Page MenuHome GnuPG
Feed All Stories

Oct 19 2022

werner committed rD2ab884d58ee0: web: Add download links for GnuPG Desktop 2.3.8 (authored by werner).
web: Add download links for GnuPG Desktop 2.3.8
Oct 19 2022, 3:40 PM
werner added a comment to T6243: SMIME on Outlook not working, if GPG-Plugin installed.

This is the first report we have on such a problem despite of hundred thousands of users. "Triage" means that we need to look at a report to check its priority.

Oct 19 2022, 1:53 PM · gpgol, Bug Report
ikloecker committed rKLEOPATRAa3d6a7be6566: Defer mapping the generic algorithm IDs to specific ones (authored by ikloecker).
Defer mapping the generic algorithm IDs to specific ones
Oct 19 2022, 12:28 PM
ikloecker committed rKLEOPATRA434563868a65: Ask the smart cards for the supported algorithms (authored by ikloecker).
Ask the smart cards for the supported algorithms
Oct 19 2022, 12:28 PM
ikloecker committed rKLEOPATRA02ef04c27daf: Allow setting/retrieving supported algorithms of OpenPGP smart cards (authored by ikloecker).
Allow setting/retrieving supported algorithms of OpenPGP smart cards
Oct 19 2022, 12:28 PM
ikloecker committed rKLEOPATRAb3dcee2709ef: Add simple struct for information on algorithms (authored by ikloecker).
Add simple struct for information on algorithms
Oct 19 2022, 12:28 PM
ikloecker committed rKLEOPATRA311a86798e36: Allow (re-)generating individual keys of OpenPGP smart cards (authored by ikloecker).
Allow (re-)generating individual keys of OpenPGP smart cards
Oct 19 2022, 12:28 PM
ikloecker committed rKLEOPATRA770f60e9a685: Set supported algorithms of a few OpenPGP smart cards (authored by ikloecker).
Set supported algorithms of a few OpenPGP smart cards
Oct 19 2022, 12:28 PM
Harrypotter06 updated subscribers of T6243: SMIME on Outlook not working, if GPG-Plugin installed.

@werner , why set to "needs triage"? At this moment plugin must be disabled if customer read crypted SMIME E-Mails. So it is critical. disable checkbox "SMIME" will not work correct. Enable "SMIME" will only encrypt as Text, but some E-Mails have HTML.
We have this issue on all systems (Windows 10 and Windows 11)

Oct 19 2022, 12:21 PM · gpgol, Bug Report
werner raised the priority of T6243: SMIME on Outlook not working, if GPG-Plugin installed from High to Needs Triage.
Oct 19 2022, 12:09 PM · gpgol, Bug Report
gniibe added a comment to T6248: FIPS compliant RSA OAEP encryption.

Please note that: libgcrypt offers ECDH functionality by gcry_pk_encrypt/gcry_pk_decrypt to construct OpenPGP public-key encryption/decryption.

Oct 19 2022, 9:05 AM · libgcrypt, FIPS, Feature Request
werner triaged T6248: FIPS compliant RSA OAEP encryption as Normal priority.

So, this is only for OAEP but not for ECDH? FWIW, GnUPG uses OAEP only for S/MIME.

Oct 19 2022, 7:54 AM · libgcrypt, FIPS, Feature Request
gniibe committed rE494886acb0bf: spawn: Update changes from gnupg. (authored by gniibe).
spawn: Update changes from gnupg.
Oct 19 2022, 7:25 AM
gniibe committed rCb77e7a225bc4: tests: Use proper format string for size_t (authored by Jakuje).
tests: Use proper format string for size_t
Oct 19 2022, 7:17 AM
gniibe committed rC4e7941587c95: cipher: Do not run RSA encryption selftest by default (authored by Jakuje).
cipher: Do not run RSA encryption selftest by default
Oct 19 2022, 7:17 AM
gniibe added a reverting change for rCf736f3c70182: tests: Expect the RSA PKCS #1.5 encryption to fail in FIPS mode: rC7468cdfc8b6a: Revert "tests: Expect the RSA PKCS #1.5 encryption to fail in FIPS mode".
Oct 19 2022, 7:17 AM
gniibe committed rC7468cdfc8b6a: Revert "tests: Expect the RSA PKCS #1.5 encryption to fail in FIPS mode" (authored by Jakuje).
Revert "tests: Expect the RSA PKCS #1.5 encryption to fail in FIPS mode"
Oct 19 2022, 7:17 AM
gniibe committed rCe83280b36be3: Revert "Do not allow PKCS #1.5 padding for encryption in FIPS" (authored by Jakuje).
Revert "Do not allow PKCS #1.5 padding for encryption in FIPS"
Oct 19 2022, 7:17 AM
gniibe added a reverting change for rCc7709f7b2384: Do not allow PKCS #1.5 padding for encryption in FIPS: rCe83280b36be3: Revert "Do not allow PKCS #1.5 padding for encryption in FIPS".
Oct 19 2022, 7:17 AM
gniibe committed rC9d56af04dce0: Revert "tests: Expect the OEAP tests to fail in FIPS mode." (authored by Jakuje).
Revert "tests: Expect the OEAP tests to fail in FIPS mode."
Oct 19 2022, 7:17 AM
gniibe added a reverting change for rC249ca431ef88: tests: Expect the OEAP tests to fail in FIPS mode.: rC9d56af04dce0: Revert "tests: Expect the OEAP tests to fail in FIPS mode.".
Oct 19 2022, 7:17 AM
gniibe committed rCc5de9e77fb33: fips: Fix fips indicator function. (authored by Jakuje).
fips: Fix fips indicator function.
Oct 19 2022, 7:17 AM
gniibe added a reverting change for rCe552e37983da: fips: Disable RSA-OAEP padding in FIPS mode.: rCa7b5cab05f6a: Revert "fips: Disable RSA-OAEP padding in FIPS mode.".
Oct 19 2022, 7:17 AM
gniibe committed rCa7b5cab05f6a: Revert "fips: Disable RSA-OAEP padding in FIPS mode." (authored by Jakuje).
Revert "fips: Disable RSA-OAEP padding in FIPS mode."
Oct 19 2022, 7:17 AM
gniibe committed rC05cb8355d3e6: fips: Mark gcry_pk_encrypt/decrypt function non-approved. (authored by Jakuje).
fips: Mark gcry_pk_encrypt/decrypt function non-approved.
Oct 19 2022, 7:17 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO58d94892b1d6: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 19 2022, 4:07 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA9f72d2d76e9b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 19 2022, 4:05 AM
gniibe changed the status of T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46 from Open to Testing.
Oct 19 2022, 3:21 AM · Windows, gnupg (gpg22), Bug Report
gniibe changed the status of T6239: gnugp 2.3.8 fails to build with --disable-ldap from Open to Testing.
Oct 19 2022, 3:20 AM · gnupg, Bug Report
gniibe added a comment to T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance).

It's not that needed, in my opinion, as nobody actually uses ECB itself (in real use case). But I understand the point of (possibly, students') benchmarking.

Oct 19 2022, 3:19 AM · libgcrypt, Feature Request
gniibe triaged T6249: gpgrt: spawn functions as Normal priority.
Oct 19 2022, 3:12 AM · gnupg, libassuan, gpgrt

Oct 18 2022

werner added a comment to T6228: TOFU data are not updated when creating an encrypted message.

FWIW: I am not anymore very convinced of our tofu code. it leaks too many information because it tracks and stored all signature verification. The model is further way too complicated and the SQL used will eventually lead to a resource problem. Maybe doing Tofu stuff in the frontend is a better idea and get rid of all the history processing which works only for fresh mails and not for data verification.

Oct 18 2022, 5:55 PM · gpgme, TOFU
ikloecker added a comment to T6228: TOFU data are not updated when creating an encrypted message.

Yes it is set to tofu+pgp. Is it now possible to change the trust-model on context based?

Oct 18 2022, 2:41 PM · gpgme, TOFU
hefee added a comment to T6228: TOFU data are not updated when creating an encrypted message.

Thanks for the report, since you are using it on the command line and it works I assume that trust-model is set to tofu+pgp? Because in the Test code there is no context flag for tofu+pgp trust model.

Oct 18 2022, 1:52 PM · gpgme, TOFU
Jakuje created T6248: FIPS compliant RSA OAEP encryption.
Oct 18 2022, 11:57 AM · libgcrypt, FIPS, Feature Request
aheinecke triaged T6228: TOFU data are not updated when creating an encrypted message as Normal priority.

Thanks for the report, since you are using it on the command line and it works I assume that trust-model is set to tofu+pgp? Because in the Test code there is no context flag for tofu+pgp trust model.

Oct 18 2022, 11:52 AM · gpgme, TOFU
aheinecke merged T6247: Cannot create protable version into T6246: Gpg4win: Mkportable only allow portable installer with installed features.
Oct 18 2022, 11:47 AM · Installer, gpg4win
aheinecke merged task T6247: Cannot create protable version into T6246: Gpg4win: Mkportable only allow portable installer with installed features.
Oct 18 2022, 11:47 AM · gpg4win, Bug Report
aheinecke added a comment to T6247: Cannot create protable version.

I tend to close this as a duplicate.

Oct 18 2022, 11:47 AM · gpg4win, Bug Report
cklassen created T6247: Cannot create protable version.
Oct 18 2022, 11:43 AM · gpg4win, Bug Report
gniibe committed rXf21d98756952: build: Remove --with-*-prefix. (authored by gniibe).
build: Remove --with-*-prefix.
Oct 18 2022, 11:21 AM
gniibe committed rX18b78e2f473b: build: Update gpg-error.m4 and libassuan.m4. (authored by gniibe).
build: Update gpg-error.m4 and libassuan.m4.
Oct 18 2022, 11:21 AM
aheinecke triaged T6246: Gpg4win: Mkportable only allow portable installer with installed features as Low priority.
Oct 18 2022, 11:03 AM · Installer, gpg4win
aheinecke claimed T6245: GpgOL: build: Update for new gpgrt-config and *.pc.

Cool, I will try it out ASAP. You must have read my mind. Only yesterday evening I ran into problems because the current code in src/Makefile.am to symlink the static libs did not work on my new dev system with a lib64 layout and thought that I needed just a patch like this to fix it properly.

Oct 18 2022, 10:50 AM · Windows, gpgol, Feature Request
aheinecke triaged T6240: Kleopatra: Add column for groups in the certificate view as Wishlist priority.

We need to understand the usecase here.

Oct 18 2022, 10:45 AM · kleopatra, Restricted Project
gniibe added projects to T6245: GpgOL: build: Update for new gpgrt-config and *.pc: Feature Request, gpgol, Windows.
Oct 18 2022, 9:14 AM · Windows, gpgol, Feature Request
carlocab awarded rGa5c382166488: dirmngr: Fix build with no LDAP support. a Party Time token.
Oct 18 2022, 8:08 AM
werner added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

We already detect mail addresses for different purposes and thus it will be easy to enclose them in angle brackets just for comparision.. Almost all trust signatures out there are created by gpg and used to restrict the mail domain. No need for different regexp. See also the comments in the code related to the history.

Oct 18 2022, 8:03 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner closed T6230: Release Libksba 1.6.2 (CVE-2022-3515) as Resolved.
Oct 18 2022, 7:52 AM · CVE, Release Info, libksba
gniibe added a comment to T6245: GpgOL: build: Update for new gpgrt-config and *.pc.

Here we go:

Oct 18 2022, 7:38 AM · Windows, gpgol, Feature Request
gniibe created T6245: GpgOL: build: Update for new gpgrt-config and *.pc.
Oct 18 2022, 7:37 AM · Windows, gpgol, Feature Request
l10n daemon script <scripty@kde.org> committed rLIBKLEO9462875e8192: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Oct 18 2022, 5:07 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOc588c121ea27: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 18 2022, 4:09 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA569c14e3350f: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 18 2022, 4:03 AM
gniibe committed rG0f13ccd0e070: gpg: Move NETLIBS after GPG_ERROR_LIBS. (authored by gniibe).
gpg: Move NETLIBS after GPG_ERROR_LIBS.
Oct 18 2022, 3:36 AM
gniibe added a comment to T6239: gnugp 2.3.8 fails to build with --disable-ldap.

Applied also in 2.2 branch.

Oct 18 2022, 3:34 AM · gnupg, Bug Report
gniibe committed rG256b3c05789d: gpg: Move NETLIBS after GPG_ERROR_LIBS (another). (authored by gniibe).
gpg: Move NETLIBS after GPG_ERROR_LIBS (another).
Oct 18 2022, 3:34 AM
gniibe committed rGb26bb03ed96f: gpg: Move NETLIBS after GPG_ERROR_LIBS. (authored by gniibe).
gpg: Move NETLIBS after GPG_ERROR_LIBS.
Oct 18 2022, 3:34 AM
gniibe committed rGa5c382166488: dirmngr: Fix build with no LDAP support. (authored by gniibe).
dirmngr: Fix build with no LDAP support.
Oct 18 2022, 3:34 AM
gniibe added a comment to T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.

Ah, sorry, I did my own changes before looking T6244#164317

Oct 18 2022, 3:33 AM · Windows, gnupg (gpg22), Bug Report
gniibe added a comment to T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.

Pushed the changes to 2.2 and master.

Oct 18 2022, 3:31 AM · Windows, gnupg (gpg22), Bug Report
gniibe claimed T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.

Thank you for your report. The issue is handling of static linking in GnuPG.

Oct 18 2022, 2:49 AM · Windows, gnupg (gpg22), Bug Report
savoury1 added a comment to T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.

Renamed bug due it being incorrect to assume this was a bug with libgpg-error. Turns out that a simple patch to g10/Makefile.am in GnuPG 2.2.40 LTS source fixes the linking error. Patch that fixed build for me is attached, which basically puts -lws2_32 in the correct location for builds with the new libgpg-error 1.46 version.

Oct 18 2022, 2:19 AM · Windows, gnupg (gpg22), Bug Report
savoury1 renamed T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46 from Libgpg-error: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46 to GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.
Oct 18 2022, 2:15 AM · Windows, gnupg (gpg22), Bug Report

Oct 17 2022

neal added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

It will be hard to fix this. GnuPG supports exactly one class of regular expressions: something bracketed between "<[^>]+[@.]" and ">$" . Even if the next release of gpg supports more regular expressions, gpg will have to wait years before it can start emitting different regular expressions for scoped tsigs by default.

Oct 17 2022, 10:30 PM · backport, gnupg (gpg22), Bug Report, Restricted Project
dkg added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

I recommend, when making a User ID with only an e-mail address, to populate the User IDs by wrapping it in an angle bracket, rather than just leaving the raw e-mail address. It's not just the regexp matcher -- there are other pieces of OpenPGP software that won't recognize a raw e-mail address in a user ID as an e-mail address. It also makes it easy to distinguish such a User ID from a User ID that is not at all an e-mail address.

Oct 17 2022, 10:23 PM · backport, gnupg (gpg22), Bug Report, Restricted Project
savoury1 created T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46.
Oct 17 2022, 8:22 PM · Windows, gnupg (gpg22), Bug Report
werner committed rD85cd5e211ac7: web: Add security advisory (authored by werner).
web: Add security advisory
Oct 17 2022, 3:52 PM
Harrypotter06 triaged T6243: SMIME on Outlook not working, if GPG-Plugin installed as High priority.
Oct 17 2022, 3:06 PM · gpgol, Bug Report
Harrypotter06 created T6243: SMIME on Outlook not working, if GPG-Plugin installed.
Oct 17 2022, 3:06 PM · gpgol, Bug Report
werner closed T6106: Release GnuPG 2.3.8 as Resolved.
Oct 17 2022, 3:04 PM · Release Info, gnupg (gpg23)
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2022q4/000476.html on T6106: Release GnuPG 2.3.8.
Oct 17 2022, 3:04 PM · Release Info, gnupg (gpg23)
werner added a comment to T6230: Release Libksba 1.6.2 (CVE-2022-3515).

Fixed Gpg4win version: https://lists.wald.intevation.org/pipermail/gpg4win-announce/2022/000098.html

Oct 17 2022, 3:03 PM · CVE, Release Info, libksba
zerbey awarded T6239: gnugp 2.3.8 fails to build with --disable-ldap a Like token.
Oct 17 2022, 2:05 PM · gnupg, Bug Report
mlaurent committed rKLEOPATRA9fd929a6274c: Port to not deprecated methods (authored by mlaurent).
Port to not deprecated methods
Oct 17 2022, 1:41 PM
aheinecke committed rWdd038f170752: web: Fix notification link for 4.0.4 (authored by aheinecke).
web: Fix notification link for 4.0.4
Oct 17 2022, 12:45 PM
werner committed rW2bd00a3c6fc1: appimage: Typo fix (authored by werner).
appimage: Typo fix
Oct 17 2022, 10:49 AM
aheinecke committed rW702b3b655958: web: Add 4.0.4 Release info (authored by aheinecke).
web: Add 4.0.4 Release info
Oct 17 2022, 9:56 AM
werner committed rD3748173afd84: swdb: GnuPG 2.2.40 (authored by werner).
swdb: GnuPG 2.2.40
Oct 17 2022, 9:39 AM
werner committed rD6ec37744ca4e: Security Advisory 6230 (authored by werner).
Security Advisory 6230
Oct 17 2022, 9:39 AM
werner committed rDf9f83f9583aa: Add CVE to the security advisory (authored by werner).
Add CVE to the security advisory
Oct 17 2022, 9:39 AM
werner committed rD4a5133ae6c77: swdb: gpg4win 4.0.4 and gnupgdesk 2.3.8 (authored by werner).
swdb: gpg4win 4.0.4 and gnupgdesk 2.3.8
Oct 17 2022, 9:39 AM
werner committed rDfb5e37e091cc: swdb: GnuPG 2.3.8 (authored by werner).
swdb: GnuPG 2.3.8
Oct 17 2022, 9:39 AM
werner set External Link to https://gnupg.org/blog/20221017-pepe-left-the-ksba.html on T6230: Release Libksba 1.6.2 (CVE-2022-3515).
Oct 17 2022, 9:26 AM · CVE, Release Info, libksba
werner added a comment to T6230: Release Libksba 1.6.2 (CVE-2022-3515).

As usual see https://gnupg.org/download for links to the latest packages. For Gpg4win see https://gpg4win.org

Oct 17 2022, 9:25 AM · CVE, Release Info, libksba
werner reopened T6230: Release Libksba 1.6.2 (CVE-2022-3515) as "Open".
Oct 17 2022, 7:56 AM · CVE, Release Info, libksba
werner renamed T6230: Release Libksba 1.6.2 (CVE-2022-3515) from Release Libksba 1.6.2 to Release Libksba 1.6.2 (CVE-2022-3515).
Oct 17 2022, 7:56 AM · CVE, Release Info, libksba
werner updated the task description for T6230: Release Libksba 1.6.2 (CVE-2022-3515).
Oct 17 2022, 7:46 AM · CVE, Release Info, libksba
l10n daemon script <scripty@kde.org> committed rKLEOPATRA55fc28074980: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Oct 17 2022, 4:51 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAd724f0cbe740: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 17 2022, 4:20 AM
gniibe claimed T6241: cross-compile fails after commit 745d333cf7b5b6fee62e3b26c8a2ccc004e017da.

Thank you for your report. IIUC, your log is the build log of GnuPG 2.2, so, I put the tag "gnupg (gpg22)".

Oct 17 2022, 3:22 AM · workaround, gnupg (gpg22), gpgrt, Bug Report

Oct 16 2022

jukivili created T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance).
Oct 16 2022, 4:57 PM · libgcrypt, Feature Request
hydra3333 created T6241: cross-compile fails after commit 745d333cf7b5b6fee62e3b26c8a2ccc004e017da.
Oct 16 2022, 6:47 AM · workaround, gnupg (gpg22), gpgrt, Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA6800453a5265: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 16 2022, 4:17 AM

Oct 15 2022

mlaurent committed rKLEOPATRA666341bc6954: Adapt to new api (scripted) (authored by mlaurent).
Adapt to new api (scripted)
Oct 15 2022, 10:16 PM
carlocab added a comment to T6181: Release GnuPG 2.2.40.

I believe https://dev.gnupg.org/T6239 also applies here. It would be great if the fix could be backported.

Oct 15 2022, 5:24 PM · gnupg (gpg22), Release Info
carlocab added a comment to T6239: gnugp 2.3.8 fails to build with --disable-ldap.

This also affects 2.2.40. Will the fix be backported there? Thanks.

Oct 15 2022, 8:07 AM · gnupg, Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA4c7fb0d0f77a: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Oct 15 2022, 5:24 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAbcb4ba2207c8: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Oct 15 2022, 4:44 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAefe28074c427: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 15 2022, 4:13 AM