Page MenuHome GnuPG
Feed Advanced Search

Today

werner closed T7792: Adding four additional options after selecting Kyber (encrypt only) when using addkey as Resolved.

Thanks for reporting/requesting.

Mon, Aug 25, 4:53 PM · PQC, gnupg26, Feature Request
werner triaged T7791: encryption fails with "Invalid Length" error when using Kyber1024 keys as High priority.
Mon, Aug 25, 4:34 PM · PQC, gnupg26, Bug Report
werner triaged T7792: Adding four additional options after selecting Kyber (encrypt only) when using addkey as Normal priority.
Mon, Aug 25, 4:30 PM · PQC, gnupg26, Feature Request

Thu, Aug 21

werner closed T7788: Invalid selection in addkey as Resolved.
Thu, Aug 21, 11:43 AM · gnupg26, Bug Report
werner triaged T7788: Invalid selection in addkey as Low priority.
Thu, Aug 21, 11:43 AM · gnupg26, Bug Report
werner merged T7787: Support exporting for of Kyber+ECC keys and subkeys into T7315: Allow exporting of PQC keys..
Thu, Aug 21, 11:19 AM · gnupg26, OpenPGP, PQC, gnupg
werner renamed T7787: Support exporting for of Kyber+ECC keys and subkeys from Cannot export secret keys to Support exporting for of Kyber+ECC keys and subkeys.
Thu, Aug 21, 11:17 AM
werner triaged T7787: Support exporting for of Kyber+ECC keys and subkeys as Normal priority.

Well, I will re-use this as a feature request to add this feature. Workaround is to list the key with --with-keygrip and backup the ~/.gnupg/private-keys-v1.d/<keygrip>.key files.

Thu, Aug 21, 11:16 AM

Fri, Aug 15

ebo moved T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive from Backlog to WIP on the gpd5x board.
Fri, Aug 15, 12:07 PM · gnupg26, gpd5x, kleopatra

Wed, Aug 13

ebo triaged T7755: Kleopatra: Show error if a certification did not succeed, even if the cause is crash of background process as Low priority.

We decided that gpg should emit a status message for success, too.
gpgme should then look for that status message instead of only absence of error.

Wed, Aug 13, 2:35 PM · gnupg, gpgme, gpd5x, kleopatra
werner added a comment to T7759: Kleopatra: Notepad encryption with S/MIME fails.

A quick check with passing ASSUAN_PIPE_CONNECT_DETACHED does not changed anything.

Wed, Aug 13, 9:54 AM · gnupg26, gpgme, kleopatra, gpd5x

Tue, Aug 12

werner added a comment to T7759: Kleopatra: Notepad encryption with S/MIME fails.

I wonder whether rA3bccb33ccd9028ff505d9979fd6c8a37393b892d which changes Assuan's waitpid function for Windows is well aligned with the my_waitpid in gpgme's assuan-support.c (which does nothing). gpgme creates a detached process in most cases but for gpgsm assuan_pipe_connect is used without the ASSUAN_PIPE_CONNECT_DETACHED flag.

Tue, Aug 12, 11:12 AM · gnupg26, gpgme, kleopatra, gpd5x
werner added a comment to T7759: Kleopatra: Notepad encryption with S/MIME fails.

Another data point is that the faulty versions use libassuan 3 with a slightly changed API. May one of the follwing chnages cause the problem?

Tue, Aug 12, 10:51 AM · gnupg26, gpgme, kleopatra, gpd5x

Mon, Aug 11

ebo added a comment to T7759: Kleopatra: Notepad encryption with S/MIME fails.

Although in VSD 3.2.2 we get no warning when configuring S/MIME debugging wrong we then get a nice message "Configuration error" when trying to encrypt with S/MIME, instead of gpgsm hanging without any message at all:

Mon, Aug 11, 5:23 PM · gnupg26, gpgme, kleopatra, gpd5x

Fri, Aug 8

ebo added a comment to T7759: Kleopatra: Notepad encryption with S/MIME fails.

The issue also occurs in VSD-3.3.2 and 4win-4.4.1 but not in VSD 3.1.26

Fri, Aug 8, 2:20 PM · gnupg26, gpgme, kleopatra, gpd5x
werner triaged T7759: Kleopatra: Notepad encryption with S/MIME fails as High priority.
Fri, Aug 8, 6:33 AM · gnupg26, gpgme, kleopatra, gpd5x

Thu, Aug 7

werner placed T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server up for grabs.
Thu, Aug 7, 12:04 PM · gnupg22, gnupg26, Feature Request, gpd5x

Mon, Aug 4

werner lowered the priority of T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive from Unbreak Now! to Normal.
Mon, Aug 4, 8:09 PM · gnupg26, gpd5x, kleopatra
werner changed the status of T7742: Extend the LDAP scheme for non-NTDS installations from Open to Testing.
Mon, Aug 4, 6:13 PM · dirmngr, LDAP, gnupg26
werner added a comment to T7742: Extend the LDAP scheme for non-NTDS installations.

The advantage of using a fingerprint for referencing a key is that there won't be any collisions in the keyid. Further this unifies the schema with an LDS (Windows) installation where DNs must anyway be unique. But take care the client needs to support this new flag. This will be the case for gnupg >= 2.5.12 (cf. T7756)

Mon, Aug 4, 6:05 PM · dirmngr, LDAP, gnupg26
werner removed a project from T5447: Add feature to delete a key from an LDAP server: Restricted Project.
Mon, Aug 4, 12:10 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner moved T5447: Add feature to delete a key from an LDAP server from QA to Done on the gnupg26 board.
Mon, Aug 4, 12:10 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner moved T5447: Add feature to delete a key from an LDAP server from Backlog to QA on the gnupg22 board.
Mon, Aug 4, 12:10 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner added a project to T5447: Add feature to delete a key from an LDAP server: gnupg22.
Mon, Aug 4, 12:09 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner moved T5447: Add feature to delete a key from an LDAP server from WiP to vsd-3.3.3 on the vsd33 board.
Mon, Aug 4, 12:09 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
gniibe added a comment to T7649: gnupg: Use KEM interface for encryption/decryption.

Applied the change above.

Mon, Aug 4, 11:19 AM · gnupg26
gniibe added a comment to T7649: gnupg: Use KEM interface for encryption/decryption.

I realized that I enbugged in rG5efabec21883: gpg:ecc: Use the common function of gnupg_get_ecc_params..
It has been regression since 2.5.9.

Mon, Aug 4, 9:39 AM · gnupg26

Fri, Aug 1

werner moved T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive from WIP to Done on the gnupg26 board.

Test on Windows by overwriting gpgtar from gpg4win-5.0.0-beta357 and also tested on Linux. Debian packages with patches are already available.

Fri, Aug 1, 4:39 PM · gnupg26, gpd5x, kleopatra
werner changed the status of T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from Open to Testing.
Fri, Aug 1, 4:37 PM · gnupg22, gnupg26, Feature Request, gpd5x
werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from Backlog to WIP on the gnupg26 board.
Fri, Aug 1, 4:19 PM · gnupg22, gnupg26, Feature Request, gpd5x
werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from Backlog to WIP on the gpd5x board.

There is a new --keyserver-option update-before-send which is enabled by default.

Fri, Aug 1, 4:18 PM · gnupg22, gnupg26, Feature Request, gpd5x

Thu, Jul 31

werner changed the status of T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive from Open to Testing.
Thu, Jul 31, 11:35 AM · gnupg26, gpd5x, kleopatra
werner claimed T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive.
Thu, Jul 31, 10:51 AM · gnupg26, gpd5x, kleopatra

Wed, Jul 30

werner added a project to T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive: gnupg26.
Wed, Jul 30, 7:49 PM · gnupg26, gpd5x, kleopatra
ebo closed T7709: Decryption with ECC smartcard keys broken as Resolved.
Wed, Jul 30, 1:46 PM · gnupg26, Bug Report, gpd5x
ebo closed T7709: Decryption with ECC smartcard keys broken, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, as Resolved.
Wed, Jul 30, 1:46 PM · gnupg26
ebo moved T7709: Decryption with ECC smartcard keys broken from WIP to Done on the gpd5x board.

tested with Gpg4win-5.0.0-beta357 (GnuPG 2.5.11):

Wed, Jul 30, 1:46 PM · gnupg26, Bug Report, gpd5x
werner closed T7719: Release GnuPG 2.5.10 as Resolved.

Note that 2.5.11 fixes a regression in 2.5.10 regarding the use of notations for 3rd party signatures. See T7743

Wed, Jul 30, 11:06 AM · Release Info, gnupg, gnupg26

Tue, Jul 29

werner added a comment to T7709: Decryption with ECC smartcard keys broken.

The card returned these 32 bytes:

1883ba0d1cacda6f357ad9caa062ebd7b3a07291a7788565caf38973bf414286

agent_card_pkdecrypt however returned 33 bytes:

411883ba0d1cacda6f357ad9caa062ebd7b3a07291a7788565caf38973bf414286

Thus the indicator byte is 0x41. The specs (librepgp, rfc4880bis) say:

Tue, Jul 29, 3:26 PM · gnupg26, Bug Report, gpd5x

Jul 25 2025

werner moved T5447: Add feature to delete a key from an LDAP server from WIP to QA on the gnupg26 board.
Jul 25 2025, 5:30 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner moved T7709: Decryption with ECC smartcard keys broken from WIP to QA on the gnupg26 board.
Jul 25 2025, 5:29 PM · gnupg26, Bug Report, gpd5x
werner changed the status of T7719: Release GnuPG 2.5.10 from Open to Testing.
Jul 25 2025, 5:28 PM · Release Info, gnupg, gnupg26
werner updated the task description for T7719: Release GnuPG 2.5.10.
Jul 25 2025, 5:27 PM · Release Info, gnupg, gnupg26
werner moved T5447: Add feature to delete a key from an LDAP server from Backlog to WiP on the vsd33 board.
Jul 25 2025, 3:29 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner moved T5447: Add feature to delete a key from an LDAP server from Backlog to WIP on the gnupg26 board.
Jul 25 2025, 3:04 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner changed the status of T5447: Add feature to delete a key from an LDAP server from Open to Testing.
Jul 25 2025, 3:04 PM · gnupg22, vsd33 (vsd-3.3.3), gnupg26, LDAP
werner triaged T7742: Extend the LDAP scheme for non-NTDS installations as Normal priority.
Jul 25 2025, 2:07 PM · dirmngr, LDAP, gnupg26
werner triaged T7620: gpgme_get_key fails to detect secret encryption subkey after key generation on card (until context is recreated) as Normal priority.
Jul 25 2025, 10:32 AM · gnupg26, gnupg, Bug Report

Jul 17 2025

werner moved T7709: Decryption with ECC smartcard keys broken from Backlog to WIP on the gpd5x board.
Jul 17 2025, 9:12 AM · gnupg26, Bug Report, gpd5x
werner changed the status of T7709: Decryption with ECC smartcard keys broken, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, from Open to Testing.
Jul 17 2025, 9:12 AM · gnupg26
werner changed the status of T7709: Decryption with ECC smartcard keys broken from Open to Testing.
Jul 17 2025, 9:12 AM · gnupg26, Bug Report, gpd5x
gniibe added a parent task for T7709: Decryption with ECC smartcard keys broken: T7649: gnupg: Use KEM interface for encryption/decryption.
Jul 17 2025, 4:24 AM · gnupg26, Bug Report, gpd5x
gniibe added a subtask for T7649: gnupg: Use KEM interface for encryption/decryption: T7709: Decryption with ECC smartcard keys broken.
Jul 17 2025, 4:24 AM · gnupg26

Jul 16 2025

werner triaged T7728: Support Yubikey attestation certificates as Normal priority.
Jul 16 2025, 3:18 PM · Feature Request, yubikey, gnupg26
gniibe added a comment to T7709: Decryption with ECC smartcard keys broken.

Here is a patch.

diff --git a/agent/divert-scd.c b/agent/divert-scd.c
index 1e5de4671..bb42dd3b4 100644
--- a/agent/divert-scd.c
+++ b/agent/divert-scd.c
@@ -517,6 +517,9 @@ agent_card_ecc_kem (ctrl_t ctrl, const unsigned char *ecc_ct,
Jul 16 2025, 12:09 PM · gnupg26, Bug Report, gpd5x
werner closed T7083: Show revocation reasons also with a standard -k listing as Resolved.
Jul 16 2025, 12:04 PM · OpenPGP, Feature Request, gnupg26
werner closed T6599: INT2FD and npth_accept, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Jul 16 2025, 12:03 PM · Windows 64, Feature Request, gnupg26
werner closed T6599: INT2FD and npth_accept as Resolved.

Several releases since the last commit and no specific bug reports. We can close this task.

Jul 16 2025, 12:03 PM · Windows 64, Feature Request, gnupg26
werner lowered the priority of T7292: gpg-mail-tube: Add more features from Normal to Low.
Jul 16 2025, 12:00 PM · Feature Request, gnupg26
werner lowered the priority of T6956: GnuPG: Allow import of gpgsk files from Normal to Low.
Jul 16 2025, 12:00 PM · gnupg26, Feature Request, Restricted Project
werner moved T7649: gnupg: Use KEM interface for encryption/decryption from Backlog to WIP on the gnupg26 board.
Jul 16 2025, 11:58 AM · gnupg26
werner closed T7698: Add support of secp256k1 for KEM API, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, as Resolved.
Jul 16 2025, 11:58 AM · gnupg26
werner closed T7698: Add support of secp256k1 for KEM API as Resolved.

Should be fixed with 2.5.9. Given that secp256 is an esoteric curve for GnuPG it does not make sense to run the entire QA process.

Jul 16 2025, 11:58 AM · gnupg26
werner closed T7289: Release GnuPG 2.5.2 as Resolved.
Jul 16 2025, 11:55 AM · gnupg, Release Info, gnupg26
werner moved T7676: Cannot decrypt a message encrypted to a Cv25519 key on a token from WIP to QA on the gnupg26 board.
Jul 16 2025, 11:54 AM · gnupg26, Bug Report
werner moved T7693: `gpg --fetch-keys` fails because of missing keyserver from WIP to QA on the gnupg26 board.
Jul 16 2025, 11:54 AM · gnupg26
werner added a project to T7709: Decryption with ECC smartcard keys broken: gnupg26.
Jul 16 2025, 11:42 AM · gnupg26, Bug Report, gpd5x

Jul 10 2025

werner triaged T7719: Release GnuPG 2.5.10 as Normal priority.
Jul 10 2025, 4:27 PM · Release Info, gnupg, gnupg26

Jul 8 2025

werner closed T7715: Dirmngr shall send a User-Agent header as Resolved.
Jul 8 2025, 3:46 PM · Feature Request, gnupg26
werner triaged T7715: Dirmngr shall send a User-Agent header as Normal priority.
Jul 8 2025, 9:50 AM · Feature Request, gnupg26

Jul 3 2025

collinfunk added a comment to T6598: Fix FD2INT for 64-bit Windows.

Can't you just use file descriptors everywhere and use _get_osfhandle once you need a HANDLE. That is what I am used to seeing in Windows code in Gnulib (although I do not touch it much).

Jul 3 2025, 4:23 AM · Windows 64, Feature Request, gnupg26

Jul 2 2025

werner reopened T6598: Fix FD2INT for 64-bit Windows as "Open".

Regarding 64bit handles https://learn.microsoft.com/en-us/windows/win32/winprog64/interprocess-communication
tells us:

Jul 2 2025, 4:41 PM · Windows 64, Feature Request, gnupg26
werner reopened T6598: Fix FD2INT for 64-bit Windows, a subtask of T6508: Port GnuPG to 64-bit Windows, as Open.
Jul 2 2025, 4:41 PM · Windows 64, Feature Request, gnupg26
werner triaged T7713: Allow to skip the qualified signature confirmation prompt as Normal priority.
Jul 2 2025, 11:41 AM · S/MIME, Feature Request, gnupg26
werner triaged T7710: Kleopatra: Paperkey can't handle curve448/kyber keys as Normal priority.

This seems to be a good opportunity to replace paperkey with a new tool to take advantage of the smaller ECC keys which allow us to re-generate most stuff.

Jul 2 2025, 9:14 AM · Feature Request, gnupg26, kleopatra

Jun 26 2025

gniibe changed the status of T7698: Add support of secp256k1 for KEM API, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, from Open to Testing.
Jun 26 2025, 6:49 AM · gnupg26
gniibe changed the status of T7698: Add support of secp256k1 for KEM API from Open to Testing.
Jun 26 2025, 6:49 AM · gnupg26

Jun 25 2025

gniibe triaged T7698: Add support of secp256k1 for KEM API as High priority.
Jun 25 2025, 3:19 AM · gnupg26

Jun 24 2025

werner added a comment to T7649: gnupg: Use KEM interface for encryption/decryption.

secp256k1 is an --expert option and not supported by other *PGP
implementations. We should actually hide this thing even more and not
even display it with --expert. Thus do no expect an immediate 2.5.9
release to fix this issue.

Jun 24 2025, 8:20 AM · gnupg26
gniibe added a comment to T7649: gnupg: Use KEM interface for encryption/decryption.

secp256k1 failure:
https://lists.gnupg.org/pipermail/gnupg-users/2025-June/067731.html

Jun 24 2025, 8:07 AM · gnupg26

Jun 18 2025

werner closed T6551: translate_sys2libc_fd_int on Windows 64-bit, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Jun 18 2025, 9:45 AM · Windows 64, Feature Request, gnupg26
werner closed T6551: translate_sys2libc_fd_int on Windows 64-bit as Resolved.
Jun 18 2025, 9:45 AM · Windows 64, Feature Request, gnupg26
werner closed T6508: Port GnuPG to 64-bit Windows as Resolved.

After several gpg4win-5 betas be can set this task to resolved.

Jun 18 2025, 9:44 AM · Windows 64, Feature Request, gnupg26
werner closed T6580: Use gnupg_fd_t if it's relevant, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Jun 18 2025, 9:43 AM · Windows 64, Feature Request, gnupg26
werner closed T6580: Use gnupg_fd_t if it's relevant as Resolved.

I claim this resolved given several gpg4win-5 betas.

Jun 18 2025, 9:43 AM · Windows 64, Feature Request, gnupg26
werner closed T6598: Fix FD2INT for 64-bit Windows, a subtask of T6508: Port GnuPG to 64-bit Windows, as Resolved.
Jun 18 2025, 9:42 AM · Windows 64, Feature Request, gnupg26
werner closed T6598: Fix FD2INT for 64-bit Windows as Resolved.

I claim this resolved given that we had several gpg4win-5 betas and no reported problems was related to this.

Jun 18 2025, 9:42 AM · Windows 64, Feature Request, gnupg26
werner added a subtask for T6465: Store the ECDH parameters in the key file: T5583: Support RSCS dedicated OpenPGP for OID..
Jun 18 2025, 9:39 AM · gnupg26, OpenPGP, scd, Bug Report
werner added a parent task for T5583: Support RSCS dedicated OpenPGP for OID.: T6465: Store the ECDH parameters in the key file.
Jun 18 2025, 9:39 AM · gnupg26, Restricted Project, scd
werner lowered the priority of T5583: Support RSCS dedicated OpenPGP for OID. from Normal to Low.

Reminder mostly to self: This is about the KDF parameters. In the light of PQC composite algorithms we may want to also prepare for PQC required stuff.

Jun 18 2025, 9:36 AM · gnupg26, Restricted Project, scd
werner added a comment to T7653: Fix gpg's passwd for Kyber with the ecc part on a card.

There should be a workaround by using

Jun 18 2025, 9:32 AM · Bug Report, gnupg26
werner moved T7676: Cannot decrypt a message encrypted to a Cv25519 key on a token from Backlog to WIP on the gnupg26 board.
Jun 18 2025, 9:30 AM · gnupg26, Bug Report
werner closed T7014: agent: Enhancement of PKDECRYPT for KEM interface, a subtask of T6815: PQC encryption for GnuPG, as Resolved.
Jun 18 2025, 9:29 AM · gnupg26, OpenPGP, PQC, gnupg
werner closed T7014: agent: Enhancement of PKDECRYPT for KEM interface as Resolved.

This was release with 2.5.7.

Jun 18 2025, 9:29 AM · gnupg26, gpgagent, Feature Request
werner closed T7014: agent: Enhancement of PKDECRYPT for KEM interface, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, as Resolved.
Jun 18 2025, 9:29 AM · gnupg26

Jun 17 2025

werner changed the status of T7693: `gpg --fetch-keys` fails because of missing keyserver from Open to Testing.

Funny old bug which shows up only if you don't have any keyserver configured. Note the FIXME in the commit ;-)

Jun 17 2025, 6:37 PM · gnupg26
m.eik created T7693: `gpg --fetch-keys` fails because of missing keyserver.
Jun 17 2025, 4:03 PM · gnupg26
gniibe closed T5964: gnupg should use the KDFs implemented in libgcrypt, a subtask of T7649: gnupg: Use KEM interface for encryption/decryption, as Resolved.
Jun 17 2025, 2:38 AM · gnupg26
gniibe closed T5964: gnupg should use the KDFs implemented in libgcrypt as Resolved.
Jun 17 2025, 2:38 AM · gnupg26, FIPS, Feature Request

Jun 11 2025

werner added a comment to T7676: Cannot decrypt a message encrypted to a Cv25519 key on a token.

I stumbled into this problems myself yesterday. Time for a new release.

Jun 11 2025, 11:24 AM · gnupg26, Bug Report