Page MenuHome GnuPG
Feed Advanced Search

Jan 10 2022

Jakuje updated subscribers of T5600: Provide module name/version API for FIPS 140-3.

Sorry for resurrecting the done task, but I got a message from @pmgdeb who noticed there is mismatch between parenthesis in the --with-fips-module-version help string. The attached patch fixes the issue and add proper help text.

Jan 10 2022, 3:41 PM · libgcrypt, FIPS, Bug Report
JanMosigItemis updated the task description for T5767: scdaemon gets stuck on smartcard access.
Jan 10 2022, 2:29 PM · Bug Report, gpg4win
JanMosigItemis created T5767: scdaemon gets stuck on smartcard access.
Jan 10 2022, 2:28 PM · Bug Report, gpg4win
aheinecke added a project to T5763: gpgme-json missing: Info Needed.

I have just checked both the installation script, which still installs gpgme-json.exe and the gpg4win-4 installer downloaded from gpg4win.org gpgme-json.exe is properly installed under <instdir>\bin gpgme-json.exe and under bin_64

Jan 10 2022, 9:00 AM · Info Needed, Bug Report, gpg4win
manphiz created T5765: gnupg2 weird memory fault on NetBSD Loongson/mips64el N32.
Jan 10 2022, 3:57 AM · MIPS, Bug Report

Jan 9 2022

werner triaged T5763: gpgme-json missing as Normal priority.
Jan 9 2022, 6:54 PM · Info Needed, Bug Report, gpg4win
jani updated the task description for T5764: Broken umlauts in the new Windows Terminal.
Jan 9 2022, 3:22 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
jani created T5764: Broken umlauts in the new Windows Terminal.
Jan 9 2022, 3:16 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
patrick renamed T5763: gpgme-json missing from gpgme-json misson to gpgme-json missing.
Jan 9 2022, 2:44 PM · Info Needed, Bug Report, gpg4win
patrick created T5763: gpgme-json missing.
Jan 9 2022, 2:42 PM · Info Needed, Bug Report, gpg4win
dkg created T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl.
Jan 9 2022, 2:41 AM · gpgrt, Bug Report

Jan 8 2022

werner added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

See T5758. The workaround is not to set a reader-port.

Jan 8 2022, 8:24 PM · Bug Report, gpg4win
werner triaged T5761: Libgcrypt: salt-length for RSA-PSS is not documented as Normal priority.
Jan 8 2022, 8:20 PM · Bug Report, Documentation, libgcrypt

Jan 7 2022

JaminCollins added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

Downgraded the gnupg to 2.2.33 using this installer and I am now able to successfully open the Kleopatra GUI.

Jan 7 2022, 7:09 PM · Bug Report, gpg4win
JaminCollins added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

Should also note that once the GUI is opened, GnuPG's smartcard deamon (32 bit) transitions to Very high power usage and appears stuck there, consuming a full logical core's worth of CPU time.

Jan 7 2022, 7:02 PM · Bug Report, gpg4win
MikhailRyazanov created T5761: Libgcrypt: salt-length for RSA-PSS is not documented.
Jan 7 2022, 4:50 PM · Bug Report, Documentation, libgcrypt

Jan 6 2022

JaminCollins renamed T5760: Kleopatra hangs loading certificate cache on Windows 11 from Kleopatra hangs ___ on Windows 11 to Kleopatra hangs loading certificate cache on Windows 11.
Jan 6 2022, 10:46 PM · Bug Report, gpg4win
JaminCollins created T5760: Kleopatra hangs loading certificate cache on Windows 11.
Jan 6 2022, 10:45 PM · Bug Report, gpg4win

Jan 4 2022

gniibe claimed T5747: Provide a way to request non-FIPS service in FIPS mode.
Jan 4 2022, 11:16 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5747: Provide a way to request non-FIPS service in FIPS mode from Backlog to Next on the FIPS board.
Jan 4 2022, 11:16 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5636: Run integrity checks + selftests from library constructor in FIPS from Next to Ready for release on the FIPS board.
Jan 4 2022, 11:16 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

And I'm testing following:

Jan 4 2022, 6:40 AM · Feature Request, FIPS, libgcrypt
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

The "at first" change done.

Jan 4 2022, 6:40 AM · Feature Request, FIPS, libgcrypt
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

At first, I think that we need to change the way how libgcrypt rejects non-approved cipher/md/mac/pk.

Jan 4 2022, 3:30 AM · Feature Request, FIPS, libgcrypt

Dec 30 2021

werner changed the status of T5732: Backport option reading in gpgconf to 2.2 from Open to Testing.

Backport done but diligent testing is required.

Dec 30 2021, 10:51 AM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)

Dec 23 2021

werner closed T5744: Issue with connecting to GPG server as Resolved.

The debug log was from gpg and not from dirmngr and thus it is not helpful. I also guess that an older dirmngr was still running, because the LE bug has been fixed in 2.3.4.

Dec 23 2021, 5:31 PM · Bug Report, gpg4win
vsajip added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

Will go into 2.3.4.

Dec 23 2021, 12:13 PM · Restricted Project, Bug Report, gnupg (gpg23)
ikloecker closed T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches as Resolved.
Dec 23 2021, 11:38 AM · Restricted Project, kleopatra, Bug Report
ikloecker added a comment to T5744: Issue with connecting to GPG server.

And --keyserver-options check-cert is removed from new gpg versions (((

Dec 23 2021, 11:36 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

Here is log in english

Dec 23 2021, 10:28 AM · Bug Report, gpg4win

Dec 22 2021

alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

And --keyserver-options check-cert is removed from new gpg versions (((

Dec 22 2021, 5:11 PM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.
Dec 22 2021, 4:48 PM · Bug Report, gpg4win
alexnadtoka reopened T5744: Issue with connecting to GPG server as "Open".
Dec 22 2021, 4:10 PM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

@werner can you show me tutorial for proper bug submit? I think it is a bug and gpg client on Windows does not support valid LetsEncrypt certificates on keyserver. It does not work with any keys server . Tested few public keyservers as well. ((

Dec 22 2021, 4:09 PM · Bug Report, gpg4win
ikloecker added a comment to T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches.

We decided to notify the user if the keyserver doesn't return fingerprints. The fingerprints are needed by Kleopatra as unique identifier for keys. Trying to make key lookup work without fingerprints isn't useful.

Dec 22 2021, 3:34 PM · Restricted Project, kleopatra, Bug Report
werner closed T5744: Issue with connecting to GPG server as Resolved.

Please see https://gnupg.org

Dec 22 2021, 7:26 AM · Bug Report, gpg4win

Dec 21 2021

werner added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

FWIW, We have a similar mechanism for the secure memory

Dec 21 2021, 6:12 PM · Feature Request, FIPS, libgcrypt
ikloecker changed the status of T5745: Kleopatra: Card holder name is not correctly decoded from Open to Testing.
Dec 21 2021, 5:02 PM · Restricted Project, kleopatra, Bug Report
Jakuje created T5747: Provide a way to request non-FIPS service in FIPS mode.
Dec 21 2021, 4:58 PM · Feature Request, FIPS, libgcrypt
Saturneric updated the task description for T5746: Pinetry always loses focus after popping up under Windows.
Dec 21 2021, 2:52 PM · Not A Bug, pinentry
Saturneric created T5746: Pinetry always loses focus after popping up under Windows.
Dec 21 2021, 2:49 PM · Not A Bug, pinentry
Saturneric added a comment to T5712: Yubikey 5 NFC only recognized immediately after it is inserted.

Recently, I have encountered many problems in adapting the graphical interface interaction between Yubikey and gnupg. I am thinking about why some settings need to be manually added to some additional settings. I found that there are many such solutions on the Internet. Is there any way that scdaemon can automatically recognize these situations and add appropriate settings.

Dec 21 2021, 2:42 PM · Documentation, Bug Report
ikloecker claimed T5745: Kleopatra: Card holder name is not correctly decoded.
Dec 21 2021, 2:33 PM · Restricted Project, kleopatra, Bug Report
ikloecker created T5745: Kleopatra: Card holder name is not correctly decoded.
Dec 21 2021, 2:32 PM · Restricted Project, kleopatra, Bug Report
werner edited projects for T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG, added: gnupg (gpg23), Bug Report; removed gnupg (gpg22).

Things are not that easy. I actually introduced a bug in 2.3.4. Here is a comment from my working copy:

Dec 21 2021, 11:22 AM · Restricted Project, Bug Report, gnupg (gpg23)
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

@werner Thank you for the answer. Please advise mailing list address.

Dec 21 2021, 10:44 AM · Bug Report, gpg4win
werner added a comment to T5744: Issue with connecting to GPG server.

For support please use the mailing list and not the bug tracker.

Dec 21 2021, 10:26 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

GNUpg version 2.3.4 was installed but did not help

Dec 21 2021, 9:41 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

Is there a way to ignore SSL check during connection? This might work. We have internal server for our users only.

Dec 21 2021, 9:39 AM · Bug Report, gpg4win
alexnadtoka created T5744: Issue with connecting to GPG server.
Dec 21 2021, 9:38 AM · Bug Report, gpg4win

Dec 20 2021

ikloecker added a comment to T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches.

That KeyListJob returns keys which have fingerprint NULL is caused by keyservers returning just key IDs instead of fingerprints. The change for T5741: dirmngr does not ask keyservers for fingerprints should fix this. Still keyservers are only guaranteed to return key IDs, so we cannot assume that keys returned by KeyListJob have fingerprints.

Dec 20 2021, 9:38 AM · Restricted Project, kleopatra, Bug Report

Dec 17 2021

Saturneric added a comment to T5737: last_update in gpgme_key_t always be nullptr.

Thanks!
I will study it soon.

Dec 17 2021, 8:13 AM · Support, gpgme
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Thank you for your quick testing.

Dec 17 2021, 1:09 AM · FIPS, libgcrypt, Bug Report
gniibe added a project to T5740: gpg error check fails: Restricted Project.

The patch worked, thank you very much.

Dec 17 2021, 12:53 AM · gpgrt, Bug Report

Dec 16 2021

Jakuje added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Thank you. Tested locally that it does what it is supposed to do and all tests passed for me as expected.

Dec 16 2021, 6:43 PM · FIPS, libgcrypt, Bug Report
Yenya added a comment to T5712: Yubikey 5 NFC only recognized immediately after it is inserted.

@werner: thanks, with the 'pcsc-shared' option it works for me (after sending SIGHUP to scdaemon, of course). So, do I understand correctly that this cannot be the default?

Dec 16 2021, 4:29 PM · Documentation, Bug Report
shoober420 added a comment to T5740: gpg error check fails.

The patch worked, thank you very much.

Dec 16 2021, 10:25 AM · gpgrt, Bug Report
ikloecker added a comment to T5737: last_update in gpgme_key_t always be nullptr.

Use the source! GnuPG is free software.

Dec 16 2021, 10:11 AM · Support, gpgme
gniibe added a comment to T5740: gpg error check fails.

Thank you for the log.

Dec 16 2021, 9:25 AM · gpgrt, Bug Report
shoober420 added a comment to T5740: gpg error check fails.

Here is the log file requested.

Dec 16 2021, 7:13 AM · gpgrt, Bug Report
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Dec 16 2021, 5:20 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Here is the change remained:

diff --git a/src/fips.c b/src/fips.c
index bcadc5f2..5499aee8 100644
--- a/src/fips.c
+++ b/src/fips.c
@@ -82,6 +82,12 @@ static void fips_new_state (enum module_states new_state);
Dec 16 2021, 5:19 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Before rebasing, I pushed a change to simplify access to no_secure_memory variable by rC209d98dcf66b: Simplify the logic for no_secure_memory..

Dec 16 2021, 5:13 AM · FIPS, libgcrypt, Bug Report

Dec 15 2021

Saturneric reopened T5737: last_update in gpgme_key_t always be nullptr as "Open".

I tested the change of last_update after importing a same key with different content, but found that there is still no change.

Dec 15 2021, 7:42 PM · Support, gpgme
gniibe claimed T5740: gpg error check fails.
Dec 15 2021, 3:31 PM · gpgrt, Bug Report
gniibe added a comment to T5740: gpg error check fails.

So, please show us gpg-error-config-test.log by your build.

Dec 15 2021, 3:04 PM · gpgrt, Bug Report
shoober420 created T5740: gpg error check fails.
Dec 15 2021, 7:12 AM · gpgrt, Bug Report

Dec 14 2021

Saturneric closed T5737: last_update in gpgme_key_t always be nullptr as Resolved.
Dec 14 2021, 4:24 PM · Support, gpgme
ikloecker added a comment to T5737: last_update in gpgme_key_t always be nullptr.

On import. Please use gnupg-devel mailing list for further API questions. This is a bug tracker and not a help forum.

Dec 14 2021, 3:57 PM · Support, gpgme
Saturneric created T5738: The ref and unref operation is confusing while using gpg_key_t and gpg_xxx_result_t.
Dec 14 2021, 2:35 PM · gpgme, Bug Report
Saturneric created T5737: last_update in gpgme_key_t always be nullptr.
Dec 14 2021, 2:26 PM · Support, gpgme
werner added a subtask for T5732: Backport option reading in gpgconf to 2.2: T5735: Kleopatra: Automatic lookup for certificates for OpenPGP card keys.
Dec 14 2021, 10:15 AM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)

Dec 13 2021

werner added a comment to T5732: Backport option reading in gpgconf to 2.2.

A clumsy workaround for the Kleo bug is to put "keyserver ldap:///" into the global gpg.conf after an ignore section containing keyserver. This will let gpgconf emit "ldap:///" unless a local gpg.conf exists.

Dec 13 2021, 5:30 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner changed Due Date from Dec 31 2021, 12:00 AM to Jan 31 2022, 12:00 AM on T5732: Backport option reading in gpgconf to 2.2.
Dec 13 2021, 1:58 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner added a project to T5732: Backport option reading in gpgconf to 2.2: Restricted Project.
Dec 13 2021, 1:57 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner triaged T5732: Backport option reading in gpgconf to 2.2 as High priority.
Dec 13 2021, 1:51 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
MangoCats added a comment to T5730: During make, compile error under Ubuntu 21.10.

Thanks. If I'm reading correctly, that fix was pushed in July. Any idea when the next release might come out?

Dec 13 2021, 4:08 AM · gpgme, Bug Report
gniibe claimed T5730: During make, compile error under Ubuntu 21.10.

Thank you for your report.

Dec 13 2021, 3:13 AM · gpgme, Bug Report

Dec 12 2021

MangoCats renamed T5730: During make, compile error under Ubuntu 21.10 from During make, compile Error under Ubuntu 21.10 to During make, compile error under Ubuntu 21.10.
Dec 12 2021, 7:14 PM · gpgme, Bug Report
MangoCats created T5730: During make, compile error under Ubuntu 21.10.
Dec 12 2021, 7:12 PM · gpgme, Bug Report

Dec 10 2021

gniibe added a project to T5331: Possibly incompatible Ed25519 signature between other implementations and 2.3-bata: Restricted Project.
Dec 10 2021, 7:45 AM · gnupg (gpg23), Bug Report
gniibe added a comment to T5331: Possibly incompatible Ed25519 signature between other implementations and 2.3-bata.

Adding comments, fixing "const" qualifier, I pushed the change.

Dec 10 2021, 7:44 AM · gnupg (gpg23), Bug Report

Dec 9 2021

Jakuje created T5726: Setting "compliance de-vs" in gpg.conf with libgcrypt 1.9.0 and newer causes confusing error messages.
Dec 9 2021, 5:33 PM · Not A Bug, libgcrypt, gnupg
gniibe added a comment to T5331: Possibly incompatible Ed25519 signature between other implementations and 2.3-bata.

A patch created:

Dec 9 2021, 7:30 AM · gnupg (gpg23), Bug Report

Dec 8 2021

ikloecker created T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches.
Dec 8 2021, 5:00 PM · Restricted Project, kleopatra, Bug Report
gniibe added a comment to T5331: Possibly incompatible Ed25519 signature between other implementations and 2.3-bata.

GnuPG 2.2 does:

  • In g10/sign.c:do_sign, it keeps leading zeros for Ed25519 signature, as opaque MPI
  • In g10/build-packet.c:do_signature which calls gpg_mpi_write to output the (opaque) MPI, leading zeros are removed.
Dec 8 2021, 12:20 PM · gnupg (gpg23), Bug Report
gniibe added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Let me explain concretely.

Dec 8 2021, 12:18 PM · gpgrt, Bug Report
outer added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Excuse me NIBE san. What if any action do you expect me to take on this matter?
__outer

Dec 8 2021, 10:22 AM · gpgrt, Bug Report
gniibe added a project to T5215: gnugp1: Fix build errors with gcc-10: Restricted Project.
Dec 8 2021, 9:10 AM · gnupg (gpg14), patch, Bug Report
gniibe added a project to T5393: gnupg coverity static analysis reports: Restricted Project.
Dec 8 2021, 9:09 AM · gnupg (gpg23), Bug Report
gniibe added a project to T5579: libksba parallel build error (windows): Restricted Project.
Dec 8 2021, 9:07 AM · libksba, Bug Report
gniibe added a project to T5617: fips: Check library integrity before running selftests: Restricted Project.
Dec 8 2021, 9:06 AM · FIPS, libgcrypt, Bug Report
gniibe renamed T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS from libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl to libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.
Dec 8 2021, 9:05 AM · gpgrt, Bug Report
gniibe added a project to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS: Restricted Project.
Dec 8 2021, 9:04 AM · gpgrt, Bug Report
gniibe added a project to T5714: tests: Do not run tests for algorithms that are not built-in: Restricted Project.
Dec 8 2021, 9:03 AM · libgcrypt, Bug Report
gniibe added a project to T5244: libgcrypt: Restrict MD5 use: Restricted Project.
Dec 8 2021, 8:59 AM · Bug Report, FIPS, libgcrypt
gniibe triaged T5636: Run integrity checks + selftests from library constructor in FIPS as Normal priority.
Dec 8 2021, 8:57 AM · FIPS, libgcrypt, Bug Report

Dec 7 2021

werner added a project to T5724: gpgconf --show-configs does not show the registry values : Windows.
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report
werner claimed T5724: gpgconf --show-configs does not show the registry values .
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report
werner triaged T5724: gpgconf --show-configs does not show the registry values as Normal priority.
Dec 7 2021, 12:36 PM · Windows, gnupg (gpg22), Bug Report