Page MenuHome GnuPG
Feed Advanced Search

Jan 12 2021

werner moved T4584: --quick-sign-key offers no way to override a current certification from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 12 2021, 11:05 AM · Restricted Project, gnupg (gpg22), Feature Request
werner added a project to T4584: --quick-sign-key offers no way to override a current certification: Restricted Project.
Jan 12 2021, 8:05 AM · Restricted Project, gnupg (gpg22), Feature Request
werner raised the priority of T4584: --quick-sign-key offers no way to override a current certification from Normal to High.
Jan 12 2021, 8:04 AM · Restricted Project, gnupg (gpg22), Feature Request

Jan 11 2021

aheinecke edited projects for T4699: X.509 certificate request more comfortable, added: Restricted Project; removed g10code.
Jan 11 2021, 10:55 AM · Restricted Project, kleopatra, S/MIME, gpg4win, Feature Request

Jan 8 2021

aheinecke added a project to T4699: X.509 certificate request more comfortable: g10code.
Jan 8 2021, 4:31 PM · Restricted Project, kleopatra, S/MIME, gpg4win, Feature Request
gniibe added a comment to T4951: Support point compression in Libgcrypt.

Reading compressed point (in keys) is supported (except for NIST P-224). When curve point is represented in compressed format, it is correctly interpreted now. So, for example, I think that with 1.9.0, gpgsm can handle certificate which uses compressed format in its curve point representation.

Jan 8 2021, 2:09 AM · Feature Request, libgcrypt

Jan 7 2021

werner moved T4873: Enable AES GCM in FIPS mode from For 1.9 to FIPS on the libgcrypt board.
Jan 7 2021, 5:59 PM · FIPS, libgcrypt, Feature Request
werner moved T4951: Support point compression in Libgcrypt from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:42 AM · Feature Request, libgcrypt
werner moved T4873: Enable AES GCM in FIPS mode from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:40 AM · FIPS, libgcrypt, Feature Request
werner claimed T4926: Add API to map a curve name to its canonical OID..
Jan 7 2021, 11:30 AM · Feature Request, libgcrypt
werner added a comment to T4951: Support point compression in Libgcrypt.

What is the state of this bug? Reading is implemented - do we really need writing (maybe to support certain smartcards)?

Jan 7 2021, 11:29 AM · Feature Request, libgcrypt
werner added a subtask for T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297): T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner added a parent task for T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452): T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner lowered the priority of T1303: Please support GCRYSEXP_FMT_BASE64 from Normal to Wishlist.
Jan 7 2021, 9:14 AM · Feature Request, libgcrypt

Jan 6 2021

rupor-github added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

I wrote https://github.com/rupor-github/win-gpg-agent to simplify usage on Windows until this issue is resolved - it handles various edge cases on Windows.

Jan 6 2021, 7:25 PM · Not A Bug, workaround, gnupg24, Windows, ssh

Jan 5 2021

werner added a comment to T3505: Port GPGME's Python bindings to Windows.

The C++, CL, Javascript and QT Bindings are all written by hand.

Jan 5 2021, 4:06 PM · Feature Request, gpgme, Python
bernhard added a comment to T3505: Port GPGME's Python bindings to Windows.

Hi Werner,

we do it for the other bindings as well.

can you elaborate?

Jan 5 2021, 3:01 PM · Feature Request, gpgme, Python
werner lowered the priority of T3505: Port GPGME's Python bindings to Windows from High to Normal.

Given all the resources we had put on this Python bindings I'd suggest to bite the bullet and replace Swig by handcrafted bindings. More work but we do it for the other bindings as well.

Jan 5 2021, 10:59 AM · Feature Request, gpgme, Python
werner lowered the priority of T4695: Remove SERIALNO as an identifier to select keys from High to Normal.

I think we can close this one, right?

Jan 5 2021, 10:54 AM · Restricted Project, Feature Request, gnupg
wiktor-k added a comment to T4694: manage first-party attestations.

For the context of all subscribed parties I think Werner refers to what Hockeypuck is doing: https://lists.gnupg.org/pipermail/gnupg-users/2020-December/064441.html

Jan 5 2021, 10:45 AM · Keyserver, Feature Request
werner lowered the priority of T4694: manage first-party attestations from High to Low.

Meanwhile there are simpler ideas and code on how to do only authenticated uploads. Thus lowering the prio.

Jan 5 2021, 10:41 AM · Keyserver, Feature Request
werner triaged T5060: Feature to migrate a card based to a file based key pair as Normal priority.
Jan 5 2021, 9:36 AM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T4961: ship gpgrt.pc as Normal priority.
Jan 5 2021, 9:34 AM · Feature Request, gpgrt

Jan 1 2021

scratchmex added a comment to T3808: Unable to safely delete IDs with shared secret keys.

Actually this isn't really a special case when you want to migrate your existing ssh keys to gpg and import them. As stated in this guide https://opensource.com/article/19/4/gpg-subkeys-ssh-multiples, what you need to do currently is export the master key with its private keys, delete the imported ssh key from your keyring and then import your private keys again.

Jan 1 2021, 3:08 PM · Feature Request

Dec 21 2020

werner closed T4788: System wide configuration of the GnuPG system as Resolved.
Dec 21 2020, 7:40 PM · gnupg (gpg23), Feature Request, gpg4win, g10code

Dec 18 2020

ikloecker changed the status of T5138: Change Reset Code not working in Kleopatra from Open to Testing.

Werner, please retest. If "Change Reset Code" still doesn't work for you, then please answer the questions in the first comment.

Dec 18 2020, 12:19 PM · Feature Request, Bug Report, kleopatra
ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

Note: Officially, Kleopatra does not support OpenPGP v1 cards. At least, according to the text that is displayed if no card is found.

Dec 18 2020, 12:15 PM · Feature Request, Bug Report, kleopatra
ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

"Change Reset Code" should work in Kleopatra. At least for OpenPGP v2+ cards. Kleopatra simply does "SCD PASSWD --reset OPENPGP.2", i.e. the same as gpg-card. I have verified that it works with a Yubikey.

Dec 18 2020, 11:11 AM · Feature Request, Bug Report, kleopatra

Dec 16 2020

gniibe reopened T4563: gpg-agent fails to sign request of PKISSH as "Open".
Dec 16 2020, 1:43 AM · Feature Request, gpgagent
gniibe closed T4563: gpg-agent fails to sign request of PKISSH as Wontfix.
Dec 16 2020, 1:42 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

If your problem is the incompatibility between standard OpenSSH (server) and PKIXSSH (client) for use of ssh-agent emulation of gpg-agent with ECDSA key, I'd suggest to apply following patch to your PKIXSSH:

diff --git a/compat.c b/compat.c
index fe71951..0c9b1ef 100644
--- a/compat.c
+++ b/compat.c
@@ -245,7 +245,6 @@ xkey_compatibility(const char *remote_version) {
 {	static sshx_compatibility info[] = {
 		{ 0, "OpenSSH*PKIX[??.*" /* 10.+ first correct */ },
 		{ 0, "OpenSSH*PKIX[X.*" /* developlement */ },
-		{ 1, "OpenSSH*" /* PKIX pre 10.0 */ },
 		{ 1, "SecureNetTerm-3.1" /* same as PKIX pre 10.0 */},
 		{ 0, NULL } };
 	p = xkey_compatibility_find(remote_version, info);
Dec 16 2020, 12:58 AM · Feature Request, gpgagent

Dec 14 2020

gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Unfortunately and confusingly, PKISSH returns "OpenSSH" when asked by "ssh -V".
Please install real OpenSSH, if this is the case for you.

Dec 14 2020, 10:52 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Quote from IRC:
hey, i've some problems with my smartcard since quite some time. i'm not sure whether it's openssh related or gnupg. it's a openpgpcard v2.0 and i have to workaround ssh logins by using "SSH_AUTH_SOCK=0 ssh ...". .gnupg/gpg-agent.conf -

the debug log: esp. "ssh sign request failed: Unknown option <GPG Agent>" and ssh says "sign_and_send_pubkey: signing failed: agent refused operation"
gpg --edit-card and --card-status works fine and sign/encrypt works fine as well. only ssh auth fails
openssh 8.1_p1, gnupg 2.2.20

Dec 14 2020, 10:31 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Yeah but it seems to be the same issue / reason. I wasn't aware that PKISSH is something else. I thought it was an extension/protocol or something

Dec 14 2020, 10:26 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I added "Feature Request", because this is a request to support:

  • A feature of bug compatibility, which is implemented wrongly in PKISSH
  • for a specific algo of key, which is not considered so useful (== ECDSA)
  • PKISSH, which is variant of OpenSSH
Dec 14 2020, 10:23 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.
In T4563#140184, @idl0r wrote:

I was and I am using OpenSSH on both sides, client and server.

Dec 14 2020, 10:20 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I was and I am using OpenSSH on both sides, client and server.

Dec 14 2020, 10:16 AM · Feature Request, gpgagent
werner added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I do not think that we should support a fork of openssh right now. If we would support it we are bound to maintain that for years - this is not a good idea.

Dec 14 2020, 10:09 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Well, I have no idea about the technical background to be honest but without this patch it doesn't work at all for me, unless I stop using the agent or workaround it by using SSH_AUTH_SOCK=0. With this patch, I can use the agent again. I don't know how many others are affected by this but it made it usable again, which wasn't the case for months already.

Dec 14 2020, 9:04 AM · Feature Request, gpgagent
gniibe lowered the priority of T4563: gpg-agent fails to sign request of PKISSH from Normal to Low.

In theory, I don't think the patch gnupg.patch works. It just ignore the flag.

Dec 14 2020, 3:19 AM · Feature Request, gpgagent
lopter added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Thank you for testing.
For the issue #1, I think it is the probelm of rG1cd615afe301: gpg,card: Allow no version information of Yubikey.. This was introduced by the support of PIV feature of Yubikey.

Dec 14 2020, 2:05 AM · Restricted Project, gnupg, Feature Request
gniibe added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Thank you for testing.
For the issue #1, I think it is the probelm of rG1cd615afe301: gpg,card: Allow no version information of Yubikey., which is fixed already. This was introduced by the support of PIV feature of Yubikey.

Dec 14 2020, 1:05 AM · Restricted Project, gnupg, Feature Request

Dec 12 2020

lopter added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Report on some testing using master:

Dec 12 2020, 9:33 PM · Restricted Project, gnupg, Feature Request
werner triaged T5179: add export-filter based on user ID calculated validity as Normal priority.
Dec 12 2020, 1:26 PM · gnupg24, gnupg (gpg23), Feature Request

Dec 11 2020

dkg created T5179: add export-filter based on user ID calculated validity.
Dec 11 2020, 6:31 PM · gnupg24, gnupg (gpg23), Feature Request

Dec 9 2020

idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I am affected by the same bug and the patch seems to work for me. Login via gpg-agent with ssh support is possible again, which wasn't before, since some openssh and/or gnupg update. Not sure.

Dec 9 2020, 12:04 PM · Feature Request, gpgagent

Dec 4 2020

werner added a comment to T4788: System wide configuration of the GnuPG system.

And I also did a backport to 2.2 :-) See rGa028f24136a062f55408a5fec84c6d31201b2143

Dec 4 2020, 12:21 PM · gnupg (gpg23), Feature Request, gpg4win, g10code
gniibe added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

if I am running master, it is now possible to have a setup where the same encryption key is shared by and usable from multiple smart cards?

Dec 4 2020, 8:30 AM · Restricted Project, gnupg, Feature Request
lopter added a comment to T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)).

Thank you for all the work! Does it mean that, if I am running master, it is now possible to have a setup where the same encryption key is shared by and usable from multiple smart cards?

Dec 4 2020, 7:55 AM · Restricted Project, gnupg, Feature Request

Dec 2 2020

aheinecke added a comment to T2227: Sign GpgOL to support group deployments.

For linking the MSI installer we already need a windows host and a windows sign host. The binaries inside that package we also sign usign the signhost / signkey which can be included in an optional / custom sign.mk during the build process. By default the path to the included sign.mk is gnupg-vsd/sign.mk in the src repo. But that can be changed of course.

Dec 2 2020, 2:10 PM · gpgol, Feature Request

Nov 30 2020

ikloecker closed T5139: Kleopatra keypair creation wizard improvement as Resolved.

Done.

Nov 30 2020, 3:05 PM · Feature Request, kleopatra
aheinecke triaged T5091: Kleopatra: Close all tabs except this one as Wishlist priority.

Okay, I usually only keep hitting crl+w in that case. But I see the point when doing imports this can be annoying.

Nov 30 2020, 10:53 AM · kleopatra, Feature Request

Nov 27 2020

werner claimed T4398: Rework Console and command line handling on Windows.
Nov 27 2020, 6:33 PM · Feature Request, gnupg (gpg23)
werner closed T5038: UTF-8 handling in the command line, a subtask of T4398: Rework Console and command line handling on Windows, as Resolved.
Nov 27 2020, 6:33 PM · Feature Request, gnupg (gpg23)
werner renamed T4398: Rework Console and command line handling on Windows from Rework Console handling on Windows to Rework Console and command line handling on Windows.
Nov 27 2020, 6:31 PM · Feature Request, gnupg (gpg23)
werner added a subtask for T4398: Rework Console and command line handling on Windows: T5038: UTF-8 handling in the command line.
Nov 27 2020, 6:26 PM · Feature Request, gnupg (gpg23)
werner lowered the priority of T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion from Normal to Wishlist.
Nov 27 2020, 5:39 PM · Keyserver, Feature Request, dirmngr

Nov 26 2020

werner reopened T4004: Curve25519 for Zeitcontrol card as "Open".
Nov 26 2020, 5:08 PM · Feature Request, scd
werner added a comment to T4004: Curve25519 for Zeitcontrol card.

You are right, the new 3.4 cards support brainpool curves in addition to the nist curves.

Nov 26 2020, 5:08 PM · Feature Request, scd
nitroalex added a comment to T4004: Curve25519 for Zeitcontrol card.

If you mean OpenPGP Card v3 standard, no it did not support cv25519 ed25519, but some other curves up until v3.4. So if there is a specific specification bringing this feature, can you might refer to the specific version? Otherwise, I think this task is still valid.
I remember the problem being the card manufacturers that are not interesting in cv25519 (yet).

Nov 26 2020, 10:06 AM · Feature Request, scd
gniibe added a subtask for T3517: dirmngr: retry without SRV due to buggy routers: T3168: dirmngr: gpg: keyserver receive failed: No keyserver available.
Nov 26 2020, 7:51 AM · Feature Request, dns, dirmngr
gniibe merged T3722: gpg "No name" error into T3517: dirmngr: retry without SRV due to buggy routers.
Nov 26 2020, 7:31 AM · Feature Request, dns, dirmngr
gniibe merged T3574: gpg-agent doesn't pick up ssh certificates into T1756: gpg-agent doesn't accept ssh certificates.
Nov 26 2020, 7:20 AM · gnupg, Feature Request
gniibe closed T4004: Curve25519 for Zeitcontrol card as Resolved.

Support was added in version 3 card.

Nov 26 2020, 7:17 AM · Feature Request, scd

Nov 23 2020

ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

As for renaming "Change Reset Code" to "Set Reset Code", what about "Change PIN" and "Change Admin PIN"? Should they also be renamed? If not, why not? Is there no default reset code? Is there a way to find out whether the reset code has already been set (in which case "change" would be more appropriate than "set")?

Nov 23 2020, 11:00 AM · Feature Request, Bug Report, kleopatra
ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

You write

This does not work.

Can you be more specific? What doesn't work? Which OS, which version of Kleopatra, what smartcard are you using?

Nov 23 2020, 10:52 AM · Feature Request, Bug Report, kleopatra
werner added a comment to T5137: gpg-agent 2.x poor performance / futex errors.

I though about this too but we need to take care about the logging functions of Libgcrypt which are intertwined with nPth (clamp function of libgpg-error).

Nov 23 2020, 9:01 AM · Feature Request, gpgagent

Nov 19 2020

Hafiz added a comment to T5136: Mega888.

{F1982353}

Nov 19 2020, 9:36 PM · gpgagent, Feature Request
gniibe added a comment to T5137: gpg-agent 2.x poor performance / futex errors.

Thanks. I understand the situation. Basically, gpg-agent's computation is done by a single thread (in current implementation), although it accepts many requests simultaneously.

Nov 19 2020, 3:21 AM · Feature Request, gpgagent

Nov 18 2020

andrey.arapov added a comment to T5137: gpg-agent 2.x poor performance / futex errors.

Note that you actually run 30 independent processes with gpg 1.4 but with gpg-agent there is just one process to handle the private key operations (decrypt). To utilize more cores you need to setup several GNUPGHOME with the same private keys.

Nov 18 2020, 2:33 PM · Feature Request, gpgagent
andrey.arapov added a comment to T5137: gpg-agent 2.x poor performance / futex errors.

I think that it is not gpg-agent but pinentry which causes millions of futex syscall errors.
For interactive use case, pinentry may be the point of contention.
I might be wrong if your key is not protected by passphrase.

If possible, please try adding arguments for gpg invocation: --pinentry-mode loopback --passphrase-file YOUR_FILE_FOR_PASSPHRASE
This can avoid the invocation of pinentry entirely.

Nov 18 2020, 2:32 PM · Feature Request, gpgagent

Nov 17 2020

werner created T5139: Kleopatra keypair creation wizard improvement.
Nov 17 2020, 8:56 AM · Feature Request, kleopatra
werner created T5138: Change Reset Code not working in Kleopatra.
Nov 17 2020, 8:47 AM · Feature Request, Bug Report, kleopatra
werner triaged T5137: gpg-agent 2.x poor performance / futex errors as Normal priority.

I change this to a feature request: Allow several processes to run public key decryption using the same set of private keys.

Nov 17 2020, 8:35 AM · Feature Request, gpgagent

Nov 16 2020

werner closed T5136: Mega888 as Spite.
Nov 16 2020, 4:10 PM · gpgagent, Feature Request
Hafiz created T5136: Mega888.
Nov 16 2020, 12:39 PM · gpgagent, Feature Request
werner triaged T5135: Provide more practical thread-safe strerror, perhaps with strerror_l as Normal priority.
Nov 16 2020, 9:08 AM · gpgrt, Feature Request
gniibe closed T4641: Libassuan: enable the environment to set compiler and linker flags for helper tools as Resolved.
Nov 16 2020, 7:28 AM · Restricted Project, libassuan, Feature Request

Nov 15 2020

werner added a comment to T5135: Provide more practical thread-safe strerror, perhaps with strerror_l.

I know these troubles.

Nov 15 2020, 1:19 PM · gpgrt, Feature Request

Nov 14 2020

pert created T5135: Provide more practical thread-safe strerror, perhaps with strerror_l.
Nov 14 2020, 4:23 PM · gpgrt, Feature Request

Nov 10 2020

ikloecker changed the status of T5094: Kleopatra: Add "revsig" support, a subtask of T5093: GnuPG: Add quick-revsig, from Open to Testing.
Nov 10 2020, 5:01 PM · Feature Request, gnupg (gpg22)
jharvell added a comment to T3950: gnupg-2.2.6 fails to find correct library config programs when cross-compiling for ARM.

Thanks for addressing this in master.

Nov 10 2020, 4:14 PM · Feature Request
gniibe closed T3950: gnupg-2.2.6 fails to find correct library config programs when cross-compiling for ARM as Wontfix.

The feature (better cross compiling) was done in master.
We close this bug report as "Won't fix" since it will never been applied to 2.2.

Nov 10 2020, 6:48 AM · Feature Request
gniibe added a comment to T3950: gnupg-2.2.6 fails to find correct library config programs when cross-compiling for ARM.

In newer releases of libgpg-error, libksba, libassuan, libgcrypt, npth and ntbtls, we updated corresponding *.m4, so that we can use new gpgrt-config program only. And gpgrt-config command supports cross compiling and multiarch libraries.

Nov 10 2020, 6:45 AM · Feature Request

Nov 4 2020

werner closed T5093: GnuPG: Add quick-revsig as Resolved.
Nov 4 2020, 8:40 AM · Feature Request, gnupg (gpg22)

Nov 3 2020

werner lowered the priority of T4972: GPG: Add Option to force passphrase constraints for symmetric encryption, too from High to Normal.

FWIW, --enforce-passphrase-constraints does already work for symmetric-only encryption since 2.2.21 (rGae8b88c635424ef3). Thus this bug is actually a feature request to have a separate set of passphrase constraints option for symmetric-only mode.

Nov 3 2020, 4:00 PM · gnupg (gpg22), Feature Request
werner raised the priority of T4972: GPG: Add Option to force passphrase constraints for symmetric encryption, too from Wishlist to High.
Nov 3 2020, 10:58 AM · gnupg (gpg22), Feature Request

Oct 29 2020

werner added a parent task for T4584: --quick-sign-key offers no way to override a current certification: T5093: GnuPG: Add quick-revsig.
Oct 29 2020, 4:40 PM · Restricted Project, gnupg (gpg22), Feature Request
werner added a subtask for T5093: GnuPG: Add quick-revsig: T4584: --quick-sign-key offers no way to override a current certification.
Oct 29 2020, 4:40 PM · Feature Request, gnupg (gpg22)
werner edited projects for T4584: --quick-sign-key offers no way to override a current certification, added: gnupg (gpg22); removed gnupg.

Indeed we need to fix/enhance this to make testing of --quick-revoke-sig easier. See over at T5093

Oct 29 2020, 4:39 PM · Restricted Project, gnupg (gpg22), Feature Request
werner changed the status of T5093: GnuPG: Add quick-revsig from Testing to Open.

I recall that I had the same bug during development. Must have slipped in again - Good catch.

Oct 29 2020, 4:36 PM · Feature Request, gnupg (gpg22)
ikloecker added a comment to T5093: GnuPG: Add quick-revsig.

I have added support for this to gpgme (and gpgme++/qgpgme). See T5094.

Oct 29 2020, 1:00 PM · Feature Request, gnupg (gpg22)
ikloecker added a comment to T5093: GnuPG: Add quick-revsig.

By the way, --quick-sign-key after --quick-revoke-sig refuses to recertify the key. -> T4584

Oct 29 2020, 12:58 PM · Feature Request, gnupg (gpg22)
ikloecker added a comment to T4584: --quick-sign-key offers no way to override a current certification.

There is another problem: Even if the first certification was revoked, trying to add a new certification with --quick-sign-key fails because '"user id" was already signed by key ...'

Oct 29 2020, 12:31 PM · Restricted Project, gnupg (gpg22), Feature Request
ikloecker added a comment to T5093: GnuPG: Add quick-revsig.

I found a bug. To reproduce generate a new key, then sign it with another key and then try to quick-revoke the signatures. This fails with "Not signed by you."

Oct 29 2020, 12:14 PM · Feature Request, gnupg (gpg22)
werner added a comment to T5093: GnuPG: Add quick-revsig.

On purpose. We actually allow user ids and gpg should somehow reflect this. As requested by you I changed it in the man page to what is suggested.

Oct 29 2020, 11:39 AM · Feature Request, gnupg (gpg22)
ikloecker added a comment to T5093: GnuPG: Add quick-revsig.

I've noticed an inconsistency between the command arguments in the man page and in the usage/error message.

Oct 29 2020, 10:06 AM · Feature Request, gnupg (gpg22)

Oct 28 2020

werner changed the status of T5093: GnuPG: Add quick-revsig from Open to Testing.
Oct 28 2020, 6:26 PM · Feature Request, gnupg (gpg22)
werner placed T5093: GnuPG: Add quick-revsig up for grabs.

The backend part is ready. Someone(tm) now needs to add it to gpgme. Extending the sign key API might be the best solution.

Oct 28 2020, 6:25 PM · Feature Request, gnupg (gpg22)
werner added a comment to T5093: GnuPG: Add quick-revsig.

I was already considering this. I bet some people will view it as a bug if it is possible to add something other than a fingerprint. I'll change it in the man page.

Oct 28 2020, 5:04 PM · Feature Request, gnupg (gpg22)