Page MenuHome GnuPG
Feed Advanced Search

Nov 3 2022

werner added a comment to rG4583f4fe2e11: gpg: Merge --rfc4880bis features into --gnupg.

Hi Vincent,

Nov 3 2022, 11:54 AM
werner committed rWcf792dca94fc: appimage: Re-add --steal-socket. (authored by werner).
appimage: Re-add --steal-socket.
Nov 3 2022, 9:33 AM

Nov 2 2022

werner committed rG82c4f26b67e9: gpg: Make --list-packets work w/o --no-armor for plain OCB packets. (authored by werner).
gpg: Make --list-packets work w/o --no-armor for plain OCB packets.
Nov 2 2022, 5:16 PM
werner committed rG9b24d8ab5018: tests: Add tr:assert-same function. (authored by werner).
tests: Add tr:assert-same function.
Nov 2 2022, 5:16 PM
werner committed rGe284f62b1c6d: tests: Add symmetric decryption tests. (authored by werner).
tests: Add symmetric decryption tests.
Nov 2 2022, 5:16 PM
werner renamed SEO_mobster from jamesjoyce to SEO_mobster.
Nov 2 2022, 5:14 PM
werner committed rGbd612f23607d: agent: Avoid blanks in the ssh key's comment. (authored by werner).
agent: Avoid blanks in the ssh key's comment.
Nov 2 2022, 10:42 AM
werner committed rO9f1f29c22706: Protect against theoretical integer overflow in TLV parser. (authored by werner).
Protect against theoretical integer overflow in TLV parser.
Nov 2 2022, 9:01 AM

Oct 31 2022

werner committed rG0a355b2fe7d8: gpg: Add compatibility flag "vsd-allow-ocb" (authored by werner).
gpg: Add compatibility flag "vsd-allow-ocb"
Oct 31 2022, 5:24 PM
werner changed the status of T6263: Allow OCB encryption in 2.2 from Open to Testing.
Oct 31 2022, 4:26 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request
werner committed rG4a9f3f94c6d1: gpg: New option --compatibility-flags (authored by werner).
gpg: New option --compatibility-flags
Oct 31 2022, 4:25 PM
werner committed rG4583f4fe2e11: gpg: Merge --rfc4880bis features into --gnupg (authored by werner).
gpg: Merge --rfc4880bis features into --gnupg
Oct 31 2022, 4:16 PM
werner committed rG5a2cef801d35: gpg: Allow only OCB for AEAD encryption. (authored by werner).
gpg: Allow only OCB for AEAD encryption.
Oct 31 2022, 4:16 PM
werner committed rG03f04dfb9a03: gpg: New option --compatibility-flags (authored by werner).
gpg: New option --compatibility-flags
Oct 31 2022, 4:16 PM
werner committed rGa545e14e8a74: gpg: Support OCB encryption. (authored by werner).
gpg: Support OCB encryption.
Oct 31 2022, 2:39 PM
werner triaged T6263: Allow OCB encryption in 2.2 as Normal priority.
Oct 31 2022, 2:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request

Oct 28 2022

werner added a project to T5704: Ed448/X448 defined in draft-ietf-openpgp-crypto-refresh-04: OpenPGP.

Meanwhile I have _some_ doubts that the v5 format is a good idea. It will introduce a lot of problems and thus a more lean way of replacing the fingerprint should be re-considered. Even if that means, we have to live with two kinds of fingerprints for a decade or so.

Oct 28 2022, 4:11 PM · gnupg24, OpenPGP, gnupg (gpg23)
werner closed T4059: Errors while building from source on Cygwin (gnupg repo) as Wontfix.

We won't do that. FWIW: We started to work on a 64 bit WIndows version of GnuPG.

Oct 28 2022, 4:07 PM · Cygwin, gnupg, Bug Report
werner closed T5947: Release GnuPG 2.3.7 as Resolved.
Oct 28 2022, 4:05 PM · CVE, Release Info, gnupg (gpg23)
werner added a comment to T5590: OpenPGP: Curve 448, modernize?.

Given that the OpenPGP WG practically decided to fork OpenPGP I don't see a reason why we should keep this bug open.

Oct 28 2022, 4:03 PM · rationale, gnupg, OpenPGP
werner closed T6029: ntbtls: Require TLS 1.2 or later + AEAD by default as Resolved.

I can't see what we shall do here.

Oct 28 2022, 3:59 PM · Not A Bug, ntbtls
werner updated subscribers of T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.
Oct 28 2022, 3:56 PM · Not A Bug, workaround, gnupg24, Windows, ssh
werner added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

Will go into 2.3.9 and gpg4win 4.0.5

Oct 28 2022, 3:56 PM · Not A Bug, workaround, gnupg24, Windows, ssh
werner closed T1621: Support multiple cards (not just readers) as Resolved.

You are using a somewhat special setup and not what has been tested with gpg (i.e. putty). In particular Cygwin based tools do not interoperate well with non-Cygwin tools.

Oct 28 2022, 3:55 PM · gnupg, Feature Request
werner changed the status of T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address from Open to Testing.
Oct 28 2022, 3:44 PM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner added a comment to T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452).

@jukivili: This has been released with 1.10.0 - shall we close this bug?

Oct 28 2022, 3:42 PM · Feature Request, libgcrypt
werner lowered the priority of T4921: Support import of PKCS#12 encoded ECC private keys. from High to Normal.

Shall we really backport this to 2.2 given that ECC for S/MIME is in most cases a smartcard thing?

Oct 28 2022, 3:38 PM · gnupg22 (gnupg-2.2.42), backport, Feature Request, S/MIME
werner closed T4098: GpgSM: Add ECC support as Resolved.

Has been release quite some time ago (2.3.8 and earlier)

Oct 28 2022, 3:36 PM · gnupg (gpg23), Feature Request, S/MIME
werner added a comment to T4938: Support Signature Card V2.0 (NKS15).

Will be released with 2.3.9

Oct 28 2022, 3:34 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T4938: Support Signature Card V2.0 (NKS15), a subtask of T4098: GpgSM: Add ECC support, as Resolved.
Oct 28 2022, 3:33 PM · gnupg (gpg23), Feature Request, S/MIME
werner closed T4938: Support Signature Card V2.0 (NKS15) as Resolved.
Oct 28 2022, 3:33 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T6252: Support ECC for Netkey cards also in 2.2 as Resolved.
Oct 28 2022, 3:32 PM · gnupg (gpg22), scd, Restricted Project
werner closed T6252: Support ECC for Netkey cards also in 2.2, a subtask of T4938: Support Signature Card V2.0 (NKS15), as Resolved.
Oct 28 2022, 3:32 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T6252: Support ECC for Netkey cards also in 2.2, a subtask of T6253: GpgSM: Backport ECC support to 2.2, as Resolved.
Oct 28 2022, 3:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner changed the status of T6253: GpgSM: Backport ECC support to 2.2, a subtask of T4098: GpgSM: Add ECC support, from Open to Testing.
Oct 28 2022, 3:32 PM · gnupg (gpg23), Feature Request, S/MIME
werner changed the status of T6253: GpgSM: Backport ECC support to 2.2 from Open to Testing.
Oct 28 2022, 3:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner committed rGb71a14238dd2: gpgsm: Also announce AES256-CBC in signatures. (authored by werner).
gpgsm: Also announce AES256-CBC in signatures.
Oct 28 2022, 3:24 PM
werner committed rG28467f3735f7: sm: Support encryption using ECDH keys. (authored by werner).
sm: Support encryption using ECDH keys.
Oct 28 2022, 3:22 PM
werner committed rGfd0ddf26990d: gpgsm: New compatibility flag "allow-ecc-encr". (authored by werner).
gpgsm: New compatibility flag "allow-ecc-encr".
Oct 28 2022, 3:22 PM
werner committed rGaa397fdcdb21: gpgsm: Also announce AES256-CBC in signatures. (authored by werner).
gpgsm: Also announce AES256-CBC in signatures.
Oct 28 2022, 3:22 PM
werner committed rGd770715e1574: gpgsm: Allow ECC encryption keys with just keyAgreement specified. (authored by werner).
gpgsm: Allow ECC encryption keys with just keyAgreement specified.
Oct 28 2022, 12:18 PM
werner committed rG1cdb67d41a41: gpgsm: Use macro constants for cert_usage_p. (authored by werner).
gpgsm: Use macro constants for cert_usage_p.
Oct 28 2022, 12:18 PM
werner committed rG934bbe67c2c0: scd: Use APP_LEARN_FLAG_KEYPAIRINFO with more apps. (authored by werner).
scd: Use APP_LEARN_FLAG_KEYPAIRINFO with more apps.
Oct 28 2022, 12:18 PM
werner committed rG7ed523ca1332: scd:nks: Support non-ESIGN signing with the Signature Card v2 (authored by werner).
scd:nks: Support non-ESIGN signing with the Signature Card v2
Oct 28 2022, 12:18 PM
werner committed rG12d3b16729b7: scd: Use app_get_slot at more places. (authored by werner).
scd: Use app_get_slot at more places.
Oct 28 2022, 12:18 PM
werner committed rG6fa4143284ef: doc: Make uploading of 2.2 manuals easier (authored by werner).
doc: Make uploading of 2.2 manuals easier
Oct 28 2022, 12:18 PM
werner added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

Fixed for master but not yet tested.

Oct 28 2022, 11:21 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner committed rG0ef54e644f19: gpg: Fix trusted introducer for user-ids with only the mbox. (authored by werner).
gpg: Fix trusted introducer for user-ids with only the mbox.
Oct 28 2022, 11:21 AM
werner added a comment to T5542: w32: Values under HKLM ignored if HKCU entry for GnuPG exists.

Is this still an issue or is the new gpgconf -X feature sufficient to detect this case?

Oct 28 2022, 10:00 AM · Windows, gnupg, Restricted Project
werner added a comment to T5778: Wish to add a generic comment or hint to encrypted data.

An outer signature or even a new packet to sign the list of encrypted session keys might also be an option which does not disturb older implementations.

Oct 28 2022, 9:54 AM · gnupg, Restricted Project
werner added a comment to T6081: MSI: Check for GnuPT on installation.

Is that still required wit the new gpgme global flag "inst-type"?

Oct 28 2022, 9:50 AM · Restricted Project, gpg4win
werner moved T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner moved T6252: Support ECC for Netkey cards also in 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg (gpg22), scd, Restricted Project
werner moved T6253: GpgSM: Backport ECC support to 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner moved T1235: adding automatic refresh-key from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg26, gnupg22, Feature Request
werner raised the priority of T1235: adding automatic refresh-key from Normal to High.
Oct 28 2022, 9:48 AM · gnupg26, gnupg22, Feature Request
werner committed rG7aaedfb10767: gpg: Import stray revocation certificates. (authored by werner).
gpg: Import stray revocation certificates.
Oct 28 2022, 9:31 AM
werner lowered the priority of T4612: Add spare space to the keybox to always allow the import of revocations. from Normal to Low.
Oct 28 2022, 9:19 AM · gnupg24, gnupg (gpg23), Bug Report

Oct 27 2022

werner awarded T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance) a Cup of Joe token.
Oct 27 2022, 8:46 AM · libgcrypt, Feature Request
werner added a comment to T6249: gpgrt: spawn functions.

I general I agree.

Oct 27 2022, 8:44 AM · gnupg, libassuan, gpgrt
werner triaged T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent as Normal priority.
Oct 27 2022, 8:27 AM · gnupg, Documentation, ssh
werner triaged T6255: --list-keys output truncated and loops repeatedly as Low priority.

There is a utility named kbxutil which can be sued to dump the pubring.kbx file without any post-processing by gpg. I would check whether there are any other keys after the VideoLAN key. iirc, kbxutil ist not commonly installed; you may need to build the software yourself or copy the pubring.kbx to Linux and check it here.

Oct 27 2022, 8:26 AM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report

Oct 26 2022

werner committed rM1c9694f8d50b: core: New global flags "inst-type". (authored by werner).
core: New global flags "inst-type".
Oct 26 2022, 12:12 PM

Oct 25 2022

werner committed rO6a92c8b0f356: Post release updates (authored by werner).
Post release updates
Oct 25 2022, 2:59 PM
werner committed rO9f54866ab768: Release 2.5.5 (authored by werner).
Release 2.5.5
Oct 25 2022, 2:59 PM
werner committed rG9c4691c73e9e: card: New commands "gpg" and "gpgsm". (authored by werner).
card: New commands "gpg" and "gpgsm".
Oct 25 2022, 2:13 PM
werner committed rG8361e13ef212: scd:nks: Support non-ESIGN signing with the Signature Card v2 (authored by werner).
scd:nks: Support non-ESIGN signing with the Signature Card v2
Oct 25 2022, 12:03 PM
werner committed rG50efcf2eb0d1: gpgsm: Use macro constants for cert_usage_p. (authored by werner).
gpgsm: Use macro constants for cert_usage_p.
Oct 25 2022, 12:03 PM
werner committed rGf3198f9d705a: card: Also show fingerprints of known X.509 certificates (authored by werner).
card: Also show fingerprints of known X.509 certificates
Oct 25 2022, 12:03 PM
werner committed rG6bd0dd762c0d: gpgsm: Allow ECC encryption keys with just keyAgreement specified. (authored by werner).
gpgsm: Allow ECC encryption keys with just keyAgreement specified.
Oct 25 2022, 12:03 PM
werner added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

@gniibe: Thanks for looking into it.

Oct 25 2022, 10:23 AM · gnupg, Documentation, ssh

Oct 24 2022

werner placed T6258: IMAP-Fix not integrated in 3.1.25-Codebase and GnuPG VS Desktop 3.1.25 up for grabs.
Oct 24 2022, 8:08 PM · Restricted Project
werner closed T6258: IMAP-Fix not integrated in 3.1.25-Codebase and GnuPG VS Desktop 3.1.25 as Resolved.

This will go into the next release.

Oct 24 2022, 8:08 PM · Restricted Project
werner committed rM830e017e5d5f: core: Protect against a theoretical integer overflow in parsetlv.c (authored by werner).
core: Protect against a theoretical integer overflow in parsetlv.c
Oct 24 2022, 1:53 PM
werner closed T6203: GpgOL (Gpg4Win 3.1.24) / Error in parsing mail-headers (empty mail-body without correct decoded encryption-scheme) when using gpgol.dll 2.5.4 (gpgol.dll 2.5.0 from 3.1.16 works) as Resolved.

Please note that gpg4win 3.1 is not anymore maintained. Gpg4win 4.0.4 is the currrent release and comes with the IMAP fix. We do not have a single GnuPG VS-Desktop customer using IMAP and thus having the fix only in the next VSD version seems to be okay.

Oct 24 2022, 1:22 PM · Restricted Project, gpgol
werner triaged T6235: Problem editing Expiration Time as Normal priority.
Oct 24 2022, 7:19 AM · gnupg24, Feature Request
werner triaged T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance) as Low priority.

Go ahead if you want to do that.

Oct 24 2022, 7:19 AM · libgcrypt, Feature Request
werner added a comment to T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent.

Surely not. We just take the key from those certificates. Note that ssh-add merely imports a key permanently into gpg-agent's key store.

Oct 24 2022, 7:18 AM · gnupg, Documentation, ssh
werner closed T6256: Version > 4.0.0 DLL not found as Resolved.
Oct 24 2022, 7:16 AM · gpg4win, Support

Oct 21 2022

werner edited projects for T6256: Version > 4.0.0 DLL not found, added: Support, gpg4win; removed Bug Report.

An old version is still installed and the libgpg-error-0.dll could not be replaced. Make sure that you deinstalled old gpg4win versions and other gnupg versions. The file version of the DLL shall be 1.46.x.x.

Oct 21 2022, 11:46 AM · gpg4win, Support
werner added a comment to T6255: --list-keys output truncated and loops repeatedly.

Are you using the keyboxd ? ("use-keyboxd" in common.conf) or is this using the default pubring.kbx.

Oct 21 2022, 6:25 AM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report

Oct 20 2022

werner triaged T6254: Warn in --recv-keys verbose output that no keys have been imported as Normal priority.
Oct 20 2022, 10:14 PM · gnupg24, Keyserver, Bug Report
werner added projects to T6254: Warn in --recv-keys verbose output that no keys have been imported: gnupg (gpg23), Keyserver.

Oh yes, the usual import statistics should be shown here.

Oct 20 2022, 10:14 PM · gnupg24, Keyserver, Bug Report
werner edited projects for T6235: Problem editing Expiration Time, added: Feature Request, gnupg (gpg23); removed Bug Report.
Oct 20 2022, 10:10 PM · gnupg24, Feature Request
werner committed rGed62b74a175e: gpgsm: Create ECC certificates with AKI and SKI by default. (authored by werner).
gpgsm: Create ECC certificates with AKI and SKI by default.
Oct 20 2022, 5:34 PM
werner committed rG9f1181e1a7ed: gpgsm: Print the key types as standard key algorithm strings. (authored by werner).
gpgsm: Print the key types as standard key algorithm strings.
Oct 20 2022, 5:34 PM
werner committed rG5ae2632002c0: gpgsm: Support decryption of ECDH data (authored by werner).
gpgsm: Support decryption of ECDH data
Oct 20 2022, 5:34 PM
werner committed rG8b2c55d3c5da: gpgsm: Remove restriction of key generation (only RSA). (authored by gniibe).
gpgsm: Remove restriction of key generation (only RSA).
Oct 20 2022, 5:34 PM
werner committed rG37a853d808f0: gpgsm: Support key generation with ECC. (authored by gniibe).
gpgsm: Support key generation with ECC.
Oct 20 2022, 5:34 PM
werner added a parent task for T6252: Support ECC for Netkey cards also in 2.2: T6253: GpgSM: Backport ECC support to 2.2.
Oct 20 2022, 2:33 PM · gnupg (gpg22), scd, Restricted Project
werner added a subtask for T6253: GpgSM: Backport ECC support to 2.2: T6252: Support ECC for Netkey cards also in 2.2.
Oct 20 2022, 2:33 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner triaged T6253: GpgSM: Backport ECC support to 2.2 as High priority.
Oct 20 2022, 2:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner changed the status of T6252: Support ECC for Netkey cards also in 2.2, a subtask of T4938: Support Signature Card V2.0 (NKS15), from Open to Testing.
Oct 20 2022, 2:12 PM · eIDAS, scd, Feature Request, S/MIME
werner changed the status of T6252: Support ECC for Netkey cards also in 2.2 from Open to Testing.
Oct 20 2022, 2:12 PM · gnupg (gpg22), scd, Restricted Project
werner added a parent task for T6252: Support ECC for Netkey cards also in 2.2: T4938: Support Signature Card V2.0 (NKS15).
Oct 20 2022, 2:11 PM · gnupg (gpg22), scd, Restricted Project
werner added a subtask for T4938: Support Signature Card V2.0 (NKS15): T6252: Support ECC for Netkey cards also in 2.2.
Oct 20 2022, 2:11 PM · eIDAS, scd, Feature Request, S/MIME
werner added a comment to T6249: gpgrt: spawn functions.

without this list we don't have an option to keep file descriptors open; its not just stderr but for example log files and descriptors which pare passed by other meands than libassuan functions.

Oct 20 2022, 1:52 PM · gnupg, libassuan, gpgrt
werner committed rG1e69676981ac: scd:nks: Don't flag the ESIGN keypair EF as encryption capable. (authored by werner).
scd:nks: Don't flag the ESIGN keypair EF as encryption capable.
Oct 20 2022, 12:23 PM
werner committed rGf24904ee3540: scd:nks: Some code cleanup. (authored by werner).
scd:nks: Some code cleanup.
Oct 20 2022, 12:23 PM
werner committed rG5cd25f4ca485: scd:nks: Support the Telesec ESIGN application. (authored by werner).
scd:nks: Support the Telesec ESIGN application.
Oct 20 2022, 12:23 PM