Page MenuHome GnuPG
Feed Advanced Search

May 16 2025

dkg added a comment to T5993: gpg should reject compressed packets outside of messages.

For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

May 16 2025, 4:12 PM · Feature Request, gnupg

May 7 2025

dkg added a comment to T7583: 2.5.5 removes sig on clean that 2.5.4 and earlier kept.

btw, my clue was that in that last --check-sigs, if i used --debug-all i got this:

May 7 2025, 10:35 PM · gnupg, Bug Report
dkg added a comment to T7583: 2.5.5 removes sig on clean that 2.5.4 and earlier kept.

This affects certification-only primary keys when doing web-of-trust calculations.

May 7 2025, 9:46 PM · gnupg, Bug Report

May 6 2025

dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.

To avoid further noise on this ticket, i've done as requested and posted to gnupg-devel : https://lists.gnupg.org/pipermail/gnupg-devel/2025-May/035875.html

May 6 2025, 10:26 PM · Not A Bug, gnupg

May 2 2025

dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.

A bit more experimentation shows the same behavior, even if Alice's tsig of Bill is full, not marginal, and even if all signatures are made in the same second, which is the finest resolution that OpenPGP objects can report.

May 2 2025, 12:48 AM · Not A Bug, gnupg
dkg added a comment to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.

Interesting analysis, thanks for the sleuthing! I'm not sure i understand why "the latest" should be preferred. For example, in the graph made in this example, which part of the graph is the "latest"? Since the path from Alice to Carol is two hops long at least, it's conceivable that one path (A→Bob→C) has both "the latest" tsig *and* "the earliest" tsig, if the other path (A→Bill→C) happens to have been made between the other two tsigs.

May 2 2025, 12:15 AM · Not A Bug, gnupg

Apr 21 2025

dkg created T7622: `gpg --encrypt --default-recipient-self` emits wrong message about "signing".
Apr 21 2025, 6:20 PM · gnupg, Bug Report

Apr 17 2025

dkg added a project to T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate: gnupg.
Apr 17 2025, 7:24 PM · Not A Bug, gnupg
dkg updated the task description for T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
Apr 17 2025, 3:16 PM · Not A Bug, gnupg
dkg updated the task description for T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
Apr 17 2025, 3:15 PM · Not A Bug, gnupg
dkg created T7611: WoT: adding a marginal trustsig reduces the validity of a downstream certificate.
Apr 17 2025, 12:26 AM · Not A Bug, gnupg