Page MenuHome GnuPG
Feed Advanced Search

Wed, Jan 21

ikloecker committed rKLEOPATRA81022af6abc3: Use de-vs filters for styling bad keys if GnuPG is de-vs compliant (authored by ikloecker).
Use de-vs filters for styling bad keys if GnuPG is de-vs compliant
Wed, Jan 21, 11:02 AM
ikloecker committed rKLEOPATRA5117366cc0d3: Add Status column to server lookup result table (authored by ikloecker).
Add Status column to server lookup result table
Wed, Jan 21, 11:02 AM
ikloecker committed rKLEOPATRA1fd58988dcec: Cope with missing key filters (authored by ikloecker).
Cope with missing key filters
Wed, Jan 21, 10:55 AM
ikloecker committed rLIBKLEObb53e1f8a820: Add IDs to some key filters (authored by ikloecker).
Add IDs to some key filters
Wed, Jan 21, 10:39 AM
ikloecker committed rKLEOPATRA9b7fae53a02d: Use de-vs filters for styling bad keys if GnuPG is de-vs compliant (authored by ikloecker).
Use de-vs filters for styling bad keys if GnuPG is de-vs compliant
Wed, Jan 21, 10:32 AM
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

With Gpg4win 5.0.0 the LISTKEYS after the server lookup lists the (ephemeral?) ca@gnupg.test certificate and (!) the bob@gnupg.test certificate (and some other certificates, but I guess those are from other tests).

Wed, Jan 21, 9:52 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. VSD 3.3.4
Wed, Jan 21, 9:45 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. Gpg4win 5.0.0
Wed, Jan 21, 9:44 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x

Tue, Jan 20

ikloecker committed rKLEOPATRAbc537d79f98f: Add Status column to server lookup result table (authored by ikloecker).
Add Status column to server lookup result table
Tue, Jan 20, 5:01 PM
ikloecker committed rLIBKLEOb7e0a41f9355: Add IDs to some key filters (authored by ikloecker).
Add IDs to some key filters
Tue, Jan 20, 4:39 PM
ikloecker claimed T8042: Kleopatra: Add expired/revoked information to ldap search results.
Tue, Jan 20, 2:49 PM · vsd34, Feature Request, gpd5x, LDAP, kleopatra
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

gpgme logs (also of vsd-3.3.4) will be useful.

Tue, Jan 20, 2:47 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker committed rKLEOPATRA6cea47c29afc: Ensure that disabled error labels are painted with disabled colors (authored by ikloecker).
Ensure that disabled error labels are painted with disabled colors
Tue, Jan 20, 2:40 PM
ikloecker committed rLIBKLEO58b03e14cdab: Ensure that disabled error labels are painted with disabled colors (authored by ikloecker).
Ensure that disabled error labels are painted with disabled colors
Tue, Jan 20, 2:39 PM
ikloecker changed the status of T7789: Kleopatra: Wrong error message when choosing an expired certificate for encryption from Open to Testing.

Fixed and backported for VSD 3.4

Tue, Jan 20, 2:19 PM · vsd34, Bug Report, gpd5x, kleopatra
ikloecker committed rKLEOPATRA69b198a058e6: Show just one error message for keys that are unusable for encryption (authored by ikloecker).
Show just one error message for keys that are unusable for encryption
Tue, Jan 20, 2:18 PM
ikloecker committed rKLEOPATRAd4e29e03af64: Show just one error message for keys that are unusable for encryption (authored by ikloecker).
Show just one error message for keys that are unusable for encryption
Tue, Jan 20, 2:16 PM
ikloecker committed rKLEOPATRA0f635a245542: Do not show (duplicate) hint for expired or revoked user IDs/keys (authored by ikloecker).
Do not show (duplicate) hint for expired or revoked user IDs/keys
Tue, Jan 20, 11:28 AM
ikloecker committed rKLEOPATRA88c9adb225f4: Handle disabled keys and otherwise unusable user IDs/keys (authored by ikloecker).
Handle disabled keys and otherwise unusable user IDs/keys
Tue, Jan 20, 11:28 AM
ikloecker committed rKLEOPATRA770a385c2ad1: Keep explicitly selected expired or revoked user ID (authored by ikloecker).
Keep explicitly selected expired or revoked user ID
Tue, Jan 20, 11:28 AM
ikloecker committed rKLEOPATRA63169fd19a7d: Don't crash with failed assert if expired or revoked user ID is selected (authored by ikloecker).
Don't crash with failed assert if expired or revoked user ID is selected
Tue, Jan 20, 11:28 AM
ikloecker committed rKLEOPATRA4e35a07e6c7c: Handle disabled keys and otherwise unusable user IDs/keys (authored by ikloecker).
Handle disabled keys and otherwise unusable user IDs/keys
Tue, Jan 20, 11:13 AM
ikloecker committed rKLEOPATRAf7256f877073: Do not show (duplicate) hint for expired or revoked user IDs/keys (authored by ikloecker).
Do not show (duplicate) hint for expired or revoked user IDs/keys
Tue, Jan 20, 11:13 AM
ikloecker committed rKLEOPATRA3f8735a0bb59: Keep explicitly selected expired or revoked user ID (authored by ikloecker).
Keep explicitly selected expired or revoked user ID
Tue, Jan 20, 11:13 AM

Mon, Jan 19

ikloecker added a comment to T8042: Kleopatra: Add expired/revoked information to ldap search results.

The gpgme logs show that the information for revoked keys should be there. We just need to check for it (and somehow visualize it).

pub:o:3072:1:3DA05D6B0A5998AF:1768822823:1863514800::::::::
fpr:::::::::C70F6D8F32DFE96F5C47C40B3DA05D6B0A5998AF:
uid:o::::::::search (valid) <search@gnupg.test>\r:
Mon, Jan 19, 4:13 PM · vsd34, Feature Request, gpd5x, LDAP, kleopatra
ikloecker renamed T8042: Kleopatra: Add expired/revoked information to ldap search results from Kleopatra: Add expired/rekoved information to ldap search results to Kleopatra: Add expired/revoked information to ldap search results.
Mon, Jan 19, 3:55 PM · vsd34, Feature Request, gpd5x, LDAP, kleopatra
ikloecker claimed T7789: Kleopatra: Wrong error message when choosing an expired certificate for encryption.
Mon, Jan 19, 3:54 PM · vsd34, Bug Report, gpd5x, kleopatra
ikloecker committed rW26fc779069cb: nsis: Read installed components from 64-bit registry (authored by ikloecker).
nsis: Read installed components from 64-bit registry
Mon, Jan 19, 3:09 PM
ikloecker committed rW6e28c6c996b6: nsis: Set correct registry view after (un)installing browser integration (authored by ikloecker).
nsis: Set correct registry view after (un)installing browser integration
Mon, Jan 19, 3:09 PM
ikloecker changed the status of T8039: NSIS: Preselection of installed components on reinstall only works with browser integration installed from Open to Testing.

Fixed. The problem was that the selected sections were stored in the 64-bit registry (unless browser integration was installed; see T8038), but they were read from the 32-bit registry.

Mon, Jan 19, 3:05 PM · Bug Report, gpd5x, Installer
ikloecker changed the status of T8038: NSIS: Updating line omitted if browser integration is installed from Open to Testing.

Fixed.

Mon, Jan 19, 3:03 PM · Bug Report, gpd5x, Installer
ikloecker triaged T8038: NSIS: Updating line omitted if browser integration is installed as Normal priority.

Let's give this Normal priority.

Mon, Jan 19, 2:23 PM · Bug Report, gpd5x, Installer
ikloecker claimed T8038: NSIS: Updating line omitted if browser integration is installed.
Mon, Jan 19, 2:21 PM · Bug Report, gpd5x, Installer

Jan 19 2026

ikloecker added a comment to T8038: NSIS: Updating line omitted if browser integration is installed.

Meh! The installation of the browser integration explicitly enables the 32-bit registry. Obviously a leftover from gpg4win 4.

Jan 19 2026, 2:04 PM · Bug Report, gpd5x, Installer
ikloecker added a comment to T8038: NSIS: Updating line omitted if browser integration is installed.

Thanks for checking! So now we know why the line is missing. Looks like installing browser integration causes a broken installation (at least with respect to registry keys).

Jan 19 2026, 2:00 PM · Bug Report, gpd5x, Installer
ikloecker changed the status of T8015: Kleopatra: Status in certificate list not updated after import from Open to Testing.

Fixed.

Jan 19 2026, 1:35 PM · kleopatra, gpd5x
ikloecker committed rLIBKLEO0422e80dc069: Check if new files occurred while the watcher was disabled (authored by ikloecker).
Check if new files occurred while the watcher was disabled
Jan 19 2026, 12:08 PM
ikloecker added a comment to T8038: NSIS: Updating line omitted if browser integration is installed.

Regarding 32-bit and 64-bit installers: The installer looks in both registry trees for the relevant registry keys, i.e. 64-bit over 32-bit and vice versa should properly uninstall the existing installation.

Jan 19 2026, 10:59 AM · Bug Report, gpd5x, Installer
ikloecker added a comment to T8039: NSIS: Preselection of installed components on reinstall only works with browser integration installed.

I understood that this is done on purpose, i.e. all other components are explicitly always preselected.

Jan 19 2026, 9:29 AM · Bug Report, gpd5x, Installer
ikloecker added a comment to T8038: NSIS: Updating line omitted if browser integration is installed.

gpg4win-5 has no idea that gpg4win-4 is installed because the former is a 64-bit installer/application and the latter a 32-bit installer/application, i.e. they use different registry trees. More important that the missing "Updating line" is very likely that the gpg4win-5 installer does not uninstall gpg4win-4. I haven't checked if NSIS is capable of detecting/uninstalling a 32-bit application from a 64-bit installer.

Jan 19 2026, 9:27 AM · Bug Report, gpd5x, Installer
ikloecker claimed T8015: Kleopatra: Status in certificate list not updated after import.
Jan 19 2026, 9:21 AM · kleopatra, gpd5x

Jan 15 2026

ikloecker committed rLIBKLEO5068e461be73: Adapt test to new signature verification texts (authored by ikloecker).
Adapt test to new signature verification texts
Jan 15 2026, 5:02 PM
ikloecker placed T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification up for grabs.

I don't know how I'm supposed to change/fix this. Not even gpg does what the ticket wants (see the sub ticket). And gpg doesn't report sufficient information to Kleopatra via gpgme. In fact, gpg doesn't emit a STATUS_TRUST_* message if the signing key is expired. Hence, gpgme reports "unknown" validity for the signing key, so that Kleopatra would always print "The used key is not certified by you or any trusted person." for expired keys even if the key was fully certified before it expired.

Jan 15 2026, 4:53 PM · gpd5x, kleopatra
ikloecker changed the status of T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked from Open to Testing.

Fixed. Some examples for the improved texts which are based on the texts that gpg prints.

  • good signature with expired key

  • good signature with revoked key

  • good signature with uncertified key

  • expired signature with certified key

  • expired signature with uncertified key

Jan 15 2026, 4:45 PM · Bug Report, gpd5x, kleopatra
ikloecker committed rLIBKLEO9b09f94aed6e: Fix and improve handling of good but not fully valid signatures (authored by ikloecker).
Fix and improve handling of good but not fully valid signatures
Jan 15 2026, 4:26 PM
ikloecker committed rLIBKLEOb2e9c2f05c04: Remove superfluous local variables (authored by ikloecker).
Remove superfluous local variables
Jan 15 2026, 4:26 PM
ikloecker triaged T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked as Normal priority.
Jan 15 2026, 2:12 PM · Bug Report, gpd5x, kleopatra
ikloecker added a comment to T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.

Screenshots how Kleopatra currently shows the result of the verifications:




Jan 15 2026, 11:26 AM · gpd5x, kleopatra
ikloecker renamed T8029: IPC error on batch import of secret kyber cert from Kleopatra: IPC error on import of secret kyber cert to IPC error on batch import of secret kyber cert.
Jan 15 2026, 10:38 AM · gnupg26, Bug Report, gpd5x, kleopatra
ikloecker changed the status of T6623: Kleopatra hangs "Loading certificate cache" on Windows 10 from Open to Testing.

I think this has been resolved in Gpg4win 5.

Jan 15 2026, 10:33 AM · gpd5x (gpd-5.0.0), kleopatra
ikloecker changed the status of T4581: Kleopatra stuck in loading the certificate cache from Open to Testing.

I think this has been resolved in Gpg4win 5.

Jan 15 2026, 10:33 AM · gpd5x (gpd-5.0.0), gpg4win, kleopatra, Bug Report
ikloecker added a project to T4581: Kleopatra stuck in loading the certificate cache: gpd5x.
Jan 15 2026, 10:32 AM · gpd5x (gpd-5.0.0), gpg4win, kleopatra, Bug Report
ikloecker moved T7434: Kleopatra: Initial keylisting hangs for ~60 seconds (gpg-agent: Socket ...S.gpg-agent cannot be bound) from Backlog to QA on the gpd5x board.
Jan 15 2026, 10:31 AM · gpd5x (gpd-5.0.0), gnupg, kleopatra
ikloecker changed the status of T7434: Kleopatra: Initial keylisting hangs for ~60 seconds (gpg-agent: Socket ...S.gpg-agent cannot be bound) from Open to Testing.

I think this has been resolved in Gpg4win 5.

Jan 15 2026, 10:31 AM · gpd5x (gpd-5.0.0), gnupg, kleopatra

Jan 14 2026

ikloecker committed rGPGMEQT86566cac0bb3: Allow specifying an export filter when exporting keys (authored by ikloecker).
Allow specifying an export filter when exporting keys
Jan 14 2026, 6:24 PM
ikloecker committed rGPGMEQTbb62785286d9: Move definition of ExportJob methods (authored by ikloecker).
Move definition of ExportJob methods
Jan 14 2026, 6:24 PM
ikloecker changed the status of T8030: Kleopatra: Add hint to filename of secret team key exports with signing key from Open to Testing.

The suffixes _ENCRYPT_SIGN and _ENCRYPT are used to differentiate the two export results.

Jan 14 2026, 4:44 PM · gpd5x, Feature Request, kleopatra
ikloecker changed the status of T8027: Kleopatra: a secret team key should always include all public key information from Open to Testing.

If only the secret encryption subkey is exported and there is a signing subkey then, additionally, to the secret subkey export a public export is added to the created file, i.e. in the created file there's a PUBLIC KEY BLOCK and a PRIVATE KEY BLOCK. (With the next version of gpgme the public key block only contains the primary key and the signing subkey. Currently, it's a full public key export of the team key.)

Jan 14 2026, 4:42 PM · Bug Report, gpd5x, kleopatra
ikloecker moved T8033: gpgme: Support --export-filter from Backlog to QA for next release on the gpgme board.
Jan 14 2026, 4:34 PM · gpgmeqt, gpgmepp, gpgme, Feature Request, gpd5x
ikloecker closed T8033: gpgme: Support --export-filter, a subtask of T8027: Kleopatra: a secret team key should always include all public key information, as Resolved.
Jan 14 2026, 4:34 PM · Bug Report, gpd5x, kleopatra
ikloecker closed T8033: gpgme: Support --export-filter as Resolved.
Jan 14 2026, 4:34 PM · gpgmeqt, gpgmepp, gpgme, Feature Request, gpd5x
ikloecker committed rKLEOPATRA8af7779feda4: Append usage hint to filename of exported secret team key (authored by ikloecker).
Append usage hint to filename of exported secret team key
Jan 14 2026, 4:32 PM
ikloecker committed rKLEOPATRA104c91a18df0: Add public signing key to secret team key export (authored by ikloecker).
Add public signing key to secret team key export
Jan 14 2026, 4:32 PM
ikloecker committed rM1823e06216f2: Allow setting export filters when exporting keys (authored by ikloecker).
Allow setting export filters when exporting keys
Jan 14 2026, 4:21 PM
ikloecker claimed T8030: Kleopatra: Add hint to filename of secret team key exports with signing key.
Jan 14 2026, 4:19 PM · gpd5x, Feature Request, kleopatra
ikloecker added a comment to T7455: Improved Sign/Encrypt/Decrypt/Verify from clipboard.

Notes:

  • The "Encrypt..." and "Sign..." operations might not be needed anymore now, that "Sign/Encrypt ..." is available?
Jan 14 2026, 2:09 PM · gpd5x, kleopatra
ikloecker triaged T8033: gpgme: Support --export-filter as Normal priority.
Jan 14 2026, 11:31 AM · gpgmeqt, gpgmepp, gpgme, Feature Request, gpd5x
ikloecker committed rKLEOPATRA96942013d79e: Require GpgME 2.0 (authored by ikloecker).
Require GpgME 2.0
Jan 14 2026, 9:51 AM
ikloecker committed rLIBKLEOd07ebf15f5fa: Require GpgME 2.0 (authored by ikloecker).
Require GpgME 2.0
Jan 14 2026, 9:38 AM

Jan 13 2026

ikloecker added a comment to T5707: Kleopatra: Use windows registry additionally to config files.

I've changed this now to "GnuPG VS-Desktop" (and "GnuPG Desktop").

Jan 13 2026, 8:05 PM · gpd5x, gpg4win, kleopatra
ikloecker committed rWb9371cfdac4b: Use the full product name as organization name for Kleopatra (authored by ikloecker).
Use the full product name as organization name for Kleopatra
Jan 13 2026, 8:04 PM
ikloecker claimed T8027: Kleopatra: a secret team key should always include all public key information.
Jan 13 2026, 5:30 PM · Bug Report, gpd5x, kleopatra
ikloecker changed the status of T5707: Kleopatra: Use windows registry additionally to config files from Open to Testing.
Jan 13 2026, 4:19 PM · gpd5x, gpg4win, kleopatra
ikloecker added a comment to T5707: Kleopatra: Use windows registry additionally to config files.

We set the following organization names for the different products:

  • Gpg4win: Gpg4win
  • GnuPG Desktop: GnuPG Desktop
  • GnuPG VS-Desktop: GnuPG VS-Desktop

i.e. the registry path for Kleopatra settings will be for example
SOFTWARE\Gpg4win\Kleopatra\<config group>\<config entry>

Jan 13 2026, 4:16 PM · gpd5x, gpg4win, kleopatra
ikloecker committed rW28298c30fec4: Configure kleopatra with different organization names (authored by ikloecker).
Configure kleopatra with different organization names
Jan 13 2026, 4:14 PM
ikloecker committed rKLEOPATRA8c1b74961ffa: Set organization name for registry lookup of config entries on Windows (authored by ikloecker).
Set organization name for registry lookup of config entries on Windows
Jan 13 2026, 4:10 PM
ikloecker claimed T5707: Kleopatra: Use windows registry additionally to config files.
Jan 13 2026, 3:13 PM · gpd5x, gpg4win, kleopatra
ikloecker added a project to T8029: IPC error on batch import of secret kyber cert: gnupg26.

@werner: gpg fails to batch import secret Kyber keys:

$ GNUPGHOME=/home/ingo/dev/g10/.gnupghomes/empty gpg --batch --import --verbose ~/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc 
gpg: WARNING: unsafe permissions on homedir '/home/ingo/dev/g10/.gnupghomes/empty'
gpg: enabled compatibility flags:
gpg: sec  brainpoolP256r1/DD89C34EF2B69576 2024-11-14  Kyber768 <kyber768@example.net>
gpg: using pgp trust model
gpg: key DD89C34EF2B69576: public key "Kyber768 <kyber768@example.net>" imported
gpg: key DD89C34EF2B69576/DD89C34EF2B69576: secret key imported
gpg: key DD89C34EF2B69576/D07DD3BF9F1AAF4F: error sending to agent: IPC parameter error
gpg: error reading '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc': IPC parameter error
gpg: import from '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc' failed: IPC parameter error
gpg: Total number processed: 0
gpg:               imported: 1
gpg:       secret keys read: 1
Jan 13 2026, 2:27 PM · gnupg26, Bug Report, gpd5x, kleopatra
ikloecker moved T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Backlog to WIP on the vsd34 board.

Backported for VSD 3.4

Jan 13 2026, 12:10 PM · gpd5x, vsd34, kleopatra
ikloecker committed rKLEOPATRAee75434aa1ef: Only show clear-signed text with good signature in notepad (authored by ikloecker).
Only show clear-signed text with good signature in notepad
Jan 13 2026, 12:10 PM
ikloecker committed rLIBKLEO06473117f5b6: Add helper to check if a signature is good (authored by ikloecker).
Add helper to check if a signature is good
Jan 13 2026, 12:09 PM
ikloecker committed rLIBKLEO01b4ee54c0e7: GIT_SILENT Fix/unify indentation (authored by ikloecker).
GIT_SILENT Fix/unify indentation
Jan 13 2026, 12:09 PM
ikloecker changed the status of T8020: Kleopatra: Notepad should not show "signed" text if signature is bad from Open to Testing.

Done. I've used the following script to create clear-signed test messages with good/bad signature signed with certificates with different validity and status (expired, revoked).

Jan 13 2026, 11:54 AM · gpd5x, vsd34, kleopatra
ikloecker committed rKLEOPATRA91e027afaf49: Only show clear-signed text with good signature in notepad (authored by ikloecker).
Only show clear-signed text with good signature in notepad
Jan 13 2026, 11:49 AM
ikloecker committed rLIBKLEO0edc897a66e0: Bump library version (authored by ikloecker).
Bump library version
Jan 13 2026, 11:17 AM
ikloecker committed rLIBKLEO3de2e13e0e96: Add helper to check if a signature is good (authored by ikloecker).
Add helper to check if a signature is good
Jan 13 2026, 11:17 AM
ikloecker closed T6932: Icons, darkmode and stuff, a subtask of T6872: Prepare transition to Qt 6/KF6, as Resolved.
Jan 13 2026, 10:31 AM
ikloecker closed T6932: Icons, darkmode and stuff as Resolved.

All sub tickets are done.

Jan 13 2026, 10:31 AM · gpd5x (gpd-5.0.0), kleopatra
ikloecker changed the status of T7429: Kleopatra: Importing certificate from Verification result dialog doesn't correctly re-verify the signature from Open to Testing.

This is ready for testing and available in 5.0.0-betaX since about a year.

Jan 13 2026, 10:13 AM · gpd5x (gpd-5.0.0), kleopatra, Bug Report
ikloecker changed the status of T7455: Improved Sign/Encrypt/Decrypt/Verify from clipboard from Open to Testing.

Should be ready for testing. This is available in 5.0.0-beta479.

Jan 13 2026, 10:11 AM · gpd5x, kleopatra
ikloecker changed the status of T7107: Kleopatra: Option "PublicKeyEncryptionOnly" from Open to Testing.

This has finally been merged.

Jan 13 2026, 10:08 AM · gpd5x, Feature Request, kleopatra
ikloecker moved T5707: Kleopatra: Use windows registry additionally to config files from Backlog to QA on the gpd5x board.
Jan 13 2026, 10:05 AM · gpd5x, gpg4win, kleopatra
ikloecker moved T7008: Kleopatra: New tabs in certficate list should use same column layout as current tab from Backlog to QA on the gpd5x board.
Jan 13 2026, 10:04 AM · vsd34, gpd5x, kleopatra
ikloecker changed the status of T7008: Kleopatra: New tabs in certficate list should use same column layout as current tab from Open to Testing.

In the meantime we don't show the imported certificates anymore in the main window as tabs but in a separate window, i.e. import tabs are no longer an issue. Please retest.

Jan 13 2026, 10:04 AM · vsd34, gpd5x, kleopatra
ikloecker changed the status of T5707: Kleopatra: Use windows registry additionally to config files from Open to Testing.

I'm pretty sure that this is done. For gpd5 the changes have been merged upstream and kconfig reads the config keys in the desired order.

Jan 13 2026, 9:56 AM · gpd5x, gpg4win, kleopatra
ikloecker placed T7267: Kleoaptra shows unknown validity for fully trusted S/MIME certificate in multipart/signed mail up for grabs.
Jan 13 2026, 9:32 AM · gpd5x, mimetreeparser
ikloecker added a parent task for T7267: Kleoaptra shows unknown validity for fully trusted S/MIME certificate in multipart/signed mail: Unknown Object (Maniphest Task).
Jan 13 2026, 9:31 AM · gpd5x, mimetreeparser

Jan 12 2026

ikloecker removed a project from T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: kleopatra.

I can reproduce this on the command line:

C:\Users\g10code>"c:\Program Files\GnuPG\bin\gpgsm.exe" --export --armor 579BAF3DF16AD462457BCC0897ADBC143D76EA7B 5A2B80F98F518D50891B1F0C7C6131AD107F9938 DB625D2BBBB5A3FD985C0233249B03090E85D402
Issuer ...: /CN=CA IVBB Deutsche Telekom AG 20/OU=Bund/O=PKI-1-Verwaltung/C=DE
Serial ...: 02195D190EBE34
Subject ..: /CN=iOS Test-Smartcard iostest01.sc/OU=BSI/O=Bund/C=DE/SerialNumber=2
    aka ..: iostest01.sc@bsi.bund.de
Keygrip ..: 527CE32FD0552D18479442EF90DD5E434C036329
Jan 12 2026, 3:36 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report
ikloecker added a project to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: gnupg26.

I can reproduce the issue only (!!!) with keyboxd (on Windows).

Jan 12 2026, 3:25 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report
ikloecker claimed T8026: Kleopatra: Export of multiple S/MIME certificates only exports one.
Jan 12 2026, 2:00 PM · gpd5x (gpd-5.0.1), gnupg26, Bug Report