Page MenuHome GnuPG
Feed All Stories

Oct 20 2021

ikloecker committed rW82c7045a61da: Update patches for libkleo and kleopatra as in Gpg4win 3.1.x (authored by ikloecker).
Update patches for libkleo and kleopatra as in Gpg4win 3.1.x
Oct 20 2021, 4:16 PM
ikloecker committed rWc5f7f899ec87: Fix gettext lib name (authored by aheinecke).
Fix gettext lib name
Oct 20 2021, 4:16 PM
ikloecker committed rW09b4ba3a5a9a: Disable async encryption in GpgOL again (authored by ikloecker).
Disable async encryption in GpgOL again
Oct 20 2021, 4:16 PM
ikloecker committed rW4d294b62005e: Remove obsolete gpgol patch (authored by aheinecke).
Remove obsolete gpgol patch
Oct 20 2021, 4:16 PM
ikloecker committed rWaf01ddf90146: Make the patches executable before running them (authored by ikloecker).
Make the patches executable before running them
Oct 20 2021, 4:16 PM
ikloecker committed rW2d383330cf40: Use variables instead of hardcoded directory names (authored by ikloecker).
Use variables instead of hardcoded directory names
Oct 20 2021, 4:16 PM
ikloecker committed rW6cb15136e998: Configure for building gpg4win when running with --build-w32 (authored by ikloecker).
Configure for building gpg4win when running with --build-w32
Oct 20 2021, 4:16 PM
mfe added a comment to T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’.

Thanks! I was able to compile the current source code of npth (1.7) (with gcc 7.1. and ldd (GNU libc) 2.3.2 ). The error error: unknown type name ‘pthread_rwlock_t’ didn't occour.

Oct 20 2021, 4:03 PM · npth, Bug Report
ikloecker closed T5663: Kleopatra's "Check for updates" does not work as Resolved.

Okay. So the product prefix has been added intentionally to the version.

Oct 20 2021, 3:50 PM · Restricted Project, gpg4win, kleopatra
ikloecker moved T5663: Kleopatra's "Check for updates" does not work from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 20 2021, 3:49 PM · Restricted Project, gpg4win, kleopatra
ikloecker added a project to T5663: Kleopatra's "Check for updates" does not work: Restricted Project.
Oct 20 2021, 3:48 PM · Restricted Project, gpg4win, kleopatra
ikloecker added a comment to T5668: gpgme: gpgme_op_query_swdb() does not report error from gpgconf.

The below change makes the function report a general error if gpgconf didn't write any output on stdout:

diff --git a/src/engine-gpgconf.c b/src/engine-gpgconf.c
index 28f91158..21211366 100644
--- a/src/engine-gpgconf.c
+++ b/src/engine-gpgconf.c
@@ -1245,6 +1245,13 @@ gpgconf_query_swdb (void *engine,
         }
     }
Oct 20 2021, 3:45 PM · Restricted Project, gpgme, Bug Report
ikloecker created T5668: gpgme: gpgme_op_query_swdb() does not report error from gpgconf.
Oct 20 2021, 3:42 PM · Restricted Project, gpgme, Bug Report
ikloecker committed rLIBKLEO3a04f6a635c9: Add helper returning the version number of the Gpg4win release (authored by ikloecker).
Add helper returning the version number of the Gpg4win release
Oct 20 2021, 1:54 PM
ikloecker committed rLIBKLEOb72f5db872bd: Bump library version (authored by ikloecker).
Bump library version
Oct 20 2021, 1:54 PM
ikloecker committed rKLEOPATRAebf19c3f859c: Use the version _number_ for the check for updates (authored by ikloecker).
Use the version _number_ for the check for updates
Oct 20 2021, 1:30 PM
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

This commit changed the behaviour:
https://invent.kde.org/pim/libkleo/-/commit/bf7af017d84747d83ec16e0f8ab03b656899bfcd#c50ded182b9e04dd8e8c34c84c3bfd32ec2c5b46_149_214

Oct 20 2021, 1:17 PM · Restricted Project, gpg4win, kleopatra
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

When changing the filel contents of C:\Program Files (x86)\Gpg4win\VERSION from

Gpg4win-3.1.15

to

3.1.15

the update check works again.

Oct 20 2021, 1:09 PM · Restricted Project, gpg4win, kleopatra
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

rW4dcba538b74e2ad2d64adb4273176a4e4f85e599 changes the contents of the VERSION file as part of T5056 both on 2020-09-20.

Oct 20 2021, 12:57 PM · Restricted Project, gpg4win, kleopatra
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

Well spotted @ikloecker !

Oct 20 2021, 12:39 PM · Restricted Project, gpg4win, kleopatra
werner lowered the priority of T5546: Kleopatra: After importing the first pubkey for a card from LDAP the keylistview is not refreshed from Normal to Low.

Lets downgrade the priority and keep it open in case we get reports from customers. The other option would be to replicate this here using our AD demo network. But that is a bit time consuming.

Oct 20 2021, 12:26 PM · scd, Info Needed, Restricted Project, kleopatra
gniibe updated the task description for T5665: libgcrypt : Restrict message digest use for FIPS 140-3.
Oct 20 2021, 12:21 PM · FIPS, Bug Report, libgcrypt
werner closed T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys. as Resolved.

Yes, but it is more complicated to do because you need to download a binary version of the keys and check that they are authentic. Most users don't known it. Anyway, I meanwhile created a Brainpool release sign key and new VSD releases are signed with that. The override option does not really harm, but we can close this bug due to the new release key.

Oct 20 2021, 12:21 PM · gnupg (gpg22), Restricted Project
gniibe added a comment to T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

Perhaps, as a library (considering the benefit of users), it would be better to allow signature verification with SHA-1, to defer the decision to application.

Oct 20 2021, 12:20 PM · FIPS, Bug Report, libgcrypt
werner added a parent task for T5653: de-vs and GnuPG 2.3.3 error: T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant.
Oct 20 2021, 12:18 PM · Restricted Project, gnupg (gpg23), kleopatra
werner added a subtask for T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant: T5653: de-vs and GnuPG 2.3.3 error.
Oct 20 2021, 12:18 PM · Restricted Project, kleopatra
werner reassigned T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant from aheinecke to ikloecker.
Oct 20 2021, 12:16 PM · Restricted Project, kleopatra
ikloecker added a comment to T5663: Kleopatra's "Check for updates" does not work.

Well, the debug output

org.kde.pim.kleopatra: No update for: "Gpg4win-3.1.15"

and, even more clearly,

GPGME 20211019T134123 07DC        _gpgme_io_spawn: check: path=0x031deff0 argv[ 0] = C:\Program Files (x86)\GnuPG\bin\gpgconf.exe
GPGME 20211019T134123 07DC        _gpgme_io_spawn: check: path=0x031deff0 argv[ 1] = --query-swdb
GPGME 20211019T134123 07DC        _gpgme_io_spawn: check: path=0x031deff0 argv[ 2] = gpg4win
GPGME 20211019T134123 07DC        _gpgme_io_spawn: check: path=0x031deff0 argv[ 3] = Gpg4win-3.1.15

reveals that Kleopatra via gpgme ran the command

gpgconf --query-swdb gpg4win Gpg4win-3.1.15

i.e. that current is "Gpg4win-3.1.15".

Oct 20 2021, 11:53 AM · Restricted Project, gpg4win, kleopatra
justus created T5667: gpg(v) prints the human-readable form of notations to the status-fd.
Oct 20 2021, 11:48 AM · Bug Report
ikloecker reassigned T5546: Kleopatra: After importing the first pubkey for a card from LDAP the keylistview is not refreshed from ikloecker to aheinecke.

I tried to reproduce this. Experimentally, I added P15CardWidget::searchPGPFpr() to OpenPGPKeyCardWidget, commented out the code that checks for an LDAP keyserver and called the function with a fixed fingerprint.

Oct 20 2021, 11:20 AM · scd, Info Needed, Restricted Project, kleopatra
werner triaged T5666: Create dropdown box for the reader-port option. as Normal priority.
Oct 20 2021, 11:05 AM · Restricted Project, kleopatra, Feature Request
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

@ikloecker Note you can easily setup a test instance using one of Microsoft'S test VMs, see https://lists.wald.intevation.org/pipermail/gpg4win-devel/2021-October/001769.html

Oct 20 2021, 10:52 AM · Restricted Project, gpg4win, kleopatra
Alexander Lohnau <alexander.lohnau@gmx.de> committed rKLEOPATRA753d7796c199: Install service meus as executables (authored by Alexander Lohnau <alexander.lohnau@gmx.de>).
Install service meus as executables
Oct 20 2021, 10:49 AM
Jakuje added a comment to T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

Thank you for having a look into that. The change looks fine, but I need to get some clarification about what "Legacy use" means for "Digital signature verification" in the Table 8 of https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-131Ar2.pdf

Oct 20 2021, 10:34 AM · FIPS, Bug Report, libgcrypt
ikloecker claimed T5546: Kleopatra: After importing the first pubkey for a card from LDAP the keylistview is not refreshed.
Oct 20 2021, 10:32 AM · scd, Info Needed, Restricted Project, kleopatra
ikloecker moved T5546: Kleopatra: After importing the first pubkey for a card from LDAP the keylistview is not refreshed from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 20 2021, 10:32 AM · scd, Info Needed, Restricted Project, kleopatra
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

We should disable the menu button until it is fixed. I think it should be on the roadmap of 4.0 to have this working.

Oct 20 2021, 10:21 AM · Restricted Project, gpg4win, kleopatra
gniibe added a comment to T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’.

I have a little concern for glibc 2.34 (which has dummy libpthread and all is actually in libc).

Oct 20 2021, 9:57 AM · npth, Bug Report
Alexander Lohnau <alexander.lohnau@gmx.de> committed rKLEOPATRA9459a42a5229: Port service menus to new install location (authored by Alexander Lohnau <alexander.lohnau@gmx.de>).
Port service menus to new install location
Oct 20 2021, 9:55 AM
werner added a comment to T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’.

Okay, any thing else missing in nPth?

Oct 20 2021, 8:37 AM · npth, Bug Report
gniibe committed rCa23cf78102f3: cipher: Reject SHA-1 for hash+sign/verify when FIPS enabled. (authored by gniibe).
cipher: Reject SHA-1 for hash+sign/verify when FIPS enabled.
Oct 20 2021, 5:40 AM
gniibe added a comment to T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

(3-1) is implemented: rCa23cf78102f3: cipher: Reject SHA-1 for hash+sign/verify when FIPS enabled.

Oct 20 2021, 5:13 AM · FIPS, Bug Report, libgcrypt
gniibe updated the task description for T5665: libgcrypt : Restrict message digest use for FIPS 140-3.
Oct 20 2021, 4:28 AM · FIPS, Bug Report, libgcrypt
gniibe added a comment to T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

For a programmer like me, it is easier if the behavior will be:

Oct 20 2021, 4:26 AM · FIPS, Bug Report, libgcrypt
gniibe triaged T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’ as Normal priority.

It was fixed in: rPTH223e59f992f9: build: Define _NPTH_NO_RWLOCK when we can't find pthread_rwlock_t. and rPTH09a12a679ec0: Fix how we expose rwlock API.

Oct 20 2021, 3:36 AM · npth, Bug Report
gniibe added a comment to T5433: libgcrypt: Do not use SHA1 by default.

The problem is that the SHA-1 as a digest algorithm itself is allowed in FIPS mode (for non-cryptographic digests), but using it as part of approved signature scheme is not allowed

Oct 20 2021, 3:27 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

The current code is inconsistent about its behavior: how non-approved digest algos are supported or not when FIPS enabled.

Oct 20 2021, 3:17 AM · FIPS, Bug Report, libgcrypt
gniibe added projects to T5665: libgcrypt : Restrict message digest use for FIPS 140-3: libgcrypt, Bug Report, FIPS.

If .fips will mean FIPS 140-3, why not the following patch?

diff --git a/cipher/sha1.c b/cipher/sha1.c
index 3bb24c7e..cb50ef66 100644
--- a/cipher/sha1.c
+++ b/cipher/sha1.c
@@ -759,7 +759,7 @@ static gcry_md_oid_spec_t oid_spec_sha1[] =
Oct 20 2021, 3:07 AM · FIPS, Bug Report, libgcrypt
gniibe renamed T5244: libgcrypt: Restrict MD5 use from libgcrypt: Restrict message digest use to libgcrypt: Restrict MD5 use.
Oct 20 2021, 3:04 AM · Bug Report, FIPS, libgcrypt
gniibe added a project to T5244: libgcrypt: Restrict MD5 use: Bug Report.

I created T5665: libgcrypt : Restrict message digest use for FIPS 140-3.

Oct 20 2021, 3:03 AM · Bug Report, FIPS, libgcrypt
gniibe triaged T5665: libgcrypt : Restrict message digest use for FIPS 140-3 as High priority.
Oct 20 2021, 2:59 AM · FIPS, Bug Report, libgcrypt
gniibe removed a project from T5244: libgcrypt: Restrict MD5 use: Restricted Project.

Let me move this ticket as DONE (now Testing status), as the subject was solved (MD5 and soft/forced/inactive things).

Oct 20 2021, 2:54 AM · Bug Report, FIPS, libgcrypt

Oct 19 2021

ikloecker moved T5662: Kleopatra: Show a list of detected card readers from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 19 2021, 6:11 PM · Restricted Project, kleopatra, Feature Request
ikloecker closed T5662: Kleopatra: Show a list of detected card readers as Resolved.
Oct 19 2021, 6:11 PM · Restricted Project, kleopatra, Feature Request
bernhard committed rW79b59bc68c27: Add necessary update to GnuPG on next-steps (authored by bernhard).
Add necessary update to GnuPG on next-steps
Oct 19 2021, 5:48 PM
bernhard committed rW8971e11e86c3: Fix minor typo in package-integrity.htm4 (authored by bernhard).
Fix minor typo in package-integrity.htm4
Oct 19 2021, 5:48 PM
bernhard committed rWa04ea8900992: Move "What's new version 3" to about history (authored by bernhard).
Move "What's new version 3" to about history
Oct 19 2021, 5:39 PM
werner added a comment to T5662: Kleopatra: Show a list of detected card readers.

Yeah, that will be helpful. Thanks. FWIW GnuPG 2.2.32 also lists PC/SC readers and not just the Linux default of CCID readers.

Oct 19 2021, 5:35 PM · Restricted Project, kleopatra, Feature Request
bernhard committed rW7a2786adc15e: Update css to make the typical DE announcement fit (authored by bernhard).
Update css to make the typical DE announcement fit
Oct 19 2021, 4:53 PM
bernhard committed rW61d74c3f0d34: Add news item for needed upgrade to GnuPG 2.2.32 (authored by bernhard).
Add news item for needed upgrade to GnuPG 2.2.32
Oct 19 2021, 4:30 PM
ikloecker added a comment to T5662: Kleopatra: Show a list of detected card readers.

Yes, the text can be selected (with the mouse) and then be copied to the clipboard.

Oct 19 2021, 3:41 PM · Restricted Project, kleopatra, Feature Request
werner triaged T5663: Kleopatra's "Check for updates" does not work as Normal priority.

Version check is a data leak anyway and thus often disabled. Thus I don't see a risk for high value targets.

Oct 19 2021, 2:59 PM · Restricted Project, gpg4win, kleopatra
werner added a comment to T5662: Kleopatra: Show a list of detected card readers.

Just to be sure: Can you c+p the strings?

Oct 19 2021, 2:25 PM · Restricted Project, kleopatra, Feature Request
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

Adding GPGME_DEBUG with 9 to the logs, there is not much more to see:

Oct 19 2021, 1:48 PM · Restricted Project, gpg4win, kleopatra
bernhard added a comment to T5663: Kleopatra's "Check for updates" does not work.

With the following settings done as described at
https://www.gpg4win.org/doc/en/gpg4win-compendium_29.html

Oct 19 2021, 1:32 PM · Restricted Project, gpg4win, kleopatra
gahr updated gahr.
Oct 19 2021, 1:18 PM
bernhard updated the task description for T5663: Kleopatra's "Check for updates" does not work.
Oct 19 2021, 1:06 PM · Restricted Project, gpg4win, kleopatra
werner assigned T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’ to gniibe.

Hello @gniibe, you did the last work on nPTh. Would you be so kind and look into this?

Oct 19 2021, 1:06 PM · npth, Bug Report
ikloecker added a comment to T5663: Kleopatra's "Check for updates" does not work.

Kleopatra runs

gpgconf --query-swdb gpg4win 3.1.15

i.e. with the current version. Here, on Linux, I get

gpg4win:3.1.15:u::0:20211012T161328:20211019T103252:3.1.16:20210611T000000:0::

as result. The u in field 2 indicates that an update is available. The (current) code should work as far as I could see by a quick glance.

Oct 19 2021, 12:54 PM · Restricted Project, gpg4win, kleopatra
gahr added a comment to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.

Thanks for the clarification. So it's just a matter of not emitting the warning I guess?

Oct 19 2021, 12:47 PM · gnupg (gpg23), MacOS, Bug Report
mfe created T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’.
Oct 19 2021, 12:26 PM · npth, Bug Report
ikloecker added a comment to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.

gnupg_bindir() uses unix_rootdir() falling back to the builtin configure time path if unix_rootdir() returns NULL. So, there is no difference.

Oct 19 2021, 12:26 PM · gnupg (gpg23), MacOS, Bug Report
ikloecker added a comment to T5662: Kleopatra: Show a list of detected card readers.

Dialog showing the list of available smartcard readers:

Oct 19 2021, 12:15 PM · Restricted Project, kleopatra, Feature Request
ikloecker committed rKLEOPATRA92de59e6958c: List available smartcard readers (authored by ikloecker).
List available smartcard readers
Oct 19 2021, 12:09 PM
Jakuje added a comment to T5433: libgcrypt: Do not use SHA1 by default.

Sorry, I was wrong. We don't need any changes.

When using gcry_pk_hash_sign and gcry_pk_hash_verify, approved digest algos are guaranteed when FIPS enabled.

Yes, it's a user of the function who supplies HD (handle for hash). (I had wrong assumption HD could be with non-approved digest algo.) But it is needed for the user to enable the HD and to feed message beforehand. At that stage, non-approved digest algo must fail.

Oct 19 2021, 11:54 AM · FIPS, libgcrypt, Bug Report
bernhard updated subscribers of T5663: Kleopatra's "Check for updates" does not work.

@werner can you prioritize?

Oct 19 2021, 11:13 AM · Restricted Project, gpg4win, kleopatra
bernhard created T5663: Kleopatra's "Check for updates" does not work.
Oct 19 2021, 11:10 AM · Restricted Project, gpg4win, kleopatra
bernhard added a comment to T4249: No connection to Keyserver possible.

This has not been set high on the priorities, because keyserver access works for most with Gpg4win (and thus GnuPG) on windows. A recent exception has been occurred about a month ago with Let's encrypt expired root certificate. So currently for Gpg4win 3.1.16 you need to update to a newer GnuPG (Version 2.2.32 at time of writing), by installing the simple installer,e.g. https://gnupg.org/ftp/gcrypt/binary/gnupg-w32-2.2.32_20211006.exe

Oct 19 2021, 10:57 AM · gnupg, dirmngr, Bug Report, gpg4win
gahr added a comment to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.

I second this. This is problematic on (Free)BSD too, where /proc is usually optional and might not be mounted at all. I concur that this should be silenced if not running in debug mode.

Oct 19 2021, 9:56 AM · gnupg (gpg23), MacOS, Bug Report
gniibe added a comment to T5433: libgcrypt: Do not use SHA1 by default.

I investigated if the possible change above (if applied) constitutes an ABI change: Indeed, it will be an ABI change, and an API change; code should be modified and build.

Oct 19 2021, 8:58 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5433: libgcrypt: Do not use SHA1 by default.

Sorry, I was wrong. We don't need any changes.

Oct 19 2021, 8:07 AM · FIPS, libgcrypt, Bug Report

Oct 18 2021

werner claimed T3204: Include documentation for technicians in Gpg4win that matches the packaged versions of GnuPG, GPGME.
Oct 18 2021, 4:42 PM · gpgweb, Windows, Documentation, gpg4win
werner added a comment to T3204: Include documentation for technicians in Gpg4win that matches the packaged versions of GnuPG, GPGME.

I would prefer to store legacy manuals on the web server. That is the easier solution.

Oct 18 2021, 4:42 PM · gpgweb, Windows, Documentation, gpg4win
ikloecker triaged T5662: Kleopatra: Show a list of detected card readers as Normal priority.
Oct 18 2021, 3:37 PM · Restricted Project, kleopatra, Feature Request
ikloecker moved T5662: Kleopatra: Show a list of detected card readers from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 18 2021, 3:33 PM · Restricted Project, kleopatra, Feature Request
ikloecker claimed T5662: Kleopatra: Show a list of detected card readers.
Oct 18 2021, 3:33 PM · Restricted Project, kleopatra, Feature Request
ikloecker created T5662: Kleopatra: Show a list of detected card readers.
Oct 18 2021, 3:32 PM · Restricted Project, kleopatra, Feature Request
werner added a comment to T5661: Symmetric only encryption with Kleopatra.

Cool. Thanks.

Oct 18 2021, 1:18 PM · Restricted Project, Feature Request, kleopatra
ikloecker committed rKLEOPATRAbfadfb38000f: Add option to use symmetric encryption only (authored by ikloecker).
Add option to use symmetric encryption only
Oct 18 2021, 12:45 PM
ikloecker committed rKLEOPATRA5b170051bdc1: Update the encryption checkboxes if symmetric only is en-/disabled (authored by ikloecker).
Update the encryption checkboxes if symmetric only is en-/disabled
Oct 18 2021, 12:45 PM
ikloecker closed T5661: Symmetric only encryption with Kleopatra as Resolved.

In the global kleopatrarc add the following config entry to enable the symmetric encryption only option by default:

[FileOperations]
symmetric-encryption-only=true
Oct 18 2021, 12:42 PM · Restricted Project, Feature Request, kleopatra
ikloecker moved T5661: Symmetric only encryption with Kleopatra from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 18 2021, 12:42 PM · Restricted Project, Feature Request, kleopatra
bernhard updated subscribers of T3204: Include documentation for technicians in Gpg4win that matches the packaged versions of GnuPG, GPGME.

@werner, because we have talked about it:

Oct 18 2021, 12:17 PM · gpgweb, Windows, Documentation, gpg4win
gniibe added a comment to T5433: libgcrypt: Do not use SHA1 by default.

I am going to implement rejecting SHA-1 through new API (hash+sign, hash+verify).

Oct 18 2021, 11:24 AM · FIPS, libgcrypt, Bug Report
werner added a comment to T5645: RSA/DSA keygen modification for FIPS/ACVP testing.

( No need to certify the DSA things)

Oct 18 2021, 11:16 AM · libgcrypt, FIPS, Bug Report
werner moved T5645: RSA/DSA keygen modification for FIPS/ACVP testing from Next to Ready for release on the FIPS board.
Oct 18 2021, 11:15 AM · libgcrypt, FIPS, Bug Report
werner moved T5617: fips: Check library integrity before running selftests from Next to Ready for release on the FIPS board.
Oct 18 2021, 11:14 AM · FIPS, libgcrypt, Bug Report
ikloecker moved T5661: Symmetric only encryption with Kleopatra from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 18 2021, 9:40 AM · Restricted Project, Feature Request, kleopatra
ikloecker added a project to T5661: Symmetric only encryption with Kleopatra: Restricted Project.
Oct 18 2021, 9:39 AM · Restricted Project, Feature Request, kleopatra
ikloecker added a comment to T5660: Second key decrypts messages it shouldn't.

I'm pretty sure that the first 3 messages are always decrypted with the first key because the passphrase of the first key is still cached. I don't think you can tell gpg to only use a specific key for decryption. The only way to make sure that gpg does not try to use the first key for decryption is to remove the private key of the first key. Alternatively, clear the cache after using the first key, but gpg might still ask the user for the passphrase of the first key.

Oct 18 2021, 9:28 AM · Support