In T5993#201111, @werner wrote:For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Feed Advanced Search
Advanced Search
Advanced Search
May 16 2025
May 16 2025
May 7 2025
May 7 2025
btw, my clue was that in that last --check-sigs, if i used --debug-all i got this:
This affects certification-only primary keys when doing web-of-trust calculations.
May 6 2025
May 6 2025
dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
To avoid further noise on this ticket, i've done as requested and posted to gnupg-devel : https://lists.gnupg.org/pipermail/gnupg-devel/2025-May/035875.html
May 2 2025
May 2 2025
dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
A bit more experimentation shows the same behavior, even if Alice's tsig of Bill is full, not marginal, and even if all signatures are made in the same second, which is the finest resolution that OpenPGP objects can report.
dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
Interesting analysis, thanks for the sleuthing! I'm not sure i understand why "the latest" should be preferred. For example, in the graph made in this example, which part of the graph is the "latest"? Since the path from Alice to Carol is two hops long at least, it's conceivable that one path (A→Bob→C) has both "the latest" tsig *and* "the earliest" tsig, if the other path (A→Bill→C) happens to have been made between the other two tsigs.
Apr 21 2025
Apr 21 2025
Apr 17 2025
Apr 17 2025
dkg updated the task description for T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
dkg updated the task description for T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.