Page MenuHome GnuPG
Feed Advanced Search

Oct 6 2021

werner committed rG323a20399d90: dirmngr: New option --ignore-cert (authored by werner).
dirmngr: New option --ignore-cert
Oct 6 2021, 11:58 AM
mfilippov awarded T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent a Like token.
Oct 6 2021, 11:24 AM · Not A Bug, workaround, gnupg24, Windows, ssh
werner committed rG687993788597: dirmngr: Fix Let's Encrypt certificate chain validation. (authored by werner).
dirmngr: Fix Let's Encrypt certificate chain validation.
Oct 6 2021, 10:41 AM
werner committed rG4b3e9a44b58e: dirmngr: New option --ignore-cert (authored by werner).
dirmngr: New option --ignore-cert
Oct 6 2021, 10:41 AM
werner triaged T5639: dirmngr uses the wrong Let's encrypt chain as High priority.
Oct 6 2021, 9:23 AM · gnupg (gpg22), dirmngr

Oct 5 2021

werner added a subtask for T5175: Kleopatra: Add support for custom groups: T5638: Make Kleopatra group configuration exportable.
Oct 5 2021, 4:37 PM · Restricted Project, kleopatra
werner added a parent task for T5638: Make Kleopatra group configuration exportable: T5175: Kleopatra: Add support for custom groups.
Oct 5 2021, 4:37 PM · Restricted Project, Feature Request, kleopatra
werner triaged T5638: Make Kleopatra group configuration exportable as High priority.
Oct 5 2021, 4:36 PM · Restricted Project, Feature Request, kleopatra

Oct 4 2021

werner moved T5433: libgcrypt: Do not use SHA1 by default from Backlog to Next on the FIPS board.
Oct 4 2021, 11:28 AM · FIPS, libgcrypt, Bug Report
werner moved T5617: fips: Check library integrity before running selftests from Backlog to Next on the FIPS board.
Oct 4 2021, 11:26 AM · FIPS, libgcrypt, Bug Report
werner moved T5550: Fix check_binary_integrity from Backlog to Next on the FIPS board.
Oct 4 2021, 11:26 AM · FIPS, libgcrypt
werner assigned T5617: fips: Check library integrity before running selftests to gniibe.
Oct 4 2021, 11:14 AM · FIPS, libgcrypt, Bug Report
werner moved T5600: Provide module name/version API for FIPS 140-3 from Backlog to Ready for release on the FIPS board.
Oct 4 2021, 11:13 AM · libgcrypt, FIPS, Bug Report
werner moved T5540: Update fipsdrv and cavs_driver.pl from Next to Ready for release on the FIPS board.
Oct 4 2021, 11:09 AM · FIPS, libgcrypt
werner raised the priority of T2385: support more than 1024 fds. from Normal to High.
Oct 4 2021, 11:08 AM · gpgrt, Feature Request, gpgme
werner added projects to T5584: gpg --list-packets lists wrong packets: gnupg (gpg22), backport.
Oct 4 2021, 10:13 AM · gnupg (gpg22), Bug Report

Oct 3 2021

werner claimed T5634: Failure with: make DESTDIR=xxx install .

Quite possibe and thanks for the report. However, this is a dev state of the things and thus not expected to work. I'll keep this open as a reminder for me, but in general I would prefer to get a report at the gnupg-devel ML.

Oct 3 2021, 5:45 PM · Bug Report
werner added a project to T5633: gpg key generation failure : MacOS.

Sorry, a hostname with slash is simply not allowed by IETF standards. Given that the hostname is part of temporary file names, you will run into an error. Yes, we could remap the slash in the mktemp function but there are lot of other plzces where the hostname is used and certain properties are expected.

Oct 3 2021, 12:32 PM · MacOS, Bug Report

Oct 1 2021

werner added projects to T5632: gpg-agent 2.3.2 conflicts with pcscd: gnupg (gpg23), scd.
Oct 1 2021, 6:15 PM · Not A Bug, yubikey, scd, gnupg (gpg23)
werner committed rG84fcd8e6eb7e: tests: Use the new gpgconf.ctl based method. (authored by werner).
tests: Use the new gpgconf.ctl based method.
Oct 1 2021, 4:07 PM
werner committed rG399ebf6d873d: build: Prepare for using installed versions for tests. (authored by werner).
build: Prepare for using installed versions for tests.
Oct 1 2021, 4:07 PM
werner committed rGdbe1b237a652: common: Support gpgconf.ctl also for BSDs. (authored by werner).
common: Support gpgconf.ctl also for BSDs.
Oct 1 2021, 4:07 PM
werner committed rGec847cf17fa8: common: Add keyword sysconfdir to the optional gpgconf.ctl file. (authored by werner).
common: Add keyword sysconfdir to the optional gpgconf.ctl file.
Oct 1 2021, 4:07 PM
werner added a comment to T5630: With GCC 4.2 gnupg-2.3.2/kbx/backend-support.c cannot be compiled Mac OS X 10.4.11, "Tiger".

Well this seems to be a gcc 4.2 bug. But well, forward declarations should go into a separate file so that tehre is only one place which would require changes. In this case it does not matter.

Oct 1 2021, 9:16 AM · gnupg (gpg23), Bug Report
werner closed T5626: 'GPGCONF --list-dirs' command option on-screen displayed results show '%3a' unexpected and unneeded characters in each line displaying a C: drive path instead of simpler expected '...:C:\...' sub-strings with only valid ':' ('colon') characters present as Resolved.
Oct 1 2021, 8:38 AM · gnupg (gpg22), UI, Not A Bug, gpg4win

Sep 29 2021

werner triaged T5629: gpg-wks-client should also print direct method URL as Normal priority.

Requires a new option or command.

Sep 29 2021, 5:28 PM · gnupg24, Feature Request, gnupg (gpg23), wkd
werner closed T5626: 'GPGCONF --list-dirs' command option on-screen displayed results show '%3a' unexpected and unneeded characters in each line displaying a C: drive path instead of simpler expected '...:C:\...' sub-strings with only valid ':' ('colon') characters present as Resolved.

Sorry, I can't read all your comments about this. The percent escaping is correct and required. If you want to use the output in a script you can get it without percent escaping by using for example

Sep 29 2021, 11:36 AM · gnupg (gpg22), UI, Not A Bug, gpg4win

Sep 28 2021

werner triaged T5594: some possible minor things in the manpage as Low priority.

Please don't, if you really feel like tha tis not resolved please re-open this ticket.

Sep 28 2021, 11:03 PM · Documentation, gnupg, Bug Report
werner triaged T5625: 'GPG -v --ver', 'GPG --verify' and 'GPG -v --verify' commands output show on screen error messages without proper 'è' Italian accented letter as Normal priority.

That pretty much looks like the other errors you have with Unicode characters - which we can't replicate.

Sep 28 2021, 11:01 PM · i18n, Bug Report, gpg4win
werner triaged T5627: 'SHA256SUM -?' or '...-help' incorrectly shows SHA1SUM name when displaying own command syntax as Wishlist priority.

This is all build from the same source. We could fix that but I'll give that a lo priority. Thanks for reporting.

Sep 28 2021, 10:58 PM · Bug Report, gpg4win
werner closed T5626: 'GPGCONF --list-dirs' command option on-screen displayed results show '%3a' unexpected and unneeded characters in each line displaying a C: drive path instead of simpler expected '...:C:\...' sub-strings with only valid ':' ('colon') characters present as Resolved.
Sep 28 2021, 10:56 PM · gnupg (gpg22), UI, Not A Bug, gpg4win
werner edited projects for T5626: 'GPGCONF --list-dirs' command option on-screen displayed results show '%3a' unexpected and unneeded characters in each line displaying a C: drive path instead of simpler expected '...:C:\...' sub-strings with only valid ':' ('colon') characters present, added: Not A Bug; removed Bug Report.

That's correct - The output needs to be percent escaped.

Sep 28 2021, 10:56 PM · gnupg (gpg22), UI, Not A Bug, gpg4win
werner created T5624: Prefill the search on server entry field in Kleopatra.
Sep 28 2021, 4:04 PM · Restricted Project, kleopatra, Feature Request
werner added projects to T5623: gpg2 hangs on many tasks on OpenIndiana (Illumos): gnupg (gpg23), Solaris.

Just to be sure. please provide the output of

Sep 28 2021, 12:13 PM · Solaris, gnupg (gpg23)
werner added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

Lots of detailed documentation but frankly, after a brief read I have not yet figured out what it really does. We won't support Cygwin stuff - this is all obsolete and awe also removed starting gpg-agent as a service for good reasons. Instead of starting gpg-agent with lot of command line args it would be better to put this into a per user or system wide config file.

Sep 28 2021, 10:13 AM · Not A Bug, workaround, gnupg24, Windows, ssh

Sep 27 2021

werner assigned T5584: gpg --list-packets lists wrong packets to gniibe.
Sep 27 2021, 10:19 AM · gnupg (gpg22), Bug Report
werner triaged T5584: gpg --list-packets lists wrong packets as High priority.
Sep 27 2021, 10:12 AM · gnupg (gpg22), Bug Report
werner committed rCdb928d97b4b6: tests: Remove old CAVS test scripts. (authored by werner).
tests: Remove old CAVS test scripts.
Sep 27 2021, 9:10 AM
werner moved T5520: Fix tests in FIPS mode from Next to Ready for release on the FIPS board.
Sep 27 2021, 8:36 AM · FIPS, libgcrypt, Bug Report

Sep 26 2021

grv87 awarded T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent a Like token.
Sep 26 2021, 5:03 AM · Not A Bug, workaround, gnupg24, Windows, ssh

Sep 23 2021

werner updated subscribers of T5574: Doubled characters in Windows console output.

That looks all pretty standard. I don't know what's going on. I need to be able to replicate it here.

Sep 23 2021, 5:26 PM · gnupg, Windows, Bug Report
werner added a comment to T5574: Doubled characters in Windows console output.

Sorry, I am not abale to replicate this with standard version of gpg. Hwoever, the portable version only changes the directories and nothing at the output code paths. THus I really wonder what's going on here. Note that the spaces used to indent the "mittels ..." are also missing.

Sep 23 2021, 8:46 AM · gnupg, Windows, Bug Report

Sep 22 2021

werner triaged T5616: asn1-parse.y:861:20: error: 'yytoknum' undeclared as Normal priority.
Sep 22 2021, 9:55 PM · toolchain, libksba, Bug Report
werner closed T5618: GPG Key Server Doesn´t Work as Resolved.

Ah well, Kleopatra has a GUI to set the keyserver - that is probably easier to use.

Sep 22 2021, 7:17 PM · Support, FAQ, Keyserver, gpg4win
werner added a comment to T5618: GPG Key Server Doesn´t Work.

The keyserver network has been shutdown a couple of months ago. We can't do anything about it. The default in newer gpg versions has changed; you may put

Sep 22 2021, 7:14 PM · Support, FAQ, Keyserver, gpg4win
werner added a comment to T5613: GpgEX does not use CSIDL_LOCAL_APPDATA.

Okay.

Sep 22 2021, 4:59 PM · Windows, kleopatra, gpgex
werner added a comment to T5613: GpgEX does not use CSIDL_LOCAL_APPDATA.

We want to deprecate the whole UI-Server thing and thus I considered it better to provide the generic socket dir instead of adding support in libkleo for the uiserver socket. For the time being, doing this in Kleopatra sounds better to me. From my understanding. libkleo shall be an interface to gpgme++, right?

Sep 22 2021, 4:10 PM · Windows, kleopatra, gpgex
werner committed rDee3cb0d8137c: swdb: GpgEX 1.0.8 (authored by werner).
swdb: GpgEX 1.0.8
Sep 22 2021, 3:44 PM
werner closed T5614: invalid certificate for https://bugs.gnupg.org as Resolved.

Since the migration to a new machine with lots of config changes this spring the redirect rules for bugs.gnupg.org were not properly adjusted and when running into an error, it seems that the admin back then ignored the problem and simply removed bugs.gnupg.org from dehydrated's list of domains. Thanks again for reporting. Should now work again.

Sep 22 2021, 2:56 PM · dev.gnupg.org, Bug Report
werner added a comment to T5614: invalid certificate for https://bugs.gnupg.org.

Sorry for your troubles but we need to protect against spam - a tracker flooded with spam is useless.

Sep 22 2021, 2:13 PM · dev.gnupg.org, Bug Report
werner added a project to T5616: asn1-parse.y:861:20: error: 'yytoknum' undeclared: libksba.

Sorry, I don't know which software has version 12.0.0 and which git master this is. In case this is stock libksba, please tell us at least the last commit id. Note that we in general do not support arbitrary versions from the repos but only released versions .

Sep 22 2021, 2:09 PM · toolchain, libksba, Bug Report
werner committed rX0b7556fa662e: Take UI-Server socket from gpgconf. (authored by werner).
Take UI-Server socket from gpgconf.
Sep 22 2021, 12:38 PM
werner committed rXe16578cf690a: Post release updates (authored by werner).
Post release updates
Sep 22 2021, 12:38 PM
werner committed rXf617777da07d: Remove unused functions (authored by werner).
Remove unused functions
Sep 22 2021, 12:38 PM
werner committed rX5069a113733d: Release 1.0.8 (authored by werner).
Release 1.0.8
Sep 22 2021, 12:38 PM
werner placed T5613: GpgEX does not use CSIDL_LOCAL_APPDATA up for grabs.
Sep 22 2021, 12:25 PM · Windows, kleopatra, gpgex
werner added a comment to T5613: GpgEX does not use CSIDL_LOCAL_APPDATA.

For Kleopatra this patch


should be sufficient. Take care this is fully untested and not very elegant.

Sep 22 2021, 12:24 PM · Windows, kleopatra, gpgex
werner added a comment to T5613: GpgEX does not use CSIDL_LOCAL_APPDATA.

It will be useful to have support in libkleo:

.

Sep 22 2021, 10:41 AM · Windows, kleopatra, gpgex

Sep 21 2021

werner closed T5615: pgpme fails compiling: void value not ignored as Resolved.

Please see T5587

Sep 21 2021, 8:44 PM · gpgme, Duplicate, Bug Report
werner added a comment to T5611: 2.3.2: test suite is failing.

Here is James' writeup on the use https://gnupg.org/blog/20210315-using-tpm-with-gnupg-2.3.html . For more details please consult the mailing lists and the commit messages.

Sep 21 2021, 8:30 PM · Support, gnupg (gpg23)
werner triaged T5613: GpgEX does not use CSIDL_LOCAL_APPDATA as High priority.
Sep 21 2021, 4:16 PM · Windows, kleopatra, gpgex
werner added a comment to T5512: Implement service indicators.

Tsss, requires to allow JS for Google.

Sep 21 2021, 3:20 PM · Feature Request, FIPS, libgcrypt
werner added projects to T5611: 2.3.2: test suite is failing: gnupg (gpg23), Support.

Ich you do not have a working TPM or emulation but the tpm libraries installed run configure with the option

--disable-tpm2d
Sep 21 2021, 3:17 PM · Support, gnupg (gpg23)
werner updated the task description for T5611: 2.3.2: test suite is failing.
Sep 21 2021, 3:14 PM · Support, gnupg (gpg23)
werner added a comment to T5610: macOS 11 or newer support: Update libtool.

That does indeed not look like something which could introduce a regression.

Sep 21 2021, 11:43 AM · gpgme, MacOS, ntbtls, npth, libksba, libassuan, libgcrypt, gpgrt
werner closed T5608: Encryption using python for international characters not working properly as Wontfix.

GnuPG 2.0 reached end-of-life nearly 4 years ago. See https://gnupg.org/download/index.html#end-of-life . Same for Gpg4win. They are not maintained and its use is very risky due to unfixed bugs. Please update to a recent version.

Sep 21 2021, 8:47 AM · gnupg (gpg20), Too Old, Python, Bug Report
werner triaged T5610: macOS 11 or newer support: Update libtool as Low priority.

macOS has low priority for us and I do not want to risk any regression.

Sep 21 2021, 8:42 AM · gpgme, MacOS, ntbtls, npth, libksba, libassuan, libgcrypt, gpgrt

Sep 20 2021

werner added a comment to T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key'.

@amit: Do you say it used to work with GnuPG 2.2.27 or did it worked with an older version?

Sep 20 2021, 7:43 PM · Support, Info Needed, gnupg (gpg22)
werner added projects to T5608: Encryption using python for international characters not working properly: gnupg, Python.

Which gpg version?
Which Python library? (gnupg is pretty generic)
How does the Python library call gpg?
Are you aware that gpg uses utf8 and not Windows Unicode?

Sep 20 2021, 7:40 PM · gnupg (gpg20), Too Old, Python, Bug Report
werner renamed T5609: keydb_get_keyblock failed with cv448 key from gpg: keydb_get_keyblock failed: Invalid object to keydb_get_keyblock failed with cv448 key .
Sep 20 2021, 7:35 PM · Restricted Project, OpenPGP, gnupg (gpg23)
werner added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

Well, while importing you get the warning:

Sep 20 2021, 4:08 PM · Support, gnupg, OpenPGP
werner added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

Yes, for migration from GnuPG 2.0 reasons, a batch import delays the key checking (i.e. converting from OpenPGP to GnuPG internal format) to the first use. Thus you don't see an error immediately. But if you encrypt something , you won't be able to decrypt it again:

Sep 20 2021, 4:00 PM · Support, gnupg, OpenPGP
werner added a comment to rKLEOPATRA107abfdb1a41: Hide create openpgp key from card command for <2.3.

FWIW: I tested it with a freshly created card and thus keys. When hitting the "create OpenPGP Key " button, a warning was shown that a key already exists, I selected the do-anyway thing but the created keys had different fingerprints then. Thus the creation time was not taken in account. I recall that I implemented this for gpg-card and thus only for 2.3 - it is just quite likely that it does not work for 2.2.

Sep 20 2021, 1:31 PM
werner changed the status of T5600: Provide module name/version API for FIPS 140-3 from Open to Testing.

Thanks. Applied with a minor change: The string is now in a new third field.

Sep 20 2021, 8:51 AM · libgcrypt, FIPS, Bug Report
werner committed rCc74fde0c3f61: Allow passing FIPS module version (authored by Jakuje).
Allow passing FIPS module version
Sep 20 2021, 8:51 AM
werner committed rC3f4dd47ba74e: Remove the forced fips mode (authored by Jakuje).
Remove the forced fips mode
Sep 20 2021, 8:51 AM
werner committed rCedbc1dd10bc3: Remove a way to inactive FIPS mode (authored by Jakuje).
Remove a way to inactive FIPS mode
Sep 20 2021, 8:51 AM
werner closed T5606: 2.3.2: compile and link time warnings as Resolved.

Thanks for reporting. However, many gcc warnings produce a lot of false positives. Thus to be useful all the warnings need to be scrutinized. Let's do this for one example

Sep 20 2021, 8:49 AM · Bug Report

Sep 19 2021

werner claimed T5600: Provide module name/version API for FIPS 140-3.
Sep 19 2021, 1:05 PM · libgcrypt, FIPS, Bug Report

Sep 17 2021

werner added a comment to T5599: Make gpg use the helpers baked into its AppImage.

The actual patch is rGd4768bb982adb5c8410303334ee8d82ba0d71f3b (our parser in dev.gnupg.org missed to pick up the bug-id due to teh use of scissor lines in the commit message).

Sep 17 2021, 5:58 PM · gnupg, Restricted Project, Feature Request
werner committed rGd4768bb982ad: common: Support a gpgconf.ctl file under Unix. (authored by werner).
common: Support a gpgconf.ctl file under Unix.
Sep 17 2021, 5:43 PM
werner committed rG9c272dc24545: common: New function substitute_envvars. (authored by werner).
common: New function substitute_envvars.
Sep 17 2021, 5:43 PM
werner committed rDe12aeb7a150b: web: New versions of the AD ldap schemes. (authored by werner).
web: New versions of the AD ldap schemes.
Sep 17 2021, 2:49 PM
werner added projects to T5590: OpenPGP: Curve 448, modernize?: gnupg (gpg23), OpenPGP.
Sep 17 2021, 11:07 AM · rationale, gnupg, OpenPGP
werner triaged T5604: Kleopatra clipboard allows to process an empty message as Low priority.
Sep 17 2021, 10:56 AM · kleopatra
werner added a project to T5603: Kleopatra button "change passphrase" is not disabled for cards.: token.
Sep 17 2021, 10:52 AM · token, kleopatra
werner created token.
Sep 17 2021, 10:52 AM
werner triaged T5603: Kleopatra button "change passphrase" is not disabled for cards. as Low priority.
Sep 17 2021, 10:51 AM · token, kleopatra
werner closed T5551: gpg-agent: DISPLAY is not set when calling pinentry-qt as Resolved.

Thanks for commenting. I close this bug then.

Sep 17 2021, 8:07 AM · qt, pinentry, gnupg
werner added a comment to T5560: gpg.exe interrupt batch execution in WindowsXp.

Remember to always pass --batch for unattended operations.

Sep 17 2021, 8:02 AM · Windows, gnupg (gpg22), Bug Report
werner added a comment to T4894: FIPS: RSA/DSA/ECDSA are missing hashing operation.

Having hash-algo in the s-exp is useful because a hash handle may carry several hashes. This is sometimes useful if you do not know the hash algorithm in advance and you need to make a guess (various PGP compatibility things in gpg). But of course we can simplify this and use the default algo from the hash handle if hash-algo is missing.

Sep 17 2021, 7:59 AM · FIPS, libgcrypt, Feature Request

Sep 16 2021

werner added a comment to T5519: Release GnuPG 2.2.30.

I introduced a regression in this version; if you run into problems please update to 2.3.31 (T5571)

Sep 16 2021, 12:32 PM · Release Info, gnupg (gpg22)
werner closed T5571: Release GnuPG 2.2.31 as Resolved.
Sep 16 2021, 12:31 PM · Release Info, gnupg (gpg22)
werner committed rD5debdcd7a4ad: swdb: GnuPG 2.2.31 (authored by werner).
swdb: GnuPG 2.2.31
Sep 16 2021, 12:00 PM
werner committed rGecf4c2f61123: Release 2.2.31 (authored by werner).
Release 2.2.31
Sep 16 2021, 11:56 AM
werner committed rG48dc463adacf: Post release updates (authored by werner).
Post release updates
Sep 16 2021, 11:56 AM
werner committed rG6eb6304c040a: po: Change German descriptions for password constraints. (authored by werner).
po: Change German descriptions for password constraints.
Sep 16 2021, 11:56 AM
werner triaged T5601: Release GnuPG 2.2.32 as Low priority.
Sep 16 2021, 11:53 AM · Release Info, gnupg (gpg22)
werner claimed T5599: Make gpg use the helpers baked into its AppImage.
Sep 16 2021, 11:23 AM · gnupg, Restricted Project, Feature Request
werner added a comment to T5598: AppImage of gpg.

Some quick ideas: On Windows we have envvars (and APIs) to determine certain locations. There is also the registry. We use of all them. IT would be best to do this simalar on Unix. We also have a control file on Windows which switches to that portable mode; maybe it is best to do this also on Unix - A text file installed alongside gpg which gpg (common/homedir.c) uses to enable the use of certain envvars to locate the root etc..

Sep 16 2021, 10:05 AM · AppImage, gnupg, Restricted Project, Feature Request