Page MenuHome GnuPG
Feed Advanced Search

Jan 25 2024

werner committed rWe9862ca9f367: Prepare NEWS for 4.3.0 (authored by werner).
Prepare NEWS for 4.3.0
Jan 25 2024, 2:00 PM
werner committed rD549d8cf9e2e6: blog: Add smartcard-backup-key (authored by werner).
blog: Add smartcard-backup-key
Jan 25 2024, 12:55 PM
werner committed rDd04361e36569: swdb: gnupg 2.4.5 (authored by werner).
swdb: gnupg 2.4.5
Jan 25 2024, 12:40 PM
werner committed rW9a27c5022bd8: Update GnuPG to version 2.4.4 (authored by werner).
Update GnuPG to version 2.4.4
Jan 25 2024, 11:59 AM
werner closed T6943: Add tool to detect and clean unsolicited copies of smartcard keys as Resolved.
Jan 25 2024, 11:57 AM · gnupg24 (gnupg-2.4.4), Feature Request
werner moved T6943: Add tool to detect and clean unsolicited copies of smartcard keys from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 25 2024, 11:57 AM · gnupg24 (gnupg-2.4.4), Feature Request
werner shifted T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from the Restricted Space space to the S1 Public space.
Jan 25 2024, 11:56 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner shifted T6943: Add tool to detect and clean unsolicited copies of smartcard keys from the Restricted Space space to the S1 Public space.
Jan 25 2024, 11:56 AM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6578: Release GnuPG 2.4.4 as Resolved.
Jan 25 2024, 11:38 AM · gnupg24 (gnupg-2.4.4), Release Info
werner moved T6578: Release GnuPG 2.4.4 from WiP to gnupg-2.4.4 on the gnupg24 board.
Jan 25 2024, 11:38 AM · gnupg24 (gnupg-2.4.4), Release Info
werner edited projects for T6578: Release GnuPG 2.4.4, added: gnupg24; removed gnupg.
Jan 25 2024, 11:37 AM · gnupg24 (gnupg-2.4.4), Release Info
werner updated the task description for T6578: Release GnuPG 2.4.4.
Jan 25 2024, 11:37 AM · gnupg24 (gnupg-2.4.4), Release Info
werner committed rG367ae8601906: Post release updates (authored by werner).
Post release updates
Jan 25 2024, 11:30 AM
werner committed rGc5429644e98b: po: msgmerge (authored by werner).
po: msgmerge
Jan 25 2024, 11:30 AM
werner committed rGa43271cc08e2: Release 2.4.4 (authored by werner).
Release 2.4.4
Jan 25 2024, 11:30 AM
werner committed rG2a4180812ac2: card: Tweak the checkcmds sub-command. (authored by werner).
card: Tweak the checkcmds sub-command.
Jan 25 2024, 11:30 AM
werner triaged T6960: Release GnuPG 2.4.5 as Low priority.
Jan 25 2024, 11:29 AM · gnupg24 (gnupg-2.4.5), Release Info

Jan 24 2024

werner awarded T6957: Add algo and keygrip columns to Kleo's certificate view a Like token.
Jan 24 2024, 6:44 PM · vsd33 (vsd-3.3.0), Restricted Project, vsd, kleopatra
werner committed rGd4976e35d2ca: gpg: Add sub-option ignore-attributes to --import-options. (authored by werner).
gpg: Add sub-option ignore-attributes to --import-options.
Jan 24 2024, 6:26 PM
werner moved T6379: Kleopatra: Brainpool key can not be moved to smart card from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 4:26 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner closed T6379: Kleopatra: Brainpool key can not be moved to smart card as Resolved.
Jan 24 2024, 4:26 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner raised the priority of T6620: Add a way to extract ECC key parameters from a public key from Normal to High.

Just a reminder, this is important for 384 bit keys (see T6379).

Jan 24 2024, 4:26 PM · Restricted Project, kleopatra, Feature Request, gpgme
werner moved T6379: Kleopatra: Brainpool key can not be moved to smart card from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 24 2024, 4:24 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner added a comment to T6379: Kleopatra: Brainpool key can not be moved to smart card.

The state of the brain is:

Jan 24 2024, 4:23 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner committed rGccd201d7db02: doc: Minor typo fix. (authored by werner).
doc: Minor typo fix.
Jan 24 2024, 3:09 PM
werner triaged T6956: GnuPG: Allow import of gpgsk files as Normal priority.

These gpgsk files are standard private-keys-v1 files with an additional Backup-info line showing for example the keygrip.
There are no certificates in the file, thus we can either use gpg or gpgsm as driver.

Jan 24 2024, 3:00 PM · gnupg26, Feature Request, Restricted Project
werner triaged T6957: Add algo and keygrip columns to Kleo's certificate view as Normal priority.
Jan 24 2024, 2:53 PM · vsd33 (vsd-3.3.0), Restricted Project, vsd, kleopatra
werner closed T4676: libgcrypt S2K (algo 3) doesn't match OpenPGP as Resolved.
Jan 24 2024, 2:50 PM · Documentation, OpenPGP
werner moved T6052: gnupg2 tpm2d tests do not work from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:46 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner closed T6052: gnupg2 tpm2d tests do not work as Resolved.

No test environment in our QA dept.

Jan 24 2024, 2:46 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner moved T6831: May chose a signing key from a not inserted card over an inserted one from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:45 PM · gnupg24 (gnupg-2.4.4), OpenPGP, patch, Bug Report
werner closed T6831: May chose a signing key from a not inserted card over an inserted one as Resolved.

Fixed in 2.4.4. Feel free to re-open if you still see problems.

Jan 24 2024, 2:45 PM · gnupg24 (gnupg-2.4.4), OpenPGP, patch, Bug Report
werner moved T6741: gpg 2.3+ may display garbled characters for date and time in non-English Windows from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:42 PM · gnupg24 (gnupg-2.4.4), i18n, Windows, Bug Report
werner closed T6741: gpg 2.3+ may display garbled characters for date and time in non-English Windows, a subtask of T4365: Encoding problem: gpg truncates multibyte characters in interactive prompts on Windows, as Resolved.
Jan 24 2024, 2:42 PM · Windows, gnupg (gpg23), Bug Report
werner closed T6741: gpg 2.3+ may display garbled characters for date and time in non-English Windows as Resolved.

No regression, assuming things work.

Jan 24 2024, 2:42 PM · gnupg24 (gnupg-2.4.4), i18n, Windows, Bug Report
werner moved T3380: Use exponential backoff when spawning agent and dirmngr from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:40 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T3380: Use exponential backoff when spawning agent and dirmngr as Resolved.

Hard to test without instrumenting the code.

Jan 24 2024, 2:40 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner moved T6796: gpg does create socketdir after every operation from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:37 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6796: gpg does create socketdir after every operation as Resolved.

Tested during development.

Jan 24 2024, 2:37 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner moved T6902: gpgconf: the questionable value 256 for flags in gpgrt_opt_t from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:36 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4)
werner added a comment to T6902: gpgconf: the questionable value 256 for flags in gpgrt_opt_t.

Tested for 2.4

Jan 24 2024, 2:35 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4)
werner moved T6710: Improve Speedo for Linux to set DT_RUNPATH. from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:34 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6710: Improve Speedo for Linux to set DT_RUNPATH. as Resolved.

@alexk and me tested this. The core functionality works.

Jan 24 2024, 2:34 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6944: The default card key generation keeps an unprotected backup of the encryption key on disk as Resolved.
Jan 24 2024, 2:31 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner closed T6944: The default card key generation keeps an unprotected backup of the encryption key on disk, a subtask of T6943: Add tool to detect and clean unsolicited copies of smartcard keys, as Resolved.
Jan 24 2024, 2:31 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner moved T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from WiP to gnupg-2.2.43 on the gnupg22 board.
Jan 24 2024, 2:31 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner moved T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:31 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner added a comment to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.

Fixed in 2.4.4 and 2.2.43 - see above for affected versions.

Jan 24 2024, 2:31 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner closed T6919: Add support for smartcafe cards as Resolved.
Jan 24 2024, 2:25 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner moved T6919: Add support for smartcafe cards from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:25 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner moved T6919: Add support for smartcafe cards from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 24 2024, 2:25 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner added a project to T6919: Add support for smartcafe cards: Restricted Project.

Works for the two sample RSA cards. Ticket may eventually be re-opened if we run into problems with ECC cards.

Jan 24 2024, 2:24 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner added a comment to T6708: Allow to inhibit the use of a default PGP keyserver.

Fixes are already in GnuPG 2.4.4 and can't be easily tested. Thus closing also for gnupg24

Jan 24 2024, 2:22 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, vsd, Feature Request
werner moved T6708: Allow to inhibit the use of a default PGP keyserver from WiP to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 2:20 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, vsd, Feature Request
werner committed rGa227a0d54da6: po: Update German translation. (authored by werner).
po: Update German translation.
Jan 24 2024, 2:06 PM
werner committed rG154ecf17bddc: speedo: Build zlib, bzip2 and sqlite also on Unix. (authored by werner).
speedo: Build zlib, bzip2 and sqlite also on Unix.
Jan 24 2024, 2:06 PM
werner committed rG3b69d8bf7146: gpg: Fix leftover unprotected card backup key. (authored by werner).
gpg: Fix leftover unprotected card backup key.
Jan 24 2024, 11:45 AM
werner closed T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag as Resolved.

Closing because we believe things are fixed and our test suite confirms that. Feel free to -reopen in case your own file does not import with 2.4.4.

Jan 24 2024, 11:42 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner moved T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:41 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner moved T6752: New minip12 does not import from Firefox anymore from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:40 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6752: New minip12 does not import from Firefox anymore as Resolved.

The test file is now part of our test suite and passes.

Jan 24 2024, 11:40 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner moved T6940: gpgsm: .p12 AES-256-CBC support from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:38 AM · gnupg24 (gnupg-2.4.4), Feature Request
werner moved T6559: GPGSM: "always trust like override" or "force" option from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:37 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
werner moved T6757: gpgsm 2.4 Fails to import P12 certificate/key from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key as Resolved.

We meanwhile have a lot of test cases in our test suite and we see no issue. Closing this bug; feel free to re-open if it is not fixed for your case in 2.4.4.

Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key, a subtask of T6752: New minip12 does not import from Firefox anymore, as Resolved.
Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6942: Differing fingerprint length with curve 448 as Resolved.

I did a couple of test on the command line which should be sufficient.

Jan 24 2024, 11:34 AM · gnupg24 (gnupg-2.4.4), Bug Report
werner moved T6942: Differing fingerprint length with curve 448 from QA to gnupg-2.4.4 on the gnupg24 board.
Jan 24 2024, 11:33 AM · gnupg24 (gnupg-2.4.4), Bug Report
werner moved T6942: Differing fingerprint length with curve 448 from WiP to QA on the gnupg24 board.
Jan 24 2024, 11:33 AM · gnupg24 (gnupg-2.4.4), Bug Report
werner claimed T6849: Release GnuPG 2.2.43.
Jan 24 2024, 11:29 AM · gnupg22 (gnupg-2.2.43), Release Info
werner moved T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from Backlog to WiP on the gnupg22 board.
Jan 24 2024, 11:23 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner added a project to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk: gnupg22.

We need to fix 2.2.42 too. This because we backported the responsible patch.

Jan 24 2024, 11:22 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner committed rGbea31c845aad: card: flush stdout to get checkcmd's info messages in order. (authored by werner).
card: flush stdout to get checkcmd's info messages in order.
Jan 24 2024, 10:39 AM
werner requested changes to D584: WIP: Add cmake build system for cpp bindings.

Having a second build system for GPGME is not a good idea. This gives us a headache for maintaining. If you really need this for private things, put this into a contrib directory and make clear that this is a non supported way to build things. And for the Qt bindings I am anyway in favor of removing them from GPGME proper.

Jan 24 2024, 8:05 AM

Jan 23 2024

werner committed rG34d19d448dd3: tests: Add two more sample p12 files (authored by werner).
tests: Add two more sample p12 files
Jan 23 2024, 2:19 PM
werner committed rGfd6c38605a0b: speedo: Add a hint to run ldconfig (authored by werner).
speedo: Add a hint to run ldconfig
Jan 23 2024, 2:19 PM
werner closed T6940: gpgsm: .p12 AES-256-CBC support as Resolved.

It is already implemented and will soon show up in 2.4.4 -)

Jan 23 2024, 1:38 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner triaged T6955: Auto-switch to 32 bit registry view in GpgRT as Normal priority.
Jan 23 2024, 1:18 PM · Feature Request, Windows 64, gpgrt
werner committed rW7e51af9073c6: Add another gnupg snapshopt and bump version to 4.3.0 (authored by werner).
Add another gnupg snapshopt and bump version to 4.3.0
Jan 23 2024, 9:46 AM
werner committed rGb7c15948610b: speedo: Minor fix to the install target (authored by werner).
speedo: Minor fix to the install target
Jan 23 2024, 9:03 AM

Jan 22 2024

werner changed the status of T6944: The default card key generation keeps an unprotected backup of the encryption key on disk, a subtask of T6943: Add tool to detect and clean unsolicited copies of smartcard keys, from Open to Testing.
Jan 22 2024, 4:53 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner changed the status of T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from Open to Testing.
Jan 22 2024, 4:53 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner changed the status of T6943: Add tool to detect and clean unsolicited copies of smartcard keys from Open to Testing.
Jan 22 2024, 4:52 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner committed rGead2982286f8: gpg: Use ephemeral mode for generating card keys. (authored by werner).
gpg: Use ephemeral mode for generating card keys.
Jan 22 2024, 4:52 PM
werner committed rG434a641d40cb: agent: Add "ephemeral" Assuan option. (authored by werner).
agent: Add "ephemeral" Assuan option.
Jan 22 2024, 4:52 PM
werner assigned T6948: unnamed semaphores leak on AIX to gniibe.
Jan 22 2024, 12:07 PM · Bug Report, AIX, npth
werner triaged T6954: Add wipememory function to gpgrt as Normal priority.
Jan 22 2024, 11:04 AM · gnupg26, gpgrt, Feature Request
werner committed rG18320d692cfd: doc: Fix description of gpg --unwrap (authored by werner).
doc: Fix description of gpg --unwrap
Jan 22 2024, 10:33 AM
werner committed rGee56f71c8a68: gpg: Add a communication object to the key generation code. (authored by werner).
gpg: Add a communication object to the key generation code.
Jan 22 2024, 10:33 AM
werner committed rGadeb17e37588: card: New subcommand "checkkeys". (authored by werner).
card: New subcommand "checkkeys".
Jan 22 2024, 10:33 AM
werner committed rGc8060a8f23a7: doc: Document Backup-info in keyformat.txt (authored by werner).
doc: Document Backup-info in keyformat.txt
Jan 22 2024, 10:33 AM

Jan 20 2024

werner closed T6949: Kleopatra & GnuPG - higher key sizes made available as Wontfix.

Sorry, we won't do that. Please search on the Net for reasons why this is not a good idea. In any case you better move to Ed25519 or - if you really feel like this - to X448. The GnuPG FAQ als gives a rationale why larger keys are not useful.

Jan 20 2024, 8:43 PM · Feature Request
werner added projects to T6948: unnamed semaphores leak on AIX: npth, AIX, Bug Report.
Jan 20 2024, 8:41 PM · Bug Report, AIX, npth

Jan 19 2024

werner set External Link to https://forum.gnupg.org/t/privater-schlussel-von-smart-card-in-kleopatra-gespeichert/3858 on T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.
Jan 19 2024, 12:38 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner triaged T6946: gpgv: Help automatic reject too short keys as Normal priority.

I noticed the Debian bug and was about to answer but a feature request is also a good thing.

Jan 19 2024, 12:27 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv
werner added a comment to T6708: Allow to inhibit the use of a default PGP keyserver.

I would also suggest that we show the git last git commit in Kleo's About dialog. That makes it far easier to see what we are testing. The Kleo version numbers are a bit arbitrary.

Jan 19 2024, 9:03 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, vsd, Feature Request
werner added a comment to T6708: Allow to inhibit the use of a default PGP keyserver.

Sorry, it was my fault building the test installer.

Jan 19 2024, 9:01 AM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, vsd, Feature Request

Jan 18 2024

werner added a comment to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.

We tested with Kleopatra:

  • Only gpg4win 4.2 is affected (the current version) but 4.1 is not affected.
  • No vsd version is affected.
Jan 18 2024, 8:35 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner added a comment to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.

FWIW, I am already working on this.

Jan 18 2024, 8:31 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report

Jan 17 2024

werner added a comment to T6637: PQC for Libgcrypt.

Regading Kyber in GnuPG, there are a couple of open questions. For example whether the implicit lengths used for the key parameters match well with the overall protocol structure. Thus, as soon as we have finished the Libgcrypt part we will address this and implement it in some way. Before we do this we have to do a couple of changes to GnuPG required for FIPS compliance.

Jan 17 2024, 4:17 PM · PQC, libgcrypt