Page MenuHome GnuPG
Feed Advanced Search

Apr 15 2021

werner added a project to T4673: 2.3-only: Don't fallback to PC/SC on failure by the internal CCID driver, only use PC/SC when --disable-ccid is specified: gnupg (gpg23).
Apr 15 2021, 8:39 AM · gnupg (gpg23), Restricted Project, scd, Feature Request

Apr 14 2021

werner triaged T5395: libksba coverity static analysis reports as Normal priority.
Apr 14 2021, 8:59 PM · libksba, Bug Report

Apr 13 2021

werner added a comment to T5393: gnupg coverity static analysis reports.

Regarding the identical branches thing: This is on purpose. The function works closely together with another one which will then BUG() out. @Jakuje: If you know some meta comment to attribute this, please let me know.

Apr 13 2021, 7:11 PM · gnupg (gpg23), Bug Report
werner added a comment to T5393: gnupg coverity static analysis reports.

@gniibe: If you don't mind I would like to steal task this from you. I have noticed a few things which could get a little code refresh in addition to the fixes.

Apr 13 2021, 6:57 PM · gnupg (gpg23), Bug Report
werner added a comment to T4884: PKCS #15 support in gpgsm.

The PKCS#15 support has meanwhile received a major update. Thus we need to test with the other cards again. If there is something special for to do for a certain task, a new subtask should be created.

Apr 13 2021, 6:43 PM · Feature Request, gnupg, scd, S/MIME
werner added a subtask for T4884: PKCS #15 support in gpgsm: Unknown Object (Maniphest Task).
Apr 13 2021, 6:41 PM · Feature Request, gnupg, scd, S/MIME
werner removed a parent task for T4884: PKCS #15 support in gpgsm: Unknown Object (Maniphest Task).
Apr 13 2021, 6:41 PM · Feature Request, gnupg, scd, S/MIME
werner added a parent task for T4884: PKCS #15 support in gpgsm: Unknown Object (Maniphest Task).
Apr 13 2021, 6:40 PM · Feature Request, gnupg, scd, S/MIME
werner closed T5387: Accept key signatures from LDAP servers as Resolved.

Done for 2.2. and 2.3.

Apr 13 2021, 2:56 PM · Feature Request, gnupg (gpg22)
werner committed rG1303b0ed84da: gpg: Do not use self-sigs-only for LDAP keyserver imports. (authored by werner).
gpg: Do not use self-sigs-only for LDAP keyserver imports.
Apr 13 2021, 2:51 PM
werner committed rG6c26e593df51: gpg: Do not use self-sigs-only for LDAP keyserver imports. (authored by werner).
gpg: Do not use self-sigs-only for LDAP keyserver imports.
Apr 13 2021, 2:47 PM
werner triaged T5394: scute: Build failure with slibtool as Normal priority.
Apr 13 2021, 8:13 AM · toolchain, Feature Request, scute

Apr 12 2021

werner added a comment to T5394: scute: Build failure with slibtool.

Regarding slibtool: I would actually like to have an easier to maintain tool than libtool (of which we use our own version) for GnuPG related software. However, its requirement "the compiler should support -std=c99" is currently a no-starter for libgcrypt and some other libs.

Apr 12 2021, 11:25 PM · toolchain, Feature Request, scute
werner committed rGd984de172c29: gpg: Minor restructuring of a function. (authored by werner).
gpg: Minor restructuring of a function.
Apr 12 2021, 5:50 PM
werner committed rGecb9265b8dc0: scd:p15: Match private keys with certificates also by labels. (authored by werner).
scd:p15: Match private keys with certificates also by labels.
Apr 12 2021, 5:50 PM
werner closed T5391: Website FAQ missing charset as Wontfix.

No Apache - No Default charset per suffix. The version for browsers is the HTML version.

Apr 12 2021, 5:43 PM · gpgweb, FAQ

Apr 9 2021

werner added projects to T4823: Test Yubikey's support for ed25519: yubikey, gnupg (gpg23).
Apr 9 2021, 8:30 PM · gnupg24, gnupg (gpg23), yubikey
werner added a comment to T5328: On the (in)security of Elgamal in OpenPGP.

This would be difficult to set up for DSA. Remotely controlled
environment, asking signing same message, using deterministic
DSA... would be not that practical.

Apr 9 2021, 7:15 PM · side-channel, CVE, libgcrypt
werner committed rG51395dbebd43: build: Change version tag also in getswdb.sh (authored by werner).
build: Change version tag also in getswdb.sh
Apr 9 2021, 6:53 PM
werner triaged T5387: Accept key signatures from LDAP servers as High priority.
Apr 9 2021, 12:25 PM · Feature Request, gnupg (gpg22)

Apr 8 2021

werner committed rG22fd48e48d00: scd: Fix duplicate output of KEYPAIRINFO by readkey command. (authored by werner).
scd: Fix duplicate output of KEYPAIRINFO by readkey command.
Apr 8 2021, 7:33 PM
werner committed rG63320ba2f814: scd:nks: Handle APP_READKEY_FLAG_INFO. (authored by werner).
scd:nks: Handle APP_READKEY_FLAG_INFO.
Apr 8 2021, 7:33 PM
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2021q2/000458.html on T5343: Release GnuPG 2.3.0.
Apr 8 2021, 11:10 AM · Release Info, gnupg (gpg23)

Apr 7 2021

werner committed rDcc0a0fc9b364: web: Minor fix. (authored by werner).
web: Minor fix.
Apr 7 2021, 9:13 PM
werner closed T5343: Release GnuPG 2.3.0 as Resolved.
Apr 7 2021, 9:09 PM · Release Info, gnupg (gpg23)
werner updated the task description for T5343: Release GnuPG 2.3.0.
Apr 7 2021, 9:09 PM · Release Info, gnupg (gpg23)
werner committed rDe72fbc5bb042: swdb: GnuPG 2.3.0 (authored by werner).
swdb: GnuPG 2.3.0
Apr 7 2021, 9:03 PM
werner committed rGf88d6a5279cb: Post release updates (authored by werner).
Post release updates
Apr 7 2021, 8:49 PM
werner committed rGc922a798a341: Release GnuPG 2.3.0 (authored by werner).
Release GnuPG 2.3.0
Apr 7 2021, 8:49 PM
werner triaged T5386: Release GnuPG 2.3.1 as Normal priority.
Apr 7 2021, 8:44 PM · gnupg (gpg23), Release Info
werner triaged T5385: libgcrypt coverity static analysis reports as Low priority.

Yes, will be fixed but it has no severity because the fault is actually by the caller.

Apr 7 2021, 6:22 PM · libgcrypt, Bug Report
werner added a project to T5380: Tools needed during a build lack of CFLAGS was passed durring configure time: MacOS.

Sorry, I can't parse your message. Please describe the problem or feature requests. Referencing external patches is not sufficient. What is vcpkg?

Apr 7 2021, 12:23 PM · MacOS, Bug Report

Apr 6 2021

werner added a project to T5381: libgpg-error coverity static analysis reports: gpgrt.

Actually I don't care about releasing resources for regression test failures.
The other missing free is for code which is commented out (#if 0) but should eventually be fixed.

Apr 6 2021, 11:29 PM · gpgrt, Bug Report
werner committed rD72877bb4ab3d: swdb: libksba 1.5.1 (authored by werner).
swdb: libksba 1.5.1
Apr 6 2021, 12:48 PM
werner committed rK1015bea2f8a5: Release 1.5.1 (authored by werner).
Release 1.5.1
Apr 6 2021, 12:27 PM
werner committed rK88392670f4e5: Post release updates (authored by werner).
Post release updates
Apr 6 2021, 12:27 PM
werner committed rK105093943554: build: Add the usual release targets. (authored by werner).
build: Add the usual release targets.
Apr 6 2021, 12:27 PM
werner triaged T5369: GnuPG build on Apple with Clang as Low priority.
Apr 6 2021, 12:10 PM · libgcrypt, MacOS, Bug Report
werner closed T5379: Release Libksba 1.5.1 as Resolved.
Apr 6 2021, 12:09 PM · libksba, Release Info
werner triaged T5379: Release Libksba 1.5.1 as Low priority.
Apr 6 2021, 11:40 AM · libksba, Release Info
werner triaged T5377: pinentry-qt dialog cannot be raised under Linux/Wayland as Normal priority.
Apr 6 2021, 9:56 AM · pinentry, Bug Report
werner committed rGe0eefba56c16: doc: Add some error locations to DETAILS. (authored by werner).
doc: Add some error locations to DETAILS.
Apr 6 2021, 9:55 AM
werner committed rG18551c6dc2c3: gpg: Fix new pseudo option compliance_de_vs (authored by werner).
gpg: Fix new pseudo option compliance_de_vs
Apr 6 2021, 9:34 AM
werner added a comment to T5371: Handle invalid compliance settings.

with the next GnuPG version (2.2.28 and 2.3.0) you can do a read

Apr 6 2021, 9:25 AM · Feature Request, Restricted Project, kleopatra

Apr 4 2021

werner triaged T5347: Update Manual Kleopatra as Normal priority.
Apr 4 2021, 7:03 PM · Documentation, kleopatra

Apr 1 2021

werner committed rG8ef0f53cb001: common: Make the compliance check more robust. (authored by werner).
common: Make the compliance check more robust.
Apr 1 2021, 1:24 PM
werner committed rG9feffc03f364: gpgconf: Return a new pseudo option compliance_de_vs. (authored by werner).
gpgconf: Return a new pseudo option compliance_de_vs.
Apr 1 2021, 1:24 PM
werner committed rGa78475fbb7b6: gpgconf: Return a new pseudo option compliance_de_vs. (authored by werner).
gpgconf: Return a new pseudo option compliance_de_vs.
Apr 1 2021, 1:15 PM
werner committed rG1d1ec1146c04: common: Make the compliance check more robust. (authored by werner).
common: Make the compliance check more robust.
Apr 1 2021, 1:15 PM
werner added a comment to T5377: pinentry-qt dialog cannot be raised under Linux/Wayland.

Seems that it is not a coincidence that Wayland starts with a W like Windows. ;-)

Apr 1 2021, 12:28 PM · pinentry, Bug Report
werner added a project to T5370: Apple M1 and Symbol not found: __gcry_mpih_mul_1: arm.
Apr 1 2021, 11:07 AM · arm, MacOS, gnupg, Bug Report
werner created riscv.
Apr 1 2021, 11:07 AM
werner created ppc.
Apr 1 2021, 11:06 AM
werner created arm.
Apr 1 2021, 11:06 AM
werner created x86.
Apr 1 2021, 11:05 AM
werner triaged T5370: Apple M1 and Symbol not found: __gcry_mpih_mul_1 as Normal priority.
Apr 1 2021, 11:02 AM · arm, MacOS, gnupg, Bug Report
werner committed rGc727951a2440: card: New flag --reread for LIST. (authored by werner).
card: New flag --reread for LIST.
Apr 1 2021, 10:34 AM
werner committed rGe17d3f866057: scd:p15: New flag APP_LEARN_FLAG_REREAD. (authored by werner).
scd:p15: New flag APP_LEARN_FLAG_REREAD.
Apr 1 2021, 10:34 AM
werner committed rGff87f4e578f4: scd: New flag --reread for LEARN (authored by werner).
scd: New flag --reread for LEARN
Apr 1 2021, 10:34 AM

Mar 31 2021

werner committed rG1c16878efd0b: scd: Replace all assert macros by the log_assert macro. (authored by werner).
scd: Replace all assert macros by the log_assert macro.
Mar 31 2021, 7:17 PM
werner added a comment to T5328: On the (in)security of Elgamal in OpenPGP.

Our tentative plan is:

Mar 31 2021, 1:34 PM · side-channel, CVE, libgcrypt
werner added a comment to rSab05fb64c143: build: Bump mimimum required Automake version..

Good catch, we need to update at several places.

Mar 31 2021, 9:19 AM
werner committed rG6ca540715139: build: Require automake 1.16.3 (authored by werner).
build: Require automake 1.16.3
Mar 31 2021, 9:19 AM
werner added a comment to T5360: scute: -fcommon needed when building with gcc-10.

FWIW, in GnuPG we use

Mar 31 2021, 9:10 AM · scute

Mar 30 2021

werner triaged T5376: gpg --fetch-keys no longer returns non 0 exit status on failure as Normal priority.

You are coming pretty late to the party ;-). Since 2.1.0 we don't use the ancient keyserver helpers anymore but reworked the entire network access. I even doubt that I can still test with a 2.0 version.

Mar 30 2021, 8:16 PM · gnupg (gpg22), Bug Report
werner added a project to T5375: getentropy usage is forbidden by Apple, but is now being forced by libgcrypt: MacOS.
Mar 30 2021, 5:44 PM · MacOS, libgcrypt
werner changed the status of T5356: gnupg2 test failure on s390x from Open to Testing.
Mar 30 2021, 5:41 PM · libgcrypt, Bug Report
werner added a comment to T5356: gnupg2 test failure on s390x.

We have two or three other open issue which I would like to address before a release. FWIW, release ticket is T5305.

Mar 30 2021, 5:41 PM · libgcrypt, Bug Report
werner added a comment to T5370: Apple M1 and Symbol not found: __gcry_mpih_mul_1.

Do what ever you want with _gcry prefixed functions - this is never considered an API or ABI break. There are some exceptions for internal functions used by macros but those are clearly marked.

Mar 30 2021, 5:38 PM · arm, MacOS, gnupg, Bug Report
werner committed rG0d6f276f61c5: card: Print the key's label if available. (authored by werner).
card: Print the key's label if available.
Mar 30 2021, 5:29 PM
werner committed rG7f9126363265: scd:p15: Return labels for keys and certificates. (authored by werner).
scd:p15: Return labels for keys and certificates.
Mar 30 2021, 5:29 PM
werner added a comment to T5365: --with-libgpg-error-prefix doesn't affect gpgrt-config path detection.

A PATH with spaces is too Windowish (or macOS). IIRC, we had once checks that the used directories have proper names; we can expect this for build environment. Spaces in file names are horrible from a security POV it is just to easy to get things wrong (hello ssh).

Mar 30 2021, 5:15 PM · MacOS, gpgrt, Cross-Compiler, libgcrypt
werner committed rG651c07a7301c: scd:p15: For CardOS make use of ISO7816_VERIFY_NOT_NEEDED. (authored by werner).
scd:p15: For CardOS make use of ISO7816_VERIFY_NOT_NEEDED.
Mar 30 2021, 11:45 AM
werner committed rGde4d3c99aa58: scd:p15: Return the creation time of the keys. (authored by werner).
scd:p15: Return the creation time of the keys.
Mar 30 2021, 11:45 AM

Mar 29 2021

werner added projects to T5373: Using GCRY_THREAD_OPTION_PTHREAD_IMPL in a file compiled with Clang generates deprecation warning: libgcrypt, clang.

Yet another identify theft scam committed by clang.

Mar 29 2021, 10:22 PM · clang, libgcrypt, Bug Report
werner committed rG592f48011790: scd:p15: Make RSA with SHA512 work with CardOS. (authored by werner).
scd:p15: Make RSA with SHA512 work with CardOS.
Mar 29 2021, 8:36 PM
werner updated the task description for T5372: assertion failure mulm_25519: different sizes in Libgrypt 1.9.
Mar 29 2021, 4:01 PM · !assert, Bug Report, libgcrypt
werner updated the task description for T5372: assertion failure mulm_25519: different sizes in Libgrypt 1.9.
Mar 29 2021, 3:58 PM · !assert, Bug Report, libgcrypt
werner created T5372: assertion failure mulm_25519: different sizes in Libgrypt 1.9.
Mar 29 2021, 3:54 PM · !assert, Bug Report, libgcrypt
werner committed rG2d2391dfc25c: agent: Skip unknown unknown ssh curves seen on cards. (authored by werner).
agent: Skip unknown unknown ssh curves seen on cards.
Mar 29 2021, 3:41 PM
werner committed rGa494b29af9cc: scd:p15: Support ECDSA and ECDH for CardOS. (authored by werner).
scd:p15: Support ECDSA and ECDH for CardOS.
Mar 29 2021, 3:41 PM
werner committed rGf129b0e97730: gpg: Allow ECDH with a smartcard returning just the x-ccordinate. (authored by werner).
gpg: Allow ECDH with a smartcard returning just the x-ccordinate.
Mar 29 2021, 3:41 PM
werner closed T5368: warning: variable 'zlen' is uninitialized as Invalid.

Please look at the code:

Mar 29 2021, 8:30 AM · ntbtls, Bug Report

Mar 28 2021

werner closed T5363: GnuPG 2.3 Windows localized gpgconf output broken as Resolved.
Mar 28 2021, 7:18 PM · Windows, gnupg
werner committed rG18d884f8411a: gpgconf: Do not i18n an empty string to the PO files meta data. (authored by werner).
gpgconf: Do not i18n an empty string to the PO files meta data.
Mar 28 2021, 10:41 AM
werner added a comment to T5363: GnuPG 2.3 Windows localized gpgconf output broken.

yep, Should be fixed in libgpg-error/src/w32-gettext.c unless we want a way to retrieve the meat data. We can also and faster fix this in gnupg proper.

Mar 28 2021, 10:32 AM · Windows, gnupg

Mar 27 2021

werner closed T5367: PDF signed with --clearsign has image distorted. as Resolved.
Mar 27 2021, 11:29 AM · Not A Bug, FAQ
werner edited projects for T5367: PDF signed with --clearsign has image distorted., added: FAQ, Not A Bug; removed Bug Report.

--clearsign may only be used for plain text documents due to line ending conversion etc.

Mar 27 2021, 11:29 AM · Not A Bug, FAQ
werner closed T5366: "*** stack smashing detected ***" in test suite as Resolved.
Mar 27 2021, 11:27 AM · gnupg (gpg23)

Mar 26 2021

werner committed rGa5e72b663b36: tests: Make sure the built keyboxd is used by the tests. (authored by werner).
tests: Make sure the built keyboxd is used by the tests.
Mar 26 2021, 5:07 PM
werner committed rG057131159b44: gpgconf: Fix another argv overflow if --homedir is used. (authored by werner).
gpgconf: Fix another argv overflow if --homedir is used.
Mar 26 2021, 4:52 PM
werner committed rGd3d57a1bc88e: gpgconf: Fix argv overflow if --homedir is used. (authored by werner).
gpgconf: Fix argv overflow if --homedir is used.
Mar 26 2021, 2:54 PM
werner committed rG6de1ec3ba59f: agent: Add debug output for failed RSA signature verification (authored by werner).
agent: Add debug output for failed RSA signature verification
Mar 26 2021, 2:54 PM
werner committed rG6a80d6f9206e: indent: Modernize mem2str. (authored by werner).
indent: Modernize mem2str.
Mar 26 2021, 2:54 PM
werner committed rG935765b451aa: common: New function to uncompress an ECC public key. (authored by werner).
common: New function to uncompress an ECC public key.
Mar 26 2021, 2:54 PM
werner committed rGa50093893cd1: gpgconf: Fix argv overflow if --homedir is used. (authored by werner).
gpgconf: Fix argv overflow if --homedir is used.
Mar 26 2021, 2:54 PM
werner claimed T5366: "*** stack smashing detected ***" in test suite.
Mar 26 2021, 2:14 PM · gnupg (gpg23)
werner assigned T5365: --with-libgpg-error-prefix doesn't affect gpgrt-config path detection to gniibe.
Mar 26 2021, 10:47 AM · MacOS, gpgrt, Cross-Compiler, libgcrypt

Mar 24 2021

werner committed rCc8c38757c428: ecc: Fix keygrip computation for compressed points. (authored by werner).
ecc: Fix keygrip computation for compressed points.
Mar 24 2021, 10:33 PM
werner shifted T5328: On the (in)security of Elgamal in OpenPGP from the Restricted Space space to the S1 Public space.
Mar 24 2021, 2:50 PM · side-channel, CVE, libgcrypt