Page MenuHome GnuPG
Feed Advanced Search

Fri, Feb 6

ebo triaged T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038 as High priority.
Fri, Feb 6, 10:10 AM · S/MIME, Bug Report, vsd34, kleopatra

Thu, Feb 5

ikloecker claimed T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 3:26 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker updated subscribers of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

@werner: Shall we backport the fix to the gpgme-1.24-branch or do we just add a patch to gpg4win's gpg4win-4-branch and/or vsd-3.3-branch?

Thu, Feb 5, 3:24 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

I have verified (by locally applying the change to a Gpg4win 4 build) that ifdef'ing-out the above hack for Windows builds fixes the display issue.

Thu, Feb 5, 3:20 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

The capping of the date seems to be caused by this workaround/hack in gpgme's _gpgme_parse_timestamp

/* Fixme: We would better use a configure test to see whether
   mktime can handle dates beyond 2038. */
if (sizeof (time_t) <= 4 && year >= 2038)
  return (time_t)2145914603; /* 2037-12-31 23:23:23 */
Thu, Feb 5, 2:27 PM · S/MIME, Bug Report, vsd34, kleopatra
mmontkowski closed T7836: GpgOL: Both disable and prefer S/MIME does not work as Invalid.

The problem resulted from a split up key (one for encryption and one for signing) Resulting in no SMIME encryption key found for one recipient and thus falling back to OpenPGP.

Thu, Feb 5, 2:24 PM · S/MIME, gpgol
timegrid created T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 1:52 PM · S/MIME, Bug Report, vsd34, kleopatra

Wed, Feb 4

ebo renamed T6152: Allow giving context to gpg-agent from Text for Import of S/MIME certificates to Allow giving context to gpg-agent.
Wed, Feb 4, 11:56 AM · gnupg26, Feature Request, S/MIME
ebo edited projects for T6152: Allow giving context to gpg-agent, added: gnupg26; removed gnupg, Restricted Project.
Wed, Feb 4, 11:53 AM · gnupg26, Feature Request, S/MIME

Tue, Feb 3

timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

The display in Okular is independent from Kleopatra, so dropping it in Kleopatra should be fine.
If a QES certificate is available, Okular should highlight and add a filter for them (which is currently not working, see T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures)

Tue, Feb 3, 1:34 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

I currently have a slight preference to drop bold and go with normal font. Werner would be ok with that, too.

Tue, Feb 3, 1:17 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid assigned T7836: GpgOL: Both disable and prefer S/MIME does not work to mmontkowski.

a) Here's a log anyway (ignore it, if decryption does always work):

Tue, Feb 3, 12:31 PM · S/MIME, gpgol
timegrid updated subscribers of T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

@svuorela said, QES certs shouldn't be required to be on a smartcard.

Tue, Feb 3, 12:20 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Using an icon for QES certificates isn't that easy because we use an icon for smartcard certificates and any list item can have at most one icon. Moreover, QES certificates are very like stored on a smartcard (isn't that even a requirement?), i.e. an icon clash is basically guaranteed.

Tue, Feb 3, 11:49 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

In T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures I had the impression, that some hint is useful for signing operations. Probably not so much in general.

Tue, Feb 3, 11:04 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Highlighting QES is mostly useful for Okular, I guess.
Maybe use a symbol with a pen? That should be self-explanatory.

Tue, Feb 3, 10:44 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo triaged T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys as Normal priority.
Tue, Feb 3, 10:40 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid added a project to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys: needs discussion.
Tue, Feb 3, 10:30 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra

Mon, Feb 2

ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

This overloading of "bold" for "my certificates", "qualified certificates" and "trusted root certificates" seems to exist since two decades. I stopped digging into ancient history at the commit that added the hard-coded default filters.

Mon, Feb 2, 5:40 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
werner added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Take care: Too many attributes (color, font) are bad style.

Mon, Feb 2, 5:08 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo updated the task description for T7836: GpgOL: Both disable and prefer S/MIME does not work.
Mon, Feb 2, 5:07 PM · S/MIME, gpgol
ebo added a comment to T7836: GpgOL: Both disable and prefer S/MIME does not work.

a) "Prefer S/MIME" only applies to encryption, not decryption. If you do not want to decrypt with GpgOL you have to disable S/MIME in GpgOL.

Mon, Feb 2, 4:47 PM · S/MIME, gpgol
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Well, the qual flag should only be set for CAs dedicated to certifying QES certificates. And those should by definition be signature certificates only, afaik.

Mon, Feb 2, 3:32 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid created T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.
Mon, Feb 2, 2:48 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra

Fri, Jan 30

timegrid closed T8053: GpgSM: `log-file` is ignored as Invalid.

Ah, thanks for the pointer, I did not expect gpgsm to behave differently here. Then it's probably intentional and I'll close this as invalid.

Fri, Jan 30, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26
pl13 added a comment to T8053: GpgSM: `log-file` is ignored.

The gnupg manual (page 113) mentions:

Fri, Jan 30, 10:30 AM · gpd5x, Bug Report, S/MIME, gnupg26

Thu, Jan 29

timegrid added a comment to T6152: Allow giving context to gpg-agent.

Current state in gpg4win-5.0.0:

Thu, Jan 29, 4:09 PM · gnupg26, Feature Request, S/MIME
ebo lowered the priority of T6516: Kleopatra: Indicate CRL check failure when validating certificates from Normal to Low.
Thu, Jan 29, 3:45 PM · gpd5x, S/MIME, kleopatra

Mon, Jan 26

timegrid added a comment to T8053: GpgSM: `log-file` is ignored.

There's no other configuration, this happens with a clean gnupghome with one smime cert + root cert and the above gpgsm.conf (output on stdin/stderr):

Mon, Jan 26, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26

Fri, Jan 23

werner added a comment to T8053: GpgSM: `log-file` is ignored.

Please run with --debug 0 which should show you which confiration files are read in which order. Is there anything in a common.conf file? A log-file statement tehre would overwrite the command line option.

Fri, Jan 23, 9:16 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid created T8053: GpgSM: `log-file` is ignored.
Fri, Jan 23, 2:28 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid changed the edit policy for T6677: GPGSM: Add support for cert extension 2.5.29.36 Policy Constraints.
Fri, Jan 23, 11:19 AM · Feature Request, gnupg26, S/MIME

Wed, Jan 21

ebo raised the priority of T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys from Normal to High.

setting to High as we need this for T7790

Wed, Jan 21, 11:40 AM · Feature Request, S/MIME, OpenPGP, gnupg26
werner closed T8032: libksba: Input validation for DER encoded INTEGER as Wontfix.
Wed, Jan 21, 10:39 AM · S/MIME, libksba, Bug Report
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

The "ca" root cert is not on the ldap, if that matters

Wed, Jan 21, 10:23 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from GnuPG: S/MIME certificate is imported on ldap search to Keyboxd: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:14 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

some other certificates, but I guess those are from other tests

Wed, Jan 21, 10:08 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a project to T8048: Keyboxd: S/MIME certificate is imported on ldap search: Bug Report.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from Kleopatra: S/MIME certificate is imported on ldap search to GnuPG: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

It also happens on CLI:

Wed, Jan 21, 9:59 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

With Gpg4win 5.0.0 the LISTKEYS after the server lookup lists the (ephemeral?) ca@gnupg.test certificate and (!) the bob@gnupg.test certificate (and some other certificates, but I guess those are from other tests).

Wed, Jan 21, 9:52 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. VSD 3.3.4
Wed, Jan 21, 9:45 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. Gpg4win 5.0.0
Wed, Jan 21, 9:44 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x

Tue, Jan 20

timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  • gpg4win 5.0.0 @ win11
Tue, Jan 20, 2:59 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

gpgme logs (also of vsd-3.3.4) will be useful.

Tue, Jan 20, 2:47 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
werner added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

I have not checked but I guess that the certificate is marked as ephemeal and kleopatra either lists ephemeral certificates or the ephemeral flag got removed to to a validation process,

Tue, Jan 20, 2:43 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

Note: This does not happen on vsd-3.3.4

Tue, Jan 20, 2:37 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid created T8048: Keyboxd: S/MIME certificate is imported on ldap search.
Tue, Jan 20, 1:56 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x

Fri, Jan 16

werner triaged T8032: libksba: Input validation for DER encoded INTEGER as Low priority.

See the gnupg-devel mailing list for more discussions. Subject: libgcrypt P256 signature malleability via weak DER enforcement"

Fri, Jan 16, 11:01 AM · S/MIME, libksba, Bug Report

Wed, Jan 14

werner added a comment to T8032: libksba: Input validation for DER encoded INTEGER.

Two historic integer encoding glitches from Peter Gutmann's style guide:

Wed, Jan 14, 10:08 AM · S/MIME, libksba, Bug Report
gniibe added a project to T8032: libksba: Input validation for DER encoded INTEGER: S/MIME.
Wed, Jan 14, 3:03 AM · S/MIME, libksba, Bug Report

Fri, Jan 9

ebo closed T7914: Card s/n number missing in gpgsm as Resolved.

in Gpg4win-5.0.0-beta479

Fri, Jan 9, 12:08 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
werner moved T7914: Card s/n number missing in gpgsm from WiP to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:17 AM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26

Jan 7 2026

werner triaged T8017: Okular: Hang on signature with smime cert and distrusted root as High priority.
Jan 7 2026, 12:06 PM · Bug Report, S/MIME, gpd5x, okular
werner added a parent task for T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys: T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Jan 7 2026, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
werner triaged T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys as Normal priority.

Traditionally we have considered expired and revoked more or less similar. The idea is that an expired key might have been compromised but the owner did not found a way to revoke it. We may want to change this policy because some users don't care too much about expired keys (cf. T7990) .

Jan 7 2026, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.
>gpgsm -v --sign --local-user "Edward Tester" test.pdf > test.gpg.p7s
gpgsm: enabled compatibility flags:
gpgsm: looking up issuer from the Dirmngr cache
gpgsm: number of matching certificates: 0
gpgsm: dirmngr cache-only key lookup failed: No data
gpgsm: issuer certificate {04A0A7E932B29D43A9B6673139AF52C0A5FC467BF5A64D044D1AC33613ABBB73CA532569F5779999114C0118CD66FDF6E92B1B0EEE2A4D5A815DA7FD892DDDE9C1} not found using authorityKeyIdentifier
gpgsm: looking up issuer from the Dirmngr cache
gpgsm: number of matching certificates: 0
gpgsm: dirmngr cache-only key lookup failed: No data
gpgsm: certificate is good
gpgsm: root certificate is not marked trusted
gpgsm: fingerprint=D4:EC:A6:B4:69:AB:B5:44:08:27:CB:3F:C7:D7:91:08:3C:10:27:DB
gpgsm: DBG: BEGIN Certificate 'issuer':
gpgsm: DBG:      serial: 01
gpgsm: DBG:   notBefore: 2020-03-26 19:41:01
gpgsm: DBG:    notAfter: 2063-04-05 17:00:00
gpgsm: DBG:      issuer: CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE
gpgsm: DBG:     subject: CN=Root-CA 2020,OU=GnuPG.com,O=g10 Code GmbH,C=DE
gpgsm: DBG:   hash algo: 1.2.840.113549.1.1.11
gpgsm: DBG:   SHA1 Fingerprint: D4:EC:A6:B4:69:AB:B5:44:08:27:CB:3F:C7:D7:91:08:3C:10:27:DB
gpgsm: DBG: END Certificate
gpgsm: after checking the fingerprint, you may want to add it manually to the list of trusted certificates.
gpgsm: validation model used: shell
gpgsm: can't sign using 'Edward Tester': Not trusted
[GNUPG:] FAILURE gpgsm-exit 50331649
Jan 7 2026, 9:33 AM · Bug Report, S/MIME, gpd5x, okular
svuorela added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

How does gpgsm react if you try to sign with the certificate?

Jan 7 2026, 9:09 AM · Bug Report, S/MIME, gpd5x, okular

Jan 6 2026

timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

Maybe it would be better to just not offer S/MIME certs with distrusted root cert?

Jan 6 2026, 2:42 PM · Bug Report, S/MIME, gpd5x, okular
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

If all processes are killed before okular is opened, i get an error on "finish signing":


Jan 6 2026, 2:15 PM · Bug Report, S/MIME, gpd5x, okular
timegrid added a comment to T8017: Okular: Hang on signature with smime cert and distrusted root.

gpgsm.log (debug-all, whole process of signing)

Jan 6 2026, 2:11 PM · Bug Report, S/MIME, gpd5x, okular
timegrid created T8017: Okular: Hang on signature with smime cert and distrusted root.
Jan 6 2026, 2:03 PM · Bug Report, S/MIME, gpd5x, okular

Dec 12 2025

ebo edited projects for T7015: gpgsm: Add status messages reporting imported certificates on --learn-card, added: gnupg26; removed gnupg, Restricted Project.
Dec 12 2025, 3:41 PM · gnupg26, S/MIME
timegrid edited projects for T7101: Automagically create a PGP key from a X.509 cert, added: gnupg26; removed Restricted Project, gnupg.
Dec 12 2025, 2:56 PM · gnupg26, Feature Request, S/MIME, OpenPGP

Nov 19 2025

werner moved T7914: Card s/n number missing in gpgsm from WIP to QA on the gnupg26 board.
Nov 19 2025, 5:42 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26

Nov 16 2025

werner moved T7914: Card s/n number missing in gpgsm from Backlog to WiP on the gnupg22 board.
Nov 16 2025, 7:12 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
werner edited projects for T7914: Card s/n number missing in gpgsm, added: gnupg22; removed gnupg.
Nov 16 2025, 7:12 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
werner changed the status of T7914: Card s/n number missing in gpgsm from Open to Testing.

Fix applied. Thanks.

Nov 16 2025, 7:10 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26

Nov 14 2025

werner triaged T7914: Card s/n number missing in gpgsm as Normal priority.
Nov 14 2025, 12:42 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26

Nov 6 2025

ebo edited projects for T6859: S/MIME keys are not deleted, added: gpd5x; removed Restricted Project.
Nov 6 2025, 11:51 AM · gpd5x, S/MIME, kleopatra, gnupg
timegrid updated the task description for T7836: GpgOL: Both disable and prefer S/MIME does not work.
Nov 6 2025, 9:11 AM · S/MIME, gpgol
timegrid renamed T7836: GpgOL: Both disable and prefer S/MIME does not work from GpgOL: Activate "Prefer S/MIME" does not work to GpgOL: Both disable and prefer S/MIME does not work.
Nov 6 2025, 8:57 AM · S/MIME, gpgol

Oct 9 2025

ebo added a comment to T7836: GpgOL: Both disable and prefer S/MIME does not work.

Might this be related to T4953?

Oct 9 2025, 5:02 PM · S/MIME, gpgol
ebo moved T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook from Backlog to Done on the gpgol board.
Oct 9 2025, 10:56 AM · S/MIME, vsd34, vsd, gpgol
mmontkowski triaged T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook as Normal priority.
Oct 9 2025, 10:15 AM · S/MIME, vsd34, vsd, gpgol
mmontkowski changed the status of T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook from Open to Testing.
Oct 9 2025, 10:14 AM · S/MIME, vsd34, vsd, gpgol
ebo moved T7836: GpgOL: Both disable and prefer S/MIME does not work from Backlog to Triage on the gpgol board.
Oct 9 2025, 9:37 AM · S/MIME, gpgol
ebo renamed T7836: GpgOL: Both disable and prefer S/MIME does not work from GpgOL: Activate/Prefer S/MIME does not work to GpgOL: Activate "Prefer S/MIME" does not work.
Oct 9 2025, 9:36 AM · S/MIME, gpgol
ebo triaged T7841: GpgOL: Concurrent access to S/MIME encrypted mail creates versions as Low priority.
Oct 9 2025, 9:25 AM · S/MIME, vsd34, vsd, gpgol

Oct 6 2025

werner reopened T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook as "Open".

(auto resolved due to the keyword "resolved" in the commit message)

Oct 6 2025, 3:36 PM · S/MIME, vsd34, vsd, gpgol
mmontkowski closed T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook as Resolved.

The window was not reenabled on failure see 8d174d5

Oct 6 2025, 2:06 PM · S/MIME, vsd34, vsd, gpgol

Oct 2 2025

timegrid created T7841: GpgOL: Concurrent access to S/MIME encrypted mail creates versions.
Oct 2 2025, 3:13 PM · S/MIME, vsd34, vsd, gpgol
timegrid added a comment to T7836: GpgOL: Both disable and prefer S/MIME does not work.

(removed: wrong statement)

Oct 2 2025, 2:09 PM · S/MIME, gpgol
timegrid added a project to T7836: GpgOL: Both disable and prefer S/MIME does not work: S/MIME.
Oct 2 2025, 1:14 PM · S/MIME, gpgol
timegrid added a comment to T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook.

Note: I also activated Sign/Encrypt by default, if that matters

Oct 2 2025, 1:14 PM · S/MIME, vsd34, vsd, gpgol
timegrid created T7837: GpgOL: Saving S/MIME encrypted draft with S/MIME disabled freezes Outlook.
Oct 2 2025, 1:12 PM · S/MIME, vsd34, vsd, gpgol

Sep 24 2025

werner triaged T7819: Export of secret S/MIME key with brainpool fails (error converting key parameters) as Wishlist priority.

ECC support for X.509 and in particular pkcs#12 format is limited. That is in general not a problem because such certificates are stored on a token and not on disk.

Sep 24 2025, 6:21 PM · vsd, S/MIME, gnupg22
timegrid created T7819: Export of secret S/MIME key with brainpool fails (error converting key parameters).
Sep 24 2025, 1:17 PM · vsd, S/MIME, gnupg22

Aug 27 2025

werner lowered the priority of T7618: gpgsm: Allow selecting keys by SHA2 fpr from Normal to Wishlist.

The problem here is that we don't have the sha-2 fingerprint in our SQL tables. Thus we would not only need to do a full table search but also parse the actual blob to compute the sha-2 fingerprint.

Aug 27 2025, 4:14 PM · S/MIME, gnupg26, Feature Request
werner lowered the priority of T6678: GPGSM: Add support for cert extension 2.5.29.54 Inhibit anyPolicy from Normal to Wishlist.
Aug 27 2025, 4:04 PM · gnupg26, S/MIME, Restricted Project
werner closed T7713: Allow to skip the qualified signature confirmation prompt as Resolved.

I have done testing using my QES certificate with all combinations of the two options.

Aug 27 2025, 12:02 PM · S/MIME, Feature Request, gnupg26

Jul 25 2025

werner closed T7738: The trustlist's qual flag is not cached correctly by gpgsm as Resolved.

Fixed for gnupg22 and gnupg26

Jul 25 2025, 5:29 PM · S/MIME, gnupg

Jul 24 2025

werner added a comment to T7738: The trustlist's qual flag is not cached correctly by gpgsm.

This does not happen with gnupg24 because the cache has not been implemented there.

Jul 24 2025, 12:33 PM · S/MIME, gnupg
werner triaged T7738: The trustlist's qual flag is not cached correctly by gpgsm as Normal priority.
Jul 24 2025, 12:22 PM · S/MIME, gnupg

Jul 2 2025

werner triaged T7713: Allow to skip the qualified signature confirmation prompt as Normal priority.
Jul 2 2025, 11:41 AM · S/MIME, Feature Request, gnupg26