Page MenuHome GnuPG
Feed All Stories

Jan 4 2019

raboof added a comment to T4308: scdaemon does not survive suspend/resume with Yubikey4.

Attached the wireshark log

Jan 4 2019, 10:53 AM · yubikey, Bug Report
gniibe claimed T4308: scdaemon does not survive suspend/resume with Yubikey4.

The workaround in T3825 is for PC/SC driver. So, it is not the case for internal stock CCID driver.
'scd reset /bye' does not let the scdaemon do reset process of the card itself. It resets the transaction of scdaemon.

Jan 4 2019, 6:16 AM · yubikey, Bug Report

Jan 3 2019

werner committed rG405feca2bdee: scd: Add two variants to the set of ISO7816 functions. (authored by werner).
scd: Add two variants to the set of ISO7816 functions.
Jan 3 2019, 3:20 PM
werner committed rGcca2b87e79cd: scd: Support "READKEY --advanced" for all cards. (authored by werner).
scd: Support "READKEY --advanced" for all cards.
Jan 3 2019, 3:20 PM
werner added a project to T4308: scdaemon does not survive suspend/resume with Yubikey4: yubikey.
Jan 3 2019, 10:22 AM · yubikey, Bug Report
raboof created T4308: scdaemon does not survive suspend/resume with Yubikey4.
Jan 3 2019, 9:30 AM · yubikey, Bug Report

Jan 2 2019

jukivili committed rC3ee6588de831: Process CCM/EAX/GCM/Poly1305 AEAD cipher modes input in 24 KiB chucks (authored by jukivili).
Process CCM/EAX/GCM/Poly1305 AEAD cipher modes input in 24 KiB chucks
Jan 2 2019, 9:04 PM
jukivili committed rC4871f11745f3: tests/benchmark: add Chacha20-Poly1305 benchmarking (authored by jukivili).
tests/benchmark: add Chacha20-Poly1305 benchmarking
Jan 2 2019, 9:04 PM
jukivili committed rCedde61f325e4: tests/benchmark: add --huge-buffers option for cipher tests (authored by jukivili).
tests/benchmark: add --huge-buffers option for cipher tests
Jan 2 2019, 9:04 PM
werner committed rG3d766924b412: doc: Typo fix in code comment (authored by werner).
doc: Typo fix in code comment
Jan 2 2019, 4:50 PM
BenM committed rMa0dbdfebbb60: python docs: post installer (authored by BenM).
python docs: post installer
Jan 2 2019, 1:26 AM
BenM committed rM207d4289d849: python: examples (authored by BenM).
python: examples
Jan 2 2019, 1:26 AM
BenM committed rMa2e7c863c821: python: post installer doc fix script (authored by BenM).
python: post installer doc fix script
Jan 2 2019, 1:26 AM
BenM committed rMef9355c2fe8f: python: docs processing (authored by BenM).
python: docs processing
Jan 2 2019, 1:26 AM

Jan 1 2019

l10n daemon script <scripty@kde.org> committed rKLEOPATRA85543cb0dc30: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Jan 1 2019, 3:08 AM

Dec 31 2018

werner triaged T4303: scheme.c:875:33: error: expected ‘;’ before ‘abort’ as Low priority.

Please never ever define NDEBUG. This is a severe misfeature of the assert macro.

Dec 31 2018, 4:58 PM · Bug Report
Yuri Chornoivan <yurchor@ukr.net> committed rKLEOPATRA33d06a7eeb7f: Fix minor Doxygen issues (authored by Yuri Chornoivan <yurchor@ukr.net>).
Fix minor Doxygen issues
Dec 31 2018, 9:30 AM

Dec 30 2018

ooo created T4307: Importing existing elgamal subkey fails.
Dec 30 2018, 9:33 PM · gnupg, Bug Report
Laurent Montel <montel@kde.org> committed rKLEOPATRAfff6ee1fec8e: Update copyright (authored by Laurent Montel <montel@kde.org>).
Update copyright
Dec 30 2018, 10:58 AM
kaspro added a comment to T4301: Handling multiple subkeys on two SmartCards.

That's exactly the point: I do want one common encryption key between the two cards: So I can distinguish between the two, but en-/decrypt with both.
One is on the GnuPG SmartCard, the other on a YubiKey - output --card-status (some things xxx'ed out) :

Dec 30 2018, 4:55 AM · Restricted Project, gnupg, scd, Bug Report
JW created T4306: nPth fails to compile in the S1 Public space.
Dec 30 2018, 1:12 AM · npth, Bug Report
JW added a project to T4305: NtbTLS fails to compile: Bug Report.
Dec 30 2018, 1:06 AM · Bug Report, ntbtls
JW added a project to T4304: gcry_control (GCRYCTL_INIT_SECMEM, 16384, 0) failed: General error: libgcrypt.
Dec 30 2018, 1:05 AM · Legacy OS, Fedora, libgcrypt, Bug Report
JW created T4305: NtbTLS fails to compile in the S1 Public space.
Dec 30 2018, 1:05 AM · Bug Report, ntbtls

Dec 29 2018

JW updated the task description for T4304: gcry_control (GCRYCTL_INIT_SECMEM, 16384, 0) failed: General error.
Dec 29 2018, 11:47 PM · Legacy OS, Fedora, libgcrypt, Bug Report
JW created T4304: gcry_control (GCRYCTL_INIT_SECMEM, 16384, 0) failed: General error.
Dec 29 2018, 11:39 PM · Legacy OS, Fedora, libgcrypt, Bug Report
JW added a comment to T4303: scheme.c:875:33: error: expected ‘;’ before ‘abort’.

Here's the patch:

Dec 29 2018, 10:24 PM · Bug Report
JW updated the task description for T4303: scheme.c:875:33: error: expected ‘;’ before ‘abort’.
Dec 29 2018, 9:50 PM · Bug Report
JW created T4303: scheme.c:875:33: error: expected ‘;’ before ‘abort’.
Dec 29 2018, 9:50 PM · Bug Report

Dec 28 2018

werner renamed T4299: Problem to verify PGP key used by Microsoft from Problem to verify PGP key to Problem to verify PGP key used by Microsoft.
Dec 28 2018, 6:14 PM · gpgol, gpg4win
werner triaged T4302: GPA wrongly reports failure to retrieve key as Normal priority.
Dec 28 2018, 6:12 PM · gpa, Bug Report
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

I contacted Microsoft Security Response Center (MSRC) in regard to this matter. They confirmed the failed PGP key verification, but have not yet any explanation for that.

Dec 28 2018, 4:12 PM · gpgol, gpg4win
gniibe added a comment to T4301: Handling multiple subkeys on two SmartCards.

Please show us your output of gpg --card-status for each card, and tell us the reason why you think "the pgp db seems screwed up".

Dec 28 2018, 3:33 AM · Restricted Project, gnupg, scd, Bug Report
gniibe added a comment to T4301: Handling multiple subkeys on two SmartCards.

For my test, six distinct keys (three subkeys for each smartcard) works fine.
IIUC, you try to use same decryption key by two smartcards. Currently, it is not supported.

Dec 28 2018, 3:13 AM · Restricted Project, gnupg, scd, Bug Report

Dec 27 2018

Laurent Montel <montel@kde.org> committed rKLEOPATRA2e36daa7949c: GIT_SILENT: Update copyright (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Update copyright
Dec 27 2018, 6:33 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRAbcae97632b4a: Use https (authored by Laurent Montel <montel@kde.org>).
Use https
Dec 27 2018, 5:55 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRA2ad455e5fd68: Use https here too (authored by Laurent Montel <montel@kde.org>).
Use https here too
Dec 27 2018, 5:55 PM
gniibe added a project to T4301: Handling multiple subkeys on two SmartCards: Info Needed.

Is it an issue when you share an decryption key E among two smartcards?
I think that when there are six distinct keys (three subkeys for one smartcard each), it works fine.
I'll try to make reproducible test case.

Dec 27 2018, 9:05 AM · Restricted Project, gnupg, scd, Bug Report
gniibe claimed T4301: Handling multiple subkeys on two SmartCards.
Dec 27 2018, 4:30 AM · Restricted Project, gnupg, scd, Bug Report

Dec 26 2018

BenM committed rMd406471d4bf9: python: examples (authored by BenM).
python: examples
Dec 26 2018, 1:09 AM

Dec 25 2018

gouttegd created T4302: GPA wrongly reports failure to retrieve key.
Dec 25 2018, 3:51 PM · gpa, Bug Report

Dec 24 2018

Laurent Montel <montel@kde.org> committed rKLEOPATRAd01178b161f0: GIT_SILENT: Prepare 5.10.1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare 5.10.1
Dec 24 2018, 2:36 PM

Dec 23 2018

kaspro created T4301: Handling multiple subkeys on two SmartCards.
Dec 23 2018, 5:01 AM · Restricted Project, gnupg, scd, Bug Report

Dec 21 2018

BenM committed rM06bca0eaa8de: python: docs (authored by BenM).
python: docs
Dec 21 2018, 11:45 PM
BenM added a comment to T4299: Problem to verify PGP key used by Microsoft.

What are MS doing when they get it right, though? I'd look at the differences between those two to identify what they've messed up here.

Dec 21 2018, 8:18 PM · gpgol, gpg4win
werner updated subscribers of T4299: Problem to verify PGP key used by Microsoft.

Thanks. The mail is a standard, non-crypto mail with one attachment. That attachment is a TNEF file which has according to ytnef(1) just one file. That file has the name gpgolPGP.dat and contains a clearsigned message.

Dec 21 2018, 1:19 PM · gpgol, gpg4win
BenM committed rMdc5f416351e4: python: groups example (authored by BenM).
python: groups example
Dec 21 2018, 11:08 AM
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Sure, I zipped the eml which failed and I´ll send it by e-mail to you

Dec 21 2018, 9:38 AM · gpgol, gpg4win
werner added a comment to T4299: Problem to verify PGP key used by Microsoft.

Is it possible that you upload or send me a copy of such a mail (wk gnupg.org)? ZIP or tar the eml file and send it in an encrypted mail to me to make sure it won't be modified on the transport.

Dec 21 2018, 8:37 AM · gpgol, gpg4win

Dec 20 2018

JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

I checked my mails in detail, and I can confirm that the error occurs only with "Microsoft security update releases". Indeed "Microsoft security advisory notification" and "Microsoft security update summary for..." will be verified correctly.

Dec 20 2018, 9:39 PM · gpgol, gpg4win
jmrexach added a comment to T4299: Problem to verify PGP key used by Microsoft.

I agree. It also happens to me. But only with mails coming from "Microsoft security update releases". Mails coming form "Microsoft security advisory notification" and Microsoft security update summary for..." are ok and are signed by the same key. It could be some trouble in MS automated email treatment.

Dec 20 2018, 7:50 PM · gpgol, gpg4win
markpaskal created T4300: Signed (sign-only) messages are blank when read on Android email clients / Outlook online.
Dec 20 2018, 3:45 PM · gpgol, Bug Report, gpg4win
Laurent Montel <montel@kde.org> committed rKLEOPATRA32d8b6457531: GIT_SILENT: use KF5_MIN_VERSION (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: use KF5_MIN_VERSION
Dec 20 2018, 8:52 AM
werner triaged T4297: The browser integration component is not installed by default as High priority.
Dec 20 2018, 8:45 AM · gpgme, UI, gpg4win
werner added a subtask for T4294: Release Libgcrypt 1.9.0: T4288: Add getrandom support for the BSDs.
Dec 20 2018, 8:44 AM · Release Info, libgcrypt
werner added a parent task for T4288: Add getrandom support for the BSDs: T4294: Release Libgcrypt 1.9.0.
Dec 20 2018, 8:44 AM · libgcrypt
werner edited projects for T4299: Problem to verify PGP key used by Microsoft, added: FAQ, OpenPGP; removed Bug Report.
Dec 20 2018, 8:40 AM · gpgol, gpg4win
JW-D created T4299: Problem to verify PGP key used by Microsoft.
Dec 20 2018, 8:38 AM · gpgol, gpg4win
Laurent Montel <montel@kde.org> committed rKLEOPATRA7bbe1c3f1e05: GIT_SILENT: Use KF5_MIN_VERSION as KF5_VERSION will be overridden by first KF5… (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Use KF5_MIN_VERSION as KF5_VERSION will be overridden by first KF5…
Dec 20 2018, 7:11 AM
gniibe added a comment to T4288: Add getrandom support for the BSDs.

This is mine:

Dec 20 2018, 7:10 AM · libgcrypt
gniibe added a comment to T4288: Add getrandom support for the BSDs.

Confirmed my theory of getentropy(3): https://reviews.freebsd.org/rS331279

Dec 20 2018, 6:45 AM · libgcrypt
gniibe added a comment to T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).

Reading this discussion: http://lists.gnu.org/archive/html/bug-libtool/2018-01/msg00014.html
It seems that it could be fixed if we care about the order of libraries.
And it's not the issue for libgpg-error, which doesn't require external libraries.

Dec 20 2018, 4:01 AM
gniibe updated the task description for T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:42 AM
gniibe updated the task description for T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:40 AM
gniibe added a comment to T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).

For binutils, in Stretch, Debian specific patch was introduced.
Then, upstream introduced --enable-new-dtags option for configure to build binutils.
Now, Debian uses --enable-new-dtags option (at build time).

Dec 20 2018, 3:38 AM
gniibe set External Link to https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=859732 on T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:11 AM
gniibe updated the task description for T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:08 AM
gniibe updated the task description for T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:07 AM
gniibe updated the task description for T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:07 AM
gniibe renamed T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well) from Use uninstalled library, which is building now to Use uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 3:05 AM
gniibe created T4298: 'make check' with uninstalled library, which is building now (even if rpath doesn't work well).
Dec 20 2018, 2:51 AM
gniibe added a parent task for T4273: agent: Request insertion of smartcard when no card present: T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).
Dec 20 2018, 12:59 AM · Feature Request, Documentation, gpgagent
gniibe added a subtask for T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)): T4273: agent: Request insertion of smartcard when no card present.
Dec 20 2018, 12:59 AM · Restricted Project, Feature Request, gnupg
gniibe triaged T4273: agent: Request insertion of smartcard when no card present as Normal priority.
Dec 20 2018, 12:57 AM · Feature Request, Documentation, gpgagent

Dec 19 2018

mgn created T4297: The browser integration component is not installed by default.
Dec 19 2018, 5:06 PM · gpgme, UI, gpg4win
werner added a comment to T4288: Add getrandom support for the BSDs.

I think we should stick with the syscall for Linux.

Dec 19 2018, 8:00 AM · libgcrypt
werner added a comment to T4273: agent: Request insertion of smartcard when no card present.

FWIW, the canonical way to make sure that gpg-agent has been started is to run

Dec 19 2018, 7:58 AM · Feature Request, Documentation, gpgagent
mjb added a comment to T4273: agent: Request insertion of smartcard when no card present.

You're very welcome. In my instance, this is "resolved" - I now get the prompt I realised I needed so to me this bug could be considered closed or wontfix, but I'll leave you to do with it as you please.

Dec 19 2018, 3:54 AM · Feature Request, Documentation, gpgagent
gniibe added a comment to T4273: agent: Request insertion of smartcard when no card present.

Basically, you are right. In addition, gpg-agent asks scdaemon about list of card/token.

Dec 19 2018, 3:47 AM · Feature Request, Documentation, gpgagent
mjb added a comment to T4273: agent: Request insertion of smartcard when no card present.

OK - so if an entry is not required in sshcontrol for a smart-card key - is the private key stub sufficiently detailed enough for the agent to realise that it can ask for that card to be inserted for an ssh connection?

Dec 19 2018, 3:35 AM · Feature Request, Documentation, gpgagent
gniibe added a comment to T4273: agent: Request insertion of smartcard when no card present.

sshcontrol entry is required for non-smartcard keys, but not for keys on smartcard. This is intentional. For gpg-agent and current format, it is only the information for gpg-agent to know if a key is for SSH or not.

Dec 19 2018, 3:31 AM · Feature Request, Documentation, gpgagent
mjb added a comment to T4273: agent: Request insertion of smartcard when no card present.

Also - going back to sshcontrol - with an ssh key added to the agent with ssh-add, an entry in sshcontrol is required - but not for a key on a smartcard. Is that intentional, or just a byproduct of the smartcard diversion that happens?

Dec 19 2018, 3:22 AM · Feature Request, Documentation, gpgagent
mjb added a comment to T4273: agent: Request insertion of smartcard when no card present.

Oh, wow - yes, adding to sshcontrol brings up the prompt - I do however need to stop the agent from being restarted on insertion for it to subsequently ask for the unlock.

Dec 19 2018, 3:09 AM · Feature Request, Documentation, gpgagent
gniibe added a comment to T4288: Add getrandom support for the BSDs.

OpenBSD uses getentropy(2). glibc (>= 2.25) has getentropy(3), too.

Dec 19 2018, 2:59 AM · libgcrypt
gniibe committed rC3028a221d39c: random: Add finalizer for rndjent. (authored by gniibe).
random: Add finalizer for rndjent.
Dec 19 2018, 2:58 AM
gniibe abandoned D461: jent random requires finalizer to deallocate secure memory.

Applied to master.

Dec 19 2018, 2:54 AM
gniibe removed a project from T4273: agent: Request insertion of smartcard when no card present: Windows.

I see your point. You are right. For SSH access, it just fails without asking insertion. It's not Windows specific.
I checked the change of history of gpg-agent, but I cannot find prompting insertion was supported.
So, I don't thin this is a regression.

Dec 19 2018, 2:52 AM · Feature Request, Documentation, gpgagent
mjb added a comment to T4273: agent: Request insertion of smartcard when no card present.

Yes, it's running. I have a scheduled task that spawns a vbscript to ensure that gpg-agent is started on login, and restarts it on insertion of a card (specifically for two reasons: windows ssh clients don't typically start agents automatically, and windows can cause gpg-agent to get a but upset after a card is removed and re-inserted. Edit: although, I think that latter reason might be resolved now... I haven't investigated deeply. more info here and here).

Dec 19 2018, 2:34 AM · Feature Request, Documentation, gpgagent
gniibe added a comment to T3731: gcry_pk_genkey() segfaults for ecdsa 384.

For the correctness of rndjent implementation, I'm applying D461: jent random requires finalizer to deallocate secure memory.

Dec 19 2018, 2:27 AM · libgcrypt, Bug Report
gniibe added a comment to T4273: agent: Request insertion of smartcard when no card present.

Thanks for your information.
Hum, you are using gpg-agent for SSH access.

Dec 19 2018, 2:19 AM · Feature Request, Documentation, gpgagent
gniibe committed rG80a08b655f8f: agent: Fix message for ACK button. (authored by gniibe).
agent: Fix message for ACK button.
Dec 19 2018, 2:06 AM

Dec 18 2018

jmrexach added a comment to T4292: gpgsm: Problems with OCSP validation / No CRL known for OCSP Cert id-pkix-ocsp-nocheck?.

werner,
I'm the spanish user. Are you also setting default ocsp responder option?
Setting only ocsp_signer doesn't worked, there are several CA's with diferent ocsp responders.

Dec 18 2018, 8:19 PM · S/MIME
tnad renamed T4295: PGP/MIME emails not decrypted from PGP/MIME emaisl not decrypted to PGP/MIME emails not decrypted.
Dec 18 2018, 3:34 PM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4292: gpgsm: Problems with OCSP validation / No CRL known for OCSP Cert id-pkix-ocsp-nocheck?.

The reporter said that it did not work for him.

Dec 18 2018, 2:44 PM · S/MIME
werner lowered the priority of T4200: Evaluate sub-addresses in gpg and wkd from High to Normal.
Dec 18 2018, 9:30 AM · gnupg, Feature Request
werner created T4296: Release libgpg-error 1.34.
Dec 18 2018, 9:17 AM · Release Info, gpgrt
werner committed rG21fc08914867: Silence compiler warnings new with gcc 8. (authored by werner).
Silence compiler warnings new with gcc 8.
Dec 18 2018, 9:13 AM
werner committed rG16424d8a34c7: wks: Do not use compression for the encrypted data. (authored by werner).
wks: Do not use compression for the encrypted data.
Dec 18 2018, 9:13 AM
werner committed rG70a8db0333e3: wks: Do not use compression for the encrypted data. (authored by werner).
wks: Do not use compression for the encrypted data.
Dec 18 2018, 8:24 AM
werner committed rD1849053f2930: swdb: Update sqlite (authored by werner).
swdb: Update sqlite
Dec 18 2018, 7:53 AM