Page MenuHome GnuPG
Feed Advanced Search

Jul 27 2017

marcus merged T3026: Export gpgme-pthread.pc into T1329: pkg-config support for gpgme.
Jul 27 2017, 4:59 PM · Won't Fix, gpgme, Feature Request
marcus merged task T3026: Export gpgme-pthread.pc into T1329: pkg-config support for gpgme.
Jul 27 2017, 4:59 PM · gpgme, Feature Request
marcus added a comment to T2694: insecure links on gnupg webpage (gnupg.org) that could be https.

Also a lot of redirects, for example this bounces you from https to http.

Jul 27 2017, 4:56 PM · In Progress, Feature Request
marcus added a comment to T2916: GPGME should have a way to suppress delete key prompts.

Could be done by adding "--yes" to the command line. Requires a new version of the gpgme_op_delete functions with a flag "force".

Jul 27 2017, 4:45 PM · gpgme (gpgme 1.23.x), Feature Request
marcus closed T2926: Design gap in openpgp card process as Wontfix.

As others have pointed out, we don't implement the Bell-Lapadula model.

Jul 27 2017, 2:44 PM · Stalled, Feature Request
marcus removed a project from T2907: make DNS look ups more parallel: gnupg (gpg23).
Jul 27 2017, 2:07 PM · Feature Request, gnupg
werner added a project to T2313: gpg --import of secret keys prompts for passwords in 2.1: S/MIME.

Well, iff we implement that for gpg we also need to implement it for gpgsm.

Jul 27 2017, 9:41 AM · S/MIME, Feature Request, Stalled, gnupg, OpenPGP
werner edited projects for T2313: gpg --import of secret keys prompts for passwords in 2.1, added: Feature Request; removed Bug Report.
Jul 27 2017, 9:40 AM · S/MIME, Feature Request, Stalled, gnupg, OpenPGP

Jul 26 2017

marcus closed T2233: Missing feedback when sending key to key server as Wontfix.
Jul 26 2017, 4:34 PM · gnupg, Feature Request
werner added a comment to T2935: use-tor should have a third possible value, "if available".

FWIW, using a Debian specific thing is not portable and Unix sockets won't work on Windows. Thus using the standard localhost connection is simpler than adding extra complexity.

Jul 26 2017, 2:17 PM · gnupg (gpg22), In Progress, Feature Request, dirmngr
werner closed T2935: use-tor should have a third possible value, "if available" as Resolved.

Okay, I implemented the second part and Tor is now used if availabale.
--no-use-tor disables Tor.
--use-tor forces use Tor and can't be reset.

Jul 26 2017, 2:06 PM · gnupg (gpg22), In Progress, Feature Request, dirmngr
werner claimed T2935: use-tor should have a third possible value, "if available".
Jul 26 2017, 10:38 AM · gnupg (gpg22), In Progress, Feature Request, dirmngr

Jul 25 2017

p91 added a comment to T2688: unlocking gpg-agent via pam?.

I am not to familiar with the gnome keyring but from looking it up on the arch wiki, it seems to have this single sign on capability.

Jul 25 2017, 7:54 PM · gpgagent, Feature Request
marcus closed T2858: way to not spawn (or despawn) gpg-agent and dirmngr as Wontfix.

Sufficient workarounds have been found.

Jul 25 2017, 7:45 PM · gnupg, dirmngr, Feature Request
lorenz added a comment to T1854: Problems with same encryption and signing key on smartcard.

That is the way I get my certificate signed, there is nothing I can do about it ;-)

Jul 25 2017, 7:35 PM · gnupg, Feature Request, scd
werner removed a project from T2688: unlocking gpg-agent via pam?: Info Needed.
Jul 25 2017, 6:39 PM · gpgagent, Feature Request
werner added a comment to T2688: unlocking gpg-agent via pam?.

So this is basically 0what GNOME does with its keyring daemon and pinentry-gnome.

Jul 25 2017, 6:38 PM · gpgagent, Feature Request
marcus added a comment to T1854: Problems with same encryption and signing key on smartcard.

It's not really a good idea to use the same RSA key for encryption and signing. (Although when I wrote scute, I couldn't generate a CSR for the encryption key, because the CSR had to be self-signed, meh).

Jul 25 2017, 6:37 PM · gnupg, Feature Request, scd
marcus updated the task description for T1854: Problems with same encryption and signing key on smartcard.
Jul 25 2017, 6:36 PM · gnupg, Feature Request, scd
p91 added a comment to T2688: unlocking gpg-agent via pam?.

Btw, this was envoy: https://github.com/vodik/envoy

Jul 25 2017, 6:34 PM · gpgagent, Feature Request
p91 added a comment to T2688: unlocking gpg-agent via pam?.

what I mean by unlocking is the act of using the passphrase to load the gpg and ssh keys and hence not needing to tip the phrase again afterwards.

Jul 25 2017, 6:34 PM · gpgagent, Feature Request
werner added a project to T2688: unlocking gpg-agent via pam?: Info Needed.

I don't understand what you mean by unlocking gpg-agent. Can you please explain in detail what you try to achieve.

Jul 25 2017, 3:52 PM · gpgagent, Feature Request

Jul 24 2017

marcus added a project to T2688: unlocking gpg-agent via pam?: gpgagent.
Jul 24 2017, 6:23 PM · gpgagent, Feature Request
marcus added a project to T2683: Add config option to connect to HW token in non-exclusive (shared) mode: scd.
Jul 24 2017, 6:19 PM · scd, Feature Request
werner lowered the priority of T1800: Allow s2k options for gpg --export-secret-key from Normal to Wishlist.
Jul 24 2017, 9:50 AM · Feature Request, gnupg

Jul 21 2017

larryv updated the task description for T1800: Allow s2k options for gpg --export-secret-key.
Jul 21 2017, 10:54 PM · Feature Request, gnupg
marcus added a project to T2439: Optionally always prompt for key confirmation for requests from restricted sockets: gpgagent.
Jul 21 2017, 5:05 PM · gpgagent, Feature Request
marcus added a comment to T2435: gpgsm combined sign and encrypt.

One problem I see is that S/MIME doesn't standardize sign+encrypt, but requires nesting of those operations, leaving it up to the implementor to pick the order etc. From an interoperability point of view, this seems like a world of hurt if you take this out of the context of MIME.

Jul 21 2017, 4:53 PM · gnupg, kleopatra, Feature Request
marcus added a comment to T2428: Implement returning data from inquire callbacks.

Do you have a use case?

Jul 21 2017, 4:31 PM · gpgme, Feature Request

Jul 20 2017

marcus closed T2404: gpg-connect-agent should have an --scdaemon option in parallel to the --dirmngr option as Wontfix.

So it seems that accessing through gpg-agent is the better solution.

Jul 20 2017, 9:51 PM · gnupg, Feature Request
marcus removed a project from T2064: please allow unattended secret key deletion: In Progress.
Jul 20 2017, 9:26 PM · gnupg, Feature Request
marcus added a parent task for T2349: Composing a private key from raw key material: T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only.
Jul 20 2017, 9:15 PM · libgcrypt, Feature Request
marcus added a subtask for T1734: [SUGGESTION] Implement a function to re-generate public keys and(!) "stubs" from private keys stored on smartcard only: T2349: Composing a private key from raw key material.
Jul 20 2017, 9:15 PM · gnupg, Feature Request
marcus edited projects for T2266: Gpg4win: Migrate Keyring to Keybox, added: Feature Request; removed Bug Report.
Jul 20 2017, 7:23 PM · Feature Request, gnupg, gpg4win
marcus closed T2178: GPA - key generation message as Wontfix.
Jul 20 2017, 7:17 PM · gpa, Feature Request
marcus added a comment to T2178: GPA - key generation message.

Changing the message affects all translations.

Jul 20 2017, 7:17 PM · gpa, Feature Request
marcus closed T2211: Wish: List all started services by gpg4win on the wiki page as Invalid.

Well, we don't maintain a wiki, so I think this should be tracked elsewhere.

Jul 20 2017, 5:57 PM · Documentation, Feature Request, gpg4win
marcus closed T2204: Wrong FAILURE message if gpg-agent cannot be started as Resolved.

With commit 9998b162b47931fb8a8ed961d53418d505358888:

Jul 20 2017, 5:54 PM · Feature Request, gnupg
dkg added a comment to T3203: gpg chokes on empty UserId.

I'd like to hear a little more about the use cases we imagine for Anonymous OpenPGP certificates.

Jul 20 2017, 4:58 PM · Feature Request, gnupg (gpg22)

Jul 19 2017

werner added a comment to T1235: adding automatic refresh-key.

T3252 is about meta data for each key.

Jul 19 2017, 5:42 PM · gnupg26, gnupg22, Feature Request
Valodim added a comment to T3203: gpg chokes on empty UserId.

Hm. Could you elaborate on that? Why do you think it's dangerous?

Jul 19 2017, 5:36 PM · Feature Request, gnupg (gpg22)
werner closed T3203: gpg chokes on empty UserId as Wontfix.

I consider allowing empty user ids too dangerous.

Jul 19 2017, 5:32 PM · Feature Request, gnupg (gpg22)
justus closed T2940: dirmngr fails for hkps when http-proxy is in use as Resolved.

Implemented in da91d2106a17c796ddb066a34db92d33b21c81f7.

Jul 19 2017, 12:31 PM · Feature Request, gnupg (gpg22), Debian, gnupg, dirmngr

Jul 18 2017

marcus closed T1747: Some command line options can not be abbreviated as Resolved.

Implemented in f17862d47.

Jul 18 2017, 6:13 PM · Feature Request, gnupg
justus claimed T2940: dirmngr fails for hkps when http-proxy is in use.
Jul 18 2017, 4:27 PM · Feature Request, gnupg (gpg22), Debian, gnupg, dirmngr

Jul 17 2017

marcus placed T1506: New key generation usability enhancements up for grabs.
Jul 17 2017, 6:27 PM · In Progress, gnupg, Feature Request
marcus placed T1173: gpg has no easy way to view the reason and description of revocation sigs up for grabs.
Jul 17 2017, 6:26 PM · gnupg, Debian, Feature Request
marcus closed T1725: addkey asks for a separate new password for every subkey created as Invalid.
Jul 17 2017, 6:02 PM · Feature Request, Not A Bug, gnupg
marcus closed T2811: please compare the timestamps of secring.gpg and .gpg-v21-migrated and consider re-migration as Wontfix.

werner said this won't be fixed.

Jul 17 2017, 5:38 PM · Won't Fix, Feature Request, gnupg
marcus closed T1426: the way gpg updates the pubring files makes it impossible to symlink it as Wontfix.
Jul 17 2017, 5:34 PM · Won't Fix, gnupg, Feature Request
marcus closed T1720: more context in key-generation prompts as Resolved.
Jul 17 2017, 3:11 PM · gnupg, Feature Request
marcus added a comment to T1720: more context in key-generation prompts.

This has been improved by e467a000f87e87582f5838964b6f1e0a960d4445

Jul 17 2017, 3:11 PM · gnupg, Feature Request
marcus closed T1417: Unhashed signature subpacket "preferred keyserver" ignored for document signatures as Wontfix.

In addition to Werner's concerns, making network requests to unverified URLs can be harmful in many ways. For example, it would allow a third-party to detect when the signature was verified, among other even nastier things.

Jul 17 2017, 2:59 PM · Feature Request, gnupg
marcus renamed T1643: gpgex context menu should allow symmetric encryption from Context menu: Symmetric encryption to gpgex context menu should allow symmetric encryption.
Jul 17 2017, 2:55 PM · gpgex, Feature Request
marcus closed T1609: Enforce signer identity when verify signature as Wontfix.
Jul 17 2017, 2:53 PM · gnupg, Feature Request
marcus edited projects for T1055: Special characters encoding issue with LDAP keyserver., added: gnupg (gpg22); removed gnupg (gpg21), gnupg.

Maybe for 2.2?

Jul 17 2017, 2:48 PM · gnupg (gpg22), Feature Request
marcus added a project to T1235: adding automatic refresh-key: Stalled.
Jul 17 2017, 2:27 PM · gnupg26, gnupg22, Feature Request
marcus placed T2145: Enhance pinentry-qt dialog title with key specific info to facilitate auto-typing up for grabs.
Jul 17 2017, 2:25 PM · pinentry, Feature Request

Jul 14 2017

justus added a comment to T2946: gpg-agent should be able to terminate when all its state expires.

Another reoccurring concern is lingering agents spawned in test suites. See, e.g. a discussion from this week: https://github.com/pazz/alot/pull/1081#issuecomment-315131053

Jul 14 2017, 1:52 PM · gnupg, Debian, gpgagent, Feature Request
marcus reopened T2946: gpg-agent should be able to terminate when all its state expires as "Open".

Well, we always have to weigh the costs with the benefits. From the description of the task, the benefit was to satisfy "people [who] really don't like having idle processes lying around", which is not a strong motivation to take implementation and maintenance cost of any solution.

Jul 14 2017, 1:21 PM · gnupg, Debian, gpgagent, Feature Request
dkg added a comment to T2946: gpg-agent should be able to terminate when all its state expires.

This is a disappointing resolution. There are many other reasons for having a daemon, which include keeping a sensitive piece of data in memory (and not on disk) for a limited period of time, while providing controlled access to it. This is exactly what gpg-agent does.

Jul 14 2017, 12:38 PM · gnupg, Debian, gpgagent, Feature Request
dkg added a comment to T1537: gpgv does not handle expired or revoked keys.

Thinking about it more broadly, i think that gpgv (and gpg, when used in signature verification mode) should have a return code that is as close to the true/false underlying semantics that users will want, rather than relying on status messages to distinguish between these cases.

Jul 14 2017, 12:29 PM · Feature Request, gnupg
dkg added a comment to T1537: gpgv does not handle expired or revoked keys.

for expiration (or for revocations flagged "key was superseded" instead of "compromised"), you can have a signature made *before* the key's expiration/revocation, but you might be verifying it *after* the key was revoked/expired.

Jul 14 2017, 12:26 PM · Feature Request, gnupg

Jul 13 2017

justus added a comment to T1537: gpgv does not handle expired or revoked keys.

Sorry, I expressed my concern poorly. gpg does recognize the keys as being expired/revoked, but this is not reflected in the exit code of the gpg/gpgv process.

Jul 13 2017, 11:46 AM · Feature Request, gnupg
marcus closed T2946: gpg-agent should be able to terminate when all its state expires as Wontfix.

Werner's comments indicate that this is expected behavior. Also, concerns were raised that this is difficult to implement correctly, and it is difficult to test. So, I am closing as wontfix.

Jul 13 2017, 1:27 AM · gnupg, Debian, gpgagent, Feature Request
marcus added a comment to T2696: SETREPEAT support for pinentry-curses.

And SETQUALITYBAR.

Jul 13 2017, 12:54 AM · pinentry, Feature Request
marcus claimed T2145: Enhance pinentry-qt dialog title with key specific info to facilitate auto-typing.
Jul 13 2017, 12:37 AM · pinentry, Feature Request
marcus edited projects for T2245: pinentry on wrong monitor, added: Feature Request, Stalled; removed Bug Report.
Jul 13 2017, 12:36 AM · Stalled, Feature Request, pinentry
marcus lowered the priority of T1760: Port pinentry-ncurses for windows from Normal to Wishlist.

It is unclear what the benefit of such a console pinentry for windows would be.

Jul 13 2017, 12:22 AM · pinentry, Feature Request
marcus closed T2263: use FD passing instead of /tmp/emacs$UID/pinentry as Wontfix.

Loopback is now officially supported, so I am closing this.

Jul 13 2017, 12:17 AM · pinentry, Feature Request
marcus merged T3084: pinentry and password managers mix poorly into T2145: Enhance pinentry-qt dialog title with key specific info to facilitate auto-typing.
Jul 13 2017, 12:10 AM · pinentry, Feature Request

Jul 12 2017

marcus closed T2249: Pinetry field "enter passphrase" won't let me paste in as Resolved.
Jul 12 2017, 11:52 PM · Feature Request, Info Needed, pinentry
marcus closed T2244: pinentry not saving/using saved GPG key password as Invalid.

I just tested this with Fedora 26, pinentry-gnome3 0.9.7 and Gnome Keyring 3.20.1. See below for a full trace. If this doesn't work for you, check that you have compiled pinentry with libsecret, and did not deactivate the feature in the gpg-agent.conf.

Jul 12 2017, 11:37 PM · pinentry, Feature Request
marcus closed T2058: Change gpg-agent to support passing command line options to pinentry as Wontfix.

Without a strong use case, I am closing this feature request. It may well turn out that like --allow-emacs-pinentry, the best solution in each case will be to add specific options, and then a generic pass-through will never be required. And we don't want to add features just in case somebody might need them in the future.

Jul 12 2017, 9:34 PM · Feature Request, gnupg
dkg added a comment to T1537: gpgv does not handle expired or revoked keys.

I don't think that's what we want. An OpenPGP certificate has a claimed temporal validity window: from the creation date of the certificate to its expiration or revocation date.

Jul 12 2017, 12:00 AM · Feature Request, gnupg

Jul 11 2017

marcus closed T2013: pinentry-curses / pinentry-tty should emit a bell when showing a dialog as Resolved.

Done.

Jul 11 2017, 7:31 PM · pinentry, Feature Request
justus added a comment to T1537: gpgv does not handle expired or revoked keys.

So both gpg and gpgv seem to return success (as in the exit code is 0) if the signature is correct, even if the key is revoked or expired:

Jul 11 2017, 5:14 PM · Feature Request, gnupg
justus triaged T3272: Make groups available through GPGME as Wishlist priority.
Jul 11 2017, 12:30 PM · gpgme, Feature Request
aheinlein created T3272: Make groups available through GPGME.
Jul 11 2017, 10:34 AM · gpgme, Feature Request

Jul 6 2017

marcus closed T1562: libassuan-config unsuitable for multilib support as Wontfix.

We don't support pkg-config, because it is not POSIX. See https://lists.gnupg.org/pipermail/gnupg-devel/2014-May/028474.html for discussion.

Jul 6 2017, 5:39 PM · Feature Request, libassuan

Jul 5 2017

marcus closed T1944: Global changing of expiration date for mainkey and subkeys as Resolved.

Given that we have reduced the number of operations to at most 2 (down from unlimited), and it is unclear if and how to proceed on this, I am closing here.

Jul 5 2017, 12:50 AM · gnupg, Feature Request

Jul 4 2017

marcus closed T1004: http://www.gnupg.org/howtos/vn/index.html does not exist as Resolved.

Fixed in rD1143a81c4691.

Jul 4 2017, 11:46 PM · gpgweb, Feature Request
werner lowered the priority of T169: Add a way to generate keypairs from a passphrase from Normal to Low.

FWIW, OpenPGP's S2K and PKCS's PBKDF2 are very similar and don't make a difference except that we have calibration code for S2K in gpg-agent.

Jul 4 2017, 3:43 PM · gnupg, Feature Request
werner lowered the priority of T2967: Allow to keep original timestamp on keysig updates from Normal to Low.
Jul 4 2017, 10:40 AM · gnupg, Feature Request

Jul 2 2017

marcus merged task T1337: No mention of --default-cert-check-level in man into T2823: generate web-based manpage from latest release.
Jul 2 2017, 12:46 PM · gpgweb, Feature Request, Documentation

Jul 1 2017

marcus merged task T2093: agent confirm default into T2265: SSH confirmation with gpg-agent on Windows has the Allow button as the default action.
Jul 1 2017, 2:51 PM · pinentry, Feature Request
marcus closed T2174: Adding a free-form note tab to cert listing in Kleopatra as Invalid.

The TOFU trust model gives some more information about certificate usage. Beyond that I don't think this is well defined to be actionable in the backend.

Jul 1 2017, 2:47 PM · kleopatra, Feature Request, gpg4win
marcus closed T2039: CRL issuingDistributionPoint support as Wontfix.

Digicert TERENAPersonalCA3 doesn't use issuingDistributionPoint anymore. It's hard to survey CRLs that are actually in use, so I don't know if there are other important users, but the fact that nobody else reported such problems is an indication that it is not widely used among dirmngr users. Supporting this is a lot of work, because it makes validating certificates much more complicated, so this is unlikely to happen without strong motivation, so I am closing this here.

Jul 1 2017, 1:52 PM · gnupg, Feature Request, dirmngr

Jun 30 2017

marcus closed T1337: No mention of --default-cert-check-level in man as Resolved.

I removed the man page and the link for now. Currently there doesn't seem to be an easy way to update it automatically.

Jun 30 2017, 9:00 PM · gpgweb, Feature Request, Documentation
marcus closed T1826: Cannot decrypt (PGP-MIME) message from Enigmail as Resolved.

PGP/MIME is supported since Gpg4win 2.3.

Jun 30 2017, 8:43 PM · Feature Request, gpg4win, gpgol
marcus closed T1721: "go back" option in CLI as Wontfix.

Most people should use a graphical user interface, and the console gui for key generation doesn't ask too many questions, while the key editor allows to go "back". So I am closing this suggestion.

Jun 30 2017, 6:31 PM · gnupg, Feature Request

Jun 29 2017

marcus added a comment to T1347: More informative error message for unusable keys.

Still no better message with gpg 2.1.21:

Jun 29 2017, 4:32 PM · gnupg, Feature Request
marcus assigned T1395: Write an architecture chapter for GnuPG to neal.

Maybe this can be done by Neal along with the book?

Jun 29 2017, 4:03 PM · gnupg, Documentation, Feature Request
marcus added a comment to T169: Add a way to generate keypairs from a passphrase.

The change werner mentioned previously is eaba8d58acda66f428870794115cb22c2590ec5e, but this is based on Elgamal. RFC4880 since then specified S2K, and better approaches are available, too (at least PBKDF2 is in libgcrypt). These could be used with HKDF for RSA and other asymmetric key generation methods.

Jun 29 2017, 4:01 PM · gnupg, Feature Request

Jun 28 2017

marcus edited projects for T2399: gpgconf is not idempotent, added: Feature Request; removed Bug Report.
Jun 28 2017, 5:29 PM · Feature Request
marcus closed T1380: Outgoing address should be configuable as Invalid.
Jun 28 2017, 5:25 PM · gpgol, Feature Request
marcus closed T2172: Add version number to gpg.exe as Resolved.
Jun 28 2017, 5:24 PM · gpg4win, Feature Request
marcus merged task T1561: configure: --with-libgpg-error-prefix doesn't impact includes into T1467: libksba's configure script reports "--with-libgpg-error-prefix", expects "--with-gpg-error-prefix".
Jun 28 2017, 5:11 PM · Feature Request, In Progress, gnupg
marcus closed T1601: Add info about gpg1 vs. gpg2 to the man page as Wontfix.

gnupg 1.4 is phased out and only receives important updates.

Jun 28 2017, 4:18 PM · Feature Request, gnupg
wltjr added a comment to T2905: EFL-based pinentry.
In T2905#99236, @justus wrote:

There is nothing to fix in the way the underlying algorithm communicates its value to the frontend. Negative values mean red, positive values green. After that, you have to normalize that to 0...100.

Jun 28 2017, 3:04 PM · pinentry, Feature Request