Page MenuHome GnuPG
Feed All Stories

Mar 17 2022

werner closed T5880: Old version of Zlib in GnuPG as Resolved.

SWDB updated - thus the latest zlib will be part of the next Windows build.

Mar 17 2022, 8:04 AM · CVE, gnupg (gpg22), gpg4win
tcataldo added a comment to T5854: Windows registry option to prevent modifications to signed/encrypted messages after validation by GpgOL.

we replace the encrypted text and attachments with the decrypted / verified parts

Mar 17 2022, 7:17 AM · gpgol, Feature Request
gniibe added projects to T5673: Using empty passphrase key pair, gpg2.2.9 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful : gnupg (gpg22), Info Needed.
Mar 17 2022, 3:33 AM · gnupg (gpg22), Bug Report
gniibe triaged T5673: Using empty passphrase key pair, gpg2.2.9 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful as Normal priority.

I can't replicate this symptom when I use gnupg1 for creating keys with no passphrase.

Mar 17 2022, 3:31 AM · gnupg (gpg22), Bug Report
gniibe added a project to T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful : Info Needed.
Mar 17 2022, 1:53 AM · gnupg24, Bug Report
gniibe added a comment to T5639: dirmngr uses the wrong Let's encrypt chain.

I think that the particular issue of Let's Encrypt Certificate was handled correctly already.

Mar 17 2022, 1:15 AM · gnupg (gpg22), dirmngr
gniibe added subtasks for T5882: Cross signing certificate in X.509 support: T5445: gpgsm fails to find path to valid X.509 root when cross-signed intermediate certificate is present, T2972: GPGSM: Chain too long on cross signed certificate.
Mar 17 2022, 12:48 AM
gniibe added a parent task for T5445: gpgsm fails to find path to valid X.509 root when cross-signed intermediate certificate is present: T5882: Cross signing certificate in X.509 support.
Mar 17 2022, 12:48 AM · S/MIME, Bug Report
gniibe added a parent task for T2972: GPGSM: Chain too long on cross signed certificate: T5882: Cross signing certificate in X.509 support.
Mar 17 2022, 12:48 AM · Bug Report, gnupg, KDE, S/MIME
gniibe added a subtask for T5882: Cross signing certificate in X.509 support: T5639: dirmngr uses the wrong Let's encrypt chain.
Mar 17 2022, 12:46 AM
gniibe added a parent task for T5639: dirmngr uses the wrong Let's encrypt chain: T5882: Cross signing certificate in X.509 support.
Mar 17 2022, 12:46 AM · gnupg (gpg22), dirmngr
gniibe triaged T5882: Cross signing certificate in X.509 support as Normal priority.
Mar 17 2022, 12:45 AM

Mar 16 2022

aheinecke added a comment to T5850: Kleopatra: "Show not certified certificates" button shows any not fully valid certificates.

Yes, makes more sense to me, too. Maybe another filter "bad" certificates, so that you can bulk delete them for example to clean up your keyring?

Mar 16 2022, 5:09 PM · Restricted Project, kleopatra, Bug Report
ikloecker updated subscribers of T5850: Kleopatra: "Show not certified certificates" button shows any not fully valid certificates.

@aheinecke What do you think?

Mar 16 2022, 4:52 PM · Restricted Project, kleopatra, Bug Report
ikloecker committed rKLEOPATRA5bad3a6b47e6: Do not remove recipient widgets when they become empty (authored by ikloecker).
Do not remove recipient widgets when they become empty
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRA60536ecf8545: Refactor: Use a single flag for keeping track of editing (authored by ikloecker).
Refactor: Use a single flag for keeping track of editing
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAc6fa286c9dd7: Fix passing focus to next recipient widget if removed had focus (authored by ikloecker).
Fix passing focus to next recipient widget if removed had focus
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRA0a86e01d19f6: Prefix error messages with "Error: " (authored by ikloecker).
Prefix error messages with "Error: "
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAac79b61bd885: GIT_SILENT: Make private methods private and c'tor explicit (authored by ikloecker).
GIT_SILENT: Make private methods private and c'tor explicit
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAf246c9803028: Make error state and message of certificate input field more accessible (authored by ikloecker).
Make error state and message of certificate input field more accessible
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAbd4a5291d81a: Disable the Encrypt button if required information is missing (authored by ikloecker).
Disable the Encrypt button if required information is missing
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRA60e3ae56ec2c: Make the error concerning a recipient input field more prominent (authored by ikloecker).
Make the error concerning a recipient input field more prominent
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAba966cc7798f: Perform key lookup only if there is no matching key or group (authored by ikloecker).
Perform key lookup only if there is no matching key or group
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAbc34c70d8983: Treat whitespace-only text as empty (authored by ikloecker).
Treat whitespace-only text as empty
Mar 16 2022, 4:47 PM
ikloecker committed rKLEOPATRAe650628e9b38: Use locateKeysJob instead of keyForMailboxJob for locating key (authored by ikloecker).
Use locateKeysJob instead of keyForMailboxJob for locating key
Mar 16 2022, 4:47 PM
werner lowered the priority of T5750: GpgOL links to an FSF page for "Unsicher GpgOL" from High to Normal.
Mar 16 2022, 4:35 PM · Restricted Project, Feature Request, gpgol
werner claimed T4729: WKD via http_proxy does not work if DNS is broken/unavailable.
Mar 16 2022, 4:31 PM · gnupg (gpg22), Restricted Project, dns, dirmngr
werner raised the priority of T4729: WKD via http_proxy does not work if DNS is broken/unavailable from Normal to High.
Mar 16 2022, 4:30 PM · gnupg (gpg22), Restricted Project, dns, dirmngr
gniibe closed T5157: libgcrypt: ARM64 Builds on macOS fail as Resolved.
Mar 16 2022, 3:09 PM · toolchain, MacOS, libgcrypt, Bug Report
gniibe closed T5157: libgcrypt: ARM64 Builds on macOS fail, a subtask of T5159: make check fails for libgcrypt on Apple Silicon / ARM Mac, as Resolved.
Mar 16 2022, 3:09 PM · Restricted Project, MacOS, libgcrypt, Bug Report
gniibe closed T5120: Incompatible Ed25519 secret key (no-encryption), a subtask of T5114: GnuPG fails to import back generated and exported EdDSA secret key., as Resolved.
Mar 16 2022, 3:07 PM · gnupg, Restricted Project, gpgagent, Bug Report
gniibe closed T5120: Incompatible Ed25519 secret key (no-encryption) as Resolved.
Mar 16 2022, 3:07 PM · gnupg (gpg22), Bug Report
gniibe closed T4931: gnupg unusable with a long path to $HOME as Resolved.
Mar 16 2022, 3:03 PM · Not A Bug, FAQ, gnupg
gniibe closed T4900: OS X 10.12 and dyld: Library not loaded: /usr/local/lib/libgcrypt.20.dylib as Resolved.
Mar 16 2022, 2:55 PM · MacOS, libgcrypt, Bug Report
bernhard added a comment to T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

The current links should be replaced or removed.

Mar 16 2022, 2:43 PM · Restricted Project, Feature Request, gpgol
ikloecker added a comment to T5881: Not all keys available in Security approval window.

You could verify this with another email address containing a +.

Mar 16 2022, 2:39 PM · Bug Report, gpgol
cklassen added a comment to T5881: Not all keys available in Security approval window.

How can I check this, @ikloecker ?

Mar 16 2022, 1:28 PM · Bug Report, gpgol
ikloecker added a comment to T5881: Not all keys available in Security approval window.

Can you check whether the + character in the email addresses is causing this?

Mar 16 2022, 1:07 PM · Bug Report, gpgol
cklassen added a project to T5881: Not all keys available in Security approval window: Bug Report.
Mar 16 2022, 1:01 PM · Bug Report, gpgol
cklassen created T5881: Not all keys available in Security approval window.
Mar 16 2022, 12:59 PM · Bug Report, gpgol
cklassen added a comment to T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

Because I'm just starting with GpgOL: Are we talking about adding links in the "Configure GpgOL" window or are there any other windows? If that is the right window maybe we could add a new tab "FAQ" and add the links there. At first I thought the links could be added to the tab "GpgOL" but there are already many entries and the other tabs don't fit well.

Mar 16 2022, 12:48 PM · Restricted Project, Feature Request, gpgol
gniibe added a comment to T5804: Using empty passphrase key pair, gpg2.3.4 fails to decrypt with error "No passphrase given" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .

I can't replicate this symptom (gpg1 generated key, no problem after migration).
Could you share the *.key file under private-keys-v1.d?

Mar 16 2022, 10:15 AM · gnupg24, Bug Report
gniibe committed rMb2a2158384a9: core: Support keylist mode for op_keylist_from_data. (authored by gniibe).
core: Support keylist mode for op_keylist_from_data.
Mar 16 2022, 8:56 AM
gniibe added a project to T5438: gpgme_op_keylist_from_data_start ignores GPGME_KEYLIST_MODE_SIGS: Restricted Project.
Mar 16 2022, 8:24 AM · gpgme (gpgme 1.23.x), OpenPGP, Bug Report
gniibe claimed T5438: gpgme_op_keylist_from_data_start ignores GPGME_KEYLIST_MODE_SIGS.
Mar 16 2022, 8:20 AM · gpgme (gpgme 1.23.x), OpenPGP, Bug Report
gniibe added a comment to T5809: Expire subkey violates assertion "! sig->hashed".

I think that this commit rG8fd150b05b74: gpg: Remove all support for v3 keys and always create v4-signatures. matters.

Mar 16 2022, 7:37 AM · Restricted Project, gnupg (gpg22), Bug Report
gniibe moved T5835: libgcrypt: More robust/portable integrity check from Next to Ready for release on the FIPS board.
Mar 16 2022, 6:16 AM · Bug Report, libgcrypt, FIPS
l10n daemon script <scripty@kde.org> committed rKLEOPATRA67a26fcfebcc: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Mar 16 2022, 3:12 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA5d097045ef6b: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Mar 16 2022, 1:46 AM

Mar 15 2022

ikloecker added a comment to T5878: State of libexpat-1 in Gpg4win.

Not relevant for Windows, but for the AppImage: Qt's X11 xcb platform plugin depends on libfontconfig and therefore indirectly depends on libexpat. So, at least on Linux X11, pinentry-qt and Kleopatra both load libexpat.

Mar 15 2022, 7:26 PM · gpg4win
werner committed rDccca767997cf: swdb: Update zlib (authored by werner).
swdb: Update zlib
Mar 15 2022, 3:37 PM
werner raised the priority of T5880: Old version of Zlib in GnuPG from Low to Normal.

All 4 CVEs are findings related to standard conforming compiler optimizations which OTOH break long standing assumptions on C coding. “Let us show that our compiler produces the fastes code ever and ignore any assumptions coders had made over the last 50 year”.

Mar 15 2022, 3:22 PM · CVE, gnupg (gpg22), gpg4win
werner set External Link to https://www.openwall.com/lists/oss-security/2016/12/05/21 on T5880: Old version of Zlib in GnuPG.
Mar 15 2022, 3:17 PM · CVE, gnupg (gpg22), gpg4win
aheinecke committed rKLEOPATRAa154b1353c4a: Configure SAST in `.gitlab-ci.yml`, creating this file if it does not already… (authored by aheinecke).
Configure SAST in `.gitlab-ci.yml`, creating this file if it does not already…
Mar 15 2022, 1:23 PM
werner renamed T5879: Source of Pinentry title from Source of password prompt to Source of Pinentry title.
Mar 15 2022, 1:04 PM · pinentry
werner triaged T5880: Old version of Zlib in GnuPG as Low priority.

Right, we are not affected by these CVE because we use only the very basic core in gpg and no higher level functions. At least for GnuPG there will be no update.

Mar 15 2022, 1:01 PM · CVE, gnupg (gpg22), gpg4win
cklassen updated the task description for T5880: Old version of Zlib in GnuPG.
Mar 15 2022, 12:55 PM · CVE, gnupg (gpg22), gpg4win
cklassen created T5880: Old version of Zlib in GnuPG.
Mar 15 2022, 11:59 AM · CVE, gnupg (gpg22), gpg4win
bernhard updated subscribers of T5878: State of libexpat-1 in Gpg4win.

One solution is to remove GPA and pinenty-gtk completely, as the used GTK+ version 2 is end-of-life. @aheinecke already asked on https://lists.wald.intevation.org/pipermail/gpg4win-users-en/2022-March/001740.html for reasons to keep GPA. (For which we should make a new issue).

Mar 15 2022, 11:44 AM · gpg4win
ikloecker added a comment to T5879: Source of Pinentry title.

Do you mean something like this

Mar 15 2022, 10:02 AM · pinentry
gniibe committed rGc6dd9ff92904: scd: Fix DEVINFO with no --watch. (authored by gniibe).
scd: Fix DEVINFO with no --watch.
Mar 15 2022, 7:39 AM

Mar 14 2022

cklassen triaged T5879: Source of Pinentry title as Wishlist priority.
Mar 14 2022, 6:15 PM · pinentry
bernhard added a comment to T5878: State of libexpat-1 in Gpg4win.

because libexpat does contain vulnerabilties

Mar 14 2022, 5:27 PM · gpg4win
cklassen triaged T5878: State of libexpat-1 in Gpg4win as Normal priority.
Mar 14 2022, 12:29 PM · gpg4win
cklassen added a comment to T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

gpgol/doc/gpl.texi (line 9)
gpgol/COPYING-ICONS (line 52)

Mar 14 2022, 11:43 AM · Restricted Project, Feature Request, gpgol
bernhard added a comment to T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

What are the other to places?

Mar 14 2022, 10:57 AM · Restricted Project, Feature Request, gpgol
gniibe added a comment to T5862: authentication with USB token.

And updated scd_validate2.py:

Mar 14 2022, 10:57 AM · gpgagent, Feature Request, scd
gniibe added a comment to T5862: authentication with USB token.

Wrote a pam module which interacts a user for auth:

Mar 14 2022, 10:55 AM · gpgagent, Feature Request, scd
cklassen added a comment to T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

When I greped for links to the FSF page (grep with string "fsf" I found out that there is one link to https://emailselfdefense.fsf.org/en/infographic.html in line 722 of src/ribbon-callbacks.cpp. Is that the link that was meant?

Mar 14 2022, 10:46 AM · Restricted Project, Feature Request, gpgol
bernhard added a comment to T5877: Dependency of libexpat-1.dll.

A simple first step would be to install pinentry-gtk only in the GPA variant.

Mar 14 2022, 9:29 AM · gpa
bernhard updated subscribers of T5750: GpgOL links to an FSF page for "Unsicher GpgOL".

I agree. @cklassen can you make a suggestion?

Mar 14 2022, 9:28 AM · Restricted Project, Feature Request, gpgol
werner committed rD7ee341b561a0: Typo fixes (authored by werner).
Typo fixes
Mar 14 2022, 9:09 AM
werner triaged T5596: Libgcrypt documentation: corrections to obvious misprints as Normal priority.

Thanks for you patches. Most of them applied cleanly despite that I delayed processing them for half a year.

Mar 14 2022, 8:59 AM · libgcrypt, patch, Documentation, Bug Report
Laurent Montel <montel@kde.org> committed rLIBKLEO02d30060e96e: GIT_SILENT: time to increase version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: time to increase version
Mar 14 2022, 7:29 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA11d25c8c9b88: GIT_SILENT: time to increase version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: time to increase version
Mar 14 2022, 7:26 AM

Mar 12 2022

Laurent Montel <montel@kde.org> committed rLIBKLEOde12c129ac5c: GIT_SILENT: prepare 5.20beta (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.20beta
Mar 12 2022, 5:35 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRAf7e55f8acf19: GIT_SILENT: prepare 5.20beta (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: prepare 5.20beta
Mar 12 2022, 5:34 PM
Valodim added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

@mieth sorry for the delay. meanwhile I adjusted the ciphersuite of the WKD gateway to include an AES-CBC suite. would be interested if it works now on the setup you tested before.

Mar 12 2022, 2:27 PM · wkd, gpg4win, Bug Report
Laurent Montel <montel@kde.org> committed rLIBKLEO2ed97c744556: GIT_SILENT: Prepare beta1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare beta1
Mar 12 2022, 1:49 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRAfc9f8cb9c5b9: GIT_SILENT: Prepare beta1 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare beta1
Mar 12 2022, 1:45 PM
Albert Astals Cid <aacid@kde.org> committed rKLEOPATRA4726377ea9ad: GIT_SILENT Upgrade release service version to 22.07.70. (authored by Albert Astals Cid <aacid@kde.org>).
GIT_SILENT Upgrade release service version to 22.07.70.
Mar 12 2022, 1:22 PM
Albert Astals Cid <aacid@kde.org> committed rKLEOPATRA7ff9c0498be6: GIT_SILENT Upgrade release service version to 22.03.80. (authored by Albert Astals Cid <aacid@kde.org>).
GIT_SILENT Upgrade release service version to 22.03.80.
Mar 12 2022, 12:46 PM
jukivili updated the task description for T4460: libgcrypt performance TODOs.
Mar 12 2022, 9:40 AM · libgcrypt
jukivili updated the task description for T4460: libgcrypt performance TODOs.
Mar 12 2022, 9:39 AM · libgcrypt
jukivili closed T5828: Improvements for gnupg data operation performance (enc/dec/sign/verify/enarmor/dearmor/etc) as Resolved.
Mar 12 2022, 9:38 AM · gnupg
jukivili closed T5860: Reducing memory copy overhead in iobuf and estream to increase OCB speed as Resolved.
Mar 12 2022, 9:38 AM · gnupg
jukivili closed T5860: Reducing memory copy overhead in iobuf and estream to increase OCB speed, a subtask of T5828: Improvements for gnupg data operation performance (enc/dec/sign/verify/enarmor/dearmor/etc), as Resolved.
Mar 12 2022, 9:38 AM · gnupg
jukivili committed rCa0db0a121571: Fix building sha512-avx512 with clang (authored by jukivili).
Fix building sha512-avx512 with clang
Mar 12 2022, 9:34 AM

Mar 11 2022

jukivili committed rC089223aa3b55: SHA512: Add AVX512 implementation (authored by jukivili).
SHA512: Add AVX512 implementation
Mar 11 2022, 4:34 PM
bernhard committed rW840b0eeb2570: Remove Jan-Oliver as Geschäftsführer Intevation (authored by bernhard).
Remove Jan-Oliver as Geschäftsführer Intevation
Mar 11 2022, 4:10 PM
aheinecke added a comment to T5877: Dependency of libexpat-1.dll.

I think this is because we install pinentry-gtk, too. So we have that GTK dependency.

Mar 11 2022, 1:47 PM · gpa
cklassen triaged T5877: Dependency of libexpat-1.dll as Low priority.
Mar 11 2022, 1:39 PM · gpa
Laurent Montel <montel@kde.org> committed rLIBKLEOd9119e21f6a7: GIT_SILENT: add coverage support in CMakePresets.json (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: add coverage support in CMakePresets.json
Mar 11 2022, 1:35 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRA0c18ce9291d1: GIT_SILENT: add coverage support in CMakePresets.json (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: add coverage support in CMakePresets.json
Mar 11 2022, 1:31 PM
gniibe committed rG665b59a0663d: Fix previous commit. (authored by gniibe).
Fix previous commit.
Mar 11 2022, 6:11 AM
gniibe added a comment to rG934864d399bb: scd: Enhance PASSWD command to accept KEYGRIP optionally..

Thank you for your comment.

Mar 11 2022, 6:07 AM

Mar 10 2022

ikloecker committed rKLEOPATRA0d2cb43c681c: Focus first unresolved recipient if validation fails (authored by ikloecker).
Focus first unresolved recipient if validation fails
Mar 10 2022, 3:50 PM
ikloecker closed T5876: Kleopatra: Make certificate selection dialog accessible, a subtask of T5824: Kleopatra: Full accessibility support, as Resolved.
Mar 10 2022, 3:26 PM · kleopatra
ikloecker closed T5876: Kleopatra: Make certificate selection dialog accessible as Resolved.
Mar 10 2022, 3:26 PM · kleopatra, Restricted Project
ikloecker committed rLIBKLEOcba503affb7c: More accessible text representations for not applicable model entries (authored by ikloecker).
More accessible text representations for not applicable model entries
Mar 10 2022, 3:25 PM