Page MenuHome GnuPG
Feed Advanced Search

Mar 22 2019

JJworx added a comment to T4408: Outlook and / or Exchange server mistake(s) forwarded mail for appointment request.

Yeah, that worked halfways. Meaning, if I try to send the forwarded mail
from inline / reader / docked mode, the Button lights up but no sending
happens. If I send it from undocked window, it works and the original
problem doesn't happen.

Mar 22 2019, 3:25 PM · gpgol, Bug Report

Mar 19 2019

aheinecke triaged T4411: Outlook O365 crashes at start with gpgol as Normal priority.
Mar 19 2019, 3:49 PM · gpg4win, kleopatra, gpgol, Bug Report
aheinecke added a comment to T4411: Outlook O365 crashes at start with gpgol.

see: https://wiki.gnupg.org/TroubleShooting#Manually_update_GpgOL_to_a_beta

Mar 19 2019, 3:49 PM · gpg4win, kleopatra, gpgol, Bug Report
aheinecke added a comment to T4411: Outlook O365 crashes at start with gpgol.

This is very strange, common to all the crashes in the log is that they happen while a keylisting is running and before the first key from that keylisting is returned. But this could be a red herring because the keylisting is always started immediately in a background thread and so it would be normal that if the crash occurs immediately that it would still be running. The keylisting code is extremely similar to Kleopatra though. So I don't understand why Kleopatra would then work for you.

Mar 19 2019, 3:48 PM · gpg4win, kleopatra, gpgol, Bug Report

Mar 18 2019

thome added a comment to T4411: Outlook O365 crashes at start with gpgol.

Since I configured call tracing the running O365 Client dies immediately after activating the addin. Same happens now if I activate the addin.
Anyways, here is the log.

Mar 18 2019, 4:25 PM · gpg4win, kleopatra, gpgol, Bug Report
aheinecke added a comment to T4411: Outlook O365 crashes at start with gpgol.

Thanks for the report. Log looks not unusual.

Mar 18 2019, 2:49 PM · gpg4win, kleopatra, gpgol, Bug Report
thome created T4411: Outlook O365 crashes at start with gpgol.
Mar 18 2019, 1:04 PM · gpg4win, kleopatra, gpgol, Bug Report
aheinecke claimed T4408: Outlook and / or Exchange server mistake(s) forwarded mail for appointment request.

I think that this might have the same underlying reason as the fixed T4321 (still open because it was not yet released).

Mar 18 2019, 11:15 AM · gpgol, Bug Report

Mar 15 2019

JJworx added a comment to T4408: Outlook and / or Exchange server mistake(s) forwarded mail for appointment request.

Additionally that workaround is a bad idea because on closing Outlook it
leads to the GPG4Win error "Not all plain text could be removed, it's
possible that plain text from decrypted mails was transferred to your
server." (roughly remembered text-wise)

Mar 15 2019, 4:42 PM · gpgol, Bug Report
JJworx created T4408: Outlook and / or Exchange server mistake(s) forwarded mail for appointment request.
Mar 15 2019, 3:04 PM · gpgol, Bug Report

Mar 12 2019

aheinecke created T4403: GpgOL: OpenPGP message detected but S/MIME verified / decrypted.
Mar 12 2019, 4:16 PM · gpg4win, gpgol

Mar 5 2019

florian2833z added a comment to T4388: GpgOL: Add draft encryption as an option..

Something to add: This also affects deleted drafts. If I write a new email and decide to delete & not send it, Outlook saves the aborted draft in the trash without encryption.

Mar 5 2019, 1:43 PM · Feature Request, gpg4win, gpgol
aheinecke created T4390: Kleopatra: Fall back to included filenames for files without extension.
Mar 5 2019, 9:45 AM · gpgol, kleopatra, gpg4win

Mar 4 2019

aheinecke added a subtask for T4388: GpgOL: Add draft encryption as an option.: T4389: Gpg4win 3.1.8.
Mar 4 2019, 9:38 AM · Feature Request, gpg4win, gpgol
aheinecke raised the priority of T4388: GpgOL: Add draft encryption as an option. from Wishlist to Normal.

Somehow I thought that storing drafts locally was not only configurable but the default. But you are right, I also can't find a way to change the storage location.

Mar 4 2019, 9:36 AM · Feature Request, gpg4win, gpgol
aheinecke added a comment to T4350: Attachments in Outlook.

Hi,
sorry for the late reply. I cannot reproduce the issue.

Mar 4 2019, 9:04 AM · Info Needed, gpgol, Bug Report, gpg4win
florian2833z added a comment to T4388: GpgOL: Add draft encryption as an option..

If there is a way to disable sychronisation of the draft folder in Outlook 2019 when using IMAP, it could mentioned in the meantime, but I couldnt find it.

Mar 4 2019, 9:00 AM · Feature Request, gpg4win, gpgol
aheinecke added a comment to T4184: Outlook 2013 Appointments vanish when send as a E-Mail.

Also reported for Contacts in T4161.

Mar 4 2019, 8:59 AM · gpgol, Bug Report, gpg4win
aheinecke merged task T4384: contact (.vcf) attachments are removed by gpgol into T4184: Outlook 2013 Appointments vanish when send as a E-Mail.
Mar 4 2019, 8:58 AM · gpgol, Bug Report, gpg4win
aheinecke merged T4384: contact (.vcf) attachments are removed by gpgol into T4184: Outlook 2013 Appointments vanish when send as a E-Mail.
Mar 4 2019, 8:58 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4384: contact (.vcf) attachments are removed by gpgol.

I think that this is the same as T4388 So I'm merging it in.

Mar 4 2019, 8:58 AM · gpgol, Bug Report, gpg4win
aheinecke created T4388: GpgOL: Add draft encryption as an option..
Mar 4 2019, 8:53 AM · Feature Request, gpg4win, gpgol
aheinecke merged T4382: GpgOL - The lock icon and draft protection into T3837: GpgOL: Message list icon is sometimes not properly updated.
Mar 4 2019, 8:51 AM · gpg4win, gpgol
aheinecke merged task T4382: GpgOL - The lock icon and draft protection into T3837: GpgOL: Message list icon is sometimes not properly updated.
Mar 4 2019, 8:51 AM · gpg4win, gpgol, Bug Report
aheinecke added a comment to T4382: GpgOL - The lock icon and draft protection.

Regarding 1. That is currently not possible. It is something we should have but which we did not yet implement. I'll move this out into a feature request.

Mar 4 2019, 8:51 AM · gpg4win, gpgol, Bug Report

Mar 1 2019

florian2833z added projects to T4382: GpgOL - The lock icon and draft protection: gpgol, gpg4win.
Mar 1 2019, 4:02 PM · gpg4win, gpgol, Bug Report
JJworx created T4384: contact (.vcf) attachments are removed by gpgol.
Mar 1 2019, 1:50 PM · gpgol, Bug Report, gpg4win

Feb 28 2019

JJworx added a comment to T4372: Make attachments deletable by copying.

The other option would also work for me. Thank you!

Feb 28 2019, 9:06 AM · gpgol, gpg4win, Feature Request

Feb 27 2019

JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

I agree! THANKS

Feb 27 2019, 2:47 PM · gpgol, gpg4win
aheinecke closed T4299: Problem to verify PGP key used by Microsoft as Resolved.

I think this can be resolved according to the last comments. We have analyzed it and found that it is not an issue on our side.

Feb 27 2019, 2:32 PM · gpgol, gpg4win
aheinecke closed T4372: Make attachments deletable by copying as Wontfix.

As a workaround you could also forward the mail to yourself and remove the attachments in the forwarded mail. This would basically work the same as I've described in the previous message.

Feb 27 2019, 1:02 PM · gpgol, gpg4win, Feature Request
aheinecke added a comment to T4372: Make attachments deletable by copying.

The next version will have a "decrypt permanently" option. Afterwards you could remove the attachments. Will this help in your use case? You could for example copy the mail into a local folder and remove the attachments then.

Feb 27 2019, 1:00 PM · gpgol, gpg4win, Feature Request
aheinecke merged T4378: Outlook hanging opening mails with S/MIME signature into T4118: GpgOL: Mitigate S/MIME Denial of Service due to CRL stalling.
Feb 27 2019, 12:57 PM · gpg4win, gpgol

Feb 22 2019

JJworx created T4372: Make attachments deletable by copying.
Feb 22 2019, 2:49 PM · gpgol, gpg4win, Feature Request

Jan 29 2019

FabioCarpi added a comment to T4350: Attachments in Outlook.

No... In this situation, my atachment is a rar file

Jan 29 2019, 10:52 AM · Info Needed, gpgol, Bug Report, gpg4win
aheinecke claimed T4350: Attachments in Outlook.

Interesting. Thanks for reporting this. This happened in the past because images had a "content-id" (so they were marked to be an embedded image) but were not really embedded. I did not have a very good fix then because it is hard for us to detect (easy for Outlook itself though) so there might be more special cases where this happens.

Jan 29 2019, 8:08 AM · Info Needed, gpgol, Bug Report, gpg4win

Jan 28 2019

FabioCarpi created T4350: Attachments in Outlook.
Jan 28 2019, 9:17 PM · Info Needed, gpgol, Bug Report, gpg4win

Jan 25 2019

aheinecke added a comment to T4345: Enigmail Posteo: Default keys are not accepted for WKD/WKS.

I know, I helped implementing that. Patrick changed it.

Jan 25 2019, 4:23 PM · gpgol, gpg4win, Enigmail
werner updated subscribers of T4345: Enigmail Posteo: Default keys are not accepted for WKD/WKS.

Enigmail used to use gpg-wks-client. @kai implemented it back then and we had a milestone meeting to show that it works with posteo.

Jan 25 2019, 4:20 PM · gpgol, gpg4win, Enigmail
aheinecke added a project to T4345: Enigmail Posteo: Default keys are not accepted for WKD/WKS: gpgol.
Jan 25 2019, 4:09 PM · gpgol, gpg4win, Enigmail

Jan 15 2019

MThib added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

Since today, I cannot send any Signed email. Outlook is crashing.
I guess it is due to the new version of GpgOL I installed.

Jan 15 2019, 5:12 PM · gpgol, Bug Report, gpg4win

Jan 14 2019

jmrexach added a comment to T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5].

You can save as text or html decrypted. And apart save the attachment. You can save as .msg in encrypted form dragging and dropping the message row to the desktop. In Outlook smime native mode you can save as .msg in encrypted mode (could be the key cache decrypts "on the fly"). This option seems disabled in gpgol.

Jan 14 2019, 8:05 PM · gpg4win, gpgol
aheinecke added a comment to T4322: GpgOL: Embedded image not visible in forwarded email.

I can reproduce it. For me the image is properly attached, I can access the file, but the embedded image does not work. This will be because the content_id is mixed up. I don't know why this happens yet.

Jan 14 2019, 2:26 PM · gpg4win, gpgol
aheinecke added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

I've opened T4322 for the image embedding issue.

Jan 14 2019, 2:25 PM · gpgol, Bug Report, gpg4win
aheinecke updated subscribers of T4322: GpgOL: Embedded image not visible in forwarded email.
Jan 14 2019, 2:22 PM · gpg4win, gpgol
aheinecke created T4322: GpgOL: Embedded image not visible in forwarded email.
Jan 14 2019, 2:22 PM · gpg4win, gpgol
aheinecke added a comment to T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5].
In T4318#121604, @che wrote:

Ok, so saving a decrypted message is not possible at the moment, right?

Jan 14 2019, 1:08 PM · gpg4win, gpgol
MThib added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

Thanks to the remediation.

Jan 14 2019, 12:56 PM · gpgol, Bug Report, gpg4win
che added a comment to T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5].

Hi Andre,

Jan 14 2019, 11:06 AM · gpg4win, gpgol
aheinecke added a subtask for T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file: T4264: Gpg4win 3.1.6.
Jan 14 2019, 10:30 AM · gpgol, Bug Report, gpg4win
aheinecke changed the status of T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file from Open to Testing.

I think I understand what is going on here:

Jan 14 2019, 10:24 AM · gpgol, Bug Report, gpg4win
MThib added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

@aheinecke the file is gpgolXXX.dat. I never got the winmail.dat (I think).

Jan 14 2019, 9:26 AM · gpgol, Bug Report, gpg4win
MThib added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

Thanks for taking care of the action.

Jan 14 2019, 9:19 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

@MThib What is the filename of the .dat with the original message, is it gpgolXXX.dat or winmail.dat and can you confirm that even without an attachment any modifications to the forwared mail are ignored and the mail is sent out as if it was send again?

Jan 14 2019, 9:09 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

There appears to be something very fishy when forwarding from the sent mails folder. Even without attachments if I forward and modify the content the original message is sent out and not the modified one.

Jan 14 2019, 8:56 AM · gpgol, Bug Report, gpg4win
aheinecke claimed T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5].

It is a bit related to T4241 indeed. As we have not yet seen a way to determine if the user actually triggered "save as" or if outlook just wants to save the modifications we can't decide when we should pass the save event and when we should block it.

Jan 14 2019, 7:56 AM · gpg4win, gpgol
aheinecke claimed T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.

Thank you for your detailed report. I agree that this can have serious consequences as it might send out unintended information. I'll look into it with high priority.

Jan 14 2019, 7:50 AM · gpgol, Bug Report, gpg4win

Jan 11 2019

MThib updated the task description for T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.
Jan 11 2019, 7:34 PM · gpgol, Bug Report, gpg4win
MThib updated the task description for T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.
Jan 11 2019, 7:30 PM · gpgol, Bug Report, gpg4win
MThib renamed T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file from Forwarded Email send the previous version of the email and attached a dat file to [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.
Jan 11 2019, 7:20 PM · gpgol, Bug Report, gpg4win
MThib created T4321: [GpgOL] Forwarded Email send the previous version of the email and attached a dat file.
Jan 11 2019, 7:19 PM · gpgol, Bug Report, gpg4win

Jan 10 2019

che added a comment to T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5].

Log file

Jan 10 2019, 9:21 AM · gpg4win, gpgol
che created T4318: GpgOl: Unable to save an encrypted message to disk [gpg4win 3.1.5] in the S1 Public space.
Jan 10 2019, 9:18 AM · gpg4win, gpgol

Jan 9 2019

JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Indeed in view of this data, it seems to be that the problem occurs by Microsoft. It fits also with the fact, that all other signatures are working fine from my experience.

Jan 9 2019, 1:34 PM · gpgol, gpg4win
jmrexach added a comment to T4299: Problem to verify PGP key used by Microsoft.

I agree. It seems a MS trouble. It remembers the trouble that you have when send email of new version available for your software. Something modifies the signed content.

Jan 9 2019, 1:01 PM · gpgol, gpg4win
aheinecke lowered the priority of T4299: Problem to verify PGP key used by Microsoft from High to Normal.

@jmrexach Thanks for the reminder, I confused those with other mails I've gotten regarding this issue.

Jan 9 2019, 12:54 PM · gpgol, gpg4win
jmrexach added a comment to T4299: Problem to verify PGP key used by Microsoft.

Andre,
Were useful for you the files that I sent yesterday? There were extracted using MFCMAPI MFCMAPI tool once emails were collected but before opened by Outlook. When it's checked one of them fails to verify signature. Other two are ok (diferent origin but the same key).

Jan 9 2019, 12:40 PM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

@JW-D I would very much like to but I still only get an error on that page. Can you give me another, working, subscribe link? Maybe I found a wrong one.

Jan 9 2019, 11:48 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

A pristine file I do not have, because every file passes GpgOL before displayed. I suggest, you subscribe to the service and if you de-install GpgOL, you should obtain a pristine file.

Jan 9 2019, 11:41 AM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

Ok. So the tooltip was another issue. Which I've fixed now.

Jan 9 2019, 10:26 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

No, I can´t confirm it, I get no reason displayed. The key which I use is shown in my screenshot (I´ll send by e-mail)

Jan 9 2019, 9:43 AM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

The tooltip:

Jan 9 2019, 9:36 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

I must make a correction of my earlier statement from today. The three Microsoft messages were not displayed in the same order on the screen on both machines. I must say, that on Outlook 2016 AND Thunderbird PGP verification still fails by "Microsoft Security Update Releases". It is the same situation as last year, nothing has been changed. I sent two files in EML format and some screenshots to A.Heinecke today.

Jan 9 2019, 9:33 AM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

I'll work on this right now. Please wait with contacting MSRC before I have a chance to find out what the problem is.

Jan 9 2019, 9:14 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Yesterday Microsoft issued three PGP signed mails. It is the first communication after MSRC confirmed failure of verification and promised to have internal procedures changed. I received those mails on two different machines, one equipped with Outlook 2016, the other with Thunderbird. Last year all messages failed on Outlook and Thunderbird, if the were issued from "Microsoft Security Update Releases".

Jan 9 2019, 9:13 AM · gpgol, gpg4win
aheinecke raised the priority of T4278: Signed mails not visible in Exchange web interface (owa) from Normal to High.

Should be looked at before the next release.

Jan 9 2019, 6:59 AM · gpgol, Bug Report, gpg4win
aheinecke merged task T4300: Signed (sign-only) messages are blank when read on Android email clients / Outlook online into T4278: Signed mails not visible in Exchange web interface (owa).
Jan 9 2019, 6:58 AM · gpgol, Bug Report, gpg4win
aheinecke merged T4300: Signed (sign-only) messages are blank when read on Android email clients / Outlook online into T4278: Signed mails not visible in Exchange web interface (owa).
Jan 9 2019, 6:58 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4300: Signed (sign-only) messages are blank when read on Android email clients / Outlook online.

Hi,
thanks for the report. We were unaware of the Andorid problem. The Web App issue was already reported similary.

Jan 9 2019, 6:58 AM · gpgol, Bug Report, gpg4win
aheinecke claimed T4295: PGP/MIME emails not decrypted.

18:25:22/11956/ERROR/mapihelp.cpp:mapi_change_message_class: can't save old message class: hr=0x80070005
18:25:22/11956/mapihelp.cpp:mapi_create_attach_table: message has 2 attachments
18:25:22/11956/mapihelp.cpp:mapi_create_attach_table: attachment info:
18:25:22/11956/ 3435173 mt=0 fname=gpgol_string_7' ct=application/pgp-encrypted' ct_parms=`(null)'
18:25:22/11956/ 3435205 mt=0 fname=gpgol_string_8' ct=application/octet-stream' ct_parms=`(null)'
18:25:22/11956/mapihelp.cpp:mapi_mark_moss_attach: Marking 3435173 as MOSS attachment
18:25:22/11956/ERROR/mapihelp.cpp:mapi_mark_moss_attach: can't set GpgOL Attach Type property: hr=0x80070005
18:25:22/11956/mapihelp.cpp:mapi_mark_moss_attach: Marking 3435205 as MOSS attachment
18:25:22/11956/ERROR/mapihelp.cpp:mapi_mark_moss_attach: can't set GpgOL Attach Type property: hr=0x80070005

Jan 9 2019, 6:55 AM · gpgol, Bug Report, gpg4win

Jan 8 2019

aheinecke added a comment to T3740: Outlook unable to send encrypted or signed emails.

Reporter in wald said that he is using GMX with POP3. I don't see how that could change compose actions but maybe Outlook internally uses a different MAPI Provider which could cause different behavior. I have not tested POP 3 in a long time so this will be the next step here.

Jan 8 2019, 8:48 AM · gpgol, Bug Report

Jan 7 2019

aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

I did in my first comment here ;-)

Jan 7 2019, 11:30 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Please, provide e-mail address, then I´ll send it asap

Jan 7 2019, 10:42 AM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

Yes, please send the mails. Maybe they will show me the problem already. :-)

Jan 7 2019, 10:29 AM · gpgol, gpg4win
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Very strange, but I tried it by myself, after your mail. The same for me. However, I can offer you to send two mails to you as EML files, one works, the other not. I using GnuPG also for verification from BSI newsletter, it works fine there. The problem is only with newsletters from "Microsoft security update releases", other Microsoft security notifications can be verified as well.

Jan 7 2019, 10:18 AM · gpgol, gpg4win
aheinecke added a comment to T4299: Problem to verify PGP key used by Microsoft.

@JW-D thanks. Please send them to aheinecke@gnupg.org

Jan 7 2019, 10:12 AM · gpgol, gpg4win
aheinecke added a comment to T3740: Outlook unable to send encrypted or signed emails.

I had a report of this by mail where the problem was that:

Jan 7 2019, 9:44 AM · gpgol, Bug Report
JW-D added a comment to T4299: Problem to verify PGP key used by Microsoft.

Yes, GpgOL in version 2.3.2 fails to verify the original message, it is labeled as "not-secure". But it happens only to "Microsoft security update releases", not to other Microsoft Security Notifications which I receive on regular base. I contacted Microsoft Security Responce Center (MSRC) and they confirmed the failure of signature verification in this case. They were not aware about it, but checked it by them self after my mail. They had no explanation for that. Labeling the message as "not-secure" would may indicate that it would be altered in transport, but MSRC did not say that. Therefore, I still assume, that we have a bug in GnuPG.

Jan 7 2019, 9:19 AM · gpgol, gpg4win
aheinecke claimed T4299: Problem to verify PGP key used by Microsoft.

If it contains a gpgolPGP.dat it means that it was already parsed by GpgOL and GpgOL created the MOSS attachment from the clearsigned original message. That it's tnef is part of the export and should not be a problem.

Jan 7 2019, 9:02 AM · gpgol, gpg4win

Dec 20 2018

markpaskal created T4300: Signed (sign-only) messages are blank when read on Android email clients / Outlook online.
Dec 20 2018, 3:45 PM · gpgol, Bug Report, gpg4win

Dec 14 2018

aheinecke added a comment to T4118: GpgOL: Mitigate S/MIME Denial of Service due to CRL stalling.

No I do not think so. Because that would already be currently the case. If you had a subverted Root CA of course you can attack. But we are only talking about CRL / OCSP here. A root CA that does not provide a CRL for certificate X is OK. As long as the Root CA that issued X issues a CRL for that. Well the usual CRL / OCSP denial of service is still possible but I don't see any subversion.

Dec 14 2018, 1:28 PM · gpg4win, gpgol
werner added a comment to T4118: GpgOL: Mitigate S/MIME Denial of Service due to CRL stalling.

Interesting idea but it does not help against attacks because all root CA are considered equal (virtually cross-signed). Thus a single not checked root CA allows to subvert all certificates.

Dec 14 2018, 1:26 PM · gpg4win, gpgol
aheinecke added a comment to T4118: GpgOL: Mitigate S/MIME Denial of Service due to CRL stalling.

I wonder if the best thing here might be another flag in the trustlist to disable CRL/OCSP checks for a single root certificate chain. I had such a request in the Gpg4win forums. Someone had a single unreacable CRL / OCSP and had to disable globally all checks for all other certs, too.

Dec 14 2018, 10:52 AM · gpg4win, gpgol

Dec 12 2018

aheinecke created T4287: GpgOL: Incompatibility with Microsoft Azure Information Protection add-in.
Dec 12 2018, 4:08 PM · gpg4win, gpgol

Dec 11 2018

werner closed T4134: GnuPG: Changing the trust model once changes the default trust model as Resolved.

Fix was released with 2.2.11

Dec 11 2018, 3:51 PM · gpg4win, gpgol, Bug Report, gnupg

Dec 10 2018

JJworx added a comment to T4278: Signed mails not visible in Exchange web interface (owa).

Hi, it's OpenPGP and the same Exchange server. Perhaps it has to do with
the "Unterhaltungsmodus" from the error message.

Dec 10 2018, 8:34 AM · gpgol, Bug Report, gpg4win
aheinecke claimed T4278: Signed mails not visible in Exchange web interface (owa).

I'm pretty sure I tested this in the past using the Outlook.com web interface. The mails should show with an unknown attachment (the signature). I can't think of any changes recently that would have changed it. I'll check again.

Dec 10 2018, 8:31 AM · gpgol, Bug Report, gpg4win

Nov 28 2018

JJworx added a comment to T4267: X.509 mails will not be decrypted.

This is a new bug, I believe, but perhaps it only appears with "broken"
S/MIME-messages of this type, So I'll first post it here:

Nov 28 2018, 9:26 AM · gpgol, Bug Report, gpg4win
JJworx added a comment to T4267: X.509 mails will not be decrypted.

fine with me

Nov 28 2018, 8:58 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T4267: X.509 mails will not be decrypted.

I'll leave the fallback to "just try to decrypt" in though because it is better then doing nothing like we did before.

Nov 28 2018, 8:49 AM · gpgol, Bug Report, gpg4win