Page MenuHome GnuPG
Feed Advanced Search

Fri, Jul 11

gniibe added a comment to T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error.

Here is an experimental change to support the feature.

Fri, Jul 11, 10:50 AM · gpgrt, Feature Request, Bug Report
gniibe added a comment to T7720: w32: Synchronous spawning gpg-agent/dirmngr/keyboxd.

I'm testing the following patch with experimental change of libgpg-error.

Fri, Jul 11, 10:45 AM · gnupg, Feature Request, Bug Report
gniibe triaged T7720: w32: Synchronous spawning gpg-agent/dirmngr/keyboxd as Wishlist priority.
Fri, Jul 11, 10:44 AM · gnupg, Feature Request, Bug Report
gniibe renamed T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error from gpgrt:w32: Spawn detached process, with standard input and standard error to gpgrt:w32: Synchronous spawning detached process, with standard input and standard error.
Fri, Jul 11, 10:39 AM · gpgrt, Feature Request, Bug Report

Wed, Jul 9

gniibe updated the task description for T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error.
Wed, Jul 9, 9:07 AM · gpgrt, Feature Request, Bug Report
gniibe triaged T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error as Wishlist priority.
Wed, Jul 9, 6:44 AM · gpgrt, Feature Request, Bug Report
gniibe claimed T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error.
Wed, Jul 9, 6:44 AM · gpgrt, Feature Request, Bug Report
gniibe created T7716: gpgrt:w32: Synchronous spawning detached process, with standard input and standard error.
Wed, Jul 9, 6:43 AM · gpgrt, Feature Request, Bug Report

Tue, Jul 8

werner closed T7715: Dirmngr shall send a User-Agent header as Resolved.
Tue, Jul 8, 3:46 PM · Feature Request, gnupg26
werner triaged T7715: Dirmngr shall send a User-Agent header as Normal priority.
Tue, Jul 8, 9:50 AM · Feature Request, gnupg26

Mon, Jul 7

ikloecker updated the task description for T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA%.
Mon, Jul 7, 4:38 PM · Feature Request, kleopatra, vsd34

Thu, Jul 3

ikloecker updated the task description for T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA%.
Thu, Jul 3, 2:31 PM · Feature Request, kleopatra, vsd34
ikloecker claimed T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA%.
Thu, Jul 3, 10:36 AM · Feature Request, kleopatra, vsd34
collinfunk added a comment to T6598: Fix FD2INT for 64-bit Windows.

Can't you just use file descriptors everywhere and use _get_osfhandle. That is what I am used to seeing in Windows code in Gnulib (although I do not touch it much).

Thu, Jul 3, 4:23 AM · Windows 64, Feature Request, gnupg26

Wed, Jul 2

werner reopened T6598: Fix FD2INT for 64-bit Windows as "Open".

Regarding 64bit handles https://learn.microsoft.com/en-us/windows/win32/winprog64/interprocess-communication
tells us:

Wed, Jul 2, 4:41 PM · Windows 64, Feature Request, gnupg26
werner reopened T6598: Fix FD2INT for 64-bit Windows, a subtask of T6508: Port GnuPG to 64-bit Windows, as Open.
Wed, Jul 2, 4:41 PM · Windows 64, Feature Request, gnupg26
werner triaged T7713: Allow to skip the qualified signature confirmation prompt as Normal priority.
Wed, Jul 2, 11:41 AM · S/MIME, Feature Request, gnupg26
werner triaged T7710: Kleopatra: Paperkey can't handle curve448/kyber keys as Normal priority.

This seems to be a good opportunity to replace paperkey with a new tool to take advantage of the smaller ECC keys which allow us to re-generate most stuff.

Wed, Jul 2, 9:14 AM · Feature Request, gnupg26, kleopatra

Mon, Jun 30

timegrid moved T6694: Random numbers from gpgme from Backlog to Done on the gpd5x board.

Ingo tested this and it worked.

Mon, Jun 30, 11:02 AM · gpd5x, gpgpass, gpgme, Feature Request

Thu, Jun 26

ebo added a project to T7328: Add Kleopatra configs to gpgconf -X: gpd5x.
Thu, Jun 26, 5:31 PM · gpd5x, Windows, gnupg, Feature Request

Wed, Jun 25

werner triaged T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA% as High priority.

But we have the same problems on Unix as described by T7699. (funny, the other bug mentioned above has 76 reversed)

Wed, Jun 25, 6:21 PM · Feature Request, kleopatra, vsd34

Mon, Jun 23

ebo raised the priority of T7581: Kleopatra: Create team key from Normal to High.
Mon, Jun 23, 3:48 PM · Feature Request, gpd5x, kleopatra

Wed, Jun 18

ebo closed T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting as Invalid.

We decided in T7579: Kleopatra: improve menu items to remove this action. Users will instead have to mark certificates they want to update and use the Update Certificates action in the "Certificates" menu.

Wed, Jun 18, 4:56 PM · Feature Request, kleopatra
werner closed T6551: translate_sys2libc_fd_int on Windows 64-bit, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Wed, Jun 18, 9:45 AM · Windows 64, Feature Request, gnupg26
werner closed T6551: translate_sys2libc_fd_int on Windows 64-bit as Resolved.
Wed, Jun 18, 9:45 AM · Windows 64, Feature Request, gnupg26
werner closed T6508: Port GnuPG to 64-bit Windows as Resolved.

After several gpg4win-5 betas be can set this task to resolved.

Wed, Jun 18, 9:44 AM · Windows 64, Feature Request, gnupg26
werner closed T6580: Use gnupg_fd_t if it's relevant, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Wed, Jun 18, 9:43 AM · Windows 64, Feature Request, gnupg26
werner closed T6580: Use gnupg_fd_t if it's relevant as Resolved.

I claim this resolved given several gpg4win-5 betas.

Wed, Jun 18, 9:43 AM · Windows 64, Feature Request, gnupg26
werner closed T6598: Fix FD2INT for 64-bit Windows, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Wed, Jun 18, 9:42 AM · Windows 64, Feature Request, gnupg26
werner closed T6598: Fix FD2INT for 64-bit Windows as Resolved.

I claim this resolved given that we had several gpg4win-5 betas and no reported problems was related to this.

Wed, Jun 18, 9:42 AM · Windows 64, Feature Request, gnupg26
werner lowered the priority of T6234: Implement access to smartcards via a generic pkcs#11 interface from Normal to Wishlist.

The actual project we had in mind for this was more or less canceled and thus I re-prioritize this task.

Wed, Jun 18, 9:38 AM · gnupg, Feature Request, scd
werner closed T7014: agent: Enhancement of PKDECRYPT for KEM interface as Resolved.

This was release with 2.5.7.

Wed, Jun 18, 9:29 AM · gnupg26, gpgagent, Feature Request

Tue, Jun 17

ebo renamed T7581: Kleopatra: Create team key from Draft: Kleopatra: Create Group key to Kleopatra: Create team key.
Tue, Jun 17, 5:30 PM · Feature Request, gpd5x, kleopatra
gniibe closed T5964: gnupg should use the KDFs implemented in libgcrypt as Resolved.
Tue, Jun 17, 2:38 AM · gnupg26, FIPS, Feature Request

Jun 2 2025

werner added a comment to T7381: gpg-mail-tube,gpg-wks-server: Allow the use of templates instead of static texts..

We do this now also for gpg-wks-server. Further gpg-wks-client now sends the current language to the server so that the server can get back to the user with a proper translated text (if configured).

Jun 2 2025, 12:38 PM · Feature Request, gnupg26
werner renamed T7381: gpg-mail-tube,gpg-wks-server: Allow the use of templates instead of static texts. from gpg-mail-tube: Allow the use of templates instead of static texts. to gpg-mail-tube,gpg-wks-server: Allow the use of templates instead of static texts..
Jun 2 2025, 12:37 PM · Feature Request, gnupg26

May 30 2025

werner changed the status of T7381: gpg-mail-tube,gpg-wks-server: Allow the use of templates instead of static texts., a subtask of T7292: gpg-mail-tube: Add more features, from Open to Testing.
May 30 2025, 2:57 PM · Feature Request, gnupg26
werner changed the status of T7381: gpg-mail-tube,gpg-wks-server: Allow the use of templates instead of static texts. from Open to Testing.

Alright. We use utf-8 in our template files and switch to QP encoding when needed.

May 30 2025, 2:57 PM · Feature Request, gnupg26

May 28 2025

aheinecke added a comment to T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting.

Just as a reminder, knowledge transfer, because this is easily overlooked in testing but at least one customer would have gotten very annoyed if we had ever deployed an "Update all certificates" function which "added" new certificates. Even with the update of a single cert, we had a "funny" issue, like if you had expired certificates from anywhere and not from WKD (which old keyrings have a lot, maybe with many uids). Suddenly an update would pull in new keys which come from WKD but maybe there they all only have one UID. Because for keyservers the identifier was the fingerprint and for WKD the identifier was the userid.
Or even worse, you explicitly threw out the OpenPGP keys from WKD because you wanted to use only S/MIME, then such a function may not search on any OpenPGP Sources.
When I worked at Kleopatra we didn't want such a feature in GnuPG. Our strategy was to update keys when they are used, about to be used or close to expiry. The whole locate-external-key thing.
I think the feature we had to update in the certificate details is good. But i recommend especially keeping the S/MIME / OpenPGP difference in mind. I would also call it "Search updated certificates" with a tooltip that it might also find "new" certificates for the user. And then an option to disable this either for S/MIME or for OpenPGP.

May 28 2025, 9:45 PM · Feature Request, kleopatra
werner moved T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign. from Backlog to QA on the gnupg26 board.
May 28 2025, 10:47 AM · gnupg24, gnupg26, Feature Request

May 27 2025

ikloecker edited projects for T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting, added: Feature Request; removed Bug Report.

Tools / Refresh OpenPGP certificates runs gpg --refresh-keys. I don't think that this command knows anything about WKD.

May 27 2025, 5:20 PM · Feature Request, kleopatra

May 26 2025

werner edited projects for T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign., added: Feature Request, gnupg26, gnupg24; removed Bug Report.
May 26 2025, 6:08 PM · gnupg24, gnupg26, Feature Request
gniibe added a parent task for T5964: gnupg should use the KDFs implemented in libgcrypt: T7649: gnupg: Use KEM interface for encryption/decryption.
May 26 2025, 6:34 AM · gnupg26, FIPS, Feature Request
gniibe added a parent task for T7014: agent: Enhancement of PKDECRYPT for KEM interface: T7649: gnupg: Use KEM interface for encryption/decryption.
May 26 2025, 6:33 AM · gnupg26, gpgagent, Feature Request
gniibe changed the status of T5964: gnupg should use the KDFs implemented in libgcrypt from Open to Testing.

Done by T7649: gnupg: Use KEM interface for encryption/decryption

May 26 2025, 6:32 AM · gnupg26, FIPS, Feature Request

May 22 2025

ebo added a project to T5006: Kleopatra: Display Names and Key-IDs for certificates after any attempt to import them.: gpd5x.
May 22 2025, 3:35 PM · gpd5x, kleopatra, Feature Request
ebo added a comment to T5006: Kleopatra: Display Names and Key-IDs for certificates after any attempt to import them..

Please solve this the same as our solution in T7630: add a button in the results window to open a new window with all the imported certificates.

May 22 2025, 3:35 PM · gpd5x, kleopatra, Feature Request
ebo renamed T7582: Kleopatra: Make default backup location for secret keys configurable from Draft: Kleopatra: make storage location configurable to Kleopatra: Make default backup location for secret keys configurable.
May 22 2025, 3:05 PM · Feature Request, gpd5x, kleopatra
alexk changed the status of T7269: Attachments vanish from forward encrypted message from Open to Testing.

Fixed in most cases.
Edge cases will be examined further.

May 22 2025, 1:37 PM · Restricted Project, Feature Request, gpgol

May 16 2025

dkg added a comment to T5993: gpg should reject compressed packets outside of messages.

For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 4:12 PM · Feature Request, gnupg
werner closed T5993: gpg should reject compressed packets outside of messages as Resolved.
May 16 2025, 2:46 PM · Feature Request, gnupg
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

(The commits had a wrong bug it in their message)

May 16 2025, 2:44 PM · Feature Request, gnupg
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

It might be useful to have samples of compressed keys:

May 16 2025, 2:20 PM · Feature Request, gnupg
werner updated subscribers of T5993: gpg should reject compressed packets outside of messages.

No, we can't do much about this. It has always been easy to create compression bombs and the more relevant thing here is compressed signed or encrypted data. Or just compressed mails. The patch by @DemiMarie is way to complicated for what it wants to achieve and actually breaks existing use cases. For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 12:04 PM · Feature Request, gnupg

May 15 2025

hej added a comment to T7581: Kleopatra: Create team key.

"Geheimen Team-Schlüssel zum internen Teilen abspeichern." is grammatically correct, but it sound very formal and clunky for a UI tooltip. It lacks clarity, therefore I suggest:

May 15 2025, 9:31 AM · Feature Request, gpd5x, kleopatra

May 14 2025

TobiasFella changed the status of T7580: Kleopatra: Add a dialog window to the disable/enable certificate action, a subtask of T7216: Kleopatra: Integrate "disabled" feature from gpg, from Open to Testing.
May 14 2025, 11:59 AM · Feature Request, kleopatra
ebo renamed T7616: Kleopatra: add test to check connectivity from Draft: Kleopatra: add test to check connectivity to Kleopatra: add test to check connectivity.
May 14 2025, 11:58 AM · gpd5x, Feature Request, kleopatra
ebo updated the task description for T7616: Kleopatra: add test to check connectivity.
May 14 2025, 11:53 AM · gpd5x, Feature Request, kleopatra
ebo updated the task description for T7616: Kleopatra: add test to check connectivity.
May 14 2025, 11:34 AM · gpd5x, Feature Request, kleopatra
ebo added a comment to T7581: Kleopatra: Create team key.

Tooltip: Save this secret key to share with other team members.
dt. Menüeintrag: Geheimen Team-Schlüssel speichern
Tooltip: Geheimen Schlüssel speichern und mit Team teilen.

May 14 2025, 11:21 AM · Feature Request, gpd5x, kleopatra
ebo added a comment to T7616: Kleopatra: add test to check connectivity.

Werner strongly prefers to include it in the self-tests instead of adding a command to the drop-down list.
I will therefore update the description accordingly.

May 14 2025, 10:15 AM · gpd5x, Feature Request, kleopatra

May 13 2025

werner closed T6941: gpgsm/dirmngr: support for end-entity certificates with an empty "Subject DN" as Resolved.

Meanwhile we have some support for an empty subject but gpgsm still prints an error notice. See the T7171 for more.

May 13 2025, 3:00 PM · gnupg26, S/MIME, Feature Request
werner added a parent task for T6941: gpgsm/dirmngr: support for end-entity certificates with an empty "Subject DN": T7171: Allow for empty Subject in X.509.
May 13 2025, 2:58 PM · gnupg26, S/MIME, Feature Request

May 11 2025

gniibe closed T7338: Revamp the FIPS service indicator as Resolved.

Included in 1.11.1.

May 11 2025, 3:24 AM · libgcrypt, FIPS, Feature Request

May 10 2025

ajschmidt8 added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.
May 10 2025, 3:22 AM · Feature Request

May 6 2025

hej added a comment to T7581: Kleopatra: Create team key.

engl. Menu Entry: Save Secret Team Key
Tooltip: Save this secret key to share with other team members.

May 6 2025, 4:10 PM · Feature Request, gpd5x, kleopatra
alexk updated the task description for T7581: Kleopatra: Create team key.
May 6 2025, 3:32 PM · Feature Request, gpd5x, kleopatra
alexk added a comment to T7581: Kleopatra: Create team key.

Discussion and background for naming things and german translation

May 6 2025, 3:20 PM · Feature Request, gpd5x, kleopatra
ikloecker updated subscribers of T7405: Kleopatra: Highlight if no valid encryption subkey exists.

For the icon:

May 6 2025, 2:57 PM · Feature Request, gpd5x, kleopatra
alexk updated the task description for T7581: Kleopatra: Create team key.
May 6 2025, 2:54 PM · Feature Request, gpd5x, kleopatra
ebo renamed T7405: Kleopatra: Highlight if no valid encryption subkey exists from Draft: Kleopatra: Highlight if no valid encryption subkey exists to Kleopatra: Highlight if no valid encryption subkey exists.
May 6 2025, 11:50 AM · Feature Request, gpd5x, kleopatra
ebo added a comment to T7405: Kleopatra: Highlight if no valid encryption subkey exists.

We decided to

May 6 2025, 11:45 AM · Feature Request, gpd5x, kleopatra

May 2 2025

bernhard added a comment to T6234: Implement access to smartcards via a generic pkcs#11 interface.

A brief update: This feature has not made it onto the roadmap of specific things to implement so far.

May 2 2025, 3:51 PM · gnupg, Feature Request, scd
ebo added a comment to T7405: Kleopatra: Highlight if no valid encryption subkey exists.

There was another customer wish for this, RT #34722

May 2 2025, 3:27 PM · Feature Request, gpd5x, kleopatra

Apr 22 2025

werner triaged T7618: gpgsm: Allow selecting keys by SHA2 fpr as Normal priority.

BTW, fingerprints for X.509 are not well defined because you get a different one when changing the *unsigned" attributes. Not a common case but one should be aware of it.

Apr 22 2025, 9:33 AM · S/MIME, gnupg26, Feature Request
ebo added a comment to T7616: Kleopatra: add test to check connectivity.

regarding the 403: one has to try the correct page AFAIK. Didn't research which one, look in the update checker code.

Apr 22 2025, 8:46 AM · gpd5x, Feature Request, kleopatra

Apr 19 2025

ametzler1 created T7618: gpgsm: Allow selecting keys by SHA2 fpr.
Apr 19 2025, 4:53 PM · S/MIME, gnupg26, Feature Request

Apr 17 2025

ikloecker added a comment to T7616: Kleopatra: add test to check connectivity.

In any case, the actual connectivity test needs to be performed by GnuPG. Otherwise we might just test whether the Qt/KDE libraries can reach versions.gnupg.org, but not whether dirmngr can. Werner proposed something like gpg --fetch-key https://gnupg.org/index.html.

Apr 17 2025, 5:33 PM · gpd5x, Feature Request, kleopatra
werner triaged T7616: Kleopatra: add test to check connectivity as Normal priority.
Apr 17 2025, 4:47 PM · gpd5x, Feature Request, kleopatra
ebo created T7616: Kleopatra: add test to check connectivity.
Apr 17 2025, 3:21 PM · gpd5x, Feature Request, kleopatra

Apr 14 2025

werner triaged T7603: gpgv has unnecessary dependency on libassuan and NPth as Low priority.
Apr 14 2025, 9:24 AM · Debian, Feature Request, gpgv

Apr 9 2025

ebo moved T7098: Change the GpgOL encryption icon according to its state from QA to WiP on the vsd33 board.

this is not yet in master and not included in the current testbulid

Apr 9 2025, 9:48 AM · vsd33, Feature Request, Restricted Project, gpgol

Apr 3 2025

werner moved T7098: Change the GpgOL encryption icon according to its state from WiP to QA on the vsd33 board.
Apr 3 2025, 9:52 AM · vsd33, Feature Request, Restricted Project, gpgol

Apr 2 2025

werner closed T5079: Add compliance flag to trustlist.txt as Resolved.

We have done all of this and the rest of the work is now in T7593

Apr 2 2025, 11:44 AM · gnupg22 (gnupg-2.2.45), gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request
werner triaged T7593: Check the trustlist de-vs flag in the per key compliance check as High priority.
Apr 2 2025, 11:43 AM · gnupg26, vsd, Restricted Project, Feature Request
werner moved T5079: Add compliance flag to trustlist.txt from Backlog to gnupg-2.2.45 on the gnupg22 board.
Apr 2 2025, 11:39 AM · gnupg22 (gnupg-2.2.45), gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request
werner closed T7337: Show a summary of all URLs with dirmngr's LISTCRL command as Resolved.
Apr 2 2025, 11:36 AM · gnupg22 (gnupg-2.2.45), Feature Request
werner moved T7337: Show a summary of all URLs with dirmngr's LISTCRL command from Backlog to gnupg-2.2.45 on the gnupg22 board.
Apr 2 2025, 11:36 AM · gnupg22 (gnupg-2.2.45), Feature Request
werner edited projects for T7328: Add Kleopatra configs to gpgconf -X, added: gnupg, Windows; removed gnupg22.
Apr 2 2025, 11:31 AM · gpd5x, Windows, gnupg, Feature Request

Mar 26 2025

Valodim added a comment to T4493: Default to HKPS, not HKP.

Hey there. I wanted to bring this up again, to see if we can perhaps get this changed after all:

Mar 26 2025, 6:04 PM · dirmngr, Feature Request
werner triaged T7584: Okular: Move config files to GNUPGHOME as Normal priority.
Mar 26 2025, 8:45 AM · Feature Request, gpd5x, okular

Mar 21 2025

ebo triaged T7582: Kleopatra: Make default backup location for secret keys configurable as Normal priority.
Mar 21 2025, 11:53 AM · Feature Request, gpd5x, kleopatra
ebo triaged T7581: Kleopatra: Create team key as Normal priority.
Mar 21 2025, 11:29 AM · Feature Request, gpd5x, kleopatra

Mar 20 2025

mmontkowski moved T7269: Attachments vanish from forward encrypted message from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Mar 20 2025, 2:12 PM · Restricted Project, Feature Request, gpgol

Mar 14 2025

werner added a comment to T6694: Random numbers from gpgme.

BTW, do we really need a C++ API for this? Might make sense due to the need for a context.

Mar 14 2025, 1:10 PM · gpd5x, gpgpass, gpgme, Feature Request
werner changed the status of T6694: Random numbers from gpgme from Open to Testing.
Mar 14 2025, 1:09 PM · gpd5x, gpgpass, gpgme, Feature Request

Mar 13 2025

mmontkowski added a comment to T7269: Attachments vanish from forward encrypted message.

Well I finally did some more tracing and removeOurAttachments_o is not called when the attachments vanish.

Mar 13 2025, 7:17 PM · Restricted Project, Feature Request, gpgol
ebo closed T7236: Kleopatra: Use filter in certificate selection for encryption as Resolved.
Mar 13 2025, 4:21 PM · gpd5x, Feature Request, kleopatra
ebo edited projects for T7236: Kleopatra: Use filter in certificate selection for encryption , added: gpd5x; removed Restricted Project.

5.0Beta:145: OK and works, both for signing and encryption

Mar 13 2025, 4:21 PM · gpd5x, Feature Request, kleopatra
werner triaged T7560: GnuPG should learn the certificates when a new card has been seen as Normal priority.
Mar 13 2025, 11:43 AM · scd, Feature Request, gnupg