Page MenuHome GnuPG
Feed Advanced Search

Jul 27 2022

werner committed rGabe69b2094dd: gpg: Look up user ID to revoke by UID hash (authored by ikloecker).
gpg: Look up user ID to revoke by UID hash
Jul 27 2022, 5:24 PM
werner changed the status of T5936: gpg: Support specifiying user ID to revoke as UID hash for --quick-revoke-uid from Open to Testing.

Backported for for 2.2.37

Jul 27 2022, 4:37 PM · gnupg (gpg23), Restricted Project, Feature Request
werner changed the status of T5936: gpg: Support specifiying user ID to revoke as UID hash for --quick-revoke-uid, a subtask of T4087: Kleopatra: Revoke User-ID, from Open to Testing.
Jul 27 2022, 4:37 PM · Restricted Project, Restricted Project, gpg4win, kleopatra, Feature Request
werner triaged T6109: Kleopatra: Better way to show expired subkeys as Normal priority.
Jul 27 2022, 3:22 PM · Feature Request, OpenPGP, kleopatra
werner changed the status of T6098: Path traversal bug in gpg-wks-server from Open to Testing.

Fix will go into 2.2.37 and 2.3.8.

Jul 27 2022, 12:33 PM · wkd, gnupg
werner committed rG73a98c139691: wkd: Bind the address to the nonce. (authored by werner).
wkd: Bind the address to the nonce.
Jul 27 2022, 12:31 PM
werner shifted T6098: Path traversal bug in gpg-wks-server from the Restricted Space space to the S1 Public space.
Jul 27 2022, 11:43 AM · wkd, gnupg
werner committed rG4c8792fa10b6: wkd: Bind the address to the nonce. (authored by werner).
wkd: Bind the address to the nonce.
Jul 27 2022, 11:43 AM
werner committed rG77090e5260e4: tests: Add missing file for tpm2d tests to the tarball. (authored by werner).
tests: Add missing file for tpm2d tests to the tarball.
Jul 27 2022, 11:43 AM
werner closed T6107: Completely lost ability to create PGP Keys as Resolved.
Jul 27 2022, 8:37 AM · Support
werner updated the task description for T6098: Path traversal bug in gpg-wks-server.
Jul 27 2022, 8:26 AM · wkd, gnupg
werner renamed T6098: Path traversal bug in gpg-wks-server from Pass traversal bug in gpg-wks-server to Path traversal bug in gpg-wks-server.
Jul 27 2022, 8:20 AM · wkd, gnupg

Jul 26 2022

werner closed T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) as Resolved.
Jul 26 2022, 9:17 PM · gnupg (gpg22), CVE, gpg4win
werner closed T5977: Smartcard PIN stays in clear in memory as Resolved.
Jul 26 2022, 9:17 PM · backport, libassuan, pinentry, scd, gnupg (gpg22), Bug Report
werner added a project to T6052: gnupg2 tpm2d tests do not work: Tests.
Jul 26 2022, 9:15 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner added a project to T6052: gnupg2 tpm2d tests do not work: TPM.
Jul 26 2022, 9:14 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner created TPM.
Jul 26 2022, 9:14 PM
werner closed T6052: gnupg2 tpm2d tests do not work as Resolved.
Jul 26 2022, 9:12 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner claimed T6052: gnupg2 tpm2d tests do not work.
Jul 26 2022, 9:12 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner triaged T6071: Duplicated output (repeated nearly once) of the GnuPG console-output to "stdout" on Windows-Console if "Legacy-Console" with any TrueType Fonts is activated under Windows as Normal priority.
Jul 26 2022, 9:07 PM · Windows, gnupg, Bug Report
werner triaged T6041: pinentry-qt dialog window no longer floats under Sway (fixed after 1.2.0) as Normal priority.
Jul 26 2022, 9:07 PM · Restricted Project, pinentry, Bug Report
werner closed T6038: gpg-wks-client excludes uid with URL in comment as Resolved.

Probably fixed meanwhile in 2.2.
Please re-open if experience this problem also with a decent gnupg 2.2 versions.

Jul 26 2022, 9:06 PM · gnupg (gpg22), wkd, Bug Report
werner closed T6014: Add support for relative redirect URI-references to dirmngr as Resolved.

Probably an invalid specified keyserver

Jul 26 2022, 9:03 PM · gnupg24, dirmngr, Bug Report
werner triaged T6051: Allow revoking last UID of primary key with expert mode as Low priority.
Jul 26 2022, 9:01 PM · OpenPGP, Feature Request, gnupg
werner triaged T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python) as Normal priority.
Jul 26 2022, 8:59 PM · Python, gpgme, Bug Report
werner closed T5899: Fix compilation of dirmngr with mingw.org's MinGW as Resolved.
Jul 26 2022, 8:58 PM · patch, Feature Request, Windows, toolchain
werner added a project to T5990: Option to ignore the user trustlist.txt: backport.
Jul 26 2022, 8:57 PM · Restricted Project, Restricted Project, gnupg (gpg22), S/MIME, gpgagent
werner closed T6037: Allow import of nwer DFN generated P12 files as Resolved.
Jul 26 2022, 8:53 PM · gnupg (gpg22), S/MIME
werner added a project to T5936: gpg: Support specifiying user ID to revoke as UID hash for --quick-revoke-uid: backport.
Jul 26 2022, 7:44 PM · gnupg (gpg23), Restricted Project, Feature Request
werner updated the task description for T5947: Release GnuPG 2.3.7.
Jul 26 2022, 7:40 PM · CVE, Release Info, gnupg (gpg23)
werner triaged T6106: Release GnuPG 2.3.8 as Normal priority.
Jul 26 2022, 7:37 PM · Release Info, gnupg (gpg23)
werner closed T5937: Release GnuPG 2.3.6 as Resolved.
Jul 26 2022, 7:34 PM · Release Info, gnupg (gpg23)
werner closed T5949: Release GnuPG 2.2.36 as Resolved.
Jul 26 2022, 7:34 PM · CVE, gnupg (gpg22), Release Info
werner triaged T6105: Release GnuPG 2.2.37 as Normal priority.
Jul 26 2022, 7:33 PM · gnupg (gpg22), Release Info
werner updated the task description for T5949: Release GnuPG 2.2.36.
Jul 26 2022, 7:31 PM · CVE, gnupg (gpg22), Release Info
werner triaged T6098: Path traversal bug in gpg-wks-server as High priority.
Jul 26 2022, 12:36 PM · wkd, gnupg
werner added projects to T6069: Kleopatra crashes when creating UIServer socket: Windows, kleopatra, Info Needed.
Jul 26 2022, 11:04 AM · Info Needed, kleopatra, Windows, Bug Report
werner triaged T6054: ambiguous error message when output file exists already as Low priority.

That is not easy to change because we show all kind of error codes. If you run in --verbose mode you should see more info.

Jul 26 2022, 11:03 AM · Bug Report
werner triaged T6053: max passphrase lengths as Normal priority.
Jul 26 2022, 10:59 AM · gnupg, Documentation
werner triaged T6058: clarify need of --batch and/or --pinentry-mode looback with --passphrase-* options as Low priority.

There won't be any semantic changes for obvious reasons.

Jul 26 2022, 10:58 AM · gnupg, Documentation
werner triaged T6085: pinentry-qt: Earlier passphrase hint when creating new key as Normal priority.
Jul 26 2022, 10:56 AM · gnupg, Restricted Project, pinentry
werner committed rG1735b5ffa879: doc: Minor typo fix (authored by werner).
doc: Minor typo fix
Jul 26 2022, 10:52 AM
werner closed T6092: Minor typo in documentation as Resolved.

Thanks for reporting.

Jul 26 2022, 10:52 AM · patch, Documentation, Bug Report
werner added a comment to T6092: Minor typo in documentation.

The first thing is a problem of the GNU makeinfo tool. Can't be fixed int the source.

Jul 26 2022, 10:50 AM · patch, Documentation, Bug Report
werner committed rG22e8dc792702: dirmngr: Ask keyservers to provide the key fingerprints (authored by ikloecker).
dirmngr: Ask keyservers to provide the key fingerprints
Jul 26 2022, 9:47 AM

Jul 25 2022

werner triaged T6068: clarify what a line is in --passphrase-fd and --passphrase-file as Low priority.
Jul 25 2022, 3:57 PM · Documentation
werner committed rGee8f1c10a7a5: gpg: Request keygrip of key to add via command interface (authored by ikloecker).
gpg: Request keygrip of key to add via command interface
Jul 25 2022, 3:18 PM
werner committed rGc1489ca0e101: wkd: Fix path traversal attack on gpg-wks-server. (authored by werner).
wkd: Fix path traversal attack on gpg-wks-server.
Jul 25 2022, 2:54 PM
werner committed rG8a63a8c8257e: wkd: Fix path traversal attack on gpg-wks-server. (authored by werner).
wkd: Fix path traversal attack on gpg-wks-server.
Jul 25 2022, 10:39 AM

Jul 11 2022

werner committed rDe2d6e8d4aa1b: swdb: GnuPG 2.3.7 (authored by werner).
swdb: GnuPG 2.3.7
Jul 11 2022, 2:16 PM
werner committed rG95651d1a4fec: Post release updates (authored by werner).
Post release updates
Jul 11 2022, 1:42 PM
werner committed rGbc5328f5119a: Release 2.3.7 (authored by werner).
Release 2.3.7
Jul 11 2022, 1:42 PM

Jul 10 2022

werner committed rG1d5bf0050e74: gpg-connect-agent: No help string for --unbuffered (authored by werner).
gpg-connect-agent: No help string for --unbuffered
Jul 10 2022, 5:01 PM

Jul 6 2022

werner committed rDaf411baa9c20: swdb: GnuPG 2.2.36 (authored by werner).
swdb: GnuPG 2.2.36
Jul 6 2022, 8:34 PM
werner added a comment to T5949: Release GnuPG 2.2.36.

Please note that due to vacation issues the signatures use the gnupg.com Brainpool based release key and some Linux distributions come with Brainpool removed from GnuPG.

Jul 6 2022, 8:33 PM · CVE, gnupg (gpg22), Release Info
werner updated the task description for T5949: Release GnuPG 2.2.36.
Jul 6 2022, 8:30 PM · CVE, gnupg (gpg22), Release Info
werner committed rG3777bc652879: Post release updates (authored by werner).
Post release updates
Jul 6 2022, 8:19 PM
werner committed rG491645b50ec9: Release 2.3.36 (authored by werner).
Release 2.3.36
Jul 6 2022, 8:19 PM

Jun 29 2022

werner triaged T6047: Dirmngr - LDAP Schema V2 not used when Base DN is specified as Normal priority.

The first ideas sounds best to me. Patches please to the mailing list.

Jun 29 2022, 5:16 PM · LDAP, dirmngr, gnupg (gpg23), Feature Request
werner committed rGf357a5f23991: gpgconf: New short options -V and -X (authored by werner).
gpgconf: New short options -V and -X
Jun 29 2022, 1:24 PM
werner committed rG15a8834b0b4a: gpgconf: New short options -V and -X (authored by werner).
gpgconf: New short options -V and -X
Jun 29 2022, 1:16 PM

Jun 27 2022

werner committed rGae2f1f0785e4: agent: Do not consider --min-passphrase-len for the magic wand. (authored by werner).
agent: Do not consider --min-passphrase-len for the magic wand.
Jun 27 2022, 6:16 PM

Jun 23 2022

werner added a comment to T6035: Portability issue: ftruncate.

ACK. P[ease add it also to 2.2.

Jun 23 2022, 10:50 AM · backport, gpgagent, gnupg
werner closed T6015: Default OpenPGP keyserver as Resolved.
Jun 23 2022, 10:48 AM · Support, gpg4win
werner triaged T6020: Make %-expandos available for --default-keyserver-url as Normal priority.
Jun 23 2022, 10:48 AM · gnupg24, Feature Request, Keyserver
werner added a subtask for T6020: Make %-expandos available for --default-keyserver-url: T6040: Allow embedding preferred keyserver URL in signatures.
Jun 23 2022, 10:47 AM · gnupg24, Feature Request, Keyserver
werner added a parent task for T6040: Allow embedding preferred keyserver URL in signatures: T6020: Make %-expandos available for --default-keyserver-url.
Jun 23 2022, 10:47 AM · gnupg24, Feature Request, Keyserver
werner triaged T6040: Allow embedding preferred keyserver URL in signatures as Normal priority.
Jun 23 2022, 10:46 AM · gnupg24, Feature Request, Keyserver
werner added a project to T6038: gpg-wks-client excludes uid with URL in comment: gnupg (gpg22).
Jun 23 2022, 10:43 AM · gnupg (gpg22), wkd, Bug Report

Jun 22 2022

werner added a comment to T5988: agent: Add new command to update private key fields.

What about rejected changes to "Key:"? Other this command would make it too easy to mess up the actual private key.

Jun 22 2022, 2:54 PM · Feature Request, ssh, gpgagent

Jun 21 2022

werner committed rG4c14bbf56fb5: sm: Update pkcs#12 module from master (authored by werner).
sm: Update pkcs#12 module from master
Jun 21 2022, 6:29 PM
werner committed rGd21ced1e3596: common: Add an easy to use DER builder. (authored by werner).
common: Add an easy to use DER builder.
Jun 21 2022, 6:29 PM

Jun 20 2022

werner removed a reviewer for D556: Disallow compressed signatures and certificates: werner.
Jun 20 2022, 8:29 PM
werner committed rG52f9e13c0cb3: sm: Improve pkcs#12 debug output. (authored by werner).
sm: Improve pkcs#12 debug output.
Jun 20 2022, 5:34 PM
werner committed rGa4e04375e84e: sm: Rework the PKCS#12 parser to support DFN issued keys. (authored by werner).
sm: Rework the PKCS#12 parser to support DFN issued keys.
Jun 20 2022, 5:34 PM
werner triaged T6037: Allow import of nwer DFN generated P12 files as Normal priority.
Jun 20 2022, 4:43 PM · gnupg (gpg22), S/MIME
werner triaged T6035: Portability issue: ftruncate as Normal priority.
Jun 20 2022, 1:08 PM · backport, gpgagent, gnupg
werner added a comment to T6033: Regression in GnuPG 2.2.34 with some ECC keys.

I fixed the title, because it is not a Windows only issue.

Jun 20 2022, 1:07 PM · Bug Report, gnupg (gpg22)
werner renamed T6033: Regression in GnuPG 2.2.34 with some ECC keys from Regression in GnuPG 2.2.34 on Windows to Regression in GnuPG 2.2.34 with some ECC keys.
Jun 20 2022, 1:06 PM · Bug Report, gnupg (gpg22)
werner added a comment to T6033: Regression in GnuPG 2.2.34 with some ECC keys.

The mentioned "g10: Fix garbled status messages in NOTATION_DATA" has nothing to do with the problem. So it can'r be the actual cause. Anway, I hope to get a 2.2.36 out this week.

Jun 20 2022, 1:05 PM · Bug Report, gnupg (gpg22)
werner added a comment to T6035: Portability issue: ftruncate.

iirc, we use ftruncate for ages now. The problem with the name ftruncate is that it looks to similar to the stdio functions. But sure, things should be flushed first.

Jun 20 2022, 12:59 PM · backport, gpgagent, gnupg
werner removed a reviewer for D555: g10: Disallow compressed signatures and certificates: gniibe.
Jun 20 2022, 8:05 AM · gnupg

Jun 17 2022

werner assigned T6033: Regression in GnuPG 2.2.34 with some ECC keys to gniibe.

The likely cause is that the secret key is not protected. Problem seems to be in gpg-agent.

Jun 17 2022, 12:39 PM · Bug Report, gnupg (gpg22)
werner triaged T6033: Regression in GnuPG 2.2.34 with some ECC keys as High priority.

Looking again at your report, I don't think it is an IPC problem (bad magic cooky was my assumption). I can replicate this with the current 2.2 but not with 2.3. Both un Unix.

Jun 17 2022, 12:36 PM · Bug Report, gnupg (gpg22)
werner committed rGbe5d06dae239: agent: Improve "Insert the card" message. (authored by werner).
agent: Improve "Insert the card" message.
Jun 17 2022, 12:24 PM
werner triaged T6030: Missing support for the Brave Web Browser on Windows as Normal priority.
Jun 17 2022, 7:48 AM · gpgme, Feature Request, gpg4win

Jun 16 2022

werner removed a member for Contributor: DemiMarie.
Jun 16 2022, 7:03 PM
werner closed T6021: GPG misparses `--list-options=show-sig-subpackets="100"a` as Wontfix.

Please don't play ping pong now,

Jun 16 2022, 7:02 PM · g10, Bug Report
werner closed T6032: Assertion failure in gpg as Invalid.

Please report such bugs to RedHat - they use a modified Libgcrypt and thus it's there bug.

Jun 16 2022, 7:00 PM · RHEL, g10, Bug Report
werner resigned from D555: g10: Disallow compressed signatures and certificates.
Jun 16 2022, 6:58 PM · gnupg
werner requested changes to D555: g10: Disallow compressed signatures and certificates.

Sorry, there is no padding packet in OpenPGP. Please do no try to push ideas from that crypto-refresh-06 thing into GnuPG. We continue to follow the last draft with consesus, which is rfc4880bis-10.

Jun 16 2022, 6:56 PM · gnupg
werner renamed T6031: Creating an overlong notation hits a fatal error. from Creating an overlong notation crashes gpg to Creating an overlong notation hits a fatal error..
Jun 16 2022, 6:54 PM · Bug Report, gnupg
werner triaged T6031: Creating an overlong notation hits a fatal error. as Wishlist priority.

The length limit of the signature sub packets are not reasy to pre-compute. Better to have a fatal error than a corrupt message. I am not sure whether we want to change this to a regualar error message - at that point we anyway need to stop.

Jun 16 2022, 6:54 PM · Bug Report, gnupg
werner edited projects for T6033: Regression in GnuPG 2.2.34 with some ECC keys, added: Not A Bug, Windows, gnupg (gpg22); removed Bug Report.

You deleted the socket file but you did not restart the agent. Thus gpg can't contact the agent anymore. On Windows we use a socket emulation which requires the socket's file only for a new connection (to get the port and magic cookie).

Jun 16 2022, 6:48 PM · Bug Report, gnupg (gpg22)
werner added a comment to T6032: Assertion failure in gpg.

Please provide a test case.

Jun 16 2022, 6:39 PM · RHEL, g10, Bug Report
werner triaged T6029: ntbtls: Require TLS 1.2 or later + AEAD by default as Normal priority.
Jun 16 2022, 6:37 PM · Not A Bug, ntbtls

Jun 15 2022

werner committed rG2766b9e56c77: agent,ssh: Fix for make not-inserted OpenPGP.3 keys available for SSH. (authored by werner).
agent,ssh: Fix for make not-inserted OpenPGP.3 keys available for SSH.
Jun 15 2022, 4:42 PM
werner committed rG1530d04725d4: agent: New option --no-user-trustlist and --sys-trustlist-name. (authored by werner).
agent: New option --no-user-trustlist and --sys-trustlist-name.
Jun 15 2022, 9:26 AM

Jun 14 2022

werner added a comment to rMd59cf1725755: tests: Add support for clear text signatures to test runner.

When I replied to the bug report I had the very same idea. Thanks for adding.

Jun 14 2022, 12:28 PM
werner closed T6027: Revisit write_status_text_and buffer as Resolved.
Jun 14 2022, 11:42 AM · Bug Report, gnupg (gpg23)