Page MenuHome GnuPG
Feed Advanced Search

Mar 22 2021

ikloecker created T5353: gpgme: Implement keylist_data for gpgsm.
Mar 22 2021, 11:56 AM · gnupg24, gnupg (gpg23), gpgme, Feature Request
ckk added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

I was also somewhat surprised to see that the max-cache-ttl options were rendered ineffective my moving the keys to a card.

Mar 22 2021, 11:56 AM · Feature Request

Mar 16 2021

werner closed T4702: Deadline for the GnuPG 2.3.0 release, a subtask of T4362: Replace the exec funtions for photoids in gpg by our standard exec functions., as Resolved.
Mar 16 2021, 4:53 PM · gnupg, Feature Request

Mar 11 2021

werner triaged T5342: Support Windows on ARM as Low priority.

Thanks for the Gpg4win praise; however we don't have the required resources yet to take this up.

Mar 11 2021, 4:21 PM · Feature Request, gpg4win
werner closed T4584: --quick-sign-key offers no way to override a current certification as Resolved.

New option --force-sign-key for 2.2.28 and 2.3. Also added support to gpgme.

Mar 11 2021, 11:54 AM · Restricted Project, gnupg (gpg22), Feature Request
werner closed T4584: --quick-sign-key offers no way to override a current certification, a subtask of T5093: GnuPG: Add quick-revsig, as Resolved.
Mar 11 2021, 11:54 AM · Feature Request, gnupg (gpg22)

Mar 9 2021

jukivili closed T4630: libgcrypt: POWER GHASH Vector Acceleration as Resolved.
Mar 9 2021, 8:45 PM · Feature Request, libgcrypt
jukivili added a comment to T4630: libgcrypt: POWER GHASH Vector Acceleration.

Pushed to master with two commits:

Mar 9 2021, 8:44 PM · Feature Request, libgcrypt
werner triaged T5344: Kleopatra: explain crypto profiles even better as Low priority.

Actually we considerto remove this feature from the GUI because with the global config we have a more versatile feature now.

Mar 9 2021, 4:21 PM · kleopatra, Feature Request, Documentation

Mar 8 2021

werner changed the status of T4398: Rework Console and command line handling on Windows from Open to Testing.

and item 6. Now for more testing.

Mar 8 2021, 9:57 PM · Feature Request, gnupg (gpg23)
werner removed a project from T5342: Support Windows on ARM: Bug Report.
Mar 8 2021, 4:59 PM · Feature Request, gpg4win
rubin created T5342: Support Windows on ARM.
Mar 8 2021, 4:22 PM · Feature Request, gpg4win

Mar 7 2021

pollo added a comment to T3362: Prevent Smartcard from caching PIN when cache-ttl is set accordingly.

Following @turkja 's advice, here's a python script I wrote that does exactly that:

Mar 7 2021, 6:39 PM · Feature Request

Mar 6 2021

jukivili closed T5337: Missing hardware features in documentation as Resolved.

Fixed typos and applied to master. Thanks.

Mar 6 2021, 4:22 PM · Feature Request, patch, libgcrypt
jukivili claimed T5337: Missing hardware features in documentation.
Mar 6 2021, 2:52 PM · Feature Request, patch, libgcrypt

Mar 5 2021

werner added a comment to T4398: Rework Console and command line handling on Windows.

Items 1 to 5 have now been resolved.

Mar 5 2021, 3:52 PM · Feature Request, gnupg (gpg23)
werner closed T4365: Encoding problem: gpg truncates multibyte characters in interactive prompts on Windows, a subtask of T4398: Rework Console and command line handling on Windows, as Resolved.
Mar 5 2021, 3:50 PM · Feature Request, gnupg (gpg23)
werner triaged T5337: Missing hardware features in documentation as Normal priority.
Mar 5 2021, 2:36 PM · Feature Request, patch, libgcrypt

Mar 4 2021

werner added a comment to T4398: Rework Console and command line handling on Windows.

So we now get UTF-8 argv in all GnuPG modules. Globing has been enabled for gpg using our own globing code instead of the ASCII only "int _dowildcard = 1;" mingw way.

Mar 4 2021, 5:19 PM · Feature Request, gnupg (gpg23)

Feb 22 2021

bobwxc added a comment to T5286: Calculate Z hash for sm2.

Excuse me, where is the link to this blog you mentioned?

Feb 22 2021, 6:17 AM · Not A Bug, Info Needed, libgcrypt, Feature Request
shaoyj added a comment to T5286: Calculate Z hash for sm2.

@bobwxc wrote:
And I found a blog seems written by the SM2 implementation author of libgcrybt -- Tianjia Zhang. He/She drew a red circle on a standard picture of the Z_A.

Excuse me, where is the link to this blog you mentioned?

Feb 22 2021, 3:44 AM · Not A Bug, Info Needed, libgcrypt, Feature Request

Feb 21 2021

bobwxc added a comment to T5286: Calculate Z hash for sm2.

We need more information on the why and when of this change. We don't want to maintain different versions of the same algorithm. The I-D expired more than 6 years ago and thus it should not be used as a reference.

Feb 21 2021, 3:20 PM · Not A Bug, Info Needed, libgcrypt, Feature Request

Feb 18 2021

gniibe added a comment to T1756: gpg-agent doesn't accept ssh certificates.

I'm sorry, if my wording sounded harsh.

Feb 18 2021, 1:50 AM · gnupg, Feature Request

Feb 17 2021

werner triaged T5304: Kleopatra: Main certificate view does not keep selected column width as Normal priority.
Feb 17 2021, 10:45 AM · Restricted Project, Bug Report, kleopatra, gpg4win
whites11 added a comment to T1756: gpg-agent doesn't accept ssh certificates.

I understand this is kind of an edge case, but having the possibility to use signed ssh keys would be very useful to me.

??? Do you understand how ssh keys are handled by ssh client and ssh-agent?

Feb 17 2021, 9:48 AM · gnupg, Feature Request
gniibe added a comment to T1756: gpg-agent doesn't accept ssh certificates.

I understand this is kind of an edge case, but having the possibility to use signed ssh keys would be very useful to me.

Feb 17 2021, 9:47 AM · gnupg, Feature Request

Feb 13 2021

szszszsz-nitrokey added a comment to T1621: Support multiple cards (not just readers).

Could you tell what is the status of this ticket? Is it planned for the development?
For some users usage is problematic when there are other readers recognized, provided by the OS or hardware platform, and ordered before the target device which in turn blocks access to it.

Feb 13 2021, 6:20 PM · gnupg, Feature Request

Feb 11 2021

werner removed a parent task for T4362: Replace the exec funtions for photoids in gpg by our standard exec functions.: T4417: Work needed for gnupg 2.3.
Feb 11 2021, 11:05 AM · gnupg, Feature Request
werner removed a parent task for T4344: Periodic check of own keys with the WKD: T4417: Work needed for gnupg 2.3.
Feb 11 2021, 11:05 AM · wkd, gnupg, Feature Request
werner removed a parent task for T4406: Allow the use of the default-new-key-algo format for --quick-gen-key.: T4417: Work needed for gnupg 2.3.
Feb 11 2021, 11:05 AM · gnupg24, Feature Request
werner removed a parent task for T3495: The --list-keys should account for groups that are defined: T4417: Work needed for gnupg 2.3.
Feb 11 2021, 11:00 AM · gnupg, Feature Request
werner added a project to T3495: The --list-keys should account for groups that are defined: gnupg.
Feb 11 2021, 11:00 AM · gnupg, Feature Request
werner added a project to T5294: Displaying the date and time at which you've replied to an email when using GPgOL: gpgol.
Feb 11 2021, 10:13 AM · gpgol, Feature Request
Alexander_Wittich created T5294: Displaying the date and time at which you've replied to an email when using GPgOL.
Feb 11 2021, 8:22 AM · gpgol, Feature Request

Feb 10 2021

werner added a subtask for T4398: Rework Console and command line handling on Windows: T4365: Encoding problem: gpg truncates multibyte characters in interactive prompts on Windows.
Feb 10 2021, 2:59 PM · Feature Request, gnupg (gpg23)
werner merged T3466: Add tool to convert a card backup key to a regular secret key into T4359: Convert backup keyfiles to regular key's.
Feb 10 2021, 2:58 PM · gnupg24, gnupg (gpg23), Feature Request
werner merged task T3466: Add tool to convert a card backup key to a regular secret key into T4359: Convert backup keyfiles to regular key's.
Feb 10 2021, 2:58 PM · gnupg (gpg23), Feature Request
werner closed T4154: allow setting passphrase from an environment variable as Wontfix.
Feb 10 2021, 2:55 PM · Feature Request, gnupg (gpg23)
werner lowered the priority of T3389: canonical OpenPGP certificate export from Normal to Wishlist.
Feb 10 2021, 11:53 AM · gnupg, Feature Request
werner renamed T2958: Extend --unwrap to also remove a compression layer. from extract signature from encrypted+signed message to Extend --unwrap to also remove a compression layer..
Feb 10 2021, 11:24 AM · gnupg24, Feature Request, gnupg (gpg23)
werner added a comment to T2958: Extend --unwrap to also remove a compression layer..

We have the --unwrap option which already does this. The problem here is that an addition compression layer is not removed. Therefore I will rename this report to add a feature strip things down to a signature or literal data packet..

Feb 10 2021, 11:23 AM · gnupg24, Feature Request, gnupg (gpg23)
werner closed T2912: command line keytocard as Wontfix.

The gpg-card is more flexible than the old gpg stuff. If there is something missing we will add it over time but it does not make sense to keep this request open.

Feb 10 2021, 11:12 AM · gnupg (gpg23), Feature Request
werner lowered the priority of T2862: support session key extraction and overriding for gpgsm from Normal to Wishlist.
Feb 10 2021, 11:10 AM · gnupg24, Feature Request, gnupg (gpg23)
werner closed T2850: auto-key-locate is annoying as Resolved.

Due to better working timeouts we have mostly soolved these problems,. Further keyservers are not anymore of great use these days.

Feb 10 2021, 11:09 AM · gnupg (gpg23), gnupg, Feature Request
werner lowered the priority of T2760: Populate comment field when exporting authentication key for SSH from Normal to Wishlist.
Feb 10 2021, 11:05 AM · gnupg24, ssh, Feature Request
werner lowered the priority of T2290: Allow gpgv2 to use armored GPG keys as keyring file with trusted keys from Normal to Wishlist.
Feb 10 2021, 11:02 AM · gnupg24, Feature Request
werner lowered the priority of T2186: --encrypt-to ambiguous with a expired and revoked key from Normal to Low.
Feb 10 2021, 11:01 AM · gnupg24, Feature Request
werner closed T1089: Please store requests in a cache to avoid sending out duplicate requests (mailto: interface) as Wontfix.
Feb 10 2021, 10:59 AM · gnupg (gpg23), gnupg, Debian, Feature Request

Feb 9 2021

werner triaged T5286: Calculate Z hash for sm2 as Low priority.

We need more information on the why and when of this change. We don't want to maintain different versions of the same algorithm. The I-D expired more than 6 years ago and thus it should not be used as a reference.

Feb 9 2021, 7:58 AM · Not A Bug, Info Needed, libgcrypt, Feature Request

Feb 5 2021

shaoyj added a comment to T5286: Calculate Z hash for sm2.

https://tools.ietf.org/html/draft-shen-sm2-ecdsa-02
Section 5.1.4.4

Feb 5 2021, 8:03 AM · Not A Bug, Info Needed, libgcrypt, Feature Request
shaoyj created T5286: Calculate Z hash for sm2.
Feb 5 2021, 7:27 AM · Not A Bug, Info Needed, libgcrypt, Feature Request

Feb 1 2021

aheinecke added a comment to T4735: Please provide an option to make --verify accept only signatures from specific trusted UID.

I'm slightly against a backport as this is a behavior change for example KMail and GpgOL which use the --sender option might get different results after this change. I don't think it would be problematic but as said I have a slight preference against backporting because changing behavior of existing calls is better something for the new major release which is in its final steps for release anyway.

Feb 1 2021, 10:47 AM · gnupg (gpg23), Feature Request
mgorny added a comment to T4735: Please provide an option to make --verify accept only signatures from specific trusted UID.

Shall we backport this to 2.2 which is our LTS release?

Feb 1 2021, 10:42 AM · gnupg (gpg23), Feature Request

Jan 30 2021

werner triaged T5281: gpg-agent / pinentry: allow to pause/mute passphrase requests for a while as Normal priority.
Jan 30 2021, 12:10 PM · gpgagent, pinentry, Feature Request
shtrom created T5281: gpg-agent / pinentry: allow to pause/mute passphrase requests for a while.
Jan 30 2021, 2:25 AM · gpgagent, pinentry, Feature Request

Jan 28 2021

gniibe closed T4301: Handling multiple subkeys on two SmartCards, a subtask of T4695: Remove SERIALNO as an identifier to select keys, as Resolved.
Jan 28 2021, 3:19 AM · Restricted Project, Feature Request, gnupg
gniibe closed T4864: New scdaemon command to watch device removal as Resolved.
Jan 28 2021, 3:08 AM · Restricted Project, Feature Request, scd, Bug Report

Jan 27 2021

leder added a comment to T5083: usecase for --detach-sign as the default signature creation method.

provided Info by comment from 20201003: please remove Tag "Info needed (Backlog)"!

Jan 27 2021, 12:44 PM · Info Needed, Feature Request

Jan 23 2021

gouttegd closed T4659: Release Pinentry-1.1.1, a subtask of T3428: pinentry-curses should be able to avoid showing *s when user enters passphrase, as Resolved.
Jan 23 2021, 11:22 PM · pinentry, Feature Request
Denisov23 closed T5092: Translate Gnupg in Italian as Resolved.
Jan 23 2021, 5:55 PM · gnupg, i18n, Feature Request
Denisov23 added projects to T5171: Wish: in GPA add other types of keys such as Kleopatra: gpa, Feature Request.
Jan 23 2021, 5:54 PM · Feature Request, gpa
Denisov23 added a comment to T5092: Translate Gnupg in Italian.

Hi,
you can close this tickets, the Italian translation has already been uploaded successfully. Don't import anything to GnuPG. Thanks a lot!

Jan 23 2021, 5:52 PM · gnupg, i18n, Feature Request

Jan 22 2021

werner raised the priority of T3211: [website] Atom/RSS feed for releases, news and/or blog from Wishlist to Normal.
Jan 22 2021, 12:04 PM · Feature Request

Jan 18 2021

werner moved T4951: Support point compression in Libgcrypt from For 1.9 to For 1.10 on the libgcrypt board.
Jan 18 2021, 7:05 PM · Feature Request, libgcrypt
werner moved T4873: Enable AES GCM in FIPS mode from FIPS to For 1.10 on the libgcrypt board.
Jan 18 2021, 7:04 PM · FIPS, libgcrypt, Feature Request
werner removed a subtask for T1303: Please support GCRYSEXP_FMT_BASE64: T4294: Release Libgcrypt 1.9.0.
Jan 18 2021, 7:02 PM · Feature Request, libgcrypt
gouttegd closed T3428: pinentry-curses should be able to avoid showing *s when user enters passphrase as Resolved.

No disagreement after more than a year, I think it’s fair to say that either everybody is fine with that feature being only present in the -qt, -tqt, -gtk, and -curses pinentries, or that nobody cares. :) Closing now, will be part of the upcoming pinentry-1.1.1.

Jan 18 2021, 2:04 PM · pinentry, Feature Request

Jan 12 2021

werner moved T4584: --quick-sign-key offers no way to override a current certification from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 12 2021, 11:05 AM · Restricted Project, gnupg (gpg22), Feature Request
werner added a project to T4584: --quick-sign-key offers no way to override a current certification: Restricted Project.
Jan 12 2021, 8:05 AM · Restricted Project, gnupg (gpg22), Feature Request
werner raised the priority of T4584: --quick-sign-key offers no way to override a current certification from Normal to High.
Jan 12 2021, 8:04 AM · Restricted Project, gnupg (gpg22), Feature Request

Jan 11 2021

aheinecke edited projects for T4699: X.509 certificate request more comfortable, added: Restricted Project; removed g10code.
Jan 11 2021, 10:55 AM · Restricted Project, kleopatra, S/MIME, gpg4win, Feature Request

Jan 8 2021

aheinecke added a project to T4699: X.509 certificate request more comfortable: g10code.
Jan 8 2021, 4:31 PM · Restricted Project, kleopatra, S/MIME, gpg4win, Feature Request
gniibe added a comment to T4951: Support point compression in Libgcrypt.

Reading compressed point (in keys) is supported (except for NIST P-224). When curve point is represented in compressed format, it is correctly interpreted now. So, for example, I think that with 1.9.0, gpgsm can handle certificate which uses compressed format in its curve point representation.

Jan 8 2021, 2:09 AM · Feature Request, libgcrypt

Jan 7 2021

werner moved T4873: Enable AES GCM in FIPS mode from For 1.9 to FIPS on the libgcrypt board.
Jan 7 2021, 5:59 PM · FIPS, libgcrypt, Feature Request
werner moved T4951: Support point compression in Libgcrypt from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:42 AM · Feature Request, libgcrypt
werner moved T4873: Enable AES GCM in FIPS mode from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:40 AM · FIPS, libgcrypt, Feature Request
werner claimed T4926: Add API to map a curve name to its canonical OID..
Jan 7 2021, 11:30 AM · Feature Request, libgcrypt
werner added a comment to T4951: Support point compression in Libgcrypt.

What is the state of this bug? Reading is implemented - do we really need writing (maybe to support certain smartcards)?

Jan 7 2021, 11:29 AM · Feature Request, libgcrypt
werner added a subtask for T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297): T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner added a parent task for T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452): T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner lowered the priority of T1303: Please support GCRYSEXP_FMT_BASE64 from Normal to Wishlist.
Jan 7 2021, 9:14 AM · Feature Request, libgcrypt

Jan 6 2021

rupor-github added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

I wrote https://github.com/rupor-github/win-gpg-agent to simplify usage on Windows until this issue is resolved - it handles various edge cases on Windows.

Jan 6 2021, 7:25 PM · Not A Bug, workaround, gnupg24, Windows, ssh

Jan 5 2021

werner added a comment to T3505: Port GPGME's Python bindings to Windows.

The C++, CL, Javascript and QT Bindings are all written by hand.

Jan 5 2021, 4:06 PM · Feature Request, gpgme, Python
bernhard added a comment to T3505: Port GPGME's Python bindings to Windows.

Hi Werner,

we do it for the other bindings as well.

can you elaborate?

Jan 5 2021, 3:01 PM · Feature Request, gpgme, Python
werner lowered the priority of T3505: Port GPGME's Python bindings to Windows from High to Normal.

Given all the resources we had put on this Python bindings I'd suggest to bite the bullet and replace Swig by handcrafted bindings. More work but we do it for the other bindings as well.

Jan 5 2021, 10:59 AM · Feature Request, gpgme, Python
werner lowered the priority of T4695: Remove SERIALNO as an identifier to select keys from High to Normal.

I think we can close this one, right?

Jan 5 2021, 10:54 AM · Restricted Project, Feature Request, gnupg
wiktor-k added a comment to T4694: manage first-party attestations.

For the context of all subscribed parties I think Werner refers to what Hockeypuck is doing: https://lists.gnupg.org/pipermail/gnupg-users/2020-December/064441.html

Jan 5 2021, 10:45 AM · Keyserver, Feature Request
werner lowered the priority of T4694: manage first-party attestations from High to Low.

Meanwhile there are simpler ideas and code on how to do only authenticated uploads. Thus lowering the prio.

Jan 5 2021, 10:41 AM · Keyserver, Feature Request
werner triaged T5060: Feature to migrate a card based to a file based key pair as Normal priority.
Jan 5 2021, 9:36 AM · gnupg24, gnupg (gpg23), Feature Request
werner triaged T4961: ship gpgrt.pc as Normal priority.
Jan 5 2021, 9:34 AM · Feature Request, gpgrt

Jan 1 2021

scratchmex added a comment to T3808: Unable to safely delete IDs with shared secret keys.

Actually this isn't really a special case when you want to migrate your existing ssh keys to gpg and import them. As stated in this guide https://opensource.com/article/19/4/gpg-subkeys-ssh-multiples, what you need to do currently is export the master key with its private keys, delete the imported ssh key from your keyring and then import your private keys again.

Jan 1 2021, 3:08 PM · Feature Request

Dec 21 2020

werner closed T4788: System wide configuration of the GnuPG system as Resolved.
Dec 21 2020, 7:40 PM · gnupg (gpg23), Feature Request, gpg4win, g10code

Dec 18 2020

ikloecker changed the status of T5138: Change Reset Code not working in Kleopatra from Open to Testing.

Werner, please retest. If "Change Reset Code" still doesn't work for you, then please answer the questions in the first comment.

Dec 18 2020, 12:19 PM · Feature Request, Bug Report, kleopatra
ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

Note: Officially, Kleopatra does not support OpenPGP v1 cards. At least, according to the text that is displayed if no card is found.

Dec 18 2020, 12:15 PM · Feature Request, Bug Report, kleopatra
ikloecker added a comment to T5138: Change Reset Code not working in Kleopatra.

"Change Reset Code" should work in Kleopatra. At least for OpenPGP v2+ cards. Kleopatra simply does "SCD PASSWD --reset OPENPGP.2", i.e. the same as gpg-card. I have verified that it works with a Yubikey.

Dec 18 2020, 11:11 AM · Feature Request, Bug Report, kleopatra

Dec 16 2020

gniibe reopened T4563: gpg-agent fails to sign request of PKISSH as "Open".
Dec 16 2020, 1:43 AM · Feature Request, gpgagent
gniibe closed T4563: gpg-agent fails to sign request of PKISSH as Wontfix.
Dec 16 2020, 1:42 AM · Feature Request, gpgagent
gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

If your problem is the incompatibility between standard OpenSSH (server) and PKIXSSH (client) for use of ssh-agent emulation of gpg-agent with ECDSA key, I'd suggest to apply following patch to your PKIXSSH:

diff --git a/compat.c b/compat.c
index fe71951..0c9b1ef 100644
--- a/compat.c
+++ b/compat.c
@@ -245,7 +245,6 @@ xkey_compatibility(const char *remote_version) {
 {	static sshx_compatibility info[] = {
 		{ 0, "OpenSSH*PKIX[??.*" /* 10.+ first correct */ },
 		{ 0, "OpenSSH*PKIX[X.*" /* developlement */ },
-		{ 1, "OpenSSH*" /* PKIX pre 10.0 */ },
 		{ 1, "SecureNetTerm-3.1" /* same as PKIX pre 10.0 */},
 		{ 0, NULL } };
 	p = xkey_compatibility_find(remote_version, info);
Dec 16 2020, 12:58 AM · Feature Request, gpgagent

Dec 14 2020

gniibe added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Unfortunately and confusingly, PKISSH returns "OpenSSH" when asked by "ssh -V".
Please install real OpenSSH, if this is the case for you.

Dec 14 2020, 10:52 AM · Feature Request, gpgagent
idl0r added a comment to T4563: gpg-agent fails to sign request of PKISSH.

Quote from IRC:
hey, i've some problems with my smartcard since quite some time. i'm not sure whether it's openssh related or gnupg. it's a openpgpcard v2.0 and i have to workaround ssh logins by using "SSH_AUTH_SOCK=0 ssh ...". .gnupg/gpg-agent.conf -

the debug log: esp. "ssh sign request failed: Unknown option <GPG Agent>" and ssh says "sign_and_send_pubkey: signing failed: agent refused operation"
gpg --edit-card and --card-status works fine and sign/encrypt works fine as well. only ssh auth fails
openssh 8.1_p1, gnupg 2.2.20

Dec 14 2020, 10:31 AM · Feature Request, gpgagent