In T7455#211465, @timegrid wrote:Notes:
- The "Encrypt..." and "Sign..." operations might not be needed anymore now, that "Sign/Encrypt ..." is available?
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed Advanced Search
Advanced Search
Advanced Search
Jan 14 2026
Jan 14 2026
timegrid changed the status of T7455: Improved Sign/Encrypt/Decrypt/Verify from clipboard from Testing to Open.
Mostly looks good to me on gpg4win-5.0.0-beta479 @ win11.
Was anything changed? What to test here?
Jan 13 2026
Jan 13 2026
I've changed this now to "GnuPG VS-Desktop" (and "GnuPG Desktop").
Am I right that for VSD we use:
• ikloecker changed the status of T5707: Kleopatra: Use windows registry additionally to config files from Open to Testing.
We set the following organization names for the different products:
- Gpg4win: Gpg4win
- GnuPG Desktop: GnuPG Desktop
- GnuPG VS-Desktop: GnuPG VS-Desktop
i.e. the registry path for Kleopatra settings will be for example
SOFTWARE\Gpg4win\Kleopatra\<config group>\<config entry>
• ebo moved T8018: Okular: No error on signature with wrong passphrase from Backlog to WIP on the gpd5x board.
• TobiasFella changed the status of T7831: Kleopatra: Configuration of the initial status of all checkboxes in the sign/encrypt dialog from Open to Testing.
timegrid changed the status of T5707: Kleopatra: Use windows registry additionally to config files from Testing to Open.
On gpg4win-5.0.0-beta479 @ win11 the registry settings are not read due to the organization name not set.
• ebo moved T6732: Visual representation of signature is a bit ugly from Backlog to QA on the gpd5x board.
A way to trigger some errors could be trying to save to c:\windows or some other place you can't do.
Or while you have the key list open in okular, remove the key underneath everything and then continue.
• ebo moved T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures from Backlog to QA on the gpd5x board.
svuorela changed the status of T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures from Open to Testing.
svuorela added a comment to T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures.
We now have a filter for qualified signatures if there is any in the list
svuorela changed the status of T8018: Okular: No error on signature with wrong passphrase from Open to Testing.
Fixed upstream with https://invent.kde.org/graphics/okular/-/merge_requests/1301 - not yet in our packaging
@werner: gpg fails to batch import secret Kyber keys:
$ GNUPGHOME=/home/ingo/dev/g10/.gnupghomes/empty gpg --batch --import --verbose ~/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc gpg: WARNING: unsafe permissions on homedir '/home/ingo/dev/g10/.gnupghomes/empty' gpg: enabled compatibility flags: gpg: sec brainpoolP256r1/DD89C34EF2B69576 2024-11-14 Kyber768 <kyber768@example.net> gpg: using pgp trust model gpg: key DD89C34EF2B69576: public key "Kyber768 <kyber768@example.net>" imported gpg: key DD89C34EF2B69576/DD89C34EF2B69576: secret key imported gpg: key DD89C34EF2B69576/D07DD3BF9F1AAF4F: error sending to agent: IPC parameter error gpg: error reading '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc': IPC parameter error gpg: import from '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc' failed: IPC parameter error gpg: Total number processed: 0 gpg: imported: 1 gpg: secret keys read: 1
Importing the same files via cli does work:
Screenshots of different imports:
gpgme.log (import of kyber team key with signing key):
gpgme.teamkey.withsigning.log422 KBDownload
gpgme.log (import of normal non team key kyber cert):
gpgme.log330 KBDownload
timegrid raised the priority of T8029: IPC error on batch import of secret kyber cert from Normal to High.
• ebo added a comment to T8030: Kleopatra: Add hint to filename of secret team key exports with signing key.
or maybe for the fist one "_ENC_ONLY"
timegrid triaged T8030: Kleopatra: Add hint to filename of secret team key exports with signing key as Normal priority.
• TobiasFella closed T7427: Kleopatra: Crash after decryption if files has an embedded file name as Resolved.
Setting to resolved, as I think it should be
• ikloecker moved T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Backlog to WIP on the vsd34 board.
Backported for VSD 3.4
• ikloecker changed the status of T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Open to Testing.
Done. I've used the following script to create clear-signed test messages with good/bad signature signed with certificates with different validity and status (expired, revoked).
All sub tickets are done.
• ikloecker changed the status of T7429: Kleopatra: Importing certificate from Verification result dialog doesn't correctly re-verify the signature from Open to Testing.
This is ready for testing and available in 5.0.0-betaX since about a year.
• ikloecker changed the status of T7455: Improved Sign/Encrypt/Decrypt/Verify from clipboard from Open to Testing.
Should be ready for testing. This is available in 5.0.0-beta479.
• ikloecker changed the status of T7107: Kleopatra: Option "PublicKeyEncryptionOnly" from Open to Testing.
This has finally been merged.
• ikloecker moved T5707: Kleopatra: Use windows registry additionally to config files from Backlog to QA on the gpd5x board.
• ikloecker moved T7008: Kleopatra: New tabs in certficate list should use same column layout as current tab from Backlog to QA on the gpd5x board.
• ikloecker changed the status of T7008: Kleopatra: New tabs in certficate list should use same column layout as current tab from Open to Testing.
In the meantime we don't show the imported certificates anymore in the main window as tabs but in a separate window, i.e. import tabs are no longer an issue. Please retest.
• ikloecker changed the status of T5707: Kleopatra: Use windows registry additionally to config files from Open to Testing.
I'm pretty sure that this is done. For gpd5 the changes have been merged upstream and kconfig reads the config keys in the desired order.
• ikloecker added a parent task for T7267: Kleoaptra shows unknown validity for fully trusted S/MIME certificate in multipart/signed mail: Unknown Object (Maniphest Task).
Jan 12 2026
Jan 12 2026
• werner changed the status of T8026: Kleopatra: Export of multiple S/MIME certificates only exports one from Open to Testing.
• werner added a comment to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one.
Thanks Eva and Ingo. It seems 2.5.17 is not too far away.
• ikloecker removed a project from T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: kleopatra.
I can reproduce this on the command line:
C:\Users\g10code>"c:\Program Files\GnuPG\bin\gpgsm.exe" --export --armor 579BAF3DF16AD462457BCC0897ADBC143D76EA7B 5A2B80F98F518D50891B1F0C7C6131AD107F9938 DB625D2BBBB5A3FD985C0233249B03090E85D402
Issuer ...: /CN=CA IVBB Deutsche Telekom AG 20/OU=Bund/O=PKI-1-Verwaltung/C=DE
Serial ...: 02195D190EBE34
Subject ..: /CN=iOS Test-Smartcard iostest01.sc/OU=BSI/O=Bund/C=DE/SerialNumber=2
aka ..: iostest01.sc@bsi.bund.de
Keygrip ..: 527CE32FD0552D18479442EF90DD5E434C036329• ikloecker added a project to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: gnupg26.
I can reproduce the issue only (!!!) with keyboxd (on Windows).
• ebo triaged T8027: Kleopatra: a secret team key should always include all public key information as High priority.
• ebo triaged T8026: Kleopatra: Export of multiple S/MIME certificates only exports one as High priority.
Jan 9 2026
Jan 9 2026
• ebo added a project to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: Bug Report.
was tested already by timegrid
Looks good to me on gpg4win-5.0.0-beta479 @ win11:
timegrid moved T7971: Kleopatra: Always use gpgme to find the GnuPG binaries from WIP to Done on the gpd5x board.
I assume, that testing the functionality is the only thing I can do here.
• werner moved T7332: Kleopatra: Initial keylisting sometimes fails or hangs for some seconds from Backlog to gnupg-2.2.52 on the gnupg22 board.
• werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from WiP to gnupg-2.2.52 on the gnupg22 board.
• werner closed T7829: w32: daemon (gpg-agent/keyboxd/dirmngr) startup and connection race when there is a socket file already as Resolved.
That was also fixed in gnupg 2.2.50 and thus vsd 3.3.3
• werner closed T7805: Permission denied on batch deletion of mixed (openpgp+smime) certs, a subtask of T7855: keybox/keydb locking issue in 2.6 , as Resolved.
timegrid moved T7567: Kleopatra: warning regarding attribute "_X_" from WIP to Done on the gpd5x board.
Looks good to me on gpg4win-5.0.0-beta479 @ win11
• werner triaged T8015: Kleopatra: Status in certificate list not updated after import as Normal priority.
timegrid updated the task description for T7285: Okular: Improvement of error messages regarding signatures.
timegrid added a project to T7285: Okular: Improvement of error messages regarding signatures: test on hold.
Tested with gpg4win-5.0.0-beta479 @ win11
timegrid moved T7773: Add reencrypt mail option to copy only encrypted mails from QA to Done on the gpgol2 board.
timegrid moved T7773: Add reencrypt mail option to copy only encrypted mails from QA to Done on the gpd5x board.
@tfry tested this, and it seems fine.
Jan 8 2026
Jan 8 2026
• ikloecker moved T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Backlog to WIP on the gpd5x board.
• ebo moved T6453: Kleopatra: Show isQualified in Certificate details if true from WIP to Done on the gpd5x board.
What I did wrong was that I did not include the global trustlist.txt (which is not read by default in Gpg4win) in the user trustlist.
This can be done by putting "include-default" at the beginning of the trustlist.txt in the users GNUPGHOME.
• ikloecker added a comment to T8015: Kleopatra: Status in certificate list not updated after import.
Okay. Confirmed and understood. The problem is that file system watcher doesn't watch the trustdb.gpg file because the file did not yet exist when the watcher was initialized. And during the import we disable the file system watcher so that it doesn't notice the creation of the file and therefore doesn't start watching it.
• werner raised the priority of T6644: GnuPG: Allow non compliant signatures in compliance mode from Wishlist to Normal.
Looks good to me on gpg4win-5.0.0-beta479 @ win11.
Ebo was also able to reproduce it like this:
• ebo updated the task description for T8022: Kleopatra: Extract a tar.gpg archive consisting of only one folder directly into a given directory.
• ebo added a project to T6793: Cleanup temporary files / dirs with decrypted content: needs discussion.
• ebo removed a project from T6793: Cleanup temporary files / dirs with decrypted content: vsd32 (vsd-3.2.0).
• ebo triaged T8022: Kleopatra: Extract a tar.gpg archive consisting of only one folder directly into a given directory as Normal priority.
Jan 7 2026
Jan 7 2026
• ebo closed T7439: Kleopatra: DecryptVerifyFilesDialog crashes when output folder does not exist as Resolved.
In Gpg4win-5.0.0-beta479 the dialog no longer exists. Problem solved ;-)
• ebo moved T7549: Kleopatra: crash on click in certificate extension dialog from QA to Done on the gpd5x board.
Gpg4win-5.0.0-beta479: works, no crash any more
• ikloecker added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.
I have verified (by looking at QTextEdit's code) that, on paste, QTextEdit splits the text for the internal representation into lines and discards any CR and LF characters.


