Page MenuHome GnuPG
Feed All Stories

Oct 24 2022

gniibe committed rMd36905bb80c4: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:44 AM
gniibe committed rTa26eff802ff7: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:43 AM
gniibe committed rKc3c1627f3423: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:42 AM
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Okay. So, I removed gpg-error-config, updated libgcrypt/m4/gpg-error.m4, and then rebuilt configure. And, gcrypt configures and builds.

Oct 24 2022, 5:33 AM · MacOS, libgcrypt, gpgrt
gniibe committed rSb1c776b5ffc8: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:24 AM
gniibe committed rC12b3bc5a0d9c: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:18 AM
gniibe committed rA6d5a2b1425b2: Fix an explanation for socket on Windows. (authored by gniibe).
Fix an explanation for socket on Windows.
Oct 24 2022, 5:15 AM
gniibe committed rA0c22952c71bd: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:15 AM
gniibe committed rGb9d05774f565: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:12 AM
gniibe committed rG54d001cc7cda: build: Update gpg-error.m4. (authored by gniibe).
build: Update gpg-error.m4.
Oct 24 2022, 5:11 AM
gniibe added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Thank you for the information.

Oct 24 2022, 5:06 AM · MacOS, libgcrypt, gpgrt
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Actually, it looks as if libgpg-error-1.46 already has that fix.

Oct 24 2022, 5:03 AM · MacOS, libgcrypt, gpgrt
gniibe added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Thank you for your quick reply.

Oct 24 2022, 4:51 AM · MacOS, libgcrypt, gpgrt
gniibe removed a project from T5010: gpgrt-config: Bug for handling Requires: Restricted Project.
Oct 24 2022, 4:48 AM · gpgrt
gniibe removed a project from T5595: gpgrt-config doesn't work well with PKG_CONFIG_LIBDIR="" and setting PKG_CONFIG_PATH: Restricted Project.
Oct 24 2022, 4:47 AM · gpgrt
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Yes, it is on macOS.

Oct 24 2022, 4:41 AM · MacOS, libgcrypt, gpgrt
gniibe claimed T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

From the information in gpg-error.pc, I think it's on macOS.

Oct 24 2022, 4:35 AM · MacOS, libgcrypt, gpgrt
gniibe committed rGe4ac00960c94: po: Update Simplified Chinese Translation. (authored by bobwxc).
po: Update Simplified Chinese Translation.
Oct 24 2022, 3:51 AM
gniibe added a comment to D562: po: Update Simplified Chinese Translation..

Pushed rGe4ac00960c94: po: Update Simplified Chinese Translation..

Oct 24 2022, 3:39 AM
gniibe accepted D562: po: Update Simplified Chinese Translation..
Oct 24 2022, 3:24 AM
seblu added a comment to T5110: Primary Key Binding Signature not updated when updating Subkey Binding Signature.

In order to remove the SHA-1 algorithm in Arch Linux package keyring, I need to resign one of my sub keys but the backsig (0x19) remain in SHA-1 as reported here.
I didn't find any solution with gnupg to update it since this bug report was opened in 2020. Do you plan to address this in a near future?

Oct 24 2022, 2:13 AM · gnupg, Bug Report
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

T5683: Deprecation of gpg-error-config

Oct 24 2022, 1:25 AM · MacOS, libgcrypt, gpgrt
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Contents of /usr/local/lib/pkgconfig/gpg-error.pc:

Oct 24 2022, 1:21 AM · MacOS, libgcrypt, gpgrt
debohman added a comment to T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.

Manually installing gpg-error-config in /usr/local/bin allows libgcrypt to configure and build.

Oct 24 2022, 1:03 AM · MacOS, libgcrypt, gpgrt
debohman created T6257: Without gpg-error-config installed (libgpg-error-1.46) libgcrypt-1.10.1 does not configure.
Oct 24 2022, 12:59 AM · MacOS, libgcrypt, gpgrt

Oct 22 2022

bobwxc requested review of D562: po: Update Simplified Chinese Translation..
Oct 22 2022, 1:52 PM
l10n daemon script <scripty@kde.org> committed rLIBKLEO520f0cf83fe3: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 22 2022, 1:41 PM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA076d21c504b2: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 22 2022, 1:34 PM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAaf691d1db07c: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 22 2022, 3:56 AM

Oct 21 2022

un99known99 added a comment to T6256: Version > 4.0.0 DLL not found.

Hi Werner,

Oct 21 2022, 12:43 PM · gpg4win, Support
werner edited projects for T6256: Version > 4.0.0 DLL not found, added: Support, gpg4win; removed Bug Report.

An old version is still installed and the libgpg-error-0.dll could not be replaced. Make sure that you deinstalled old gpg4win versions and other gnupg versions. The file version of the DLL shall be 1.46.x.x.

Oct 21 2022, 11:46 AM · gpg4win, Support
gniibe added a comment to T6249: gpgrt: spawn functions.

I see. I understand the use cases for POSIX to keep some file descriptors.

Oct 21 2022, 8:41 AM · gnupg, libassuan, gpgrt
un99known99 updated the task description for T6256: Version > 4.0.0 DLL not found.
Oct 21 2022, 8:20 AM · gpg4win, Support
un99known99 updated the task description for T6256: Version > 4.0.0 DLL not found.
Oct 21 2022, 8:18 AM · gpg4win, Support
un99known99 created T6256: Version > 4.0.0 DLL not found.
Oct 21 2022, 8:18 AM · gpg4win, Support
raysatiro added a comment to T6255: --list-keys output truncated and loops repeatedly.

I don't have common.conf but I do have pubring.kbx. I meant I plan to remove that key from my keyring because it's like a decade old and expired, but I figured maybe it was somehow related to this bug since it's the last key shown, so I've left it in.

Oct 21 2022, 7:17 AM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report
werner added a comment to T6255: --list-keys output truncated and loops repeatedly.

Are you using the keyboxd ? ("use-keyboxd" in common.conf) or is this using the default pubring.kbx.

Oct 21 2022, 6:25 AM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA4672e9439afb: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 21 2022, 4:16 AM

Oct 20 2022

werner triaged T6254: Warn in --recv-keys verbose output that no keys have been imported as Normal priority.
Oct 20 2022, 10:14 PM · gnupg24, Keyserver, Bug Report
werner added projects to T6254: Warn in --recv-keys verbose output that no keys have been imported: gnupg (gpg23), Keyserver.

Oh yes, the usual import statistics should be shown here.

Oct 20 2022, 10:14 PM · gnupg24, Keyserver, Bug Report
raysatiro created T6255: --list-keys output truncated and loops repeatedly.
Oct 20 2022, 10:11 PM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report
werner edited projects for T6235: Problem editing Expiration Time, added: Feature Request, gnupg (gpg23); removed Bug Report.
Oct 20 2022, 10:10 PM · gnupg24, Feature Request
raysatiro created T6254: Warn in --recv-keys verbose output that no keys have been imported.
Oct 20 2022, 9:56 PM · gnupg24, Keyserver, Bug Report
Jakuje added a comment to T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF.

In regards to this issue, we were also notified that the MD API using gcry_md_setkey() can be used to calculate HMACs and it does not have the needed input key length limitation. From the discussion here I read that we would like to keep the internal usage still available so my proposal would be to to add similar check as in gcry_mac_setkey() into the above function. Together with the revert, it is available in the following merge request:

Oct 20 2022, 6:33 PM · backport, libgcrypt, FIPS
werner committed rGed62b74a175e: gpgsm: Create ECC certificates with AKI and SKI by default. (authored by werner).
gpgsm: Create ECC certificates with AKI and SKI by default.
Oct 20 2022, 5:34 PM
werner committed rG9f1181e1a7ed: gpgsm: Print the key types as standard key algorithm strings. (authored by werner).
gpgsm: Print the key types as standard key algorithm strings.
Oct 20 2022, 5:34 PM
werner committed rG5ae2632002c0: gpgsm: Support decryption of ECDH data (authored by werner).
gpgsm: Support decryption of ECDH data
Oct 20 2022, 5:34 PM
werner committed rG8b2c55d3c5da: gpgsm: Remove restriction of key generation (only RSA). (authored by gniibe).
gpgsm: Remove restriction of key generation (only RSA).
Oct 20 2022, 5:34 PM
werner committed rG37a853d808f0: gpgsm: Support key generation with ECC. (authored by gniibe).
gpgsm: Support key generation with ECC.
Oct 20 2022, 5:34 PM
werner added a parent task for T6252: Support ECC for Netkey cards also in 2.2: T6253: GpgSM: Backport ECC support to 2.2.
Oct 20 2022, 2:33 PM · gnupg (gpg22), scd, Restricted Project
werner added a subtask for T6253: GpgSM: Backport ECC support to 2.2: T6252: Support ECC for Netkey cards also in 2.2.
Oct 20 2022, 2:33 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner triaged T6253: GpgSM: Backport ECC support to 2.2 as High priority.
Oct 20 2022, 2:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner changed the status of T6252: Support ECC for Netkey cards also in 2.2, a subtask of T4938: Support Signature Card V2.0 (NKS15), from Open to Testing.
Oct 20 2022, 2:12 PM · eIDAS, scd, Feature Request, S/MIME
werner changed the status of T6252: Support ECC for Netkey cards also in 2.2 from Open to Testing.
Oct 20 2022, 2:12 PM · gnupg (gpg22), scd, Restricted Project
werner added a parent task for T6252: Support ECC for Netkey cards also in 2.2: T4938: Support Signature Card V2.0 (NKS15).
Oct 20 2022, 2:11 PM · gnupg (gpg22), scd, Restricted Project
werner added a subtask for T4938: Support Signature Card V2.0 (NKS15): T6252: Support ECC for Netkey cards also in 2.2.
Oct 20 2022, 2:11 PM · eIDAS, scd, Feature Request, S/MIME
werner added a comment to T6249: gpgrt: spawn functions.

without this list we don't have an option to keep file descriptors open; its not just stderr but for example log files and descriptors which pare passed by other meands than libassuan functions.

Oct 20 2022, 1:52 PM · gnupg, libassuan, gpgrt
werner committed rG1e69676981ac: scd:nks: Don't flag the ESIGN keypair EF as encryption capable. (authored by werner).
scd:nks: Don't flag the ESIGN keypair EF as encryption capable.
Oct 20 2022, 12:23 PM
werner committed rGf24904ee3540: scd:nks: Some code cleanup. (authored by werner).
scd:nks: Some code cleanup.
Oct 20 2022, 12:23 PM
werner committed rG5cd25f4ca485: scd:nks: Support the Telesec ESIGN application. (authored by werner).
scd:nks: Support the Telesec ESIGN application.
Oct 20 2022, 12:23 PM
werner committed rGb19958278931: scd:nks: Return USAGE information for KEYINFO command. (authored by gniibe).
scd:nks: Return USAGE information for KEYINFO command.
Oct 20 2022, 12:23 PM
werner committed rG8bccd95b38f2: scd:nks: Add support for signing plain SHA-2 digests. (authored by ikloecker).
scd:nks: Add support for signing plain SHA-2 digests.
Oct 20 2022, 12:23 PM
werner committed rG77b008d1e74b: scd:nks: Handle APP_READKEY_FLAG_INFO. (authored by werner).
scd:nks: Handle APP_READKEY_FLAG_INFO.
Oct 20 2022, 12:23 PM
werner committed rG3c1acb7b9fa4: scd:nks: Support READKEY with keygrip and for "NKS-IDLM" keyref. (authored by gniibe).
scd:nks: Support READKEY with keygrip and for "NKS-IDLM" keyref.
Oct 20 2022, 12:23 PM
werner committed rG1f2823e0beee: scd:nks: Add support of KEYGRIP for do_readcert. (authored by gniibe).
scd:nks: Add support of KEYGRIP for do_readcert.
Oct 20 2022, 12:23 PM
werner committed rG0979ae349131: scd:nks: Factor out pubkey retrieval from keygrip handling. (authored by gniibe).
scd:nks: Factor out pubkey retrieval from keygrip handling.
Oct 20 2022, 12:23 PM
werner committed rGea7234d2f591: scd:nks: Factor out iteration over filelist. (authored by gniibe).
scd:nks: Factor out iteration over filelist.
Oct 20 2022, 12:23 PM
werner committed rGc9eb4c063231: scd:nks: Fix caching keygrip (more). (authored by gniibe).
scd:nks: Fix caching keygrip (more).
Oct 20 2022, 12:23 PM
werner committed rGcf5f6896f810: scd:nks: Minor additions to the basic IDLM application support. (authored by werner).
scd:nks: Minor additions to the basic IDLM application support.
Oct 20 2022, 12:23 PM
werner committed rGf1bd7369a754: scd,nks: Fix caching keygrip. (authored by gniibe).
scd,nks: Fix caching keygrip.
Oct 20 2022, 12:23 PM
werner committed rGc1c3331cf965: scd:nks: Emit the algo string with KEYPAIRINFO (authored by werner).
scd:nks: Emit the algo string with KEYPAIRINFO
Oct 20 2022, 12:23 PM
werner committed rGc99870f790c6: scd:nks: Fix certificate read problem with TCOS signature card v2. (authored by werner).
scd:nks: Fix certificate read problem with TCOS signature card v2.
Oct 20 2022, 12:23 PM
werner committed rGfe698586b5d4: scd:nks: Implement writecert for the Signature card v2. (authored by werner).
scd:nks: Implement writecert for the Signature card v2.
Oct 20 2022, 12:23 PM
werner committed rG60ba61e78ea3: scd:nks: Add framework to support IDKey cards. (authored by werner).
scd:nks: Add framework to support IDKey cards.
Oct 20 2022, 12:23 PM
werner committed rGa974d8aefab1: scd:nks: Fix remaining tries warning in --reset mode. (authored by werner).
scd:nks: Fix remaining tries warning in --reset mode.
Oct 20 2022, 12:23 PM
werner committed rGbbef2d17902b: scd:nks: Support decryption using ECDH. (authored by werner).
scd:nks: Support decryption using ECDH.
Oct 20 2022, 12:23 PM
werner committed rGa83281176c2b: scd:nks: Get the PIN prompts right for the Signature Card (authored by werner).
scd:nks: Get the PIN prompts right for the Signature Card
Oct 20 2022, 12:23 PM
werner committed rGf5e0469d6e74: scd:nks: Add do_with_keygrip and implement a cache. (authored by werner).
scd:nks: Add do_with_keygrip and implement a cache.
Oct 20 2022, 12:23 PM
werner committed rG471e610fcd63: scd:nks: Allow retrieving certificates from a Signature Card v.20 (authored by werner).
scd:nks: Allow retrieving certificates from a Signature Card v.20
Oct 20 2022, 12:23 PM
jrg.sichermann added a comment to T6251: Invalid ID in GpgOL while sending myself a signed and encrypted message.

PS
The problem is also active, if I send an encryptet (not signed) message to myself.
If I get mails from other people, wich are encryptet using smime and the same certtificate and signed by the sender, there is no problem. GpgOL works fine here.

Oct 20 2022, 11:49 AM · Info Needed, S/MIME, gpgol
Jakuje added a comment to T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF.

I read the document (SP 800-131Ar2) again. I think that it would be irrelevant for PKDF2, because it's password KDF, not deriving additional keys from a Cryptographic Key.

Oct 20 2022, 11:12 AM · backport, libgcrypt, FIPS
werner triaged T6252: Support ECC for Netkey cards also in 2.2 as High priority.
Oct 20 2022, 10:56 AM · gnupg (gpg22), scd, Restricted Project
jrg.sichermann created T6251: Invalid ID in GpgOL while sending myself a signed and encrypted message.
Oct 20 2022, 9:22 AM · Info Needed, S/MIME, gpgol
gniibe committed rA61f69c73f364: experiment: New SENDFD command to implement sendfd feature. (authored by gniibe).
experiment: New SENDFD command to implement sendfd feature.
Oct 20 2022, 8:58 AM
gniibe added a comment to T6249: gpgrt: spawn functions.
  • assuan_pipe_connect and internal _assuan_spawn
Oct 20 2022, 8:13 AM · gnupg, libassuan, gpgrt
alca7raz added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

Are you sure you are using SSH user certificates for SSH authentication? I have trouble with SSH certificate authentication instead of public-key authentication.

Oct 20 2022, 8:07 AM · gnupg, Documentation, ssh
werner added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

The latter. Detecting mail addresses with regexp is anyway a kludge and we have more stringent code to detect mail addresses in a user-id.

Oct 20 2022, 7:50 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

I am using this many years now without any problems. Also my collegues and many other folks I know. Thus the question is how your system differs from commonly used systems.

Oct 20 2022, 7:48 AM · gnupg, Documentation, ssh
gniibe committed rE5ad97e8fa628: gpgrt_spawn_process, gpgrt_spawn_process_fd: Change the API. (authored by gniibe).
gpgrt_spawn_process, gpgrt_spawn_process_fd: Change the API.
Oct 20 2022, 7:29 AM
gniibe committed rGde01fb8131fd: agent,common,dirmngr,tests,tools: Remove spawn PREEXEC argument. (authored by gniibe).
agent,common,dirmngr,tests,tools: Remove spawn PREEXEC argument.
Oct 20 2022, 7:23 AM
alca7raz added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

I have tried the stable version (2.3.8). Sadly, it doesn't work. 'agent refused operation' again. And I think it may have nothing to do with OpenSSH certificates because NIST256&384&512 keys do work in this situation.

Oct 20 2022, 6:36 AM · gnupg, Documentation, ssh
l10n daemon script <scripty@kde.org> committed rLIBKLEOa4e91a066db9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 20 2022, 5:11 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA7aa79bb2fb61: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 20 2022, 5:09 AM
dkg added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

@werner i'm not sure i understand what "easy to enclose them in angle brackets just for comparison" means.

Oct 20 2022, 2:48 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
gniibe added a comment to T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF.

I read the document (SP 800-131Ar2) again. I think that it would be irrelevant for PKDF2, because it's password KDF, not deriving additional keys from a Cryptographic Key.

Oct 20 2022, 2:15 AM · backport, libgcrypt, FIPS

Oct 19 2022

ikloecker added inline comments to rD34eed1bd03f3: web: Fix last commit.
Oct 19 2022, 9:00 PM
werner added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

We do not support OpenSSH certificates but ignore such requests. However, the keys from the certificates will be imported correctly. You should use the stable version of GnuPG (2.3.8) and not the LTS version 2.,2.

Oct 19 2022, 7:36 PM · gnupg, Documentation, ssh
neverpanic added a comment to rC857e6f467d0f: kdf:pkdf2: Require longer input when FIPS mode..

This causes ACVP tests to fail, so apparently the assumption that passphrases must be at least 14 bytes was incorrect. ACVP testing tests values larger than 8 bytes. I'll try to clarify whether that's a limit we need to enforce, or just what NIST wants to test. In any case, we will probably have to revert this.

Oct 19 2022, 7:00 PM
werner committed rD34eed1bd03f3: web: Fix last commit (authored by werner).
web: Fix last commit
Oct 19 2022, 4:10 PM
alca7raz created T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.
Oct 19 2022, 3:56 PM · gnupg, Documentation, ssh