Page MenuHome GnuPG
Feed All Stories

Jun 13 2018

werner committed rC5600d2d6b236: Release 1.8.3 (authored by werner).
Release 1.8.3
Jun 13 2018, 10:01 AM
Eagle_Erwin committed rO11b39fb70f14: Update Dutch translation. (authored by Eagle_Erwin).
Update Dutch translation.
Jun 13 2018, 9:08 AM
gniibe added a comment to T4011: CVE-2018-0495.

Pushed fixes to the repository at 16:00+0900 (09:00+0200). It's 0700Z.

Jun 13 2018, 9:05 AM · CVE, libgcrypt
gniibe committed rC9be06c6b2e5c: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe committed rC9010d1576e27: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe committed rC325ab0b312e6: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe added a comment to T4011: CVE-2018-0495.

In master, it's

commit 9010d1576e278a4274ad3f4aa15776c28f6ba965
Author: NIIBE Yutaka <gniibe@fsij.org>
Date:   Wed Jun 13 15:28:58 2018 +0900
Jun 13 2018, 8:59 AM · CVE, libgcrypt
gniibe updated the task description for T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:09 AM · dirmngr, gnupg
gniibe renamed T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1 from dirmngr/dns.c issue with dnsmasq to dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:08 AM · dirmngr, gnupg
werner updated the task description for T4016: Libgcrypt release 1.8.3.
Jun 13 2018, 8:07 AM · Release Info, CVE, libgcrypt
werner added a comment to T4016: Libgcrypt release 1.8.3.

1.8.3 has not yet been released and thus there is no NEWS entries and there can't be a 1.8.3 tag. You are right that the README still says 1.7. I'll fix that for 1.8.3. Why do you think maintenance of 1.7 stopped; the AUTHORS file and the new EOL statements on the download page say that we are going to maintain it until 2019-06-30.

Jun 13 2018, 8:06 AM · Release Info, CVE, libgcrypt
gniibe created T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:02 AM · dirmngr, gnupg
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

What about another record type for standalone revocations, something line "rev0" or "revx"? This would solve the problem on how to distinguish merged revocation signatures (ie with a preceding "pub") from standalone revocations.

Jun 13 2018, 7:58 AM · gnupg, Bug Report
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

can i get a confirmation that the options you're considering for --with-colons --show-keys when confronted with a revocation certificate will be either:

Jun 13 2018, 12:16 AM · gnupg, Bug Report

Jun 12 2018

RAmbidge added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

@tinkerwolf This is weird... I've reinstalled my PC from scratch with an initial account set as local, and was able to set up GPG4Win perfectly fine for the first time on my PC (as I did in the VM). So, set up a VM with an initial account set up from an online account. GPG4Win started up fine... I am now really confused!! Somewhere within the getting set up with an online account, something has to be happening that interferes with dirmngr..
Will investigate further.

Jun 12 2018, 11:24 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

@RAmbidge are you able to further test this by using a VM with a MS account? I don't have the means right now, or I'd do it myself.

Jun 12 2018, 4:18 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
werner committed rGcb52eb76b3ba: Some preparations to eventuallt use gpgrt_argparse. (authored by werner).
Some preparations to eventuallt use gpgrt_argparse.
Jun 12 2018, 4:13 PM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

By "dummy pub line" I think you're proposing output that looks something like this instead of just the rev: line.:

Jun 12 2018, 3:47 PM · gnupg, Bug Report
aheinecke committed rW057c37ca1d87: Update libkleo kleopatra and kde-l10n (authored by aheinecke).
Update libkleo kleopatra and kde-l10n
Jun 12 2018, 2:24 PM
aheinecke committed rOe9839bebf322: po: Update portugese translation (authored by aheinecke).
po: Update portugese translation
Jun 12 2018, 2:15 PM
werner committed rG440472663d60: Require libgpg-error 1.29 and remove internal logging functions. (authored by werner).
Require libgpg-error 1.29 and remove internal logging functions.
Jun 12 2018, 1:45 PM
aheinecke committed rO2d63f5839887: po: Update german translation (authored by aheinecke).
po: Update german translation
Jun 12 2018, 1:41 PM
werner updated subscribers of T4011: CVE-2018-0495.

Publication is planned for the 13th, 1500Z

Jun 12 2018, 1:12 PM · CVE, libgcrypt
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

As long as we don't check the signature we don't need the pubkey. That would make it actually easier becuase we have only one case and not 3 or more (bad signature, no pubkey, etc).

Jun 12 2018, 1:10 PM · gnupg, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

That actually makes sense, because it works fine on my laptop, where it's been a local account from the start, but it's broken on my desktop where it was originally a MS account, but is now local.

Jun 12 2018, 12:44 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
aheinecke committed rO28a7464d13c0: Remove engine.c from potfiles (authored by aheinecke).
Remove engine.c from potfiles
Jun 12 2018, 11:19 AM
aheinecke committed rOc02b9f60f970: Auto update po files (authored by aheinecke).
Auto update po files
Jun 12 2018, 11:19 AM
aheinecke committed rO30f7ea667190: Remove removed bitmaps from extra dist (authored by aheinecke).
Remove removed bitmaps from extra dist
Jun 12 2018, 11:19 AM
aheinecke committed rKLEOPATRA9956e1ce8820: Bump patch version (authored by aheinecke).
Bump patch version
Jun 12 2018, 11:10 AM
aheinecke closed T3978: GpgOL: Problem with automatic resolution of ambigous keys as Resolved.

Fixed with https://commits.kde.org/libkleo/79f0cb79817e44b4eab864c573740c1501e796bd

Jun 12 2018, 11:07 AM · Bug Report, gpgol
aheinecke closed T3978: GpgOL: Problem with automatic resolution of ambigous keys, a subtask of T3925: Gpg4win 3.1.2, as Resolved.
Jun 12 2018, 11:07 AM · gpg4win
aheinecke committed rWf95ad3988662: Update gpgme and gnupg for testing (authored by aheinecke).
Update gpgme and gnupg for testing
Jun 12 2018, 10:06 AM
aheinecke committed rKLEOPATRA199c7cd53841: Change icon to open selection dlg in lineedit (authored by aheinecke).
Change icon to open selection dlg in lineedit
Jun 12 2018, 10:05 AM
gniibe renamed T4004: Curve25519 for Zeitcontrol card from Curve22519 for Zeitcontrol card to Curve25519 for Zeitcontrol card.
Jun 12 2018, 9:51 AM · Feature Request, scd
gniibe committed rG92d3dc9e1933: g10: Fix enum_secret_keys for card keys. (authored by gniibe).
g10: Fix enum_secret_keys for card keys.
Jun 12 2018, 9:22 AM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

Revocation certificates consist of *only* the revocation packet, right? Claiming that the revocation cert contains more than the revocation packet (when it doesn't) seems more troubling from an API perspective than just telling people to expect a single rev: line if they are looking at a revocation certificate.

Jun 12 2018, 9:12 AM · gnupg, Bug Report
werner closed T4019: --export-filter drop-subkey filter type should have usage option property as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Feature Request
werner closed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Bug Report
werner committed rGfe621cc64b13: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:06 AM
aheinecke created T4020: GnuPG: Add Error or Warning if a --passphrase option is used without pinentry-mode loopback.
Jun 12 2018, 9:05 AM · gpg4win, gnupg
werner committed rGe8f439e05474: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:05 AM
werner committed rG86b64876bef0: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 9:05 AM
dkg added a comment to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).

thanks for looking into this so quickly. where is your patch? i don't see it on the master branch yet.

Jun 12 2018, 9:05 AM · gnupg, Bug Report
werner claimed T4018: gpg --with-colons --show-keys does not show revocation certificates.

That will be a bit of work. We can't list a standalone key yet because the the key listing code expects a public or secret key as first packet. Further it would be advisable to insert a dummy "pub" key record before the "rev" record because the advise as always been to use "pub" or "sec" as start of a key keyblock.

Jun 12 2018, 9:02 AM · gnupg, Bug Report
gniibe committed rG8f99299a54a0: card: Fix memory leak for fetch-url sub command. (authored by gniibe).
card: Fix memory leak for fetch-url sub command.
Jun 12 2018, 8:55 AM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

ee1fc420fb9741b2cfaea6fa820a00be2923f514 contains a proposed fix for this.

Jun 12 2018, 8:50 AM · gnupg, Bug Report
dkg committed rGee1fc420fb97: gpg: Print revocation certificate details when showing with-colons. (authored by dkg).
gpg: Print revocation certificate details when showing with-colons.
Jun 12 2018, 8:48 AM
werner added projects to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`): gnupg, backport.

Thanks for reporting and your patch. However, I used a different way to solve this bug.

Jun 12 2018, 8:46 AM · gnupg, Bug Report
werner triaged T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as High priority.
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner claimed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner triaged T4018: gpg --with-colons --show-keys does not show revocation certificates as High priority.
Jun 12 2018, 8:22 AM · gnupg, Bug Report
werner triaged T4019: --export-filter drop-subkey filter type should have usage option property as Normal priority.

Thanks. Pushed to master. I think it should also go into 2.2.

Jun 12 2018, 8:21 AM · gnupg, Feature Request
werner committed rG2ddfb5bef920: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 8:19 AM
dkg added a comment to T4019: --export-filter drop-subkey filter type should have usage option property.

I've just pushed e037657edaf0b3ee9d2e30f6fe3edf6879976472 on the fix-T4019 branch

Jun 12 2018, 6:49 AM · gnupg, Feature Request
dkg committed rGe037657edaf0: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 6:49 AM
dkg renamed T4019: --export-filter drop-subkey filter type should have usage option property from --export-filter drop-subkey filter type should have usage_flag option property to --export-filter drop-subkey filter type should have usage option property.
Jun 12 2018, 6:43 AM · gnupg, Feature Request
gniibe committed rGba7e934945a5: g10: Move enum_secret_keys to skclist.c. (authored by gniibe).
g10: Move enum_secret_keys to skclist.c.
Jun 12 2018, 6:01 AM
gniibe committed rGed9030cb2a67: g10: Prefer to available card keys for decryption. (authored by gniibe).
g10: Prefer to available card keys for decryption.
Jun 12 2018, 6:01 AM
gniibe committed rGb0c00ce0af1b: g10: Fix comment of enum_secret_keys. (authored by gniibe).
g10: Fix comment of enum_secret_keys.
Jun 12 2018, 6:01 AM
dkg created T4019: --export-filter drop-subkey filter type should have usage option property.
Jun 12 2018, 3:41 AM · gnupg, Feature Request
dkg updated the task description for T4018: gpg --with-colons --show-keys does not show revocation certificates.
Jun 12 2018, 1:11 AM · gnupg, Bug Report
dkg added a comment to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).

see e051c279216ecd4ec9a48e13ccc695f5ab667b2a

Jun 12 2018, 1:02 AM · gnupg, Bug Report
dkg committed rGe051c279216e: gpg: set full --dry-run when used with --show-keys (authored by dkg).
gpg: set full --dry-run when used with --show-keys
Jun 12 2018, 1:02 AM
dkg added a comment to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).

I note that --import-options show-only --import has the same effect as --show-keys -- that is, the revocation cert is imported. so the error is in the import-options code itself. I'll push a fix-T4017 branch shortly with a proposed correction.

Jun 12 2018, 1:00 AM · gnupg, Bug Report

Jun 11 2018

olf added a comment to T4016: Libgcrypt release 1.8.3.

I just noticed, that a tag for Libgcrypt 1.8.3 seems to be missing: https://dev.gnupg.org/source/libgcrypt/tags/LIBGCRYPT-1.8-BRANCH/

Jun 11 2018, 11:36 PM · Release Info, CVE, libgcrypt
dkg created T4018: gpg --with-colons --show-keys does not show revocation certificates in the S1 Public space.
Jun 11 2018, 11:34 PM · gnupg, Bug Report
dkg created T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).
Jun 11 2018, 11:10 PM · gnupg, Bug Report
werner committed rC846f8fe8b3be: ecc: Improve gcry_mpi_ec_curve_point (authored by werner).
ecc: Improve gcry_mpi_ec_curve_point
Jun 11 2018, 7:19 PM
werner committed rC54620a27f450: mpi: New internal function _gcry_mpi_cmpabs. (authored by werner).
mpi: New internal function _gcry_mpi_cmpabs.
Jun 11 2018, 7:19 PM
werner added a comment to T3986: GpgOL: Mitigate manipulations of encrypted S/MIME mails.

Thanks for the writeup. Maybe this could be the base for a gnupg.org/blog article.

Jun 11 2018, 6:56 PM · gpg4win, gpgol
aheinecke committed rOc9a173782e33: Clean reply / forwards of unsigned S/MIME Mails (authored by aheinecke).
Clean reply / forwards of unsigned S/MIME Mails
Jun 11 2018, 6:54 PM
aheinecke committed rOa1a0f0aa53b0: Extend mail class for better reply/forward handling (authored by aheinecke).
Extend mail class for better reply/forward handling
Jun 11 2018, 6:54 PM
aheinecke committed rO49cc27fd092d: Improve unsigned S/MIME HTML handling (authored by aheinecke).
Improve unsigned S/MIME HTML handling
Jun 11 2018, 6:54 PM
aheinecke committed rO5a2f1ac5880d: Cleanup unused options and add a warning shown opt (authored by aheinecke).
Cleanup unused options and add a warning shown opt
Jun 11 2018, 6:54 PM
aheinecke added a comment to T3986: GpgOL: Mitigate manipulations of encrypted S/MIME mails.

Here is what we have now. We decided explictly not to offer a "yes I want to do something less secure" button as we think that using Unsigned S/MIME Mails is avoidable. Also we want to be more secure by default then Outlook. From a User Experience standpoint a "Yes more convenient but less secure" button basically educates users to always select that button.

Jun 11 2018, 6:15 PM · gpg4win, gpgol
mkrambach committed rMe154554e9a48: js: removed config (authored by mkrambach).
js: removed config
Jun 11 2018, 3:12 PM
werner committed rD51549ca5dbdc: web: Announce 1.4.23 (authored by werner).
web: Announce 1.4.23
Jun 11 2018, 1:31 PM
mkrambach committed rMe97e6c06e950: js: Add key creation to Keyring (authored by mkrambach).
js: Add key creation to Keyring
Jun 11 2018, 12:14 PM
werner closed T4012: Diagnostic is shown with the original filename not being sanitized. as Resolved.
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner renamed T4012: Diagnostic is shown with the original filename not being sanitized. from Diagnostic is shown with the original filename not beeing sanitized. to Diagnostic is shown with the original filename not being sanitized..
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner closed T4015: Release 1.4.23, a subtask of T4012: Diagnostic is shown with the original filename not being sanitized., as Resolved.
Jun 11 2018, 11:23 AM · gnupg, CVE, Bug Report
werner closed T4015: Release 1.4.23 as Resolved.
Jun 11 2018, 11:23 AM · Release Info, gnupg (gpg14), CVE
werner committed rD71724d3c3baf: swdb: Release of Gnupg 1.4.23 (authored by werner).
swdb: Release of Gnupg 1.4.23
Jun 11 2018, 11:16 AM
werner committed rGf32dbf396ae7: Post release updates (authored by werner).
Post release updates
Jun 11 2018, 11:10 AM
werner committed rG8ae6a246bef5: Release 1.4.23 (authored by werner).
Release 1.4.23
Jun 11 2018, 11:10 AM
werner committed rGdd6192bfea80: po: Auto update (authored by werner).
po: Auto update
Jun 11 2018, 11:10 AM
werner added a project to T4015: Release 1.4.23: Release Info.
Jun 11 2018, 9:59 AM · Release Info, gnupg (gpg14), CVE
werner added a project to T4016: Libgcrypt release 1.8.3: Release Info.
Jun 11 2018, 9:58 AM · Release Info, CVE, libgcrypt
werner set the color for Release Info to Pink.
Jun 11 2018, 9:58 AM
werner changed the edit policy for T4016: Libgcrypt release 1.8.3.
Jun 11 2018, 9:55 AM · Release Info, CVE, libgcrypt
werner created T4015: Release 1.4.23.
Jun 11 2018, 9:52 AM · Release Info, gnupg (gpg14), CVE
werner renamed T4012: Diagnostic is shown with the original filename not being sanitized. from Diagnostic with original filename is not sanitized. to Diagnostic is shown with the original filename not beeing sanitized..
Jun 11 2018, 9:50 AM · gnupg, CVE, Bug Report
werner committed rG615b9d1fb779: doc: Include release info from 2.2.8 (authored by werner).
doc: Include release info from 2.2.8
Jun 11 2018, 9:04 AM
werner committed rGdc96fd883571: doc: Mention new command --show-keys in the 2.2.7 NEWS. (authored by werner).
doc: Mention new command --show-keys in the 2.2.7 NEWS.
Jun 11 2018, 9:04 AM
werner committed rGcbb84b336126: gpg: Set some list options with --show-keys (authored by werner).
gpg: Set some list options with --show-keys
Jun 11 2018, 8:58 AM
werner committed rGd2bc66f241a6: gpg: Set some list options with --show-keys (authored by werner).
gpg: Set some list options with --show-keys
Jun 11 2018, 8:57 AM
gniibe closed T3844: Able to certify public keys without a certify key present when using smartcard. as Resolved.

Yes, closing.

Jun 11 2018, 8:41 AM · gnupg (gpg22), Bug Report
gniibe committed rGc03a3eb01d2d: g10: Enumerated keys for decryption should be unique. (authored by gniibe).
g10: Enumerated keys for decryption should be unique.
Jun 11 2018, 8:01 AM
RAmbidge added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

I'm having the same issue. I read somewhere that it's likely caused by using an online Windows account to login with. So I converted to local log in. Issue persists. As a test, I've just set up a VM with a local account set up at install, and GPG4Win works perfectly fine. So I'm guessing that there may be an issue which stays in the files system caused by online account users. I'm not a programmer and have no idea how or where to look to see what's causing it and how to fix it though.

Jun 11 2018, 1:04 AM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report

Jun 10 2018

werner committed rD031285b8ea7d: donations: Use a tag cloud for all years (authored by werner).
donations: Use a tag cloud for all years
Jun 10 2018, 7:31 PM