Page MenuHome GnuPG
Feed Advanced Search

Dec 13 2021

werner closed T5641: Release GnuPG 2.2.33 as Resolved.
Dec 13 2021, 1:46 PM · Release Info, gnupg (gpg22)

Dec 7 2021

werner added a project to T5724: gpgconf --show-configs does not show the registry values : Windows.
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report
werner claimed T5724: gpgconf --show-configs does not show the registry values .
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report
werner triaged T5724: gpgconf --show-configs does not show the registry values as Normal priority.
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report
gniibe triaged T5721: gpg22: Update *.m4 to prefer use of gpgrt-config and *.pc to *-config as Wishlist priority.
Dec 7 2021, 8:00 AM · gnupg (gpg22)
gniibe added a project to T5120: Incompatible Ed25519 secret key (no-encryption): Restricted Project.
Dec 7 2021, 7:43 AM · gnupg (gpg22), Bug Report
gniibe added a comment to T5120: Incompatible Ed25519 secret key (no-encryption).

For GnuPG 2.2, it's better to be conservative (least change of behavior, if any).

Dec 7 2021, 7:17 AM · gnupg (gpg22), Bug Report

Dec 6 2021

gniibe closed T5644: Heuristic for default reader detection as Resolved.
Dec 6 2021, 12:57 AM · Restricted Project, Feature Request, gnupg (gpg22)

Nov 25 2021

gniibe added a comment to T5120: Incompatible Ed25519 secret key (no-encryption).

My proposal is applying SOS (MPI with leading zero octets) patches, for 2.2, because there may be existing keys with SOS already.

Nov 25 2021, 6:17 AM · gnupg (gpg22), Bug Report
gniibe reopened T5120: Incompatible Ed25519 secret key (no-encryption) as "Open".

It's not yet solved.

Nov 25 2021, 6:14 AM · gnupg (gpg22), Bug Report

Nov 23 2021

werner changed the status of T5644: Heuristic for default reader detection from Open to Testing.
Nov 23 2021, 1:28 PM · Restricted Project, Feature Request, gnupg (gpg22)
werner closed T5650: Check problems with gpgconf and global config files as Resolved.
Nov 23 2021, 1:27 PM · Restricted Project, gnupg (gpg22)
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2021q4/000467.html on T5641: Release GnuPG 2.2.33.
Nov 23 2021, 1:26 PM · Release Info, gnupg (gpg22)
werner updated the task description for T5641: Release GnuPG 2.2.33.
Nov 23 2021, 11:56 AM · Release Info, gnupg (gpg22)
werner triaged T5703: Release GnuPG 2.2.34 as Low priority.
Nov 23 2021, 11:47 AM · Release Info, gnupg (gpg22)
werner closed T5076: [solved] gpg-agent respawn another process randomly and causes cached passphrase check failed / expired as Resolved.
Nov 23 2021, 9:18 AM · gnupg (gpg22), Bug Report
werner closed T5205: GNuPG compile error as Resolved.
Nov 23 2021, 9:17 AM · gnupg (gpg22), toolchain, Support
werner closed T5120: Incompatible Ed25519 secret key (no-encryption) as Resolved.

I guess this is solved. Feel free to re-open and schedule for 2.2.34

Nov 23 2021, 9:15 AM · gnupg (gpg22), Bug Report
werner lowered the priority of T5235: Delays in dirmngr http connections on Windows from Normal to Low.
Nov 23 2021, 9:14 AM · can't replicate, dirmngr, ntbtls, Windows, gnupg (gpg22)
werner added a project to T5235: Delays in dirmngr http connections on Windows: can't replicate.

Might be a TOR Thing?

Nov 23 2021, 9:14 AM · can't replicate, dirmngr, ntbtls, Windows, gnupg (gpg22)

Nov 13 2021

werner closed T5685: Clear stale --trusted-key records from the trustdb, a subtask of T5058: Review --trusted-key, as Resolved.
Nov 13 2021, 9:03 PM · gnupg24, gnupg (gpg23)
werner closed T5301: Decrypting a message that has multiple SKESK packets sometimes fails as Wontfix.
Nov 13 2021, 2:43 PM · gnupg (gpg22), Bug Report
werner closed T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key' as Resolved.
Nov 13 2021, 2:42 PM · Support, Info Needed, gnupg (gpg22)

Nov 12 2021

gniibe added a project to T5644: Heuristic for default reader detection: Restricted Project.
Nov 12 2021, 5:50 AM · Restricted Project, Feature Request, gnupg (gpg22)

Nov 3 2021

ikloecker merged T5675: Kleopatra 3.1.16 / Keyservers related functions are not working into T5639: dirmngr uses the wrong Let's encrypt chain.
Nov 3 2021, 1:53 PM · gnupg (gpg22), dirmngr

Oct 27 2021

werner triaged T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key' as Low priority.

Sure there are logs, see the options log-file and debug in the man pages.
To sign using specific subkey or the main key, use the fingerprint of the key and append an exclamation mark.
For example

Oct 27 2021, 1:12 PM · Support, Info Needed, gnupg (gpg22)

Oct 22 2021

werner moved T5650: Check problems with gpgconf and global config files from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 22 2021, 12:25 PM · Restricted Project, gnupg (gpg22)
werner moved T5650: Check problems with gpgconf and global config files from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 22 2021, 12:24 PM · Restricted Project, gnupg (gpg22)
werner changed the status of T5650: Check problems with gpgconf and global config files from Open to Testing.
Oct 22 2021, 12:22 PM · Restricted Project, gnupg (gpg22)
gniibe added a comment to T5644: Heuristic for default reader detection.

I put my initial try by rG752422a792ce: scd: Select a reader for PC/SC..

Oct 22 2021, 6:51 AM · Restricted Project, Feature Request, gnupg (gpg22)
gniibe added a comment to T5644: Heuristic for default reader detection.

I found this: https://gist.github.com/PatrickLang/7be00ba46a43eca3ef64ffe64b494749#user-content-conflicts-with-windows-hello--virtual-smart-card

Oct 22 2021, 4:45 AM · Restricted Project, Feature Request, gnupg (gpg22)

Oct 20 2021

werner closed T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys. as Resolved.

Yes, but it is more complicated to do because you need to download a binary version of the keys and check that they are authentic. Most users don't known it. Anyway, I meanwhile created a Brainpool release sign key and new VSD releases are signed with that. The override option does not really harm, but we can close this bug due to the new release key.

Oct 20 2021, 12:21 PM · gnupg (gpg22), Restricted Project

Oct 14 2021

swimmerm added a project to T5626: 'GPGCONF --list-dirs' command option on-screen displayed results show '%3a' unexpected and unneeded characters in each line displaying a C: drive path instead of simpler expected '...:C:\...' sub-strings with only valid ':' ('colon') characters present: gnupg (gpg22).
Oct 14 2021, 11:13 PM · gnupg (gpg22), UI, Not A Bug, gpg4win

Oct 13 2021

ikloecker added a comment to T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys..

Wouldn't it be safer to use gpgv for verifying the signature than to add a code path to gpg to circumvent the hard de-vs compliance check?

Oct 13 2021, 5:05 PM · gnupg (gpg22), Restricted Project
werner triaged T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys. as High priority.
Oct 13 2021, 3:01 PM · gnupg (gpg22), Restricted Project

Oct 12 2021

werner added a comment to T5644: Heuristic for default reader detection.

On my new Windows 10 laptop I see a "Windows Hello for Business 1". Thus put everything with "Windows Hello" at the end of the list or skip unless a reader-port is set. IIRC there are device with "virtual" or "Virtual" in their name, they don't make sense for us either. I would also put devices with "SCM" or "Identiv" to the top of the list. In particular the substrings "SPR532" seems to identify the Identiv SPR332 which is what we use here and actualay a suggested reader for GnUPG VS-Desktop.

Oct 12 2021, 8:44 AM · Restricted Project, Feature Request, gnupg (gpg22)
gniibe added a comment to T5644: Heuristic for default reader detection.

Please tell me reader names to skip.

Oct 12 2021, 7:23 AM · Restricted Project, Feature Request, gnupg (gpg22)

Oct 11 2021

werner triaged T5650: Check problems with gpgconf and global config files as High priority.
Oct 11 2021, 5:39 PM · Restricted Project, gnupg (gpg22)
gniibe claimed T5644: Heuristic for default reader detection.
Oct 11 2021, 6:47 AM · Restricted Project, Feature Request, gnupg (gpg22)

Oct 8 2021

werner added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

There won't be any other 3.1 release - install GnuPG 2.2.32 on top of Gpg4win 3.1.16

Oct 8 2021, 3:18 PM · gnupg (gpg22), dirmngr
werner raised the priority of T5644: Heuristic for default reader detection from Normal to High.
Oct 8 2021, 2:51 PM · Restricted Project, Feature Request, gnupg (gpg22)
bernhard added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

My experience on a Window 10 system (with Gpg4win 3.1.15 which has GnuPG 2.2.27) was, that removing the expired root certificate did not help with https://keyserver.ubuntu.com and the intermediate certificate was not in the windows store, so it could not be removed.

Oct 8 2021, 12:01 PM · gnupg (gpg22), dirmngr
ikloecker added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

Removing an intermediate cert from your local system doesn't help because any correctly configured server will send you all necessary intermediate certs together with the server cert. You'd have to remove the expired root certificate instead (see Workaround 1 on https://www.openssl.org/blog/blog/2021/09/13/LetsEncryptRootCertExpire/). The problem is that this will break certificate verification for any servers that still use the old intermediate cert, e.g. keyserver.ubuntu.com.

Oct 8 2021, 9:16 AM · gnupg (gpg22), dirmngr

Oct 7 2021

werner added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

The LE web site has instruction on how to do this. However, it is complicated and depends on your system. The intermediate cert you listed is signed by the expired old root cert. If you remove this intermediate cert the other root cert will be found and we are done. The old LE certs had a 4 tier chain and the new one a 3 tier.
See https://dev.gnupg.org/rG341ab0123a8fa386565ecf13f6462a73a137e6a4 and https://letsencrypt.org/images/isrg-hierarchy.png

Oct 7 2021, 5:33 PM · gnupg (gpg22), dirmngr
werner triaged T5644: Heuristic for default reader detection as Normal priority.
Oct 7 2021, 4:07 PM · Restricted Project, Feature Request, gnupg (gpg22)
bernhard added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

One problem I see is that keyserver.ubuntu.com delivers a problematic intermediate(?) certificate:

Oct 7 2021, 1:59 PM · gnupg (gpg22), dirmngr
bernhard added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

If there is no easy way to install a new version of GnuPG, e.g. for Gpg4win or for GNU/Linux distributions: It may make sense to have instructions for the workaround ready.

Oct 7 2021, 9:30 AM · gnupg (gpg22), dirmngr
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2021q4/000465.html on T5601: Release GnuPG 2.2.32.
Oct 7 2021, 7:55 AM · Release Info, gnupg (gpg22)

Oct 6 2021

werner added a comment to T5571: Release GnuPG 2.2.31.

Please update to 2.2.32 if you have problems with keyservers etc.

Oct 6 2021, 9:22 PM · Release Info, gnupg (gpg22)
werner closed T5584: gpg --list-packets lists wrong packets as Resolved.

Backported to 2.2.32

Oct 6 2021, 9:21 PM · gnupg (gpg22), Bug Report
werner closed T5639: dirmngr uses the wrong Let's encrypt chain as Resolved.
Oct 6 2021, 9:20 PM · gnupg (gpg22), dirmngr
werner closed T5601: Release GnuPG 2.2.32 as Resolved.
Oct 6 2021, 9:19 PM · Release Info, gnupg (gpg22)
werner triaged T5641: Release GnuPG 2.2.33 as Low priority.
Oct 6 2021, 9:14 PM · Release Info, gnupg (gpg22)
werner added a comment to T5571: Release GnuPG 2.2.31.

We have been hit by the Let's Encrypt root cert switch. Thus a fixed version will soon be released. See T5639 for details of the problem.

Oct 6 2021, 5:58 PM · Release Info, gnupg (gpg22)
werner added a comment to T5487: GnuPG 2.2.28 not working with Yubikey NEO.

You mean Gpg4win. The solution for Gpg4win 3.1.x is to install the latest GnUPG LTS installer for Windows on top of the latest Gpg4win version. See
https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000464.html
Noet that there will very soon be a 2.2.32 to fix a problem with Let's encrypt protected keyservers (T5639).

Oct 6 2021, 5:53 PM · yubikey, gnupg (gpg22), Bug Report
DanielHabenicht added a comment to T5487: GnuPG 2.2.28 not working with Yubikey NEO.

Just for everbody else who might be waiting for a new release. Workaround is to simply use the previous version: https://www.gpg4win.de/change-history-de.html (3.1.15)

Oct 6 2021, 5:21 PM · yubikey, gnupg (gpg22), Bug Report
werner triaged T5639: dirmngr uses the wrong Let's encrypt chain as High priority.
Oct 6 2021, 9:23 AM · gnupg (gpg22), dirmngr

Oct 4 2021

werner added projects to T5584: gpg --list-packets lists wrong packets: gnupg (gpg22), backport.
Oct 4 2021, 10:13 AM · gnupg (gpg22), Bug Report

Oct 3 2021

amit added a comment to T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key'.

Hey, are there any other logs that I can grab? Is there a way to override the defaults, which will allow me to use the right key to sign?

Oct 3 2021, 10:39 PM · Support, Info Needed, gnupg (gpg22)

Sep 30 2021

gniibe edited projects for T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key', added: gnupg (gpg22), Info Needed; removed gnupg.
Sep 30 2021, 3:20 AM · Support, Info Needed, gnupg (gpg22)

Sep 17 2021

luweitest added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

Tried and no change -- cmd window still flashes away.

Sep 17 2021, 8:14 AM · Windows, gnupg (gpg22), Bug Report
werner added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

Remember to always pass --batch for unattended operations.

Sep 17 2021, 8:02 AM · Windows, gnupg (gpg22), Bug Report
luweitest renamed T5560: gpg.exe interrupt batch execution in WindowsXp from gpg.exe changes the properties of command line window and do not quit normally in batch execution to gpg.exe interrupt batch execution in WindowsXp.
Sep 17 2021, 5:33 AM · Windows, gnupg (gpg22), Bug Report
luweitest added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

Thanks to jaclaz@msfn.org, the workaround is to use pipe operation like:
pause|"C:\Program Files\GnuPG\bin\gpg.exe" --verify "%1"
He also confirmed that gpg.exe does interrupt batch processing, regardless what command is followed.
And I have tested in Windows 7, batch processing is not interrupted. Since this bug is WindowsXp specific, "won't fix" should be more proper.

Sep 17 2021, 5:32 AM · Windows, gnupg (gpg22), Bug Report

Sep 16 2021

werner added a comment to T5519: Release GnuPG 2.2.30.

I introduced a regression in this version; if you run into problems please update to 2.3.31 (T5571)

Sep 16 2021, 12:32 PM · Release Info, gnupg (gpg22)
werner closed T5571: Release GnuPG 2.2.31 as Resolved.
Sep 16 2021, 12:31 PM · Release Info, gnupg (gpg22)
werner triaged T5601: Release GnuPG 2.2.32 as Low priority.
Sep 16 2021, 11:53 AM · Release Info, gnupg (gpg22)

Sep 14 2021

werner closed T5560: gpg.exe interrupt batch execution in WindowsXp as Invalid.
Sep 14 2021, 2:03 PM · Windows, gnupg (gpg22), Bug Report
werner closed T4972: GPG: Add Option to force passphrase constraints for symmetric encryption, too as Resolved.

Won't be implemented as a new option because --check-sym-passphrase-pattern and --check-passphrase-pattern (since 2.2.30) can be used to implement the same in a more flexible way.

Sep 14 2021, 2:02 PM · gnupg (gpg22), Feature Request
werner lowered the priority of T5085: Filter APDUs in log output from Normal to Low.
Sep 14 2021, 2:00 PM · gnupg, Feature Request, scd
werner added a comment to T5120: Incompatible Ed25519 secret key (no-encryption).

gniibe: What's the state of this?

Sep 14 2021, 1:59 PM · gnupg (gpg22), Bug Report
werner lowered the priority of T5301: Decrypting a message that has multiple SKESK packets sometimes fails from Normal to Wishlist.

Currently I see no need to fix this for 2.2

Sep 14 2021, 1:58 PM · gnupg (gpg22), Bug Report
werner closed T5322: gpg erroring when the terminal is too small to show the ncurses pinentry dialog as Resolved.
Sep 14 2021, 1:56 PM · gnupg (gpg22), gpgagent, pinentry, Bug Report
werner closed T5536: Backport the extended gpg-check-pattern to 2.2 as Resolved.

Released with 2.2.30 (T5519)

Sep 14 2021, 1:52 PM · gnupg (gpg22)

Sep 13 2021

werner added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

Sorry, GnuPG proper has no context menu or any graphic user interface. You need to install Gpg4win for this. Regarding use of gpg by other programs: There has been no change - other programs need to use the status-fd/command-fd interface and that has always been defined as UTF-8 and not as any native codepage. Please ask the makers of The Bat what is going wrong there.

Sep 13 2021, 9:35 AM · Windows, gnupg (gpg22), Bug Report

Sep 9 2021

werner lowered the priority of T5079: Add compliance flag to trustlist.txt from High to Normal.
Sep 9 2021, 3:08 PM · gnupg22, gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request

Sep 8 2021

bjmgeek added a comment to T3748: GPA is stuck if keyring is too big and trust-model is tofu+pgp.

I verified that manually putting the DB in WAL mode also resolved this issue, since writers don't block readers in WAL mode.

Sep 8 2021, 10:07 PM · TOFU, gnupg (gpg22), gpa

Sep 6 2021

MaXi32 added a comment to T5076: [solved] gpg-agent respawn another process randomly and causes cached passphrase check failed / expired.

I think this issue is solved. For systemd, I need to run this as --supervised option not the --daemon option. The --daemon option has bug.

Sep 6 2021, 6:36 AM · gnupg (gpg22), Bug Report

Aug 31 2021

werner renamed T5583: Support RSCS dedicated OpenPGP for OID. from Support RSCS dedicated OpenPGP fpr OID. to Support RSCS dedicated OpenPGP for OID..
Aug 31 2021, 5:26 PM · gnupg26, Restricted Project, scd
werner triaged T5583: Support RSCS dedicated OpenPGP for OID. as Normal priority.
Aug 31 2021, 5:26 PM · gnupg26, Restricted Project, scd

Aug 30 2021

leder added a comment to T5580: gpg2 proves signature correct, even if empty file is removed.

I think this behaviour has something to do with "attached signature"?!

Aug 30 2021, 9:23 PM · gnupg, FAQ
leder updated the task description for T5580: gpg2 proves signature correct, even if empty file is removed.
Aug 30 2021, 9:06 PM · gnupg, FAQ
leder created T5580: gpg2 proves signature correct, even if empty file is removed.
Aug 30 2021, 9:06 PM · gnupg, FAQ

Aug 27 2021

werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2021q3/000463.html on T5519: Release GnuPG 2.2.30.
Aug 27 2021, 3:23 PM · Release Info, gnupg (gpg22)

Aug 26 2021

werner changed the edit policy for T5571: Release GnuPG 2.2.31.
Aug 26 2021, 9:27 PM · Release Info, gnupg (gpg22)
werner changed the edit policy for T5519: Release GnuPG 2.2.30.
Aug 26 2021, 9:27 PM · Release Info, gnupg (gpg22)
werner closed T5519: Release GnuPG 2.2.30 as Resolved.
Aug 26 2021, 9:26 PM · Release Info, gnupg (gpg22)
werner triaged T5571: Release GnuPG 2.2.31 as Low priority.
Aug 26 2021, 9:12 PM · Release Info, gnupg (gpg22)
werner changed the status of T5555: Cannot add existing ECDSA key as a signing subkey from Open to Testing.
Aug 26 2021, 11:54 AM · gnupg24, Bug Report
werner added a comment to T5555: Cannot add existing ECDSA key as a signing subkey.

I tried applied the bulk of the patch to 2.2 but w/o reading the key creation time from the card. We don't have the supporting code for latter in 2.2. However this does not make sense. Users should switch to 2.3 if they needs this feature.

Aug 26 2021, 11:53 AM · gnupg24, Bug Report

Aug 25 2021

werner claimed T5555: Cannot add existing ECDSA key as a signing subkey.

Will do.

Aug 25 2021, 11:56 AM · gnupg24, Bug Report
gniibe added a comment to T5555: Cannot add existing ECDSA key as a signing subkey.

To fix this, rG48251cf9a7d3: gpg: Improve generation of keys stored on card (brainpool,cv25519). for GnuPG 2.3 should be backported.

Aug 25 2021, 4:19 AM · gnupg24, Bug Report
gniibe closed T5297: SCM SPR332 smartcard reader support broken as Resolved.
Aug 25 2021, 3:33 AM · gnupg (gpg22), scd, Bug Report

Aug 24 2021

werner closed T5491: Console output failure with no-unicode font: GnuPG 2.2.28 is not working with »encrypt-to« in gpg.conf without specifying another recipient. as Resolved.
Aug 24 2021, 7:57 PM · gnupg (gpg22), Windows, Bug Report

Aug 23 2021

luweitest added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

So it is related to code page. Screenshots may be more informative:

Aug 23 2021, 8:23 AM · Windows, gnupg (gpg22), Bug Report

Aug 21 2021

werner triaged T5560: gpg.exe interrupt batch execution in WindowsXp as Normal priority.

Frankly, I don fully understand your report. Can you please clarify?
Note that with 2.2.8 we introduced full Unicode support on the command line. If you see scrambled output you may want to "chcp 65001" to get the output correctly rendered.

Aug 21 2021, 12:53 PM · Windows, gnupg (gpg22), Bug Report

Aug 17 2021

werner closed T5537: Use CSIDL_LOCAL_APPDATA for the socketdir as Resolved.

I have done tests with 2.2 and no problems showed up.

Aug 17 2021, 5:18 PM · Windows, Restricted Project, gnupg (gpg22)

Aug 14 2021

werner triaged T5555: Cannot add existing ECDSA key as a signing subkey as High priority.
Aug 14 2021, 1:25 PM · gnupg24, Bug Report

Aug 13 2021

werner updated subscribers of T5519: Release GnuPG 2.2.30.
Aug 13 2021, 11:53 AM · Release Info, gnupg (gpg22)
werner changed the edit policy for T5519: Release GnuPG 2.2.30.
Aug 13 2021, 11:53 AM · Release Info, gnupg (gpg22)