Page MenuHome GnuPG
Feed All Stories

Dec 18 2020

ikloecker added a comment to T5184: scd: Generating CSR for NetKey card key fails.

Yes, makes sense. Although, you should use datalen = indatalen; in the last line (to prevent typos in the numbers).

Dec 18 2020, 9:19 AM · scd
gniibe added a comment to T5184: scd: Generating CSR for NetKey card key fails.

IIUC, for completeness, it would be good to add the lines like:

Dec 18 2020, 7:54 AM · scd
Laurent Montel <montel@kde.org> committed rLIBKLEO21335d07f825: GIT_SILENT: prepare 5.16.1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.16.1
Dec 18 2020, 7:26 AM
gniibe committed rCc90fb0d8fb7a: Reorganize self-tests for HMAC. (authored by gniibe).
Reorganize self-tests for HMAC.
Dec 18 2020, 7:22 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA2958bbdb019e: GIT_SILENT: prepare 5.16.1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.16.1
Dec 18 2020, 7:16 AM

Dec 17 2020

stig124 created T5185: Language change issue, wrong locale is used and mess everything.
Dec 17 2020, 8:59 PM · Bug Report, gpg4win
werner committed rG4a3836e2b2f9: gpg: New AKL method "ntds" (authored by werner).
gpg: New AKL method "ntds"
Dec 17 2020, 6:26 PM
werner committed rG1194e4f7e2df: dirmngr: Support "ldap:///" for the current AD user. (authored by werner).
dirmngr: Support "ldap:///" for the current AD user.
Dec 17 2020, 6:26 PM
werner committed rG559efd23e936: gpg: New AKL method "ntds" (authored by werner).
gpg: New AKL method "ntds"
Dec 17 2020, 6:23 PM
werner committed rG776bef74c778: dirmngr: Support "ldap:///" for the current AD user. (authored by werner).
dirmngr: Support "ldap:///" for the current AD user.
Dec 17 2020, 6:23 PM
ikloecker committed rKLEOPATRA5e480a78c3e0: Allow creation of CSRs for card keys of NetKey cards (authored by ikloecker).
Allow creation of CSRs for card keys of NetKey cards
Dec 17 2020, 3:28 PM
ikloecker committed rKLEOPATRA8932a36c13e6: Trigger a full update of the card status after the NullPIN was set (authored by ikloecker).
Trigger a full update of the card status after the NullPIN was set
Dec 17 2020, 3:28 PM
ikloecker committed rKLEOPATRA66c0a62e2045: Use ChangePinCommand for changing PINs of NetKey cards (authored by ikloecker).
Use ChangePinCommand for changing PINs of NetKey cards
Dec 17 2020, 3:28 PM
ikloecker committed rKLEOPATRA9abbbddba509: Make sure that status information is updated after UI setup (authored by ikloecker).
Make sure that status information is updated after UI setup
Dec 17 2020, 3:28 PM
ikloecker created T5184: scd: Generating CSR for NetKey card key fails.
Dec 17 2020, 3:08 PM · scd
werner committed rGc75fd7553290: dirmngr: Allow LDAP searches via fingerprint. (authored by werner).
dirmngr: Allow LDAP searches via fingerprint.
Dec 17 2020, 11:20 AM
werner committed rGc28cb5282b14: dirmngr: Store all version 2 schema attributes. (authored by werner).
dirmngr: Store all version 2 schema attributes.
Dec 17 2020, 11:20 AM
werner committed rGac8ece92662d: dirmngr: Support the new Active Directory schema (authored by werner).
dirmngr: Support the new Active Directory schema
Dec 17 2020, 11:20 AM
werner committed rG0e88c73bc94f: dirmngr: Do not store the useless pgpSignerID in the LDAP. (authored by werner).
dirmngr: Do not store the useless pgpSignerID in the LDAP.
Dec 17 2020, 11:20 AM
werner committed rGe47de8538200: dirmngr: Fix adding keys to an LDAP server. (authored by werner).
dirmngr: Fix adding keys to an LDAP server.
Dec 17 2020, 11:20 AM
werner committed rG2cadcce3e877: dirmngr: Allow LDAP searches via fingerprint. (authored by werner).
dirmngr: Allow LDAP searches via fingerprint.
Dec 17 2020, 10:23 AM
werner committed rG2b06afbf260f: dirmngr: Finalize Active Directory LDAP Schema (authored by werner).
dirmngr: Finalize Active Directory LDAP Schema
Dec 17 2020, 10:23 AM

Dec 16 2020

ikloecker changed the status of T5183: Kleopatra: Generate S/MIME CSR for OpenPGP card key from Open to Testing.

Ready for testing.

Dec 16 2020, 12:19 PM · Restricted Project, kleopatra
ikloecker changed the status of T5183: Kleopatra: Generate S/MIME CSR for OpenPGP card key, a subtask of T5123: Kleopatra: Generate OpenPGP pubkey S/MIME CSR from existing card, from Open to Testing.
Dec 16 2020, 12:19 PM · kleopatra
ikloecker committed rKLEOPATRA0b12d7705e81: Allow creation of CSRs for card keys of OpenPGP cards (authored by ikloecker).
Allow creation of CSRs for card keys of OpenPGP cards
Dec 16 2020, 12:15 PM
ikloecker committed rKLEOPATRA6106b1f87514: Refactor OpenPGPCard and PGPCardWidget (authored by ikloecker).
Refactor OpenPGPCard and PGPCardWidget
Dec 16 2020, 12:15 PM
ikloecker created T5183: Kleopatra: Generate S/MIME CSR for OpenPGP card key.
Dec 16 2020, 9:25 AM · Restricted Project, kleopatra
gniibe added a comment to T5182: libgcrypt self tests for FIPS 140.

I cannot find good test vectors for PBKDF2 with HMAC-SHA-2.

Dec 16 2020, 6:53 AM · Restricted Project, libgcrypt
gniibe added a comment to T5167: GnuPG 2.25 still have problems related to Yubikey NEO..

Nice, I gonna apply the patch and see if resolves for me!

Dec 16 2020, 3:55 AM · gnupg (gpg22), yubikey, ssh, scd, Bug Report
gbschenkel added a comment to T5167: GnuPG 2.25 still have problems related to Yubikey NEO..

Nice, I gonna apply the patch and see if resolves for me!

Dec 16 2020, 3:25 AM · gnupg (gpg22), yubikey, ssh, scd, Bug Report
gniibe committed rG3c55e15cee4b: scd:ccid: Call libusb_clear_halt in ccid_vendor_specific_setup. (authored by gniibe).
scd:ccid: Call libusb_clear_halt in ccid_vendor_specific_setup.
Dec 16 2020, 2:18 AM
gniibe committed rG585cfca0a60b: scd:ccid: Revert the addition of libusb_clear_halt for EP_INTR. (authored by gniibe).
scd:ccid: Revert the addition of libusb_clear_halt for EP_INTR.
Dec 16 2020, 2:18 AM
gniibe reopened T4563: gpg-agent fails to sign request of PKISSH as "Open".
Dec 16 2020, 1:43 AM · Feature Request, gpgagent
gniibe closed T4563: gpg-agent fails to sign request of PKISSH as Wontfix.
Dec 16 2020, 1:42 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

If your problem is the incompatibility between standard OpenSSH (server) and PKIXSSH (client) for use of ssh-agent emulation of gpg-agent with ECDSA key, I'd suggest to apply following patch to your PKIXSSH:

diff --git a/compat.c b/compat.c
index fe71951..0c9b1ef 100644
--- a/compat.c
+++ b/compat.c
@@ -245,7 +245,6 @@ xkey_compatibility(const char *remote_version) {
 {	static sshx_compatibility info[] = {
 		{ 0, "OpenSSH*PKIX[??.*" /* 10.+ first correct */ },
 		{ 0, "OpenSSH*PKIX[X.*" /* developlement */ },
-		{ 1, "OpenSSH*" /* PKIX pre 10.0 */ },
 		{ 1, "SecureNetTerm-3.1" /* same as PKIX pre 10.0 */},
 		{ 0, NULL } };
 	p = xkey_compatibility_find(remote_version, info);
Dec 16 2020, 12:58 AM · Feature Request, gpgagent
ikloecker committed rLIBKLEO1f76573e275f: Merge branch 'work/static-analysis' into 'master' (authored by ikloecker).
Merge branch 'work/static-analysis' into 'master'
Dec 16 2020, 12:22 AM

Dec 15 2020

ikloecker changed the status of T5127: Kleopatra: Generate S/MIME CSR for PIV card key from Open to Testing.

Ready for testing

Dec 15 2020, 6:33 PM · kleopatra
ikloecker changed the status of T5127: Kleopatra: Generate S/MIME CSR for PIV card key, a subtask of T5123: Kleopatra: Generate OpenPGP pubkey S/MIME CSR from existing card, from Open to Testing.
Dec 15 2020, 6:33 PM · kleopatra
ikloecker committed rKLEOPATRAfb1ef2181f59: Improve/simplify layout of PIV card widget (authored by ikloecker).
Improve/simplify layout of PIV card widget
Dec 15 2020, 6:32 PM
ikloecker committed rKLEOPATRA86b349a947e8: Improve usability of CSR creation (authored by ikloecker).
Improve usability of CSR creation
Dec 15 2020, 5:51 PM
ikloecker committed rKLEOPATRA4385c4db475e: Connect signals after UI setup is complete to prevent a crash (authored by ikloecker).
Connect signals after UI setup is complete to prevent a crash
Dec 15 2020, 5:51 PM
ikloecker committed rKLEOPATRA9dfd273c9bae: After creating the CSR write it to disk asking the user for a location (authored by ikloecker).
After creating the CSR write it to disk asking the user for a location
Dec 15 2020, 5:51 PM
werner committed rG2c6bb03cfb56: dirmngr: Remove superfluous attribute from the LDAP schema. (authored by werner).
dirmngr: Remove superfluous attribute from the LDAP schema.
Dec 15 2020, 3:50 PM
werner committed rGa2434ccabdd1: dirmngr: Store all version 2 schema attributes. (authored by werner).
dirmngr: Store all version 2 schema attributes.
Dec 15 2020, 3:50 PM
Laurent Montel <montel@kde.org> committed rLIBKLEOf29bb83638fd: GIT_SILENT: Fix typo (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Fix typo
Dec 15 2020, 1:53 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRA40b9a421b964: GIT_SILENT: Fix typo (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Fix typo
Dec 15 2020, 1:51 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRAe0236c45a948: Allow to use UNITY build see https://cmake. (authored by Laurent Montel <montel@kde.org>).
Allow to use UNITY build see https://cmake.
Dec 15 2020, 7:48 AM
Laurent Montel <montel@kde.org> committed rLIBKLEO17042deb161a: Allow to use UNITY build see https://cmake. (authored by Laurent Montel <montel@kde.org>).
Allow to use UNITY build see https://cmake.
Dec 15 2020, 7:47 AM
gniibe renamed T5182: libgcrypt self tests for FIPS 140 from libgcrypt tests for FIPS 140 to libgcrypt self tests for FIPS 140.
Dec 15 2020, 6:50 AM · Restricted Project, libgcrypt
gniibe added a comment to T5182: libgcrypt self tests for FIPS 140.

Our tests are now in tests/basic.c.

Dec 15 2020, 6:36 AM · Restricted Project, libgcrypt
gniibe added a comment to T5182: libgcrypt self tests for FIPS 140.

For CMAC tests, we would need to use newer test vectors.

Dec 15 2020, 6:35 AM · Restricted Project, libgcrypt
gniibe created T5182: libgcrypt self tests for FIPS 140.
Dec 15 2020, 6:30 AM · Restricted Project, libgcrypt

Dec 14 2020

werner committed rGe9ddd61fe979: dirmngr: Support the new Active Directory schema (authored by werner).
dirmngr: Support the new Active Directory schema
Dec 14 2020, 7:48 PM
werner committed rGcc056eb534c1: dirmngr: Do not store the useless pgpSignerID in the LDAP. (authored by werner).
dirmngr: Do not store the useless pgpSignerID in the LDAP.
Dec 14 2020, 7:48 PM
werner committed rG37a899d0e4fd: dirmngr: Fix adding keys to an LDAP server. (authored by werner).
dirmngr: Fix adding keys to an LDAP server.
Dec 14 2020, 7:48 PM
werner set Due Date to Mar 31 2021, 12:00 AM on T4294: Release Libgcrypt 1.9.0.
Dec 14 2020, 1:21 PM · Release Info, libgcrypt
aheinecke created T5181: Kleopatra: Simplify newkey generation.
Dec 14 2020, 12:56 PM · kleopatra
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Unfortunately and confusingly, PKISSH returns "OpenSSH" when asked by "ssh -V".
Please install real OpenSSH, if this is the case for you.

Dec 14 2020, 10:52 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Quote from IRC:
hey, i've some problems with my smartcard since quite some time. i'm not sure whether it's openssh related or gnupg. it's a openpgpcard v2.0 and i have to workaround ssh logins by using "SSH_AUTH_SOCK=0 ssh ...". .gnupg/gpg-agent.conf -

the debug log: esp. "ssh sign request failed: Unknown option <GPG Agent>" and ssh says "sign_and_send_pubkey: signing failed: agent refused operation"
gpg --edit-card and --card-status works fine and sign/encrypt works fine as well. only ssh auth fails
openssh 8.1_p1, gnupg 2.2.20

Dec 14 2020, 10:31 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Yeah but it seems to be the same issue / reason. I wasn't aware that PKISSH is something else. I thought it was an extension/protocol or something

Dec 14 2020, 10:26 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I added "Feature Request", because this is a request to support:

  • A feature of bug compatibility, which is implemented wrongly in PKISSH
  • for a specific algo of key, which is not considered so useful (== ECDSA)
  • PKISSH, which is variant of OpenSSH
Dec 14 2020, 10:23 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.
In T4563#140184, @idl0r wrote:

I was and I am using OpenSSH on both sides, client and server.

Dec 14 2020, 10:20 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I was and I am using OpenSSH on both sides, client and server.

Dec 14 2020, 10:16 AM · Feature Request, gpgagent
werner added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I do not think that we should support a fork of openssh right now. If we would support it we are bound to maintain that for years - this is not a good idea.

Dec 14 2020, 10:09 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Well, I have no idea about the technical background to be honest but without this patch it doesn't work at all for me, unless I stop using the agent or workaround it by using SSH_AUTH_SOCK=0. With this patch, I can use the agent again. I don't know how many others are affected by this but it made it usable again, which wasn't the case for months already.

Dec 14 2020, 9:04 AM · Feature Request, gpgagent
gniibe changed the status of T5170: card: Allow use cases with no corresponding *.key file under private-keys-v1.d from Open to Testing.
Dec 14 2020, 6:58 AM · Restricted Project, gnupg (gpg23)
gniibe lowered the priority of T4563: gpg-agent fails to sign request of PKISSH from Normal to Low.

In theory, I don't think the patch gnupg.patch works. It just ignore the flag.

Dec 14 2020, 3:19 AM · Feature Request, gpgagent
lopter added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Thank you for testing.
For the issue #1, I think it is the probelm of rG1cd615afe301: gpg,card: Allow no version information of Yubikey.. This was introduced by the support of PIV feature of Yubikey.

Dec 14 2020, 2:05 AM · Restricted Project, gnupg, Feature Request
gniibe added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Thank you for testing.
For the issue #1, I think it is the probelm of rG1cd615afe301: gpg,card: Allow no version information of Yubikey., which is fixed already. This was introduced by the support of PIV feature of Yubikey.

Dec 14 2020, 1:05 AM · Restricted Project, gnupg, Feature Request

Dec 13 2020

Laurent Montel <montel@kde.org> committed rLIBKLEO7e95286bbe2d: GIT_SILENT: increase version about compile without deprecated method (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: increase version about compile without deprecated method
Dec 13 2020, 2:12 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRA714cf24a2f1c: GIT_SILENT: increase version about compile without deprecated method (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: increase version about compile without deprecated method
Dec 13 2020, 2:11 PM
Laurent Montel <montel@kde.org> committed rLIBKLEOa9cf6af1033a: GIT_SILENT: Time to create version. (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Time to create version.
Dec 13 2020, 9:53 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA17ed2fa042e7: GIT_SILENT: Time to create version. (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Time to create version.
Dec 13 2020, 9:51 AM

Dec 12 2020

lopter added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Report on some testing using master:

Dec 12 2020, 9:33 PM · Restricted Project, gnupg, Feature Request
martinralbrecht closed T4800: python-gpgme signature revokation assertion error: `gpg->cmd.code' failed as Resolved.

You're right. Thank you.

Dec 12 2020, 8:28 PM · gpgme, Bug Report
TaaviE added a comment to T5180: PKA export uses algorithm number for "ECDSA Curve P-384 with SHA-384" instead of "Ed25519" for "Ed25519/Ec25519" keys.

Oh, any chance GPG could inform the user when using export-pka that it is dead/deprecated? Also thanks for the quick reply.

Dec 12 2020, 1:36 PM · Bug Report
werner closed T5180: PKA export uses algorithm number for "ECDSA Curve P-384 with SHA-384" instead of "Ed25519" for "Ed25519/Ec25519" keys as Invalid.

PKA is dead but anyway: What you see is a record from a DNS zone file which has a specific semantic. The 14 for example means that 20 bytes follow.

Dec 12 2020, 1:28 PM · Bug Report
werner triaged T5179: add export-filter based on user ID calculated validity as Normal priority.
Dec 12 2020, 1:26 PM · gnupg24, gnupg (gpg23), Feature Request
TaaviE created T5180: PKA export uses algorithm number for "ECDSA Curve P-384 with SHA-384" instead of "Ed25519" for "Ed25519/Ec25519" keys.
Dec 12 2020, 1:08 PM · Bug Report

Dec 11 2020

dkg created T5179: add export-filter based on user ID calculated validity.
Dec 11 2020, 6:31 PM · gnupg24, gnupg (gpg23), Feature Request
ikloecker committed rKLEOPATRAe093eac2adf5: Allow creation of CSRs for card keys of PIV cards (authored by ikloecker).
Allow creation of CSRs for card keys of PIV cards
Dec 11 2020, 1:20 PM
ikloecker committed rKLEOPATRAf35ea48ee469: Factor switching of card and app into common helper function (authored by ikloecker).
Factor switching of card and app into common helper function
Dec 11 2020, 1:20 PM
ikloecker committed rKLEOPATRAd4fef80c7662: Define GPGMEPP_ERR_SOURCE_DEFAULT and use Error::fromCode() (authored by ikloecker).
Define GPGMEPP_ERR_SOURCE_DEFAULT and use Error::fromCode()
Dec 11 2020, 1:20 PM
ikloecker committed rKLEOPATRAec967f053ee0: Set initial (static) KeyPairInfo for PIV cards (authored by ikloecker).
Set initial (static) KeyPairInfo for PIV cards
Dec 11 2020, 1:20 PM
ikloecker committed rKLEOPATRAf4b40d89a85f: Show basic information about card keys above certificate info (authored by ikloecker).
Show basic information about card keys above certificate info
Dec 11 2020, 1:20 PM
TaaviE added a comment to T5177: GPG WKD lookup does not send correct SNI.

The specs might just want to say that it just expects the wildcard to be broken, not that it expects an empty record.

Dec 11 2020, 10:49 AM · FAQ, wkd
werner added a comment to T5177: GPG WKD lookup does not send correct SNI.

Than put something into the TXT - it does not matter and is only used to break the wildcard.

Dec 11 2020, 10:41 AM · FAQ, wkd
werner added a comment to T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client.

Hartmut, please read Andre's mail again - we can't do anything about it if Outlook considers an extra delay of 20ms as too slow.

Dec 11 2020, 10:07 AM · Support, gpg4win
werner closed T5178: scdaemon will throw "app_decipher failed" if "gpg --card-status" not issued beforehand as Resolved.

See the release info over at T5052 which notes the problem. See T5140 for details and update to 2.2.25.

Dec 11 2020, 10:04 AM · Duplicate, gnupg
HackyJ added a comment to T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client.

Andre,

thats wrong.
if i disable the Addin, the effect is gone.

Best regards
Hartmut

Von: aheinecke (Andre Heinecke) <noreply@dev.gnupg.org>
Gesendet: Freitag, 11. Dezember 2020 08:35
An: hartmut.jacobi@hotmail.de
Betreff: [Task] [Closed] T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client

aheinecke closed this task as "Invalid".
aheinecke added a comment.

Hi, you can change the default mail app under systemsettings in windwos 10, this has nothing to do with GpgOL, and the delayed start report, I can't do anything about. Outlook just shows this for any COM Addin to shift the blame, seriously we took 0,02s or 20ms on your system for our initialization. That is reasonably fast.

TASK DETAIL
https://dev.gnupg.org/T5176

EMAIL PREFERENCES
https://dev.gnupg.org/settings/panel/emailpreferences/

To: aheinecke

Cc: aheinecke, gnupg, HackyJ, Neurone, ccharabaruk, gp_ast

This is an automated email from the GnuPG development hub. If you have registered in the past at https://bugs.gnupg.org/ your account was migrated automatically. You can visit https://dev.gnupg.org/ to set a new password and update your email preferences.

Dec 11 2020, 9:51 AM · Support, gpg4win
Laurent Montel <montel@kde.org> committed rLIBKLEOe59aa9f5f93b: Properly include QStringList . Forward declaring it breaks with Qt6 (authored by Laurent Montel <montel@kde.org>).
Properly include QStringList . Forward declaring it breaks with Qt6
Dec 11 2020, 8:54 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA100374a956f1: Properly include QStringList . Forward declaring it breaks with Qt6 (authored by Laurent Montel <montel@kde.org>).
Properly include QStringList . Forward declaring it breaks with Qt6
Dec 11 2020, 8:54 AM
aheinecke closed T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client as Invalid.

Hi, you can change the default mail app under systemsettings in windwos 10, this has nothing to do with GpgOL, and the delayed start report, I can't do anything about. Outlook just shows this for any COM Addin to shift the blame, seriously we took 0,02s or 20ms on your system for our initialization. That is reasonably fast.

Dec 11 2020, 8:34 AM · Support, gpg4win
Laurent Montel <montel@kde.org> committed rLIBKLEO5761d61cbe52: GIT_SILENT: prepare 5.16.1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.16.1
Dec 11 2020, 8:16 AM
gniibe committed rG3b3926308813: scd:nks: Support READKEY with keygrip and for "NKS-IDLM" keyref. (authored by gniibe).
scd:nks: Support READKEY with keygrip and for "NKS-IDLM" keyref.
Dec 11 2020, 6:12 AM
gniibe committed rGb7c087375d84: scd:nks: Factor out pubkey retrieval from keygrip handling. (authored by gniibe).
scd:nks: Factor out pubkey retrieval from keygrip handling.
Dec 11 2020, 6:12 AM
gniibe added a comment to T5150: scd: For NetKey cards READKEY with keygrip fails.

Reading the code again, I think that some configuration of NKS card doesn't work well, when it has no certificates but keys (e.g. IDLM config).
I'm going to fix do_readkey as well (the approach #1).

Dec 11 2020, 1:13 AM · backport, gnupg (gpg23), scd

Dec 10 2020

TaaviE added a comment to T5177: GPG WKD lookup does not send correct SNI.

Cloudflare doesn't seem to allow empty DNS TXT records...

Dec 10 2020, 4:30 PM · FAQ, wkd
aleprovencio created T5178: scdaemon will throw "app_decipher failed" if "gpg --card-status" not issued beforehand in the S1 Public space.
Dec 10 2020, 4:29 PM · Duplicate, gnupg
werner closed T5177: GPG WKD lookup does not send correct SNI as Resolved.

From the specs:

Dec 10 2020, 4:28 PM · FAQ, wkd