Page MenuHome GnuPG
Feed Advanced Search

Nov 28 2023

werner edited projects for T6843: after enable kdf-setup impossible change user/admin pin, added: Support; removed Bug Report.
Nov 28 2023, 1:25 PM · gnupg22 (gnupg-2.2.43), scd, yubikey

Nov 27 2023

werner committed rGa6eefa99963a: gpgsm: Set validity flag in keylisting to n for untrusted root cert. (authored by werner).
gpgsm: Set validity flag in keylisting to n for untrusted root cert.
Nov 27 2023, 2:09 PM
werner committed rG73aa6dc6e41f: gpgsm: Set validity flag in keylisting to n for untrusted root cert. (authored by werner).
gpgsm: Set validity flag in keylisting to n for untrusted root cert.
Nov 27 2023, 2:09 PM
werner moved T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from QA to gnupg-2.2.42 on the gnupg22 board.
Nov 27 2023, 2:07 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner added a comment to T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust.

Tested on Windows with Kleopatra and 2.2 and with gpgme and 2.4 on Unix.

Nov 27 2023, 2:06 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner moved T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from WiP to QA on the gnupg22 board.
Nov 27 2023, 2:05 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner changed the status of T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from Open to Testing.
Nov 27 2023, 2:05 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner edited projects for T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust, added: gnupg22; removed gpgme.
Nov 27 2023, 2:04 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner added a comment to T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust.

Okay, I known do the same what we do for a single root certificate, that is mark it as "not trusted" ('n').

Nov 27 2023, 2:00 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner added a comment to T6465: Store the ECDH parameters in the key file.

We already have the ECDH parameters for OpenPGP in the gpg-agent API. The question is how large the data for PQC will be - likely we need to use an inquire already for this reason.

Nov 27 2023, 9:12 AM · gnupg26, OpenPGP, scd, Bug Report

Nov 26 2023

werner edited projects for T6838: keyboxd hangs on stale locks after changing hostname, added: gnupg24; removed gnupg24 (gnupg-2.4.4).
Nov 26 2023, 4:10 PM · gnupg24 (gnupg-2.4.4), Bug Report
werner added a comment to T6838: keyboxd hangs on stale locks after changing hostname.

That is a feature. Consider the case that ~/.gnupg is on network file system and thus possible in use on several boxes. Thus before we remove stale lock files we do not only compare the PID but also the hostname. Granted, this is rare but we have had such cases in the past with locks.

Nov 26 2023, 4:10 PM · gnupg24 (gnupg-2.4.4), Bug Report

Nov 25 2023

werner committed rD5d06d3b9392c: Fix some links (authored by werner).
Fix some links
Nov 25 2023, 7:31 PM

Nov 23 2023

werner committed rG4c456bf07508: scd:openpgp: Fallback to default ECDH params in writekey. (authored by werner).
scd:openpgp: Fallback to default ECDH params in writekey.
Nov 23 2023, 4:07 PM
werner committed rG1d472e4934b8: scd:openpgp: Print a diagnostic for the use of default ECDH params. (authored by werner).
scd:openpgp: Print a diagnostic for the use of default ECDH params.
Nov 23 2023, 4:07 PM
werner added a parent task for T6620: Add a way to extract ECC key parameters from a public key: T6465: Store the ECDH parameters in the key file.
Nov 23 2023, 12:04 PM · Restricted Project, kleopatra, Feature Request, gpgme
werner added a subtask for T6465: Store the ECDH parameters in the key file: T6620: Add a way to extract ECC key parameters from a public key.
Nov 23 2023, 12:04 PM · gnupg26, OpenPGP, scd, Bug Report
werner added a comment to T6379: Kleopatra: Brainpool key can not be moved to smart card.

See also T6465

Nov 23 2023, 12:03 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra

Nov 22 2023

werner added projects to T6832: MimeTreeParser can't find Kleopatra executable on Windows: kleopatra, Bug Report.
Nov 22 2023, 9:42 AM · vsd32 (vsd-3.2.0), Restricted Project, Bug Report, kleopatra

Nov 21 2023

werner committed rW2943b0a8103f: Update to gnupg 2.2.42-beta243 (authored by werner).
Update to gnupg 2.2.42-beta243
Nov 21 2023, 2:12 PM
werner committed rG4c700e3afe56: Update NEWS (authored by werner).
Update NEWS
Nov 21 2023, 12:37 PM
werner moved T6829: Kleopatra: Loop reading keys from smartcard from Backlog to WiP on the vsd32 board.

We always try to update the stub files because meta data of the key material might have changed due to the use on another box. On Windows the file system watch might be triggered by the remove of a key file right before writing it (cf. the usual Windows rename file problem) which is the cause for the loop. The new patches now detect whether a key file actually changed and avoid writing it back to disk.

Nov 21 2023, 12:35 PM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra
werner committed rG09329d52b5f0: agent: Update the key file only if changed (slight return). (authored by werner).
agent: Update the key file only if changed (slight return).
Nov 21 2023, 12:24 PM
werner committed rGa91f268d6cdf: agent: Update the key file only if changed (slight return). (authored by werner).
agent: Update the key file only if changed (slight return).
Nov 21 2023, 12:16 PM
werner triaged T6831: May chose a signing key from a not inserted card over an inserted one as Normal priority.
Nov 21 2023, 10:32 AM · gnupg24 (gnupg-2.4.4), OpenPGP, patch, Bug Report
werner committed rG5bab257d3a52: agent: Update the key file only if not changed. (authored by werner).
agent: Update the key file only if not changed.
Nov 21 2023, 9:06 AM
werner committed rG813bb65d952d: common: Check wether to set the modified flag in nve_set. (authored by werner).
common: Check wether to set the modified flag in nve_set.
Nov 21 2023, 9:02 AM
werner committed rGcf2d3f7ba0b7: agent: Update the key file only if not changed. (authored by werner).
agent: Update the key file only if not changed.
Nov 21 2023, 8:42 AM
werner committed rGe43bd2a7a783: scd: New option --debug-allow-pin-logging. (authored by werner).
scd: New option --debug-allow-pin-logging.
Nov 21 2023, 8:42 AM

Nov 20 2023

werner added a comment to T6829: Kleopatra: Loop reading keys from smartcard.

Confirmed with two other cards. in the gpg-agent log I also see MARKTRUSTED not supported lines while the card is inserted - this is cause by the loop in Kleo.

Nov 20 2023, 1:02 PM · vsd32 (vsd-3.2.0), Restricted Project, kleopatra

Nov 17 2023

werner lowered the priority of T4195: Fix time API in gpgme from High to Normal.
Nov 17 2023, 11:01 AM · gnupg, kleopatra, Restricted Project, gpgme, Feature Request
werner edited projects for T4195: Fix time API in gpgme, added: gnupg; removed gnupg22.

This is a generic parent task and does not require workboards for specific branches.

Nov 17 2023, 10:59 AM · gnupg, kleopatra, Restricted Project, gpgme, Feature Request
werner moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the gnupg22 board.
Nov 17 2023, 10:55 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner committed rWbe2b3abdb131: Update to gnupg 2.2 snapshot 239 (authored by werner).
Update to gnupg 2.2 snapshot 239
Nov 17 2023, 10:48 AM
werner committed rG59ec69138172: po: Update the German translation (authored by werner).
po: Update the German translation
Nov 17 2023, 10:12 AM

Nov 16 2023

werner committed rG5304c9b080b4: scd:p15: Basic support for Starcos 3.2. (authored by werner).
scd:p15: Basic support for Starcos 3.2.
Nov 16 2023, 5:29 PM
werner committed rGa33ad8f9bf92: scd: Minor debug output tweak (authored by werner).
scd: Minor debug output tweak
Nov 16 2023, 5:29 PM
werner committed rW0f891d73bd23: Update libksba to 1.6.5 and libgcrypt 1.8.11 (authored by werner).
Update libksba to 1.6.5 and libgcrypt 1.8.11
Nov 16 2023, 11:11 AM
werner closed T6822: Release Libksba 1.6.5 as Resolved.
Nov 16 2023, 11:11 AM · libksba, Release Info
werner committed rD71b59cd659b3: swdb: Libgcrypt 1.8.1 and libksba 1.6.5 (authored by werner).
swdb: Libgcrypt 1.8.1 and libksba 1.6.5
Nov 16 2023, 11:08 AM
werner committed rKaea6f0ee144a: Post release updates. (authored by werner).
Post release updates.
Nov 16 2023, 11:07 AM
werner committed rK7b3e4785e542: Release 1.6.5 (authored by werner).
Release 1.6.5
Nov 16 2023, 11:07 AM
werner triaged T6822: Release Libksba 1.6.5 as Low priority.
Nov 16 2023, 10:59 AM · libksba, Release Info
werner closed T6335: Release Libgcrypt 1.8.11 as Resolved.
Nov 16 2023, 10:55 AM · libgcrypt, Release Info
werner committed rCdeee31bb39ea: Post release updates (authored by werner).
Post release updates
Nov 16 2023, 10:48 AM
werner committed rC8598f2d6fefc: Release 1.8.11 (authored by werner).
Release 1.8.11
Nov 16 2023, 10:48 AM

Nov 15 2023

werner committed rGa5dbd985c29b: w32: Actually add the manifest to the dirmngr. (authored by werner).
w32: Actually add the manifest to the dirmngr.
Nov 15 2023, 2:35 PM
werner added a comment to T6789: MSI: Update does not seem to be able to kill gpg-agent anymore.

FWIW, the Fileversion is actually the Git revision in decimal

Nov 15 2023, 1:58 PM · vsd32 (vsd-3.2.0), Restricted Project, gpgagent, gpg4win
werner added a comment to T6820: SCD: Invalid ID when decrypting with brainpool key .

You can't decrypt using the Esign application on such a card. Please provide more information off-tracker.

Nov 15 2023, 11:05 AM · Not A Bug, gnupg
werner closed T6802: Trying to sign with a brainpool X509 key results in non-compliance error as Resolved.
Nov 15 2023, 9:28 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report
werner moved T6802: Trying to sign with a brainpool X509 key results in non-compliance error from QA to gnupg-2.4.4 on the gnupg24 board.
Nov 15 2023, 9:28 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report
werner added a comment to T6802: Trying to sign with a brainpool X509 key results in non-compliance error.

Testing in 2.4 will not be easy because it requires code modification just for testing. However, de-vs is not supported by 2.4 and the greater plan is to get 2.6 approved for de-vs.

Nov 15 2023, 9:27 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report

Nov 14 2023

werner added a comment to T6818: GPGME: Finding gpgme-w32-spawn.exe should be optional.

I'd prefer to not use the spawn helper at all. All currrent Windows versions allow to decide which handles are to be inherited and thus there is no more need for the helper.

Nov 14 2023, 7:53 PM · Windows, gpgme
werner changed the status of T6654: gpgsm: p12 passphrase visible in debug output from Open to Testing.
Nov 14 2023, 3:10 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner committed rGdef8f5f3d28b: gpg,gpgsm: Hide password in debug output also for asked passwords. (authored by werner).
gpg,gpgsm: Hide password in debug output also for asked passwords.
Nov 14 2023, 3:09 PM
werner committed rGcdc28c59fe5d: gpg,gpgsm: Hide password in debug output also for asked passwords. (authored by werner).
gpg,gpgsm: Hide password in debug output also for asked passwords.
Nov 14 2023, 3:08 PM
werner committed rDd52a8c7b7b41: swdb: Libgcrypt 1.10.3 (authored by werner).
swdb: Libgcrypt 1.10.3
Nov 14 2023, 2:56 PM
werner changed the status of T6654: gpgsm: p12 passphrase visible in debug output from Testing to Open.
Nov 14 2023, 2:38 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner moved T3269: (Constant-time) modular reduction from For 1.10 to Backlog on the libgcrypt board.

@gniibe: This is a pretty old bug; given all the changes of the last year, should we close it now?

Nov 14 2023, 1:21 PM · libgcrypt
werner closed T6747: sexp string including \0 as Resolved.
Nov 14 2023, 1:18 PM · libgcrypt, Bug Report
werner closed T6217: sha3: wrong results for large inputs as Resolved.
Nov 14 2023, 1:18 PM · libgcrypt, FIPS, Bug Report
werner closed T4873: Enable AES GCM in FIPS mode as Resolved.
Nov 14 2023, 1:17 PM · FIPS, libgcrypt, Feature Request
werner closed T4873: Enable AES GCM in FIPS mode, a subtask of T5870: libgcrypt: AEAD API for FIPS 140 (in future), as Resolved.
Nov 14 2023, 1:17 PM · Feature Request, FIPS, libgcrypt
werner moved T6747: sexp string including \0 from Backlog to For 1.10 on the libgcrypt board.
Nov 14 2023, 1:15 PM · libgcrypt, Bug Report
werner moved T6217: sha3: wrong results for large inputs from Backlog to For 1.10 on the libgcrypt board.
Nov 14 2023, 1:14 PM · libgcrypt, FIPS, Bug Report
werner closed T6817: Release Libgcrypt 1.10.3 as Resolved.
Nov 14 2023, 1:13 PM · Release Info, libgcrypt
werner closed T5905: Release Libgcrypt 1.10.2 as Resolved.
Nov 14 2023, 12:55 PM · Release Info, libgcrypt
werner created T6817: Release Libgcrypt 1.10.3.
Nov 14 2023, 12:54 PM · Release Info, libgcrypt
werner committed rKeb23f853f178: Add Brainpool curve detection using parameters with compressed BP. (authored by werner).
Add Brainpool curve detection using parameters with compressed BP.
Nov 14 2023, 10:47 AM
werner lowered the priority of T6575: gpgtar: General Error is emitted instead of more specific error codes from High to Normal.
Nov 14 2023, 10:39 AM · gpgme (gpgme 1.23.x), vsd32 (vsd-3.2.0), Restricted Project
werner renamed T6575: gpgtar: General Error is emitted instead of more specific error codes from gpgtar: General Error instead of proper error codes to gpgtar: General Error is emitted instead of more specific error codes when only signing.
Nov 14 2023, 10:38 AM · gpgme (gpgme 1.23.x), vsd32 (vsd-3.2.0), Restricted Project
werner added a comment to T6575: gpgtar: General Error is emitted instead of more specific error codes.

You are creating a signed archiv? Why - gpgtar is used for encryption.

Nov 14 2023, 10:32 AM · gpgme (gpgme 1.23.x), vsd32 (vsd-3.2.0), Restricted Project
werner committed rG697d54cecaa5: gpgsm: Re-introduce the bad passphrase hint for pkcs#12. (authored by werner).
gpgsm: Re-introduce the bad passphrase hint for pkcs#12.
Nov 14 2023, 9:48 AM
werner committed rGe6cedba11900: gpgsm: Re-introduce the bad passphrase hint for pkcs#12. (authored by werner).
gpgsm: Re-introduce the bad passphrase hint for pkcs#12.
Nov 14 2023, 9:47 AM
werner placed T6802: Trying to sign with a brainpool X509 key results in non-compliance error up for grabs.
Nov 14 2023, 9:26 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report

Nov 13 2023

werner committed rG6fab7b075adf: gpg: Implement a parser for Kyber encrypted packets. (authored by werner).
gpg: Implement a parser for Kyber encrypted packets.
Nov 13 2023, 4:28 PM
werner triaged T6796: gpg does create socketdir after every operation as Normal priority.
Nov 13 2023, 4:18 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6814: Bad performance of gpg -K when have a lot of keys with keyboxd as Resolved.

That's right: -K is merely a -k which prints only keys which have at least one secret key or a stub key (for smartcards) available.

Nov 13 2023, 4:16 PM · gnupg, Not A Bug
werner triaged T6815: PQC encryption for GnuPG as Normal priority.
Nov 13 2023, 4:06 PM · gnupg26, OpenPGP, PQC, gnupg
werner moved T6802: Trying to sign with a brainpool X509 key results in non-compliance error from WiP to QA on the gnupg22 board.
Nov 13 2023, 3:50 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report
werner moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the gnupg22 board.
Nov 13 2023, 3:49 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner moved T6736: Year 2038 issue for key validity date from QA to gnupg-2.2.42 on the gnupg22 board.
Nov 13 2023, 3:49 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report
werner moved T6736: Year 2038 issue for key validity date from WiP to QA on the gnupg22 board.
Nov 13 2023, 3:48 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report
werner edited projects for T6809: not possible to delete an account before moderator approval of account, added: dev.gnupg.org; removed Bug Report.
Nov 13 2023, 1:27 PM · dev.gnupg.org
werner closed T6809: not possible to delete an account before moderator approval of account as Resolved.

Thanks for commenting from the other account. This allowed me to disable the account. Deleting and account is hard in Phabricator thus we do it only very rarely. But disable is basically the same.

Nov 13 2023, 1:26 PM · dev.gnupg.org
werner added a comment to T6809: not possible to delete an account before moderator approval of account.

I just verified the new account. Please delete (i.e. disable) it yourself - I can't easily figure out whether it is really your account.

Nov 13 2023, 8:50 AM · dev.gnupg.org
werner renamed T6811: gpgv: Read-only trustedkeys.kbx should not be compressed from gpgv prints out a warning that it cannot allocate a lock to gpgv does not correctly fallback to trustedkeys.kbx.
Nov 13 2023, 8:43 AM · gnupg24 (gnupg-2.4.5), gpgv, Bug Report
werner triaged T6811: gpgv: Read-only trustedkeys.kbx should not be compressed as Normal priority.

Problem seems to be that there is no ~/trustedkeys.gpg file and that the fallback to the kbx file does not anymore work. I can replicate that with 2.40 and 2.4.4-beta.

Nov 13 2023, 8:43 AM · gnupg24 (gnupg-2.4.5), gpgv, Bug Report

Nov 12 2023

werner triaged T6810: gpgv: missing entry in "FILES" section in gpgv.texi as Normal priority.
Nov 12 2023, 1:21 PM · gnupg, Documentation
werner edited projects for T6811: gpgv: Read-only trustedkeys.kbx should not be compressed, added: Support; removed Bug Report.

That version of gpg is too old that I will look at it.

Nov 12 2023, 1:19 PM · gnupg24 (gnupg-2.4.5), gpgv, Bug Report

Nov 10 2023

werner moved T6805: GpgOL: RSA 2048 Key generated in VSD from Backlog to WiP on the vsd32 board.

That sounds very good.

Nov 10 2023, 2:31 PM · gpgme, vsd32 (vsd-3.2.0), gpgol, Restricted Project
werner committed rWbb6698d975ee: Update packages to a new gnupg 2.2 snapshot (authored by werner).
Update packages to a new gnupg 2.2 snapshot
Nov 10 2023, 11:19 AM
werner committed rG6d3b52a94b8d: Update NEWS. (authored by werner).
Update NEWS.
Nov 10 2023, 10:06 AM
werner triaged T6807: Kleo shows 3 certs in a chain while there are only two as Normal priority.
Nov 10 2023, 10:04 AM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra
werner committed rM1bfd5e92d023: tests: Add option --chain to run-keylist (authored by werner).
tests: Add option --chain to run-keylist
Nov 10 2023, 9:52 AM
werner reopened T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST as "Open".

I disagree. We already talked about this and we should proceed as planned.

Nov 10 2023, 9:42 AM · vsd32 (vsd-3.2.0), vsd, Restricted Project, gpgol
werner moved T6719: Support Proxy-Authorization: Negotiate on Windows from Backlog to WiP on the gnupg22 board.
Nov 10 2023, 9:11 AM · gnupg24, gnupg22, Feature Request, Restricted Project
werner moved T6545: Support CRL extension issuingDistributionPoint from WiP to Backlog on the gnupg22 board.
Nov 10 2023, 9:08 AM · workaround, gnupg26, Restricted Project, libksba, gnupg22, Feature Request
werner closed T6395: ADSK Feature as Resolved.

Further investigation showed that this was due to a bogus key creating during I wrote the code.

Nov 10 2023, 9:08 AM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), OpenPGP
werner moved T6395: ADSK Feature from WiP to gnupg-2.2.42 on the gnupg22 board.
Nov 10 2023, 9:07 AM · gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.1), OpenPGP