Page MenuHome GnuPG
Feed Advanced Search

Yesterday

werner moved T7866: Allow separate LDAP keyserver for uploading from QA to WIP on the gnupg26 board.
Fri, Jan 9, 3:50 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner changed the status of T7990: export-minimal unexpectedly omits expired key from Open to Testing.
Fri, Jan 9, 3:43 PM · gnupg26, Feature Request, Gentoo
werner committed rG0bcd9be9a068: gpg: New export-option "keep-expired-subkeys" (authored by werner).
gpg: New export-option "keep-expired-subkeys"
Fri, Jan 9, 3:35 PM
werner added a comment to T7990: export-minimal unexpectedly omits expired key.

So w/o the new option we have:

Fri, Jan 9, 3:11 PM · gnupg26, Feature Request, Gentoo
werner triaged T7990: export-minimal unexpectedly omits expired key as High priority.
Fri, Jan 9, 2:47 PM · gnupg26, Feature Request, Gentoo
werner added a comment to T7993: Documentation: make clear that detached signatures are preferred.

I updated the rendered form of the English GPH with a warning and a link to the blog.

Fri, Jan 9, 2:45 PM · Documentation
werner closed T7993: Documentation: make clear that detached signatures are preferred as Resolved.

Thanks for the hint.

Fri, Jan 9, 2:30 PM · Documentation
werner committed rD124678b1cf19: faq: Mention the cleartext signed blog and fix the keyserver entry (authored by werner).
faq: Mention the cleartext signed blog and fix the keyserver entry
Fri, Jan 9, 2:25 PM
werner committed rG0e37a6779e56: doc: Improve the "Programmatic use of GnuPG" section. (authored by werner).
doc: Improve the "Programmatic use of GnuPG" section.
Fri, Jan 9, 2:17 PM
werner closed T7994: Documentation: mention `status-fd` in "Programmatic use of GnuPG" as Resolved.

Will be in the next release.

Fri, Jan 9, 2:02 PM · gnupg, Documentation
werner closed T7663: Certificated signed using SHA-1 isn't trusted, but needs --force-sign-key to re-sign. as Resolved.
Fri, Jan 9, 1:42 PM · gnupg26, Feature Request
werner removed a project from T6815: PQC encryption for GnuPG: gnupg26.

it does not make sense to have a workboard item for this parent ticket.

Fri, Jan 9, 1:40 PM · OpenPGP, PQC, gnupg
werner closed T7298: gpg --quick-set-expire fails for V5 subkeys as Resolved.
Fri, Jan 9, 1:39 PM · gnupg24, gnupg26, Bug Report
werner moved T7298: gpg --quick-set-expire fails for V5 subkeys from QA to done on the gnupg24 board.
Fri, Jan 9, 1:38 PM · gnupg24, gnupg26, Bug Report
werner added a comment to T7866: Allow separate LDAP keyserver for uploading.

Independent of keyserver order in dirmngr.conf, --search-keys still offers keys from the upload server, but the download fails:

Fri, Jan 9, 1:35 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner added a comment to T7866: Allow separate LDAP keyserver for uploading.

For "Although the upload server is used for upload, the gpg message still displays the first keyserver" see T8025

Fri, Jan 9, 1:28 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner triaged T8025: Display the correct LDAP server in gpg if the upload flag is in use. as Normal priority.
Fri, Jan 9, 1:28 PM · Bug Report, LDAP, gnupg26
werner closed T7676: Cannot decrypt a message encrypted to a Cv25519 key on a token as Resolved.

I am using that version and key daily. No problems seen.

Fri, Jan 9, 1:25 PM · gnupg26, Bug Report
werner closed T7649: gnupg: Use KEM interface for encryption/decryption as Resolved.
Fri, Jan 9, 1:24 PM · gnupg26
werner edited projects for T6421: Improve error message if no reset code (PUK) is set, added: gnupg26; removed gnupg22, gnupg24.

I think we won't fix that for 2.2

Fri, Jan 9, 11:32 AM · gnupg26, Feature Request, gpgrt
werner edited projects for T6436: Double pinentry on change password, added: gnupg26; removed gnupg24.
Fri, Jan 9, 11:28 AM · gnupg26, Feature Request, gnupg22, Restricted Project
werner changed the status of T7840: Oddity with 7816 change_reference_data from Testing to Open.
Fri, Jan 9, 11:27 AM · Bug Report, gnupg22, gnupg26, scd
werner moved T7840: Oddity with 7816 change_reference_data from QA to Done on the gnupg26 board.
Fri, Jan 9, 11:27 AM · Bug Report, gnupg22, gnupg26, scd
werner moved T7332: Kleopatra: Initial keylisting sometimes fails or hangs for some seconds from Backlog to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:25 AM · gnupg22 (gnupg-2.2.52), gnupg24, gpd5x, kleopatra, Bug Report
werner closed T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server as Resolved.
Fri, Jan 9, 11:22 AM · gnupg22 (gnupg-2.2.52), gnupg26, Feature Request, gpd5x
werner moved T7730: gpg: retrieve a certificate from an LDAP server before sending it to the LDAP server from WiP to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:22 AM · gnupg22 (gnupg-2.2.52), gnupg26, Feature Request, gpd5x
werner closed T7829: w32: daemon (gpg-agent/keyboxd/dirmngr) startup and connection race when there is a socket file already, a subtask of T7658: Okular: Dirmngr startup timeout on signature validation, as Resolved.
Fri, Jan 9, 11:21 AM · Bug Report, gpd5x, okular
werner closed T7829: w32: daemon (gpg-agent/keyboxd/dirmngr) startup and connection race when there is a socket file already as Resolved.

That was also fixed in gnupg 2.2.50 and thus vsd 3.3.3

Fri, Jan 9, 11:21 AM · gnupg22 (gnupg-2.2.52), Bug Report, gpd5x, okular
werner moved T7829: w32: daemon (gpg-agent/keyboxd/dirmngr) startup and connection race when there is a socket file already from QA to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:19 AM · gnupg22 (gnupg-2.2.52), Bug Report, gpd5x, okular
werner moved T7914: Card s/n number missing in gpgsm from WiP to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:17 AM · gnupg22 (gnupg-2.2.52), scd, S/MIME, Feature Request, gnupg26
werner moved T2196: keydb locking can result in deadlock in 2.2 from Backlog to gnupg-2.2.52 on the gnupg22 board.
Fri, Jan 9, 11:15 AM · gnupg22 (gnupg-2.2.52), Bug Report
werner closed T2196: keydb locking can result in deadlock in 2.2 as Resolved.

That was fixed with 2.2.52 which fixed a bug in the fix done in 2.2.50 (see rG31fef13df1). Note that 2.2.48 to 2.2.50 had only internal releases.

Fri, Jan 9, 11:15 AM · gnupg22 (gnupg-2.2.52), Bug Report
werner created gnupg22 (gnupg-2.2.52).
Fri, Jan 9, 11:11 AM
werner closed T7805: Permission denied on batch deletion of mixed (openpgp+smime) certs as Resolved.

Given that the 2.2 fix has been tested and resolved and we don't have another ticket for 2.6, we can close this one.

Fri, Jan 9, 11:07 AM · gnupg, vsd, kleopatra
werner closed T7805: Permission denied on batch deletion of mixed (openpgp+smime) certs, a subtask of T7855: keybox/keydb locking issue in 2.6 , as Resolved.
Fri, Jan 9, 11:07 AM · gnupg26, gpd5x
werner lowered the priority of T7889: libgcrypt: HAVE_BROKEN_MLOCK from High to Normal.

Okay, let's backport this.

Fri, Jan 9, 11:04 AM · backport, libgcrypt, Bug Report
werner lowered the priority of T7895: Kleopatra: Handbook outdated from High to Normal.
Fri, Jan 9, 11:01 AM · Documentation, gpd5x, kleopatra
werner closed T7904: GnuPG may downgrade digest algorithm to SHA1, a subtask of T7900: Cleartext Signature Forgery in GnuPG, as Resolved.
Fri, Jan 9, 11:01 AM · Not A Bug, OpenBSD, gnupg
werner closed T7904: GnuPG may downgrade digest algorithm to SHA1 as Resolved.

Note that for exploiting this bug a second preimage attack for SHA-1 is required. This kind of attack on SHA1 is not yet possible.

Fri, Jan 9, 11:01 AM · gnupg, Bug Report
werner triaged T8015: Kleopatra: Status in certificate list not updated after import as Normal priority.
Fri, Jan 9, 10:56 AM · kleopatra, gpd5x

Thu, Jan 8

werner changed the status of T7892: keyboxd: subkey listing issue with ADSKs from Open to Testing.
Thu, Jan 8, 4:13 PM · gnupg26, Bug Report, keyboxd, gnupg
werner raised the priority of T6644: GnuPG: Allow non compliant signatures in compliance mode from Wishlist to Normal.
Thu, Jan 8, 1:21 PM · vsd, gpd5x, kleopatra, gnupg22

Wed, Jan 7

werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

I think we are all wrong here. We were tricked by the fact that regardless of the outcome of the signature verification the signed content is shown. That is surprising for a cleartext signature because that one can be viewed anyway. Thus I propose to not update the clipboard unless the signature checks out.

Wed, Jan 7, 3:08 PM · gpd5x, vsd34, kleopatra
werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

I originally uploaded a wrong copy of the file. Now fixed; the correct checksum is 8d830a2dd7e1e14ecbc47b8cdc61d393e9d3f62c

Wed, Jan 7, 2:32 PM · gpd5x, vsd34, kleopatra
werner added a comment to T8020: Kleopatra: Notepad should not show "signed" text if signature is bad.

is a spoofed file which verifies okay but shows the inserted and not signed final line. FWIW, gpa gets it right.

Wed, Jan 7, 1:25 PM · gpd5x, vsd34, kleopatra
werner triaged T8017: Okular: Hang on signature with smime cert and distrusted root as High priority.
Wed, Jan 7, 12:06 PM · Bug Report, S/MIME, gpd5x, okular
werner triaged T8018: Okular: No error on signature with wrong passphrase as Normal priority.
Wed, Jan 7, 12:04 PM · Bug Report, gpd5x, okular
werner added a parent task for T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys: T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification.
Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
werner added a subtask for T7790: Kleopatra: "no trusted certification" should have precedence over "expired" in signature verification: T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys.
Wed, Jan 7, 12:03 PM · gpd5x, kleopatra
werner triaged T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys as Normal priority.

Traditionally we have considered expired and revoked more or less similar. The idea is that an expired key might have been compromised but the owner did not found a way to revoke it. We may want to change this policy because some users don't care too much about expired keys (cf. T7990) .

Wed, Jan 7, 12:03 PM · Feature Request, S/MIME, OpenPGP, gnupg26
werner added a comment to T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks.

Right. And the MDC detects this and only if says okay you get a good decryption status back.

Wed, Jan 7, 11:57 AM · Not A Bug, gnupg

Tue, Jan 6

werner committed rD488a4777c9f7: web: Fix typo (authored by werner).
web: Fix typo
Tue, Jan 6, 5:51 PM
werner committed rD7ac55ef6c70b: web: Swap Mastodon icon wth Fernmeldegeheimnis (authored by werner).
web: Swap Mastodon icon wth Fernmeldegeheimnis
Tue, Jan 6, 5:43 PM
werner committed rD142e60f21764: web: Link to our mastodon account. (authored by werner).
web: Link to our mastodon account.
Tue, Jan 6, 4:27 PM
werner committed rD63dde190af01: web: New debian packages (authored by werner).
web: New debian packages
Tue, Jan 6, 4:01 PM
werner added a comment to T1825: Add a re-encrypt to additional key.

Regarding my comment T1825#191055 : The mane page has long been updated and gpgme support is also available. For the symmetric session key, see the feature request T8016

Tue, Jan 6, 12:53 PM · gpd5x, gnupg26, Feature Request
werner triaged T8016: Keep symmetric encryption keys with --add-recipients as Low priority.
Tue, Jan 6, 12:51 PM · gpd5x, gnupg26, Feature Request
werner triaged T8013: gpgconf does not support the --enable-win32-openssh-support option for gpg-agent as Normal priority.

Frankly, he OpenSSH support for Windows was experimental and I have never tested it. If it can be confirmed that this really works and is useful, it will be easy to add the opeion to gpgconf. Note that the gpgconf option feature handles only a subset of all options on purpose.

Tue, Jan 6, 8:53 AM · Feature Request, ssh, gnupg26, Windows

Mon, Jan 5

werner updated the task description for T7906: Memory Corruption in ASCII-Armor Parsing.
Mon, Jan 5, 4:27 PM · gnupg, Bug Report
werner committed rG5f4ad39b16a4: doc: Rename an internal function to clarity the purpose. (authored by werner).
doc: Rename an internal function to clarity the purpose.
Mon, Jan 5, 4:08 PM
werner triaged T8012: Missing error on first key search without keyserver as Normal priority.
Mon, Jan 5, 3:17 PM · dirmngr, Bug Report, gnupg26
werner committed rG8d4fc76677cc: dirmngr: Help detection of bad keyserver configurations. (authored by werner).
dirmngr: Help detection of bad keyserver configurations.
Mon, Jan 5, 2:45 PM
werner changed the visibility for T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks.
Mon, Jan 5, 11:27 AM · Not A Bug, gnupg
werner changed the visibility for T7901: Cleartext Signature Forgery in NotDashEscaped header implementation in GnuPG.
Mon, Jan 5, 11:26 AM · gnupg, Bug Report
werner changed the visibility for T7900: Cleartext Signature Forgery in GnuPG.
Mon, Jan 5, 11:26 AM · Not A Bug, OpenBSD, gnupg

Fri, Jan 2

werner committed rGb8805d9a0f52: gpg: Error out on unverified output for non-detached signatures. (authored by werner).
gpg: Error out on unverified output for non-detached signatures.
Fri, Jan 2, 4:38 PM
werner changed the status of T7900: Cleartext Signature Forgery in GnuPG from Open to Testing.

(Testing for now for better visibility. Real or Semi-real bugs with fixes are already set to Resolved)

Fri, Jan 2, 4:38 PM · Not A Bug, OpenBSD, gnupg
werner changed the status of T7902: OpenPGP Cleartext Signature Framework, a subtask of T7900: Cleartext Signature Forgery in GnuPG, from Open to Testing.
Fri, Jan 2, 4:35 PM · Not A Bug, OpenBSD, gnupg
werner changed the status of T7902: OpenPGP Cleartext Signature Framework from Open to Testing.
Fri, Jan 2, 4:35 PM · Not A Bug, OpenPGP, FAQ, gnupg
werner closed T7903: Multiple Plaintext Attack on Detached PGP Signatures in GnuPG, a subtask of T7900: Cleartext Signature Forgery in GnuPG, as Resolved.
Fri, Jan 2, 4:24 PM · Not A Bug, OpenBSD, gnupg
werner closed T7903: Multiple Plaintext Attack on Detached PGP Signatures in GnuPG as Resolved.
Fri, Jan 2, 4:24 PM · Not A Bug, OpenPGP, gnupg
werner changed the status of T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks, a subtask of T7900: Cleartext Signature Forgery in GnuPG, from Open to Testing.
Fri, Jan 2, 4:22 PM · Not A Bug, OpenBSD, gnupg
werner changed the status of T7907: Encrypted Message Malleability Checks are Incorrectly Enforced Causing Plaintext Recovery Attacks from Open to Testing.

The described attack is not easy to understand and as of today the
gpg.fail website seems to have the same content as the draft we
received on 2025-10-23. There it states:

Fri, Jan 2, 4:22 PM · Not A Bug, gnupg
werner added a subtask for T7528: Make it possible to run Kleopatra VSD and Kleopatra GPD in parallel: T8008: GpgEX: UI server already running.
Fri, Jan 2, 2:08 PM · vsd34, test on hold, gpd5x, kleopatra
werner added a parent task for T8008: GpgEX: UI server already running: T7528: Make it possible to run Kleopatra VSD and Kleopatra GPD in parallel.
Fri, Jan 2, 2:08 PM · gpd5x, kleopatra, gpgex
werner added a comment to T8008: GpgEX: UI server already running.

No it is not related to T4030 because that has not yet been implemented. I am just upload a beta479 which should fix problem as wel as other similar problems.

Fri, Jan 2, 1:57 PM · gpd5x, kleopatra, gpgex
werner closed T8007: FTP website displays 2.4 stable as Resolved.
Fri, Jan 2, 1:52 PM · Bug Report
werner closed T8007: FTP website displays 2.4 stable, a subtask of T8006: 2.4 » 2.5 stable mentions, as Resolved.
Fri, Jan 2, 1:52 PM
werner added a comment to T8007: FTP website displays 2.4 stable.

Please use the the swdb.lst which has all the version info. The website is actually build using this info. Well, except for the README file in the FTP section. I will update that too.

Fri, Jan 2, 1:46 PM · Bug Report
werner committed rW0e6db1134b42: Update GnupG and frontend packages (authored by werner).
Update GnupG and frontend packages
Fri, Jan 2, 11:49 AM
werner added a comment to T7990: export-minimal unexpectedly omits expired key.

new export option keep-expired?

Fri, Jan 2, 11:47 AM · gnupg26, Feature Request, Gentoo

Thu, Jan 1

werner committed rD18a889b403c7: web: Update current version on the main page. (authored by werner).
web: Update current version on the main page.
Thu, Jan 1, 6:51 PM
werner closed T8002: Homepage shows 2.4.9 as current version as Resolved.

Thanks for reporting. Will be fixed in a few minutes.

Thu, Jan 1, 6:51 PM · Bug Report

Tue, Dec 30

werner committed rGd97e52cc7fc5: scd:openpgp: register vendor 4d52 (authored by werner).
scd:openpgp: register vendor 4d52
Tue, Dec 30, 5:48 PM
werner committed rD0e492b433a2f: swdb: GnuPG 2.4.9 (authored by werner).
swdb: GnuPG 2.4.9
Tue, Dec 30, 2:47 PM
werner committed rG4e17acdcc098: Post release updates (authored by werner).
Post release updates
Tue, Dec 30, 2:39 PM
werner committed rG21c7d29d6ed2: Release 2.4.9 (authored by werner).
Release 2.4.9
Tue, Dec 30, 2:39 PM
werner committed rG4c621127ee49: po: msgmerge (authored by werner).
po: msgmerge
Tue, Dec 30, 2:39 PM
werner updated the task description for T8001: Release GnuPG 2.4.9.
Tue, Dec 30, 1:49 PM · gnupg, Release Info
werner updated the task description for T7428: Release GnuPG 2.4.8.
Tue, Dec 30, 1:48 PM · gnupg, Release Info
werner triaged T8001: Release GnuPG 2.4.9 as Normal priority.
Tue, Dec 30, 1:48 PM · gnupg, Release Info
werner added a comment to T7990: export-minimal unexpectedly omits expired key.

What about prolonging the expired key?

Tue, Dec 30, 1:26 PM · gnupg26, Feature Request, Gentoo
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2025q4/000500.html on T7995: Release GnuPG 2.5.16.
Tue, Dec 30, 10:19 AM · gnupg, Release Info
werner committed rDf18d9ee65669: web: Announce 2.5.16 (authored by werner).
web: Announce 2.5.16
Tue, Dec 30, 10:01 AM
werner closed T7906: Memory Corruption in ASCII-Armor Parsing as Resolved.

Also fixed in the other active branches.

Tue, Dec 30, 9:56 AM · gnupg, Bug Report
werner closed T7906: Memory Corruption in ASCII-Armor Parsing, a subtask of T7900: Cleartext Signature Forgery in GnuPG, as Resolved.
Tue, Dec 30, 9:56 AM · Not A Bug, OpenBSD, gnupg
werner committed rG4ecc5122f20e: gpg: Fix possible memory corruption in the armor parser. (authored by werner).
gpg: Fix possible memory corruption in the armor parser.
Tue, Dec 30, 9:53 AM
werner updated the task description for T7940: Release GnuPG 2.5.15.
Tue, Dec 30, 9:18 AM · gnupg, Release Info
werner updated the task description for T7995: Release GnuPG 2.5.16.
Tue, Dec 30, 9:16 AM · gnupg, Release Info
werner updated the task description for T7996: Release GnuPG 2.5.17.
Tue, Dec 30, 9:15 AM · gnupg, Release Info