should select available signing key on card (even with -u option).

Hi, currently to be able to use 2 different cards with 2 different sets of subkeys from the same primary key (home and work) I need to manually delete ~/.gnupg/private-keys-v1.d/* everytime I want to switch from the first card to the second.

Sep 21 2017, 12:14 PM · Restricted Project, Feature Request, gnupg
gniibe added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

@bluca I created a ticket for smartcard, so that this ticket can focus on the issue of available keys on host. If anything, please add comment to T3416: gpg should select available signing key on card (even with -u option).

Sep 21 2017, 2:10 AM · gnupg (gpg22), Feature Request
gniibe created T3416: gpg should select available signing key on card (even with -u option).
Sep 21 2017, 2:07 AM · Restricted Project, Feature Request, gnupg
gniibe updated the task description for T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).
Sep 21 2017, 2:03 AM · Restricted Project, gnupg, Feature Request
bluca added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

@gniibe yes, I can reproduce the problem using -u.
But why does picking a UID force the usage of the first known subkey? Is that expected behaviour? Is there a relationship between UIDs and subkeys?

Sep 21 2017, 12:04 AM · gnupg (gpg22), Feature Request

Sep 20 2017

gniibe added a comment to T1967: GnuPG should select a key for signing without trying to use missing subkeys.

I have updated D297: 785_sign-fix.patch patch to minimize the impact only to secret key lookup.

Sep 20 2017, 12:08 PM · gnupg (gpg22), Feature Request
gniibe removed a project from T1967: GnuPG should select a key for signing without trying to use missing subkeys: Restricted Project.

My change only addressed the use case with smartcard. So, I removed [TESTING] tag.

Sep 20 2017, 7:55 AM · gnupg (gpg22), Feature Request
gniibe closed T1983: gpg2 prefers missing secret key to available key on card as Resolved.

Now, 2.1.22 or later supports automatic selection of secret key by available key on card.
Closing.

Sep 20 2017, 7:49 AM · Bug Report, gnupg
gniibe closed T1983: gpg2 prefers missing secret key to available key on card, a subtask of T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)), as Resolved.
Sep 20 2017, 7:49 AM · Restricted Project, gnupg, Feature Request

Sep 19 2017

dmaroulidis added a comment to T3409: Grammatical error in el_GR translation.

My pleasure.

Sep 19 2017, 3:00 PM · i18n, gnupg
werner closed T3409: Grammatical error in el_GR translation as Resolved.

Thanks.

Sep 19 2017, 8:52 AM · i18n, gnupg

Sep 14 2017

dmaroulidis added a comment to T3409: Grammatical error in el_GR translation.

Updated translation el.po file from latest commit in gnupg repo.

Sep 14 2017, 8:18 PM · i18n, gnupg
dmaroulidis added a comment to T3409: Grammatical error in el_GR translation.

This error appears in versions 2.1.15 to 2.2.0 on all platforms.

Sep 14 2017, 8:07 PM · i18n, gnupg
dmaroulidis created T3409: Grammatical error in el_GR translation in the S1 Public space.
Sep 14 2017, 4:51 PM · i18n, gnupg