Page MenuHome GnuPG
Feed All Stories

Jun 16 2023

werner committed rA413b294f0081: Next release will be 3.0 (authored by werner).
Next release will be 3.0
Jun 16 2023, 10:02 AM
werner committed rA049b8001f163: Flush data before clearing the confidential flag. (authored by werner).
Flush data before clearing the confidential flag.
Jun 16 2023, 10:02 AM
gniibe claimed T6539: The digest&sign/verify API with SHAKE-class digests does not work.
Jun 16 2023, 9:36 AM · libgcrypt, FIPS, Bug Report
gniibe added a comment to T6539: The digest&sign/verify API with SHAKE-class digests does not work.

I found this use case: RFC 8702
"Use of the SHAKE One-Way Hash Functions in the Cryptographic Message Syntax (CMS)": https://www.rfc-editor.org/rfc/rfc8702.html

Jun 16 2023, 9:35 AM · libgcrypt, FIPS, Bug Report
gniibe added a comment to T6539: The digest&sign/verify API with SHAKE-class digests does not work.

Another possibility for digest&sign API: it is possible to determine the length of required hash function by the underlining field Fp of the curve in use. Then, use this length instead. It's better than to (try to) get the length by _gcry_md_get_algo_dlen (for SHAKE, it's undefined).

Jun 16 2023, 9:16 AM · libgcrypt, FIPS, Bug Report
gniibe changed the status of T6507: SCRYPT does not work in FIPS mode from Open to Testing.

Fixed in both of master and 1.10 branch.

Jun 16 2023, 8:11 AM · libgcrypt, FIPS, Bug Report
gniibe committed rC70b1b036f3ee: tests: Allow KDF measurement in FIPS mode. (authored by gniibe).
tests: Allow KDF measurement in FIPS mode.
Jun 16 2023, 8:04 AM
gniibe committed rCf4bff832c7f5: cipher:kdf: Move FIPS mode check to _gcry_kdf_derive. (authored by gniibe).
cipher:kdf: Move FIPS mode check to _gcry_kdf_derive.
Jun 16 2023, 8:04 AM
gniibe changed the status of T6515: GPG in FIPS mode spits out useless "out of core handler ignored in FIPS mode" message on every execution from Open to Testing.
Jun 16 2023, 7:28 AM · FIPS, Bug Report
gniibe claimed T6515: GPG in FIPS mode spits out useless "out of core handler ignored in FIPS mode" message on every execution.

For libgcrypt, initially when the code was put, it made some sense.
Now, it's useless, so, let's simply remove the message.

Jun 16 2023, 7:28 AM · FIPS, Bug Report
gniibe committed rC6c79dcddd151: Remove out of core handler setting message in FIPS mode. (authored by gniibe).
Remove out of core handler setting message in FIPS mode.
Jun 16 2023, 7:26 AM
gniibe changed the status of T6511: EdDSA support in FIPS mode from Open to Testing.

Added: rC547dfb5aecc1: cipher:ecc: Add selftests for EdDSA.
Added: rC3ac2bba4a4b1: cipher:ecc: Implement PCT for EdDSA.

Jun 16 2023, 7:12 AM · FIPS, libgcrypt, Bug Report
gniibe committed rC3ac2bba4a4b1: cipher:ecc: Implement PCT for EdDSA. (authored by gniibe).
cipher:ecc: Implement PCT for EdDSA.
Jun 16 2023, 7:12 AM
gniibe committed rC97f4a94d5960: build: Detect broken GCC for x86/AVX512 intrinsics. (authored by gniibe).
build: Detect broken GCC for x86/AVX512 intrinsics.
Jun 16 2023, 6:13 AM
gniibe committed rC547dfb5aecc1: cipher:ecc: Add selftests for EdDSA. (authored by gniibe).
cipher:ecc: Add selftests for EdDSA.
Jun 16 2023, 5:05 AM
gniibe committed rC73d2f5d93541: tests: EdDSA keys work in FIPS mode (authored by Jakuje).
tests: EdDSA keys work in FIPS mode
Jun 16 2023, 4:49 AM
gniibe committed rCc08ea202d916: ecc: Enable Ed25519 and Ed448 in FIPS mode (authored by Jakuje).
ecc: Enable Ed25519 and Ed448 in FIPS mode
Jun 16 2023, 4:49 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA349e93a64322: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Jun 16 2023, 3:53 AM

Jun 15 2023

Jakuje created T6539: The digest&sign/verify API with SHAKE-class digests does not work.
Jun 15 2023, 5:34 PM · libgcrypt, FIPS, Bug Report
werner triaged T6538: Move mailing lists to al-kindi as Normal priority.
Jun 15 2023, 5:00 PM · dev.gnupg.org
werner moved T6477: WKD redirects and dirmngr redirect rewriting from WiP to QA on the gnupg24 board.
Jun 15 2023, 3:12 PM · gnupg24 (gnupg-2.4.3), wkd, dirmngr
werner added a comment to T6477: WKD redirects and dirmngr redirect rewriting.

I have now disabled the rewriting in the 2.4 branch. Those who want to keep the old behaviour may add

Jun 15 2023, 3:09 PM · gnupg24 (gnupg-2.4.3), wkd, dirmngr
werner committed rG0a63afc79a04: dirmngr: Disable the HTTP redirect rewriting. (authored by werner).
dirmngr: Disable the HTTP redirect rewriting.
Jun 15 2023, 3:06 PM
werner committed rGbf04b07327a5: dirmngr: New option --compatibility-flags. (authored by werner).
dirmngr: New option --compatibility-flags.
Jun 15 2023, 3:06 PM
werner set the icon for dirmngr to Tag.
Jun 15 2023, 2:08 PM
werner edited Description on dirmngr.
Jun 15 2023, 2:07 PM
werner moved T6477: WKD redirects and dirmngr redirect rewriting from Backlog to WiP on the gnupg24 board.
Jun 15 2023, 2:03 PM · gnupg24 (gnupg-2.4.3), wkd, dirmngr
werner claimed T6477: WKD redirects and dirmngr redirect rewriting.
Jun 15 2023, 2:03 PM · gnupg24 (gnupg-2.4.3), wkd, dirmngr
werner lowered the priority of T6524: Kleopatra / Gpgtar: Cancel does not kill the job from Unbreak Now! to High.
Jun 15 2023, 2:02 PM · Restricted Project, kleopatra
werner committed rGe9c337c0b94b: gpgsm: New option --input-size-hint. (authored by werner).
gpgsm: New option --input-size-hint.
Jun 15 2023, 2:00 PM
werner committed rG2178f35dffdc: gpg: New option --no-compress as alias for -z0. (authored by werner).
gpg: New option --no-compress as alias for -z0.
Jun 15 2023, 2:00 PM
werner committed rG3bab25d7d519: gpgtar: New option --no-compress. (authored by werner).
gpgtar: New option --no-compress.
Jun 15 2023, 2:00 PM
mlaurent committed rKLEOPATRA05d5f20d7629: Merge remote-tracking branch 'origin' into kf6 (authored by mlaurent).
Merge remote-tracking branch 'origin' into kf6
Jun 15 2023, 1:53 PM
ikloecker committed rKLEOPATRA04adbffa2aee: Add missing getter for output file name (authored by ikloecker).
Add missing getter for output file name
Jun 15 2023, 1:43 PM
ebo closed T6154: Kleopatra: Assert in CertifyCertificateCommand after setting ownertrust of key as Resolved.

could not trigger it with the described steps on windows

Jun 15 2023, 1:38 PM · Restricted Project, kleopatra
ikloecker committed rKLEOPATRAa15434ddc59b: Check for existing files before starting any encryption tasks (authored by ikloecker).
Check for existing files before starting any encryption tasks
Jun 15 2023, 1:33 PM
ikloecker committed rKLEOPATRA31f84464df70: Only ask the user for overwrite permission if file exists (authored by ikloecker).
Only ask the user for overwrite permission if file exists
Jun 15 2023, 1:33 PM
ikloecker committed rKLEOPATRA2a304b8f5a08: Use custom label text only for progress label (authored by ikloecker).
Use custom label text only for progress label
Jun 15 2023, 1:33 PM
ikloecker committed rKLEOPATRAd4a5f9c2512e: Let OverwritePolicy take care of asking users whether to overwrite a file (authored by ikloecker).
Let OverwritePolicy take care of asking users whether to overwrite a file
Jun 15 2023, 1:33 PM
ikloecker committed rKLEOPATRA9c9027f85254: Fix removing of temporary files with UNC paths (authored by ikloecker).
Fix removing of temporary files with UNC paths
Jun 15 2023, 1:33 PM
werner committed rM91bbb1e482da: core: Send a input-size-hint for gpgsm. (authored by werner).
core: Send a input-size-hint for gpgsm.
Jun 15 2023, 1:00 PM
ebo closed T6488: Kleopatra: moving decrypted Folder to USB device fails as Resolved.

works for 4,1 GB, too.
(Tested with Gpg4win-4.2.0-beta346)

Jun 15 2023, 12:55 PM · kleopatra, Restricted Project
ebo moved T6373: Kleopatra: Show progress dialog when moving decrypted archive to final destination from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jun 15 2023, 12:25 PM · Restricted Project, kleopatra
ebo closed T6473: Kleopatra: "Change Validity" does ignore the option "Also update the validity period of the subkeys" as Resolved.
Jun 15 2023, 12:23 PM · kleopatra, Restricted Project
werner committed rGa88aeee12990: gpgsm: Fix last commit (authored by werner).
gpgsm: Fix last commit
Jun 15 2023, 12:20 PM
ikloecker changed the status of T6373: Kleopatra: Show progress dialog when moving decrypted archive to final destination from Testing to Open.

Move back to the backlog and trigger re-evalutation of priority (which was high).

Jun 15 2023, 12:08 PM · Restricted Project, kleopatra
ikloecker changed the status of T6373: Kleopatra: Show progress dialog when moving decrypted archive to final destination, a subtask of T5478: Kleopatra: Performance problems decrypting and encrypting large Archives, from Testing to Open.
Jun 15 2023, 12:08 PM · Restricted Project, gpgme, kleopatra
ikloecker created T6537: Make KIO::move work on Windows when moving between different partitions.
Jun 15 2023, 12:05 PM · Restricted Project, kleopatra
werner moved T6534: gpg's progress_filter needs to use uint64_t from WiP to QA on the gnupg24 board.
Jun 15 2023, 11:21 AM · gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.3), Feature Request, Restricted Project, Windows
werner committed rG6944aefa3c2e: kbx,w32: Disable the fd-passing. (authored by werner).
kbx,w32: Disable the fd-passing.
Jun 15 2023, 11:17 AM
werner committed rGcd7f286486f2: gpgtar: Emit FAILURE status line. (authored by werner).
gpgtar: Emit FAILURE status line.
Jun 15 2023, 11:17 AM
werner committed rG5f46bcaaa082: sm: Emit STATUS_FAILURE for non-implemented commands. (authored by werner).
sm: Emit STATUS_FAILURE for non-implemented commands.
Jun 15 2023, 11:17 AM
werner committed rG48b56485548e: common,w32: Set a proper error code when creating an output file. (authored by werner).
common,w32: Set a proper error code when creating an output file.
Jun 15 2023, 11:17 AM
werner committed rG6657230f9ee4: w32: Add missing supportedOS Ids for Windows-10 (authored by werner).
w32: Add missing supportedOS Ids for Windows-10
Jun 15 2023, 11:17 AM
werner committed rG3fbe10172f0a: w32: Add missing manifests and set a requestedExecutionLevel. (authored by werner).
w32: Add missing manifests and set a requestedExecutionLevel.
Jun 15 2023, 11:17 AM
werner committed rG80097bc78bf7: gpg: Return ERROR status for --quick-sign-key. (authored by werner).
gpg: Return ERROR status for --quick-sign-key.
Jun 15 2023, 11:17 AM
gniibe committed rG0f8e5f1c1db0: po: Update Japanese Translation. (authored by gniibe).
po: Update Japanese Translation.
Jun 15 2023, 11:17 AM
gniibe committed rG6a2cb8cfd714: agent,w32: Fix resource leak for a process. (authored by gniibe).
agent,w32: Fix resource leak for a process.
Jun 15 2023, 11:17 AM
werner committed rG9f2f7a51b243: gpg: Skip keys found via ADSKs. (authored by werner).
gpg: Skip keys found via ADSKs.
Jun 15 2023, 11:17 AM
werner committed rGa048a93ed2c3: common: New function nve_set (authored by werner).
common: New function nve_set
Jun 15 2023, 11:17 AM
werner committed rG14828c75be10: gpg: Fix searching for the ADSK key when adding an ADSK. (authored by werner).
gpg: Fix searching for the ADSK key when adding an ADSK.
Jun 15 2023, 11:17 AM
werner committed rG13013ec1c0d3: agent: Create and use Token entries to track the display s/n. (authored by werner).
agent: Create and use Token entries to track the display s/n.
Jun 15 2023, 11:17 AM
werner committed rG05f29b5c7caa: agent: Update key files by first writing to a temp file. (authored by werner).
agent: Update key files by first writing to a temp file.
Jun 15 2023, 11:17 AM
werner committed rGa1015bf2fc07: agent: Do not overwrite a key file by a shadow key file. (authored by werner).
agent: Do not overwrite a key file by a shadow key file.
Jun 15 2023, 11:17 AM
werner committed rGf953d67446fa: Prepare the NEWS for the next release (authored by werner).
Prepare the NEWS for the next release
Jun 15 2023, 11:17 AM
werner committed rG4cfa2efdc6f8: po: Translated one new string to German. (authored by werner).
po: Translated one new string to German.
Jun 15 2023, 11:17 AM
werner committed rG550bc15b006d: po: msgmerge done (authored by werner).
po: msgmerge done
Jun 15 2023, 11:17 AM
werner committed rG3c97dc2714b6: Post release updates (authored by werner).
Post release updates
Jun 15 2023, 11:17 AM
werner committed rG9e86dac84f37: Release 2.4.2 (authored by werner).
Release 2.4.2
Jun 15 2023, 11:17 AM
werner committed rG2c1d5d5cd35c: po: Update Czech translation (authored by petr_p).
po: Update Czech translation
Jun 15 2023, 11:17 AM
werner committed rGc8f6fdcd359a: build: Always build the wixlib with a release (authored by werner).
build: Always build the wixlib with a release
Jun 15 2023, 11:17 AM
werner committed rG89da4a32ab77: doc: Replace remaining "gpg2" by "gpg". (authored by werner).
doc: Replace remaining "gpg2" by "gpg".
Jun 15 2023, 11:17 AM
werner committed rGbaa88832153d: gpg: Set default expiration date to 3 years. (authored by werner).
gpg: Set default expiration date to 3 years.
Jun 15 2023, 11:17 AM
werner committed rGc68dd2287237: gpg: Add --list-filter properties key_expires and key_expires_d. (authored by werner).
gpg: Add --list-filter properties key_expires and key_expires_d.
Jun 15 2023, 11:17 AM
werner committed rG7b7fdf45e5d8: common: New function substitute_vars. (authored by werner).
common: New function substitute_vars.
Jun 15 2023, 11:17 AM
werner committed rG207c99567ced: dirmngr: Extend the AD_QUERY command. (authored by werner).
dirmngr: Extend the AD_QUERY command.
Jun 15 2023, 11:17 AM
werner committed rG695cb04af521: gpg: Print status line and proper diagnostics for write errors. (authored by werner).
gpg: Print status line and proper diagnostics for write errors.
Jun 15 2023, 11:17 AM
werner committed rGca3f0e66bcf6: w32: Map ERROR_FILE_INVALID to EIO. (authored by werner).
w32: Map ERROR_FILE_INVALID to EIO.
Jun 15 2023, 11:17 AM
werner committed rG64509134d47a: speedo,w32: Call gpgconf --kill all (authored by aheinecke).
speedo,w32: Call gpgconf --kill all
Jun 15 2023, 11:17 AM
werner committed rG808494b48577: gpg: Make progress work for large files on Windows. (authored by werner).
gpg: Make progress work for large files on Windows.
Jun 15 2023, 11:17 AM
werner committed rGc58067415fe9: gpgsm: Print PROGRESS status lines. (authored by werner).
gpgsm: Print PROGRESS status lines.
Jun 15 2023, 11:17 AM
werner committed rM8796456d235d: tests: Add option --cancel to run-encrypt. (authored by werner).
tests: Add option --cancel to run-encrypt.
Jun 15 2023, 11:03 AM
werner committed rMeb68948c4388: core: Use 64 bit instead of gpgme_off_t for some internal functions. (authored by werner).
core: Use 64 bit instead of gpgme_off_t for some internal functions.
Jun 15 2023, 11:03 AM
werner added a project to T6534: gpg's progress_filter needs to use uint64_t: gpgme.

And of course we also need to adjust GPGME

Jun 15 2023, 10:58 AM · gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.3), Feature Request, Restricted Project, Windows
werner added a comment to T6534: gpg's progress_filter needs to use uint64_t.

We also need PROGRESS lines in gpgsm.

Jun 15 2023, 10:36 AM · gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), gnupg24 (gnupg-2.4.3), Feature Request, Restricted Project, Windows
gniibe committed rCed879d832659: cipher:ecc: Fix EdDSA secret key check. (authored by gniibe).
cipher:ecc: Fix EdDSA secret key check.
Jun 15 2023, 6:42 AM
gniibe committed rCf4019ed225bf: context: Make the context chain-able. (authored by gniibe).
context: Make the context chain-able.
Jun 15 2023, 4:27 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA131d4ddcfa01: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Jun 15 2023, 3:59 AM
gniibe added a comment to rCc160e1a85f82: cipher:pubkey: Fix non-use of flexible array member..

I agree that the "future" won't come, ever. (for libgcrypt)

Jun 15 2023, 2:02 AM

Jun 14 2023

ebo closed T6452: Kleopatra: Configurable default for certification expiry as Resolved.

works

Jun 14 2023, 2:15 PM · Restricted Project, kleopatra
werner added a project to T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag: Bug Report.
Jun 14 2023, 12:39 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
werner triaged T6536: Extend P12 parser for ShroudedKeyBag inside a CertBag as Normal priority.
Jun 14 2023, 12:36 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Bug Report, S/MIME, Restricted Project
ebo closed T6330: Kleopatra: Additional Expiry handling as Resolved.

works

Jun 14 2023, 11:55 AM · kleopatra, Restricted Project
ebo added a comment to T6473: Kleopatra: "Change Validity" does ignore the option "Also update the validity period of the subkeys".

It does not work as described for subkeys with later expiry dates if the primary key has already expired:


Change validity on the 12th for that key results in:

Jun 14 2023, 11:24 AM · kleopatra, Restricted Project
werner added a comment to rCc160e1a85f82: cipher:pubkey: Fix non-use of flexible array member..

I doubt that we will ever be able to use the flexible array thingy. The old pattern has been used for nearly 50 years and replacing it will just introduce bugs.
Do you use offsetof for that reason?

Jun 14 2023, 11:19 AM
gniibe committed rCc160e1a85f82: cipher:pubkey: Fix non-use of flexible array member. (authored by gniibe).
cipher:pubkey: Fix non-use of flexible array member.
Jun 14 2023, 10:13 AM
gniibe committed rC86fcf8292208: cipher:ecc: Support gcry_pk_hash_sign/verify for EdDSA. (authored by gniibe).
cipher:ecc: Support gcry_pk_hash_sign/verify for EdDSA.
Jun 14 2023, 7:59 AM
gniibe added a comment to T6511: EdDSA support in FIPS mode.

I found that for EdDSA other than pure Ed25519, it can supply context.
I changed the semantics and API for adding context and input data, as we need to support both simultaneously.

Jun 14 2023, 7:49 AM · FIPS, libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rKLEOPATRA844aafd12c09: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Jun 14 2023, 5:22 AM
gniibe added a comment to T6511: EdDSA support in FIPS mode.

I changed the lg-input-data.diff patch not to break the ABI, reusing the published symbol of gcry_pk_random_override_new.
With this approach, if/when needed, backporting may be easier.
Drawback is debugging internal of libgcrypt will be a bit confusing.

Jun 14 2023, 4:50 AM · FIPS, libgcrypt, Bug Report