Page MenuHome GnuPG
Feed All Stories

Feb 7 2024

werner removed a project from T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature: C++.

Oh well, it does not use the c++ binding .

Feb 7 2024, 9:25 AM · gpgme, Bug Report
werner triaged T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature as Normal priority.
Feb 7 2024, 9:22 AM · gpgme, Bug Report
werner triaged T6962: gpg lock issue on Alma Linux upgraded servers as Normal priority.
Feb 7 2024, 9:21 AM · Support, gnupg
werner triaged T6975: The option --default-key gives up too early if there are multiple matches as Normal priority.
Feb 7 2024, 9:21 AM · Feature Request, gnupg
werner triaged T6976: RSA PKCS#1v1.5 signatures with SHA3 use invalid encoding as Normal priority.
Feb 7 2024, 9:20 AM · FIPS, libgcrypt, Bug Report
aheinecke triaged T6966: Kleopatra: Show which certificates in a group are not usable for encryption as Low priority.

I don't think that we need to show which keys are compliant or not because that is already shown by the VS-NfD compliance status. And then we only have left the case where the keys are expired / revoked so a user could sort by validity to find out which ones are those.

Feb 7 2024, 9:20 AM · vsd33 (vsd-3.3.0), Restricted Project, kleopatra
werner added projects to T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature: gpgme, C++.
Feb 7 2024, 9:20 AM · gpgme, Bug Report
werner added projects to T6976: RSA PKCS#1v1.5 signatures with SHA3 use invalid encoding: libgcrypt, FIPS.
Feb 7 2024, 9:17 AM · FIPS, libgcrypt, Bug Report
aheinecke triaged T6971: Kleopatra: "General Error" is given instead of "Wrong PIN" as Normal priority.

Yes that probably gets lost along the way, where we communicate with scdaemon to generate the key. Needs to be tracked down. Such things can be very confusing to users. Especially if that increases the PIN Retry counter!

Feb 7 2024, 9:14 AM · gpgme, kleopatra, Restricted Project
aheinecke triaged T6970: Kleopatra: Hide non-matching keygroups when using a key filter as Normal priority.

Yes I think that some keys must match, e.g. if you filter for S/MIME you only want to see groups where at least one S/MIME certificate is part of the group. Or for expired to see if there are groups with expired certificates in them.

Feb 7 2024, 9:11 AM · vsd33, Restricted Project, kleopatra
werner added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

Feb 7 2024, 9:09 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO2f107ea10319: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 4:48 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA3e6b27ae6a1c: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 4:47 AM
l10n daemon script <scripty@kde.org> committed rMTP85a7eb4ec2f3: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:54 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO31573c8c853b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:54 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAd54d8fcbcd69: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:54 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA28b4d428fa71: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Feb 7 2024, 3:51 AM
Angel added a comment to T6975: The option --default-key gives up too early if there are multiple matches.

Ingo, I concede it might be considered a bug on Request Tracker that it does not allow to specify the key as a fingerprint (or calculates it automatically from the email instead of relying on gpg doing it), but you generally want to keep expired keys around for decryption.

Feb 7 2024, 3:29 AM · Feature Request, gnupg
l10n daemon script <scripty@kde.org> committed rMTPdeca30dec120: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:13 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6908b0c08ec7: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:13 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO586aaac37070: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 3:13 AM
l10n daemon script <scripty@kde.org> committed rMTP68443a711849: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 2:19 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOdfcc9c9f85db: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 2:17 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA768e3a7e7172: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 7 2024, 2:17 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA8047042e3f47: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Feb 7 2024, 2:12 AM

Feb 6 2024

lecris added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

Could you write a quick patch file for that? (I don't have a working source build, I am using the Fedora spec file + patches)

Feb 6 2024, 5:18 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

The old debug output is in genral okay but what I would do is to add a couple of log_debug calls like

Feb 6 2024, 5:16 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner committed rE49507cf6977f: core: Add "wipe" mode flag. (authored by werner).
core: Add "wipe" mode flag.
Feb 6 2024, 5:07 PM
werner committed rE1fdd8749014c: core: New function gpgrt_wipememory. (authored by werner).
core: New function gpgrt_wipememory.
Feb 6 2024, 5:07 PM
werner closed T6978: Add a command mode to the option parser as Resolved.
Feb 6 2024, 4:04 PM · Feature Request, gpgrt
TobiasFella committed rLIBKLEO3c2c3232cd7c: Use qstrcmp (authored by TobiasFella).
Use qstrcmp
Feb 6 2024, 3:19 PM
werner committed rEb113114c7498: argparser: Implement a command mode. (authored by werner).
argparser: Implement a command mode.
Feb 6 2024, 3:13 PM
TobiasFella committed rLIBKLEO0f343da65c85: Simplify smime filtering (authored by TobiasFella).
Simplify smime filtering
Feb 6 2024, 2:43 PM
werner triaged T6978: Add a command mode to the option parser as Normal priority.
Feb 6 2024, 2:41 PM · Feature Request, gpgrt
TobiasFella committed rLIBKLEOb240c4fa4199: Simplify smime filtering (authored by TobiasFella).
Simplify smime filtering
Feb 6 2024, 2:40 PM
TobiasFella committed rKLEOPATRAdbb39443d682: Adapt SignEncryptWidget to be based on UserIDs instead of Keys (authored by TobiasFella).
Adapt SignEncryptWidget to be based on UserIDs instead of Keys
Feb 6 2024, 1:52 PM
TobiasFella committed rLIBKLEO50bb390b470a: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 6 2024, 1:40 PM
ikloecker added a comment to T6725: Kleopatra: encryption via menu button does only encrypt files, not folders.

And not using the native Windows dialog isn't an option because people are used to the Windows dialog. I absolutely hate it when some application on Linux doesn't use the KDE dialog but its own dialog because it behaves slightly differently and it doesn't have my bookmarked folders.

Feb 6 2024, 1:27 PM · kleopatra, Restricted Project
ikloecker added a comment to T6725: Kleopatra: encryption via menu button does only encrypt files, not folders.

We cannot

Switch to gpgtar if folders are involved. In that case "Sign/Encrypt Folder" would no longer be needed.

because we don't know that folders are involved. And I don't think we can hide the folders, so that users cannot select folders and wonder why they are not encrypted, because Microsoft thought it would be a great idea to basically use the Windows Explorer as File Open/Select/Save dialog. And, of course, they won't change this because this would break all existing Windows applications if suddenly folders are returned.

Feb 6 2024, 1:24 PM · kleopatra, Restricted Project
ikloecker added a comment to T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature.

Does the run-verify example (in gpgme/tests) hang when verifying a corrupted file?

Feb 6 2024, 1:12 PM · gpgme, Bug Report
lecris added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

@werner I managed to recover the old .p12 that has the error. And this is still replicable. Is there a debug flag that would be useful or can we setup some private live-debugging for this?

Feb 6 2024, 12:18 PM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
ebo added a comment to T6725: Kleopatra: encryption via menu button does only encrypt files, not folders.

I would like to change the description of this ticket.
Which way do we want to go?

Feb 6 2024, 11:48 AM · kleopatra, Restricted Project
TobiasFella committed rLIBKLEO4a26284ed8bf: Don't mess with openpgp user ids (authored by TobiasFella).
Don't mess with openpgp user ids
Feb 6 2024, 11:34 AM
TobiasFella committed rLIBKLEO088b9c831160: Don't mess with openpgp user ids (authored by TobiasFella).
Don't mess with openpgp user ids
Feb 6 2024, 11:21 AM
ebo closed T3660: I cannot encrypt any folder on w10 as Resolved.

Closing this outdated ticket

Feb 6 2024, 11:16 AM · Bug Report, gpg4win
TobiasFella committed rLIBKLEO2c87066fad01: Remove filtering and name/email hacks (authored by TobiasFella).
Remove filtering and name/email hacks
Feb 6 2024, 10:50 AM
ebo renamed T6970: Kleopatra: Hide non-matching keygroups when using a key filter from Hide non-matching keygroups when using a key filter to Kleopatra: Hide non-matching keygroups when using a key filter.
Feb 6 2024, 10:46 AM · vsd33, Restricted Project, kleopatra
ebo added a project to T6970: Kleopatra: Hide non-matching keygroups when using a key filter: Restricted Project.
Feb 6 2024, 10:45 AM · vsd33, Restricted Project, kleopatra
ikloecker claimed T6846: Kleopatra: learn TCOS cards automatically.
Feb 6 2024, 10:15 AM · vsd33, Restricted Project, kleopatra
TobiasFella committed rLIBKLEOe61f3bb96863: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 6 2024, 9:52 AM
Karam changed Version from 1.17.1 (tested also on 1.22.0 to libgpgme 1.17.1 (tested also on 1.22.0) on T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature.
Feb 6 2024, 9:36 AM · gpgme, Bug Report
Karam created T6977: gpgme_op_verify from libgpgme hang without returning anything when verifying corrupted file signature.
Feb 6 2024, 9:35 AM · gpgme, Bug Report
TobiasFella committed rLIBKLEO43900fc91d4e: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 6 2024, 9:34 AM
TobiasFella committed rLIBKLEOc14508615bf9: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 6 2024, 9:28 AM
TobiasFella committed rLIBKLEOe08ee7ac9d26: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 6 2024, 9:11 AM
TobiasFella committed rLIBKLEO0cb529bedac6: Apply 1 suggestion(s) to 1 file(s) (authored by ikloecker).
Apply 1 suggestion(s) to 1 file(s)
Feb 6 2024, 9:10 AM
TobiasFella committed rLIBKLEOc5b465c6b6d3: Rework UserIdProxyModel data handling (authored by TobiasFella).
Rework UserIdProxyModel data handling
Feb 6 2024, 9:10 AM
werner committed rC52f18b9ffe6c: doc: Fix link to the s-expression description. (authored by werner).
doc: Fix link to the s-expression description.
Feb 6 2024, 9:09 AM
TobiasFella committed rLIBKLEO3711f5e93b42: Apply 1 suggestion(s) to 1 file(s) (authored by ikloecker).
Apply 1 suggestion(s) to 1 file(s)
Feb 6 2024, 9:02 AM
ikloecker added a comment to T6975: The option --default-key gives up too early if there are multiple matches.

Quite frankly, if a third party application calls gpg with anything other than fingerprints to specify keys it's asking for trouble. I have changed KMail from using user IDs to using fingerprints when calling gpg more than 20 years ago.

Feb 6 2024, 8:42 AM · Feature Request, gnupg
l10n daemon script <scripty@kde.org> committed rLIBKLEO4fc784e315da: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 5:51 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA72ba19b983ae: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 5:50 AM
l10n daemon script <scripty@kde.org> committed rMTPc294a5c6093a: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 4:40 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOc2690574d532: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 4:40 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAe303bdaf8c0d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 4:40 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOb7b41c110a13: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 3:52 AM
l10n daemon script <scripty@kde.org> committed rMTPc60fccce8f72: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 3:52 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA91a19af15907: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 3:52 AM
Angel reopened T6975: The option --default-key gives up too early if there are multiple matches as "Open".

Sorry, Werner, but I have to disagree on this. Specifying them by fingerprint only works if you have a specific field for the key (including the case where you are just it on the config file).

Feb 6 2024, 3:17 AM · Feature Request, gnupg
l10n daemon script <scripty@kde.org> committed rMTP950de7d19334: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 2:35 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOcec0c3604553: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 2:35 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAa02a962ce666: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 6 2024, 2:33 AM

Feb 5 2024

neverpanic added a comment to T6976: RSA PKCS#1v1.5 signatures with SHA3 use invalid encoding.

I'm attaching a proposed patch. We should decide whether this is the correct encoding to use for SHAKE128 and SHAKE256, because they are variable-length output functions and there is an alternative encoding that has a field for the length, which is likely better suited, but currently not really well supported by libgcrypt (since this would be dynamic content in the ASN.1 encoding).

Feb 5 2024, 5:39 PM · FIPS, libgcrypt, Bug Report
neverpanic created T6976: RSA PKCS#1v1.5 signatures with SHA3 use invalid encoding.
Feb 5 2024, 5:37 PM · FIPS, libgcrypt, Bug Report
TobiasFella committed rKLEOPATRAe1238027cb91: Adapt SignEncryptWidget to be based on UserIDs instead of Keys (authored by TobiasFella).
Adapt SignEncryptWidget to be based on UserIDs instead of Keys
Feb 5 2024, 4:54 PM
TobiasFella committed rLIBKLEOaeff1ff46549: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 5 2024, 4:50 PM
TobiasFella committed rLIBKLEOdc6535e65697: Rework UserIdProxyModel data handling (authored by TobiasFella).
Rework UserIdProxyModel data handling
Feb 5 2024, 4:13 PM
TobiasFella committed rLIBKLEO0c19d69f29b9: Adapt KeySelectionCombo to use user IDs instead of Keys (authored by TobiasFella).
Adapt KeySelectionCombo to use user IDs instead of Keys
Feb 5 2024, 4:12 PM
TobiasFella committed rLIBKLEO955e7a765891: Rework UserIdProxyModel data handling (authored by TobiasFella).
Rework UserIdProxyModel data handling
Feb 5 2024, 4:12 PM
werner committed rD1ea209620bc7: web: Improve wording of Libgcrypt's security model. (authored by werner).
web: Improve wording of Libgcrypt's security model.
Feb 5 2024, 3:14 PM
werner committed rG23d9093d9b05: More NEWS. (authored by werner).
More NEWS.
Feb 5 2024, 1:02 PM
dvratil moved T6891: KMail: IMAP flags are sometimes not synced / shown correctly from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Feb 5 2024, 10:25 AM · Restricted Project, KMail
dvratil moved T6862: Document how to switch akonadi database backend to sqlite from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Feb 5 2024, 10:25 AM · Restricted Project, KMail
dvratil moved T6776: KOrganizer: Reminders only for attendees from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Feb 5 2024, 10:25 AM · Restricted Project, KDE
mlaurent committed rKLEOPATRAaec4de30aa3e: GIT_SILENT: add SPDX-FileCopyrightText/SPDX-License-Identifier (authored by mlaurent).
GIT_SILENT: add SPDX-FileCopyrightText/SPDX-License-Identifier
Feb 5 2024, 8:57 AM
werner closed T6975: The option --default-key gives up too early if there are multiple matches as Wontfix.

Instead of tweaking this and risk a regression for some users I added a suggested to the man page to use a fingerprint.

Feb 5 2024, 8:53 AM · Feature Request, gnupg
werner committed rG5842eee80523: doc: Suggest the use of a fingerprint for --default-key. (authored by werner).
doc: Suggest the use of a fingerprint for --default-key.
Feb 5 2024, 8:52 AM
mlaurent committed rKLEOPATRA64a2693b6204: Use KF_MIN_VERSION/KMIME_VERSION in windows because for the moment version is… (authored by mlaurent).
Use KF_MIN_VERSION/KMIME_VERSION in windows because for the moment version is…
Feb 5 2024, 8:46 AM
werner closed T6972: Explicitly deprecate --use-embedded-filename -- it is hazardous as Resolved.

Unfortunately there are real world applications which make use of this option in special environments. Thus we can't remove it. I improved the warning in the man page.

Feb 5 2024, 8:44 AM · Documentation, gnupg, patch
werner committed rGe5f24218fcd8: doc: Improve warning for --use-embedded-filename. (authored by werner).
doc: Improve warning for --use-embedded-filename.
Feb 5 2024, 8:43 AM
werner closed T6974: Bump requisites on 2.2.x as Resolved.
Feb 5 2024, 8:24 AM · gnupg
werner committed rG3d46eb6cf799: common: Update requisites (authored by Angel).
common: Update requisites
Feb 5 2024, 8:24 AM
werner added a project to T6974: Bump requisites on 2.2.x: gnupg.

There will be a 2.2.43 soonish. Thanks for the patch.

Feb 5 2024, 8:24 AM · gnupg
werner committed rGcbe0956df0f9: gpgsm: Increase salt size in pkcs#12 parser. (authored by werner).
gpgsm: Increase salt size in pkcs#12 parser.
Feb 5 2024, 8:15 AM
werner committed rG214d3ffe0f91: gpgsm: Increase salt size in pkcs#12 parser. (authored by werner).
gpgsm: Increase salt size in pkcs#12 parser.
Feb 5 2024, 8:15 AM
werner committed rG375c3a238ab6: gpgsm: cleanup on error paths (authored by Angel).
gpgsm: cleanup on error paths
Feb 5 2024, 8:15 AM
werner added a comment to T6757: gpgsm 2.4 Fails to import P12 certificate/key.

I would have expected an error message right after

Feb 5 2024, 8:09 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6973: uninitialized err on p12_parse as Resolved.

Thanks. Applied to 2.4 will eventually be merged into master.

Feb 5 2024, 7:55 AM · gnupg
l10n daemon script <scripty@kde.org> committed rLIBKLEO858eff164e7e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 5 2024, 5:48 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA72a1c62f2eff: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Feb 5 2024, 5:47 AM