Page MenuHome GnuPG
Feed Advanced Search

Dec 27 2015

estellnb added a comment to T2205: GnuPG does not detect damaged keys on import.

Dec 27 2015, 5:51 PM · Not A Bug, Debian, Bug Report, gnupg
estellnb added a comment to T2205: GnuPG does not detect damaged keys on import.

Dec 27 2015, 5:51 PM · Not A Bug, Debian, Bug Report, gnupg
estellnb added a comment to T2205: GnuPG does not detect damaged keys on import.

As I am not sure how to attach files to this report I have uploaded them here:
http://www.elstel.org/uploads/gnupg/

Dec 27 2015, 5:50 PM · Not A Bug, Debian, Bug Report, gnupg
estellnb added a comment to T2205: GnuPG does not detect damaged keys on import.

Dec 27 2015, 5:50 PM · Not A Bug, Debian, Bug Report, gnupg
estellnb added projects to T2205: GnuPG does not detect damaged keys on import: gnupg (gpg14), Keyserver, gnupg, Bug Report, Debian.
Dec 27 2015, 5:36 PM · Not A Bug, Debian, Bug Report, gnupg
estellnb set Version to 1.4.12 on T2205: GnuPG does not detect damaged keys on import.
Dec 27 2015, 5:36 PM · Not A Bug, Debian, Bug Report, gnupg

Dec 26 2015

nervengiftlabs added a comment to T2150: Generating keys on OpenPGP card yields wrong public key.

The patch seems to have fixed it.

Dec 26 2015, 2:37 PM · Bug Report, gnupg, gnupg (gpg21)

Dec 24 2015

patrick added projects to T2204: Wrong FAILURE message if gpg-agent cannot be started: gnupg, Bug Report.
Dec 24 2015, 4:35 PM · Feature Request, gnupg
patrick set Version to 2.1.10 on T2204: Wrong FAILURE message if gpg-agent cannot be started.
Dec 24 2015, 4:35 PM · Feature Request, gnupg
gniibe added a comment to T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected.

I removed the not-working checkbkupkey subcommand in
44aee35e69540510617aea4b886ef845590960fe

Dec 24 2015, 3:58 AM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)
gniibe added a comment to T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected.

Also fixed the bkuptocard subcommand in: 40959add1ba0efc1f4aa87fa075fa42423eff73c

Dec 24 2015, 3:55 AM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)

Dec 23 2015

gniibe closed T2201: genkey1024.test fails as Resolved.
Dec 23 2015, 10:14 AM · Bug Report, gnupg
gniibe added a comment to T2201: genkey1024.test fails.

Fixed in aecf1a3c.

Dec 23 2015, 10:14 AM · Bug Report, gnupg

Dec 22 2015

neal set Version to 5c75992 on T2201: genkey1024.test fails.
Dec 22 2015, 3:21 PM · Bug Report, gnupg
neal added projects to T2201: genkey1024.test fails: gnupg, Bug Report.
Dec 22 2015, 3:21 PM · Bug Report, gnupg
gniibe added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Thank you again.

It is likely that the token itself doesn't work well after wakeup from sleep
mode. In this case, all that we can do is re-inserting the token manually.

I'm not sure how PC/SC service handles USB reset after wakeup.

Dec 22 2015, 8:43 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Dec 22 2015, 7:52 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Sorry to say, but mapping the error to "no reader" doesn't help. The first
reset event doesn't get handled. Later it trys to remove the reader but it's
not getting correctly resetted/reinserted again.

I've attached the debug log again

Dec 22 2015, 7:52 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
gniibe added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Thank you for further testing.
I think that current code doesn't handle the case when card goes inactive/reset
while reader keeps working. Current code only goes to the reset sequence for a
card again when it detects reader failure. So, although the concept is
different, I think mapping PSCS_W_CARD_RESET to SW_HOST_NO_READER (for now) will
work. Given the situation we don't yet support multiple cards, this workaround
would be OK for a while.

Dec 22 2015, 2:10 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Dec 22 2015, 12:35 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Nope. Neither mapping the "reset card" event to SW_HOST_CARD_INACTIVE or
SW_HOST_NO_CARD helps. It seems that somewhere in the code the return code
SW error codes are not being handled correctly and the card doesn't get
resetted.

I've attached a small log where you can see that pcsc returns the error
reason "reset card" which then gets remapped to "Card reset required" (was
general error before). I also can see that the error is getting mapped to
GPG_ERR_CARD_RESET (because of the error message "Card reset required")
leaving the daemon around with no working card and reporting general errors
again (0x100b).

Additional Info: This bug only happens when you put your computer/laptop
into sleep mode while the smartcard/reader (yubikey) is plugged in. If I
remove the reader before putting it to sleep and attaching it after getting
out of the sleep mode, the scdaemon works fine.

Dec 22 2015, 12:35 AM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report

Dec 21 2015

dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

D338: 740_0002-scd-map-card-reset-event.patch

Dec 21 2015, 11:29 PM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

Maybe it's more appropriate to map the PSCS_W_CARD_RESET event to the
SW_HOST_CARD_INACTIVE error code which later gets mapped to GPG_ERR_CARD_RESET
error code.

I've attached the patch file. It would make sense to backport this mapping as
well. Right now it's not yet tested.

Dec 21 2015, 11:29 PM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
dhoffend added a comment to T2167: Unplugging USB Smartcard/Yubikey causes problems with scdaemon.

I found another problem with the smartcard service under windows. Putting
the system into sleep mode and waking it up again creates an 0x80100068
error code (aka PCSC_W_RESET_CARD).

I'll test if it helps to map the RESET_CARD event to the same REMOVE_CARD
event to get the card reactivated after sleep mode.

Logfile:
2015-12-21 22:16:57 scdaemon[10040] DBG: send apdu: c=00 i=CA p1=00 p2=C4
lc=-1 le=256 em=0
2015-12-21 22:16:57 scdaemon[10040] DBG: PCSC_data: 00 CA 00 C4 00
2015-12-21 22:16:57 scdaemon[10040] pcsc_transmit failed: reset card
(0x80100068)
2015-12-21 22:16:57 scdaemon[10040] apdu_send_simple(0) failed: general
error

Dec 21 2015, 10:35 PM · gnupg (gpg22), Restricted Project, patch, Windows 64, scd, Windows, Windows 32, Bug Report
bhyde added a comment to T2200: redefinition of typedef ‘ctrl_t’.

I was using "gcc (GCC) 4.4.7 20120313 (Red Hat 4.4.7-11)", and then I
just updated to "gcc (GCC) 4.4.7 20120313 (Red Hat 4.4.7-16)". Sadly,
no change.

Dec 21 2015, 4:55 PM · gnupg, Bug Report
werner closed T1973: Wrong line endings when decrypting to console as Resolved.
Dec 21 2015, 4:17 PM · Windows 32, Windows, Bug Report, gnupg
werner added a comment to T1973: Wrong line endings when decrypting to console.

Okay, Feel free to re-open if you see it again.

Dec 21 2015, 4:17 PM · Windows 32, Windows, Bug Report, gnupg
werner removed a project from T1973: Wrong line endings when decrypting to console: Info Needed.
Dec 21 2015, 4:17 PM · Windows 32, Windows, Bug Report, gnupg
werner added a project to T2200: redefinition of typedef ‘ctrl_t’: gnupg.
Dec 21 2015, 11:44 AM · gnupg, Bug Report
gniibe removed a project from T1962: gnupg 1.4.x adds unknown ECC subkeys repeatedly.: In Progress.
Dec 21 2015, 6:50 AM · Bug Report, gnupg
gniibe added a comment to T1962: gnupg 1.4.x adds unknown ECC subkeys repeatedly..

Fixed in 1.4.20 (and 2.0.28).

Dec 21 2015, 6:50 AM · Bug Report, gnupg
gniibe closed T1962: gnupg 1.4.x adds unknown ECC subkeys repeatedly. as Resolved.
Dec 21 2015, 6:50 AM · Bug Report, gnupg

Dec 19 2015

kristianf added a comment to T2197: --disable-tofu seems to also disable gnutls.

Thanks, I can confirm that this solves it.

Dec 19 2015, 11:40 AM · Bug Report, gnupg
kristianf closed T2197: --disable-tofu seems to also disable gnutls as Resolved.
Dec 19 2015, 11:40 AM · Bug Report, gnupg
kristianf removed a project from T2197: --disable-tofu seems to also disable gnutls: Restricted Project.
Dec 19 2015, 11:40 AM · Bug Report, gnupg

Dec 18 2015

werner closed T2164: Use pool.sks-keyservers.net directly as default in dirmngr.conf-skel (instead of the CNAME) as Resolved.
Dec 18 2015, 5:24 PM · Won't Fix, gnupg, Feature Request
werner added a project to T2164: Use pool.sks-keyservers.net directly as default in dirmngr.conf-skel (instead of the CNAME): Won't Fix.
Dec 18 2015, 5:24 PM · Won't Fix, gnupg, Feature Request
werner added a comment to T2106: Support SHA-256 fingerprints for ssh.

That fingerprint looks more like gibberish than something which should be
compared by the user. In that regard a SHA-1 fingerprint looks much more
serious and IMHO will be more secure than a base-64 fingerprint where you have
to explain that the users also need to match the case - if they are at all able
to compare that fingerprint.

We should take this to the mailing list.

Dec 18 2015, 5:20 PM · gnupg (gpg22), gnupg, ssh, Feature Request
werner set Version to 2.1.10 on T2197: --disable-tofu seems to also disable gnutls.
Dec 18 2015, 5:16 PM · Bug Report, gnupg
werner added a comment to T2197: --disable-tofu seems to also disable gnutls.

Fixed with commit af14285

Dec 18 2015, 5:16 PM · Bug Report, gnupg
werner added a project to T2197: --disable-tofu seems to also disable gnutls: Restricted Project.
Dec 18 2015, 5:16 PM · Bug Report, gnupg
werner claimed T2197: --disable-tofu seems to also disable gnutls.
Dec 18 2015, 5:04 PM · Bug Report, gnupg
werner added a comment to T2197: --disable-tofu seems to also disable gnutls.

pkg-config weirdness.

Dec 18 2015, 5:04 PM · Bug Report, gnupg
gniibe added a comment to T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected.

Fixed in
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=b30c15bf7c5336c4abb1f9dcd974cd77ba6c61a7

Dec 18 2015, 2:52 AM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)
gniibe added a project to T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected: Restricted Project.
Dec 18 2015, 2:52 AM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)

Dec 17 2015

werner added a comment to T1832: gpg --send-keys fails silently if keyserver unavailable.

backported by dkg with commit 0c3d764 for 1.4.19

Dec 17 2015, 3:48 PM · gnupg (gpg14), backport, Bug Report, gnupg
werner removed a project from T1832: gpg --send-keys fails silently if keyserver unavailable: In Progress.
Dec 17 2015, 3:48 PM · gnupg (gpg14), backport, Bug Report, gnupg
werner closed T1832: gpg --send-keys fails silently if keyserver unavailable as Resolved.
Dec 17 2015, 3:48 PM · gnupg (gpg14), backport, Bug Report, gnupg
gniibe added a comment to T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected.

I'm considering fixing this.

Dec 17 2015, 1:13 PM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)
gniibe claimed T2169: Smartcard card-edit generate fails when off-card backup of encryption key is selected.
Dec 17 2015, 1:13 PM · gnupg24, gnupg26, Bug Report, gpgagent, gnupg (gpg21)

Dec 16 2015

aheinecke closed T2191: Only encrypt does not work if S/MIME support is disabled as Resolved.
Dec 16 2015, 5:32 PM · Bug Report, gnupg, gpgol
aheinecke added a comment to T2191: Only encrypt does not work if S/MIME support is disabled.

Fixed with rev. b879f5b

Dec 16 2015, 5:32 PM · Bug Report, gnupg, gpgol
neal added a comment to T2186: --encrypt-to ambiguous with a expired and revoked key.

I've implemented this in fc010b6. If you get a chance to test it, I'd
appreciate any feedback! Thanks!

Dec 16 2015, 2:45 PM · gnupg24, Feature Request
neal added a project to T2186: --encrypt-to ambiguous with a expired and revoked key: Restricted Project.
Dec 16 2015, 2:45 PM · gnupg24, Feature Request
neal added a comment to T2198: --encrypt-to finds bogus ambiguity.

This is a bug and was fixed in 2e4e10c1. As you correctly observe, it only
impacts fingerprints and thus your workaround is good. Sorry about that!

Dec 16 2015, 1:07 PM · Bug Report, gnupg
neal closed T2198: --encrypt-to finds bogus ambiguity as Resolved.
Dec 16 2015, 1:07 PM · Bug Report, gnupg
neal added a comment to T2195: keyring: cache consistency problem.

To do writes, we use a copy-update-move scheme. Thus, all updates are atomic.
A read fopen()s the keyring or keybox, seeks and reads. If an update occurs
between the seek and read, the reader will see the old version: fopen is
associated with the inode, not the filename:

  reader                writer
  -------               -------
  fopen("keyring.pub")
  seek(fp)
                         cp("keyring.pub", "keyring.pub~")
                         update("keyring.pub~")
                         mv("keyring.pub~", "keyring.pub")
  read(fp)

Thus, writers don't interfere with readers.

We need to lock the underlying file for updates to avoid the case in which two
updates occur nearly simultaneously, but only one is saved. (Also, since the
updates occur in keyring.pub~, we need to ensure exclusive access to that file.)

  writer1                           writer2
  -------                           -------
  cp("keyring.pub", "keyring.pub~")
  update("keyring.pub~")
                                    cp("keyring.pub", "keyring.pub~")
                                    update("keyring.pub~")
  mv("keyring.pub~", "keyring.pub")
                                    mv("keyring.pub~", "keyring.pub")

In the above case, writer1's update is lost. (Note: it could be worse: if both
update keyring.pub~ simultaneously, there could be corruption.)

The bug that I'm describing below only has to do with the key present cache,
which becomes inconsistent, because we don't track external writes.

Dec 16 2015, 10:49 AM · Bug Report, gnupg
gniibe added a comment to T2106: Support SHA-256 fingerprints for ssh.

It is base64 trimmed the last '='.

Introducing new specifier, say %f, would be good, while keeping %F as is.
%f includes the hash algorithm string as SSH does.

Dec 16 2015, 2:45 AM · gnupg (gpg22), gnupg, ssh, Feature Request
gniibe added a comment to T2195: keyring: cache consistency problem.

I think that current lock/unlock mechanism is only for mutual exclusion between
multiple writers. I mean, lock/unlock is done to avoid inconsistency caused by
multiple writers.

It seems that we forget to implement mutual exclusion between writers and
readers, as Neal described.

Before 2.1.10, the write access was limited to specific interactive usage
patterns and it didn't cause major problems (it caused rarely if happened).
Now, I think that we should implement mutual exclusion between readers and writers.

Dec 16 2015, 1:45 AM · Bug Report, gnupg
nrickert added projects to T2198: --encrypt-to finds bogus ambiguity: gnupg, Bug Report.
Dec 16 2015, 12:21 AM · Bug Report, gnupg

Dec 15 2015

neal added a project to T2197: --disable-tofu seems to also disable gnutls: gnupg.
Dec 15 2015, 10:30 PM · Bug Report, gnupg
neal added a project to T2164: Use pool.sks-keyservers.net directly as default in dirmngr.conf-skel (instead of the CNAME): gnupg.
Dec 15 2015, 9:54 PM · Won't Fix, gnupg, Feature Request
neal added projects to T2196: keydb locking can result in deadlock in 2.2: gnupg, Bug Report.
Dec 15 2015, 8:14 PM · gnupg22 (gnupg-2.2.52), Bug Report
neal added a comment to T2193: keyring / keybox race.

D342: 738_0001-gpg-Fix-TOCTTOU-when-updating-keyblocks.patch

Dec 15 2015, 8:08 PM · Bug Report, gnupg
neal added a comment to T2193: keyring / keybox race.

I've attached a fix that does a very small and straightforward modification to
keydb_update_keyblock, which fixes this problem for both the keyring and keybox.

Dec 15 2015, 8:08 PM · Bug Report, gnupg
guilhem removed a project from T2176: --default-key and --local-user stopped working with gpg 2.1.10 and offline master keys: Restricted Project.
Dec 15 2015, 4:00 PM · gnupg, Bug Report
guilhem closed T2176: --default-key and --local-user stopped working with gpg 2.1.10 and offline master keys as Resolved.
Dec 15 2015, 4:00 PM · gnupg, Bug Report
guilhem set Version to 2.1.10 on T2176: --default-key and --local-user stopped working with gpg 2.1.10 and offline master keys.
Dec 15 2015, 4:00 PM · gnupg, Bug Report
guilhem added a comment to T2176: --default-key and --local-user stopped working with gpg 2.1.10 and offline master keys.

I confirm that I'm not able to reproduce T2176 (guilhem on Dec 11 2015, 02:21 PM / Roundup) nor T2176 (guilhem on Dec 11 2015, 01:07 PM / Roundup) with 4ffe44c, so
I'm changing the issue to “resolved”. Thanks for the prompt action!

Dec 15 2015, 4:00 PM · gnupg, Bug Report
neal added a comment to T2193: keyring / keybox race.

My proposed solution is to change keydb_update_keyblock. We don't actually need
to touch the keybox or keyring code.

By the new behavior, I guess you mean getting an error when deleting a key, but
it fails because another process already deleted it. If something like this
were to current occur, then we'd end up with silent corruption. So, it's not
clear how this new behavior would introduce new behavior that could raise problems.

Dec 15 2015, 1:50 PM · Bug Report, gnupg
werner added a comment to T2193: keyring / keybox race.

atomicly here mean that the update/insert functions locate an possibly existing
key using the fingerprint while holding the lock.

Anyway, to really fix that we need a daemon taking control of all keys - a task
for 2.3,

Dec 15 2015, 12:47 PM · Bug Report, gnupg
werner added a comment to T2193: keyring / keybox race.

I was aware of that problem but always wondered why I never noticed such a case.
Your analysis is correct and explains the problem. The locking of the keyblock
does not help here (it was introduced only a few years ago).

Instead of making use of found.offset and fix that with your suggested trick we
should not use the offset at all but let the update and insert functions handle
it atomicly - this may result in an insert/update error (e.g. if another process
inserted/deleted the key) but that is an expected outcome if two processes
manipulate the same key.

This should not be fixed for the old keyring format but only for the keybox format:

  1. The keyring format is deprecated
  2. This introduces a new behaviour and may raise other problems.

If you want to fix that, please do that in a new branch.

Dec 15 2015, 12:44 PM · Bug Report, gnupg
neal added a comment to T2187: gpg2 --gen-revoke 0x${FINGERPRINT} produces infinite output stream.

This should be fixed in 2e4e10c. Please let me know if it works for you (and
feel free to mark this bug as resolved if it does).

Dec 15 2015, 12:22 PM · Bug Report, gnupg
neal added a project to T2187: gpg2 --gen-revoke 0x${FINGERPRINT} produces infinite output stream: Restricted Project.
Dec 15 2015, 12:22 PM · Bug Report, gnupg
neal added a project to T2176: --default-key and --local-user stopped working with gpg 2.1.10 and offline master keys: gnupg.
Dec 15 2015, 11:17 AM · gnupg, Bug Report
neal added projects to T2195: keyring: cache consistency problem: gnupg, Bug Report.
Dec 15 2015, 11:10 AM · Bug Report, gnupg
neal added projects to T2194: keyring: cache consistency problem: gnupg, Bug Report.
Dec 15 2015, 11:03 AM · Bug Report, gnupg
neal added a comment to T2187: gpg2 --gen-revoke 0x${FINGERPRINT} produces infinite output stream.

I found the bug. I'll try to create a patch soon. Thanks for reporting this.

Dec 15 2015, 10:51 AM · Bug Report, gnupg
neal added a comment to T2186: --encrypt-to ambiguous with a expired and revoked key.

This is a good suggestion. Thanks.

Dec 15 2015, 9:01 AM · gnupg24, Feature Request
neal added a comment to T2187: gpg2 --gen-revoke 0x${FINGERPRINT} produces infinite output stream.

Just to be clear: you tested with, say, a long key id, and the output was fine?
In other words, the problem only occurs when specifying a fingerprint?

Dec 15 2015, 8:19 AM · Bug Report, gnupg
gniibe added a project to T1686: GPG Smartcard daemons not detecting card change Windows 8.1: Restricted Project.
Dec 15 2015, 5:23 AM · gnupg, Windows 32, gnupg (gpg20), Windows, Bug Report
gniibe added a comment to T1686: GPG Smartcard daemons not detecting card change Windows 8.1.

I think that this was fixed in:
http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=d1a97585c5e73fbc7d4cf90e38f76ffc5aea305f

It will be in 2.1.11 and 2.0.30.

Dec 15 2015, 5:23 AM · gnupg, Windows 32, gnupg (gpg20), Windows, Bug Report
gniibe closed T1081: scd: "card error" after usb reader plug/unplug cycle, needs hard restart as Resolved.
Dec 15 2015, 5:15 AM · gnupg, gpg4win, scd, Feature Request
gniibe added a comment to T1081: scd: "card error" after usb reader plug/unplug cycle, needs hard restart.

I confirmed that this is fixed in 2.0 and 2.1.

Dec 15 2015, 5:15 AM · gnupg, gpg4win, scd, Feature Request
gniibe added a project to T2154: encrypt_dek ignores gcry_pk_encrypt return value: In Progress.
Dec 15 2015, 4:43 AM · In Progress, Bug Report, gnupg
gniibe claimed T2154: encrypt_dek ignores gcry_pk_encrypt return value.
Dec 15 2015, 4:43 AM · In Progress, Bug Report, gnupg
gniibe added a comment to T2154: encrypt_dek ignores gcry_pk_encrypt return value.

Thank you. There is no reason. It is fixed in:

http://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=commit;h=4ee881bff4c8fdfa4b3b7a4b7afab611471e97f1

Dec 15 2015, 4:43 AM · In Progress, Bug Report, gnupg
gniibe claimed T2153: agent_pksign_do ignores do_encode_raw_pkcs1 do_encode_md return values.
Dec 15 2015, 4:36 AM · Bug Report, gnupg
gniibe added a comment to T2153: agent_pksign_do ignores do_encode_raw_pkcs1 do_encode_md return values.

Thank you for your audit.

It ignores the calculated value if it detects failure of gcry_pk_verify.
This is now a kind of standard practice to avoid possible attacks.

Here is a reference:
https://securityblog.redhat.com/2015/09/02/factoring-rsa-keys-with-tls-perfect-forward-secrecy/

Dec 15 2015, 4:36 AM · Bug Report, gnupg
gniibe added a comment to T2150: Generating keys on OpenPGP card yields wrong public key.

For my case with OpenPGPcard, the patch fixed the problem of wrong fingerprint
computation. Please test with the patch.

Dec 15 2015, 1:11 AM · Bug Report, gnupg, gnupg (gpg21)
gniibe added a comment to T2150: Generating keys on OpenPGP card yields wrong public key.

Sorry for my mistake for reading your post. I considered it would be the case
for m, but I also fixed the case for e, the exponent.
Here, I reproduce the problem with OpenPGPcard (while it only occurs 1/256 with
Gnuk Token).
I confirmed that original OpenPGPcard returns e as four bytes 00 01 00 01 with
0x00 in front. This causes 100% failure for fingerprint computation.
I'm going to test the patch with OpenPGPcard. (I'm now installing newer
libgpg-error, to build master of GnuPG.)

Dec 15 2015, 12:47 AM · Bug Report, gnupg, gnupg (gpg21)

Dec 14 2015

neal added a comment to T2193: keyring / keybox race.

Note the corruption that occurs is rather subtle. It occurs silently, because
copy_some_packets doesn't throw an error if the next packet to process doesn't
start on STOPOFF, but continues until the offset of the next packet to process
is at *or exceeds* STOPOFF.

Imagine that we have a keyblock A at offset 0 and a second keyblock B at offset
100 with 2 packets:

  • A
  • B
  • The first gpg process does a search for the key at offset 100
  • A second process looks up and updates the key block (A') at offset 0 such

that it now has a length of 150 and 4 packets after offset 100.

  1. The initial process "updates" B to B'. hd->found.offset now point into the

middle of A'. In keyring.c:do_copy, the first 100 bytes plus any bytes required
to complete the last packet are copied (by copy_some_packets). The next 2
packets are deleted (skip_some_packets) and the new keyblock is inserted. We
now have the following:

  • 100+ bytes of A'
  • B'
  • Last two packets of A'
  • B

And B appears to be duplicated.

Dec 14 2015, 9:30 PM · Bug Report, gnupg
neal added a comment to T2193: keyring / keybox race.

Note: there is also a TOCTTOU bug for keydb_search / keydb_get_keyblock.

Dec 14 2015, 9:13 PM · Bug Report, gnupg
neal updated subscribers of T2193: keyring / keybox race.
Dec 14 2015, 9:07 PM · Bug Report, gnupg
neal added projects to T2193: keyring / keybox race: gnupg, Bug Report.
Dec 14 2015, 9:07 PM · Bug Report, gnupg
gp_ast added a comment to T1973: Wrong line endings when decrypting to console.

Hi Neal, I am not able to reproduce the issue with GnuPG 2.1.10 anymore.

Dec 14 2015, 6:30 PM · Windows 32, Windows, Bug Report, gnupg
boehmtho added a comment to T1624: Gpgtar fails when files have non ASCII characters.

Hello Andre,

Dec 14 2015, 2:11 PM · gnupg, Windows 32, Windows, Bug Report
aheinecke added projects to T2191: Only encrypt does not work if S/MIME support is disabled: gpgol, gnupg, Bug Report.
Dec 14 2015, 12:53 PM · Bug Report, gnupg, gpgol
aheinecke changed Version from 2.0.29 to 2.1.10 on T2135: Keyring locking on Windows broken.
Dec 14 2015, 12:27 PM · Bug Report, gpg4win, Windows, gnupg, Windows 32
aheinecke reassigned T2135: Keyring locking on Windows broken from aheinecke to werner.
Dec 14 2015, 12:27 PM · Bug Report, gpg4win, Windows, gnupg, Windows 32