Page MenuHome GnuPG
Feed All Stories

Apr 8 2019

JW-D added a comment to T4451: Kleopatra: OpenPGP Smart Card decription / private key not found.

Well, I can narrow the root case. A Yubikey 5 was successfull installed and can be used. Then I started to test the OpenPGP card. I recognized, that by pressing F5 in Kleopatara a change between YubiKey and Smart Card happens. However, if I test it via command line, Yubikey does not change, although it is dismounted and the smart card is inserted. Probably therefore, the private key cannot be found. It should be mentioned that I have a computer with integrated smart card reader. First I configured the card, then the Yubikey. I started to test the Yubikey first. Therefore, I believe it is a mess in detection of smart card / Yubikey if used parallel.

Apr 8 2019, 8:02 AM · Windows, kleopatra, Bug Report, gpg4win

Apr 7 2019

JW-D created T4451: Kleopatra: OpenPGP Smart Card decription / private key not found.
Apr 7 2019, 2:25 PM · Windows, kleopatra, Bug Report, gpg4win
devnexen created D476: [libgcrypt] NetBSD support explicit_memset.
Apr 7 2019, 10:55 AM
jukivili committed rCa3683b6f6231: Add SHA512/224 and SHA512/256 algorithms (authored by jukivili).
Add SHA512/224 and SHA512/256 algorithms
Apr 7 2019, 9:32 AM
jukivili committed rCe76cd0e2b1f6: Optimizations for digest final functions (authored by jukivili).
Optimizations for digest final functions
Apr 7 2019, 9:32 AM
jukivili committed rCc6055aaccac8: Remove extra buffer flush at begining of digest final functions (authored by jukivili).
Remove extra buffer flush at begining of digest final functions
Apr 7 2019, 9:32 AM
jukivili committed rCc54b1c96c644: tests/basic: add hash test for small block sizes (authored by jukivili).
tests/basic: add hash test for small block sizes
Apr 7 2019, 9:32 AM
jukivili committed rC74ef3ecbf94e: Burn stack in transform functions for SHA2 AMD64 implementations (authored by jukivili).
Burn stack in transform functions for SHA2 AMD64 implementations
Apr 7 2019, 9:32 AM
jukivili committed rCf3d4bd90662f: Burn stack in transform functions for SHA1 AMD64 implementations (authored by jukivili).
Burn stack in transform functions for SHA1 AMD64 implementations
Apr 7 2019, 9:32 AM
jukivili committed rCb982900bfe64: Add AVX2/BMI2 implementation of SHA1 (authored by jukivili).
Add AVX2/BMI2 implementation of SHA1
Apr 7 2019, 9:32 AM
kloczek added a comment to T4415: Does not build using gcc 9.

Which one version gcc 9 you've been using?
May I see gcc -v ?

Apr 7 2019, 8:46 AM · Info Needed, toolchain, Bug Report
werner added projects to T4450: erron on gpa: gpg4win, gpa.

And please do not use Gpg4win 3.16 but the bug fixed release 3.1.7.

Apr 7 2019, 8:22 AM · Info Needed, gpa, gpg4win
werner added a comment to T4450: erron on gpa.

Please explain in detail what you did to receive this error message.

Apr 7 2019, 8:20 AM · Info Needed, gpa, gpg4win
werner added a comment to T4415: Does not build using gcc 9.

@gniibe already wrote: “With gcc-9 in Debian experimental, everything goes well.”

Apr 7 2019, 8:19 AM · Info Needed, toolchain, Bug Report

Apr 6 2019

Laurent Montel <montel@kde.org> committed rKLEOPATRA91b92fd37da9: It's already defined in FrameworkCompilerSettings (authored by Laurent Montel <montel@kde.org>).
It's already defined in FrameworkCompilerSettings
Apr 6 2019, 12:05 PM
kloczek added a comment to T4415: Does not build using gcc 9.

BTW: fedora corp provides already free access to build envs with gcc 9 which can be easily integrated with CIs.

Apr 6 2019, 8:49 AM · Info Needed, toolchain, Bug Report
kloczek added a comment to T4415: Does not build using gcc 9.

What you mean " it is not reproducible for u"?
Did you try to use gcc 9 and you had no problems compiling gnupg or you don't have access to build env with gcc 9?
Try to google to "gcc 9 pragma" and you will find several discussions and patches done by people fixing similar issues.

Apr 6 2019, 8:48 AM · Info Needed, toolchain, Bug Report
gniibe added a project to T4415: Does not build using gcc 9: Info Needed.
Apr 6 2019, 3:58 AM · Info Needed, toolchain, Bug Report
gniibe added a comment to T4415: Does not build using gcc 9.

@kloczek , it is not reproducible for us, so, we consider it may be a problem other than GnuPG itself, possibly, some specific build configuration parameter(s) for GCC, or something by unreleased code.
Please file a report with how to reproduce your problem.

Apr 6 2019, 3:57 AM · Info Needed, toolchain, Bug Report
sapienza created T4450: erron on gpa.
Apr 6 2019, 12:11 AM · Info Needed, gpa, gpg4win

Apr 5 2019

werner added a comment to T4448: Add "Autocrypt" key-origin.
  • If the original key origin is a KEYSERVER or WKD it is fine to fetch an update of the key from a keyserver/wkd without user interaction.
  • if the key origin is file it can be assumed that the key has bee received hand to hand and thus the existence of that key should not be made public.
Apr 5 2019, 5:12 PM · Feature Request
werner closed T4377: gpg-agent does not anymore restart a killed scdaemon as Resolved.

I did lot of tests in the last weeks while working on gpg-card.

Apr 5 2019, 5:07 PM · gnupg (gpg23), gpgagent, scd
patrick added a comment to T4448: Add "Autocrypt" key-origin.

I did not yet implement the use of "key origin" in Enigmail. I don't believe that it adds much value, because I anyway need to track more details about autocrypt keys separately from the keyring (such as the peer-state).

Apr 5 2019, 5:07 PM · Feature Request
werner placed T4312: Paypal account for GnuPG e.V. up for grabs.
Apr 5 2019, 5:06 PM · Verein
werner closed T3801: gpg --import cannot display user ID as Resolved.

Well, it took long to fix. My original plan was to fix it while reworking getkey.c but that I have not yet come to work on that.

Apr 5 2019, 5:05 PM · gnupg (gpg23)
werner committed rGea32842d5c2e: gpg: Fix printing of the user id during import. (authored by werner).
gpg: Fix printing of the user id during import.
Apr 5 2019, 5:04 PM
dkg added a comment to T4448: Add "Autocrypt" key-origin.

does the proposed mail value indicate that the key was received over e-mail, or is it intended to have some more nuanced semantics?

Apr 5 2019, 4:47 PM · Feature Request
Valodim added a comment to T4448: Add "Autocrypt" key-origin.

I disagree that it's conceptionally the same, unless you also consider any key on an HTTP server to be "conceptionally the same" as WKD.

Apr 5 2019, 4:34 PM · Feature Request
werner added a comment to T4448: Add "Autocrypt" key-origin.

Conceptionally it is the same. You receive a key and start to use it, everything else is not a matter of gpg; in particular not the autocrypt protocol.

Apr 5 2019, 4:26 PM · Feature Request
Valodim added a comment to T4448: Add "Autocrypt" key-origin.

Certain origins do have special treatment but in general the key origin is meta data for the frontend.

Apr 5 2019, 10:56 AM · Feature Request
aheinecke updated subscribers of T4448: Add "Autocrypt" key-origin.

I agree with you and GpgOL handles it that way so for me this would work. But I'm not actually implementing autocrypt, so I also added @patrick to the subscribers.
I've talked about using key-origin in Enigmail with him in Brussels and I would be interested what he thinks Enigmail might require and if gpg could be improved for that.

Apr 5 2019, 9:29 AM · Feature Request
kloczek added a comment to T4415: Does not build using gcc 9.

Why do you think that it is gcc bug?

Apr 5 2019, 9:29 AM · Info Needed, toolchain, Bug Report
werner triaged T4448: Add "Autocrypt" key-origin as Normal priority.
Apr 5 2019, 9:27 AM · Feature Request
werner triaged T4415: Does not build using gcc 9 as Normal priority.

So this seems to be a gcc bug, right. Then we should close this bug.

Apr 5 2019, 9:26 AM · Info Needed, toolchain, Bug Report
werner changed the edit policy for toolchain.
Apr 5 2019, 9:26 AM
werner triaged T4374: unable to login to gnupg.org with a twitter account as Normal priority.
Apr 5 2019, 9:21 AM · dev.gnupg.org
werner added a comment to T4448: Add "Autocrypt" key-origin.

autocrypt is not different from attaching a file to a (signed) message as it has always been done. We have no special treatment for that in gpg. Certain origins do have special treatment but in general the key origin is meta data for the frontend. For example it allows us to update a key received from WKD when it has expired.

Apr 5 2019, 9:18 AM · Feature Request
werner triaged T4447: Fix addition of new GPG keys to LDAP as High priority.
Apr 5 2019, 9:07 AM · gnupg (gpg23), patch, LDAP, dirmngr, Bug Report
aheinecke closed T4449: Configurable timer for having-to-input passphrase via "kleopatra" as Resolved.

Hi,
if I don't misunderstand you, we already have that:

Apr 5 2019, 8:41 AM · Feature Request
aheinecke added a comment to T4448: Add "Autocrypt" key-origin.

My interpretation of the key-origin is that it's basically up to the application what it does with the information. It is added information, like the TOFU history we can have. I don't necessarily think in terms of "trustworthyness".

Apr 5 2019, 8:36 AM · Feature Request
esdee created T4449: Configurable timer for having-to-input passphrase via "kleopatra".
Apr 5 2019, 8:15 AM · Feature Request

Apr 4 2019

Valodim added a comment to T4448: Add "Autocrypt" key-origin.

I'm a bit confused. The origin of Autocrypt keys is clearly different from keyservers ("ks"), why would they use the same value? I was aware that origin values are mapped to integers, but your description seems to imply that these integers have significant ordering in terms of trust. The documentation in the man page is a bit bare bones, but my interpretation of "key-origin" was that it simply stated the method of discovery for a key, leaving any implications of trust to the client. Is this incorrect?

Apr 4 2019, 7:23 PM · Feature Request
dkg added a comment to T4448: Add "Autocrypt" key-origin.

@werner: what if the autocrypt header is in a dkim-signed message, and the dkim signature covers the autocrypt header, and the dkim signature is verifiable using dnssec? is it still the same as from a keyserver?

Apr 4 2019, 6:32 PM · Feature Request
werner added a comment to T4448: Add "Autocrypt" key-origin.

Receiving a key by mail should in general be considered unknown and is not more trustworthy than receiving a key from a keyserver. I would suggest that you use "ks-pref" for this purpose. That origin value has no special meaning in gnupg but is numerical ordered between keyserver and and DANE; gpgme currently maps it to keyserver level anyway.

Apr 4 2019, 5:50 PM · Feature Request
werner committed rG958172cc3acb: scd:piv: Fix RSA decryption. (authored by werner).
scd:piv: Fix RSA decryption.
Apr 4 2019, 12:53 PM
werner committed rG310944aa3797: doc: Minor change to the included yat2m. (authored by werner).
doc: Minor change to the included yat2m.
Apr 4 2019, 12:53 PM
werner committed rE86cb22ad3b7a: yat2m: Change style for @samp and add @kbd. (authored by werner).
yat2m: Change style for @samp and add @kbd.
Apr 4 2019, 12:31 PM
Valodim renamed T4448: Add "Autocrypt" key-origin from Add "Autocrypt" origin to Add "Autocrypt" key-origin.
Apr 4 2019, 11:06 AM · Feature Request
Valodim created T4448: Add "Autocrypt" key-origin.
Apr 4 2019, 11:05 AM · Feature Request
gniibe committed rGf1cf799a37f3: scd: Better handling of timeout and time extension. (authored by gniibe).
scd: Better handling of timeout and time extension.
Apr 4 2019, 9:02 AM

Apr 3 2019

werner triaged T4446: please add --quick-revoke-subkey as Normal priority.
Apr 3 2019, 10:46 PM · Restricted Project, gnupg24, Feature Request
jukivili added a comment to T3786: Unexpectedly slow decryption for AEAD (and CFB).

This is largely solved.

Apr 3 2019, 9:33 PM · gnupg (gpg23), Bug Report
werner committed rG2c9b68f28de1: gpg: Improve the code to decrypt using PIV cards. (authored by werner).
gpg: Improve the code to decrypt using PIV cards.
Apr 3 2019, 5:46 PM
werner committed rG679b8f1c0454: scd: New options --info and --info-only for READKEY. (authored by werner).
scd: New options --info and --info-only for READKEY.
Apr 3 2019, 5:46 PM
werner committed rG2b1135cf920c: scd: New standard attributes $ENCRKEYID and $SIGNKEYID. (authored by werner).
scd: New standard attributes $ENCRKEYID and $SIGNKEYID.
Apr 3 2019, 3:33 PM
werner committed rGec6a6779236a: gpg: Allow decryption using PIV cards. (authored by werner).
gpg: Allow decryption using PIV cards.
Apr 3 2019, 3:33 PM
gray created T4447: Fix addition of new GPG keys to LDAP.
Apr 3 2019, 11:27 AM · gnupg (gpg23), patch, LDAP, dirmngr, Bug Report
werner committed rG1f688e0d1dba: gpg: Avoid endless loop if a card's serial number can't be read. (authored by werner).
gpg: Avoid endless loop if a card's serial number can't be read.
Apr 3 2019, 11:26 AM
gray created D475: Fix addition of new GPG keys to LDAP.
Apr 3 2019, 11:19 AM
ap4y added a comment to T4009: POLDI: Support for EC (nist, brainpool, at least).

I implemented support for ECC and DSA public keys in poldi. Tested with ECC (curve 25519) key on Gnuk smartcard (Nitrokey Start).

Apr 3 2019, 11:07 AM · poldi, Feature Request
werner committed rGbcca3acb87c3: card: Allow card selection with LIST. (authored by werner).
card: Allow card selection with LIST.
Apr 3 2019, 11:04 AM
werner committed rG2d3392c147a2: gpg: Print modern style key info for non-decryptable keys. (authored by werner).
gpg: Print modern style key info for non-decryptable keys.
Apr 3 2019, 11:04 AM

Apr 2 2019

werner committed rGa480182f9d7e: gpg: Allow direct key generation from card with --full-gen-key. (authored by werner).
gpg: Allow direct key generation from card with --full-gen-key.
Apr 2 2019, 6:57 PM
werner committed rGf95222604382: common: Extend function pubkey_algo_string. (authored by werner).
common: Extend function pubkey_algo_string.
Apr 2 2019, 6:57 PM
dkg created T4446: please add --quick-revoke-subkey.
Apr 2 2019, 5:41 PM · Restricted Project, gnupg24, Feature Request
werner committed rGcb2065967465: scd: Add dummy option --application-priority. (authored by werner).
scd: Add dummy option --application-priority.
Apr 2 2019, 1:32 PM
werner committed rG48e7977709b6: dirmngr: Improve domaininfo cache update algorithm. (authored by werner).
dirmngr: Improve domaininfo cache update algorithm.
Apr 2 2019, 1:32 PM
werner committed rG0a30ce036a61: dirmngr: Better error code for http status 413. (authored by werner).
dirmngr: Better error code for http status 413.
Apr 2 2019, 1:32 PM
werner committed rGe100ace7f8a7: dirmngr: Improve domaininfo cache update algorithm. (authored by werner).
dirmngr: Improve domaininfo cache update algorithm.
Apr 2 2019, 1:23 PM
aheinecke committed rW4ae7f364f519: Minor update of pkg-copyright for 2019 (authored by aheinecke).
Minor update of pkg-copyright for 2019
Apr 2 2019, 8:35 AM
aheinecke committed rW358c291f558f: web: Update license pages (authored by aheinecke).
web: Update license pages
Apr 2 2019, 8:35 AM

Apr 1 2019

jukivili placed T4425: libgcrypt relocation error on aarch64 up for grabs.

I think commit https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=09c27280cc09798d15369b3a143036b7ab5ddd69 should be backported to 1.8 branch of libgcrypt.

Apr 1 2019, 9:16 PM · asm, libgcrypt, Bug Report
robbat2 added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

HTTP/1.1 spec, RFC 7230, Section 5.4, paragraph 2:
https://tools.ietf.org/html/rfc7230#section-5.4

Apr 1 2019, 8:24 PM · Keyserver, dns, dirmngr, Bug Report
werner added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

Please be so kind and point me to the specs stating that you should put the IP address into Host:

Apr 1 2019, 8:01 PM · Keyserver, dns, dirmngr, Bug Report
werner committed rG9ed1aa56c4bb: sm: Show the usage flags when generating a key from a card. (authored by werner).
sm: Show the usage flags when generating a key from a card.
Apr 1 2019, 7:59 PM
werner committed rGe47524c34a2a: gpg: Prepare card code to allow other than OpenPGP cards. (authored by werner).
gpg: Prepare card code to allow other than OpenPGP cards.
Apr 1 2019, 7:59 PM
werner committed rG0fad61de159a: gpg: New card function agent_scd_keypairinfo. (authored by werner).
gpg: New card function agent_scd_keypairinfo.
Apr 1 2019, 7:59 PM
werner committed rG334b16b868e7: gpg: Remove two unused card related functions. (authored by werner).
gpg: Remove two unused card related functions.
Apr 1 2019, 6:35 PM
werner committed rG3a4534d82682: gpg: Remove unused arg in a card related function. (authored by werner).
gpg: Remove unused arg in a card related function.
Apr 1 2019, 6:35 PM
robbat2 added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

It's up to GPG to send the Host header that shows the user's intent.

Apr 1 2019, 6:20 PM · Keyserver, dns, dirmngr, Bug Report
dkg committed rG5b1b5be65f34: NEWS: correct typo in header (authored by dkg).
NEWS: correct typo in header
Apr 1 2019, 4:36 PM
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

Here's an ugly hack to make this work (patch based on v2.2.15).

Apr 1 2019, 2:24 PM · Restricted Project, Feature Request, gnupg
werner added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

So in short you want:

  1. Allow to specify a keyserver by IP without any DNS lookups.
  2. When connecting via IP use the IP address for Host:.
Apr 1 2019, 12:55 PM · Keyserver, dns, dirmngr, Bug Report
aheinecke committed rKLEOPATRAc591cb20edfe: Persist expand state in keytreevie (authored by aheinecke).
Persist expand state in keytreevie
Apr 1 2019, 11:11 AM
werner closed T4268: Provide a method to build a simple WKD server filestructure on Windows as Resolved.
Apr 1 2019, 10:58 AM · wkd, Windows
werner created T4445: New feature to list keys signed by a certain key..
Apr 1 2019, 10:56 AM · gnupg24, Feature Request, gnupg (gpg23)
werner triaged T4443: IPv6 address with scope not accepted as keyserver as Normal priority.
Apr 1 2019, 10:24 AM · gnupg24, dirmngr, dns, Bug Report
bernhard added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

@werner
It is good practive to open a public ticket for many projects, because otherwise the XMPP users don't know if the fact is already known, reported or being worked on. Alternatively: Let us document the procedure in public what someone should do, if the xmpp server ist down or the certificate is expired. What is that procedure?

Apr 1 2019, 10:24 AM
werner closed T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29 as Resolved.

Right, no need to open a ticket. Jens has no account here anyway.

Apr 1 2019, 10:22 AM
aheinecke added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

I gave the usual ping. Yes I'm note sure why it's not automated. Our jabber server is hosted by a volunteer so it is not in our hands.

Apr 1 2019, 8:47 AM
bernhard added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

As it ran out again before this issue got officially closed, I'll reopen it with an extended title.
Wasn't the idea to automate this somehow? >:)

Apr 1 2019, 8:39 AM
bernhard renamed T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29 from jabber.quux.de certificate ran out 2019-01-28 to jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.
Apr 1 2019, 8:38 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA6440f4564f7f: Merge remote-tracking branch 'origin/Applications/19.04' (authored by Laurent Montel <montel@kde.org>).
Merge remote-tracking branch 'origin/Applications/19.04'
Apr 1 2019, 7:47 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA453056d826c8: Convert to camelcase include (authored by Laurent Montel <montel@kde.org>).
Convert to camelcase include
Apr 1 2019, 7:47 AM

Mar 31 2019

robbat2 created T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.
Mar 31 2019, 10:35 PM · Keyserver, dns, dirmngr, Bug Report
robbat2 created T4443: IPv6 address with scope not accepted as keyserver.
Mar 31 2019, 9:41 PM · gnupg24, dirmngr, dns, Bug Report
jukivili committed rCced7508c857c: blowfish: add three rounds parallel handling to generic C implementation (authored by jukivili).
blowfish: add three rounds parallel handling to generic C implementation
Mar 31 2019, 9:13 PM
jukivili committed rC4ec566b3689e: cast5: add three rounds parallel handling to generic C implementation (authored by jukivili).
cast5: add three rounds parallel handling to generic C implementation
Mar 31 2019, 9:13 PM
jukivili committed rC8a0e68be1020: cast5: read Kr four blocks at time and shift for current round (authored by jukivili).
cast5: read Kr four blocks at time and shift for current round
Mar 31 2019, 9:13 PM
jukivili committed rC0fe918fa897c: Add helper function for adding value to cipher block (authored by jukivili).
Add helper function for adding value to cipher block
Mar 31 2019, 9:13 PM