Page MenuHome GnuPG
Feed Advanced Search

Today

gniibe added a comment to T7709: Decryption with ECC smartcard keys broken.

Here is a patch.

diff --git a/agent/divert-scd.c b/agent/divert-scd.c
index 1e5de4671..bb42dd3b4 100644
--- a/agent/divert-scd.c
+++ b/agent/divert-scd.c
@@ -517,6 +517,9 @@ agent_card_ecc_kem (ctrl_t ctrl, const unsigned char *ecc_ct,
Wed, Jul 16, 12:09 PM · gnupg26, Bug Report, gpd5x
ebo added a project to T7098: Change the GpgOL encryption icon according to its state: gpd5x.
Wed, Jul 16, 11:56 AM · gpd5x, vsd33, Feature Request, Restricted Project, gpgol
werner added a project to T7709: Decryption with ECC smartcard keys broken: gnupg26.
Wed, Jul 16, 11:42 AM · gnupg26, Bug Report, gpd5x
werner assigned T7709: Decryption with ECC smartcard keys broken to gniibe.
Wed, Jul 16, 11:42 AM · gnupg26, Bug Report, gpd5x
ebo updated the task description for T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA%.
Wed, Jul 16, 10:51 AM · gpd5x, Feature Request, kleopatra, vsd34
ebo renamed T7709: Decryption with ECC smartcard keys broken from Decryption with smartcard keys broken to Decryption with ECC smartcard keys broken.
Wed, Jul 16, 10:27 AM · gnupg26, Bug Report, gpd5x
ikloecker moved T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA% from Backlog to WIP on the gpd5x board.
Wed, Jul 16, 9:13 AM · gpd5x, Feature Request, kleopatra, vsd34
ikloecker added a project to T7700: Kleopatra: Move kleopatrarc away from %LOCALAPPDATA%: gpd5x.

Add gpd5x tag to ensure testing with Gpg4win.

Wed, Jul 16, 9:13 AM · gpd5x, Feature Request, kleopatra, vsd34

Yesterday

ikloecker updated the task description for T7574: Migration of group config from old location to new location is broken.
Tue, Jul 15, 6:02 PM · Windows, gpd5x, kleopatra
ikloecker changed the status of T7574: Migration of group config from old location to new location is broken from Open to Testing.

It's intentional that with Gpg4win migration from %LOCALAPPDATA% does not work because %LOCALAPPDATA% is used by VSD (and GPD) but not by any old Gpg4win.

Tue, Jul 15, 5:50 PM · Windows, gpd5x, kleopatra
ebo changed the status of T7574: Migration of group config from old location to new location is broken from Testing to Open.

As timegrid has not experienced the older versions himself, he misunderstood this. Ingo's description is correct.
(%LOCALAPPDATA% was the location of kleopatragroupsrc before VSD 3.3.0.)

Tue, Jul 15, 4:50 PM · Windows, gpd5x, kleopatra
ebo triaged T7718: Kleopatra: improve information for invalid S/MIME certificates as Normal priority.
Tue, Jul 15, 1:38 PM · gpd5x, kleopatra
ebo added a comment to T7709: Decryption with ECC smartcard keys broken.

The issue remains with gpg 2.5.9 from Gpg4win-5.0.0-beta345.
Here a gpg-agent log for the failed decryption:

Tue, Jul 15, 1:35 PM · gnupg26, Bug Report, gpd5x

Mon, Jul 14

ebo moved T7630: Kleopatra: Get rid of the imported certificates tabs from WIP to QA on the gpd5x board.
Mon, Jul 14, 6:00 PM · kleopatra, gpd5x
ebo moved T7091: Kleopatra: Simple copy key to card from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7154: Kleopatra: Dragging and dropping a certificate from the main view onto itself shouldn't trigger an import from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, Bug Report, kleopatra
ebo moved T7580: Kleopatra: Add a dialog window to the disable/enable certificate action from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7639: Kleopatra: Version information sometimes not shown. from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · vsd33, Bug Report, gpd5x, kleopatra
ebo moved T7528: Make it possible to run Kleopatra VSD and Kleopatra GPD in parallel from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T6930: pinentry-qt window is not parented to Kleopatra on Wayland from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra, Bug Report
ebo moved T7509: gpg4win: Make the AppImage build work with the new Docker-based build script from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, AppImage, gpg4win
ebo moved T7666: Kleopatra: Rework versioning from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7612: Kleopatra: ignores its own language settings for the filter names from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7655: Kleopatra: show a progress window when updating a certificate from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7610: Kleopatra: Update custom colored UI elements when colors change from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7515: Kleopatra: reduce the number of actions in the context menu from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7708: Kleopatra: Pretty display names for kyber algos from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7704: Kleopatra: Add option to start it as additional process from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · vsd34, gpd5x, kleopatra
ebo moved T7703: Kleopatra: Validity icons in selected rows missing from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · Bug Report, kleopatra, gpd5x
ebo moved T7355: Keyboard navigation inside the Notepad text editor from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, a11y, kleopatra
ebo moved T7707: Kleopatra: Unformatted fingerprints from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, kleopatra
ebo moved T7712: Moving encrypted emails to folder fails from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, vsd33, gpgol
ebo moved T7714: GPGOL: Attachment treated as text from WIP to QA on the gpd5x board.
Mon, Jul 14, 5:59 PM · gpd5x, vsd33, gpgol
hej added a comment to T7701: Draft: Kleopatra: Add information for verification results.

a: expired certificate
Dialog text:
The signature is invalid: The signing certificate has expired.

Mon, Jul 14, 12:16 PM · gpd5x, kleopatra

Fri, Jul 11

ebo added a comment to T7701: Draft: Kleopatra: Add information for verification results.

After further discussion, I propose the following. All tool tips and the last dialog text were changed:

Fri, Jul 11, 3:17 PM · gpd5x, kleopatra
ebo added a comment to T7709: Decryption with ECC smartcard keys broken.

I have not tested this extensively but it seems to me after some fast checks that the pivotal point here is the usage of a brainpool key on a smart card for the decryption.

Fri, Jul 11, 11:35 AM · gnupg26, Bug Report, gpd5x
ebo added a comment to T7709: Decryption with ECC smartcard keys broken.

I have not tested this extensively but it seems to me after some fast checks that the pivotal point here is the usage of a brainpool key on a smart card for the decryption.

Fri, Jul 11, 11:27 AM · gnupg26, Bug Report, gpd5x

Thu, Jul 10

ebo raised the priority of T7240: GpgOL: Config dialog not registering as closed from Normal to High.

tested with Gpg4win 5.0Beta-336

Thu, Jul 10, 4:49 PM · gpd5x, qt, gpgol
ebo updated the task description for T7718: Kleopatra: improve information for invalid S/MIME certificates.
Thu, Jul 10, 4:28 PM · gpd5x, kleopatra
ebo updated the task description for T7718: Kleopatra: improve information for invalid S/MIME certificates.
Thu, Jul 10, 4:23 PM · gpd5x, kleopatra
ebo triaged T7706: Okular: "Save as" does not work as Normal priority.

Likely connected to T7705: Okular: Error on signature if the original file is overwritten

Thu, Jul 10, 4:05 PM · Bug Report, okular, gpd5x
ebo triaged T7705: Okular: Error on signature if the original file is overwritten as Normal priority.

I can confirm this.

Thu, Jul 10, 4:00 PM · Bug Report, okular, gpd5x
ebo created T7718: Kleopatra: improve information for invalid S/MIME certificates.
Thu, Jul 10, 3:02 PM · gpd5x, kleopatra
TobiasFella added a comment to T7556: Kleopatra: Sign/encrypt window improvement (KF6).

Edit 2025-06-26:
And please Fix the ALT shortcut in the "Sign / Encrypt", "Sign" and "Encrypt" button to S or E, respectively. One can hardly see the mark at the "i" and its unintuitive, anyway:

Thu, Jul 10, 2:43 PM · gpd5x, kleopatra
TobiasFella changed the status of T7630: Kleopatra: Get rid of the imported certificates tabs from Open to Testing.
Thu, Jul 10, 1:35 PM · kleopatra, gpd5x
TobiasFella moved T7630: Kleopatra: Get rid of the imported certificates tabs from Backlog to WIP on the gpd5x board.
Thu, Jul 10, 1:35 PM · kleopatra, gpd5x
ikloecker updated the task description for T7717: Draft: Location of qt-application config files.
Thu, Jul 10, 11:42 AM · vsd34, gpd5x, okular
ebo created T7717: Draft: Location of qt-application config files.
Thu, Jul 10, 9:54 AM · vsd34, gpd5x, okular

Wed, Jul 9

ebo set External Link to https://forum.gnupg.org/t/pcs-dead-for-30-minutes-after-clicking-send-with-the-recent-versions-of-gpg4win/6599/10 on T7714: GPGOL: Attachment treated as text .
Wed, Jul 9, 1:05 PM · gpd5x, vsd33, gpgol
ebo moved T7495: Kleopatra: Improve success message on keyserver upload from WIP to QA on the gpd5x board.
Wed, Jul 9, 12:43 PM · kleopatra, gpd5x
werner shifted T7714: GPGOL: Attachment treated as text from the Restricted Space space to the S1 Public space.
Wed, Jul 9, 11:48 AM · gpd5x, vsd33, gpgol

Tue, Jul 8

ikloecker added a comment to T7658: Okular: Dirmngr startup timeout on signature validation.

Staring at some Process Monitor logs I noticed that dirmngr wastes 3-4 seconds trying to connect to localhost:9050 and localhost:9150 looking for tor. After adding no-use-tor to dirmngr.conf dirmngr starts reasonably fast.

Tue, Jul 8, 3:16 PM · Bug Report, gpd5x, okular
ikloecker added a comment to T7379: Kleopatra: Learning certificates of Signature v2.0 card fails if a Yubikey is plugged in as well.

Kleopatra does now read the certificates from the card and import them itself instead of relying on gpgsm --learn-card.

Tue, Jul 8, 1:43 PM · gpd5x, kleopatra
TobiasFella added a comment to T7553: Kleopatra: change string and logic for option to continue showing the result window .

Remove the lines starting with ShowResultsAfter[...] in kleopatrarc

Tue, Jul 8, 12:15 PM · gpd5x, kleopatra

Mon, Jul 7

ikloecker added a comment to T7658: Okular: Dirmngr startup timeout on signature validation.

I have built the run-* test programs of gpgme for Windows. run-keylist --cms --secret takes about 23 seconds. 3.7 seconds are gpgme initialization/setup (gpgconf --list-dirs, gpgconf --list-components, gpg --version, gpgsm --version, gpgconf --version). Most time (2 x 6-8 s) is lost starting gpg-agent and dirmngr. (keyboxd is not enabled here.)

Mon, Jul 7, 3:47 PM · Bug Report, gpd5x, okular
mmontkowski moved T7712: Moving encrypted emails to folder fails from Backlog to WiP on the vsd33 board.
Mon, Jul 7, 2:44 PM · gpd5x, vsd33, gpgol
mmontkowski moved T7712: Moving encrypted emails to folder fails from Backlog to WIP on the gpd5x board.
Mon, Jul 7, 2:43 PM · gpd5x, vsd33, gpgol
mmontkowski edited projects for T7712: Moving encrypted emails to folder fails, added: vsd33, gpd5x; removed vsd33 (vsd-3.3.3), gpd5x (gpd-5.0.0).
Mon, Jul 7, 2:43 PM · gpd5x, vsd33, gpgol
mmontkowski changed the status of T7714: GPGOL: Attachment treated as text from Open to Testing.
Mon, Jul 7, 2:42 PM · gpd5x, vsd33, gpgol
mmontkowski moved T7714: GPGOL: Attachment treated as text from Backlog to WiP on the vsd33 board.
Mon, Jul 7, 2:42 PM · gpd5x, vsd33, gpgol
mmontkowski moved T7714: GPGOL: Attachment treated as text from Backlog to WIP on the gpgol board.
Mon, Jul 7, 2:42 PM · gpd5x, vsd33, gpgol
mmontkowski moved T7714: GPGOL: Attachment treated as text from Backlog to WIP on the gpd5x board.
Mon, Jul 7, 2:41 PM · gpd5x, vsd33, gpgol
mmontkowski added projects to T7714: GPGOL: Attachment treated as text : vsd33, gpd5x.
Mon, Jul 7, 2:41 PM · gpd5x, vsd33, gpgol

Fri, Jul 4

timegrid added a comment to T7709: Decryption with ECC smartcard keys broken.

commands with -v

Fri, Jul 4, 1:59 PM · gnupg26, Bug Report, gpd5x
werner added a comment to T7709: Decryption with ECC smartcard keys broken.

Please always add -v t commands like "gpg --decrypt test.txt.gpg". To decide whether this is smartcard or gpg-agent releated, I need to see a log file form gpg-agent and scdaemon. The latter is more important. I would suggest "debug ipc,app,cardio"

Fri, Jul 4, 1:27 PM · gnupg26, Bug Report, gpd5x

Thu, Jul 3

TobiasFella changed the status of T7707: Kleopatra: Unformatted fingerprints from Open to Testing.
Thu, Jul 3, 1:00 PM · gpd5x, kleopatra
ikloecker closed T6921: Kleopatra / Qt6: Improve accessibility detection for "Desert" high contrast scheme and fix it upstream, a subtask of T6932: Icons, darkmode and stuff, as Resolved.
Thu, Jul 3, 10:20 AM · gpd5x, kleopatra
ikloecker closed T6921: Kleopatra / Qt6: Improve accessibility detection for "Desert" high contrast scheme and fix it upstream as Resolved.

For KF5-based builds this is resolved because the improved heuristic for detecting light high-contrast themes (like "Desert") is used for VSD 3.3 and Gpg4win 4.4.

Thu, Jul 3, 10:20 AM · Windows, gpd5x, kleopatra
ikloecker changed the status of T7355: Keyboard navigation inside the Notepad text editor from Open to Testing.

For simplicity (and because I think entering tab characters isn't really essential for the notepad) I decided to go with the first solution.

Thu, Jul 3, 9:42 AM · gpd5x, a11y, kleopatra
ikloecker claimed T7355: Keyboard navigation inside the Notepad text editor.
Thu, Jul 3, 9:09 AM · gpd5x, a11y, kleopatra

Wed, Jul 2

ikloecker changed the status of T7704: Kleopatra: Add option to start it as additional process from Open to Testing.

Ready for testing.

Wed, Jul 2, 2:00 PM · vsd34, gpd5x, kleopatra
TobiasFella moved T7707: Kleopatra: Unformatted fingerprints from Backlog to WIP on the gpd5x board.
Wed, Jul 2, 1:21 PM · gpd5x, kleopatra
TobiasFella added a comment to T7707: Kleopatra: Unformatted fingerprints.

and for certification revocation (and some other places): https://invent.kde.org/pim/libkleo/-/merge_requests/197

Wed, Jul 2, 1:21 PM · gpd5x, kleopatra
TobiasFella added a comment to T7707: Kleopatra: Unformatted fingerprints.

For card stuff: https://invent.kde.org/pim/kleopatra/-/merge_requests/400

Wed, Jul 2, 1:07 PM · gpd5x, kleopatra
TobiasFella claimed T7707: Kleopatra: Unformatted fingerprints.
Wed, Jul 2, 12:49 PM · gpd5x, kleopatra
TobiasFella added a comment to T7707: Kleopatra: Unformatted fingerprints.

For the tooltips: https://invent.kde.org/pim/libkleo/-/merge_requests/196

Wed, Jul 2, 12:49 PM · gpd5x, kleopatra
TobiasFella changed the status of T7708: Kleopatra: Pretty display names for kyber algos from Open to Testing.
Wed, Jul 2, 12:40 PM · gpd5x, kleopatra
TobiasFella renamed T7709: Decryption with ECC smartcard keys broken from Kleopatra: Decryption with smartcard keys broken to Decryption with smartcard keys broken.
Wed, Jul 2, 12:40 PM · gnupg26, Bug Report, gpd5x

Tue, Jul 1

timegrid closed T7702: Kleopatra: Printing on win11 aborts silently as Resolved.

Ok, it was a missing update (although windows claimed to be up-to-date).
After installing 2025-06 [...] KB5060829 the Microsoft Print to PDF feature is available again and printing also works in Kleopatra/Okular.

Tue, Jul 1, 6:49 PM · Windows, Bug Report, kleopatra, gpd5x
ikloecker changed the status of T7703: Kleopatra: Validity icons in selected rows missing from Open to Testing.

A second patch fixes the problem with the button in the smart card view.

Tue, Jul 1, 4:57 PM · Bug Report, kleopatra, gpd5x
ikloecker added a comment to T7703: Kleopatra: Validity icons in selected rows missing.

I have added a patch to disable recoloring of the status icons in Gpg4win. This ensures that the status icons in the selected rows don't get all-white.

Tue, Jul 1, 4:09 PM · Bug Report, kleopatra, gpd5x
ikloecker added a comment to T7703: Kleopatra: Validity icons in selected rows missing.

Upstream bug report for invisible status icons: https://bugs.kde.org/show_bug.cgi?id=506434 (Icon coloring is inherently incompatible with colored Breeze status icons)

Tue, Jul 1, 3:47 PM · Bug Report, kleopatra, gpd5x
timegrid added a comment to T7702: Kleopatra: Printing on win11 aborts silently.

It's also the same error in Okular, when a pdf is printed.

Tue, Jul 1, 2:18 PM · Windows, Bug Report, kleopatra, gpd5x
timegrid added a comment to T7702: Kleopatra: Printing on win11 aborts silently.

Same on gpg4win-4.4.1 @ win11 (here a bit more debugview context)

3	3.503991	8584	kleopatra.exe	org.kde.pim.kleopatra: Paperkey export finished:  0 status:  QProcess::NormalExit
4	3.691599	8584	kleopatra.exe	QPrintDialog: Cannot be used on non-native printers
5	3.691981	8584	kleopatra.exe	QPrintDialog: Cannot be used on non-native printers
6	3.692752	8584	kleopatra.exe	org.kde.pim.kleopatra: Printing aborted.
Tue, Jul 1, 1:44 PM · Windows, Bug Report, kleopatra, gpd5x
TobiasFella added a comment to T7702: Kleopatra: Printing on win11 aborts silently.

Works fine here.

Tue, Jul 1, 1:29 PM · Windows, Bug Report, kleopatra, gpd5x
timegrid added a comment to T7709: Decryption with ECC smartcard keys broken.

version

C:\Users\g10\Desktop\tmp\scdecrypt>gpg --version
gpg (GnuPG) 2.5.8
libgcrypt 1.11.1
Copyright (C) 2025 g10 Code GmbH
License GNU GPL-3.0-or-later <https://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.
Tue, Jul 1, 1:26 PM · gnupg26, Bug Report, gpd5x
ikloecker added a comment to T7709: Decryption with ECC smartcard keys broken.

gpg --version?
gpg -K?

Tue, Jul 1, 1:18 PM · gnupg26, Bug Report, gpd5x
TobiasFella moved T7708: Kleopatra: Pretty display names for kyber algos from Backlog to WIP on the gpd5x board.
Tue, Jul 1, 1:06 PM · gpd5x, kleopatra
TobiasFella triaged T7708: Kleopatra: Pretty display names for kyber algos as Normal priority.
Tue, Jul 1, 1:06 PM · gpd5x, kleopatra
timegrid updated the task description for T7709: Decryption with ECC smartcard keys broken.
Tue, Jul 1, 12:45 PM · gnupg26, Bug Report, gpd5x
timegrid added a comment to T7709: Decryption with ECC smartcard keys broken.

You're right, it also errors on gpg directly:

Tue, Jul 1, 12:44 PM · gnupg26, Bug Report, gpd5x
ikloecker claimed T7703: Kleopatra: Validity icons in selected rows missing.
Tue, Jul 1, 12:25 PM · Bug Report, kleopatra, gpd5x
TobiasFella added a comment to T7709: Decryption with ECC smartcard keys broken.

I can't reproduce. Please check whether this works if you use gpg directly; it's a bit unlikely that this is kleopatra-specific, since kleopatra doesn't really care whether the key is on a smartcard or not.

Tue, Jul 1, 12:18 PM · gnupg26, Bug Report, gpd5x
ikloecker set External Link to https://invent.kde.org/pim/kleopatra/-/merge_requests/399 on T7704: Kleopatra: Add option to start it as additional process.
Tue, Jul 1, 11:26 AM · vsd34, gpd5x, kleopatra
hej added a comment to T7701: Draft: Kleopatra: Add information for verification results.

a: expired certificate

Tue, Jul 1, 10:28 AM · gpd5x, kleopatra
ikloecker moved T7704: Kleopatra: Add option to start it as additional process from Backlog to WIP on the gpd5x board.
Tue, Jul 1, 9:30 AM · vsd34, gpd5x, kleopatra

Mon, Jun 30

ikloecker moved T7379: Kleopatra: Learning certificates of Signature v2.0 card fails if a Yubikey is plugged in as well from WIP to Backlog on the gpd5x board.
Mon, Jun 30, 4:50 PM · gpd5x, kleopatra
ikloecker changed the status of T7612: Kleopatra: ignores its own language settings for the filter names from Open to Testing.
Mon, Jun 30, 4:49 PM · gpd5x, kleopatra
ikloecker added a comment to T7639: Kleopatra: Version information sometimes not shown..

If this should also work in gpg4win-5.0.0-beta336 @ win10 (beta compliance mode), it does not:

Mon, Jun 30, 4:48 PM · vsd33, Bug Report, gpd5x, kleopatra
ikloecker changed the status of T7610: Kleopatra: Update custom colored UI elements when colors change, a subtask of T6932: Icons, darkmode and stuff, from Open to Testing.
Mon, Jun 30, 4:40 PM · gpd5x, kleopatra