Page MenuHome GnuPG
Feed All Stories

May 29 2024

TobiasFella committed rKLEOPATRAf57cea421bc4: Add default keytreeview context menu (authored by TobiasFella).
Add default keytreeview context menu
May 29 2024, 9:39 AM
TobiasFella committed rKLEOPATRA7b2f1d363d46: KeyTreeView: copy ID-like data without spaces (authored by TobiasFella).
KeyTreeView: copy ID-like data without spaces
May 29 2024, 9:39 AM
TobiasFella committed rKLEOPATRAfd05123d54cd: Add copy Action to main key list (authored by TobiasFella).
Add copy Action to main key list
May 29 2024, 9:39 AM
werner triaged T7136: libgcrypt: Implement constant-time RSA decryption (Marvin attack fix) as Low priority.

We discussed this forth and back with the RedHat people at our jour-fix to explain that the Kairo fix is done at the wrong layer - this needs to be done at the protocol layer and not in the building blocks. This is not covered by our security policy and @gniibe already came up with some extra support to help at the protocol layer. There are only a few use cases where this side-channel or the Minerva one (for ECDSA) should be considered (e.g. time stamping services). Generally required protection against DoS are also pat of the mitigation.

May 29 2024, 8:22 AM · libgcrypt, Bug Report
gniibe committed rE6c05b35977c9: Cleaner semantics for _gpgrt_process_spawn without a callback. (authored by gniibe).
Cleaner semantics for _gpgrt_process_spawn without a callback.
May 29 2024, 8:20 AM
jukivili added a comment to T7136: libgcrypt: Implement constant-time RSA decryption (Marvin attack fix).

I left review comments in gitlab. One additional concern is license for mpi-mul-cs.c, original code not having copyright information... "does not have any copyright information, assuming public domain".

May 29 2024, 8:01 AM · libgcrypt, Bug Report
l10n daemon script <scripty@kde.org> committed rMTPe03520df95a5: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 5:54 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOf4b803e2f70a: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 5:53 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA0d7fc7f7b3b8: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 5:52 AM
l10n daemon script <scripty@kde.org> committed rMTP65b31c1e43f7: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 3:42 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOd7e50ef495d8: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 3:41 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA5d9c9e6c08ff: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 29 2024, 3:39 AM

May 28 2024

dkg created T7137: unreliable RSA decryption.
May 28 2024, 10:03 PM · OpenPGP, Not A Bug, gnupg
Jakuje created T7136: libgcrypt: Implement constant-time RSA decryption (Marvin attack fix).
May 28 2024, 7:07 PM · libgcrypt, Bug Report
CarlSchwan committed rKLEOPATRA0704ee53bbb4: Move group config to GNUPGHOME (authored by CarlSchwan).
Move group config to GNUPGHOME
May 28 2024, 5:54 PM
Jakuje added a comment to T7129: Fix static reports by static analyser in gnugp.

In PATCH GnuPG 12/15] sm: Avoid use of uninitialized variable I can't see where ERR was not initialized.

May 28 2024, 5:28 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
werner moved T7129: Fix static reports by static analyser in gnugp from Backlog to WiP on the gnupg24 board.
May 28 2024, 5:20 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
werner added a comment to T7129: Fix static reports by static analyser in gnugp.

All except the above mentioned applied to master - will be backported to 2.4

May 28 2024, 5:20 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
werner added a comment to T7129: Fix static reports by static analyser in gnugp.

In PATCH GnuPG 12/15] sm: Avoid use of uninitialized variable I can't see where ERR was not initialized.

May 28 2024, 5:19 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
werner committed rG9adaa79ab43e: gpg-auth: Fix use after free. (authored by Jakuje).
gpg-auth: Fix use after free.
May 28 2024, 5:18 PM
werner committed rGdcb0b6fd4822: gpgsm: Avoid double free when checking rsaPSS signatures. (authored by Jakuje).
gpgsm: Avoid double free when checking rsaPSS signatures.
May 28 2024, 5:18 PM
werner committed rG28c705a3be5c: gpgsm: Silence a lint warning (authored by werner).
gpgsm: Silence a lint warning
May 28 2024, 5:18 PM
werner committed rG379fc5569d60: agent: Avoid uninitialized access in GENKEY command on parameter error. (authored by Jakuje).
agent: Avoid uninitialized access in GENKEY command on parameter error.
May 28 2024, 5:18 PM
werner committed rG4c1b0070354d: scd: Avoid buffer overrun with more than 16 PC/SC readers. (authored by Jakuje).
scd: Avoid buffer overrun with more than 16 PC/SC readers.
May 28 2024, 5:18 PM
werner committed rGbdbf5cee2ff5: agent: Avoid double free of empty string in the PIN caching. (authored by werner).
agent: Avoid double free of empty string in the PIN caching.
May 28 2024, 5:18 PM
werner committed rGfdc500395640: agent: Make sure to return success in ephemeral store mode. (authored by werner).
agent: Make sure to return success in ephemeral store mode.
May 28 2024, 5:18 PM
werner committed rG021c27510b52: wks: Make sure that ERR is always initialized. (authored by werner).
wks: Make sure that ERR is always initialized.
May 28 2024, 5:18 PM
werner committed rGbcc002cd45d1: gpg: Avoid a double free on error in the key generation. (authored by werner).
gpg: Avoid a double free on error in the key generation.
May 28 2024, 5:18 PM
TobiasFella committed rKLEOPATRAa5548c380f5f: WebOfTrustWidget: Add option to only show own certifications (authored by TobiasFella).
WebOfTrustWidget: Add option to only show own certifications
May 28 2024, 4:37 PM
TobiasFella committed rKLEOPATRAd57973958c90: Refactor (authored by TobiasFella).
Refactor
May 28 2024, 4:35 PM
TobiasFella committed rKLEOPATRAcc1ebbc35504: Refactor (authored by TobiasFella).
Refactor
May 28 2024, 4:35 PM
TobiasFella committed rKLEOPATRAbd99bca3474a: Bump version (authored by TobiasFella).
Bump version
May 28 2024, 4:35 PM
TobiasFella committed rKLEOPATRA1f6050c8876c: Apply 1 suggestion(s) to 1 file(s) (authored by ikloecker).
Apply 1 suggestion(s) to 1 file(s)
May 28 2024, 4:35 PM
TobiasFella committed rKLEOPATRA4a0dfa17a6ef: Bump likleo dependency (authored by TobiasFella).
Bump likleo dependency
May 28 2024, 4:35 PM
TobiasFella committed rKLEOPATRAc91f4f3f653f: WebOfTrustWidget: Add option to only show own certifications (authored by TobiasFella).
WebOfTrustWidget: Add option to only show own certifications
May 28 2024, 4:35 PM
Jakuje added a comment to T7129: Fix static reports by static analyser in gnugp.

Fair enough. This is more theoretical and could happen only on huge reads. Using ssize_t for read() return value is safe option, but really does not make sense to adhere to it in cases where the reads must be smaller.

May 28 2024, 4:23 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
TobiasFella committed rKLEOPATRAbd4a39f5176a: Implementing adding ADSKs (authored by TobiasFella).
Implementing adding ADSKs
May 28 2024, 4:11 PM
werner added a comment to T7129: Fix static reports by static analyser in gnugp.

I do not understand why there should be an integer overflow:

May 28 2024, 4:10 PM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
TobiasFella committed rKLEOPATRA079a7f1fa66e: Implementing adding ADSKs (authored by TobiasFella).
Implementing adding ADSKs
May 28 2024, 3:26 PM
TobiasFella committed rKLEOPATRAe7c9f47c362d: Implementing adding ADSKs (authored by TobiasFella).
Implementing adding ADSKs
May 28 2024, 2:58 PM
TobiasFella committed rKLEOPATRA88cc294b563b: Implementing adding ADSKs (authored by TobiasFella).
Implementing adding ADSKs
May 28 2024, 2:58 PM
TobiasFella committed rKLEOPATRAc084fa40a944: Refactor (authored by TobiasFella).
Refactor
May 28 2024, 1:49 PM
TobiasFella committed rLIBKLEOde14b840c933: Add functions for getting signature and userid object to UserIDListProxyModel (authored by TobiasFella).
Add functions for getting signature and userid object to UserIDListProxyModel
May 28 2024, 1:34 PM
mlaurent committed rMTP3a102d8b0ace: Use [[nodiscard]] (authored by mlaurent).
Use [[nodiscard]]
May 28 2024, 1:33 PM
werner committed rGd631c8198c25: tpm: Improve error handling and check returned lengths. (authored by werner).
tpm: Improve error handling and check returned lengths.
May 28 2024, 1:32 PM
werner committed rG2e4b1f785055: tpm: Do not use fprintf for logging. (authored by werner).
tpm: Do not use fprintf for logging.
May 28 2024, 1:32 PM
TobiasFella committed rKLEOPATRA2d863f1a06cd: Improve revocation dialog (authored by TobiasFella).
Improve revocation dialog
May 28 2024, 12:18 PM
TobiasFella committed rLIBKLEO19bca0ad25bc: Add ClipboardRole to KeyListModel (authored by TobiasFella).
Add ClipboardRole to KeyListModel
May 28 2024, 12:12 PM
TobiasFella committed rKLEOPATRA096f9b24d975: Add default keytreeview context menu (authored by TobiasFella).
Add default keytreeview context menu
May 28 2024, 12:09 PM
TobiasFella committed rKLEOPATRA27883b8961e4: KeyTreeView: copy ID-like data without spaces (authored by TobiasFella).
KeyTreeView: copy ID-like data without spaces
May 28 2024, 12:09 PM
TobiasFella committed rKLEOPATRAf4ba28684053: Add copy Actiont to main key list (authored by TobiasFella).
Add copy Actiont to main key list
May 28 2024, 12:09 PM
werner assigned T7130: Fix static reports by static analyser in libgcrypt to gniibe.
May 28 2024, 11:08 AM · libgcrypt, Bug Report
werner raised the priority of T7129: Fix static reports by static analyser in gnugp from Normal to High.
May 28 2024, 11:08 AM · gnupg22 (gnupg-2.2.44), gnupg24 (2.4.6), Bug Report
ikloecker changed External Link from https://invent.kde.org/pim/libkleo/-/merge_requests/102 to https://invent.kde.org/pim/kleopatra/-/merge_requests/216 on T6931: Kleopatra: Move kleopatragroupsrc to GNUPGHOME.
May 28 2024, 9:27 AM · vsd33 (vsd-3.3.0), Restricted Project, kleopatra
TobiasFella committed rKLEOPATRA5780ab222eec: Trim text for key list filtering (authored by TobiasFella).
Trim text for key list filtering
May 28 2024, 9:16 AM
werner raised a concern with rE8dc6e3281e17: Import spawn functions from GnuPG master..
May 28 2024, 9:00 AM
mlaurent committed rMTP4ce3acc8447f: GIT_SILENT prepare 6.1.1 (authored by mlaurent).
GIT_SILENT prepare 6.1.1
May 28 2024, 7:57 AM
mlaurent committed rKLEOPATRAc2b3b38a9d0e: GIT_SILENT prepare 6.1.1 (authored by mlaurent).
GIT_SILENT prepare 6.1.1
May 28 2024, 7:55 AM
gniibe committed rAd5e0aa3f74cb: Modify documentation for new release. (authored by gniibe).
Modify documentation for new release.
May 28 2024, 5:10 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA03b18adf4595: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 28 2024, 5:01 AM
gniibe committed rE8dc6e3281e17: Import spawn functions from GnuPG master. (authored by gniibe).
Import spawn functions from GnuPG master.
May 28 2024, 4:52 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOd72c89765e26: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 28 2024, 3:26 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA0983147f7893: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 28 2024, 3:24 AM

May 27 2024

CarlSchwan committed rKLEOPATRAeb56fe662063: Move group config to GNUPGHOME (authored by CarlSchwan).
Move group config to GNUPGHOME
May 27 2024, 5:13 PM
CarlSchwan committed rKLEOPATRAbed01c8d59a2: Move group config to GNUPGHOME (authored by CarlSchwan).
Move group config to GNUPGHOME
May 27 2024, 5:10 PM
TobiasFella committed rLIBKLEO5dde20252b75: Fix clipboardrole for UserIDProxyModel (authored by TobiasFella).
Fix clipboardrole for UserIDProxyModel
May 27 2024, 4:30 PM
TobiasFella committed rKLEOPATRA1508013632c6: Remove groupbox (authored by TobiasFella).
Remove groupbox
May 27 2024, 3:05 PM
TobiasFella committed rKLEOPATRAf641615982d8: Remove spacing in front of radio buttons (authored by TobiasFella).
Remove spacing in front of radio buttons
May 27 2024, 3:05 PM
CarlSchwan committed rOJ53a285237717: Fix compilation with Qt 6.7 (authored by CarlSchwan).
Fix compilation with Qt 6.7
May 27 2024, 2:30 PM
TobiasFella committed rKLEOPATRA53a87e0ae0e1: Bump version (authored by TobiasFella).
Bump version
May 27 2024, 2:25 PM
TobiasFella committed rKLEOPATRAd3e8f4b0a5b3: Refactor (authored by TobiasFella).
Refactor
May 27 2024, 2:24 PM
TobiasFella committed rLIBKLEO4c5aba79cd8d: Add functions for getting signature and userid object to UserIDListProxyModel (authored by TobiasFella).
Add functions for getting signature and userid object to UserIDListProxyModel
May 27 2024, 2:23 PM
ebo created T7135: GpgOL: POP3 issue.
May 27 2024, 2:21 PM · gpgol, Restricted Project
TobiasFella committed rKLEOPATRA346776c0632c: Apply 1 suggestion(s) to 1 file(s) (authored by ikloecker).
Apply 1 suggestion(s) to 1 file(s)
May 27 2024, 1:46 PM
werner added a comment to T7134: Kleopatra: Allow PIN reset with Admin-PIN.

For OpenPGP cards >= v2.0 there is no PUK due to updated ISO standards but we use the term in Kleopatra for the Reset-Code.

May 27 2024, 1:42 PM · Feature Request, Restricted Project, kleopatra
TobiasFella committed rKLEOPATRA2c201445dfca: Add column enum for SubkeysWidget (authored by TobiasFella).
Add column enum for SubkeysWidget
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA662f31c2d498: Add column enum for CardInfoTab (authored by TobiasFella).
Add column enum for CardInfoTab
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA008b7005863f: Remove unused data (authored by TobiasFella).
Remove unused data
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA4a8d63499626: Apply 1 suggestion(s) to 1 file(s) (authored by ikloecker).
Apply 1 suggestion(s) to 1 file(s)
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA6e8265cfb509: Show fingerprint instead of Key ID by default (authored by TobiasFella).
Show fingerprint instead of Key ID by default
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRAda379ac2dce7: Add keygrip column to subkeys view (authored by TobiasFella).
Add keygrip column to subkeys view
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA12040209e323: Show more correct info when key is on card and on the computer (authored by TobiasFella).
Show more correct info when key is on card and on the computer
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA2dc5fdc66c8b: Add Fingerprint column to card info tab (authored by TobiasFella).
Add Fingerprint column to card info tab
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRAa0e13fe9954f: Trim text for key list filtering (authored by TobiasFella).
Trim text for key list filtering
May 27 2024, 12:31 PM
TobiasFella committed rKLEOPATRA0395c0fd1ec4: Copy key ids, fingerprints, and keygrips without spaces (authored by TobiasFella).
Copy key ids, fingerprints, and keygrips without spaces
May 27 2024, 12:23 PM
TobiasFella committed rKLEOPATRA43fa8720c9ad: Copy key ids, fingerprints, and keygrips without spaces (authored by TobiasFella).
Copy key ids, fingerprints, and keygrips without spaces
May 27 2024, 11:48 AM
TobiasFella committed rLIBKLEO34b06b6aefca: Add ClipboardRole to KeyListModel (authored by TobiasFella).
Add ClipboardRole to KeyListModel
May 27 2024, 11:47 AM
ebo moved T5138: Change Reset Code not working in Kleopatra from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 27 2024, 11:26 AM · Restricted Project, Feature Request, Bug Report, kleopatra
ebo created T7134: Kleopatra: Allow PIN reset with Admin-PIN.
May 27 2024, 11:24 AM · Feature Request, Restricted Project, kleopatra
ebo added a project to T5138: Change Reset Code not working in Kleopatra: Restricted Project.
May 27 2024, 11:16 AM · Restricted Project, Feature Request, Bug Report, kleopatra
alexk added a comment to T5447: Add feature to delete a key from an LDAP server.

Also required for an actium feature with UI.

May 27 2024, 10:15 AM · vsd33, Restricted Project, gnupg24, LDAP
ikloecker added a comment to T7095: Kleopatra: show designated revoker in details window.

Information about revocation keys can now be retrieved from a Key object (see T7118).

May 27 2024, 9:58 AM · Restricted Project, kleopatra
ikloecker moved T7118: gpgme: Add support for designated revokers from Restricted Project Column to Restricted Project Column on the Restricted Project board.
May 27 2024, 9:56 AM · gpgme, Restricted Project, kleopatra
ikloecker closed T7118: gpgme: Add support for designated revokers, a subtask of T7095: Kleopatra: show designated revoker in details window, as Resolved.
May 27 2024, 9:55 AM · Restricted Project, kleopatra
ikloecker closed T7118: gpgme: Add support for designated revokers as Resolved.

Information about revocation keys can now be retrieved from a Key object. Verified with internal test runners. Independent tests will be done with T7095.

May 27 2024, 9:55 AM · gpgme, Restricted Project, kleopatra
werner added a comment to T6481: BEGIN_ENCRYPTION status output happens later in 2.4.1 (breaks Emacs's EasyPG).

This is not a bug. We changed it as a convenience for some Emacs users.

May 27 2024, 8:26 AM · Emacs, gnupg, Bug Report
mlaurent committed rKLEOPATRA85202211ea03: Use context i18n (authored by mlaurent).
Use context i18n
May 27 2024, 8:18 AM
mlaurent committed rLIBKLEO5241145ec568: Use context i18n (authored by mlaurent).
Use context i18n
May 27 2024, 8:18 AM
dkg added a comment to T6481: BEGIN_ENCRYPTION status output happens later in 2.4.1 (breaks Emacs's EasyPG).

Are you saying that concern about "risking a regression" is the reason to not fix this bug, which is itself a regression, and was introduced into the a point release in the current "long term support" branch?

May 27 2024, 6:21 AM · Emacs, gnupg, Bug Report
l10n daemon script <scripty@kde.org> committed rLIBKLEO752f80c70f39: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
May 27 2024, 5:05 AM