Page MenuHome GnuPG
Feed Advanced Search

Apr 12 2018

werner added a comment to T3869: libgpg-error-1.28 on Solaris.

Argh. I missed that. Probably because I searched for libgpg-error but I myself renamed the tag recently :-(.

Apr 12 2018, 8:24 AM · Solaris, gpgrt, Bug Report
gniibe changed the status of T3869: libgpg-error-1.28 on Solaris from Open to Testing.

Put the check in configure.

Apr 12 2018, 2:45 AM · Solaris, gpgrt, Bug Report

Apr 11 2018

werner added a comment to T3894: re-evaluate default randomness choices during key generation on GNU/Linux platforms.

To clarify: We already use the getrandom system call if it is available. To map /dev/random to /dev/urandom you can create a file /etc/gcrypt/random.conf with this line:

Apr 11 2018, 8:55 PM · libgcrypt, gnupg
dkg created T3894: re-evaluate default randomness choices during key generation on GNU/Linux platforms.
Apr 11 2018, 8:01 PM · libgcrypt, gnupg
aheinecke added a comment to T3884: Erroneous warning message when re-sending signed message + sending fails and locks GpgOL.

Oops. I confused the ticket numbers rO34f6bb73882e: Implement send again for crypto mails. Would be the correct commit for this ticket.

Apr 11 2018, 3:31 PM · gpgol, Bug Report, gpg4win
aheinecke changed the status of T3882: gpgol does not decrypt mails send by Evolution from Open to Testing.

Right, outlook.com is often problematic, although it might be a generic Exchange 2016 problem. Outlook.com and Exchange 2016 behave much the same.

Apr 11 2018, 2:24 PM · gpgol, Bug Report
gniibe added a comment to T3891: kdf-setup does not set admin and user PIN codes.

For the situation where PINs are not factory setting, given the specification, I don't know how to achieve "to align all PWs and the KDF-DO with correct values"; It might depend on card's implementation.

Apr 11 2018, 11:07 AM · Restricted Project, scd, Bug Report
Arnaud added a comment to T3891: kdf-setup does not set admin and user PIN codes.

You are right about the fact that multiple steps could result in unusable cards in case of power down before all commands have been issued. Nevertheless, in practice, these commands would involve very few treatments on the token (i.e. no cryptographic operation or heavy data transfer) and it should really not take long to complete the three steps (admin PIN update, user PIN update, KDF-DO update).

Apr 11 2018, 10:29 AM · Restricted Project, scd, Bug Report
gniibe added a project to T3843: Unable to generate RSA4096 keys on Yubikey 4 on OSX Sierra: Info Needed.
Apr 11 2018, 10:02 AM · Info Needed, MacOS, yubikey, scd, Bug Report
gniibe triaged T3843: Unable to generate RSA4096 keys on Yubikey 4 on OSX Sierra as Normal priority.
Apr 11 2018, 10:02 AM · Info Needed, MacOS, yubikey, scd, Bug Report
gniibe triaged T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly as Normal priority.
Apr 11 2018, 10:01 AM · ssh, gpgagent, Bug Report
Fgp added a comment to T3882: gpgol does not decrypt mails send by Evolution.

I'm not sure about that (Bug in Evolution), because I see ist only in E-Mails send by Evolution via Mircosoft (outlook.com) and not if Mails werden send by Evolution via Google (gmail.com).

Apr 11 2018, 8:15 AM · gpgol, Bug Report
BenM added a comment to T3751: man page syntax mentions token "[args]" but then does not define it.

What's in daily use for 15 yrs? GPGME? I thought GPGME was new,

Apr 11 2018, 5:46 AM · Documentation, Bug Report
BenM added a comment to T3546: ERR 219 on --refresh-keys / --send-keys /....

Since the initial redacted data for those four keys is still accessible, I checked all of those keys manually and none of them are on the keyservers. Since the OP was connecting to the specified keyserver successfully prior to that failure, I believe this is the cause of the error and not another DNS vs. Dirmngr conflict.

Apr 11 2018, 4:13 AM · dns, Bug Report
BenM claimed T3813: GPGME error: "invalid crypto engine" in the MSYS2 version.
Apr 11 2018, 3:37 AM · Python, gpgme, Bug Report
BenM added a comment to T3813: GPGME error: "invalid crypto engine" in the MSYS2 version.

This may be related to T3515: Gpg4win: Gpgconf used to open "windows" and slows down kleo startup since it depends on data from gpgconf.

Apr 11 2018, 3:35 AM · Python, gpgme, Bug Report
gniibe closed T3825: Scdaemon needs to restart after wake up from sleep mode for YubiKey to work on Windows as Resolved.

Workaround is implemented in 2.2.6.

Apr 11 2018, 1:59 AM · gpg4win, gpgagent, gnupg (gpg22), scd, Windows, Bug Report, yubikey
gniibe closed T3781: ECC encryption key on-card generation broken as Resolved.

Fixed in 2.2.6.

Apr 11 2018, 1:58 AM · g10, scd, Bug Report
gniibe changed the status of T3877: not all malloc performed in libgcrypt covered by gcry_set_allocation_handler from Open to Testing.
Apr 11 2018, 1:52 AM · libgcrypt, Bug Report
gniibe claimed T3877: not all malloc performed in libgcrypt covered by gcry_set_allocation_handler.
Apr 11 2018, 1:16 AM · libgcrypt, Bug Report
gniibe claimed T3891: kdf-setup does not set admin and user PIN codes.
Apr 11 2018, 1:13 AM · Restricted Project, scd, Bug Report

Apr 10 2018

gniibe added a comment to T3891: kdf-setup does not set admin and user PIN codes.

My interpretation of the specification is different.
By requiring the condition of setting KDF-DO (it is only valid to setup KDF-DO when PINs are factory setting), Gnuk works well with current "kdf-setup".
If the procedure of setting KDF-DO includes multiple steps with KDF-DO update and PIN update, there is a risk of power down which results unusable card.

Apr 10 2018, 11:38 PM · Restricted Project, scd, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.
dirmngr -v --debug ipc,dns,network --log-file - --server --debug-wait 3
Apr 10 2018, 8:41 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
werner triaged T3892: python: Fix crash by leaving struct members intact as High priority.
Apr 10 2018, 4:58 PM · gpgme, Bug Report
aheinecke added a comment to T3882: gpgol does not decrypt mails send by Evolution.

I've got an example mail. The problem is that the mail itself is "Content-Type: multipart/mixed; boundary="_003_DB4PR08MB01092D175DE8C1861B5D0BC197BF0DB4PR08MB0109eurp_"
"

Apr 10 2018, 4:10 PM · gpgol, Bug Report
4tmuelle added a comment to T3892: python: Fix crash by leaving struct members intact.

dunno how to attach a patch here... trying to copy it verbatim

Apr 10 2018, 3:32 PM · gpgme, Bug Report
4tmuelle added a comment to T3892: python: Fix crash by leaving struct members intact.

reproducer

Apr 10 2018, 3:31 PM · gpgme, Bug Report
4tmuelle created T3892: python: Fix crash by leaving struct members intact.
Apr 10 2018, 3:30 PM · gpgme, Bug Report
Arnaud added parent tasks for T3891: kdf-setup does not set admin and user PIN codes: T3152: KDF DO support in OpenPGP card, T3823: gpg frontend support to setup KDF DO.
Apr 10 2018, 2:41 PM · Restricted Project, scd, Bug Report
Arnaud created T3891: kdf-setup does not set admin and user PIN codes.
Apr 10 2018, 2:41 PM · Restricted Project, scd, Bug Report
werner added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

--debug-wait 3

Apr 10 2018, 1:51 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

@werner here's the only output I get:

Apr 10 2018, 10:53 AM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
werner triaged T3381: dirmngr won't start on Windows 10 with admin level account as Normal priority.

Please kill all existing dirmngr instances and don't run any programs which will trigger it to be started (e.g. Kleopatra). Then run in a _standard_ shell (cmd.exe):

Apr 10 2018, 10:48 AM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
aheinecke created T3890: Gpg4win: p7s and p7m not properly registered as double click handled for GPA or Kleo on Windows 7.
Apr 10 2018, 10:28 AM · Bug Report, gpg4win
aheinecke created T3889: GpgOL: Window management does not work well in OL 2010.
Apr 10 2018, 10:26 AM · Bug Report, gpg4win, gpgol
aheinecke created T3888: Kleopatra: S/MIME trees in keylist are minimized on refresh.
Apr 10 2018, 10:07 AM · Bug Report, gpg4win, kleopatra
aheinecke created T3887: Kleopatra: Not finishing commands.
Apr 10 2018, 10:05 AM · Bug Report, gpg4win, kleopatra
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

I, too, have this problem. I have Windows 10 Pro 64-bit with BitDefender Total Security. My first reaction when this wasn't working was to disable all functions on BitDefender. That didn't help, so I ran dirmngr as admin in cmd (I despise PowerShell) without any luck. I created a non-admin user and ran it in there, again without luck. I've come up dry. No logs, no output, and no answers. Is there anything shy of downgrading dirmngr that will make this work? Has there been any progress as to figuring this out?

Apr 10 2018, 10:05 AM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
aheinecke claimed T3886: attachments can't be removed.

I'll go for a warning / error for now and see if I can fix the renumbering.

Apr 10 2018, 8:24 AM · gpgol, Bug Report, gpg4win
werner changed the status of T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly from Open to Testing.

Thanks. I took these patches and simplified them. Not test tested, though,.

Apr 10 2018, 8:08 AM · ssh, gpgagent, Bug Report
gniibe added a comment to T3877: not all malloc performed in libgcrypt covered by gcry_set_allocation_handler.

Note:
When we change the allocation, hmac256.c will not be standalone any more (as commented in the head of the file), and we will need to change the compile-command line to include libgpg-error.

Apr 10 2018, 7:09 AM · libgcrypt, Bug Report
gniibe added a comment to T3731: gcry_pk_genkey() segfaults for ecdsa 384.

I check this report again.
The test is single thread, IIUC.

Apr 10 2018, 3:08 AM · libgcrypt, Bug Report
dkg reopened T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly as "Open".

Thanks for the fix! however, the fix only addresses the two flags we currently know about. I've pushed a branch T3880-fix that tries to implement the If the agent does not support the requested flags […] It must reply with a SSH_AGENT_FAILURE message part of the spec.

Apr 10 2018, 12:14 AM · ssh, gpgagent, Bug Report

Apr 9 2018

werner closed T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly as Resolved.

It is in 2.2.6

Apr 9 2018, 10:46 PM · ssh, gpgagent, Bug Report
JJworx added a comment to T3886: attachments can't be removed.

In fact, renumbering of attachments happens also by just viewing them repeatedly. This likely causes multiple copies somewhere, reducing disk space.

Apr 9 2018, 2:07 PM · gpgol, Bug Report, gpg4win
JJworx created T3886: attachments can't be removed.
Apr 9 2018, 1:54 PM · gpgol, Bug Report, gpg4win
aheinecke added a parent task for T3884: Erroneous warning message when re-sending signed message + sending fails and locks GpgOL: T3742: Gpg4win 3.1.0.
Apr 9 2018, 11:55 AM · gpgol, Bug Report, gpg4win
aheinecke claimed T3884: Erroneous warning message when re-sending signed message + sending fails and locks GpgOL.

Thanks for the report and the spelling fixes :-)

Apr 9 2018, 11:54 AM · gpgol, Bug Report, gpg4win
JJworx created T3884: Erroneous warning message when re-sending signed message + sending fails and locks GpgOL.
Apr 9 2018, 11:40 AM · gpgol, Bug Report, gpg4win
werner triaged T3881: Window sizing issue as Normal priority.
Apr 9 2018, 10:26 AM · gpa, Bug Report
werner closed T3832: Encrypting to a specifc recipient also encrypts to an unwanted one as Invalid.

Oh, you used a single dash and not a double dash in --armor. That is obviously the problem. As per Unix history all option characters may be combined unless they take an option arg; in that case the arg for the option may go directly after the option letter. We can't change that because lots of people and scripts use -rRECIPIENT.

Apr 9 2018, 10:22 AM · gnupg (gpg22), Bug Report
aheinecke triaged T3882: gpgol does not decrypt mails send by Evolution as Normal priority.

Thanks for the report.

Apr 9 2018, 8:55 AM · gpgol, Bug Report
gniibe added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

I see. Got it.

Apr 9 2018, 1:20 AM · gnupg (gpg22), Bug Report

Apr 6 2018

werner closed T3872: Invalid --sender option does not produce parseable output as Resolved.

To be released with 2.26 next week

Apr 6 2018, 5:43 PM · gnupg (gpg22), Bug Report
werner added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

Right with (2) (1) will not occur if the key has been created with GnuPG. However, we have caches in the code path and further rogue software may create creates, interesting keys (tm). Thus I consider it better to explicitly request keys with cert flag set.

Apr 6 2018, 4:38 PM · gnupg (gpg22), Bug Report
gniibe added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

The patch has two parts; (1) detecting signature by incapable key and (2) limiting key with relevant capability.
I think that (1) is enough. I wonder with (2), (1) would not occur.

Apr 6 2018, 1:34 PM · gnupg (gpg22), Bug Report
Fgp created T3882: gpgol does not decrypt mails send by Evolution.
Apr 6 2018, 11:57 AM · gpgol, Bug Report
werner added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

Forget my former comment. We only need to check subkeys becuase the primary key can always certify.
Here is a new revision of the patch:

Apr 6 2018, 11:32 AM · gnupg (gpg22), Bug Report
werner added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

I have another patch proposal to check the key usage. However, there is a catch-22. We get the usage flags from the key signatures and thus we can only check them after we checked the key signature.

Apr 6 2018, 11:16 AM · gnupg (gpg22), Bug Report
werner closed T1828: card-edit/fetch assumes signing key is master key and fails if not as Resolved.
Apr 6 2018, 9:37 AM · Bug Report, gnupg
werner edited projects for T3844: Able to certify public keys without a certify key present when using smartcard., added: gnupg (gpg22); removed gnupg (gpg20).

The gpg20 tag was a typo.

Apr 6 2018, 9:26 AM · gnupg (gpg22), Bug Report
gniibe added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

Sorry, the patch above is completely wrong, since pk->pubkey_usage is not the right key to check.

Apr 6 2018, 8:55 AM · gnupg (gpg22), Bug Report
gniibe changed the status of T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly from Open to Testing.
Apr 6 2018, 8:51 AM · ssh, gpgagent, Bug Report
gniibe added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

If someone claims this is a kind of vulnerability, I think that what we need to fix is signature checking side:


Speaking about this, similar patch would be required to gpg1.4.

Apr 6 2018, 2:28 AM · gnupg (gpg22), Bug Report
thwaller created T3881: Window sizing issue.
Apr 6 2018, 2:02 AM · gpa, Bug Report
mideal added a comment to T3879: passphrase dialogue: "mismatch" message not deleted during next try.

Installed pinentry version is:

Apr 6 2018, 1:35 AM · pinentry, Bug Report
gniibe added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

The bug is specific to 2.2, which may select available key on card. When such a selection, checking the PK->REQ_USAGE was missed.

Apr 6 2018, 1:09 AM · gnupg (gpg22), Bug Report

Apr 5 2018

bcl added a comment to T3844: Able to certify public keys without a certify key present when using smartcard..

Shouldn't this also be applied to STABLE-BRANCH-1-4?

Apr 5 2018, 6:18 PM · gnupg (gpg22), Bug Report
dkg created T3880: gpg-agent's ssh-agent does not handle flags in signing requests properly.
Apr 5 2018, 5:43 PM · ssh, gpgagent, Bug Report
werner added projects to T3843: Unable to generate RSA4096 keys on Yubikey 4 on OSX Sierra: scd, yubikey.
Apr 5 2018, 5:22 PM · Info Needed, MacOS, yubikey, scd, Bug Report
aheinecke changed the status of T3875: Sending signed mail fails repeatedly from Open to Testing.

This problem should be gone with Gpg4win-3.1.0-beta48. While I could not reproduce it I've tried to fix it and changed the hard error to a debug log in case something is unexpected here. I believe that this is safe.

Apr 5 2018, 3:17 PM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T3857: Gpg4win 3.0.3 GpgOL crashes with old mails already verified by GPG4win 2.x.

I tried to reproduce this again, using S/MIME Mails, installing gpg4win 2.x etc. It did not crash for me :-/

Apr 5 2018, 3:15 PM · gpgol, Bug Report, gpg4win
werner triaged T3848: Use of secure memory when generating secret primes in libgcrypt as Normal priority.

Hmmm, needs to be investigated.

Apr 5 2018, 2:49 PM · libgcrypt, Bug Report
werner triaged T3877: not all malloc performed in libgcrypt covered by gcry_set_allocation_handler as Normal priority.

For secmem.c this is on purpose. For the others we should fix that.

Apr 5 2018, 2:48 PM · libgcrypt, Bug Report
werner claimed T3872: Invalid --sender option does not produce parseable output.

Okay. We need to add a FAILURE status so that gpgme can better report this invocation error. Due to the double fork it won't be able to see the exit status. I assume you have the same problem in Enigmail.

Apr 5 2018, 2:47 PM · gnupg (gpg22), Bug Report
werner assigned T3878: not all calloc performed in libgcrypt covered by gcry_set_allocation_handler to smueller_chronox.de.

Thanks. Indeed this should also use the x... wrappers. It is not severe because this value is only used as a fixed constant.
Thus we won't fix it in 1.8 but should do this 1.9.

Apr 5 2018, 2:43 PM · libgcrypt, Bug Report
aheinecke added a project to T3879: passphrase dialogue: "mismatch" message not deleted during next try: pinentry.
Apr 5 2018, 12:51 PM · pinentry, Bug Report
aheinecke triaged T3879: passphrase dialogue: "mismatch" message not deleted during next try as Low priority.

Can you please provide the version of the tool "pinentry"

Apr 5 2018, 12:51 PM · pinentry, Bug Report

Apr 4 2018

mideal renamed T3879: passphrase dialogue: "mismatch" message not deleted during next try from passphrase dialogue: "mismatch" message not delete during next try to passphrase dialogue: "mismatch" message not deleted during next try.
Apr 4 2018, 8:30 PM · pinentry, Bug Report
mideal created T3879: passphrase dialogue: "mismatch" message not deleted during next try.
Apr 4 2018, 8:29 PM · pinentry, Bug Report
JFi created T3878: not all calloc performed in libgcrypt covered by gcry_set_allocation_handler.
Apr 4 2018, 3:05 PM · libgcrypt, Bug Report
JFi created T3877: not all malloc performed in libgcrypt covered by gcry_set_allocation_handler.
Apr 4 2018, 1:44 PM · libgcrypt, Bug Report
aheinecke triaged T3871: GpgOL-signed mail is visible as yellow closed letter even when read in non-GpgOL-Outlook as Normal priority.

Normal prio as I don't think that this is a regression.

Apr 4 2018, 10:37 AM · gpgol, Bug Report, gpg4win
aheinecke added a parent task for T3875: Sending signed mail fails repeatedly: T3864: Gpg4win-3.1.0 Release blocker.
Apr 4 2018, 9:32 AM · gpgol, Bug Report, gpg4win
aheinecke triaged T3875: Sending signed mail fails repeatedly as High priority.

Thanks for trying out the beta. I was about to open an issue about this as someone in the forum reported the same thing. https://wald.intevation.org/forum/message.php?msg_id=5759

Apr 4 2018, 9:31 AM · gpgol, Bug Report, gpg4win
JJworx created T3875: Sending signed mail fails repeatedly.
Apr 4 2018, 9:15 AM · gpgol, Bug Report, gpg4win

Apr 3 2018

bernhard added a comment to T2019: Order of magnitude degradation in performance in gpg2 cf gpg.

@dkg thanks for the link.

Apr 3 2018, 11:57 AM · Stalled, Bug Report, gnupg
gniibe added a comment to T3842: OpenPGP Smart card V2.1 returns truncated RSA signatures if leading bytes of signature are 0.

Yes, I meant the document. Please note that I am also one of users of the specification (for GnuPG, and for Gnuk Token). I am not defending, but try to explain the current situation.

Apr 3 2018, 1:30 AM · Not A Bug, scd
gniibe changed the status of T3844: Able to certify public keys without a certify key present when using smartcard. from Open to Testing.

I think that I located the bug and fixed. I wonder why Werner put gpg20 tag.

Apr 3 2018, 1:25 AM · gnupg (gpg22), Bug Report

Apr 2 2018

MSoegtrop added a comment to T3842: OpenPGP Smart card V2.1 returns truncated RSA signatures if leading bytes of signature are 0.

I was referring to this document:

Apr 2 2018, 11:25 AM · Not A Bug, scd
gniibe claimed T3844: Able to certify public keys without a certify key present when using smartcard..
Apr 2 2018, 10:43 AM · gnupg (gpg22), Bug Report
gniibe added a comment to T3842: OpenPGP Smart card V2.1 returns truncated RSA signatures if leading bytes of signature are 0.

You describe it as 'manual'. AFAIK, it's the specification for the functionality.
I have an experience implementing the functionality, following the specification.
And my own implementation does always return 512 bytes for RSA-4096. So, I could support your opinion.

Apr 2 2018, 7:16 AM · Not A Bug, scd

Apr 1 2018

patrick created T3872: Invalid --sender option does not produce parseable output.
Apr 1 2018, 12:21 PM · gnupg (gpg22), Bug Report

Mar 30 2018

gniibe changed the status of T3781: ECC encryption key on-card generation broken from Open to Testing.
Mar 30 2018, 4:52 AM · g10, scd, Bug Report
gniibe added a comment to T3781: ECC encryption key on-card generation broken.

Furthermore, I changed to have an explicit command: key-attr

Mar 30 2018, 4:52 AM · g10, scd, Bug Report

Mar 29 2018

JJworx closed T3860: Automatic check for fitting key fails as Resolved.
Mar 29 2018, 2:54 PM · Bug Report, gpg4win
JJworx added a comment to T3860: Automatic check for fitting key fails.

I can verify the problem will be solved with 3.1.0, this can be closed.

Mar 29 2018, 2:54 PM · Bug Report, gpg4win
JJworx created T3871: GpgOL-signed mail is visible as yellow closed letter even when read in non-GpgOL-Outlook.
Mar 29 2018, 2:51 PM · gpgol, Bug Report, gpg4win
gniibe triaged T3781: ECC encryption key on-card generation broken as Normal priority.

I changed the interaction so that user can specify RSA or ECC, then when it's for ECC, specifying curve.

Mar 29 2018, 6:10 AM · g10, scd, Bug Report
gniibe added a comment to T3843: Unable to generate RSA4096 keys on Yubikey 4 on OSX Sierra.

It looks like something wrong happened in scdaemon. Could you please try with following? .gnupg/scdaemon.conf

Mar 29 2018, 2:59 AM · Info Needed, MacOS, yubikey, scd, Bug Report