Page MenuHome GnuPG
Feed All Stories

Nov 10 2021

gniibe committed rC915839abc54a: doc: Fix NEWS entry to refer CVE-2021-40528. (authored by gniibe).
doc: Fix NEWS entry to refer CVE-2021-40528.
Nov 10 2021, 3:49 AM
gniibe committed rCb118681ebc4c: doc: Fix NEWS entry to refer CVE-2021-40528. (authored by gniibe).
doc: Fix NEWS entry to refer CVE-2021-40528.
Nov 10 2021, 3:49 AM
gniibe committed rK0d7a62c355ea: libtool: Link without -flat_namespace for macOS. (authored by gniibe).
libtool: Link without -flat_namespace for macOS.
Nov 10 2021, 3:37 AM
gniibe committed rM50daf3d75d66: libtool: Link without -flat_namespace for macOS. (authored by gniibe).
libtool: Link without -flat_namespace for macOS.
Nov 10 2021, 3:24 AM
gniibe added a project to T5610: macOS 11 or newer support: Update libtool: gpgme.

Also applied to gpgme.

Nov 10 2021, 3:07 AM · gpgme, MacOS, ntbtls, npth, libksba, libassuan, libgcrypt, gpgrt
gniibe added a comment to T5610: macOS 11 or newer support: Update libtool.

Since there is no problem with libgpg-error 1.43, I applied it to other libraries: npth, libassuan, libksba, and ntbtls.

Nov 10 2021, 3:04 AM · gpgme, MacOS, ntbtls, npth, libksba, libassuan, libgcrypt, gpgrt
gniibe added a comment to T5512: Implement service indicators.

I'll fix regressions: failures of pubkey and pkcs1v2.

Nov 10 2021, 2:09 AM · Feature Request, FIPS, libgcrypt
jcross added a comment to T5555: Cannot add existing ECDSA key as a signing subkey.

Friendly ping @werner

Nov 10 2021, 1:32 AM · gnupg24, Bug Report

Nov 9 2021

werner added a comment to T5523: jitter entropy RNG update.

Yes, keep the internal SHA-3.

Nov 9 2021, 11:33 AM · FIPS, libgcrypt
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

We will have rnd-getentropy.c

Nov 9 2021, 11:16 AM · FIPS, libgcrypt, Bug Report
gniibe claimed T5636: Run integrity checks + selftests from library constructor in FIPS.
Nov 9 2021, 11:08 AM · FIPS, libgcrypt, Bug Report
gniibe moved T5636: Run integrity checks + selftests from library constructor in FIPS from Backlog to Next on the FIPS board.
Nov 9 2021, 11:08 AM · FIPS, libgcrypt, Bug Report
werner committed rD758940e1ad69: drafts,openpgp-webkey-service: Clarify when to use the direct method. (authored by werner).
drafts,openpgp-webkey-service: Clarify when to use the direct method.
Nov 9 2021, 9:09 AM
werner committed rG0c8bc154342b: wks: Do not mark key files as executable (authored by bmwiedemann).
wks: Do not mark key files as executable
Nov 9 2021, 9:06 AM
werner committed rG60be00b0336b: wks: Allow access to newly created dirs (authored by bmwiedemann).
wks: Allow access to newly created dirs
Nov 9 2021, 9:06 AM
werner committed rG46ada6a9bd83: wks: Do not mark key files as executable (authored by bmwiedemann).
wks: Do not mark key files as executable
Nov 9 2021, 9:06 AM
werner committed rGf54feb447000: wks: Allow access to newly created dirs (authored by bmwiedemann).
wks: Allow access to newly created dirs
Nov 9 2021, 9:06 AM
werner committed rG8d6968c52cc8: doc: Minor fix for --http-proxy. (authored by werner).
doc: Minor fix for --http-proxy.
Nov 9 2021, 9:06 AM
werner closed T5680: Optional, larger key sizes for the Blowfish cipher as Wontfix.

Blowfish is not part of OpenPGP and according to its creator not the best cipher. Sorry to say no. You may nevertheless be interested in the recent discussion threads on PQC on the cryptography ML.

Nov 9 2021, 8:06 AM · Feature Request
gniibe added a comment to T5512: Implement service indicators.

Applied and pushed symmetric algo for basic.

Nov 9 2021, 7:37 AM · Feature Request, FIPS, libgcrypt
gniibe committed rCfb931073707e: tests: Explicit FIPS checking for symmetric algorithms. (authored by Jakuje).
tests: Explicit FIPS checking for symmetric algorithms.
Nov 9 2021, 7:37 AM
gniibe committed rC2a899b5b8458: tests: Benchmark also larger RSA keys in FIPS mode (authored by Jakuje).
tests: Benchmark also larger RSA keys in FIPS mode
Nov 9 2021, 7:37 AM
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Let me clean up rndlinux.c for current use case, at first.

Nov 9 2021, 7:07 AM · FIPS, libgcrypt, Bug Report
gniibe added a comment to T5523: jitter entropy RNG update.

I decided to use 3.3.0 disabling pthread feature.

Nov 9 2021, 6:41 AM · FIPS, libgcrypt
Heino created T5680: Optional, larger key sizes for the Blowfish cipher.
Nov 9 2021, 6:35 AM · Feature Request

Nov 8 2021

Heiko Becker <heiko.becker@kde.org> committed rLIBKLEO49e32463f364: GIT SILENT Change BRANCH_GROUP to stable-kf5-qt5 (authored by Heiko Becker <heiko.becker@kde.org>).
GIT SILENT Change BRANCH_GROUP to stable-kf5-qt5
Nov 8 2021, 10:46 PM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAa7abeea92d99: GIT SILENT Change BRANCH_GROUP to stable-kf5-qt5 (authored by Heiko Becker <heiko.becker@kde.org>).
GIT SILENT Change BRANCH_GROUP to stable-kf5-qt5
Nov 8 2021, 10:44 PM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA42c9be0d72a5: GIT_SILENT Upgrade release service version to 22.03.70. (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Upgrade release service version to 22.03.70.
Nov 8 2021, 8:57 PM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA4c38902471a4: GIT_SILENT Upgrade release service version to 21.11.80. (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Upgrade release service version to 21.11.80.
Nov 8 2021, 8:26 PM
nsauter added a comment to T4513: dirmngr should try the configured keyservers anyway even if they are all dead.

Any news here? Is this issue going to be fixed or not? It's really annoying.

Nov 8 2021, 1:05 PM · Feature Request, Keyserver, dirmngr
ikloecker claimed T5638: Make Kleopatra group configuration exportable.
Nov 8 2021, 9:43 AM · Restricted Project, Feature Request, kleopatra
ikloecker changed the status of T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog from Open to Testing.
Nov 8 2021, 9:41 AM · Restricted Project, kleopatra, Feature Request
ikloecker renamed T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog from Kleopatra: Do not offer "invisible" options in GnuPG System configuration dialog to Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.
Nov 8 2021, 9:41 AM · Restricted Project, kleopatra, Feature Request
Jakuje added a comment to T5512: Implement service indicators.

Thank you for merging the important parts of the patches and implementing similar stuff for DSA. You are right that DSA is supported in the 140-3 specs so it is fine to keep it enabled with the keylength constraints.

Nov 8 2021, 9:02 AM · Feature Request, FIPS, libgcrypt
gniibe added a comment to T5512: Implement service indicators.

Applied parts except part 2.
The part 3 are modified version, so that memory can be released correctly.

Nov 8 2021, 6:58 AM · Feature Request, FIPS, libgcrypt
gniibe committed rCdf66bd94e6e3: dsa: Add checks in FIPS mode. (authored by gniibe).
dsa: Add checks in FIPS mode.
Nov 8 2021, 6:54 AM
gniibe committed rC1f45fec20822: tests: Add 2k RSA key working in FIPS mode. (authored by Jakuje).
tests: Add 2k RSA key working in FIPS mode.
Nov 8 2021, 6:54 AM
gniibe committed rC1b29be8e7e49: tests: Fix basic.c:check_pubkey. (authored by gniibe).
tests: Fix basic.c:check_pubkey.
Nov 8 2021, 6:54 AM
gniibe committed rCcc3571a1f224: tests: Expect errors from algorithms not supported in FIPS mode. (authored by gniibe).
tests: Expect errors from algorithms not supported in FIPS mode.
Nov 8 2021, 6:54 AM
gniibe committed rC40d63d09b2d0: rsa: Check keylen constraints for key operations. (authored by Jakuje).
rsa: Check keylen constraints for key operations.
Nov 8 2021, 6:54 AM
gniibe committed rCff5ab6a80934: cipher: Respect the disabled flag of pubkey algorithms (authored by Jakuje).
cipher: Respect the disabled flag of pubkey algorithms
Nov 8 2021, 6:54 AM

Nov 7 2021

Laurent Montel <montel@kde.org> committed rLIBKLEOcf27ab5f08d8: GIT_SILENT: prepare 5.19.0beta1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.19.0beta1
Nov 7 2021, 5:25 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRA297ccea15127: GIT_SILENT: prepare 5.19.0beta1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.19.0beta1
Nov 7 2021, 5:23 PM

Nov 6 2021

werner closed T5544: Kleopatra: Ensure that file encryption dialogs has shortcuts on all actions, a subtask of T5535: Kleopatra: Check that accessibility is also supported for VS-NfD, as Resolved.
Nov 6 2021, 4:42 PM · Restricted Project, kleopatra
werner closed T5544: Kleopatra: Ensure that file encryption dialogs has shortcuts on all actions as Resolved.

Closing. In case the audit will request more, we can re-open this task.

Nov 6 2021, 4:42 PM · kleopatra, Restricted Project
werner closed T5535: Kleopatra: Check that accessibility is also supported for VS-NfD as Resolved.

I think we can close this. In January we will have an external audit (BITV) which hopefully will confirm our tests. They auditor will also provide a list of things to improve (if any).

Nov 6 2021, 4:40 PM · Restricted Project, kleopatra

Nov 5 2021

Jakuje added a comment to T5512: Implement service indicators.

Implicit indicators mean that we need to go through the all algorithms and verify that they work if they have approved key sizes/parameters and do not work when they do not.

Nov 5 2021, 2:27 PM · Feature Request, FIPS, libgcrypt
ikloecker committed rKLEOPATRA7a043fd5e570: GIT_SILENT: Minor code cleanup (authored by ikloecker).
GIT_SILENT: Minor code cleanup
Nov 5 2021, 12:51 PM
ikloecker committed rKLEOPATRA0b7978d55049: Import certificates from files containing OpenPGP and X.509 certificates (authored by ikloecker).
Import certificates from files containing OpenPGP and X.509 certificates
Nov 5 2021, 12:51 PM
ikloecker committed rLIBKLEOcc28dad68e99: Put ui headers next to corresponding ui cpp files and sort all lists (authored by ikloecker).
Put ui headers next to corresponding ui cpp files and sort all lists
Nov 5 2021, 10:28 AM
ikloecker committed rLIBKLEO6b7a986ad550: Skip any config options beyond "invisible" level (authored by ikloecker).
Skip any config options beyond "invisible" level
Nov 5 2021, 10:28 AM
ikloecker committed rLIBKLEO66bd5175f280: Explicitly exclude deprecated gpg/keyserver option from config UI (authored by ikloecker).
Explicitly exclude deprecated gpg/keyserver option from config UI
Nov 5 2021, 10:28 AM
ikloecker committed rLIBKLEOe684b2e9f1fe: Do not show empty groups in GnuPG System configuration (authored by ikloecker).
Do not show empty groups in GnuPG System configuration
Nov 5 2021, 10:28 AM
ikloecker committed rLIBKLEO7b1fa6ef4297: Skip any config options beyond expert level (authored by ikloecker).
Skip any config options beyond expert level
Nov 5 2021, 10:28 AM
ikloecker added a comment to T5638: Make Kleopatra group configuration exportable.

Yes, no, maybe. :-) Thanks for asking!

Nov 5 2021, 10:14 AM · Restricted Project, Feature Request, kleopatra
gniibe committed rC976673425784: doc: Reference the new FIPS 140-3 (authored by Jakuje).
doc: Reference the new FIPS 140-3
Nov 5 2021, 7:45 AM
gniibe added a comment to T5636: Run integrity checks + selftests from library constructor in FIPS.

Firstly, applied uncontroversial part in rC976673425784: doc: Reference the new FIPS 140-3

Nov 5 2021, 7:23 AM · FIPS, libgcrypt, Bug Report
Laurent Montel <montel@kde.org> committed rLIBKLEO68178cdb09df: GIT_SILENT: prepare 5.19.0 beta1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.19.0 beta1
Nov 5 2021, 7:02 AM
gniibe added a comment to D540: Adding poll/ppoll to NPTH.

I use unsigned long instead of nfds_t, so that a user doesn't need to include <poll.h> when he doesn't use poll/ppoll API.

Nov 5 2021, 6:22 AM
gniibe requested review of D540: Adding poll/ppoll to NPTH.
Nov 5 2021, 6:21 AM
gniibe added a comment to D539: Using poll instead, removing use of select for POSIX system.

Don't apply tests/gpg/t-support.h, it's only for testing this patch.
When test, before running 'make check' please do:

Nov 5 2021, 3:26 AM
gniibe updated the diff for D539: Using poll instead, removing use of select for POSIX system.

Update to include the change of tests.
Also include a change for tests/gpg/t-support.h to run tests under artificial environment.

Nov 5 2021, 3:25 AM
Beauregardo added a comment to T5678: Request to have key algorithms named in "list-packets" rather than emitting an algorithm ID.

I have been using pgpdump for a long time, but it is out of date with regards to ECC. I have looked at its source code but would rather spend my time on my own code.

Nov 5 2021, 1:32 AM · Feature Request

Nov 4 2021

Laurent Montel <montel@kde.org> committed rLIBKLEO142d0238a2e2: Allow to show header in qtc6 (authored by Laurent Montel <montel@kde.org>).
Allow to show header in qtc6
Nov 4 2021, 8:37 PM
werner added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

Please no new levels. And also consider the problems with global config files, conditionals and values taking from the registry. We can't simply do everything in the GUI - it would get too complex and we end up supporting the supportive config dialogs. Maybe a syntax checking editor would eventually be better.

Nov 4 2021, 5:37 PM · Restricted Project, kleopatra, Feature Request
werner triaged T5678: Request to have key algorithms named in "list-packets" rather than emitting an algorithm ID as Low priority.

OpenPGP folks now the algo number by heart ;-)

Nov 4 2021, 5:29 PM · Feature Request
werner closed T5679: Incorrectly aligned text for print-md and print-mds (echoed, piped text only) as Resolved.
Nov 4 2021, 5:27 PM · Bug Report
werner added a comment to T5679: Incorrectly aligned text for print-md and print-mds (echoed, piped text only).

Fixed and tested on Linux. Thanks.

Nov 4 2021, 5:27 PM · Bug Report
werner committed rGd9deac779190: gpg: Fix indentation of --print-mds and --print-md sha512. (authored by werner).
gpg: Fix indentation of --print-mds and --print-md sha512.
Nov 4 2021, 5:27 PM
werner committed rGfa738173f9d8: gpgconf: New command --show-configs. (authored by werner).
gpgconf: New command --show-configs.
Nov 4 2021, 4:37 PM
werner committed rGc36f9917bbdd: scd: Add new OpenPGP card vendor. (authored by werner).
scd: Add new OpenPGP card vendor.
Nov 4 2021, 4:37 PM
Heino created T5679: Incorrectly aligned text for print-md and print-mds (echoed, piped text only).
Nov 4 2021, 4:11 PM · Bug Report
aheinecke added a comment to T5638: Make Kleopatra group configuration exportable.

How would you handle a combination of X509 Certificates and PGP Certificates in that case? Wouldn't that require two files?

Nov 4 2021, 3:51 PM · Restricted Project, Feature Request, kleopatra
ikloecker added a comment to T5675: Kleopatra 3.1.16 / Keyservers related functions are not working.

I suppose you have rebooted the PC after installing GnuPG 2.3.32. Just to make sure. And double check that there is only one dirmngr.exe with version 2.2.32 installed on your system.

Nov 4 2021, 2:45 PM · Keyserver, kleopatra, Bug Report
ikloecker added a comment to T5638: Make Kleopatra group configuration exportable.

I was planning to export the certificates in the usual textual formats (.asc, .pem) with the information about the groups added as armor headers for OpenPGP and explanatory text for CMS. This would allow the certificates to be imported with any software supporting OpenPGP or X.509 certificates. When importing certificates Kleopatra simply looks for the additional group information and adds/updates the groups (probably after asking the user).

Nov 4 2021, 2:37 PM · Restricted Project, Feature Request, kleopatra
ikloecker triaged T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog as Normal priority.
Nov 4 2021, 12:11 PM · Restricted Project, kleopatra, Feature Request
ikloecker abandoned D538: gpgconf: Make gpg/keyserver option available again.

Has been merged into master.

Nov 4 2021, 12:09 PM · gnupg (gpg23)
ikloecker closed T5462: gpgconf: Make gpg/keyserver option available again as Resolved.
Nov 4 2021, 12:07 PM · gnupg (gpg23), Restricted Project
ikloecker closed T5462: gpgconf: Make gpg/keyserver option available again, a subtask of T5461: Kleopatra: Does not change OpenPGP keyserver configured in gpg.conf, as Resolved.
Nov 4 2021, 12:07 PM · Restricted Project, kleopatra, Bug Report
ikloecker committed rG0a7d772a5c43: gpgconf: Allow changing gpg's deprecated keyserver option (authored by ikloecker).
gpgconf: Allow changing gpg's deprecated keyserver option
Nov 4 2021, 12:03 PM
HannesESS changed the status of T5675: Kleopatra 3.1.16 / Keyservers related functions are not working from Duplicate to Wontfix.

I did a complete reinstall after cleaning out the complete system incl. registry.
No change in behavior of Gpg4win.

Nov 4 2021, 11:49 AM · Keyserver, kleopatra, Bug Report
Beauregardo created T5678: Request to have key algorithms named in "list-packets" rather than emitting an algorithm ID.
Nov 4 2021, 11:35 AM · Feature Request
ikloecker added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

Regarding the level "internal" I just remembered that gpgconf doesn't list "internal" options. Given that didn't find any internal options that could probably be changed. Or we add yet another level. Or, all invisible options, that shall be offered to users are promoted (or demoted?) from "invisible" to "expert" level.

Nov 4 2021, 9:48 AM · Restricted Project, kleopatra, Feature Request
aheinecke added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

Okay, but then we need a new level for those options that really must not be shown in a UI, but that still need to be accessible via gpgconf. In fact, there is the level "internal" which does not yet seem to be used for any options, but that seems suitable at least for the deprecated gpg/keyserver option.

Nov 4 2021, 9:32 AM · Restricted Project, kleopatra, Feature Request
ikloecker added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

Okay, but then we need a new level for those options that really must not be shown in a UI, but that still need to be accessible via gpgconf. In fact, there is the level "internal" which does not yet seem to be used for any options, but that seems suitable at least for the deprecated gpg/keyserver option.

Nov 4 2021, 9:22 AM · Restricted Project, kleopatra, Feature Request
aheinecke added a comment to T5638: Make Kleopatra group configuration exportable.

While we should have an explicit Import setting I would also like to have a file extension like "kgrp" for key group, cgrp for certificate group is already used by another software.
So that we can register this with a file handler in windows so that such files can get an icon and a double click handler.

Nov 4 2021, 9:15 AM · Restricted Project, Feature Request, kleopatra
aheinecke added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

I had explicitly added these options because for me the whole "GnuPG System" is an expert level configuration. I would rather move the very important options like the agent timeout settings out of this and then maybe show an info when the user first selects those settings that changing options here could lead to errors in operation.

Nov 4 2021, 9:10 AM · Restricted Project, kleopatra, Feature Request
ikloecker added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

:-) I thought about such a setting, but at first I want to exclude invisible options from Kleopatra's UI.

Nov 4 2021, 8:40 AM · Restricted Project, kleopatra, Feature Request
ikloecker added a comment to D538: gpgconf: Make gpg/keyserver option available again.
In D538#5324, @werner wrote:

Having it invisible is okay for me. But we should not support the keyserver option in gpg.conf via Kleopatra anymore. This option needs to be faded out.

Nov 4 2021, 8:36 AM · gnupg (gpg23)
werner accepted D537: scd: Add new Openpgp card vendor name..

Sorry, I obviously forgot to add this vendor.

Nov 4 2021, 8:07 AM
werner added a comment to D538: gpgconf: Make gpg/keyserver option available again.

Having it invisible is okay for me. But we should not support the keyserver option in gpg.conf via Kleopatra anymore. This option needs to be faded out. Actually there are more problems in 2.2 here: In particular the global options are not manageable by a gpgconf. Thus there is no guarantee that the keyserver option actually shows the correct value if global options are used.

Nov 4 2021, 8:00 AM · gnupg (gpg23)
werner added a comment to T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.

FWIW, GPA has a setting where you can select at which level options are shown (but not invisible). IIRC we had the same in Kleopatra but it has been removed.

Nov 4 2021, 7:52 AM · Restricted Project, kleopatra, Feature Request
gniibe added a comment to T2385: support more than 1024 fds..

For libgcrypt, it was fixed in: T5637: Use poll for libgcrypt (support more than 1024 fds)

Nov 4 2021, 3:54 AM · gpgrt, Feature Request, gpgme
gniibe requested review of D539: Using poll instead, removing use of select for POSIX system.
Nov 4 2021, 3:50 AM
gniibe changed the status of T5637: Use poll for libgcrypt (support more than 1024 fds), a subtask of T2385: support more than 1024 fds., from Open to Testing.
Nov 4 2021, 1:43 AM · gpgrt, Feature Request, gpgme
gniibe changed the status of T5637: Use poll for libgcrypt (support more than 1024 fds) from Open to Testing.
Nov 4 2021, 1:43 AM · libgcrypt, Feature Request
gniibe committed rE61843dace32f: estream: Only include sys/select.h when needed. (authored by gniibe).
estream: Only include sys/select.h when needed.
Nov 4 2021, 1:41 AM

Nov 3 2021

HannesESS added a comment to T5675: Kleopatra 3.1.16 / Keyservers related functions are not working.

THX for the quick reply Ingo...

Nov 3 2021, 5:48 PM · Keyserver, kleopatra, Bug Report
ikloecker created T5677: Kleopatra: Do not offer deprecated gpg/keyserver option in GnuPG System configuration dialog.
Nov 3 2021, 3:40 PM · Restricted Project, kleopatra, Feature Request
werner committed rD5abd69a5e1ee: swdb: Libgpg-error 1.43 (authored by werner).
swdb: Libgpg-error 1.43
Nov 3 2021, 3:29 PM