Page MenuHome GnuPG
Feed Advanced Search

Yesterday

ebo created T7103: Confusing error message when changing passphrase/password of subkey.
Thu, Apr 25, 3:58 PM · gnupg24, gnupg22

Tue, Apr 23

werner triaged T7099: Disable the import of certain card objects as Normal priority.
Tue, Apr 23, 2:54 PM · scd, gnupg24, Restricted Project, Feature Request
werner added a project to T1825: Add a re-encrypt to additional key: Restricted Project.
Tue, Apr 23, 2:10 PM · Restricted Project, gnupg24, Feature Request
werner added a comment to T1825: Add a re-encrypt to additional key.

Another important use-case is to provide a way to migrate to a newer smartcard.

Tue, Apr 23, 2:10 PM · Restricted Project, gnupg24, Feature Request

Mon, Apr 22

gniibe closed T5436: gpg-agent 2.3.1: PIN caching not working for decrypt operations as Resolved.

Please continue on T7041. This ticket is going to be closed (as the problem described was fixed already).

Mon, Apr 22, 8:09 AM · gnupg24, yubikey, Bug Report

Tue, Apr 16

mdawar added a comment to T5436: gpg-agent 2.3.1: PIN caching not working for decrypt operations.

Yes I have pcsc-shared in my scdaemon.conf.
I've just tried removing both pcsc-shared and disable-application piv and PIN caching worked as expected.

Tue, Apr 16, 8:00 AM · gnupg24, yubikey, Bug Report
gniibe added a comment to T5436: gpg-agent 2.3.1: PIN caching not working for decrypt operations.

Are you using PC/SC shared mode? If so, it may be the case of T7041.

Tue, Apr 16, 7:16 AM · gnupg24, yubikey, Bug Report

Mon, Apr 15

werner edited projects for T5436: gpg-agent 2.3.1: PIN caching not working for decrypt operations, added: gnupg24; removed gnupg (gpg23).
Mon, Apr 15, 8:58 PM · gnupg24, yubikey, Bug Report

Tue, Apr 9

werner triaged T7041: Yubikey (PGP + PIV) --pcsc-shared: PIN requires every time as Normal priority.
Tue, Apr 9, 1:42 PM · yubikey, gnupg24, scd, Bug Report

Thu, Apr 4

werner moved T7072: addkey "set your own capabilities" silently sets Restricted Encryption capability from Backlog to QA on the gnupg24 board.
Thu, Apr 4, 4:51 PM · gnupg24
werner changed the status of T7072: addkey "set your own capabilities" silently sets Restricted Encryption capability from Open to Testing.
Thu, Apr 4, 4:50 PM · gnupg24
werner added a comment to T7072: addkey "set your own capabilities" silently sets Restricted Encryption capability.

Pretty obvious. RENC is an allowed usage for an RSA key and thus set in the mask. I restricted this but allowed to set it anyway when using the "=sr" shortcut (here to set as signing and R-enc). Thanks for reporting.

Thu, Apr 4, 4:40 PM · gnupg24
werner triaged T7072: addkey "set your own capabilities" silently sets Restricted Encryption capability as Normal priority.
Thu, Apr 4, 4:09 PM · gnupg24

Wed, Mar 27

ebo triaged T7063: UID origin should change if the key origin was changed by reimporting a key from WKD as Normal priority.
Wed, Mar 27, 4:23 PM · gnupg24

Mar 19 2024

werner added a comment to T7044: Deadlock on Windows in sdaemon.

The reset was due to running gpg-connect-agent reset /bye. I am currently testing something elese will get back as soon as I can turn back to 2.4

Mar 19 2024, 10:22 AM · Bug Report, Windows, gnupg24
gniibe added a comment to T7044: Deadlock on Windows in sdaemon.

There are two locks here; (1) rw_lock for card_top (list of cards) access and (2) individual card lock.
It looks for me that:

  • don't know how/what the thread 7208.2 does
  • the thread 7208.3: KEYINFO, then PKSIGN (gets read lock for card_top, then, individual card lock)
  • the thread 7208.4: SERIALNO --all (and wait for write lock for card_top)
Mar 19 2024, 7:33 AM · Bug Report, Windows, gnupg24

Mar 18 2024

werner moved T6719: Support Proxy-Authorization: Negotiate on Windows from QA to WiP on the gnupg22 board.
Mar 18 2024, 4:22 PM · gnupg24, gnupg22, Feature Request, Restricted Project
werner moved T6719: Support Proxy-Authorization: Negotiate on Windows from WiP to QA on the gnupg22 board.
Mar 18 2024, 4:22 PM · gnupg24, gnupg22, Feature Request, Restricted Project
werner triaged T7044: Deadlock on Windows in sdaemon as High priority.
Mar 18 2024, 8:48 AM · Bug Report, Windows, gnupg24

Mar 7 2024

werner closed T6960: Release GnuPG 2.4.5 as Resolved.
Mar 7 2024, 3:23 PM · gnupg24, Release Info
werner triaged T7030: Release GnuPG 2.4.6 as Low priority.
Mar 7 2024, 3:09 PM · Release Info, gnupg24

Mar 6 2024

werner changed the status of T6719: Support Proxy-Authorization: Negotiate on Windows from Open to Testing.
Mar 6 2024, 11:49 AM · gnupg24, gnupg22, Feature Request, Restricted Project
werner changed the status of T7000: Take derive usage into account for pkcs#15 cards. from Open to Testing.
Mar 6 2024, 11:47 AM · gnupg24 (gnupg-2.4.5), Bug Report, scd

Mar 4 2024

Zymlex added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

In case if someone finds it through a search:

Mar 4 2024, 9:51 PM · Not A Bug, workaround, gnupg24, Windows, ssh
werner moved T7025: --trusted-key and --no-options mismatch from Backlog to WiP on the gnupg22 board.
Mar 4 2024, 3:24 PM · gnupg24 (gnupg-2.4.5), Bug Report, gnupg22
werner changed the status of T7025: --trusted-key and --no-options mismatch from Open to Testing.
Mar 4 2024, 3:24 PM · gnupg24 (gnupg-2.4.5), Bug Report, gnupg22
werner moved T7025: --trusted-key and --no-options mismatch from Backlog to WiP on the gnupg24 board.

How to test:

Mar 4 2024, 3:11 PM · gnupg24 (gnupg-2.4.5), Bug Report, gnupg22
werner triaged T7025: --trusted-key and --no-options mismatch as Normal priority.
Mar 4 2024, 1:45 PM · gnupg24 (gnupg-2.4.5), Bug Report, gnupg22

Feb 28 2024

jak added a comment to T6946: gpgv: Help automatic reject too short keys.

So after taking this down to where it was only patching status.h and mainproc.c to add a write_status_output() I realized the whole issue is down to status-codes.h not being updated automatically if you apply a patch to status.h in a released version.

Feb 28 2024, 1:33 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv
jak added a comment to T6946: gpgv: Help automatic reject too short keys.

Having looked at the build log again after applying the patch, I see the first test failing is

Feb 28 2024, 12:29 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv
ebo removed a project from T6956: GnuPG: Allow import of gpgsk files: gnupg22.
Feb 28 2024, 11:15 AM · Feature Request, gnupg24, Restricted Project

Feb 27 2024

werner added a project to T6678: GPGSM: Add support for cert extension 2.5.29.54 Inhibit anyPolicy: gnupg24.
Feb 27 2024, 3:55 PM · gnupg24, S/MIME, Restricted Project
werner added a project to T6677: GPGSM: Add support for cert extension 2.5.29.36 Policy Constraints: gnupg24.
Feb 27 2024, 3:54 PM · gnupg24, S/MIME, Restricted Project

Feb 21 2024

werner added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

Okay, backported to 2.2.

Feb 21 2024, 3:13 PM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report

Feb 19 2024

werner added projects to T6986: Refresh OpenPGP keys should check WKD: Feature Request, Bug Report.
Feb 19 2024, 5:03 PM · Bug Report, Feature Request, gnupg24, Restricted Project, kleopatra
werner renamed T6986: Refresh OpenPGP keys should check WKD from Kleopatra: Refresh OpenPGP keys should check WKD to Refresh OpenPGP keys should check WKD.
Feb 19 2024, 5:02 PM · Bug Report, Feature Request, gnupg24, Restricted Project, kleopatra
werner added a project to T6986: Refresh OpenPGP keys should check WKD: gnupg24.

I need to come up with a better strategy here. --refresh-keys is a very useful command and it should do what the user expects. Maybe we can adjust the behaviour iff we detect that there is an LDAP keyserver.

Feb 19 2024, 5:02 PM · Bug Report, Feature Request, gnupg24, Restricted Project, kleopatra
werner added a parent task for T7000: Take derive usage into account for pkcs#15 cards.: T7001: Support D-TRUST ECC cards.
Feb 19 2024, 1:54 PM · gnupg24 (gnupg-2.4.5), Bug Report, scd
werner moved T7000: Take derive usage into account for pkcs#15 cards. from Backlog to WiP on the gnupg24 board.
Feb 19 2024, 1:51 PM · gnupg24 (gnupg-2.4.5), Bug Report, scd
werner triaged T7000: Take derive usage into account for pkcs#15 cards. as Normal priority.
Feb 19 2024, 1:45 PM · gnupg24 (gnupg-2.4.5), Bug Report, scd
Angel added a comment to T5444: "gpg: key generation failed: Unknown elliptic curve" from "Key-Type: default".

Interesting. So the problem is not actually the Key-Type, but that the default key-type requires a Key-Curve parameter which has no value by default

Feb 19 2024, 2:15 AM · gnupg24, gnupg (gpg23)

Feb 16 2024

gniibe added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

I was wrong for the semantics of proxy->outtoken. It is zero when run_proxy_connect is called and enabled during the negotiation.

Feb 16 2024, 8:28 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

@hlein Thanks a lot for quick testing.

Feb 16 2024, 8:14 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
hlein added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

Thank you @gniibe! Applied the rG848546b05ab0: dirmngr: Fix the regression of use of proxy for TLS connection. changes here, and 2.4.4 works here now.

Feb 16 2024, 5:22 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

IIUC, the code for keep_alive is for negotiation of proxy. If so, something like this is the fix:

Feb 16 2024, 5:17 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe moved T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy from WiP to QA on the gnupg24 board.
Feb 16 2024, 3:51 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe reassigned T6811: gpgv: Read-only trustedkeys.kbx should not be compressed from gniibe to werner.
Feb 16 2024, 3:45 AM · gnupg24 (gnupg-2.4.5), gnupg22, gpgv, Bug Report
gniibe reassigned T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy from gniibe to werner.
Feb 16 2024, 3:44 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe added a project to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy: gnupg22.

Right. I was wrong assuming the code in 2.2 branch is stable (that is: well tested).

Feb 16 2024, 3:40 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report

Feb 15 2024

thesamesam added a comment to T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy.

Per https://dev.gnupg.org/rG04cbc3074aa98660b513a80f623a7e9f0702c7c9#83517, it looks like the fix might be incomplete?

Feb 15 2024, 10:43 PM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
ebo reassigned T6956: GnuPG: Allow import of gpgsk files from TobiasFella to werner.

Werner wants the import via gpg-agent

Feb 15 2024, 9:07 AM · Feature Request, gnupg24, Restricted Project
ebo moved T6425: improve pinentry behavior and texts in smart card context from Backlog to WiP on the gnupg24 board.
Feb 15 2024, 8:27 AM · gnupg24 (gnupg-2.4.5), scd, Bug Report, Restricted Project
ebo moved T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy from Backlog to WiP on the gnupg24 board.
Feb 15 2024, 8:26 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report
gniibe changed the status of T6997: gnupg-2.4.4 breaks dirmngr fetching keys via hkps:// from behind a proxy from Open to Testing.

Thank you for the report. There was a problem in: rG845d5e61d8e1: dirmngr: Cleanup the http module.
Pushed the fix in: rG04cbc3074aa9: dirmngr: Fix proxy with TLS.

Feb 15 2024, 7:44 AM · gnupg24 (gnupg-2.4.5), gnupg22, Bug Report

Feb 14 2024

jak added a comment to T5444: "gpg: key generation failed: Unknown elliptic curve" from "Key-Type: default".

It works in 2.4.4 if you add

Feb 14 2024, 10:30 AM · gnupg24, gnupg (gpg23)

Feb 13 2024

jak added a comment to T6946: gpgv: Help automatic reject too short keys.

So I cherry-picked this onto 2.4.4 and I ended up with a failing build due to failed tests (it built fine without the patch)

Feb 13 2024, 11:35 AM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv

Feb 10 2024

werner changed the status of T6946: gpgv: Help automatic reject too short keys from Open to Testing.

We check the actual used signature and the corresponding (sub)key. Whether you trust this key is a different thing and we are not able to check that. Note that the same subkey may be used with different primary keys. The whole point of gpgv is to that you pass a list of trusted keys - actually this makes this new option superfluous but in gpg it makes sense. It was easy to add it to gpgv, though.

Feb 10 2024, 2:31 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv

Feb 8 2024

ikloecker added a comment to T6956: GnuPG: Allow import of gpgsk files.

Checking if the file already exists doesn't help. In fact, typically the file (containing the shadow key for the card key) will already exist. But one could check if there is already a private key with this keygrip. Then restoring could be refused, so that the worst that can happen is that the shadow key (which can be recovered from the smart card) is overwritten with a corrupt file.

Feb 8 2024, 9:42 PM · Feature Request, gnupg24, Restricted Project
aheinecke merged T6934: Kleopatra: Import of gpgsk files into T6956: GnuPG: Allow import of gpgsk files.
Feb 8 2024, 10:33 AM · Feature Request, gnupg24, Restricted Project
aheinecke assigned T6956: GnuPG: Allow import of gpgsk files to TobiasFella.

I think the attack ingo talks about would mostly be covered by checking if the file already exists before moving it into the private directory.

Feb 8 2024, 10:31 AM · Feature Request, gnupg24, Restricted Project

Feb 5 2024

Angel added a comment to T6946: gpgv: Help automatic reject too short keys.

Do note there could be subkeys as well.

Feb 5 2024, 1:59 AM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv

Feb 4 2024

Angel added a comment to T5444: "gpg: key generation failed: Unknown elliptic curve" from "Key-Type: default".

I recently stumbled upon this as well.

Feb 4 2024, 11:59 PM · gnupg24, gnupg (gpg23)

Jan 29 2024

ebo closed T6806: Fix off by one day in the expiry date calculation as Resolved.

Setting a date on the command line is in UTC, displayed in Kleopatra is the corresponding local date which might therefore be one day of. This is as intended and the same for dates before or after the Y2038 cut off.
-> Works with Gpg4win-4.3.0

Jan 29 2024, 1:27 PM · Bug Report, gnupg24

Jan 26 2024

werner closed T6961: On Windows the gpgtar --status-fd 2 does not show the gpg status lines as Resolved.

Oh, well it does happen only with --status-fd=2 because of a c+p error by me. For status-fd > 2, as used by GPGME, there is no problem, because this is handled by an exception list.

Jan 26 2024, 10:31 AM · gnupg24 (gnupg-2.4.5), Bug Report
gniibe closed T6579: gnupg-2.4.3 build failure as Resolved.

Fixed in 2.4.4.

Jan 26 2024, 1:00 AM · gnupg24, Gentoo, Bug Report

Jan 25 2024

werner triaged T6961: On Windows the gpgtar --status-fd 2 does not show the gpg status lines as Normal priority.
Jan 25 2024, 3:39 PM · gnupg24 (gnupg-2.4.5), Bug Report
werner shifted T6943: Add tool to detect and clean unsolicited copies of smartcard keys from the Restricted Space space to the S1 Public space.
Jan 25 2024, 11:56 AM · gnupg24 (gnupg-2.4.4), Feature Request
werner edited projects for T6578: Release GnuPG 2.4.4, added: gnupg24; removed gnupg.
Jan 25 2024, 11:37 AM · gnupg24 (gnupg-2.4.4), Release Info
werner triaged T6960: Release GnuPG 2.4.5 as Low priority.
Jan 25 2024, 11:29 AM · gnupg24, Release Info

Jan 24 2024

ebo closed T6654: gpgsm: p12 passphrase visible in debug output as Resolved.

Hidden for Gpg4win-4.3.0-beta571, too

Jan 24 2024, 5:08 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), vsd32 (vsd-3.2.0), S/MIME, Restricted Project
werner closed T6379: Kleopatra: Brainpool key can not be moved to smart card as Resolved.
Jan 24 2024, 4:26 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner moved T6379: Kleopatra: Brainpool key can not be moved to smart card from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 24 2024, 4:24 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner added a comment to T6379: Kleopatra: Brainpool key can not be moved to smart card.

The state of the brain is:

Jan 24 2024, 4:23 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, kleopatra
werner triaged T6956: GnuPG: Allow import of gpgsk files as Normal priority.

These gpgsk files are standard private-keys-v1 files with an additional Backup-info line showing for example the keygrip.
There are no certificates in the file, thus we can either use gpg or gpgsm as driver.

Jan 24 2024, 3:00 PM · Feature Request, gnupg24, Restricted Project
werner closed T6052: gnupg2 tpm2d tests do not work as Resolved.

No test environment in our QA dept.

Jan 24 2024, 2:46 PM · gnupg24 (gnupg-2.4.4), Tests, TPM, Bug Report
werner closed T6831: May chose a signing key from a not inserted card over an inserted one as Resolved.

Fixed in 2.4.4. Feel free to re-open if you still see problems.

Jan 24 2024, 2:45 PM · gnupg24 (gnupg-2.4.4), OpenPGP, patch, Bug Report
werner closed T6741: gpg 2.3+ may display garbled characters for date and time in non-English Windows as Resolved.

No regression, assuming things work.

Jan 24 2024, 2:42 PM · gnupg24 (gnupg-2.4.4), i18n, Windows, Bug Report
werner closed T3380: Use exponential backoff when spawning agent and dirmngr as Resolved.

Hard to test without instrumenting the code.

Jan 24 2024, 2:40 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6796: gpg does create socketdir after every operation as Resolved.

Tested during development.

Jan 24 2024, 2:37 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner added a comment to T6902: gpgconf: the questionable value 256 for flags in gpgrt_opt_t.

Tested for 2.4

Jan 24 2024, 2:35 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4)
werner closed T6710: Improve Speedo for Linux to set DT_RUNPATH. as Resolved.

@alexk and me tested this. The core functionality works.

Jan 24 2024, 2:34 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner closed T6944: The default card key generation keeps an unprotected backup of the encryption key on disk, a subtask of T6943: Add tool to detect and clean unsolicited copies of smartcard keys, as Resolved.
Jan 24 2024, 2:31 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner added a comment to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.

Fixed in 2.4.4 and 2.2.43 - see above for affected versions.

Jan 24 2024, 2:31 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner moved T6919: Add support for smartcafe cards from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 24 2024, 2:25 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner added a project to T6919: Add support for smartcafe cards: Restricted Project.

Works for the two sample RSA cards. Ticket may eventually be re-opened if we run into problems with ECC cards.

Jan 24 2024, 2:24 PM · gnupg24 (gnupg-2.4.4), Restricted Project, Feature Request, scd
werner closed T6752: New minip12 does not import from Firefox anymore as Resolved.

The test file is now part of our test suite and passes.

Jan 24 2024, 11:40 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key as Resolved.

We meanwhile have a lot of test cases in our test suite and we see no issue. Closing this bug; feel free to re-open if it is not fixed for your case in 2.4.4.

Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner closed T6757: gpgsm 2.4 Fails to import P12 certificate/key, a subtask of T6752: New minip12 does not import from Firefox anymore, as Resolved.
Jan 24 2024, 11:36 AM · gnupg24 (gnupg-2.4.4), S/MIME, Bug Report
werner moved T6942: Differing fingerprint length with curve 448 from WiP to QA on the gnupg24 board.
Jan 24 2024, 11:33 AM · gnupg24 (gnupg-2.4.4), Bug Report
werner moved T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from Backlog to WiP on the gnupg22 board.
Jan 24 2024, 11:23 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner added a project to T6944: The default card key generation keeps an unprotected backup of the encryption key on disk: gnupg22.

We need to fix 2.2.42 too. This because we backported the responsible patch.

Jan 24 2024, 11:22 AM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report

Jan 23 2024

ebo closed T4704: Wrong error message when key is expired as Resolved.

In Gpg4win-4.3.0-beta571 with GnuPG 2.4.4-beta132

>echo test | gpg --sign --default-key F8D51DE0EE16E9B57009B8DE458612006D8E6F0D
gpg: Warning: not using 'F8D51DE0EE16E9B57009B8DE458612006D8E6F0D' as default key: Key expired
gpg: all values passed to '--default-key' ignored
gpg: no default secret key: Unusable secret key
gpg: signing failed: Unusable secret key
Jan 23 2024, 1:40 PM · gnupg24 (gnupg-2.4.4), UI, Bug Report
werner closed T6940: gpgsm: .p12 AES-256-CBC support as Resolved.

It is already implemented and will soon show up in 2.4.4 -)

Jan 23 2024, 1:38 PM · gnupg24 (gnupg-2.4.4), Feature Request

Jan 22 2024

werner changed the status of T6944: The default card key generation keeps an unprotected backup of the encryption key on disk, a subtask of T6943: Add tool to detect and clean unsolicited copies of smartcard keys, from Open to Testing.
Jan 22 2024, 4:53 PM · gnupg24 (gnupg-2.4.4), Feature Request
werner changed the status of T6944: The default card key generation keeps an unprotected backup of the encryption key on disk from Open to Testing.
Jan 22 2024, 4:53 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner changed the status of T6943: Add tool to detect and clean unsolicited copies of smartcard keys from Open to Testing.
Jan 22 2024, 4:52 PM · gnupg24 (gnupg-2.4.4), Feature Request

Jan 19 2024

aheinecke closed T6708: Allow to inhibit the use of a default PGP keyserver as Resolved.
Jan 19 2024, 9:39 PM · gnupg24 (gnupg-2.4.4), gnupg22 (gnupg-2.2.42), Restricted Project, vsd, Feature Request
aheinecke added a comment to T6946: gpgv: Help automatic reject too short keys.

The min-rsa option was introduced due because the de-vs compliance allowed 2048 bit until the end of 2023 and we used a trick in our configuration file to switch that relaxed handling off with this year. I don't think that the --ciompliance option is really useful becuase it would also disallow ed25519.

A better option would be an --assert-algo option similar to the --assert-signer which we already have in gpg.

Jan 19 2024, 8:53 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv
werner set External Link to https://forum.gnupg.org/t/privater-schlussel-von-smart-card-in-kleopatra-gespeichert/3858 on T6944: The default card key generation keeps an unprotected backup of the encryption key on disk.
Jan 19 2024, 12:38 PM · gnupg22 (gnupg-2.2.43), gnupg24 (gnupg-2.4.4), OpenPGP, scd, Bug Report
werner triaged T6946: gpgv: Help automatic reject too short keys as Normal priority.

I noticed the Debian bug and was about to answer but a feature request is also a good thing.

Jan 19 2024, 12:27 PM · gnupg24 (gnupg-2.4.5), Feature Request, gpgv