Page MenuHome GnuPG
Feed Advanced Search

May 6 2016

neal added a comment to T2193: keyring / keybox race.

Patch applied in dc417bf0c555a7416d0aedde6645fd1087660f92 (Dec 15, 2015)

May 6 2016, 8:56 PM · Bug Report, gnupg
werner added a project to T2186: --encrypt-to ambiguous with a expired and revoked key: Stalled.
May 6 2016, 8:31 PM · gnupg24, Feature Request
werner removed a project from T2186: --encrypt-to ambiguous with a expired and revoked key: Restricted Project.
May 6 2016, 8:31 PM · gnupg24, Feature Request
werner added a comment to T2186: --encrypt-to ambiguous with a expired and revoked key.

iirc, we removed the patch from 2.1 due to some problems. We plan to work on it
in 2.3.

May 6 2016, 8:31 PM · gnupg24, Feature Request
werner added a comment to T2193: keyring / keybox race.

Neal, what is the status of this bug?

May 6 2016, 8:29 PM · Bug Report, gnupg
werner assigned T2193: keyring / keybox race to neal.
May 6 2016, 8:29 PM · Bug Report, gnupg
werner removed a project from T1060: extract signature from encrypted and signed file/message: Restricted Project.
May 6 2016, 8:28 PM · gnupg (gpg21), gnupg, Debian, Feature Request
werner closed T1060: extract signature from encrypted and signed file/message as Resolved.
May 6 2016, 8:28 PM · gnupg (gpg21), gnupg, Debian, Feature Request
werner added a comment to T2071: Processes invoking gpgme_op_decrypt() should not incur a delay due to the invocation of gpg-agent.

We still need to check whether has been fixed for 1.4 and 2.0.

May 6 2016, 8:27 PM · Restricted Project, gnupg, Bug Report
werner closed T2147: auto-key-retrieve does not work if keyserver is set in dirmngr.conf instead of gpg.conf as Resolved.
May 6 2016, 8:24 PM · gnupg, Bug Report
werner removed a project from T2147: auto-key-retrieve does not work if keyserver is set in dirmngr.conf instead of gpg.conf: Restricted Project.
May 6 2016, 8:24 PM · gnupg, Bug Report
werner closed T2181: ship sks-keyservers.netCA.pem in distributed tarball as Resolved.
May 6 2016, 8:24 PM · gnupg, Bug Report, dirmngr
werner removed a project from T2181: ship sks-keyservers.netCA.pem in distributed tarball: Restricted Project.
May 6 2016, 8:24 PM · gnupg, Bug Report, dirmngr
werner added a project to T2348: Improve detection of IPv6 and IPv4 availibility: dirmngr.
May 6 2016, 8:23 PM · gnupg, Feature Request, dirmngr
werner updated subscribers of T2348: Improve detection of IPv6 and IPv4 availibility.
May 6 2016, 8:23 PM · gnupg, Feature Request, dirmngr
werner added a comment to T2107: dirmngr crash when searching keyservers on OpenBSD.

Duplicate of T2348

May 6 2016, 8:23 PM · Duplicate, gnupg, Bug Report, dirmngr
werner removed a project from T2107: dirmngr crash when searching keyservers on OpenBSD: Restricted Project.
May 6 2016, 8:23 PM · Duplicate, gnupg, Bug Report, dirmngr
werner added a project to T2107: dirmngr crash when searching keyservers on OpenBSD: Duplicate.
May 6 2016, 8:23 PM · Duplicate, gnupg, Bug Report, dirmngr
werner closed T2107: dirmngr crash when searching keyservers on OpenBSD as Resolved.
May 6 2016, 8:23 PM · Duplicate, gnupg, Bug Report, dirmngr
werner added projects to T2348: Improve detection of IPv6 and IPv4 availibility: Feature Request, gnupg.
May 6 2016, 8:22 PM · gnupg, Feature Request, dirmngr
werner added a comment to T2246: Regression: home dir no longer automatically created.

For which branches has this been fixed?
Do we have releases for all of them?

May 6 2016, 8:20 PM · Bug Report, gnupg
werner added a comment to T2236: Importing a key with badly ordered packets doesn't reorder it, and while --edit-key does reorder it doesn't move the signature packets to the right place.

2.1.12 does a verbose check and fix during --edit-key. We will eventually call
that reorder function during import. But let's wait for bug reports with the
--edit-key triggered code.

May 6 2016, 8:18 PM · gnupg (gpg22), Bug Report
werner added a comment to T2275: Corrupted keybox if created by gpgsm.

Fixed in 2.1.12

May 6 2016, 8:16 PM · Bug Report, gnupg, gnupg (gpg21)
werner removed a project from T2275: Corrupted keybox if created by gpgsm: Restricted Project.
May 6 2016, 8:16 PM · Bug Report, gnupg, gnupg (gpg21)
werner closed T2275: Corrupted keybox if created by gpgsm as Resolved.
May 6 2016, 8:16 PM · Bug Report, gnupg, gnupg (gpg21)
werner added a comment to T2294: missing key for symbolic link tofu.d/email/*/file.db lead to segfaul.

closing due to the release of 2.1.12.

May 6 2016, 8:15 PM · gnupg, Bug Report
werner removed a project from T2294: missing key for symbolic link tofu.d/email/*/file.db lead to segfaul: Restricted Project.
May 6 2016, 8:15 PM · gnupg, Bug Report
werner closed T2294: missing key for symbolic link tofu.d/email/*/file.db lead to segfaul as Resolved.
May 6 2016, 8:15 PM · gnupg, Bug Report
werner removed a project from T2288: --quiet option produces logging output: Restricted Project.
May 6 2016, 8:14 PM · Bug Report, gnupg, gnupg (gpg21)
werner closed T2288: --quiet option produces logging output as Resolved.
May 6 2016, 8:14 PM · Bug Report, gnupg, gnupg (gpg21)
werner removed a project from T2315: No reliable way to select a uid for --quick-sign-key: Restricted Project.
May 6 2016, 8:14 PM · gnupg, Bug Report
werner closed T2315: No reliable way to select a uid for --quick-sign-key as Resolved.
May 6 2016, 8:14 PM · gnupg, Bug Report
werner added a comment to T2315: No reliable way to select a uid for --quick-sign-key.

Fixed in 2.1.12

May 6 2016, 8:14 PM · gnupg, Bug Report
werner lowered the priority of T2346: Invalid import result in gnupg 2.1 when importing secret keys from Normal to Low.
May 6 2016, 8:09 PM · Bug Report, gnupg, gnupg (gpg21)
gniibe removed a project from T2095: Stop installing gpg-zip(1): In Progress.
May 6 2016, 6:04 AM · Documentation, Bug Report, gnupg
gniibe closed T2095: Stop installing gpg-zip(1) as Resolved.
May 6 2016, 6:04 AM · Documentation, Bug Report, gnupg

May 4 2016

werner removed a project from T2134: iconv.dll is still a problem: Restricted Project.
May 4 2016, 5:26 PM · Feature Request, gnupg
werner closed T2134: iconv.dll is still a problem as Resolved.
May 4 2016, 5:26 PM · Feature Request, gnupg
werner added a comment to T2134: iconv.dll is still a problem.

Should be solved now: Use Libgpg-error 1.22 and GnuPG 2.1.12.

May 4 2016, 5:26 PM · Feature Request, gnupg
aheinecke set Version to master on T2346: Invalid import result in gnupg 2.1 when importing secret keys.
May 4 2016, 10:28 AM · Bug Report, gnupg, gnupg (gpg21)
aheinecke added projects to T2346: Invalid import result in gnupg 2.1 when importing secret keys: gnupg (gpg21), gnupg, Bug Report.
May 4 2016, 10:28 AM · Bug Report, gnupg, gnupg (gpg21)
aheinecke added a comment to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.

Thanks for the clarification. I'll ignore it in QGpgME then, too.

And after grepping for KEYEXPIRED in doc I have now found the DETAILS
documentation of which I was unaware until now. :-)

May 4 2016, 9:38 AM · Bug Report, gnupg, KDE
aheinecke closed T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired as Resolved.
May 4 2016, 9:38 AM · Bug Report, gnupg, KDE
werner added a comment to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.

This is documented behaviour; see below. GPA ignores this status line.

  • KEYEXPIRED <expire-timestamp> The key has expired. expire-timestamp is the expiration time in seconds since Epoch. This status line is not very useful because it will also be emitted for expired subkeys even if this subkey is not used. To check whether a key used to sign a message has expired, the EXPKEYSIG status line is to be used. Note, that the TIMESTAMP may either be a number of seconds since Epoch or an ISO 8601 string which can be detected by the presence of the letter 'T'.
May 4 2016, 9:31 AM · Bug Report, gnupg, KDE

May 2 2016

gniibe added a comment to T2306: Rare smartcard errors with gnupg master.

Another problem has been fixed in 6677d8b.
I intentionally set up more hubs from computer to the device to cause an error.
When an error occurred, scdaemon continued to report "Card error", even after I
inserted the device directly to the computer.
Now, it returns "No such device" for severe errors, and scdaemon can recover
from such errors.

May 2 2016, 9:04 AM · Bug Report, gnupg, scd

Apr 29 2016

aheinecke added a comment to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.

D366: 825_fix-in-gpgmepp.patch

Apr 29 2016, 6:45 PM · Bug Report, gnupg, KDE
aheinecke added a comment to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.

Note to self.

The problem is that editinteractor in edit_interactor_callback_impl checks
status_to_error before the GpgSignKeyEditInteractor::nextState implementation
has the chance to ignore that status with needsNoResponse.

A fix in GpgMEpp could be to ignore the error if the state machine was not
started. E.g. we have not yet send any command.

Attached patch fixes the problem. But I'm not sure that this does not cause
regressions e.g. when trying to add a uid to an expired key or trying to
actually sign expired uid's. :-/

Apr 29 2016, 6:45 PM · Bug Report, gnupg, KDE
aheinecke added projects to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired: KDE, gnupg, Bug Report.
Apr 29 2016, 4:48 PM · Bug Report, gnupg, KDE
aheinecke set External Link to https://bugs.kde.org/show_bug.cgi?id=358392 on T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.
Apr 29 2016, 4:48 PM · Bug Report, gnupg, KDE
aheinecke added a comment to T2339: Edit-key with-colons reports KEYEXPIRED on status-fd if one subkey (or selfsig?) is expired.

Apr 29 2016, 4:48 PM · Bug Report, gnupg, KDE

Apr 28 2016

gniibe added a comment to T2306: Rare smartcard errors with gnupg master.

The particular problem of T2306 (aheinecke on Apr 25 2016, 06:53 PM / Roundup) has been fixed in cb4fee8.

I think that it was not always reproducible because it depends on timing (only
when it detected an error at bulk_in, the problem happened). I'm not sure if
the difference of old/new libusb mattered for this problem.

Apr 28 2016, 5:53 AM · Bug Report, gnupg, scd
gniibe added a project to T2306: Rare smartcard errors with gnupg master: Restricted Project.
Apr 28 2016, 5:53 AM · Bug Report, gnupg, scd

Apr 27 2016

werner added a comment to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.

Those libraries are not GnuPG specific.

Apr 27 2016, 12:05 PM · Bug Report, gnupg

Apr 26 2016

martin_vahi added a comment to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.

Thank You. I noticed later that, indeed, at the first instance,
there's a problem with the library, but I corrected that issue
with the other try, the one that is described at

https://bugs.gnupg.org/gnupg/file821/2016_04_gnupg_v_2_1_11_build_log.txt

---citation--start----
gcc -DHAVE_CONFIG_H -I. -I.. -I../common -
DLOCALEDIR=\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04/gnup
g/share/locale\" -
DGNUPG_BINDIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04/
gnupg/bin\"" -
DGNUPG_LIBEXECDIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016
_04/gnupg/lib\"" -
DGNUPG_LIBDIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04/
gnupg/lib64/gnupg\"" -
DGNUPG_DATADIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04
/gnupg/share/gnupg\"" -
DGNUPG_SYSCONFDIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016
_04/gnupg/etc/gnupg\"" -
DGNUPG_LOCALSTATEDIR="\"/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2
016_04/gnupg/var\"" -
I/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04/libgcrypt/includ
e -
I/home/ts2/m_local/bin_p_originaalid/GNU_Privacy_Guard/v2016_04/libksba/include
-Wall -Wno-pointer-sign -Wpointer-arith -mtune=native -ftree-vectorize -MT
libkeybox_a-keybox-util.o -MD -MP -MF .deps/libkeybox_a-keybox-util.Tpo -c -o
libkeybox_a-keybox-util.o test -f 'keybox-util.c' || echo './'keybox-util.c
In file included from keybox-defs.h:42:0,

from keybox-util.c:29:

../common/stringhelp.h: In function ‘make_filename’:
../common/stringhelp.h:55:52: error: expected declaration specifiers before â
€˜GPGRT_ATTR_SENTINEL’
char *make_filename( const char *first_part, ... ) GPGRT_ATTR_SENTINEL(0);

^

---citation--end------

Besides, given the small size of the GnuPG, shouldn't the
few GnuPG specific libraries just be subfolders of the
GnuPG project? If not in the repository, then at least
at the release tar-ball? It would avoid the
"library wrongly installed" part.

Apr 26 2016, 12:55 PM · Bug Report, gnupg
werner added a comment to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.

libksba has not been installed properly.

Apr 26 2016, 11:40 AM · Bug Report, gnupg

Apr 25 2016

aheinecke added a comment to T2306: Rare smartcard errors with gnupg master.

I can make "a" problem (not sure if it is "the" problem) reproducible with the
following command (as root):

AUTHFILE="/sys/bus/usb/devices/4-1.2/authorized" ; echo 0 > "$AUTHFILE" ; sleep
1 ; echo 1 > "$AUTHFILE"

This was based on:
http://askubuntu.com/questions/645/how-do-you-reset-a-usb-device-from-the-command-line/61165#61165

where 4-1.2 is the id of my reader. The error message in scdaemon log is
slightly different but the behavior is the same. It's in an error state until I
kill it.

Apr 25 2016, 6:53 PM · Bug Report, gnupg, scd

Apr 23 2016

martin_vahi added a comment to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.

Apr 23 2016, 1:04 PM · Bug Report, gnupg
martin_vahi added a comment to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.

I'm not sure, if it is relevant, but
I tried to build the newer version, the v2.1.11, id est the "GnuPG Modern"
and it did not go so well either, despite the fact that
I custom-built the dependent libraries and put their bin folders to
PATH and lib64 folders LD_LIBRARY_PATH prior to attempting
to build the gnupg.

Apr 23 2016, 1:04 PM · Bug Report, gnupg
martin_vahi added projects to T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux: gnupg, Bug Report.
Apr 23 2016, 11:14 AM · Bug Report, gnupg
martin_vahi set Version to 2.0.30 on T2333: gnupg-2.0.30 (2016-03-31 Stable) Fails to Compile on openSUSE Linux.
Apr 23 2016, 11:14 AM · Bug Report, gnupg

Apr 22 2016

dkg added a comment to T2331: gpg-preset-passphrase fails to work with gpg1.

Thanks for the explanation, Werner.

This note might also be worth adding to the gpg-preset-passphrase manpage.

Apr 22 2016, 3:51 PM · Bug Report, gnupg
werner added a comment to T2331: gpg-preset-passphrase fails to work with gpg1.

gpg1 does not known about keygrips. Instead of the keygrip, gpg1 uses the
fingerprint as cacheid for gpg-agent. The agent's command GET_PASSPHRAE, as
used by gpg1, uses a different cache mode from what gpg-preset-passphrases uses.
Thus even if you replace the keygrip with the fingerprint of the (sub)key, it
won't work.

I'll add

Note, that the tool @command{gpg-preset-passphrase}, which comes
with GnuPG-2, cannot be used to preset a passphrase for this
version of GnuPG.

to the gpg 1 man page.

Apr 22 2016, 9:57 AM · Bug Report, gnupg
dkg set Version to 1.4.20 on T2331: gpg-preset-passphrase fails to work with gpg1.
Apr 22 2016, 7:34 AM · Bug Report, gnupg
dkg added projects to T2331: gpg-preset-passphrase fails to work with gpg1: gnupg, Bug Report.
Apr 22 2016, 7:34 AM · Bug Report, gnupg
gniibe added a comment to T2306: Rare smartcard errors with gnupg master.

I'm reading the implementation of new libusb.
If I guess correctly, the picture of the problem would be:

  • New libusb somehow caches (or uses cache of kernel's) USB device list structures.
  • When the device is plugged off/on (or hardware failures), the cache should be

updated.

  • GnuPG's ccid-driver possibly keeps using staled data of USB device list.

I'll check the implementation detail, and try fixing this.
I think that current ccid-driver with new libusb has an issue for memory leaks
for device list, so, it should be reviewed and modified anyway.

It would be good if we could have a reproducible scenario.

Apr 22 2016, 1:53 AM · Bug Report, gnupg, scd

Apr 21 2016

werner added a comment to T2134: iconv.dll is still a problem.

I have implemented iconv in libgpg-error master (commit 1cd1ddb). This is a
stripped down version of win-iconv where I removed the feature to load another
libiconv and disabled the mlang.dll (whatever this is) for now.

With gnupg master commit bd4d656 tehre is no more need for libiconv for Windows.

Apr 21 2016, 9:58 AM · Feature Request, gnupg
werner added a project to T2134: iconv.dll is still a problem: Restricted Project.
Apr 21 2016, 9:58 AM · Feature Request, gnupg

Apr 20 2016

werner claimed T2134: iconv.dll is still a problem.
Apr 20 2016, 4:28 PM · Feature Request, gnupg
werner added a comment to T2070: Can not leave passphrase empty when exporting secret key.

I already sent Justsus some code I started with to restore that feature.

Apr 20 2016, 3:59 PM · Duplicate, Bug Report, gnupg
justus added a comment to T2312: GnuPG 2.1 migration fails due to permissions but appears to succeed.

Fixed in f8adf1a.

Apr 20 2016, 3:05 PM · gnupg, Bug Report
justus closed T2312: GnuPG 2.1 migration fails due to permissions but appears to succeed as Resolved.
Apr 20 2016, 3:05 PM · gnupg, Bug Report
dkg added a comment to T2070: Can not leave passphrase empty when exporting secret key.

Thanks for looking into this, Justus.

While you're working on this, it might make sense to consider restoration of the
--export-options export-reset-subkey-passwd flag, which was dropped in 2.1.

This flag was used by at least one GnuPG downstream (monkeysphere); its absence
causes "monkeysphere subkey-to-ssh-agent" to fail.

In GnuPG 1.4.x and 2.0.x, the option was defined this way:

export-reset-subkey-passwd
       When  using  the  --export-secret-subkeys  command,  this
       option resets the passphrases for all exported subkeys to
       empty. This is useful when the exported subkey is  to  be
       used  on an unattended machine where a passphrase doesn't
       necessarily make sense. Defaults to no.
Apr 20 2016, 2:58 PM · Duplicate, Bug Report, gnupg
justus claimed T2312: GnuPG 2.1 migration fails due to permissions but appears to succeed.
Apr 20 2016, 11:39 AM · gnupg, Bug Report
justus claimed T2070: Can not leave passphrase empty when exporting secret key.
Apr 20 2016, 11:13 AM · Duplicate, Bug Report, gnupg
justus added a comment to T2070: Can not leave passphrase empty when exporting secret key.

Related T2324.

Apr 20 2016, 11:13 AM · Duplicate, Bug Report, gnupg
justus added a comment to T2324: gpg --batch --export-secret-key fails (requires user interaction) if key has no passphrase.

Werner: Yes please.

Apr 20 2016, 10:53 AM · gnupg, OpenPGP, Bug Report

Apr 19 2016

werner added a comment to T2324: gpg --batch --export-secret-key fails (requires user interaction) if key has no passphrase.

I have some stashed work to fix this but it is not ready - let me know if you
want to work on it.

Apr 19 2016, 8:09 PM · gnupg, OpenPGP, Bug Report
werner added a project to T2315: No reliable way to select a uid for --quick-sign-key: Restricted Project.
Apr 19 2016, 5:59 PM · gnupg, Bug Report
werner added a comment to T2315: No reliable way to select a uid for --quick-sign-key.

commit d02de6c should fix that.

Use '=' for an exact match and optionally '*' for a substring match.

Apr 19 2016, 5:59 PM · gnupg, Bug Report
werner closed T2310: Set 'confirm' flag with smartcard as Resolved.
Apr 19 2016, 2:22 PM · gnupg, gpgagent, Feature Request
justus added a comment to T2324: gpg --batch --export-secret-key fails (requires user interaction) if key has no passphrase.

*See also T2070

Apr 19 2016, 1:00 PM · gnupg, OpenPGP, Bug Report
gregoire renamed T2310: Set 'confirm' flag with smartcard from Set 'config' flag with smartcard to Set 'confirm' flag with smartcard.
Apr 19 2016, 11:39 AM · gnupg, gpgagent, Feature Request
gregoire added a comment to T2310: Set 'confirm' flag with smartcard.

I think I was confused by the fact that I didn't use ssh-add to add the key and
I didn't realize that I could add it manually to sshcontrol. I did that and it
now works as expected. Sorry about the noise.

Although maybe it would be nice to be able to make 'confirm' the default for
keys which are not listed in sshcontrol. But that's a very minor thing.

Apr 19 2016, 11:39 AM · gnupg, gpgagent, Feature Request
werner added a comment to T2324: gpg --batch --export-secret-key fails (requires user interaction) if key has no passphrase.

See also issue20170

Apr 19 2016, 10:46 AM · gnupg, OpenPGP, Bug Report
werner added projects to T2324: gpg --batch --export-secret-key fails (requires user interaction) if key has no passphrase: OpenPGP, gnupg.
Apr 19 2016, 10:46 AM · gnupg, OpenPGP, Bug Report
werner set Version to 2.1 on T2070: Can not leave passphrase empty when exporting secret key.
Apr 19 2016, 10:45 AM · Duplicate, Bug Report, gnupg
gniibe claimed T2298: Unblocking a smartcard PIN not possible in 2.1.
Apr 19 2016, 6:41 AM · Info Needed, gnupg, scd, Bug Report
gniibe added a comment to T2298: Unblocking a smartcard PIN not possible in 2.1.

Please describe the interaction. IIUC, isn't it pinentry problem?
Did you input your PIN? For "2 - unblock PIN" operation, you need to
authenticate as admin, did you input your PIN for admin? Wasn't it a failure of
PIN input for admin or user, whatever?

Apr 19 2016, 6:41 AM · Info Needed, gnupg, scd, Bug Report
gniibe added a comment to T2282: Invalid flag adding encryption subkey with Curve 25519.

libgcrypt 1.7.0 is out. Please test with it.

Apr 19 2016, 6:26 AM · Not A Bug, Bug Report, gnupg

Apr 18 2016

mech added a comment to T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only).

HKPS won't be the reason, we use plain HKP

as of gpg.conf
keyserver hkp://keyserver.int.myCompany.com:11371

BTW. The versions in the previous post should have been 2.0.28 and 2.0.30 vs.
2.1.11, of course.

Apr 18 2016, 1:34 PM · gnupg, Bug Report
justus claimed T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only).
Apr 18 2016, 1:01 PM · gnupg, Bug Report
justus added a comment to T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only).

Hello. If you are using https to talk to your keyserver, your problem might be
Issue 1950 which we fixed in GnuPG 2.1.10.

Apr 18 2016, 1:01 PM · gnupg, Bug Report
mech added a comment to T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only).

A collegue of mine now has a similar problem with GnuPG on MacOS during gpg
--refesh-keys from an in-house SKS keyserver (set in gpg.conf)

Happens with GnuPG 2.2.28 and GnuPG 2.2.30. Problem disappeared with GnuPG 2.1.11.
Hence changed category back to gnupg as it's no Windows-only problem anymore.
Still assume that it is somewhat related to larger key rings.

gpg: Total number processed: 392
gpg: unchanged: 392
gpg: keyserver communications error: Not found
gpg: keyserver communications error: Bad public key
gpg: keyserver refresh failed: Bad public key

Apr 18 2016, 9:27 AM · gnupg, Bug Report
mech added a project to T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only): gnupg.
Apr 18 2016, 9:27 AM · gnupg, Bug Report
mech removed a project from T2297: Refresh keys fails for whole (large) keyring since GnuPG 2.0.27+ (gpg4win only): gpg4win.
Apr 18 2016, 9:27 AM · gnupg, Bug Report

Apr 15 2016

dkg added a comment to T2313: gpg --import of secret keys prompts for passwords in 2.1.

I understand the reason for re-encrypting -- i'm quite happy that the agent is
sensible about improving the security of the key when it adopts it.

my concern is that users don't know what to expect, and that different workflows
result in different sets of keys stored in the agent.

So i'd recommend that when importing without --batch, if the password fails for
any reason, gpg should fall back to the fast migration "kludge" rather than just
skipping that keyblock. That way the imported secret key material will still be
available and can be cleaned up/hardened on first successful use.

Apr 15 2016, 2:20 PM · S/MIME, Feature Request, Stalled, gnupg, OpenPGP
werner added a project to T2312: GnuPG 2.1 migration fails due to permissions but appears to succeed: gnupg.
Apr 15 2016, 8:39 AM · gnupg, Bug Report
werner added projects to T2313: gpg --import of secret keys prompts for passwords in 2.1: OpenPGP, gnupg.
Apr 15 2016, 8:38 AM · S/MIME, Feature Request, Stalled, gnupg, OpenPGP
werner set Version to 2.1 on T2313: gpg --import of secret keys prompts for passwords in 2.1.
Apr 15 2016, 8:38 AM · S/MIME, Feature Request, Stalled, gnupg, OpenPGP
werner added a project to T2316: ssh-add ignores keys already in private-keys-v1.d but not in sshcontrol: gnupg.
Apr 15 2016, 8:31 AM · gnupg, Not A Bug, Bug Report, ssh, gpgagent, gnupg (gpg21)