Page MenuHome GnuPG
Feed All Stories

Mar 14 2023

werner moved T6386: gpg-agent 2.2: Command "READKEY --card --no-data -- OPENPGP.1" overwrites protected-private-key with shadowed-private-key from Backlog to QA on the gnupg22 board.

Ignoring the error seems to be the best choice. I also think that --force should not overwrite a shadow key file. It seems safer to explicitly delete the key first. A --force option for READKEY does not sound right.

Mar 14 2023, 10:26 AM · gnupg22 (gnupg-2.2.42), Bug Report
werner committed rGb28d9ff865a0: agent: Do not overwrite a key file by a shadow key file. (authored by werner).
agent: Do not overwrite a key file by a shadow key file.
Mar 14 2023, 10:16 AM
werner committed rG4f754caad885: agent: Make --disable-extended-key-format a dummy option. (authored by werner).
agent: Make --disable-extended-key-format a dummy option.
Mar 14 2023, 10:16 AM
werner added a comment to T6386: gpg-agent 2.2: Command "READKEY --card --no-data -- OPENPGP.1" overwrites protected-private-key with shadowed-private-key.

I did some reworking and the outcome of the READKEY command is now (agent log):

Mar 14 2023, 10:01 AM · gnupg22 (gnupg-2.2.42), Bug Report
werner closed T6406: gpg-agent: Fail on expiring YubiKey PIN as Resolved.
Mar 14 2023, 9:31 AM · Not A Bug, yubikey, gpgagent
uwi added a comment to T6407: Portable installation shows empty window for Kleopatra.

I checked it: There was an empty bin/gpgconf.ctl, and there still is.
Trying it again today, I still get error messages most notably about failed self-tests, but surprisingly the window is no longer empty.
Instead it seems to take an eternity (minutes, actually still not finished after three minutes) until the certificate cache is loaded.
Maybe the problem is the "Check Point Endpoint Security" being active on the client. It looks as if it prevents use of Kleopatra.
As I don't have administrator rights ("for security reasons"), I cannot analyze what's actually going on.

Mar 14 2023, 9:28 AM · kleopatra, Bug Report, gpg4win
l10n daemon script <scripty@kde.org> committed rLIBKLEOd1ab3070ae7b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 14 2023, 4:43 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAcd1356c1a2b7: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 14 2023, 4:42 AM
gniibe committed rCfae63f517906: tests: Improve test coverage for FIPS service indicators. (authored by Jakuje).
tests: Improve test coverage for FIPS service indicators.
Mar 14 2023, 4:33 AM
gniibe committed rCe0a5a9eb8301: fips: Explicitly disable overriding random in FIPS mode. (authored by Jakuje).
fips: Explicitly disable overriding random in FIPS mode.
Mar 14 2023, 4:33 AM
gniibe committed rC4c1c8a707f96: fips: Explicitly allow only some PK flags. (authored by Jakuje).
fips: Explicitly allow only some PK flags.
Mar 14 2023, 4:33 AM
gniibe committed rC0b7ad923978f: doc: Document the new FIPS indicators. (authored by tobhe).
doc: Document the new FIPS indicators.
Mar 14 2023, 4:33 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA4e9a7de6f364: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 14 2023, 3:01 AM

Mar 13 2023

danisanti added a comment to T6406: gpg-agent: Fail on expiring YubiKey PIN.

I never made a threat model. But definitely *any* cracker, should be out of my system, either from governmental agencies or from a kiddo in Russia.
I know that I have someone that is remote accessing my machine, since I got some tells. And that this cracker have used my Emacs text editor.

Mar 13 2023, 10:00 PM · Not A Bug, yubikey, gpgagent
ikloecker added a comment to T6409: Kleopatra: misleading representation of key with multiple uids in sign/encrypt dialog.

For non-vsde-enabled installations the green check symbol is okay because in the given context (encryption) it indicates that the key can be used.

Mar 13 2023, 9:05 PM · vsd, Feature Request, Restricted Project, kleopatra
mlaurent committed rLIBKLEO413b7eb3801a: GIT_SILENT: don't duplicate KF_MIN_VERSION (authored by mlaurent).
GIT_SILENT: don't duplicate KF_MIN_VERSION
Mar 13 2023, 7:45 PM
ebo created T6409: Kleopatra: misleading representation of key with multiple uids in sign/encrypt dialog.
Mar 13 2023, 3:04 PM · vsd, Feature Request, Restricted Project, kleopatra
mlaurent committed rLIBKLEO8b8afdc83130: GIT_SILENT: time to increase version (authored by mlaurent).
GIT_SILENT: time to increase version
Mar 13 2023, 1:57 PM
uwi added a comment to T6408: Multiple key rings (Groups).

Seeing that there are "groups" in Kleopatra, I read the docs, and they suggested that the groups are for addressing multiple recipients.

Mar 13 2023, 1:56 PM · Feature Request, gpg4win
mlaurent committed rKLEOPATRAfdbd14c41085: GIT_SILENT: time to increase version (authored by mlaurent).
GIT_SILENT: time to increase version
Mar 13 2023, 1:54 PM
aheinecke closed T6408: Multiple key rings (Groups) as Invalid.

Settings -> Configure Groups.

Mar 13 2023, 11:37 AM · Feature Request, gpg4win
aheinecke closed T6407: Portable installation shows empty window for Kleopatra as Invalid.

It seems that you are missing the step "Create a new file called gpgconf.ctl in the folder Gpg4win_Portable/bin."

Mar 13 2023, 11:35 AM · kleopatra, Bug Report, gpg4win
uwi created T6408: Multiple key rings (Groups).
Mar 13 2023, 10:55 AM · Feature Request, gpg4win
uwi created T6407: Portable installation shows empty window for Kleopatra.
Mar 13 2023, 10:50 AM · kleopatra, Bug Report, gpg4win
aheinecke changed the status of T6346: Kleopatra: Run self test only at the first start on windows, a subtask of T6259: Kleopatra: Improve startup performance , from Open to Testing.
Mar 13 2023, 10:01 AM · vsd32 (vsd-3.2.0), gnupg, kleopatra, Restricted Project
aheinecke changed the status of T6346: Kleopatra: Run self test only at the first start on windows from Open to Testing.
Mar 13 2023, 10:01 AM · kleopatra, Restricted Project
werner added a comment to T6386: gpg-agent 2.2: Command "READKEY --card --no-data -- OPENPGP.1" overwrites protected-private-key with shadowed-private-key.

I am pretty sure we have the same problem in 2.4 - due to different access patterns it might not exhibit itself.

Mar 13 2023, 9:34 AM · gnupg22 (gnupg-2.2.42), Bug Report
werner committed rG6d792ae2eb46: agent: Make --disable-extended-key-format a dummy option. (authored by werner).
agent: Make --disable-extended-key-format a dummy option.
Mar 13 2023, 9:12 AM
ikloecker moved T6373: Kleopatra: Show progress dialog when moving decrypted archive to final destination from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Mar 13 2023, 8:21 AM · Restricted Project, kleopatra
werner committed rGdb73f17f0c97: gpgconf,w32: Also print a GnuPG Install Directory Registry entry (authored by werner).
gpgconf,w32: Also print a GnuPG Install Directory Registry entry
Mar 13 2023, 7:45 AM
werner edited projects for T6406: gpg-agent: Fail on expiring YubiKey PIN, added: Not A Bug; removed Bug Report.

Smartcard PINs are different from passphrase for on-disk keys. Once a PIN is entered the smartcard is unlocked as long as it is powered up. In theory we could power down and power up the card to lock it. The question here is what is your threat model? If you have malware on your system it could simply brick your token or, more common, peek at your PIN.

Mar 13 2023, 7:29 AM · Not A Bug, yubikey, gpgagent
l10n daemon script <scripty@kde.org> committed rLIBKLEO148c82f9dddc: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 13 2023, 4:56 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA743e9c995b9a: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 13 2023, 4:56 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOb65a99aab857: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 13 2023, 3:15 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA83b8d2b49a17: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 13 2023, 3:14 AM

Mar 12 2023

werner added a comment to T6280: Release GnuPG 2.2.41.

Pushed to this site. Thanks for noting.

Mar 12 2023, 8:08 PM · gnupg22, Release Info
l10n daemon script <scripty@kde.org> committed rLIBKLEO15b6685e38f3: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 7:06 PM
l10n daemon script <scripty@kde.org> committed rLIBKLEOa731d8d9084b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 4:31 PM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA1f8b8867ab1d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 4:31 PM
mlaurent committed rLIBKLEO3f51238acad6: GIT_SILENT: master is open (authored by mlaurent).
GIT_SILENT: master is open
Mar 12 2023, 10:45 AM
mlaurent committed rKLEOPATRA2699982b5b26: GIT_SILENT: master is open (authored by mlaurent).
GIT_SILENT: master is open
Mar 12 2023, 10:43 AM
mlaurent committed rLIBKLEO102078debe4c: GIT_SILENT: prepare 23.04 beta (authored by mlaurent).
GIT_SILENT: prepare 23.04 beta
Mar 12 2023, 10:26 AM
mlaurent committed rKLEOPATRA9813daaccee6: GIT_SILENT: prepare 23.04 beta (authored by mlaurent).
GIT_SILENT: prepare 23.04 beta
Mar 12 2023, 10:24 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO72f744fbc57d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 7:26 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAb62e0b97d6a3: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 7:23 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAfa6c4acf42b7: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Mar 12 2023, 6:47 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO51a36790ac6b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 4:33 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA505f6dbca9db: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 12 2023, 4:30 AM

Mar 11 2023

lazka added a comment to T6280: Release GnuPG 2.2.41.

I think this is still missing a tag in git (I don't see it in https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=tags)

Mar 11 2023, 9:27 PM · gnupg22, Release Info
danisanti created T6406: gpg-agent: Fail on expiring YubiKey PIN.
Mar 11 2023, 4:50 PM · Not A Bug, yubikey, gpgagent
mlaurent committed rLIBKLEO0022fef9d2a7: GIT_SILENT: master is opened (authored by mlaurent).
GIT_SILENT: master is opened
Mar 11 2023, 9:25 AM
mlaurent committed rLIBKLEOd5ee09eaaec2: GIT_SILENT: prepare 5.23.0 beta (authored by mlaurent).
GIT_SILENT: prepare 5.23.0 beta
Mar 11 2023, 9:10 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO8a35b23b60f1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 11 2023, 6:21 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA0b9800a69ca9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 11 2023, 6:19 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA2debdc4244d0: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Mar 11 2023, 5:57 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO8ebdb98887b9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 11 2023, 3:22 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA3fb2b73c0ee5: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 11 2023, 3:20 AM

Mar 10 2023

Albert Astals Cid <aacid@kde.org> committed rKLEOPATRAb1ec928003af: GIT_SILENT Upgrade release service version to 23.07.70. (authored by Albert Astals Cid <aacid@kde.org>).
GIT_SILENT Upgrade release service version to 23.07.70.
Mar 10 2023, 9:49 PM
Albert Astals Cid <aacid@kde.org> committed rKLEOPATRAb9dd9af8e0eb: GIT_SILENT Upgrade release service version to 23.03.80. (authored by Albert Astals Cid <aacid@kde.org>).
GIT_SILENT Upgrade release service version to 23.03.80.
Mar 10 2023, 8:52 PM
saper added a comment to T5401: Imported ECC/Ed25519 subkey has unusable key file in private-keys-v1.d.

I've run into a variant of this, too. If I generate they key just using (genkey (ecc (curve "Ed25519"))), it is recognized as an encryption key. One needs to use (genkey (ecc (curve "Ed25519")(flags eddsa))).

Mar 10 2023, 4:54 PM · gnupg24, Bug Report
werner accepted D565: curses: Change error reported for terminal issues.
Mar 10 2023, 4:11 PM
ebo closed T5711: Kleopatra: Keyserver config does not fallback to default as Resolved.
Mar 10 2023, 1:41 PM · Restricted Project, kleopatra
ebo added a comment to T5711: Kleopatra: Keyserver config does not fallback to default.

works

Mar 10 2023, 1:40 PM · Restricted Project, kleopatra
saper added a comment to T5623: gpg2 hangs on many tasks on OpenIndiana (Illumos).

@gniibe I have submitted D565 to change the error message on curses initialization to "Required environment variable not set"

Mar 10 2023, 12:27 PM · Solaris, gnupg (gpg23)
saper added a reviewer for D565: curses: Change error reported for terminal issues: ikloecker.
Mar 10 2023, 12:25 PM
saper requested review of D565: curses: Change error reported for terminal issues.
Mar 10 2023, 12:23 PM
ikloecker committed rLIBKLEO563a217a7594: Show indicator for compliance of selected keys (authored by ikloecker).
Show indicator for compliance of selected keys
Mar 10 2023, 12:12 PM
ikloecker committed rLIBKLEOcb700cea92ca: Show status of compliance in tooltip (authored by ikloecker).
Show status of compliance in tooltip
Mar 10 2023, 12:12 PM
ikloecker committed rLIBKLEO1a9f27b6155b: Use neutral icon for non-compliant, valid keys (authored by ikloecker).
Use neutral icon for non-compliant, valid keys
Mar 10 2023, 12:12 PM
ikloecker committed rLIBKLEO4ae176bcd27e: Set status string also for trusted keys (authored by ikloecker).
Set status string also for trusted keys
Mar 10 2023, 12:12 PM
werner committed rG56ca164684b6: dirmngr: Add command "GETINFO stats". (authored by werner).
dirmngr: Add command "GETINFO stats".
Mar 10 2023, 11:35 AM
werner closed T6404: dirmngr/sks-keyservers.netCA.pem is expired and should be removed as Resolved.

Its not used, so it can't harm.

Mar 10 2023, 11:22 AM · Bug Report
werner closed T6405: Trojan identified in virustotal as Resolved.

Also recall that Antivirus software needs to search for a competitive advantage over other vendors and in particular over Windows Defender. Thus they need to show some extra positives compared to the Windows Defender. Who care whether this is a false positive - ppl like to get some evidence that their new AV software has a (phoney) advantage.

Mar 10 2023, 11:21 AM · Bug Report
ebo added a comment to T6379: Kleopatra: Brainpool key can not be moved to smart card.

It effects Yubikeys and ZeitControl cards (version 3.4)

Mar 10 2023, 10:04 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
Carlos1957 added a comment to T6405: Trojan identified in virustotal.

Many thanks for the information. I suspected it also, but wanted your assessment.

Mar 10 2023, 10:04 AM · Bug Report
ebo added a comment to T6379: Kleopatra: Brainpool key can not be moved to smart card.

We got a user report that the issue did not occur before their update from 3.1.25 to 3.1.26

Mar 10 2023, 9:07 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
ikloecker added a comment to T6405: Trojan identified in virustotal.

Well, virus checkers aren't perfect. If 1 out of 65 checkers reports a finding, then the probability that this finding is a false positive is very high. You would better report this to the vendor of NANO-Antivirus, so that they can fix the false positive warning.

Mar 10 2023, 8:58 AM · Bug Report
Carlos1957 created T6405: Trojan identified in virustotal.
Mar 10 2023, 7:57 AM · Bug Report
bjk committed rP00765e9320e0: pinentry-curses: Handle SETREPEAT. (authored by bjk).
pinentry-curses: Handle SETREPEAT.
Mar 10 2023, 6:20 AM
bjk committed rP2923707e7553: curses: Add password quality meter. (authored by bjk).
curses: Add password quality meter.
Mar 10 2023, 6:20 AM
bjk committed rP2f109972e4a2: curses: Add SETREPEATOK and quality bar colors. (authored by bjk).
curses: Add SETREPEATOK and quality bar colors.
Mar 10 2023, 6:20 AM
bjk committed rP3a7eaa2262f9: curses: Fix line graphics with error string present. (authored by bjk).
curses: Fix line graphics with error string present.
Mar 10 2023, 6:20 AM
bjk committed rP6e66bebecb25: curses: Fix quality bar percentage logic. (authored by bjk).
curses: Fix quality bar percentage logic.
Mar 10 2023, 6:20 AM
bjk committed rGbe77a7ab8a8b: agent: Try to SETREPEATOK if the pinentry supports it. (authored by bjk).
agent: Try to SETREPEATOK if the pinentry supports it.
Mar 10 2023, 5:52 AM

Mar 9 2023

werner committed rGb52a0e244ae1: dirmngr: Distinguish between "no crl" and "crl not trusted". (authored by werner).
dirmngr: Distinguish between "no crl" and "crl not trusted".
Mar 9 2023, 6:29 PM

Mar 8 2023

erialor created T6404: dirmngr/sks-keyservers.netCA.pem is expired and should be removed.
Mar 8 2023, 6:09 PM · Bug Report
werner committed rG65288fc52f0c: keyboxd: Allow import of v0 certificates. (authored by werner).
keyboxd: Allow import of v0 certificates.
Mar 8 2023, 4:12 PM
werner committed rMc1f6535f144d: core: Also detect legacy X.509 v0 certificates. (authored by werner).
core: Also detect legacy X.509 v0 certificates.
Mar 8 2023, 3:55 PM
werner committed rGd2d1db886083: gpg,gpgsm: New option --log-time (authored by werner).
gpg,gpgsm: New option --log-time
Mar 8 2023, 3:12 PM
werner committed rG2d088176b4bd: dirmngr: Minor code cleanup in the CRL cache. (authored by werner).
dirmngr: Minor code cleanup in the CRL cache.
Mar 8 2023, 3:12 PM
werner committed rM76351c4877d6: tests: Add option --binary to run-verify (authored by werner).
tests: Add option --binary to run-verify
Mar 8 2023, 12:42 PM
werner committed rGabcf0116ee45: scd: Fix checking memory allocation. (authored by gniibe).
scd: Fix checking memory allocation.
Mar 8 2023, 11:04 AM
werner committed rG37d7ee8b9846: agent: Add translatable text for Caps Lock hint (authored by ikloecker).
agent: Add translatable text for Caps Lock hint
Mar 8 2023, 11:04 AM
werner committed rG2a13f7f9dc75: gpgsm: Strip trailing zeroes from detached signatures. (authored by werner).
gpgsm: Strip trailing zeroes from detached signatures.
Mar 8 2023, 11:02 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA7a3f33aeb1b8: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 8 2023, 4:49 AM
gniibe committed rG4e391d95e071: scd: Fix checking memory allocation. (authored by gniibe).
scd: Fix checking memory allocation.
Mar 8 2023, 3:38 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA71827cd52aa1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Mar 8 2023, 3:08 AM
gniibe moved T6376: FIPS 140-3: add explicit indicators for md and mac to unblock MD5 in apt from Backlog to Next on the FIPS board.
Mar 8 2023, 2:39 AM · libgcrypt, Feature Request, Ubuntu, Debian, FIPS
gniibe changed the status of T6376: FIPS 140-3: add explicit indicators for md and mac to unblock MD5 in apt from Open to Testing.

Thank you.
Applied to both (master and 1.10).

Mar 8 2023, 2:39 AM · libgcrypt, Feature Request, Ubuntu, Debian, FIPS
gniibe committed rCdc4a60e2d70b: fips: Unblock MD5 in fips mode but mark non-approved in indicator. (authored by tobhe).
fips: Unblock MD5 in fips mode but mark non-approved in indicator.
Mar 8 2023, 2:39 AM