Page MenuHome GnuPG
Feed Advanced Search

Jan 24 2024

werner closed T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag as Resolved.

Closing because we believe things are fixed and our test suite confirms that. Feel free to -reopen in case your own file does not import with 2.4.4.

Jan 24 2024, 11:42 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner moved T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:41 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner moved T6752: New minip12 does not import from Firefox anymore from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:40 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6752: New minip12 does not import from Firefox anymore as Resolved.

The test file is now part of our test suite and passes.

Jan 24 2024, 11:40 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner moved T6559: GPGSM: "always trust like override" or "force" option from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:37 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
werner moved T6757: gpgsm 2.4 Fails to import P12 certificate/key from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key as Resolved.

We meanwhile have a lot of test cases in our test suite and we see no issue. Closing this bug; feel free to re-open if it is not fixed for your case in 2.4.4.

Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key, a subtask of T6752: New minip12 does not import from Firefox anymore, as Resolved.
Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Jan 16 2024

werner moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the gnupg24 board.
Jan 16 2024, 10:49 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner triaged T6941: gpgsm/dirmngr: support for end-entity certificates with an empty "Subject DN" as Normal priority.

Interesting. I need to look closer at it. I scheduled it for 2.4 but it won't be in the forthcoming 2.4.4. There are still other interesting things on the short list (e.g. timestamping support) but we may do that only in 2.6.

Jan 16 2024, 10:47 AM · gnupg26, S/MIME, Feature Request

Jan 5 2024

lecris added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

Hope so too. If there was a docker image or something I would gladly test it, otherwise I'll report back as soon as a release is out

Jan 5 2024, 11:46 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner moved T6757: gpgsm 2.4 Fails to import P12 certificate/key from Backlog to QA on the gnupg24 board.

We can't test this but assume that the fix for T6752 is sufficient here.

Jan 5 2024, 11:44 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Jan 4 2024

werner closed T1839: Can't Encrypt with PIV-I Encryption Certificate - Unsupported Certificate as Resolved.

Note that we now have also an option instead of the workaround from 2015

Jan 4 2024, 4:18 PM · dirmngr, gnupg, Feature Request, S/MIME

Dec 16 2023

aheinecke added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

We were hoping before christmas. But it is unlikely due to some other stuff we had to do. Early Jan. Definitely a priority for us right now to get it out.

Dec 16 2023, 3:41 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Dec 15 2023

lecris added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

@werner Any news on when will 2.4.4 will land? I cannot figure out how to build the project from source, and I couldn't adapt the Fedora packaging to build it either. I would like to have a way to finally sign my git commits.

Dec 15 2023, 2:17 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Dec 12 2023

aheinecke added a comment to T6859: S/MIME keys are not deleted.

Checking if the key is not otherwise used is unrelated and should be a diifferent Task since this also relates to OpenPGP. For me this Task is about creating a similar API for gpgsm (--delete-secret-key) that we have for OpenPGP.

Dec 12 2023, 7:12 AM · Restricted Project, S/MIME, kleopatra, gnupg

Dec 11 2023

ebo added a comment to T6859: S/MIME keys are not deleted.

As it is so complicated to check all possibilities:

Dec 11 2023, 5:12 PM · Restricted Project, S/MIME, kleopatra, gnupg
werner added a comment to T6859: S/MIME keys are not deleted.

Searching by keygrip is actually fast with keyboxd.

Dec 11 2023, 5:04 PM · Restricted Project, S/MIME, kleopatra, gnupg
aheinecke lowered the priority of T6859: S/MIME keys are not deleted from Normal to Low.

Actually prio is rather low or even Wontfix. Since it has been this way forever and no one really complained. I think deleting secret keys esp. for S/MIME where you can't just create a testing key but need to have it signed by a CA is not really there.

Dec 11 2023, 1:15 PM · Restricted Project, S/MIME, kleopatra, gnupg
aheinecke triaged T6859: S/MIME keys are not deleted as Normal priority.

I know I discussed this with werner several times and never really understood it because it makes for an inconsistent user interface / user experience. You delete an OpenPGP Secret key and then the keyfile is gone, you delete an S/MIME secret key and then the keyfile still exists. But it has been so forever T960
Maybe kleopatra should for the very rare cases where a key is used by multiple certificates do a search for the keygrip and warn if this also deletes the secret portion of another secret key? But that would then be also true for OpenPGP.

Dec 11 2023, 1:12 PM · Restricted Project, S/MIME, kleopatra, gnupg

Dec 4 2023

ikloecker moved T6807: Kleo shows 3 certs in a chain while there are only two from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Dec 4 2023, 5:07 PM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra
ikloecker changed the status of T6807: Kleo shows 3 certs in a chain while there are only two from Open to Testing.
Dec 4 2023, 5:06 PM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra
ikloecker added a comment to T6807: Kleo shows 3 certs in a chain while there are only two.

Fixed. This regression was introduced with the fix for T5697: Kleopatra: Crashes or hangs on circular certificate chains.

Dec 4 2023, 5:05 PM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra
ikloecker claimed T6807: Kleo shows 3 certs in a chain while there are only two.

Which certificate list? The list in the main view? Or the certificate list of a smart card?

Dec 4 2023, 4:21 PM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra

Nov 28 2023

werner closed T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust as Resolved.
Nov 28 2023, 5:00 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME

Nov 27 2023

aheinecke added a comment to T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust.

Thank you very much on behalf of our S/MIME users. This also makes it easier for us in the frontend to show a consistent UI.

Nov 27 2023, 4:07 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner moved T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from QA to gnupg-2.2.42 on the gnupg22 board.
Nov 27 2023, 2:07 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner added a comment to T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust.

Tested on Windows with Kleopatra and 2.2 and with gpgme and 2.4 on Unix.

Nov 27 2023, 2:06 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner moved T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from WiP to QA on the gnupg22 board.
Nov 27 2023, 2:05 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner changed the status of T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust from Open to Testing.
Nov 27 2023, 2:05 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner edited projects for T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust, added: gnupg22; removed gpgme.
Nov 27 2023, 2:04 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
werner added a comment to T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust.

Okay, I known do the same what we do for a single root certificate, that is mark it as "not trusted" ('n').

Nov 27 2023, 2:00 PM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME

Nov 25 2023

aheinecke assigned T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust to werner.

My very simple patch for this would be:

Nov 25 2023, 7:35 AM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME
aheinecke triaged T6841: GPGSM / GPGME: Untrusted root CA's cause certificates to be invalid instead of Unknown trust as Normal priority.
Nov 25 2023, 6:14 AM · gnupg22 (gnupg-2.2.42), Restricted Project, S/MIME

Nov 21 2023

ebo moved T6654: gpgsm: p12 passphrase visible in debug output from QA to gnupg-2.2.42 on the gnupg22 board.
Nov 21 2023, 4:50 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
ebo moved T6654: gpgsm: p12 passphrase visible in debug output from QA to vsd-3.2.0 on the vsd32 board.
Nov 21 2023, 4:02 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
ebo added a comment to T6654: gpgsm: p12 passphrase visible in debug output.

is now hidden in VS-Desktop-3.1.90.287-Beta

Nov 21 2023, 4:01 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 20 2023

aheinecke moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the vsd32 board.
Nov 20 2023, 10:31 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 17 2023

werner moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the gnupg22 board.
Nov 17 2023, 10:55 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 15 2023

ebo moved T6654: gpgsm: p12 passphrase visible in debug output from QA to WiP on the vsd32 board.
Nov 15 2023, 10:36 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 14 2023

werner changed the status of T6654: gpgsm: p12 passphrase visible in debug output from Open to Testing.
Nov 14 2023, 3:10 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner changed the status of T6654: gpgsm: p12 passphrase visible in debug output from Testing to Open.
Nov 14 2023, 2:38 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke updated subscribers of T6654: gpgsm: p12 passphrase visible in debug output.

Sorry @ebo tested this on Windows with 2.2. I myself should have tested it since the test is trivial and only took me about 30 seconds to type. Similar to T6701 this should have never reached the QA stage. I am including myself now that we have someone for QA that I test my own changes less. We need to talk / think about that in our whole team. We developers should test more before sending an issue into QA.

Nov 14 2023, 2:32 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 13 2023

werner moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the gnupg22 board.
Nov 13 2023, 3:49 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke moved T6654: gpgsm: p12 passphrase visible in debug output from WiP to QA on the vsd32 board.

Yes it is in the gnupg beta235 which is part of vsd-beta 277

Nov 13 2023, 11:45 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke added a comment to T6654: gpgsm: p12 passphrase visible in debug output.

Need to check if this is in the beta or not before moving it to the QA board.

Nov 13 2023, 10:15 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke moved T6654: gpgsm: p12 passphrase visible in debug output from QA to WiP on the vsd32 board.
Nov 13 2023, 10:13 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke moved T6654: gpgsm: p12 passphrase visible in debug output from Backlog to QA on the vsd32 board.
Nov 13 2023, 10:09 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke added a project to T6654: gpgsm: p12 passphrase visible in debug output: vsd32.
Nov 13 2023, 10:08 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 10 2023

werner triaged T6807: Kleo shows 3 certs in a chain while there are only two as Normal priority.
Nov 10 2023, 10:04 AM · vsd33 (vsd-3.3.0), Restricted Project, S/MIME, Bug Report, kleopatra
werner moved T6654: gpgsm: p12 passphrase visible in debug output from Backlog to WiP on the gnupg22 board.
Nov 10 2023, 9:03 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner moved T6654: gpgsm: p12 passphrase visible in debug output from Backlog to WiP on the gnupg24 board.
Nov 10 2023, 9:03 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 9 2023

ebo moved T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Nov 9 2023, 3:27 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner added projects to T6654: gpgsm: p12 passphrase visible in debug output: gnupg22, gnupg24.
Nov 9 2023, 1:27 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
aheinecke claimed T6654: gpgsm: p12 passphrase visible in debug output.

Thanks, I will test this and if it works as expected I would also put it in 2.2. since it was pointed out to me from a customer at our approval institution and I think they will be glad if they see that this is gone in the next release and I don't see any regression risk associated with that change.

Nov 9 2023, 9:30 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
gniibe changed the status of T6654: gpgsm: p12 passphrase visible in debug output from Open to Testing.

Pushed the change to master/2.4.

Nov 9 2023, 5:41 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Nov 8 2023

werner triaged T6804: Change the default AKI and SKI to use the keygrip as Normal priority.
Nov 8 2023, 2:20 PM · Bug Report, S/MIME, gnupg24
gniibe added a comment to T6654: gpgsm: p12 passphrase visible in debug output.

I guess that it's a case of specifying static passphrase. If so, here is the patch:

diff --git a/g10/call-agent.c b/g10/call-agent.c
index cb7053396..c44c1cddb 100644
--- a/g10/call-agent.c
+++ b/g10/call-agent.c
@@ -161,6 +161,7 @@ default_inq_cb (void *opaque, const char *line)
             || has_leading_keyword (line, "NEW_PASSPHRASE"))
            && opt.pinentry_mode == PINENTRY_MODE_LOOPBACK)
     {
+      assuan_begin_confidential (parm->ctx);
       if (have_static_passphrase ())
         {
           s = get_static_passphrase ();
@@ -187,6 +188,7 @@ default_inq_cb (void *opaque, const char *line)
             err = assuan_send_data (parm->ctx, pw, strlen (pw));
           xfree (pw);
         }
+      assuan_end_confidential (parm->ctx);
     }
   else if ((s = has_leading_keyword (line, "CONFIRM"))
            && opt.pinentry_mode == PINENTRY_MODE_LOOPBACK
diff --git a/sm/call-agent.c b/sm/call-agent.c
index 883c0c644..7f7205f26 100644
--- a/sm/call-agent.c
+++ b/sm/call-agent.c
@@ -222,7 +222,9 @@ default_inq_cb (void *opaque, const char *line)
            && have_static_passphrase ())
     {
       const char *s = get_static_passphrase ();
+      assuan_begin_confidential (parm->ctx);
       err = assuan_send_data (parm->ctx, s, strlen (s));
+      assuan_end_confidential (parm->ctx);
     }
   else
     log_error ("ignoring gpg-agent inquiry '%s'\n", line);

(I also found similar case for gpg as well as gpgsm.)

Nov 8 2023, 6:04 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project

Oct 30 2023

ebo reopened T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag as "Testing".
Oct 30 2023, 3:36 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
ebo closed T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag as Resolved.

works, the secret part is now imported, too, tested with VS-Desktop-3.1.90.258-Beta

Oct 30 2023, 3:36 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
ebo moved T6253: GpgSM: Backport ECC support to 2.2 from QA to gnupg-2.2.42 on the gnupg22 board.
Oct 30 2023, 3:25 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
ebo closed T6253: GpgSM: Backport ECC support to 2.2, a subtask of T4098: GpgSM: Add ECC support, as Resolved.
Oct 30 2023, 3:24 PM · gnupg (gpg23), Feature Request, S/MIME
ebo closed T6253: GpgSM: Backport ECC support to 2.2 as Resolved.

works: my brainpool X509 testcertificate is shown as compliant

Oct 30 2023, 3:24 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME

Oct 25 2023

lecris added a comment to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag.

Would love to test this, but I can't seem to compile this project, getting stuck at The system does not provide a working iconv function. Is there a Fedora based dockerfile or equivalent where I could build it? Here is the reference Fedora source. I have tried to hack it and build from a gitarchive, but I am still encountering issues No rule to make target 'audit-events.h', needed by 'all'. Stop.

Oct 25 2023, 3:44 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner moved T6559: GPGSM: "always trust like override" or "force" option from QA for next release to gpgme 1.23.x on the gpgme board.
Oct 25 2023, 10:40 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project

Oct 24 2023

werner removed projects from T6770: Add --ignore-cert-extensions to dirmngr: gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42).

According to our rules an initial set of tags should never be a milestone but be in the Backlog or, if work already started,in the WiP column. Because it is anyway invalid, I removed the tags.

Oct 24 2023, 3:36 PM · S/MIME, Restricted Project
werner placed T6253: GpgSM: Backport ECC support to 2.2 up for grabs.
Oct 24 2023, 2:55 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner added a comment to T6253: GpgSM: Backport ECC support to 2.2.

T6536 has been fixed. With today's commits the Brainpool curves are now also flagged as compliant in gpgsm.

Oct 24 2023, 2:55 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner changed the status of T6752: New minip12 does not import from Firefox anymore from Open to Testing.
Oct 24 2023, 2:17 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner added a comment to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag.

Now fixed in 2.2 and 2.4 (commits rG08f0b9ea2e955209d467f1ff624bf7abd10ae7ac and rG7661d2fbc6eb533016df63a86ec3e35bf00cfb1f). See also T6752

Oct 24 2023, 2:16 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project

Oct 20 2023

aheinecke added a comment to T6770: Add --ignore-cert-extensions to dirmngr.

That output was also misleading,. that was from before I added the ignore-crl-extension in there. I was confused because I still got the error:

Oct 20 2023, 4:23 PM · S/MIME, Restricted Project
aheinecke closed T6770: Add --ignore-cert-extensions to dirmngr as Invalid.

So dirmngr already has that option.

Oct 20 2023, 4:08 PM · S/MIME, Restricted Project
aheinecke triaged T6770: Add --ignore-cert-extensions to dirmngr as High priority.
Oct 20 2023, 2:57 PM · S/MIME, Restricted Project

Oct 17 2023

ebo added a comment to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag.

With VS-Desktop-3.1.90.246-Beta I can not import the secret part of the edward.tester@demo.gnupg.com.p12 Testkey (ECC brainpool).
I do not see any error message.

Oct 17 2023, 3:51 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project

Oct 16 2023

lecris added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

Thanks, what should I look out for? I don't think I can provide the .p12 directly because it is from a production provider that I do not have full access. I can provide the log and x509 public certificate again using the firefox generated one.

Oct 16 2023, 2:19 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner added a parent task for T6757: gpgsm 2.4 Fails to import P12 certificate/key: T6752: New minip12 does not import from Firefox anymore.
Oct 16 2023, 1:23 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner added a subtask for T6752: New minip12 does not import from Firefox anymore: T6757: gpgsm 2.4 Fails to import P12 certificate/key.
Oct 16 2023, 1:23 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner triaged T6757: gpgsm 2.4 Fails to import P12 certificate/key as Normal priority.

Recent Mozilla again changed some things. Please see T6752. Can you please provide a sample in case this is not the same problem as in T6752?

Oct 16 2023, 1:22 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Oct 10 2023

lecris updated the task description for T6757: gpgsm 2.4 Fails to import P12 certificate/key.
Oct 10 2023, 5:47 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
lecris added a project to T6757: gpgsm 2.4 Fails to import P12 certificate/key: S/MIME.
Oct 10 2023, 5:46 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
wenzehan added a comment to T6752: New minip12 does not import from Firefox anymore.

115.3.1esr

Oct 10 2023, 1:22 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner added a comment to T6752: New minip12 does not import from Firefox anymore.

Yes, there is clearly a problem with the handling of NDEF. I have a fix for that but there are other oddities in that pkcs12 object. Do you have the Firefox version you used to create this?

Oct 10 2023, 11:13 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner claimed T6752: New minip12 does not import from Firefox anymore.
Oct 10 2023, 10:06 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner triaged T6752: New minip12 does not import from Firefox anymore as Normal priority.
Oct 10 2023, 9:37 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report

Oct 5 2023

werner moved T6253: GpgSM: Backport ECC support to 2.2 from WiP to QA on the gnupg22 board.

That has been done modulo the bug which existed for both versions, I fixed today (T6536)

Oct 5 2023, 11:30 AM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner moved T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 5 2023, 10:42 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner edited projects for T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag, added: gnupg24; removed gnupg24 (gnupg-2.4.3).
Oct 5 2023, 10:39 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner added a comment to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag.

Okay, I found and fixed the import problem in 2.4 and will backport this to 2.2

Oct 5 2023, 10:26 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project

Sep 28 2023

ebo moved T6253: GpgSM: Backport ECC support to 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Sep 28 2023, 1:20 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
aheinecke triaged T6740: scd: Add / improve support for DINSIG cards as Wishlist priority.
Sep 28 2023, 9:55 AM · S/MIME, scd

Sep 18 2023

ebo moved T6559: GPGSM: "always trust like override" or "force" option from QA to gnupg-2.2.42 on the gnupg22 board.
Sep 18 2023, 4:15 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
ebo moved T6559: GPGSM: "always trust like override" or "force" option from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Sep 18 2023, 3:42 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
ebo closed T6559: GPGSM: "always trust like override" or "force" option as Resolved.
Sep 18 2023, 3:39 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
ebo added a comment to T6559: GPGSM: "always trust like override" or "force" option.

Tested on the command line with

  • a previously valid certificate after setting its root certificate to untrusted
  • a expired certificate without the root certificate in the certificate list
Sep 18 2023, 3:31 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
ebo added a comment to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag.

With Gpg4win-4.2.1-beta31 I can no longer import the secret part of the edward.tester@demo.gnupg.com.p12 Testkey. Error is "Invalid object".

Sep 18 2023, 3:11 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
ebo moved T4779: GpgSM: "Invalid Object" error when importing .p12 certs with wrong passphrase from QA to gnupg-2.4.3 on the gnupg24 board.
Sep 18 2023, 2:42 PM · gnupg24 (gnupg-2.4.3), Restricted Project, gnupg (gpg23), S/MIME
ebo moved T4779: GpgSM: "Invalid Object" error when importing .p12 certs with wrong passphrase from Backlog to QA on the gnupg24 board.
Sep 18 2023, 2:42 PM · gnupg24 (gnupg-2.4.3), Restricted Project, gnupg (gpg23), S/MIME
ebo closed T4779: GpgSM: "Invalid Object" error when importing .p12 certs with wrong passphrase as Resolved.

With VS-Desktop-3.2.0.0-beta214 and Gpg4win-4.2.1-beta31 the error is "Bad Passphrase" in this case.
I do not see a reason why this ticket is still open.
The already resolved Kleopatra Task T5713 is probably a duplicate of this one.

Sep 18 2023, 2:23 PM · gnupg24 (gnupg-2.4.3), Restricted Project, gnupg (gpg23), S/MIME

Sep 14 2023

ebo moved T6253: GpgSM: Backport ECC support to 2.2 from QA to WiP on the gnupg22 board.

pkcs12 import should be backported, too

Sep 14 2023, 3:08 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME

Sep 8 2023

werner moved T6559: GPGSM: "always trust like override" or "force" option from Backlog to QA for next release on the gpgme board.
Sep 8 2023, 3:45 PM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project