Page MenuHome GnuPG
Feed Advanced Search

Aug 12 2020

werner committed rG2af884c64354: scd: Log info about CCIDs with permission problems. (authored by werner).
scd: Log info about CCIDs with permission problems.
Aug 12 2020, 4:45 PM
werner committed rG9a8d7e41bba1: scd: Map some error codes from libusb to ccid-driver error codes. (authored by werner).
scd: Map some error codes from libusb to ccid-driver error codes.
Aug 12 2020, 4:45 PM
werner closed T5016: Gnupg should support WAYLAND_DISPLAY variable for pinentry as Resolved.

Thanks. Added to 2.2.

Aug 12 2020, 9:30 AM · gnupg (gpg20), Feature Request
werner committed rG3cf920a1e353: common: Pass the WAYLAND_DISPLAY envvar along (authored by werner).
common: Pass the WAYLAND_DISPLAY envvar along
Aug 12 2020, 9:30 AM
werner committed rG3944430ffeaa: common: Pass the WAYLAND_DISPLAY envvar along (authored by werner).
common: Pass the WAYLAND_DISPLAY envvar along
Aug 12 2020, 9:28 AM
werner triaged T5021: Trying to sign using SHA512 and a Nitrokey Pro 2 produces "Conditions of use not satisfied" as High priority.

You used --personal-digest-preferences to force the use of SHA-512, right?

Aug 12 2020, 8:54 AM · gnupg (gpg22), Bug Report

Aug 11 2020

werner committed rD7c3059762dc8: web: Remove s from the menu title (authored by werner).
web: Remove s from the menu title
Aug 11 2020, 2:15 PM
werner committed rD955a8095d754: web: Make it easier to access the documentation index. (authored by werner).
web: Make it easier to access the documentation index.
Aug 11 2020, 2:05 PM
werner closed T5020: Exclude 3DES Cipher and SHA1 Digest as Resolved.

OpenPGP (RFC-4880) requires support for 3DES and SHA-1 thus you can't disable them. However, they are not used in practice because the key preference guarantee the use of more modern algorithms,

Aug 11 2020, 1:59 PM · OpenPGP, gnupg, Not A Bug
werner committed rD3aee210f5bba: web: Fix last Scute change (authored by werner).
web: Fix last Scute change
Aug 11 2020, 1:53 PM
werner committed rSa1a41e938e49: Add a simple but hopefully useful man page. (authored by werner).
Add a simple but hopefully useful man page.
Aug 11 2020, 1:46 PM
werner committed rDad546a090959: web: Fix links on the new scute page. (authored by werner).
web: Fix links on the new scute page.
Aug 11 2020, 12:35 PM
werner committed rSb1f226fd4f5b: Slightly modernize the layout of the manual (authored by werner).
Slightly modernize the layout of the manual
Aug 11 2020, 11:41 AM
werner committed rD97fa904a0c11: web: Update the scute page and add files from scute.org (authored by werner).
web: Update the scute page and add files from scute.org
Aug 11 2020, 10:20 AM
werner committed rS1b5bba1d4ca6: Remove doc/website and move doc/manual one dir up (authored by werner).
Remove doc/website and move doc/manual one dir up
Aug 11 2020, 10:00 AM
werner committed rS008815f81edd: Minor updates of the manual. (authored by werner).
Minor updates of the manual.
Aug 11 2020, 10:00 AM
werner committed rEfd1340085bc6: core,w32: Use timeout in es_poll even if there are no FDs. (authored by werner).
core,w32: Use timeout in es_poll even if there are no FDs.
Aug 11 2020, 8:01 AM

Aug 10 2020

werner added a comment to T5018: Export keys to secure card failure: gpg: KEYTOCARD failed: Unusable secret key.

Do you mean you want to copy a backup key created while generating the keys for the card onto a new card?

Aug 10 2020, 6:28 PM · Info Needed, Bug Report
werner committed rS6a04d254d188: Introduce global config file /etc/gnupg/scute.conf. (authored by werner).
Introduce global config file /etc/gnupg/scute.conf.
Aug 10 2020, 3:41 PM
werner committed rS78b7c2d5d3e0: Support pre-formatted PSS signatures. (authored by werner).
Support pre-formatted PSS signatures.
Aug 10 2020, 3:41 PM
werner committed rGbb096905b9ee: agent: Add option --pss to pksign to be used by smartcards. (authored by werner).
agent: Add option --pss to pksign to be used by smartcards.
Aug 10 2020, 10:34 AM
werner committed rGcbf203801e02: scd:piv: Allow signing using PSS. (authored by werner).
scd:piv: Allow signing using PSS.
Aug 10 2020, 10:34 AM

Aug 9 2020

werner closed T4713: Bug in get_best_pubkey_byname as Resolved.

We won't do that for 2.2.

Aug 9 2020, 5:25 PM · Restricted Project, gnupg (gpg23)
werner closed T4966: Jitter entropy RNG disable on non-x86? as Resolved.

Solved in master (1.9). We won't do it in 1.8.

Aug 9 2020, 5:22 PM · libgcrypt, Bug Report
werner closed T4798: Shutdown dirmngr dosn't work with multiple instances executing as Resolved.

Use

gpgconf --kill dirmngr

to stop it.

Aug 9 2020, 5:20 PM · Bug Report
werner closed T4862: pubkeys are imported despite the --no-auto-key-retrieve option as Resolved.

No more info was provided.

Aug 9 2020, 5:19 PM · Too Old, FAQ, gnupg

Aug 8 2020

werner merged task T5017: Kleopatra can't decrypt the tor. I can't verify the signature. into Restricted Maniphest Task.
Aug 8 2020, 11:41 PM · FAQ
werner edited projects for T5017: Kleopatra can't decrypt the tor. I can't verify the signature., added: FAQ; removed Bug Report.

Download the corresponding tor signature file. Then enter that file name.

Aug 8 2020, 11:40 PM · FAQ
werner added a project to T5016: Gnupg should support WAYLAND_DISPLAY variable for pinentry: gnupg (gpg20).
Aug 8 2020, 10:44 AM · gnupg (gpg20), Feature Request

Aug 6 2020

werner committed rG646a30fd394a: gpgsm: New option --chuid. (authored by werner).
gpgsm: New option --chuid.
Aug 6 2020, 4:16 PM
werner committed rGd10f45184c44: gpgconf: New option --chuid. (authored by werner).
gpgconf: New option --chuid.
Aug 6 2020, 4:16 PM
werner committed rG8ff00ef0de87: common: New helper function gnupg_chuid. (authored by werner).
common: New helper function gnupg_chuid.
Aug 6 2020, 4:16 PM
werner committed rD248efb067e1c: web: Okay, okay, signature_key is in the root (authored by werner).
web: Okay, okay, signature_key is in the root
Aug 6 2020, 11:39 AM
werner committed rD882217eafbc7: web: Add top menu entry for the release keys (authored by werner).
web: Add top menu entry for the release keys
Aug 6 2020, 11:32 AM
werner committed rG077448225777: build: Remove expired key of David Shaw from distsigkey.gpg. (authored by werner).
build: Remove expired key of David Shaw from distsigkey.gpg.
Aug 6 2020, 11:28 AM
werner committed rGfdcf536f7053: build: Remove expired key of David Shaw from distsigkey.gpg. (authored by werner).
build: Remove expired key of David Shaw from distsigkey.gpg.
Aug 6 2020, 11:28 AM
werner committed rDa3c1fd36589f: web: Remove expired dist keys (authored by werner).
web: Remove expired dist keys
Aug 6 2020, 11:25 AM

Aug 5 2020

werner committed rGd847f0651ab4: gpg: Add level 16 to --gen-random (authored by werner).
gpg: Add level 16 to --gen-random
Aug 5 2020, 4:55 PM
werner committed rEe0dab4843ded: Make --lib-version work again. (authored by werner).
Make --lib-version work again.
Aug 5 2020, 12:26 PM
werner committed rD93f3d5890a48: Update key for data-privacy@gnupg.org (authored by werner).
Update key for data-privacy@gnupg.org
Aug 5 2020, 12:14 AM

Aug 4 2020

werner committed rG9c57de75cf36: sm: Also show the SHA-256 fingerprint. (authored by werner).
sm: Also show the SHA-256 fingerprint.
Aug 4 2020, 11:21 AM
werner committed rGe7d70923901e: sm: Also show the SHA-256 fingerprint. (authored by werner).
sm: Also show the SHA-256 fingerprint.
Aug 4 2020, 11:11 AM
werner added a comment to T5009: OS X 10.12 and FAIL: random.

There are no log file but you can run the test by hand:

Aug 4 2020, 10:29 AM · libgcrypt, Bug Report
werner committed rGb2590f2e47fe: tests: Improve handling of spaces in $PATH (authored by werner).
tests: Improve handling of spaces in $PATH
Aug 4 2020, 10:28 AM
werner committed rGe9736995c82f: speedo: Tie build to libgcrypt 1.8 (authored by werner).
speedo: Tie build to libgcrypt 1.8
Aug 4 2020, 10:28 AM
werner closed T4975: undefined-shift in block_filter as Resolved.
Aug 4 2020, 10:19 AM · gnupg (gpg22), Bug Report
werner committed rC01b441308838: random/jitterentropy: fix USE_JENT == JENT_USES_GETTIME code path (authored by jukivili).
random/jitterentropy: fix USE_JENT == JENT_USES_GETTIME code path
Aug 4 2020, 10:15 AM
werner committed rDbd31b013b98c: swdb: Make libgcrypt also available as libgcrypt18 (authored by werner).
swdb: Make libgcrypt also available as libgcrypt18
Aug 4 2020, 10:13 AM

Jul 31 2020

werner updated the task description for T5007: Imported key cannot be used to encrypt..
Jul 31 2020, 9:36 AM · Not A Bug, gpg4win
werner closed T5007: Imported key cannot be used to encrypt. as Resolved.

Iyou look at the key on the command line (or with Kleopatra's certificate manager), for example by using "gpg --list-key foo@bar.com" or by applying the command "gpg --show-keys" on the pasted keyblock you get this:

Jul 31 2020, 9:36 AM · Not A Bug, gpg4win

Jul 30 2020

werner committed rCd9103048d11b: mpi: Support opaque MPI with gcry_mpi_print. (authored by gniibe).
mpi: Support opaque MPI with gcry_mpi_print.
Jul 30 2020, 11:57 AM
werner closed T4872: Support opaque MPI with gcry_mpi_print as Resolved.

Patch backported to 2.2

Jul 30 2020, 10:28 AM · Restricted Project, Feature Request, libgcrypt

Jul 29 2020

werner added a comment to T5005: Unified single header file if it offers same API.

We have had this in the past but it led to subtle build and, worse, runtime problems. Thus the decision to provide architecture dependent files and have configure complain for wrong files. Right, you sometimes get false warnings for non-matching cpu-vendor-os strings but I consider this less severe than the old problem.

Jul 29 2020, 1:33 PM · libassuan, gpgrt
werner triaged T5006: Kleopatra: Display Names and Key-IDs for certificates after any attempt to import them. as Normal priority.
Jul 29 2020, 1:22 PM · gpd5x, kleopatra, Feature Request

Jul 28 2020

werner removed a member for g10code: BenM.
Jul 28 2020, 2:45 PM
werner added a member for g10code: ikloecker.
Jul 28 2020, 2:44 PM
werner triaged T5001: Card specification enhancement as Normal priority.
Jul 28 2020, 8:54 AM · Feature Request, scd

Jul 27 2020

werner added a comment to T5001: Card specification enhancement.

Well, it is now defined. We use a CMS object containing an OpenPGP keyblock container. Right, there is no open standard for it but with OIDs you don't really need them. it is a bit of a hack but it works with the majority of deployed cards and the overhead is quite small.

Jul 27 2020, 2:34 PM · Feature Request, scd

Jul 26 2020

werner added a comment to T5001: Card specification enhancement.

Item 2 and 3 have already been solved by allowing to store a minimal key.

Jul 26 2020, 11:22 PM · Feature Request, scd

Jul 20 2020

werner added a comment to T5000: trustdb,keybox: Adding support of v5key.

I deferred this thing because I hoped to implement this in the keyboxd. Another option is to use a truncated fingerprint - for displaying purposes we anyway truncate to 25 byte and 20 byte should also be okay until we can move this to keyboxd. But okay, if you want to add support please go ahead but make sure that there are no fatal conditions if a gpg 2.2 accesses the v5 enabled trustdb.

Jul 20 2020, 9:26 AM · Restricted Project, gnupg (gpg23)

Jul 17 2020

werner added a comment to T4998: scdaemon: PC/SC "No such device" without reader-port.

That could also be the reason for some strange behaviour I have sometimes with my bunch or readers. I have not had the time to look into this and thus opted for a gpgconf --kill scdaemon which fixes things quickly but of course this is a bad workaround.

Jul 17 2020, 3:02 PM · Restricted Project, scd, Bug Report
werner closed T4310: GPGME: Add ssh export mode as Resolved.

C++ interface is also availabale in 1.14.0 (see rM690d967196d9).

Jul 17 2020, 12:06 PM · gpgme (gpgme 1.23.x), Feature Request
werner closed T4820: gpgme's json test fails with gpg 2.2.19 as Resolved.
Jul 17 2020, 11:41 AM · gpgme (gpgme 1.23.x), Bug Report
werner closed T4996: Release GPGME 1.14.0 as Resolved.
Jul 17 2020, 11:25 AM · gpgme, Release Info
werner updated the task description for T4996: Release GPGME 1.14.0.
Jul 17 2020, 11:01 AM · gpgme, Release Info
werner added a comment to T4992: ssh Yubikey not recognized, but Yubikey works with GPG well.

iirc, you need to start gpg-agent before you use putty; thus do a "gpg -K" or "gpgconf --launch gpg-agent".

Jul 17 2020, 10:46 AM · ssh, yubikey, Bug Report, gpg4win
werner added a comment to T4994: Windows: assuan_sock_init or WSAStartup by main/_init_common_subsystem.

Thanks for looking into this. However, I do not understand the problem behind it. Is it the need to link against the socket lib? 10 or 15 years ago things were more complicated because two TCP stacks were in use and you could use the modern one only if a certain service pack or Explorer version was installed. That might be the reasons for some of the peculiarities we have in the code.

Jul 17 2020, 10:44 AM · Restricted Project, gnupg, Windows
werner claimed T4997: 2.2.21 breaks passphrase-repeat and password checking.
Jul 17 2020, 10:34 AM · Bug Report, gnupg (gpg22)
werner added a subtask for T4897: Release GnuPG 2.2.21: T4997: 2.2.21 breaks passphrase-repeat and password checking.
Jul 17 2020, 10:33 AM · gnupg (gpg22), Release Info
werner added a parent task for T4997: 2.2.21 breaks passphrase-repeat and password checking: T4897: Release GnuPG 2.2.21.
Jul 17 2020, 10:33 AM · Bug Report, gnupg (gpg22)
werner triaged T4997: 2.2.21 breaks passphrase-repeat and password checking as Normal priority.

Right 2.2.21 fixes a long standing bug in symmetric encryption in that the configured passphrase constraints were not checked. Eventually we will add a second sec of constraints here but for now the same constrains as for private key protection are used.

Jul 17 2020, 10:32 AM · Bug Report, gnupg (gpg22)

Jul 16 2020

werner committed rD40fa90e0047e: swdb: release of gpgme 1.14.0 (authored by werner).
swdb: release of gpgme 1.14.0
Jul 16 2020, 7:56 PM
werner committed rM6d7bf78ca5af: Release 1.14.0 (authored by werner).
Release 1.14.0
Jul 16 2020, 5:33 PM
werner committed rM81db4122450b: Post release updates (authored by werner).
Post release updates
Jul 16 2020, 5:33 PM
werner created T4996: Release GPGME 1.14.0.
Jul 16 2020, 5:13 PM · gpgme, Release Info
werner committed rMdfeedcc28d04: core: Also allow GPGME_EXPORT_MODE_SSH for gpgme_op_export. (authored by werner).
core: Also allow GPGME_EXPORT_MODE_SSH for gpgme_op_export.
Jul 16 2020, 4:49 PM
werner added a project to T3957: GPGME: mkdefsinc segfaults on windows: unreproducible.
Jul 16 2020, 3:29 PM · unreproducible, toolchain, Documentation, Windows, gpgme
werner closed T3957: GPGME: mkdefsinc segfaults on windows as Invalid.

No info received

Jul 16 2020, 3:27 PM · unreproducible, toolchain, Documentation, Windows, gpgme
werner edited projects for T3948: GPGSM: Multiple issues reported to KMail, added: gnupg; removed gpgme.
Jul 16 2020, 3:23 PM · gnupg, S/MIME
werner added a project to T3794: GPGME: Make it possible to switch trust model per context: Feature Request.
Jul 16 2020, 3:21 PM · Feature Request, gpgol, gpgme
werner closed T3515: Gpg4win: Gpgconf used to open "windows" and slows down kleo startup as Resolved.

I am not any longer interested to see the real cause; eventually we will replace it anyway with a modern CreateProcess.

Jul 16 2020, 3:19 PM · Windows, gpgme
werner closed T3512: gpgme test failure when run with gpg version 1 as Invalid.

Reconsidering this: Running the test suite with gpg1 is not a proper use case. gpg1 may be installed in addition to gpg but it should never be used on a build machine solely.

Jul 16 2020, 3:09 PM · gnupg (gpg14), gpgme, Bug Report
werner lowered the priority of T3512: gpgme test failure when run with gpg version 1 from Normal to Low.
Jul 16 2020, 3:07 PM · gnupg (gpg14), gpgme, Bug Report
werner edited projects for T3471: gpgme decryptverify indicating wrongly an error., added: gnupg, Not A Bug; removed gpgme.

I don't see any error here. There is a trailing LF on the binary data which gpg rightfully complains about.

Jul 16 2020, 3:06 PM · Not A Bug, gnupg, Bug Report
werner closed T3413: gpgme_op_delete doesn't return failure when loopback mode is enabled as Wontfix.
Jul 16 2020, 2:53 PM · gpgme, Bug Report
werner closed T3396: use swig to generate Ruby bindings for gpgme as Wontfix.

As of today we don't want to maintain another binding; see T3395

Jul 16 2020, 2:52 PM · Feature Request, gpgme
werner closed T3395: use swig to generate Perl bindings for gpgme as Wontfix.

The Python bindings are troublesome enough; as of today we don't want to maintain a Perl module.

Jul 16 2020, 2:51 PM · Feature Request, gpgme
werner closed T3356: gpgme test suite failure in lang/qt/tests/t-config.cpp on mipsel as Invalid.

No info received in3 years.

Jul 16 2020, 2:49 PM · Too Old, gpgme, Bug Report
werner closed T3348: gpgsm: should default to --disable-crl-checks as Wontfix.
Jul 16 2020, 2:45 PM · gpgme, gnupg, S/MIME
werner moved T3272: Make groups available through GPGME from Backlog to For a future release on the gpgme board.
Jul 16 2020, 2:43 PM · gpgme, Feature Request
werner added a parent task for T2919: fix gpgme/gpgsm pipe server session with use_descriptor_passing (was: mutt + gpgme problems with some Outlook S/MIME emails): T4257: GPGME: op_verify failes for S/MIME with EBADF in multithreaded signature verification.
Jul 16 2020, 2:42 PM · gpgme, Bug Report
werner added a subtask for T4257: GPGME: op_verify failes for S/MIME with EBADF in multithreaded signature verification: T2919: fix gpgme/gpgsm pipe server session with use_descriptor_passing (was: mutt + gpgme problems with some Outlook S/MIME emails).
Jul 16 2020, 2:42 PM · S/MIME, gpgme
werner closed T4028: GPGME: Subkeys not marked correcly as secret as Resolved.

Has already been fixed with T4061.

Jul 16 2020, 2:40 PM · gpgme
werner lowered the priority of T4195: Fix time API in gpgme from Normal to Low.
Jul 16 2020, 2:38 PM · gnupg, kleopatra, Restricted Project, gpgme, Feature Request
werner moved T4310: GPGME: Add ssh export mode from Backlog to QA for next release on the gpgme board.
Jul 16 2020, 2:36 PM · gpgme (gpgme 1.23.x), Feature Request
werner reassigned T4310: GPGME: Add ssh export mode from werner to aheinecke.

C part done; C++ interface is not yet done.

Jul 16 2020, 2:35 PM · gpgme (gpgme 1.23.x), Feature Request
werner committed rM7f9e0ca57b29: core: New export mode to export as OpenSSH public key. (authored by werner).
core: New export mode to export as OpenSSH public key.
Jul 16 2020, 12:02 PM
werner committed rG970e43130506: gpg: Do not close stdout after --export-ssh-key (authored by werner).
gpg: Do not close stdout after --export-ssh-key
Jul 16 2020, 11:43 AM
werner committed rG5c514a274ca8: gpg: Do not close stdout after --export-ssh-key (authored by werner).
gpg: Do not close stdout after --export-ssh-key
Jul 16 2020, 11:32 AM
werner added a comment to T4975: undefined-shift in block_filter.

Well, it changes the behaviour on error and thus it should not be backported to 2.2 so that existsing error reports about corrupted data don't change. Fine for master.

Jul 16 2020, 11:30 AM · gnupg (gpg22), Bug Report