Page MenuHome GnuPG
Feed All Stories

Feb 2 2022

gniibe closed T5692: New entropy gatherer using the genentropy system call. as Resolved.
Feb 2 2022, 1:22 AM · libgcrypt, FIPS
gniibe closed T4894: FIPS: RSA/DSA/ECDSA are missing hashing operation as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt, Feature Request
gniibe closed T5710: FIPS: disable DSA for FIPS as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5723: libgcrypt: Remove random-fips.c as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5523: jitter entropy RNG update as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5541: Envvar LIBGCRYPT_FORCE_FIPS_MODE as Resolved.
Feb 2 2022, 1:20 AM · Feature Request, FIPS, libgcrypt
gniibe closed T5550: Fix check_binary_integrity as Resolved.
Feb 2 2022, 1:20 AM · FIPS, libgcrypt
gniibe closed T5508: Allow hardware optimizations in FIPS as Resolved.
Feb 2 2022, 1:20 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5244: libgcrypt: Restrict MD5 use as Resolved.
Feb 2 2022, 1:19 AM · Bug Report, FIPS, libgcrypt
gniibe closed T5520: Fix tests in FIPS mode as Resolved.
Feb 2 2022, 1:18 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5617: fips: Check library integrity before running selftests as Resolved.
Feb 2 2022, 1:17 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5645: RSA/DSA keygen modification for FIPS/ACVP testing as Resolved.
Feb 2 2022, 1:16 AM · libgcrypt, FIPS, Bug Report
gniibe moved T5512: Implement service indicators from Next to Ready for release on the FIPS board.
Feb 2 2022, 1:15 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5691: Release libgcrypt 1.10.0 from Next to Ready for release on the FIPS board.
Feb 2 2022, 1:15 AM · FIPS, Release Info, libgcrypt

Feb 1 2022

werner committed rD87c005211f03: swdb: Libgcrypt 1.10.0 non-public release (authored by werner).
swdb: Libgcrypt 1.10.0 non-public release
Feb 1 2022, 10:11 PM
werner committed rCdd99ef53d9ee: Prepare master for future work (authored by werner).
Prepare master for future work
Feb 1 2022, 9:56 PM
werner changed the status of T5691: Release libgcrypt 1.10.0 from Open to Testing.
Feb 1 2022, 9:49 PM · FIPS, Release Info, libgcrypt
werner triaged T5810: Release Libgcrypt 1.10.1 as Low priority.
Feb 1 2022, 9:38 PM · libgcrypt, Release Info
erlandm added a comment to T5809: Expire subkey violates assertion "! sig->hashed".

Here is the output of --list-packets of the offending key, anonymised:

  1. off=0 ctb=99 tag=6 hlen=3 plen=418 :public key packet: version 4, algo 17, created 985690138, expires 0 pkey[0]: [1024 bits] pkey[1]: [160 bits] pkey[2]: [1024 bits] pkey[3]: [1023 bits] keyid: <KEY_ID>
  2. off=421 ctb=b4 tag=13 hlen=2 plen=35 :user ID packet: "XXXXXXXXXXXXX"
  3. off=458 ctb=88 tag=2 hlen=2 plen=120 :signature packet: algo 17, keyid <KEY_ID> version 4, created 1629537425, md5len 0, sigclass 0x13 digest algo 2, begin of digest a8 22 hashed subpkt 33 len 21 (issuer fpr v4 <XXXXXXXXXXXXXX><KEY_ID>) hashed subpkt 2 len 4 (sig created 2021-08-21) hashed subpkt 27 len 1 (key flags: 23) hashed subpkt 11 len 4 (pref-sym-algos: 9 8 7 2) hashed subpkt 21 len 5 (pref-hash-algos: 8 9 10 11 2) hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1) hashed subpkt 30 len 1 (features: 01) hashed subpkt 23 len 1 (keyserver preferences: 80) subpkt 16 len 8 (issuer key ID <KEY_ID>) data: [158 bits] data: [159 bits]
  4. off=580 ctb=b9 tag=14 hlen=3 plen=525 :public sub key packet: version 4, algo 16, created 985690139, expires 0 pkey[0]: [2048 bits] pkey[1]: [2 bits] pkey[2]: [2046 bits] keyid: YYYYYYYYYYYYYYY
  5. off=1108 ctb=88 tag=2 hlen=2 plen=63 :signature packet: algo 17, keyid <KEY_ID> version 3, created 985690139, md5len 5, sigclass 0x18 digest algo 2, begin of digest 94 e5 data: [159 bits] data: [156 bits]
Feb 1 2022, 4:52 PM · Restricted Project, gnupg (gpg22), Bug Report
werner added a project to T5809: Expire subkey violates assertion "! sig->hashed": gnupg (gpg22).
Feb 1 2022, 4:24 PM · Restricted Project, gnupg (gpg22), Bug Report
werner added a comment to T5809: Expire subkey violates assertion "! sig->hashed".

This code

Feb 1 2022, 4:23 PM · Restricted Project, gnupg (gpg22), Bug Report
werner committed rG57d546674d08: dirmngr: Avoid initial delay on the first keyserver access. (authored by werner).
dirmngr: Avoid initial delay on the first keyserver access.
Feb 1 2022, 4:06 PM
werner committed rGdde88897e2c5: dirmngr: Avoid initial delay on the first keyserver access. (authored by werner).
dirmngr: Avoid initial delay on the first keyserver access.
Feb 1 2022, 4:02 PM
werner committed rGd426ed66ac04: gpg: Set --verbose and clear --quiet in debug mode. (authored by werner).
gpg: Set --verbose and clear --quiet in debug mode.
Feb 1 2022, 3:21 PM
werner committed rG623a427b0cb6: sm: Partly revert last commit. (authored by werner).
sm: Partly revert last commit.
Feb 1 2022, 3:21 PM
werner committed rG51edea995d35: gpg,sm: Set --verbose and clear --quiet in debug mode. (authored by werner).
gpg,sm: Set --verbose and clear --quiet in debug mode.
Feb 1 2022, 3:18 PM
erlandm updated the task description for T5809: Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:05 PM · Restricted Project, gnupg (gpg22), Bug Report
erlandm renamed T5809: Expire subkey violates assertion "! sig->hashed" from Expire subkey violates asserion "! sig->hashed" to Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:04 PM · Restricted Project, gnupg (gpg22), Bug Report
erlandm created T5809: Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:03 PM · Restricted Project, gnupg (gpg22), Bug Report
pmgdeb added a comment to T5806: Error codes in rsa.c:generate_fips().

Thanks, Werner. This was originally reported by Alejandro Masino.

Feb 1 2022, 2:44 PM · libgcrypt, Bug Report
aheinecke committed rW6a738876e5c2: Also sign additional files for NSIS package (authored by aheinecke).
Also sign additional files for NSIS package
Feb 1 2022, 1:35 PM
aheinecke committed rWde70a2f074fb: Update Kleopatra and dependencies (authored by aheinecke).
Update Kleopatra and dependencies
Feb 1 2022, 1:35 PM
gniibe committed rE433aba9e778e: build,tests: Fix detection of have_lock_optimization. (authored by gniibe).
build,tests: Fix detection of have_lock_optimization.
Feb 1 2022, 2:30 AM
gniibe added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Pushed the change in rE433aba9e778e: build,tests: Fix detection of have_lock_optimization..

Feb 1 2022, 2:20 AM · gpgrt, Bug Report
gniibe added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

@marv Thank you for your report.

Feb 1 2022, 1:33 AM · gpgrt, Bug Report

Jan 31 2022

ikloecker moved T5808: gpgme: Add support for importing keys given by key id from a keyserver from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 31 2022, 4:08 PM · gpgme, Restricted Project
ikloecker triaged T5808: gpgme: Add support for importing keys given by key id from a keyserver as Normal priority.
Jan 31 2022, 4:08 PM · gpgme, Restricted Project
marv added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Hey gniibe,

Jan 31 2022, 4:06 PM · gpgrt, Bug Report
werner closed T5806: Error codes in rsa.c:generate_fips() as Resolved.

Thanks

Jan 31 2022, 1:31 PM · libgcrypt, Bug Report
werner committed rC217bf0a0e7be: rsa: Fix regression in not returning an error for prime generation. (authored by werner).
rsa: Fix regression in not returning an error for prime generation.
Jan 31 2022, 12:54 PM
werner triaged T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries as Normal priority.
Jan 31 2022, 12:42 PM · Feature Request, gpg4win
ikloecker moved T5805: Kleopatra or GnuPG: Auto retrieve signers key from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 31 2022, 11:58 AM · gnupg, kleopatra, Restricted Project
gniibe committed rCcb9df21fcbb0: cipher: Initialize values not to confuse static analyzers (authored by Jakuje).
cipher: Initialize values not to confuse static analyzers
Jan 31 2022, 11:24 AM
gniibe committed rC904e168bdb2a: random: Avoid dereference of the ec before checking for NULL (authored by Jakuje).
random: Avoid dereference of the ec before checking for NULL
Jan 31 2022, 11:24 AM
gniibe committed rCd2003618e6bf: fips: Remove unused assignment (authored by Jakuje).
fips: Remove unused assignment
Jan 31 2022, 11:24 AM
gniibe committed rC0f38e6a877f1: cipher: Remove dead code in for the siv mode (authored by Jakuje).
cipher: Remove dead code in for the siv mode
Jan 31 2022, 11:24 AM
bernhard created T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries .
Jan 31 2022, 10:49 AM · Feature Request, gpg4win
aheinecke reassigned T5805: Kleopatra or GnuPG: Auto retrieve signers key from werner to ikloecker.

As this hinders the trusted-introducer setup in Keyserver centric deployments we should treat this with high priority.

Jan 31 2022, 10:05 AM · gnupg, kleopatra, Restricted Project
gniibe committed rC77512c510bf7: kdf: Fix computation by big-endian machine. (authored by gniibe).
kdf: Fix computation by big-endian machine.
Jan 31 2022, 5:08 AM
gniibe committed rC7dc488ae036a: ciper/blake2: Make sure to clean up the stack. (authored by gniibe).
ciper/blake2: Make sure to clean up the stack.
Jan 31 2022, 2:03 AM
gniibe added projects to T5797: New API for modern password hash function: Feature Request, Restricted Project.
Jan 31 2022, 1:22 AM · Feature Request, libgcrypt

Jan 30 2022

jukivili committed rC409f69167983: kdf/argon2: use BLAKE2b hash_buffers function instead of _gcry_md_* (authored by jukivili).
kdf/argon2: use BLAKE2b hash_buffers function instead of _gcry_md_*
Jan 30 2022, 11:30 PM
jukivili committed rC54369c66bedd: kdf: handle errors from thread dispatch/wait functions (authored by jukivili).
kdf: handle errors from thread dispatch/wait functions
Jan 30 2022, 11:30 PM
jukivili committed rC03a0eedefe3e: tests/t-kdf: few changes to pthread example and fix win32/win64 builds (authored by jukivili).
tests/t-kdf: few changes to pthread example and fix win32/win64 builds
Jan 30 2022, 11:30 PM
jukivili committed rCc5aead8aebc7: Rename KDF job functions and function types (authored by jukivili).
Rename KDF job functions and function types
Jan 30 2022, 11:30 PM

Jan 29 2022

pmgdeb created T5806: Error codes in rsa.c:generate_fips().
Jan 29 2022, 2:07 PM · libgcrypt, Bug Report
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAb997ef60255c: GIT_SILENT Upgrade release service version to 21.12.2. (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Upgrade release service version to 21.12.2.
Jan 29 2022, 12:27 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA9aeae3ef75be: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Jan 29 2022, 12:27 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAfec935205dea: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Jan 29 2022, 12:27 AM

Jan 28 2022

werner closed T5794: Cannot add ed25519 SSH key with empty comment as Resolved.

Thanks for the report. To keep things easy the empty comment is now translated to "(none)".

Jan 28 2022, 8:03 PM · ssh, gnupg (gpg22), Bug Report
werner committed rG2331900d1cc0: ssh: Fix adding an ed25519 key with a zero length comment. (authored by werner).
ssh: Fix adding an ed25519 key with a zero length comment.
Jan 28 2022, 8:01 PM
werner committed rG934a60de6b88: ssh: Fix adding an ed25519 key with a zero length comment. (authored by werner).
ssh: Fix adding an ed25519 key with a zero length comment.
Jan 28 2022, 8:01 PM
werner closed T5800: gpgconf: Ignores keyserver option in gpgsm.conf as Resolved.
Jan 28 2022, 5:30 PM · Restricted Project, Bug Report, gnupg (gpg22)
werner closed T5800: gpgconf: Ignores keyserver option in gpgsm.conf, a subtask of T5732: Backport option reading in gpgconf to 2.2, as Resolved.
Jan 28 2022, 5:30 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner closed T5732: Backport option reading in gpgconf to 2.2 as Resolved.
Jan 28 2022, 5:30 PM · Restricted Project, Bug Report, kleopatra, backport, gnupg (gpg22)
werner committed rG34ea19aff99f: gpg: Allow --dearmor to decode all kinds of armor files. (authored by werner).
gpg: Allow --dearmor to decode all kinds of armor files.
Jan 28 2022, 12:17 PM
aheinecke triaged T5805: Kleopatra or GnuPG: Auto retrieve signers key as Normal priority.
Jan 28 2022, 9:28 AM · gnupg, kleopatra, Restricted Project
gniibe added a comment to T5797: New API for modern password hash function.

Pushed rC254fb14044cf: kdf: Change new KDF API.

Jan 28 2022, 9:08 AM · Feature Request, libgcrypt
gniibe committed rC254fb14044cf: kdf: Change new KDF API. (authored by gniibe).
kdf: Change new KDF API.
Jan 28 2022, 9:08 AM
aheinecke added a comment to T5777: Kleopatra: Remove all external links which would open a browser.

Wow! That is a great idea. Thanks!

Jan 28 2022, 9:03 AM · kleopatra, Restricted Project
werner lowered the priority of T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful from High to Normal.
Jan 28 2022, 7:20 AM · gnupg24, Bug Report
werner added projects to T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful : gnupg (gpg23), Bug Report.
Jan 28 2022, 7:20 AM · gnupg24, Bug Report
werner updated the task description for T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .
Jan 28 2022, 7:20 AM · gnupg24, Bug Report
werner updated the task description for T5803: outlook restarts on adding a address to a new email.
Jan 28 2022, 7:17 AM · gpgol, Bug Report, gpg4win
gniibe committed rC6467287ba121: cipher: Implement variable-length hash function for Argon2. (authored by gniibe).
cipher: Implement variable-length hash function for Argon2.
Jan 28 2022, 6:51 AM
gniibe committed rC4cbbd87e2af0: kdf: Implement Argon2 KDF using blake2b_vl_hash function. (authored by gniibe).
kdf: Implement Argon2 KDF using blake2b_vl_hash function.
Jan 28 2022, 6:51 AM
engel97 updated the task description for T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .
Jan 28 2022, 1:50 AM · gnupg24, Bug Report
engel97 renamed T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful from Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful to Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .
Jan 28 2022, 1:50 AM · gnupg24, Bug Report
engel97 triaged T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful as High priority.
Jan 28 2022, 1:49 AM · gnupg24, Bug Report

Jan 27 2022

permaBox created T5803: outlook restarts on adding a address to a new email.
Jan 27 2022, 10:20 PM · gpgol, Bug Report, gpg4win
ikloecker committed rLIBKLEOb49d0fb3a6b0: Also exclude deprecated gpgsm/keyserver option for GnuPG 2.2.34+ (authored by ikloecker).
Also exclude deprecated gpgsm/keyserver option for GnuPG 2.2.34+
Jan 27 2022, 4:53 PM
ikloecker changed the status of T5777: Kleopatra: Remove all external links which would open a browser from Open to Testing.

I have added a setting which can be used to block URLs with certain schemes.

Jan 27 2022, 4:27 PM · kleopatra, Restricted Project
ikloecker committed rKLEOPATRA333fe62582a9: Allow URLs with certain schemes to be blocked by Kleopatra (authored by ikloecker).
Allow URLs with certain schemes to be blocked by Kleopatra
Jan 27 2022, 4:06 PM
werner committed rGf2d1187fcde3: gpgsm: Retire the new --ldapserver. (authored by werner).
gpgsm: Retire the new --ldapserver.
Jan 27 2022, 3:24 PM
werner committed rGe1fc053dc1ad: gpgconf: Tweak the use of ldapserver. (authored by werner).
gpgconf: Tweak the use of ldapserver.
Jan 27 2022, 3:23 PM
werner committed rGed798a97f54f: gpgconf: Teach --show-config the legacy gpgconf.conf. (authored by werner).
gpgconf: Teach --show-config the legacy gpgconf.conf.
Jan 27 2022, 2:44 PM
werner committed rG977b61ddab0c: gpgconf: Return again "keyserver" for gpgsm. (authored by werner).
gpgconf: Return again "keyserver" for gpgsm.
Jan 27 2022, 2:44 PM
ikloecker claimed T5777: Kleopatra: Remove all external links which would open a browser.
Jan 27 2022, 10:47 AM · kleopatra, Restricted Project
ikloecker changed the status of T5755: Kleopatra: Export secret subkeys from Open to Testing.
Jan 27 2022, 10:44 AM · Restricted Project, Feature Request, kleopatra
werner committed rDece75b2bf564: swdb: Release gpgrt 1.44 (authored by werner).
swdb: Release gpgrt 1.44
Jan 27 2022, 10:34 AM
werner closed T5676: Release Libgpg-error 1.44 as Resolved.
Jan 27 2022, 10:32 AM · Release Info, gpgrt
ikloecker changed the status of T5791: Kleopatra: Make settings read-only if corresponding GnuPG config entries or KConfigXT entries are read-only from Open to Testing.
Jan 27 2022, 10:28 AM · Restricted Project, kleopatra
ikloecker added a comment to T5791: Kleopatra: Make settings read-only if corresponding GnuPG config entries or KConfigXT entries are read-only.

This should now work for all settings in Kleopatra's configuration dialog.

Jan 27 2022, 10:28 AM · Restricted Project, kleopatra
ikloecker committed rLIBKLEOdbe78f2cd0eb: Explicitly exclude deprecated gpgsm/keyserver option from config UI (authored by ikloecker).
Explicitly exclude deprecated gpgsm/keyserver option from config UI
Jan 27 2022, 10:14 AM
werner committed rEf8cf25ee6b2e: build: Fixes for make distcheck (authored by werner).
build: Fixes for make distcheck
Jan 27 2022, 10:03 AM
werner committed rE663b91fe91af: Add Turkish translations (authored by Emir SARI <emir_sari@icloud.com>).
Add Turkish translations
Jan 27 2022, 10:03 AM
werner committed rEb4f0f809e126: Post release updates (authored by werner).
Post release updates
Jan 27 2022, 10:03 AM
werner committed rE54eff9cb9ac8: Release 1.44 (authored by werner).
Release 1.44
Jan 27 2022, 10:03 AM
werner triaged T5802: Release libgpg-error 1.45 as Low priority.
Jan 27 2022, 10:00 AM · Release Info, gpgrt
ikloecker changed the status of T5801: Kleopatra: Add support for the new dirmngr/ldapserver option to configure X.509 servers from Open to Testing.

This change adds support for the new "ldapserver" option of dirmngr.
The now deprecated "keyserver" option of gpgsm is still read, but
changes are always written to the new option (and the old option is
cleared). This change removes support for the ancient "LDAP Server"
pseudo-option which new versions of gpgconf no longer support.

Jan 27 2022, 9:21 AM · Restricted Project, kleopatra