Page MenuHome GnuPG
Feed Advanced Search

Today

timegrid added a comment to T8052: GnuPG: First listing of secret keys is empty.

To reproduce the hang, a loop will suffice (usually happens within the first 15 times, once it needed 50 runs):

Mon, Jan 26, 11:39 AM · Bug Report, gpgagent, gpd5x, gnupg26
timegrid added a comment to T8053: GpgSM: `log-file` is ignored.

There's no other configuration, this happens with a clean gnupghome with one smime cert + root cert and the above gpgsm.conf (output on stdin/stderr):

Mon, Jan 26, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26

Fri, Jan 23

werner added a comment to T8053: GpgSM: `log-file` is ignored.

Please run with --debug 0 which should show you which confiration files are read in which order. Is there anything in a common.conf file? A log-file statement tehre would overwrite the command line option.

Fri, Jan 23, 9:16 PM · gpd5x, Bug Report, S/MIME, gnupg26
ebo created T8054: Key expiration year during key creation only shown with 2 digits.
Fri, Jan 23, 3:48 PM · gnupg26
timegrid updated the task description for T8052: GnuPG: First listing of secret keys is empty.
Fri, Jan 23, 2:43 PM · Bug Report, gpgagent, gpd5x, gnupg26
timegrid created T8053: GpgSM: `log-file` is ignored.
Fri, Jan 23, 2:28 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid added a project to T8052: GnuPG: First listing of secret keys is empty: Bug Report.
Fri, Jan 23, 2:22 PM · Bug Report, gpgagent, gpd5x, gnupg26
timegrid created T8052: GnuPG: First listing of secret keys is empty.
Fri, Jan 23, 2:14 PM · Bug Report, gpgagent, gpd5x, gnupg26
timegrid removed a project from T6545: Support CRL extension issuingDistributionPoint: gnupg22.
Fri, Jan 23, 11:49 AM · workaround, gnupg26, Restricted Project, libksba, Feature Request
timegrid edited projects for T6436: Double pinentry on change password, added: gpd5x; removed gnupg22, Restricted Project.
Fri, Jan 23, 11:47 AM · gpd5x, gnupg26, Feature Request
timegrid changed the edit policy for T6677: GPGSM: Add support for cert extension 2.5.29.36 Policy Constraints.
Fri, Jan 23, 11:19 AM · Feature Request, gnupg26, S/MIME

Wed, Jan 21

ebo raised the priority of T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys from Normal to High.

setting to High as we need this for T7790

Wed, Jan 21, 11:40 AM · Feature Request, S/MIME, OpenPGP, gnupg26
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

The "ca" root cert is not on the ldap, if that matters

Wed, Jan 21, 10:23 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from GnuPG: S/MIME certificate is imported on ldap search to Keyboxd: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:14 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

some other certificates, but I guess those are from other tests

Wed, Jan 21, 10:08 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a project to T8048: Keyboxd: S/MIME certificate is imported on ldap search: Bug Report.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from Kleopatra: S/MIME certificate is imported on ldap search to GnuPG: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x

Mon, Jan 19

thesamesam added a comment to T7990: export-minimal unexpectedly omits expired key.

It works well for us. Thanks again.

Mon, Jan 19, 7:05 AM · gnupg26, Feature Request, Gentoo

Thu, Jan 15

ikloecker renamed T8029: IPC error on batch import of secret kyber cert from Kleopatra: IPC error on import of secret kyber cert to IPC error on batch import of secret kyber cert.
Thu, Jan 15, 10:38 AM · gnupg26, Bug Report, gpd5x, kleopatra

Tue, Jan 13

ikloecker added a project to T8029: IPC error on batch import of secret kyber cert: gnupg26.

@werner: gpg fails to batch import secret Kyber keys:

$ GNUPGHOME=/home/ingo/dev/g10/.gnupghomes/empty gpg --batch --import --verbose ~/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc 
gpg: WARNING: unsafe permissions on homedir '/home/ingo/dev/g10/.gnupghomes/empty'
gpg: enabled compatibility flags:
gpg: sec  brainpoolP256r1/DD89C34EF2B69576 2024-11-14  Kyber768 <kyber768@example.net>
gpg: using pgp trust model
gpg: key DD89C34EF2B69576: public key "Kyber768 <kyber768@example.net>" imported
gpg: key DD89C34EF2B69576/DD89C34EF2B69576: secret key imported
gpg: key DD89C34EF2B69576/D07DD3BF9F1AAF4F: error sending to agent: IPC parameter error
gpg: error reading '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc': IPC parameter error
gpg: import from '/home/ingo/dev/g10/testdata/exported/Kyber768_0xDD89C34EF2B69576_SECRET.asc' failed: IPC parameter error
gpg: Total number processed: 0
gpg:               imported: 1
gpg:       secret keys read: 1
Tue, Jan 13, 2:27 PM · gnupg26, Bug Report, gpd5x, kleopatra
ebo edited projects for T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:48 PM · gpd5x (gpd-5.0.0), gnupg26, kleopatra
ebo edited projects for T1825: Add a re-encrypt to additional key, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:46 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
ebo edited projects for T7709: Decryption with ECC smartcard keys broken, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:45 PM · gpd5x (gpd-5.0.0), gnupg26, Bug Report
ebo edited projects for T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:45 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
ebo edited projects for T7759: Kleopatra: Notepad encryption with S/MIME fails, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:45 PM · gpd5x (gpd-5.0.0), gnupg26, gpgme, kleopatra
ebo edited projects for T7855: keybox/keydb locking issue in 2.6 , added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:45 PM · gpd5x (gpd-5.0.0), gnupg26
ebo edited projects for T7983: gpg: the validity of a secret key is changed by making a certification with it, added: gpd5x (gpd-5.0.0); removed gpd5x.
Tue, Jan 13, 12:45 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Mon, Jan 12

werner changed the status of T8026: Kleopatra: Export of multiple S/MIME certificates only exports one from Open to Testing.
Mon, Jan 12, 4:51 PM · gnupg26, Bug Report, gpd5x
werner added a comment to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one.

Thanks Ingo. It seems 2.5.17 is not too far away.

Mon, Jan 12, 4:28 PM · gnupg26, Bug Report, gpd5x
ikloecker removed a project from T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: kleopatra.

I can reproduce this on the command line:

C:\Users\g10code>"c:\Program Files\GnuPG\bin\gpgsm.exe" --export --armor 579BAF3DF16AD462457BCC0897ADBC143D76EA7B 5A2B80F98F518D50891B1F0C7C6131AD107F9938 DB625D2BBBB5A3FD985C0233249B03090E85D402
Issuer ...: /CN=CA IVBB Deutsche Telekom AG 20/OU=Bund/O=PKI-1-Verwaltung/C=DE
Serial ...: 02195D190EBE34
Subject ..: /CN=iOS Test-Smartcard iostest01.sc/OU=BSI/O=Bund/C=DE/SerialNumber=2
    aka ..: iostest01.sc@bsi.bund.de
Keygrip ..: 527CE32FD0552D18479442EF90DD5E434C036329
Mon, Jan 12, 3:36 PM · gnupg26, Bug Report, gpd5x
ikloecker added a project to T8026: Kleopatra: Export of multiple S/MIME certificates only exports one: gnupg26.

I can reproduce the issue only (!!!) with keyboxd (on Windows).

Mon, Jan 12, 3:25 PM · gnupg26, Bug Report, gpd5x

Fri, Jan 9

werner moved T7866: Allow separate LDAP keyserver for uploading from QA to WIP on the gnupg26 board.
Fri, Jan 9, 3:50 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner changed the status of T7990: export-minimal unexpectedly omits expired key from Open to Testing.
Fri, Jan 9, 3:43 PM · gnupg26, Feature Request, Gentoo
werner added a comment to T7990: export-minimal unexpectedly omits expired key.

So w/o the new option we have:

Fri, Jan 9, 3:11 PM · gnupg26, Feature Request, Gentoo
werner triaged T7990: export-minimal unexpectedly omits expired key as High priority.
Fri, Jan 9, 2:47 PM · gnupg26, Feature Request, Gentoo
timegrid added a comment to T7866: Allow separate LDAP keyserver for uploading.

The behaviour might have changed a bit because of the ldap: prefix i use now, or i have missed this case the last time:
Given some cert on the "download" server, I can find it, if dirmngr.conf contains only the "download" server, or if the "download" server is listed first:

Fri, Jan 9, 2:17 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
ebo added a project to T7804: de-vs compliance not shown if also password encrypted: test on hold.

testing will wait for special build

Fri, Jan 9, 1:55 PM · test on hold, gnupg22 (gnupg-2.2.49), vsd33 (vsd-3.3.3), Bug Report, vsd, gnupg26
werner closed T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign. as Resolved.
Fri, Jan 9, 1:42 PM · gnupg26, Feature Request
werner closed T7298: gpg --quick-set-expire fails for V5 subkeys as Resolved.
Fri, Jan 9, 1:39 PM · gnupg24, gnupg26, Bug Report
werner moved T7298: gpg --quick-set-expire fails for V5 subkeys from QA to done on the gnupg24 board.
Fri, Jan 9, 1:38 PM · gnupg24, gnupg26, Bug Report
werner added a comment to T7866: Allow separate LDAP keyserver for uploading.

Independent of keyserver order in dirmngr.conf, --search-keys still offers keys from the upload server, but the download fails:

Fri, Jan 9, 1:35 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner added a comment to T7866: Allow separate LDAP keyserver for uploading.

For "Although the upload server is used for upload, the gpg message still displays the first keyserver" see T8025

Fri, Jan 9, 1:28 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner triaged T8025: Display the correct LDAP server in gpg if the upload flag is in use. as Normal priority.
Fri, Jan 9, 1:28 PM · Bug Report, LDAP, gnupg26
werner closed T7676: Cannot decrypt a message encrypted to a Cv25519 key on a token as Resolved.

I am using that version and key daily. No problems seen.

Fri, Jan 9, 1:25 PM · gnupg26, Bug Report
werner closed T7649: gnupg: Use KEM interface for encryption/decryption as Resolved.
Fri, Jan 9, 1:24 PM · gnupg26
timegrid closed T7893: GnuPG: Decryption fails if the pinentry dialog for the first tried recipient is canceled as Resolved.

Looks good to me on gpg4win-5.0.0-beta479 @ win11:

Fri, Jan 9, 1:18 PM · gnupg26, gnupg
ebo closed T7757: Kleopatra: Error "no data" on decryption of tar.gpg archive as Resolved.

was tested already by timegrid

Fri, Jan 9, 1:11 PM · gpd5x (gpd-5.0.0), gnupg26, kleopatra
ebo closed T7491: Confusing additional pinentry on creation of new keypair with ADSK configured as Resolved.

This does not happen any more, tested with Gpg4win-5.0.0-beta479

Fri, Jan 9, 1:09 PM · gpgagent, gnupg26, gnupg
ebo closed T7315: Allow export and import of PQC secret keys., a subtask of T6815: PQC encryption for GnuPG, as Resolved.
Fri, Jan 9, 12:29 PM · OpenPGP, PQC, gnupg
ebo closed T7315: Allow export and import of PQC secret keys. as Resolved.

Tested with Gpg4win-5.0.0-beta479

Fri, Jan 9, 12:29 PM · gnupg26, OpenPGP, PQC, gnupg
ebo closed T7914: Card s/n number missing in gpgsm as Resolved.

in Gpg4win-5.0.0-beta479

Fri, Jan 9, 12:08 PM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
ebo closed T7892: keyboxd: subkey listing issue with ADSKs as Resolved.

with Gpg4win-5.0.0-beta479 the listing after creating the new key with ADSK looks ok now:

Fri, Jan 9, 11:44 AM · gnupg26, Bug Report, keyboxd, gnupg
werner edited projects for T6421: Improve error message if no reset code (PUK) is set, added: gnupg26; removed gnupg22, gnupg24.

I think we won't fix that for 2.2

Fri, Jan 9, 11:32 AM · gnupg26, Feature Request, gpgrt
werner edited projects for T6436: Double pinentry on change password, added: gnupg26; removed gnupg24.
Fri, Jan 9, 11:28 AM · gpd5x, gnupg26, Feature Request
werner changed the status of T7840: Oddity with 7816 change_reference_data from Testing to Open.
Fri, Jan 9, 11:27 AM · Bug Report, gnupg22, gnupg26, scd
werner moved T7840: Oddity with 7816 change_reference_data from QA to Done on the gnupg26 board.
Fri, Jan 9, 11:27 AM · Bug Report, gnupg22, gnupg26, scd
werner closed T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server as Resolved.
Fri, Jan 9, 11:22 AM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from WiP to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:22 AM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
werner moved T7914: Card s/n number missing in gpgsm from WiP to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:17 AM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
werner closed T7805: Permission denied on batch deletion of mixed (openpgp+smime) certs, a subtask of T7855: keybox/keydb locking issue in 2.6 , as Resolved.
Fri, Jan 9, 11:07 AM · gpd5x (gpd-5.0.0), gnupg26

Thu, Jan 8

werner changed the status of T7892: keyboxd: subkey listing issue with ADSKs from Open to Testing.
Thu, Jan 8, 4:13 PM · gnupg26, Bug Report, keyboxd, gnupg
ebo closed T7983: gpg: the validity of a secret key is changed by making a certification with it as Resolved.
Thu, Jan 8, 3:40 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Wed, Jan 7

ebo added a comment to T8012: Missing error on first key search without keyserver.

It looks similar if the key is in a WKD: First search fails without error, only "no certificates found" is shown. Clicking "Search" again results then in the expected key being found and shown.

Wed, Jan 7, 3:14 PM · dirmngr, Bug Report, gnupg26
werner added a parent task for T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys: T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
werner triaged T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys as Normal priority.

Traditionally we have considered expired and revoked more or less similar. The idea is that an expired key might have been compromised but the owner did not found a way to revoke it. We may want to change this policy because some users don't care too much about expired keys (cf. T7990) .

Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
ikloecker added a comment to T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.

Interestingly, gpg also prints the warning about the missing trusted key signature when verifying a signature made with a revoked key that has a valid certification by a trusted key. This could be intentional (because the revocation invalidates all certifications), but it's still a bit surprising.

Wed, Jan 7, 11:42 AM · Feature Request, S/MIME, OpenPGP, gnupg26
ikloecker created T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.
Wed, Jan 7, 11:20 AM · Feature Request, S/MIME, OpenPGP, gnupg26

Tue, Jan 6

the13thletter added a comment to T8013: gpgconf does not support the --enable-win32-openssh-support option for gpg-agent.

Frankly, he OpenSSH support for Windows was experimental and I have never tested it. If it can be confirmed that this really works and is useful, it will be easy to add the opeion to gpgconf.

Tue, Jan 6, 10:04 PM · Feature Request, ssh, gnupg26, Windows
timegrid closed T1825: Add a re-encrypt to additional key as Resolved.
Tue, Jan 6, 12:57 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
werner added a comment to T1825: Add a re-encrypt to additional key.

Regarding my comment T1825#191055 : The mane page has long been updated and gpgme support is also available. For the symmetric session key, see the feature request T8016

Tue, Jan 6, 12:53 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
werner triaged T8016: Keep symmetric encryption keys with --add-recipients as Low priority.
Tue, Jan 6, 12:51 PM · gpd5x, gnupg26, Feature Request
timegrid moved T1825: Add a re-encrypt to additional key from QA to Done on the gnupg26 board.
Tue, Jan 6, 12:28 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
timegrid moved T1825: Add a re-encrypt to additional key from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11:

  • gpg --show-only-session-key --decrypt FILE shows only the session key
  • gpg --add-recipients -r UID1 FILE adds recipients (tested with one or more uids)
  • gpg --change-recipients -r UID FILE changes the recipients (tested with one or more uids)
Tue, Jan 6, 12:28 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
timegrid moved T7983: gpg: the validity of a secret key is changed by making a certification with it from QA to Done on the gnupg26 board.
Tue, Jan 6, 12:08 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
timegrid moved T7983: gpg: the validity of a secret key is changed by making a certification with it from QA to Done on the gpd5x board.

Looks good to me on gpg4win-5.0.0-beta479 @ win11.
I can't reproduce ebo's nor pl13's issue.

Tue, Jan 6, 12:07 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
ebo moved T7983: gpg: the validity of a secret key is changed by making a certification with it from Backlog to QA on the gpd5x board.
Tue, Jan 6, 11:20 AM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
ebo moved T7983: gpg: the validity of a secret key is changed by making a certification with it from Backlog to QA on the gnupg26 board.
Tue, Jan 6, 11:20 AM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
werner triaged T8013: gpgconf does not support the --enable-win32-openssh-support option for gpg-agent as Normal priority.

Frankly, he OpenSSH support for Windows was experimental and I have never tested it. If it can be confirmed that this really works and is useful, it will be easy to add the opeion to gpgconf. Note that the gpgconf option feature handles only a subset of all options on purpose.

Tue, Jan 6, 8:53 AM · Feature Request, ssh, gnupg26, Windows

Mon, Jan 5

werner triaged T8012: Missing error on first key search without keyserver as Normal priority.
Mon, Jan 5, 3:17 PM · dirmngr, Bug Report, gnupg26
timegrid created T8012: Missing error on first key search without keyserver.
Mon, Jan 5, 1:37 PM · dirmngr, Bug Report, gnupg26
timegrid moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from QA to Done on the gnupg26 board.
Mon, Jan 5, 12:54 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
timegrid moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from WIP to Done on the gpd5x board.

The problem was the keyserver configuration, which does not include a scheme (ldap:):

keyserver ldap.gnupg.test:389:uid=LordPrivySeal,ou=GnuPG Users,dc=gnupg,dc=test:pass:dc=gnupg,dc=test:
Mon, Jan 5, 12:53 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request

Dec 23 2025

werner changed the status of T7983: gpg: the validity of a secret key is changed by making a certification with it from Open to Testing.
Dec 23 2025, 12:34 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Dec 22 2025

werner triaged T7983: gpg: the validity of a secret key is changed by making a certification with it as High priority.
Dec 22 2025, 5:29 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
werner added a comment to T7983: gpg: the validity of a secret key is changed by making a certification with it.

This has likely a similar cause as T1794

Dec 22 2025, 3:14 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
pl13 added a comment to T7983: gpg: the validity of a secret key is changed by making a certification with it.

I have been able to reproduce this on linux with gnupg 2.5.14.
I had two users (named Alice and Bob in the example), each generating a key pair.
These are the steps:

  • Both users have the "use-keyboxd" option in their common.conf (i could not reproduce the bug without this option)
Dec 22 2025, 9:03 AM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Dec 18 2025

werner placed T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server up for grabs.
Dec 18 2025, 12:11 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from WIP to QA on the gnupg26 board.
Dec 18 2025, 12:11 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
werner added a comment to T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server.

Well, I tested this again. I created a new key and saved a copy. The I updated the expiration date to 2035 and sent the key to the LDAP server. Then I deleted the updated key locally and imported the old copy. Thus I have now:

Dec 18 2025, 12:09 PM · gpd5x (gpd-5.0.0), gnupg22 (gnupg-2.2.52), gnupg26, Feature Request
werner added a comment to T7983: gpg: the validity of a secret key is changed by making a certification with it.

Yesterday I was able to reproduce it once. But despite more than a dozen more tries yesterday and this morning, I could not anymore replicate it. I tested on Unix and one oddity was that I forgot to kill the keyboxd for a clean new test and thus it could serve old keys despite that the pubring.db was already deleted (but the inode still open by keyboxd).

Dec 18 2025, 10:21 AM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Dec 17 2025

ebo added a project to T7983: gpg: the validity of a secret key is changed by making a certification with it: keyboxd.
Dec 17 2025, 4:19 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
ebo added a project to T7983: gpg: the validity of a secret key is changed by making a certification with it: Bug Report.
Dec 17 2025, 4:14 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
ebo added a comment to T7983: gpg: the validity of a secret key is changed by making a certification with it.

This is really weird behavior. It seems other secret keys in the keyring may also change to "undefined" validity when the certification is done with another key. And something about the key which is certified is important.
But it can also happen that it is enough to just import a secret key without certifying anything with it for it to be shown as "undefined" validity.

Dec 17 2025, 3:04 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26
ebo created T7983: gpg: the validity of a secret key is changed by making a certification with it.
Dec 17 2025, 12:28 PM · gpd5x (gpd-5.0.0), keyboxd, Bug Report, gnupg26

Dec 16 2025

ebo renamed T7892: keyboxd: subkey listing issue with ADSKs from keyboxd: a new subkey is sometimes not stored in the fingerprint table. to keyboxd: subkey listing issue with ADSKs.
Dec 16 2025, 12:28 PM · gnupg26, Bug Report, keyboxd, gnupg
ebo moved T7892: keyboxd: subkey listing issue with ADSKs from QA to Backlog on the gnupg26 board.

This relates to T7917: Check for revocation of the ADSK's original subkey

Dec 16 2025, 12:25 PM · gnupg26, Bug Report, keyboxd, gnupg
ebo added a comment to T7892: keyboxd: subkey listing issue with ADSKs.

The expected behavior is that only "Ted" (the key from where the ADSK originates) is listed, regardless of ADSKs, on every listing.
Because for regular keys there can only ever be one, "gpg -k" shows always only one key.
Subkeys which are ADSKs shall therefore never be listed with this command.

Dec 16 2025, 12:23 PM · gnupg26, Bug Report, keyboxd, gnupg
ebo changed the status of T7892: keyboxd: subkey listing issue with ADSKs from Testing to Open.

Tested with Gpg4win-5.0.0-beta446, identically to the procedure from the description:

Dec 16 2025, 11:57 AM · gnupg26, Bug Report, keyboxd, gnupg

Dec 15 2025

timegrid edited projects for T6853: GpgTar: S/MIME decryption fails with input/output error, added: gpd5x, gnupg26; removed gnupg, Restricted Project.
Dec 15 2025, 11:17 AM · gnupg26, gpd5x, gpgtar
timegrid edited projects for T4446: please add --quick-revoke-subkey, added: gnupg26; removed Restricted Project, gnupg24.
Dec 15 2025, 11:14 AM · gnupg26, Feature Request