Page MenuHome GnuPG
Feed Advanced Search

Jan 17 2022

dkg reopened T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl as "Open".

Thanks for looking into this, @gniibe! over on https://bugs.debian.org/1003313 Helmut is asking for a re-consideration because he wanted to match arm-linux-musleabihf. Would you be ok with a change like my proposal rE371d1c952297f781277b979a4662859ec80fe836 (on branch dkg/expand-musl), that expands *-*-linux-musl to *-*-linux-musl* ?

Jan 17 2022, 7:56 PM · gpgrt, Bug Report
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

After commenting out the options that gpgconf 2.3 complains about I get:

$ gpgconf --version
gpgconf (GnuPG) 2.3.5-beta17
Copyright (C) 2021 Free Software Foundation, Inc.
License GNU GPL-3.0-or-later <https://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Jan 17 2022, 5:28 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

I tried to see what gpgconf from master says, but I only get

$gpgconf --list-options gpg
gpgconf: unknown option 'try-secret-key' at '/etc/gnupg/gpgconf.conf', line 95
gpgconf: unknown option 'reader-port' at '/etc/gnupg/gpgconf.conf', line 96
Jan 17 2022, 5:20 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

This also doesn't look right:

Jan 17 2022, 5:01 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

The following looks very much like a bug.

Jan 17 2022, 4:35 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

Example:
/etc/gnupg/gpg.conf:

default-key B81CE112B26A8EA8BE7B95D2E375339BF4C51840
Jan 17 2022, 4:28 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
ikloecker added a comment to T5732: Backport option reading in gpgconf to 2.2.

With rG8c878ae4c9dfa9fe26aa15f4f9db3e86833575e9 some rules for allow-mark-trusted were removed from doc/examples/gpgconf.conf, but the comments below which are supposed to explain the example rules still talk about allow-mark-trusted.

Jan 17 2022, 4:04 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner changed the edit policy for T5783: All s2k hardenings silently ignored when exporting private keys.
Jan 17 2022, 10:39 AM · Not A Bug, gpgagent, OpenPGP, gpg4win, gnupg
gyakovlev added a comment to T5785: libgcrypt-1.9.4 build failure on ppc64le.

sorry, I'm a bit confused now and probably everything I wrote above is incorrect.

Jan 17 2022, 8:47 AM · Gentoo, Bug Report
gyakovlev added a comment to T5785: libgcrypt-1.9.4 build failure on ppc64le.

thanks for approving account.
build error happens in automatic configuration (when --enable-ppc-crypto-support is omitted from ./configure) and -mcpu=powerpc64le, -mcpu=power8 or power9 or -mpower8-vector flags are not passed to compiler.

Jan 17 2022, 8:18 AM · Gentoo, Bug Report
werner added a project to T5782: Kleopatra: Smartcard unusable secret key until used via command line: kleopatra.
Jan 17 2022, 7:45 AM · kleopatra, Bug Report, gpg4win
gniibe added a project to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG: Restricted Project.

Backported to 2.2, too.

Jan 17 2022, 6:24 AM · Restricted Project, Bug Report, gnupg (gpg23)
thesamesam updated subscribers of T5785: libgcrypt-1.9.4 build failure on ppc64le.

On behalf of @gyakovlev (pending approval for his account):

[03:05:23]  <@gyakovlev>  AC_DEFINE(HAVE_COMPATIBLE_CC_PPC_ALTIVEC,1,
[03:05:23]  <@gyakovlev>         [Defined if underlying compiler supports PowerPC AltiVec/VSX/crypto intrinsics])
[03:05:34]  <@gyakovlev> they should definitely check for __POWER8_VECTOR__ 1
[03:05:44]  <@gyakovlev> it's not plain altivec
[03:06:52]  <@gyakovlev> that power check should check for __POWER8_VECTOR__
[03:06:52]  <@gyakovlev> not only for what they check already.
[03:08:59]  <@gyakovlev> it probably should be checked after __powerpc64__ or instead of it.
Jan 17 2022, 4:09 AM · Gentoo, Bug Report
thesamesam added a project to T5785: libgcrypt-1.9.4 build failure on ppc64le: Gentoo.
Jan 17 2022, 3:34 AM · Gentoo, Bug Report
thesamesam added a comment to T5785: libgcrypt-1.9.4 build failure on ppc64le.

Looks like it's triggered if e.g. -mcpu=power9 isn't in CFLAGS.

Jan 17 2022, 3:34 AM · Gentoo, Bug Report
thesamesam added a comment to T5785: libgcrypt-1.9.4 build failure on ppc64le.

Build log here:

Jan 17 2022, 3:32 AM · Gentoo, Bug Report
thesamesam created T5785: libgcrypt-1.9.4 build failure on ppc64le.
Jan 17 2022, 3:31 AM · Gentoo, Bug Report

Jan 16 2022

vitusb renamed T5783: All s2k hardenings silently ignored when exporting private keys from All s2k hardenings silently ignored when doin an export of private keys to All s2k hardenings silently ignored when exporting private keys.
Jan 16 2022, 2:10 PM · Not A Bug, gpgagent, OpenPGP, gpg4win, gnupg
vitusb raised the priority of T5783: All s2k hardenings silently ignored when exporting private keys from High to Needs Triage.
Jan 16 2022, 12:25 PM · Not A Bug, gpgagent, OpenPGP, gpg4win, gnupg

Jan 14 2022

joeyberkovitz created T5782: Kleopatra: Smartcard unusable secret key until used via command line.
Jan 14 2022, 2:54 PM · kleopatra, Bug Report, gpg4win

Jan 12 2022

twpayne added a comment to T5772: pinentry-mac: PIN not escaped when using quality bar.

You'll have to talk to the people you got pinentry-mac from.

Jan 12 2022, 9:48 PM · pinentry, Bug Report
werner triaged T5772: pinentry-mac: PIN not escaped when using quality bar as Normal priority.

I don't know about pinentry-mac but it seems to be another name for
one our our regular pinentry variants.

Jan 12 2022, 3:23 PM · pinentry, Bug Report
ikloecker added a comment to T5772: pinentry-mac: PIN not escaped when using quality bar.

We provide lots of different flavors of pinentry, but we do not provide pinentry-mac. You'll have to talk to the people you got pinentry-mac from.

Jan 12 2022, 3:15 PM · pinentry, Bug Report
ALLEE created T5773: Encrypt file extension as pgp.
Jan 12 2022, 2:42 PM · Support
twpayne created T5772: pinentry-mac: PIN not escaped when using quality bar.
Jan 12 2022, 2:08 PM · pinentry, Bug Report
werner added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

Thanks for diving into the history of that code.

Jan 12 2022, 8:55 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

Here is the backport to 2.2:

Jan 12 2022, 7:35 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

In the original code, register_trusted_keyid is used in keygen.c, so that it updates user_utk_list, thus, will be into utk_list.
This should be done, by adding the keyid to utk_list directly.

Jan 12 2022, 5:41 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe triaged T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG as High priority.

Things have been a bit buggy here (probably, since the beginning).
In g10/trustdb.c,

Jan 12 2022, 5:31 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe claimed T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.
Jan 12 2022, 2:32 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

Let me clarify:

Jan 12 2022, 2:32 AM · Restricted Project, Bug Report, gnupg (gpg23)
gniibe added a project to T5730: During make, compile error under Ubuntu 21.10: gpgme.
Jan 12 2022, 1:46 AM · gpgme, Bug Report

Jan 11 2022

werner moved T5600: Provide module name/version API for FIPS 140-3 from Next to Ready for release on the FIPS board.
Jan 11 2022, 11:05 AM · libgcrypt, FIPS, Bug Report
dkg closed T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl as Resolved.

Thank you, @gniibe ! i'm applying your change to the debian packaging as 1.43-2. i'll let you know if it doesn't satisfy the folks trying to crossbuild debian on top of musl.

Jan 11 2022, 9:53 AM · gpgrt, Bug Report
dkg created T5769: fix typo in autogen.sh.
Jan 11 2022, 9:06 AM · Documentation, gpgrt
gniibe added a comment to T5600: Provide module name/version API for FIPS 140-3.

Thank you.
Applied.

Jan 11 2022, 6:39 AM · libgcrypt, FIPS, Bug Report
gniibe moved T5600: Provide module name/version API for FIPS 140-3 from Ready for release to Next on the FIPS board.
Jan 11 2022, 6:37 AM · libgcrypt, FIPS, Bug Report
gniibe added a project to T5712: Yubikey 5 NFC only recognized immediately after it is inserted: Documentation.
Jan 11 2022, 5:32 AM · Documentation, Bug Report
gniibe claimed T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl.
Jan 11 2022, 5:24 AM · gpgrt, Bug Report
gniibe added a comment to T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl.

Thank you for forwarding from Debian.

Jan 11 2022, 5:23 AM · gpgrt, Bug Report

Jan 10 2022

manphiz added a comment to T5765: gnupg2 weird memory fault on NetBSD Loongson/mips64el N32.

Thanks Werner! As I'm on NetBSD I was able to use ktrace instead, and you can find the output at https://termbin.com/zm2c. (It expires in 1 month. Let me know if you would like me to paste the full output here.)

Jan 10 2022, 9:19 PM · MIPS, Bug Report
jani added a comment to T5764: Broken umlauts in the new Windows Terminal.

That seems to (mostly) work partially fix PowerShell pipeline output at least:

Jan 10 2022, 7:09 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
patrick closed T5763: gpgme-json missing as Invalid.

Oh, I' sorry - my fault. I searched in ...\GnuPG\bin instead of ...\gpg4win\bin

Jan 10 2022, 6:44 PM · Info Needed, Bug Report, gpg4win
werner added projects to T5764: Broken umlauts in the new Windows Terminal: gnupg (gpg23), i18n.
Jan 10 2022, 6:17 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
werner added a comment to T5764: Broken umlauts in the new Windows Terminal.

We use GetConsoleOutputCP but fallback to GetACP if the former fails. For some reasons one of the functions seems to return 437.

Jan 10 2022, 6:16 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
werner added a project to T5765: gnupg2 weird memory fault on NetBSD Loongson/mips64el N32: MIPS.

Given that you are already using libgcrypt 1.9, can you please try gnupg 2.3.4.

Jan 10 2022, 6:04 PM · MIPS, Bug Report
werner closed T5767: scdaemon gets stuck on smartcard access as Resolved.

That is annoying enough that we should do a new release. I close this bug, though.

Jan 10 2022, 6:00 PM · Bug Report, gpg4win
ikloecker added a comment to T5767: scdaemon gets stuck on smartcard access.

See T5758: scd: loop forever with reader_port, when open_pcsc_reader failed. Yes, the workaround is not to set reader-port.

Jan 10 2022, 5:01 PM · Bug Report, gpg4win
Jakuje updated subscribers of T5600: Provide module name/version API for FIPS 140-3.

Sorry for resurrecting the done task, but I got a message from @pmgdeb who noticed there is mismatch between parenthesis in the --with-fips-module-version help string. The attached patch fixes the issue and add proper help text.

Jan 10 2022, 3:41 PM · libgcrypt, FIPS, Bug Report
JanMosigItemis updated the task description for T5767: scdaemon gets stuck on smartcard access.
Jan 10 2022, 2:29 PM · Bug Report, gpg4win
JanMosigItemis created T5767: scdaemon gets stuck on smartcard access.
Jan 10 2022, 2:28 PM · Bug Report, gpg4win
aheinecke added a project to T5763: gpgme-json missing: Info Needed.

I have just checked both the installation script, which still installs gpgme-json.exe and the gpg4win-4 installer downloaded from gpg4win.org gpgme-json.exe is properly installed under <instdir>\bin gpgme-json.exe and under bin_64

Jan 10 2022, 9:00 AM · Info Needed, Bug Report, gpg4win
manphiz created T5765: gnupg2 weird memory fault on NetBSD Loongson/mips64el N32.
Jan 10 2022, 3:57 AM · MIPS, Bug Report

Jan 9 2022

werner triaged T5763: gpgme-json missing as Normal priority.
Jan 9 2022, 6:54 PM · Info Needed, Bug Report, gpg4win
jani updated the task description for T5764: Broken umlauts in the new Windows Terminal.
Jan 9 2022, 3:22 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
jani created T5764: Broken umlauts in the new Windows Terminal.
Jan 9 2022, 3:16 PM · gnupg24, i18n, gnupg (gpg23), Bug Report, gpg4win
patrick renamed T5763: gpgme-json missing from gpgme-json misson to gpgme-json missing.
Jan 9 2022, 2:44 PM · Info Needed, Bug Report, gpg4win
patrick created T5763: gpgme-json missing.
Jan 9 2022, 2:42 PM · Info Needed, Bug Report, gpg4win
dkg created T5762: libgpg-error: permit auto-introspection on non-glibc platforms like musl.
Jan 9 2022, 2:41 AM · gpgrt, Bug Report

Jan 8 2022

werner added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

See T5758. The workaround is not to set a reader-port.

Jan 8 2022, 8:24 PM · Bug Report, gpg4win
werner triaged T5761: Libgcrypt: salt-length for RSA-PSS is not documented as Normal priority.
Jan 8 2022, 8:20 PM · Bug Report, Documentation, libgcrypt

Jan 7 2022

JaminCollins added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

Downgraded the gnupg to 2.2.33 using this installer and I am now able to successfully open the Kleopatra GUI.

Jan 7 2022, 7:09 PM · Bug Report, gpg4win
JaminCollins added a comment to T5760: Kleopatra hangs loading certificate cache on Windows 11.

Should also note that once the GUI is opened, GnuPG's smartcard deamon (32 bit) transitions to Very high power usage and appears stuck there, consuming a full logical core's worth of CPU time.

Jan 7 2022, 7:02 PM · Bug Report, gpg4win
MikhailRyazanov created T5761: Libgcrypt: salt-length for RSA-PSS is not documented.
Jan 7 2022, 4:50 PM · Bug Report, Documentation, libgcrypt

Jan 6 2022

JaminCollins renamed T5760: Kleopatra hangs loading certificate cache on Windows 11 from Kleopatra hangs ___ on Windows 11 to Kleopatra hangs loading certificate cache on Windows 11.
Jan 6 2022, 10:46 PM · Bug Report, gpg4win
JaminCollins created T5760: Kleopatra hangs loading certificate cache on Windows 11.
Jan 6 2022, 10:45 PM · Bug Report, gpg4win

Jan 4 2022

gniibe claimed T5747: Provide a way to request non-FIPS service in FIPS mode.
Jan 4 2022, 11:16 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5747: Provide a way to request non-FIPS service in FIPS mode from Backlog to Next on the FIPS board.
Jan 4 2022, 11:16 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5636: Run integrity checks + selftests from library constructor in FIPS from Next to Ready for release on the FIPS board.
Jan 4 2022, 11:16 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

And I'm testing following:

Jan 4 2022, 6:40 AM · Feature Request, FIPS, libgcrypt
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

The "at first" change done.

Jan 4 2022, 6:40 AM · Feature Request, FIPS, libgcrypt
gniibe added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

At first, I think that we need to change the way how libgcrypt rejects non-approved cipher/md/mac/pk.

Jan 4 2022, 3:30 AM · Feature Request, FIPS, libgcrypt

Dec 30 2021

werner changed the status of T5732: Backport option reading in gpgconf to 2.2 from Open to Testing.

Backport done but diligent testing is required.

Dec 30 2021, 10:51 AM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)

Dec 23 2021

werner closed T5744: Issue with connecting to GPG server as Resolved.

The debug log was from gpg and not from dirmngr and thus it is not helpful. I also guess that an older dirmngr was still running, because the LE bug has been fixed in 2.3.4.

Dec 23 2021, 5:31 PM · Bug Report, gpg4win
vsajip added a comment to T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG.

Will go into 2.3.4.

Dec 23 2021, 12:13 PM · Restricted Project, Bug Report, gnupg (gpg23)
ikloecker closed T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches as Resolved.
Dec 23 2021, 11:38 AM · Restricted Project, kleopatra, Bug Report
ikloecker added a comment to T5744: Issue with connecting to GPG server.

And --keyserver-options check-cert is removed from new gpg versions (((

Dec 23 2021, 11:36 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

Here is log in english

Dec 23 2021, 10:28 AM · Bug Report, gpg4win

Dec 22 2021

alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

And --keyserver-options check-cert is removed from new gpg versions (((

Dec 22 2021, 5:11 PM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.
Dec 22 2021, 4:48 PM · Bug Report, gpg4win
alexnadtoka reopened T5744: Issue with connecting to GPG server as "Open".
Dec 22 2021, 4:10 PM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

@werner can you show me tutorial for proper bug submit? I think it is a bug and gpg client on Windows does not support valid LetsEncrypt certificates on keyserver. It does not work with any keys server . Tested few public keyservers as well. ((

Dec 22 2021, 4:09 PM · Bug Report, gpg4win
ikloecker added a comment to T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches.

We decided to notify the user if the keyserver doesn't return fingerprints. The fingerprints are needed by Kleopatra as unique identifier for keys. Trying to make key lookup work without fingerprints isn't useful.

Dec 22 2021, 3:34 PM · Restricted Project, kleopatra, Bug Report
werner closed T5744: Issue with connecting to GPG server as Resolved.

Please see https://gnupg.org

Dec 22 2021, 7:26 AM · Bug Report, gpg4win

Dec 21 2021

werner added a comment to T5747: Provide a way to request non-FIPS service in FIPS mode.

FWIW, We have a similar mechanism for the secure memory

Dec 21 2021, 6:12 PM · Feature Request, FIPS, libgcrypt
ikloecker changed the status of T5745: Kleopatra: Card holder name is not correctly decoded from Open to Testing.
Dec 21 2021, 5:02 PM · Restricted Project, kleopatra, Bug Report
Jakuje created T5747: Provide a way to request non-FIPS service in FIPS mode.
Dec 21 2021, 4:58 PM · Feature Request, FIPS, libgcrypt
Saturneric updated the task description for T5746: Pinetry always loses focus after popping up under Windows.
Dec 21 2021, 2:52 PM · Not A Bug, pinentry
Saturneric created T5746: Pinetry always loses focus after popping up under Windows.
Dec 21 2021, 2:49 PM · Not A Bug, pinentry
Saturneric added a comment to T5712: Yubikey 5 NFC only recognized immediately after it is inserted.

Recently, I have encountered many problems in adapting the graphical interface interaction between Yubikey and gnupg. I am thinking about why some settings need to be manually added to some additional settings. I found that there are many such solutions on the Internet. Is there any way that scdaemon can automatically recognize these situations and add appropriate settings.

Dec 21 2021, 2:42 PM · Documentation, Bug Report
ikloecker claimed T5745: Kleopatra: Card holder name is not correctly decoded.
Dec 21 2021, 2:33 PM · Restricted Project, kleopatra, Bug Report
ikloecker created T5745: Kleopatra: Card holder name is not correctly decoded.
Dec 21 2021, 2:32 PM · Restricted Project, kleopatra, Bug Report
werner edited projects for T5742: Apparent regressions between 2.2.32 and 2.2.33 of GnuPG, added: gnupg (gpg23), Bug Report; removed gnupg (gpg22).

Things are not that easy. I actually introduced a bug in 2.3.4. Here is a comment from my working copy:

Dec 21 2021, 11:22 AM · Restricted Project, Bug Report, gnupg (gpg23)
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

@werner Thank you for the answer. Please advise mailing list address.

Dec 21 2021, 10:44 AM · Bug Report, gpg4win
werner added a comment to T5744: Issue with connecting to GPG server.

For support please use the mailing list and not the bug tracker.

Dec 21 2021, 10:26 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

GNUpg version 2.3.4 was installed but did not help

Dec 21 2021, 9:41 AM · Bug Report, gpg4win
alexnadtoka added a comment to T5744: Issue with connecting to GPG server.

Is there a way to ignore SSL check during connection? This might work. We have internal server for our users only.

Dec 21 2021, 9:39 AM · Bug Report, gpg4win
alexnadtoka created T5744: Issue with connecting to GPG server.
Dec 21 2021, 9:38 AM · Bug Report, gpg4win

Dec 20 2021

ikloecker added a comment to T5725: Kleopatra: Certificate lookup shows only one result even if there are 100s matches.

That KeyListJob returns keys which have fingerprint NULL is caused by keyservers returning just key IDs instead of fingerprints. The change for T5741: dirmngr does not ask keyservers for fingerprints should fix this. Still keyservers are only guaranteed to return key IDs, so we cannot assume that keys returned by KeyListJob have fingerprints.

Dec 20 2021, 9:38 AM · Restricted Project, kleopatra, Bug Report

Dec 17 2021

Saturneric added a comment to T5737: last_update in gpgme_key_t always be nullptr.

Thanks!
I will study it soon.

Dec 17 2021, 8:13 AM · Support, gpgme