Page MenuHome GnuPG
Feed All Stories

May 29 2019

ostroffjh created T4547: improve error message ("Not enabled") when using Tor network and standard resolver.
May 29 2019, 11:17 PM · dirmngr, gnupg (gpg22), Bug Report
dkg added a comment to T4487: libksba: please refresh ASN.1 components from more recent RFCs with BSD licensing.

Perhaps i wasn't clear enough in the earlier messages on this thread. The inclusion of restrictively-licensed code in a file that also claims LGPL/GPL appears to be an unredistributable license. Could you please clarify why the GPL or LGPL applies to libksba while it contains src/cms.asn in its current form?

May 29 2019, 7:52 PM · libksba, Feature Request
dkg added a comment to T4545: gpg ships gpgscm but not any of the necessary *.scm files.

we've never shipped a binary gpgscm in any debian package. I was just reviewing the differences between what we ship and what upstream ships, and i noticed this discrepancy.

May 29 2019, 7:36 PM · Bug Report
ideaantenna removed projects from T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0: Enigmail, gpgagent.
May 29 2019, 7:00 PM · Not A Bug, gnupg, gpgme, Bug Report
ideaantenna updated the task description for T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0.
May 29 2019, 6:55 PM · Not A Bug, gnupg, gpgme, Bug Report
ideaantenna added projects to T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0: gpgme, gnupg.
May 29 2019, 6:52 PM · Not A Bug, gnupg, gpgme, Bug Report
ideaantenna updated the task description for T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0.
May 29 2019, 6:39 PM · Not A Bug, gnupg, gpgme, Bug Report
ideaantenna updated the task description for T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0.
May 29 2019, 6:35 PM · Not A Bug, gnupg, gpgme, Bug Report
ideaantenna created T4546: make check error on gnupg-2.2.15 and gpgme-1.13.0.
May 29 2019, 6:30 PM · Not A Bug, gnupg, gpgme, Bug Report
aheinecke committed rWbc9c730e0bf5: Revert po to native encodings (authored by aheinecke).
Revert po to native encodings
May 29 2019, 12:44 PM
aheinecke committed rWfe214b94888b: Update packages (authored by aheinecke).
Update packages
May 29 2019, 12:44 PM
aheinecke committed rW8f8754473de8: Revert NSIS merge fore makefile, too (authored by aheinecke).
Revert NSIS merge fore makefile, too
May 29 2019, 12:44 PM
aheinecke committed rW45888467977d: Fixup it encoding (authored by aheinecke).
Fixup it encoding
May 29 2019, 12:44 PM
aheinecke committed rW9d44664bb5a0: Revert encoding change for it (authored by aheinecke).
Revert encoding change for it
May 29 2019, 12:44 PM
aheinecke committed rW9eb021d35b3a: Update packages (authored by aheinecke).
Update packages
May 29 2019, 12:44 PM
aheinecke committed rLIBKLEOa6abfe39dbe2: Filter out unusabale keys ion keyapproval dlg (authored by aheinecke).
Filter out unusabale keys ion keyapproval dlg
May 29 2019, 11:00 AM
matheusmoreira added a comment to T3465: --pinentry-mode loopback with --delete-secret-keys.

I also experienced this issue while testing my --delete-secret-key patches. Passing --pinentry-program /usr/bin/pinentry-tty to the gpg-agent worked around it.

May 29 2019, 10:16 AM · gnupg, Bug Report
matheusmoreira updated the task description for T4544: More prompts before key deletion.
May 29 2019, 10:10 AM · gnupg, Feature Request, patch
matheusmoreira updated the summary of D485: gpg: add the --delete-secret-subkeys command.
May 29 2019, 10:09 AM
matheusmoreira updated the diff for D481: gpg: confirm deletion of each key individually.

Add confirmation prompt for exactly-specified public subkeys.

May 29 2019, 10:06 AM
matheusmoreira updated the diff for D488: gpg: add the --delete-secret-key-stubs command.

Add documentation.

May 29 2019, 10:05 AM
matheusmoreira updated the diff for D485: gpg: add the --delete-secret-subkeys command.

Add documentation.

May 29 2019, 10:03 AM
matheusmoreira updated the task description for T4544: More prompts before key deletion.
May 29 2019, 10:00 AM · gnupg, Feature Request, patch
werner committed rDa0794c862a03: web: Release announce for 2.2.16 (authored by werner).
web: Release announce for 2.2.16
May 29 2019, 9:28 AM
gniibe committed rG6790eaf95292: agent: Add A-flag for KEYINFO output for card. (authored by gniibe).
agent: Add A-flag for KEYINFO output for card.
May 29 2019, 9:24 AM
werner added a comment to T4536: dirmngr fails to find OCSP signer certificate when responder is identified with key ID.

Thanks, the mentioned OpenSSL option should be helpful.

May 29 2019, 9:19 AM · S/MIME, gnupg (gpg22), Bug Report
misterzed88 added a comment to T4536: dirmngr fails to find OCSP signer certificate when responder is identified with key ID.

A high level test description is:

  1. Configure both gpgsm and dirmngr to use OCSP.
  2. Import the responder signer certificate with gpgsm --import.
  3. Use a certificate with OCSP responder extension present, or configure a default OCSP responder in dirmngr.
  4. Configure your OCSP responder to identify itself with key ID (and not subject name)
  5. Attempt to sign or verify with gpgsm.
  6. You should get an error, with dirmngr logs showing that the responder signer certificate could not be found.
May 29 2019, 9:11 AM · S/MIME, gnupg (gpg22), Bug Report
misterzed88 added a comment to T4535: gpgsm --sign prints misleading error message when using default key.

Thank you for a quick fix (despite this being a minor problem).

May 29 2019, 8:51 AM · gnupg (gpg22), S/MIME, Bug Report
werner added a project to T4541: C implementation of AES is vulnerable to side-channel attacks: side-channel.
May 29 2019, 8:29 AM · side-channel, libgcrypt, Bug Report
werner set the color for side-channel to Grey.
May 29 2019, 8:29 AM
werner triaged T4541: C implementation of AES is vulnerable to side-channel attacks as Normal priority.

Thanks for taking the time to describe this attack vector. We will need to study this closer to balance such a change with other side effects of this.

May 29 2019, 8:27 AM · side-channel, libgcrypt, Bug Report
werner closed T4545: gpg ships gpgscm but not any of the necessary *.scm files as Wontfix.

gpgscm will anyway be moved to libgpg-error and then installed as part of that package. Given that we install it for quite some time with gnupg, I won't remove it unless we can be sure that it has been installed by libgpg-error. Feel free to remove it from Debian, though,

May 29 2019, 8:19 AM · Bug Report
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2019q2/000438.html on T4509: Release GnuPG 2.2.16.
May 29 2019, 8:15 AM · Release Info, gnupg (gpg22)
gniibe claimed T3465: --pinentry-mode loopback with --delete-secret-keys.

I wrote a patch in a topic branch: rG108c22c9c50a: g10,agent: Support CONFIRM for --delete-key.
I think that gpg-agent side,

  • agent/call-pinentry.c: This part is good
  • agent/command.c: I wonder if use of status for passing the information of prompt is good or not

Perhaps, we need an improvement in

  • g10/call-agent.c: how to ask user, by cpr_* function with no keyword is good?
  • Currently, only using DESC
  • Only applying to DELETE_KEY command
  • Can be applied also to:
    • PKSIGN
    • PKDECRYPT
May 29 2019, 5:30 AM · gnupg, Bug Report
gniibe changed the status of T4539: libgpg-error on Windows: strerror_s can be used instead of strerror_r from Open to Testing.

Fix pushed.

May 29 2019, 4:19 AM · gpgrt, Feature Request
gniibe committed rEa9052f7b7fe5: po: Update Japanese translation. (authored by gniibe).
po: Update Japanese translation.
May 29 2019, 4:19 AM
gniibe committed rEcd49ee71887c: Detect to use strerror_s. (authored by gniibe).
Detect to use strerror_s.
May 29 2019, 4:15 AM
gniibe claimed T4539: libgpg-error on Windows: strerror_s can be used instead of strerror_r.

I think that detecting strerror_s by configure is better, because it's a new feature on Windows.

May 29 2019, 3:54 AM · gpgrt, Feature Request
dkg committed rG175d194b5d60: doc/wks.texi: fix typo (authored by dkg).
doc/wks.texi: fix typo
May 29 2019, 3:09 AM
gniibe closed T4461: Memory leak in read_block as Resolved.
May 29 2019, 3:08 AM · Bug Report
gniibe closed T4494: UBsan finding "armor.c:1159:11: runtime error: member access within null pointer..." as Resolved.
May 29 2019, 3:06 AM · gnupg
gniibe closed T4504: Asan findings in iconv configure test causing config failure as Resolved.
May 29 2019, 3:05 AM · gpgrt, gnupg
dkg created T4545: gpg ships gpgscm but not any of the necessary *.scm files.
May 29 2019, 2:41 AM · Bug Report

May 28 2019

slandden reopened T4541: C implementation of AES is vulnerable to side-channel attacks as "Open".
May 28 2019, 8:14 PM · side-channel, libgcrypt, Bug Report
slandden closed T4541: C implementation of AES is vulnerable to side-channel attacks as Invalid.

I do not have a PoC (or much interest in making one, I have too many more important things to do), but I believe this to be correct, based heavily on PPC knowledge of Nicolas König <koenigni@student.ethz.ch> . This attack also applies to AMD, Intel, and ARM.

May 28 2019, 8:12 PM · side-channel, libgcrypt, Bug Report
werner closed T4509: Release GnuPG 2.2.16 as Resolved.
May 28 2019, 6:14 PM · Release Info, gnupg (gpg22)
werner triaged T4544: More prompts before key deletion as Low priority.
May 28 2019, 6:12 PM · gnupg, Feature Request, patch
werner committed rG6b06fb3cc550: Add changes from 2.2 to NEWS. (authored by werner).
Add changes from 2.2 to NEWS.
May 28 2019, 6:09 PM
werner committed rD47a3a0226003: swdb: GnuPG 2.2.16 (authored by werner).
swdb: GnuPG 2.2.16
May 28 2019, 6:07 PM
werner committed rD51f561f7a043: swdb: Update sqlite to 3.28 (authored by werner).
swdb: Update sqlite to 3.28
May 28 2019, 6:07 PM
werner committed rDb08fa3d7bd77: drafts,openpgp-webkey-service: Publish revision -08. (authored by werner).
drafts,openpgp-webkey-service: Publish revision -08.
May 28 2019, 6:07 PM
matheusmoreira updated the diff for D482: gpg: confirm again before deleting primary key.
May 28 2019, 5:55 PM
matheusmoreira updated the diff for D481: gpg: confirm deletion of each key individually.
May 28 2019, 5:53 PM
matheusmoreira updated the diff for D488: gpg: add the --delete-secret-key-stubs command.
May 28 2019, 5:52 PM
matheusmoreira updated the diff for D485: gpg: add the --delete-secret-subkeys command.
May 28 2019, 5:50 PM
matheusmoreira updated the diff for D480: gpg: factor out secret key deletion function.

Remove gpg_ prefix from function.

May 28 2019, 5:46 PM
matheusmoreira abandoned D483: po: add portuguese primary key deletion message.

Squashed: D482

May 28 2019, 5:43 PM
matheusmoreira abandoned D486: po: add portuguese description for new command.

Squashed: D485

May 28 2019, 5:43 PM
matheusmoreira abandoned D489: po: add portuguese translation for the new command.

Squashed: D488

May 28 2019, 5:41 PM
werner committed rGf9934dcb57ca: Post release updates (authored by werner).
Post release updates
May 28 2019, 5:40 PM
werner committed rG3f2b7a53ddc4: Release GnuPG 2.2.16 (authored by werner).
Release GnuPG 2.2.16
May 28 2019, 5:40 PM
werner committed rG626e05f07af1: po: Auto-update (authored by werner).
po: Auto-update
May 28 2019, 5:40 PM
matheusmoreira added a task to D488: gpg: add the --delete-secret-key-stubs command: T4544: More prompts before key deletion.
May 28 2019, 5:39 PM
matheusmoreira added a task to D480: gpg: factor out secret key deletion function: T4544: More prompts before key deletion.
May 28 2019, 5:39 PM
matheusmoreira added a task to D485: gpg: add the --delete-secret-subkeys command: T4544: More prompts before key deletion.
May 28 2019, 5:39 PM
matheusmoreira added revisions to T4544: More prompts before key deletion: D480: gpg: factor out secret key deletion function, D485: gpg: add the --delete-secret-subkeys command, D488: gpg: add the --delete-secret-key-stubs command, D481: gpg: confirm deletion of each key individually, D482: gpg: confirm again before deleting primary key.
May 28 2019, 5:39 PM · gnupg, Feature Request, patch
matheusmoreira added a task to D482: gpg: confirm again before deleting primary key: T4544: More prompts before key deletion.
May 28 2019, 5:39 PM
matheusmoreira added a task to D481: gpg: confirm deletion of each key individually: T4544: More prompts before key deletion.
May 28 2019, 5:39 PM
matheusmoreira abandoned D479: gpg: avoid deletion of keys not specified by user.

A better solution has been commited: cc6069ac6ecd

May 28 2019, 5:35 PM
maiden_taiwan added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

I should add that using gpg on the command line works fine over SSH. The problem occurs only inside Emacs over SSH.

May 28 2019, 5:22 PM · Emacs, Documentation, pinentry, Bug Report
matheusmoreira created T4544: More prompts before key deletion in the S1 Public space.
May 28 2019, 5:21 PM · gnupg, Feature Request, patch
maiden_taiwan added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

Ah, I added the --verbose option and got this output (sanitized by me):

May 28 2019, 5:19 PM · Emacs, Documentation, pinentry, Bug Report
werner added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

Sorry, I forgot to mention it. You need to add -v to the command line.

May 28 2019, 5:14 PM · Emacs, Documentation, pinentry, Bug Report
maiden_taiwan added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

Thank you, werner. Could you please tell me an exact GPG command to do this signing, and tell me where the output line should appear? I tried this command on the command line:

May 28 2019, 5:10 PM · Emacs, Documentation, pinentry, Bug Report
werner closed T4462: GnuPG: Segfaults trying to encrypt / locate by mbox for specific keys as Resolved.
May 28 2019, 5:08 PM · Bug Report, gnupg
werner updated the task description for T4509: Release GnuPG 2.2.16.
May 28 2019, 5:08 PM · Release Info, gnupg (gpg22)
werner closed T4510: Update our copy of SQLite to 3.28, a subtask of T4509: Release GnuPG 2.2.16, as Resolved.
May 28 2019, 5:04 PM · Release Info, gnupg (gpg22)
werner closed T4510: Update our copy of SQLite to 3.28 as Resolved.
May 28 2019, 5:04 PM · CVE
werner edited projects for T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs, added: pinentry; removed gpgagent.

Which pinentry are you using in in what mode? Please do a sign operation and watch out for a line similar to:

May 28 2019, 4:30 PM · Emacs, Documentation, pinentry, Bug Report
aheinecke committed rO2dcf132c8b6c: Always pass write in NeedsFirstAfterWrite state (authored by aheinecke).
Always pass write in NeedsFirstAfterWrite state
May 28 2019, 3:31 PM
aheinecke committed rOd3e81ef9cce0: Fix T3656 workaround for encrypted S/MIME (authored by aheinecke).
Fix T3656 workaround for encrypted S/MIME
May 28 2019, 3:31 PM
aheinecke committed rO2216aaecb56f: Fix moving / closing S/MIME mails with attachments (authored by aheinecke).
Fix moving / closing S/MIME mails with attachments
May 28 2019, 3:31 PM
aheinecke committed rO5bd3e5bd7eef: Add accessor for msgtype (authored by aheinecke).
Add accessor for msgtype
May 28 2019, 3:31 PM
aheinecke committed rO7dc8d46807c4: Use unquoted content id for related attachments (authored by aheinecke).
Use unquoted content id for related attachments
May 28 2019, 3:31 PM
aheinecke committed rO4df3dfaf43f7: Fix refcount error in rare error handler (authored by aheinecke).
Fix refcount error in rare error handler
May 28 2019, 3:31 PM
aheinecke added a comment to T4525: GpgOL: Error when moving opened S/MIME Mails with attachments on Exchange.

My understanding of this issue and the fix for it is that Outlook with exchange detects that our mails are S/MIME mails. As the attachments are modified by us outlook wants to save the changes on move. This fails because it can't do the crypto. Leading to the error. This also happens when such a mail is closed.

May 28 2019, 3:16 PM · g10code, gpg4win, Bug Report, gpgol
aheinecke created T4543: GpgOL: Moved S/MIME mails can no longer be read by other clients.
May 28 2019, 3:10 PM · g10code, S/MIME, gpg4win, gpgol
maiden_taiwan added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

I also tried adding this to my gpg-agent.conf file:

May 28 2019, 2:05 PM · Emacs, Documentation, pinentry, Bug Report
maiden_taiwan added a comment to T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.

Oh, in case it wasn't clear, the idea that another application (GNU emacs) is receiving keystrokes meant for the gpg-agent prompt is probably a security risk....

May 28 2019, 2:01 PM · Emacs, Documentation, pinentry, Bug Report
maiden_taiwan created T4542: gpg-agent loses characters when prompting for a GPG passphrase over SSH in Emacs.
May 28 2019, 2:00 PM · Emacs, Documentation, pinentry, Bug Report
aheinecke added a subtask for T4322: GpgOL: Embedded image not visible in forwarded email: T4389: Gpg4win 3.1.8.
May 28 2019, 1:20 PM · gpg4win, gpgol
aheinecke added a parent task for T4389: Gpg4win 3.1.8: T4322: GpgOL: Embedded image not visible in forwarded email.
May 28 2019, 1:20 PM · gpg4win, Release Info
aheinecke added a comment to T4322: GpgOL: Embedded image not visible in forwarded email.

We did not remove the "<>" from the content id. This worked for the first display but when forwarding they got doubled and it broke.

May 28 2019, 1:20 PM · gpg4win, gpgol
werner added a comment to T4536: dirmngr fails to find OCSP signer certificate when responder is identified with key ID.

Do you have any test cases? Note that T3966 is due to missing support for SHA-256.

May 28 2019, 12:36 PM · S/MIME, gnupg (gpg22), Bug Report
werner added a project to T4541: C implementation of AES is vulnerable to side-channel attacks: libgcrypt.

Can you please give more details and tell whether this is powerpc specific.

May 28 2019, 12:34 PM · side-channel, libgcrypt, Bug Report
werner closed T3966: Dirmngr: no suitable certificate found to verify the OCSP response as Resolved.
May 28 2019, 12:32 PM · gpg4win, dirmngr, S/MIME
werner committed rG5281ecbe3ae8: dirmngr: Allow for other hash algorithms than SHA-1 in OCSP. (authored by werner).
dirmngr: Allow for other hash algorithms than SHA-1 in OCSP.
May 28 2019, 12:32 PM
werner committed rG4699e294cc9e: dirmngr: Improve finding OCSP cert. (authored by werner).
dirmngr: Improve finding OCSP cert.
May 28 2019, 12:31 PM
werner committed rG405f41007c35: dirmngr: Allow for other hash algorithms than SHA-1 in OCSP. (authored by werner).
dirmngr: Allow for other hash algorithms than SHA-1 in OCSP.
May 28 2019, 12:31 PM
werner committed rGa2a90717466a: agent: Make an MD encoding function more robust. (authored by werner).
agent: Make an MD encoding function more robust.
May 28 2019, 12:31 PM