Page MenuHome GnuPG
Feed Advanced Search

Oct 29 2024

werner committed rMa304ec0ede93: core: New context flags "known-notations". (authored by werner).
core: New context flags "known-notations".
Oct 29 2024, 12:02 PM
werner added a comment to T6799: Kleopatra configuration files in wrong places.

Thus the rule is that all our Qt applications except for pinentry need to fist initialize gpgme to get the actually used GNUPGEHOME. gpgconf either takes this from the GNUPGHOME envvar or from its default or via its gpgconf.ctl file.
The latter can eventually be used to move the default homedir to %APPDATA%\gnupg-vsd so to allow using different versions of the gnupg engine.

Oct 29 2024, 9:37 AM · gpd5x, kleopatra

Oct 28 2024

werner triaged T7348: Display in web interface when no native client for the given email account is found as Normal priority.
Oct 28 2024, 9:47 AM · gpgol2
werner added a comment to T7351: 2.2.45 exitcode 2 when importing revocation cert for expired key.

Indeed, gpg fixes a long standing bug in that expired trusted-keys were not correctly handled. Thus this error message

Oct 28 2024, 9:46 AM · gnupg, Bug Report

Oct 25 2024

werner added a comment to T7350: Kleopatra: Don't offer "Trust root certificate" if users are not allowed to do this.

If we fix this bug for 2.2 we need to have a configure way to revert to the old behaviour. That needs to be a kleopatra config. Or we just don't fix this bug for current vsd but only for gpg4win and the next generation vsd.

Oct 25 2024, 12:14 PM · vsd33 (vsd-3.3.0), gpd5x, kleopatra
werner edited projects for T4060: Add ability to mark critical notations as "recognized" during signature verification, added: gnupg; removed gnupg (gpg22).

Solved for gnupg 2.2, 2.4 and 2.6. GPGME support still missing.

Oct 25 2024, 12:10 PM · gnupg, gpgme, Feature Request

Oct 24 2024

werner added a comment to T7349: Kleopatra: inconsistent behavior of "Trust root certificate".

iirc, Kleopatra modifies the trustlist.txt on its own. The import case is handled by gpgsm which pops up boths dialogs.
Kleopatra should also not offer to add a root CA if gpg-agent's mark-trusted feature has been disabled.

Oct 24 2024, 3:59 PM · gpd5x, kleopatra

Oct 23 2024

werner closed T6185: `gpg2 --list-keys --with-colons > /dev/full` exits with status 0 as Resolved.

Also done for gpgsm in gnupg26 (master)

Oct 23 2024, 11:42 AM · Bug Report, gnupg
werner committed rG18081e2ecf43: gpgsm: Terminate key listing on output write error. (authored by werner).
gpgsm: Terminate key listing on output write error.
Oct 23 2024, 11:42 AM

Oct 22 2024

werner closed T7255: Release GnuPG 2.2.45 as Resolved.
Oct 22 2024, 6:29 PM · gnupg22 (gnupg-2.2.45), Release Info
werner committed rG5c0383d558cc: Post release updates (authored by werner).
Post release updates
Oct 22 2024, 6:24 PM
werner committed rG8838e795e93e: po: msgmerge (authored by werner).
po: msgmerge
Oct 22 2024, 6:24 PM
werner committed rG8e3fc26d4a1e: Release 2.2.45 (authored by werner).
Release 2.2.45
Oct 22 2024, 6:24 PM
werner committed rGae383e0e7363: po: Update German translation (authored by werner).
po: Update German translation
Oct 22 2024, 6:24 PM
werner triaged T7344: libgpg-error: nullptr as Normal priority.
Oct 22 2024, 4:58 PM · gpgrt, Bug Report
werner added a project to T7344: libgpg-error: nullptr: gpgrt.

The C comittee is getting more an more absurd by adding new keywords. Breaking software for fun and funding. Workaround should be easy: Don't use the C23 option.

Oct 22 2024, 4:57 PM · gpgrt, Bug Report
werner added a comment to T7329: Update about data of Kleopatra.

What about the simplification below. Add more authors and sort-lines as you like. There is no legal necessary to show a full list of copyright holders. Authors are not a legal term in the context of software because software is not considered a piece or art. From the GNU coding standards related to the version/about output:

Oct 22 2024, 4:39 PM · vsd33 (vsd-3.3.0), gpd5x, kleopatra
werner changed the status of T7255: Release GnuPG 2.2.45 from Open to Testing.
Oct 22 2024, 4:07 PM · gnupg22 (gnupg-2.2.45), Release Info
werner moved T7255: Release GnuPG 2.2.45 from Backlog to gnupg-2.2.45 on the gnupg22 board.
Oct 22 2024, 4:07 PM · gnupg22 (gnupg-2.2.45), Release Info
werner edited projects for T7255: Release GnuPG 2.2.45, added: gnupg22; removed gnupg.
Oct 22 2024, 4:07 PM · gnupg22 (gnupg-2.2.45), Release Info
werner updated the task description for T7255: Release GnuPG 2.2.45.
Oct 22 2024, 3:31 PM · gnupg22 (gnupg-2.2.45), Release Info
werner closed T7254: Release GnuPG 2.2.45 as Invalid.

See T7255 instead.

Oct 22 2024, 3:29 PM · Duplicate, Release Info
werner moved T7254: Release GnuPG 2.2.45 from WiP to gnupg-2.2.45 on the gnupg22 board.
Oct 22 2024, 3:23 PM · Duplicate, Release Info

Oct 21 2024

werner committed rG51b7bb910658: common: Fix test for the assumed compliance. (authored by werner).
common: Fix test for the assumed compliance.
Oct 21 2024, 5:15 PM

Oct 18 2024

werner raised the priority of T6694: Random numbers from gpgme from Normal to High.
Oct 18 2024, 2:01 PM · gpd5x, gpgpass, gpgme, Feature Request

Oct 15 2024

werner committed rW8f688386fb67: Update to latest component snapshots (authored by werner).
Update to latest component snapshots
Oct 15 2024, 2:20 PM
werner committed rG4728d7f0df33: po: Update German translation (authored by werner).
po: Update German translation
Oct 15 2024, 1:40 PM
werner committed rGafe87ffc08e1: speedo: Enable additional runtime protections on Windows. (authored by werner).
speedo: Enable additional runtime protections on Windows.
Oct 15 2024, 1:40 PM
werner created T7338: Revamp the FIPS service indicator.
Oct 15 2024, 11:24 AM · libgcrypt, FIPS, Feature Request
werner triaged T7334: Kleopatra: ADSK shown as "unknown recipient" as Normal priority.
Oct 15 2024, 9:52 AM · gpd5x, kleopatra
werner added a comment to T7334: Kleopatra: ADSK shown as "unknown recipient".

There is no such concept of a primary keyblock for a subkey. Using the same subkey for several primary keys is non frequent but nevertheless seen use-case. Thus this behaviour is not ADSK specific. I would suggest to first search the keyblock used for decryption to get the name of another subkey - only if that is not found search the keyring for that subkey and thus the primary key and its user id.

Oct 15 2024, 9:51 AM · gpd5x, kleopatra
werner closed T7335: S/MIME keys are not listed correctly as Resolved.

FWIW, the cache has not been implemented in 2.4 (which will be used for the next gpg4win) and thus there is no need for a fix there.

Oct 15 2024, 9:46 AM · gnupg, Bug Report
werner committed rG374195e741cf: gpgsm: Fix cached istrusted lookup. (authored by werner).
gpgsm: Fix cached istrusted lookup.
Oct 15 2024, 9:46 AM
werner added a comment to T7335: S/MIME keys are not listed correctly.

Was fixed last Thursday with commit rG69a8aefa5bf77136b77383b94e34ba784c1cce89 for 2.2 and will soon make it to master.

Oct 15 2024, 9:43 AM · gnupg, Bug Report

Oct 14 2024

werner committed rGcb5f4aba57dc: dirmngr: Print a brief list of URLs with LISTCRLS. (authored by werner).
dirmngr: Print a brief list of URLs with LISTCRLS.
Oct 14 2024, 5:06 PM
werner committed rGf8b1b7b4df86: dirmngr: Print a brief list of URLs with LISTCRLS. (authored by werner).
dirmngr: Print a brief list of URLs with LISTCRLS.
Oct 14 2024, 5:06 PM
werner added a comment to T7334: Kleopatra: ADSK shown as "unknown recipient".

It is not of the recipient's business to know which certificate also uses a subkey. For all the user needs to know that it is a subkey which belongs to a primary key. In this regard this is not different from a shared encryption subkey as used by many sites for role addresses. For a subkey the user id of its primary should always been show.

Oct 14 2024, 5:00 PM · gpd5x, kleopatra
werner added inline comments to rGf8bf5e01f766: build: Use AC_C_BIGENDIAN for detecting endian..
Oct 14 2024, 4:55 PM
werner triaged T7337: Show a summary of all URLs with dirmngr's LISTCRL command as Normal priority.
Oct 14 2024, 4:41 PM · gnupg22 (gnupg-2.2.45), Feature Request

Oct 13 2024

werner added a comment to T7334: Kleopatra: ADSK shown as "unknown recipient".

Yes. I think that Kleo does not yet fully support the R-flag indicating an ADSK.

Oct 13 2024, 7:59 PM · gpd5x, kleopatra

Oct 11 2024

werner renamed T7333: Allow gpg to auto-upload a new own key to LDAP servers from Allow gpg to auto-upload a new key to LDAP servers to Allow gpg to auto-upload a new own key to LDAP servers.
Oct 11 2024, 2:34 PM · vsd33, gnupg22, Unknown Object (Project)
werner triaged T7333: Allow gpg to auto-upload a new own key to LDAP servers as High priority.
Oct 11 2024, 2:32 PM · vsd33, gnupg22, Unknown Object (Project)
werner closed T6929: Kleopatra: Allow revocation of RSA 2048 keys as Resolved.
Oct 11 2024, 2:25 PM · kleopatra, gnupg
werner added a comment to rE1860f6407f83: spawn: Add new function to modify environment..
$ echo -n _gpgrt_spawn_actions_set_envchange | wc -c
34
Oct 11 2024, 10:45 AM
werner added a comment to T7332: Kleopatra: Initial keylisting sometimes fails or hangs for some seconds.

systemd based Linux?

Oct 11 2024, 10:32 AM · gnupg24, gnupg22, gpd5x, kleopatra, Bug Report
werner removed a member for g10code: bad.
Oct 11 2024, 9:30 AM
werner removed a member for g10code: MuckiSG.
Oct 11 2024, 9:30 AM

Oct 10 2024

werner committed rG69a8aefa5bf7: gpgsm: Fix cached istrusted lookup. (authored by werner).
gpgsm: Fix cached istrusted lookup.
Oct 10 2024, 6:06 PM
werner added a comment to T7133: Add feature to load designated revoker from LDAP.

I do not want to do that for 2.2.45 (T7255) because we want to do that release RSN

Oct 10 2024, 9:47 AM · vsd33, Feature Request, gnupg22
werner triaged T7321: Kleopatra: add warning symbol to all unusable groups as Normal priority.
Oct 10 2024, 9:45 AM · vsd33 (vsd-3.3.0), Unknown Object (Project), kleopatra
werner triaged T7323: scdaemon hangs up (when output from scdaemon is not consumed by gpg-agent) as High priority.
Oct 10 2024, 9:45 AM · Windows, Bug Report, scd
werner triaged T7324: Autostart as Normal priority.

Is there a mechanism which can be used for this? Of course this could be done using the usual autostart feature, or we turn the server into a Windows service (ask @alexk). Start the client along with kleopatra?

Oct 10 2024, 9:02 AM · gpgol2
werner triaged T7325: Guide users into installing manifest.xml as Normal priority.
Oct 10 2024, 8:59 AM · gpgol2
werner triaged T7326: Encrypted drafts as Normal priority.
Oct 10 2024, 8:59 AM · gpgol2
werner triaged T7329: Update about data of Kleopatra as Normal priority.
Oct 10 2024, 8:58 AM · vsd33 (vsd-3.3.0), gpd5x, kleopatra
werner edited projects for T7330: gpgrt should use destructor instead of atexit for cleanup, added: Feature Request; removed Bug Report.
Oct 10 2024, 8:57 AM · Feature Request, gpgrt
werner triaged T7330: gpgrt should use destructor instead of atexit for cleanup as Normal priority.

Thanks for opening a bug report. This is better for our workflow.

Oct 10 2024, 8:57 AM · Feature Request, gpgrt

Oct 9 2024

werner added projects to T7323: scdaemon hangs up (when output from scdaemon is not consumed by gpg-agent): scd, Bug Report.

But the DEVINFO --watch is required to trigger this hang? Kleopatra does not use this but we see simlar hangs from time to time in the current version.

Oct 9 2024, 6:18 PM · Windows, Bug Report, scd
werner added a project to T7328: Add Kleopatra configs to gpgconf -X: Feature Request.
Oct 9 2024, 4:18 PM · gpd5x, Windows, gnupg, Feature Request
werner updated the image for gpd5x from F15172262: profile to F15172321: profile.
Oct 9 2024, 3:55 PM
werner set the image for gpd5x to F15172262: profile.
Oct 9 2024, 3:53 PM
werner created gpd5x.
Oct 9 2024, 3:52 PM

Oct 8 2024

werner edited Description on gpgol.
Oct 8 2024, 12:33 PM
werner edited Description on gpgol2.
Oct 8 2024, 12:31 PM

Oct 7 2024

werner committed rM1a7bc88ee756: core: New flag fields beta_compliance. (authored by werner).
core: New flag fields beta_compliance.
Oct 7 2024, 10:33 AM
werner committed rGb287fb577587: Implement GNUPG_ASSUME_COMPLIANCE envvar for testing (authored by werner).
Implement GNUPG_ASSUME_COMPLIANCE envvar for testing
Oct 7 2024, 9:57 AM
werner committed rGe8858807bcaf: gpg: Emit status error for an invalid ADSK. (authored by werner).
gpg: Emit status error for an invalid ADSK.
Oct 7 2024, 8:30 AM
werner committed rG85d8fa57db0a: gpg: Emit status error for an invalid ADSK. (authored by werner).
gpg: Emit status error for an invalid ADSK.
Oct 7 2024, 8:30 AM
werner committed rGa8b503c42bd4: gpg: Emit status error for an invalid ADSK. (authored by werner).
gpg: Emit status error for an invalid ADSK.
Oct 7 2024, 8:30 AM
werner added a comment to T7322: Kleopatra: General error if ADSK is not configured correctly.

With the new patch you get this now:

[GNUPG:] KEY_CONSIDERED F40ADB902B24264AA42E50BF92EDB04BFF325CF3 1
[GNUPG:] ERROR add_adsk 53
gpg: key "F40ADB902B24264AA42E50BF92EDB04BFF325CF3!" not found: Unusable public key
gpg: Did you specify the fingerprint of a subkey?
[GNUPG:] FAILURE gpg-exit 33554433
Oct 7 2024, 8:26 AM · vsd33 (vsd-3.3.0), Unknown Object (Project), gnupg

Oct 4 2024

werner added a comment to T7308: Speed up the X.509 key listings.

Test on a dedicated Windows box (T 460, i5-6300U@2.40GHz, harddisk):

VSD Versiongpg versionLoad time
3.1.262.2.411:59
3.2.4 beta-22.2.45 beta 250:46
Oct 4 2024, 3:03 PM · S/MIME, Feature Request, gnupg
werner committed rD7ccbda17a2e6: web: Add an entry for 2.6 into the EOL list (authored by werner).
web: Add an entry for 2.6 into the EOL list
Oct 4 2024, 2:07 PM
werner committed rGf8f6c6c76166: gpgsm: Add compatibility flag no-keyinfo-cache (authored by werner).
gpgsm: Add compatibility flag no-keyinfo-cache
Oct 4 2024, 12:22 PM
werner committed rG9087c1d3637c: gpgsm: Implement a cache for the KEYINFO queries. (authored by werner).
gpgsm: Implement a cache for the KEYINFO queries.
Oct 4 2024, 12:19 PM
werner committed rGa5527edebbad: gpgsm: Add compatibility flag no-keyinfo-cache (authored by werner).
gpgsm: Add compatibility flag no-keyinfo-cache
Oct 4 2024, 12:19 PM
werner committed rG09d4b8f496dd: gpgsm: Use a cache for ISTRUSTED queries. (authored by werner).
gpgsm: Use a cache for ISTRUSTED queries.
Oct 4 2024, 12:19 PM
werner committed rG4fa82eec43e8: agent: Add option --status to the LISTRUSTED command. (authored by werner).
agent: Add option --status to the LISTRUSTED command.
Oct 4 2024, 12:19 PM
werner edited projects for T4537: gpgsm support for timestamp signatures, added: gnupg26; removed gnupg24.
Oct 4 2024, 12:14 PM · gnupg26, S/MIME, Feature Request
werner claimed T7319: gpgsm/dirmngr: Improve forward path-building via http AIA extension in x.509 certificates.
Oct 4 2024, 12:10 PM · S/MIME, gnupg26, Feature Request
werner added a comment to T7308: Speed up the X.509 key listings.

Overall effect of these changes tested on a small Windows VM is only 47 -> 26 seconds. Did also tests with --kbx-buffer-size but that does not make it better than the default, either.

Oct 4 2024, 12:05 PM · S/MIME, Feature Request, gnupg
werner closed T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy as Resolved.
Oct 4 2024, 11:46 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.5), Bug Report
werner closed T6843: after enable kdf-setup impossible change user/admin pin as Resolved.
Oct 4 2024, 11:45 AM · gnupg22 (gnupg-2.2.43), scd, yubikey
werner moved T6843: after enable kdf-setup impossible change user/admin pin from QA to gnupg-2.2.43 on the gnupg22 board.
Oct 4 2024, 11:45 AM · gnupg22 (gnupg-2.2.43), scd, yubikey
werner changed the status of T6843: after enable kdf-setup impossible change user/admin pin from Resolved to Duplicate.
Oct 4 2024, 11:45 AM · gnupg22 (gnupg-2.2.43), scd, yubikey
werner closed T6843: after enable kdf-setup impossible change user/admin pin as Resolved.

Porting to 2.2 was straightforward - we won't give it an extra QA run.

Oct 4 2024, 11:45 AM · gnupg22 (gnupg-2.2.43), scd, yubikey
werner closed T6811: gpgv: Read-only trustedkeys.kbx should not be compressed as Resolved.

We won't fix that for 2.2.

Oct 4 2024, 11:40 AM · gnupg24 (gnupg-2.4.5), gpgv, Bug Report
werner moved T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy from QA to gnupg-2.2.43 on the gnupg22 board.
Oct 4 2024, 11:38 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.5), Bug Report
werner moved T6882: Make ADSK configurable for new keys from QA to gnupg-2.2.45 on the gnupg22 board.
Oct 4 2024, 11:35 AM · gnupg24 (2.4.6), gnupg22 (gnupg-2.2.45)
werner removed a project from T6882: Make ADSK configurable for new keys: Unknown Object (Project).
Oct 4 2024, 11:34 AM · gnupg24 (2.4.6), gnupg22 (gnupg-2.2.45)
werner removed a project from T6882: Make ADSK configurable for new keys: vsd33.
Oct 4 2024, 11:34 AM · gnupg24 (2.4.6), gnupg22 (gnupg-2.2.45)

Oct 2 2024

werner committed rG241971fac0fc: gpgsm: Implement a cache for the KEYINFO queries. (authored by werner).
gpgsm: Implement a cache for the KEYINFO queries.
Oct 2 2024, 5:52 PM
werner committed rGef2be95258d2: gpgsm: Use a cache for ISTRUSTED queries. (authored by werner).
gpgsm: Use a cache for ISTRUSTED queries.
Oct 2 2024, 5:52 PM
werner committed rG4275d5fa7a51: agent: Add option --status to the LISTRUSTED command. (authored by werner).
agent: Add option --status to the LISTRUSTED command.
Oct 2 2024, 5:52 PM
werner lowered the priority of T7313: gpgconf --list-options does not handle multiple trusted-keys. from Normal to Low.
Oct 2 2024, 5:15 PM · Feature Request, gnupg
werner added a member for Contributor: m.eik.
Oct 2 2024, 10:13 AM
werner added a member for g10code: m.eik.
Oct 2 2024, 10:09 AM
werner triaged T7317: Update the gnupg.org FAQ as Normal priority.
Oct 2 2024, 8:48 AM · www.gnupg.org, FAQ
werner added a comment to T7316: Curve25519/v5 key cannot be exported.

Using the shorter OID for v5 is on purpose; thus we need to fix the export.

Oct 2 2024, 8:36 AM · gnupg26, OpenPGP, PQC, gnupg

Oct 1 2024

werner triaged T7315: Allow exporting of PQC keys. as Normal priority.
Oct 1 2024, 6:12 PM · gnupg26, OpenPGP, PQC, gnupg
werner archived gnupg22 (gnupg-2.2.45).
Oct 1 2024, 2:03 PM