Page MenuHome GnuPG
Feed Advanced Search

Apr 10 2015

gniibe claimed T1081: scd: "card error" after usb reader plug/unplug cycle, needs hard restart.
Apr 10 2015, 10:08 AM · gnupg, gpg4win, scd, Feature Request
gniibe claimed T1323: Poldi should allow password entry when a card is not inserted.
Apr 10 2015, 9:59 AM · Feature Request, poldi

Apr 9 2015

werner added a comment to T1944: Global changing of expiration date for mainkey and subkeys.

Not yet.

Apr 9 2015, 1:57 PM · gnupg, Feature Request
werner added a project to T1945: pin entry prompt should include more structured metadata: Feature Request.
Apr 9 2015, 1:44 PM · gnupg, Feature Request
werner removed a project from T1945: pin entry prompt should include more structured metadata: Bug Report.
Apr 9 2015, 1:44 PM · gnupg, Feature Request
werner added a comment to T1945: pin entry prompt should include more structured metadata.

For a regular private key wie have such an indentifier. We don't have it for
symmetric passphrases but they are very rarely used. There is also no need to
have any cache for a smart card PIN.

The OpenPGP information as conveyed with SETDESC ist not a stable idnetification
but I think I can add something else. Not for 2.1.3 but soon after it.

Apr 9 2015, 1:44 PM · gnupg, Feature Request

Apr 8 2015

guilhem closed T1710: Fine-grained --fast-list-mode as Resolved.
Apr 8 2015, 10:29 PM · patch, gnupg, Feature Request
guilhem added a comment to T1710: Fine-grained --fast-list-mode.

Done in c238340:

http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=c2383407bba5eefea486464a31e02846124c9da5

Apr 8 2015, 10:29 PM · patch, gnupg, Feature Request
gnupgpacker added projects to T1944: Global changing of expiration date for mainkey and subkeys: Feature Request, gnupg.
Apr 8 2015, 8:22 AM · gnupg, Feature Request

Apr 4 2015

werner added a project to T1932: GnuPG 2.1 (gpgsm):set default of 'hash-algo' from sha1 to sha256: Feature Request.
Apr 4 2015, 11:15 AM · Feature Request, gnupg, gnupg (gpg21), S/MIME
werner lowered the priority of T1932: GnuPG 2.1 (gpgsm):set default of 'hash-algo' from sha1 to sha256 from High to Normal.
Apr 4 2015, 11:15 AM · Feature Request, gnupg, gnupg (gpg21), S/MIME
werner added a project to T1113: sign + encryption OK but decryption failed with 3072 bits key on smartcard V2: Documentation.
Apr 4 2015, 11:14 AM · Not A Bug, gnupg, Feature Request, Documentation, scd
werner added projects to T1113: sign + encryption OK but decryption failed with 3072 bits key on smartcard V2: scd, Feature Request, gnupg.
Apr 4 2015, 11:13 AM · Not A Bug, gnupg, Feature Request, Documentation, scd
werner removed a project from T1113: sign + encryption OK but decryption failed with 3072 bits key on smartcard V2: Bug Report.
Apr 4 2015, 11:13 AM · Not A Bug, gnupg, Feature Request, Documentation, scd
werner added a project to T1939: Listing a keybox isn't as fast as promised: Bug Report.
Apr 4 2015, 11:08 AM · Duplicate, Bug Report, gnupg
werner added a comment to T1939: Listing a keybox isn't as fast as promised.

I know. It is a regression. I will look into it soon.

Apr 4 2015, 11:08 AM · Duplicate, Bug Report, gnupg

Apr 3 2015

gniibe added a project to T1854: Problems with same encryption and signing key on smartcard: gnupg.
Apr 3 2015, 6:12 AM · gnupg, Feature Request, scd
gniibe added a comment to T1854: Problems with same encryption and signing key on smartcard.

I understand your case.

Apr 3 2015, 6:12 AM · gnupg, Feature Request, scd
gniibe claimed T1854: Problems with same encryption and signing key on smartcard.
Apr 3 2015, 6:12 AM · gnupg, Feature Request, scd
gniibe claimed T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only.
Apr 3 2015, 6:09 AM · gnupg, Feature Request
gniibe claimed T1405: Print a warning for readers not supporting extended APDUs..
Apr 3 2015, 5:54 AM · scd, Feature Request, gnupg
gniibe added a comment to T1509: gnupg2 (gpg-agent): Disable producing of core dumps for gpg-agent via prctl(PR_SET_DUMPABLE, 0) as ssh-agent does.

As I wrote to #712744, distribution nowadays is conservative enough for its
default kernel settings, and it doesn't require each application to have special
settings.

I think that we will be able to close this soon.

Apr 3 2015, 5:51 AM · gnupg, Debian, gnupg (gpg20), Feature Request, gpgagent
gniibe claimed T1621: Support multiple cards (not just readers).
Apr 3 2015, 5:41 AM · gnupg, Feature Request
gniibe claimed T1618: Make gnupg more friendly to multiple readers.
Apr 3 2015, 5:40 AM · gnupg, Feature Request, scd
gniibe claimed T1930: PATCH: Be more flexible on PC/SC reader selection.
Apr 3 2015, 4:35 AM · gnupg, Feature Request, scd

Apr 1 2015

guilhem added a comment to T1710: Fine-grained --fast-list-mode.

I created (1938) a new issue for the extreme slowness of --list-sigs on a
keybox. 1938 is most likely a bug, while 1710 is merely a quickfix for an
algorithmic issue in --list-sigs. However if with keybox “random access to the
keys is now really fast”, maybe it a proper fix could easily be implemented
instead. See also

http://lists.gnupg.org/pipermail/gnupg-devel/2015-February/029541.html
Apr 1 2015, 4:27 PM · patch, gnupg, Feature Request
guilhem set Version to 2.1.2 on T1939: Listing a keybox isn't as fast as promised.
Apr 1 2015, 4:19 PM · Duplicate, Bug Report, gnupg
guilhem added projects to T1939: Listing a keybox isn't as fast as promised: Feature Request, gnupg.
Apr 1 2015, 4:19 PM · Duplicate, Bug Report, gnupg
dkg added a comment to T1710: Fine-grained --fast-list-mode.

I'm also seeing this extreme delay from gpg --list-sigs 2.1.2 on a large
keyring, particularly when using kbx. It seems likely that there is a bug here.

Apr 1 2015, 12:42 AM · patch, gnupg, Feature Request

Mar 24 2015

werner closed T1925: Broken link pointing to http://egd.sourceforge.org/ instead of .sourceforge.net as Resolved.
Mar 24 2015, 11:39 AM · gpgweb, Feature Request
werner added a comment to T1925: Broken link pointing to http://egd.sourceforge.org/ instead of .sourceforge.net.

Thanks. Fix pushed to the repo.

Mar 24 2015, 11:39 AM · gpgweb, Feature Request

Mar 21 2015

anstein added a comment to T1930: PATCH: Be more flexible on PC/SC reader selection.

D292: 591_gnupg-2.0.27-pkcs11_reader_match.patch

Mar 21 2015, 8:29 PM · gnupg, Feature Request, scd
anstein added projects to T1930: PATCH: Be more flexible on PC/SC reader selection: scd, Feature Request, gnupg.
Mar 21 2015, 8:29 PM · gnupg, Feature Request, scd

Mar 16 2015

werner removed a project from T1747: Some command line options can not be abbreviated: Bug Report.
Mar 16 2015, 3:14 PM · Feature Request, gnupg
werner added a project to T1747: Some command line options can not be abbreviated: Feature Request.
Mar 16 2015, 3:14 PM · Feature Request, gnupg

Mar 15 2015

stebe added projects to T1925: Broken link pointing to http://egd.sourceforge.org/ instead of .sourceforge.net: Feature Request, gpgweb.
Mar 15 2015, 5:50 PM · gpgweb, Feature Request

Mar 13 2015

dkg added a comment to T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only.

This shows up elsewhere too:

http://forum.yubico.com/viewtopic.php?f=26&t=1171

says:

For some inexplicable reason, GnuPG cannot extract the public key from a
smartcard except during generation. That means that to use the key from
another computer, you either have to copy the public key from the original
computer's GnuPG keyring, or you need to set the URL attribute to a file
which contains the PGP public key block. Otherwise, the token is effectively
locked to a single computer, and unuseable if you happen to trash your
keyring unless you regenerate a key.

It would be nice to streamline this case.

Mar 13 2015, 10:50 PM · gnupg, Feature Request

Mar 10 2015

werner added a comment to T1917: Provide a way to determine available ECC Curves.

Done with commit 14af2be

$ gpg --with-colons --list-config curve
cfg:curve:ed25519;nistp256;nistp384;nistp521;brainpoolP256r1;brainpoolP384r1;brainpoolP512r1;secp256k1

Mar 10 2015, 3:45 PM · gnupg, Feature Request
werner closed T1917: Provide a way to determine available ECC Curves as Resolved.
Mar 10 2015, 3:45 PM · gnupg, Feature Request
werner added a comment to T1919: Libgcrypt in Gpg4Win has AES-NI support disabled.

Since then we did a lot of work on Libgcrypt so that the AES-NI code is
different from May 2012. It is possible that we accidently clobbered a register
which might have been the reason for the VirtualBox failure.

I can't remember the test case, but any use of AES should have hit it. Just use
gpg where AES is the default anyway. I suggest to revert that patch an see what
happens.

Mar 10 2015, 10:56 AM · libgcrypt, Feature Request, gpg4win
werner closed T1869: Case value not in enumerated type as Resolved.
Mar 10 2015, 10:00 AM · Not A Bug, libgcrypt, Feature Request
werner added a comment to T1869: Case value not in enumerated type.

Yes it is not for a reason - checkout the comments to see why.

Mar 10 2015, 10:00 AM · Not A Bug, libgcrypt, Feature Request
werner added a project to T1869: Case value not in enumerated type: Not A Bug.
Mar 10 2015, 10:00 AM · Not A Bug, libgcrypt, Feature Request
werner closed T1871: Adding 'int' to a string does not append to the string as Resolved.
Mar 10 2015, 9:57 AM · Not A Bug, libgcrypt, Feature Request
werner added a project to T1871: Adding 'int' to a string does not append to the string: Not A Bug.
Mar 10 2015, 9:57 AM · Not A Bug, libgcrypt, Feature Request
werner added a comment to T1871: Adding 'int' to a string does not append to the string.

Sure it does not. This is C! What a plain silly warning.

Mar 10 2015, 9:57 AM · Not A Bug, libgcrypt, Feature Request
werner added a comment to T1882: warning: comparison of array 'hd->buf' equal to a null pointer is always false.

No c+p of warnings please! Use gnupg-devel for such things.

Mar 10 2015, 9:56 AM · Mistaken, libgcrypt, Feature Request
werner added a project to T1882: warning: comparison of array 'hd->buf' equal to a null pointer is always false: Mistaken.
Mar 10 2015, 9:56 AM · Mistaken, libgcrypt, Feature Request
werner closed T1882: warning: comparison of array 'hd->buf' equal to a null pointer is always false as Resolved.
Mar 10 2015, 9:56 AM · Mistaken, libgcrypt, Feature Request
werner added a comment to T1883: missing test case for buf_cpy.

Please write one and sent it to gcrypt-devel. You should also provide some
eveidence for your believe.

Mar 10 2015, 9:43 AM · Info Needed, Feature Request, libgcrypt
werner added a project to T1883: missing test case for buf_cpy: Feature Request.
Mar 10 2015, 9:43 AM · Info Needed, Feature Request, libgcrypt
werner lowered the priority of T1883: missing test case for buf_cpy from Normal to Wishlist.
Mar 10 2015, 9:43 AM · Info Needed, Feature Request, libgcrypt

Mar 9 2015

aheinecke added projects to T1919: Libgcrypt in Gpg4Win has AES-NI support disabled: gpg4win, Feature Request, libgcrypt.
Mar 9 2015, 6:41 PM · libgcrypt, Feature Request, gpg4win
aheinecke updated subscribers of T1919: Libgcrypt in Gpg4Win has AES-NI support disabled.
Mar 9 2015, 6:41 PM · libgcrypt, Feature Request, gpg4win

Mar 6 2015

npcole added projects to T1917: Provide a way to determine available ECC Curves: Feature Request, gnupg.
Mar 6 2015, 1:13 PM · gnupg, Feature Request
npcole set Version to 2.1 on T1917: Provide a way to determine available ECC Curves.
Mar 6 2015, 1:13 PM · gnupg, Feature Request
JW set Version to 1.6.3 on T1882: warning: comparison of array 'hd->buf' equal to a null pointer is always false.
Mar 6 2015, 5:52 AM · Mistaken, libgcrypt, Feature Request
JW added projects to T1882: warning: comparison of array 'hd->buf' equal to a null pointer is always false: Feature Request, libgcrypt.
Mar 6 2015, 5:52 AM · Mistaken, libgcrypt, Feature Request

Mar 5 2015

JW added projects to T1871: Adding 'int' to a string does not append to the string: Feature Request, libgcrypt.
Mar 5 2015, 11:29 PM · Not A Bug, libgcrypt, Feature Request
JW set Version to 1.6.3 on T1869: Case value not in enumerated type.
Mar 5 2015, 11:22 PM · Not A Bug, libgcrypt, Feature Request
JW added projects to T1869: Case value not in enumerated type: Feature Request, libgcrypt.
Mar 5 2015, 11:22 PM · Not A Bug, libgcrypt, Feature Request

Feb 27 2015

lorenz added projects to T1854: Problems with same encryption and signing key on smartcard: scd, Feature Request.
Feb 27 2015, 2:15 PM · gnupg, Feature Request, scd

Feb 22 2015

rillig added a comment to T1849: Show revocation certificate details.

After trying some more, I found out some things.

I just have to run "gpg revoke.asc", without any options.

But then, the reason text that I entered when generating the revocation
certificate is not shown. Nor is the numeric reason.

gpg: standalone signature of class 0x20
gpg: Signature made 02/22/15 15:46:23 Eur using DSA key ID BACCF5EE
gpg: standalone revocation - use "gpg --import" to apply

And I dont understand what “class 0x20” means.

Feb 22 2015, 4:53 PM · gnupg, Feature Request
rillig added projects to T1849: Show revocation certificate details: Feature Request, gnupg.
Feb 22 2015, 4:40 PM · gnupg, Feature Request

Feb 20 2015

werner added a comment to T1806: Pinentry-qt should have support for Qt5.

How much time would it take to migrate to QT5?

Feb 20 2015, 9:07 AM · pinentry, Feature Request

Feb 18 2015

werner added a comment to T1840: gpg-agent should have prompt-for-use mechanism.

We already have that "confirm" flag for ssh and thus adding code to use it for
the extra-socket feature should be easy. The open question is how to disable
this feature on a per key base. A ~/.gnupg/confirmcontrol or similar file could
be used to record those keys which do not need confirmation or if persistance is
not required a checkbox in pinentry could be used to show the confirmation
dialog only once per session.

Feb 18 2015, 10:46 AM · gnupg, Feature Request

Feb 16 2015

dkg added projects to T1840: gpg-agent should have prompt-for-use mechanism: Feature Request, gnupg.
Feb 16 2015, 6:06 AM · gnupg, Feature Request

Feb 11 2015

werner added a project to T1831: Remove gpgkey2ssh, source and build target: Stalled.
Feb 11 2015, 12:16 PM · gnupg, Feature Request
werner added a comment to T1831: Remove gpgkey2ssh, source and build target.

This will eventually be done but not right now. I keep this bug report as a
reminder.

I granted you permissions to edit other bug reports. However, this patch is not
required.

Feb 11 2015, 12:16 PM · gnupg, Feature Request
werner closed T1830: Use https for links in documentation. as Resolved.
Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a project to T1830: Use https for links in documentation.: gnupg.
Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a comment to T1830: Use https for links in documentation..

I just changed the remaining http references to gnupg.org to https (on master).
Thanks.
Changing them in coments and in the outdated FAQ does not make sense.

Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a project to T1833: Add support for JSON output: Won't Fix.
Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request
werner closed T1833: Add support for JSON output as Resolved.
Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request
werner added a comment to T1833: Add support for JSON output.

Nope. See my comments at
https://lists.gnupg.org/pipermail/gnupg-users/2015-February/052401.html

Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request

Feb 7 2015

xvilka added projects to T1833: Add support for JSON output: Feature Request, gnupg.
Feb 7 2015, 10:31 PM · Won't Fix, gnupg, Feature Request
Jan-Oliver_Wagner added projects to T1831: Remove gpgkey2ssh, source and build target: Feature Request, gnupg.
Feb 7 2015, 3:21 PM · gnupg, Feature Request
Jan-Oliver_Wagner added a comment to T1830: Use https for links in documentation..

D282: 546_0001-Use-https-for-links-in-documentation.patch

Feb 7 2015, 2:35 PM · gnupg, Feature Request
Jan-Oliver_Wagner added a project to T1830: Use https for links in documentation.: Feature Request.
Feb 7 2015, 2:33 PM · gnupg, Feature Request

Feb 4 2015

werner added projects to T1827: Allow to batch up key refreshs in dirmngr: dirmngr, Feature Request, gnupg.
Feb 4 2015, 9:23 AM · gnupg, Feature Request, dirmngr

Feb 2 2015

werner added projects to T1825: Add a re-encrypt to additional key: Feature Request, gnupg.
Feb 2 2015, 6:32 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request

Jan 28 2015

werner removed a project from T1821: cannot specify secret key to decrypt msg with multiple recipients: Bug Report.
Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg
werner added projects to T1821: cannot specify secret key to decrypt msg with multiple recipients: Feature Request, Won't Fix.
Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg

Jan 26 2015

werner added a comment to T1064: gpgsm: manual page misses to document options.

Should be fixed by commit 017c6f8fba9ae141a46084d6961ba60c4230f97a
on 2014-06-24.

Jan 26 2015, 2:59 PM · backport, gnupg, Debian, Feature Request
werner closed T1064: gpgsm: manual page misses to document options as Resolved.
Jan 26 2015, 2:59 PM · backport, gnupg, Debian, Feature Request

Jan 22 2015

werner closed T1602: Manual page and --help output discrepancies as Resolved.
Jan 22 2015, 5:53 PM · gnupg, Feature Request
werner added a comment to T1602: Manual page and --help output discrepancies.

Okay, that took long :-(: commit da4db172 - will go into 2.1.2.

    I added options shown with --help but missing in the man page.
    However, --help won't show everything listed in the man age and
    frankly there are even more options not listed anywhere (to see them
    use --dump-options).

I also kept one British translation ;-)
Thanks for the report.

Jan 22 2015, 5:53 PM · gnupg, Feature Request

Jan 21 2015

headsup added a comment to T1814: Add option to output the signed text with --verify.

That's fine... or just make the wording in the man page more clear. Under
--verify, it talks about using --output with cleartext signed data. That seemed
to imply (to me) that --output is used _with_ --verify. I think it should be
clearer that --output is to be used _without_ --verify or that --output has no
effect when using --verify.

So this could be treated as just a documentation bug rather than create yet
another new option.

For what it's worth, I don't think backward compatibility is an important
concern here. If someone was using --output with --verify before, they likely
were under the impression that the combination worked when in reality the two
options together just weren't a valid combination. It seems unlikely that
anyone would depend on --output being ignored when used with --verify, and so
making the combination work now should not cause legitimate compatibility problems.

If the combination of --output with --verify is not made to work, there should
probably be a warning emitted (in addition to fixing the documentation).

In summary, it seems to me that viable options are at least the following:

  • make --output work with --verify (possibly bad for compatibility reasons in

the rare use case of someone depending on current behavior of the currently
invalid combination)

  • fix man page in the --verify section - specifically, clarify the text

discussing using --output

  • add some new option
  • warn if an invalid combination of options exists (e.g., --verify with

--current in the current implementation <= 2.1.1)

These are not necessarily exclusive choices.

I guess I would prefer to allow the combination to work or warn and fix the
docs. Not as keen to add yet another new option - there's already a lot.

I can work up a patch if we can settle on a direction.

Jan 21 2015, 5:45 PM · Feature Request, gnupg
werner added a project to T1814: Add option to output the signed text with --verify: gnupg.
Jan 21 2015, 3:31 PM · Feature Request, gnupg
werner added a project to T1814: Add option to output the signed text with --verify: Feature Request.
Jan 21 2015, 3:31 PM · Feature Request, gnupg

Jan 10 2015

werner added a comment to T1809: add option for SHA256 and SHA512 fingerprint.

MD5 is not used bu OpenPGP. It is allowed for backward compatibility but even
that has been dropped for GnuPG 2.1.

The use of SHA-1 fingerprints is hardwired into OpenPGP and to change this a
complete new key format needs to be specified. In any case the fingerprints
are not a problem right now.

Using Base64 fingerprints are actually a bad idea because they are to hard to
compare for a human.

Jan 10 2015, 6:20 PM · gnupg, Feature Request, Won't Fix

Jan 9 2015

kolAflash added a comment to T1809: add option for SHA256 and SHA512 fingerprint.

P.S.
SHA512 probably would be the right thing. If someone's too lazy to compare such
a long fingerprint, he can still choose just to compare just one half of it.

Jan 9 2015, 2:44 PM · gnupg, Feature Request, Won't Fix
kolAflash added a comment to T1809: add option for SHA256 and SHA512 fingerprint.

Sure, a standard for that would be great.

MD5 is pretty much broken for security purposes and I would wonder, if that's
not also true in the context of OpenPGP.

You're probably much closer to the people responsible for the OpenPGP standard.
Are there any efforts to introduce SHA512-BASE64 fingerprints? (or at least SHA256)

Jan 9 2015, 2:38 PM · gnupg, Feature Request, Won't Fix
werner added projects to T1809: add option for SHA256 and SHA512 fingerprint: Won't Fix, gnupg.
Jan 9 2015, 1:00 PM · gnupg, Feature Request, Won't Fix
werner added a comment to T1809: add option for SHA256 and SHA512 fingerprint.

Such fingerprints are not specifed by OpenPGP. It is also questionable whether
this will be used, given that one could also print an 256 bit ECC key directly.
Yeah, that is a bit different than the fingerprint but it raises the importance
of have a standard before coming up with an arbitrary fingerprint scheme.

Jan 9 2015, 1:00 PM · gnupg, Feature Request, Won't Fix

Jan 8 2015

kolAflash added a project to T1809: add option for SHA256 and SHA512 fingerprint: Feature Request.
Jan 8 2015, 11:42 AM · gnupg, Feature Request, Won't Fix

Jan 6 2015

werner added a comment to T1805: gpg-agent: Wakes up periodically.

Linux specific things are a no-go unless really needed.

Yes, things could be adjusted to wake up only if reallyneeded but it requires
more code.

What is the problem you try to solve? Do you have any measurements that show
that battery life is improved by changing this?

Jan 6 2015, 10:38 AM · Feature Request, gnupg
eric_debian.org added a comment to T1805: gpg-agent: Wakes up periodically.

Well if my reading is correct, the housekeeping happens in handle_tick(). 3
things are happening:

  1. Checks for lost parent. This could be converted to a signal (at least on

linux)

  1. Checks for socket permissions. This is checked only every 60 seconds, so we

don't need to wake up every two seconds to check it.

  1. Checks for lost connection to scdaemon... does this have to happen so

frequently?

dirmngr also seems to wake up often to check the if it's time to do housekeeping
(which it does every 10 minutes). Seems like this could also be improved?

scdaemon does seem harder, but not everyone is using smartcards.

Jan 6 2015, 7:34 AM · Feature Request, gnupg

Jan 5 2015

werner added a project to T1805: gpg-agent: Wakes up periodically: Feature Request.
Jan 5 2015, 6:19 PM · Feature Request, gnupg
aheinecke added projects to T1806: Pinentry-qt should have support for Qt5: Feature Request, pinentry.
Jan 5 2015, 10:27 AM · pinentry, Feature Request