Page MenuHome GnuPG
Feed Advanced Search

Today

werner added a subtask for T4108: Support for verifying OpenPGP standalone and timestamp signatures: T4503: include extension for OpenPGP creation timestamp in X.509 output.
Tue, Feb 17, 9:57 AM · gnupg24, gnupg (gpg23), Feature Request
werner added a parent task for T4503: include extension for OpenPGP creation timestamp in X.509 output: T4108: Support for verifying OpenPGP standalone and timestamp signatures.
Tue, Feb 17, 9:57 AM · Feature Request, S/MIME
werner added a parent task for T4108: Support for verifying OpenPGP standalone and timestamp signatures: T4537: gpgsm support for timestamp signatures.
Tue, Feb 17, 9:56 AM · gnupg24, gnupg (gpg23), Feature Request
werner added a subtask for T4537: gpgsm support for timestamp signatures: T4108: Support for verifying OpenPGP standalone and timestamp signatures.
Tue, Feb 17, 9:56 AM · gnupg26, S/MIME, Feature Request
werner committed rG6d81e29392ed: po: Update Portuguese Translation. (authored by Daniel Cerqueira <dan.git@lispclub.com>).
po: Update Portuguese Translation.
Tue, Feb 17, 9:25 AM
werner committed rGac99481ee65a: g10: fix uninit use in aead filter. (authored by Sam James via Gnupg-devel <gnupg-devel@gnupg.org>).
g10: fix uninit use in aead filter.
Tue, Feb 17, 9:17 AM
werner committed rG0f5c9c845fda: g10: check null in assert (authored by Sam James via Gnupg-devel <gnupg-devel@gnupg.org>).
g10: check null in assert
Tue, Feb 17, 9:17 AM
werner committed rG1687dd35ee98: g10: fix uninit use (authored by Sam James via Gnupg-devel <gnupg-devel@gnupg.org>).
g10: fix uninit use
Tue, Feb 17, 9:17 AM

Sun, Feb 15

werner added a comment to T8094: libgcrypt: EC least leak failure.

FWIW: Okay, gmime is still a wrapper around gpgme. After decryption it has the ability to get the used session key from the gpgme result structure. Thus, I have been on the wrong trail. The actual problem is not gpgme but more GnuPG's use of Libgcrypt or an actual regression in Libgcrypt. Well, Friday 13th.

Sun, Feb 15, 4:37 PM · Info Needed, libgcrypt, Bug Report
werner added a comment to T8099: Kleopatra: no default OpenPGP server configured.

This has been specified in 1997 by PGP 5 for a good reason. We talked often enough about this and it does not help to repeat your ideas over and over again. RFC9580 specifies a different protocol than OpenPGP as specified by RFC2440 and RFC4880 but alas grabbed the name OpenPGP for this.

Sun, Feb 15, 3:26 PM · Keyserver, Support, gpg4win
werner added a comment to T8108: Gpgmepp getrandom zbase32 code has zero byte at the end.

I can't speak for gpgmpp but for gpgme. And the gpgme manual says:

Sun, Feb 15, 3:21 PM · Documentation, gpgmepp, Bug Report

Fri, Feb 13

werner committed rX146a0b455d69: po: Update Russian translation (authored by Ineiev <ineiev@gnu.org>).
po: Update Russian translation
Fri, Feb 13, 5:13 PM
werner committed rKb9e8f4b3d8d7: Fix double increment in DN parser while counting hexdigits. (authored by werner).
Fix double increment in DN parser while counting hexdigits.
Fri, Feb 13, 4:32 PM
werner moved T7133: Add feature to load designated revoker from LDAP from Backlog to WIP on the vsd34 board.
Fri, Feb 13, 3:35 PM · backport, vsd34, Feature Request, gnupg22
werner changed the status of T7133: Add feature to load designated revoker from LDAP from Open to Testing.
Fri, Feb 13, 3:35 PM · backport, vsd34, Feature Request, gnupg22
werner committed rG753175c74e9d: gpg: Autoload designated revoker key and ADSK when needed. (authored by werner).
gpg: Autoload designated revoker key and ADSK when needed.
Fri, Feb 13, 3:34 PM
werner added a comment to T7333: Allow gpg to auto-upload a new own key to LDAP servers.

Has now been backported to be released with 2.2.53

Fri, Feb 13, 2:55 PM · vsd34, gnupg26, gnupg22
werner moved T7333: Allow gpg to auto-upload a new own key to LDAP servers from Backlog to WIP on the vsd34 board.
Fri, Feb 13, 2:55 PM · vsd34, gnupg26, gnupg22
werner changed the status of T7333: Allow gpg to auto-upload a new own key to LDAP servers, a subtask of T6713: Kleopatra or GPG: Configuration to auto publish key changes, from Open to Testing.
Fri, Feb 13, 2:54 PM · kleopatra, Unknown Object (Project)
werner changed the status of T7333: Allow gpg to auto-upload a new own key to LDAP servers from Open to Testing.
Fri, Feb 13, 2:54 PM · vsd34, gnupg26, gnupg22
werner committed rG30ef06a56aa4: gpg: Add option --no-auto-key-upload. (authored by werner).
gpg: Add option --no-auto-key-upload.
Fri, Feb 13, 2:53 PM
werner committed rG780fac7788a8: gpg: Make --auto-upload also work for the --quick commands. (authored by werner).
gpg: Make --auto-upload also work for the --quick commands.
Fri, Feb 13, 2:53 PM
werner committed rG5feb3ba62cda: gpg: Make --auto-upload also work for --edit-key (authored by werner).
gpg: Make --auto-upload also work for --edit-key
Fri, Feb 13, 2:53 PM
werner committed rG5714ff20b4ac: gpg: New option --auto-key-upload (authored by werner).
gpg: New option --auto-key-upload
Fri, Feb 13, 2:53 PM
werner moved T7866: Allow separate LDAP keyserver for uploading from WIP to Done on the gnupg26 board.
Fri, Feb 13, 2:28 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner moved T7866: Allow separate LDAP keyserver for uploading from Backlog to WiP on the gnupg22 board.
Fri, Feb 13, 2:28 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner committed rG9c8232da83da: dirmngr: Improve LDAP debug output. (authored by werner).
dirmngr: Improve LDAP debug output.
Fri, Feb 13, 2:28 PM
werner committed rG39ca2f6dad38: dirmngr: New LDAP keyserver flag "upload" (authored by werner).
dirmngr: New LDAP keyserver flag "upload"
Fri, Feb 13, 2:28 PM
werner changed the status of T7866: Allow separate LDAP keyserver for uploading from Open to Testing.
Fri, Feb 13, 2:28 PM · gnupg22, vsd34, LDAP, Feature Request, gnupg26
werner committed rE57db619a0a69: po: Update Russian translation (authored by Ineiev <ineiev@gnu.org>).
po: Update Russian translation
Fri, Feb 13, 2:19 PM
werner added a comment to T8101: Upgrade of local (portable) installation failed.

Yeah sure.

Fri, Feb 13, 1:56 PM · Bug Report, gpg4win
werner committed rGPA181817bee9ee: po: Update Russian translation (authored by Ineiev <ineiev@gnu.org>).
po: Update Russian translation
Fri, Feb 13, 1:42 PM
werner edited projects for T8099: Kleopatra: no default OpenPGP server configured, added: Support, Keyserver; removed Bug Report.

keys.openpgp.org has two problems: a) it is a centralized service due to the requirement to confirm mail addresses. b) For non-confirmed keys it returns broken OpenPGP keys (ie. without a user id and thus without important information). For these reasons and the general problems with the keyserver-(networks) there is no more default.

Fri, Feb 13, 11:03 AM · Keyserver, Support, gpg4win
werner closed T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038 as Resolved.
Fri, Feb 13, 10:56 AM · Bug Report
werner closed T6464: No error message if PIN wrong on keytocard as Wontfix.
Fri, Feb 13, 10:55 AM · Unknown Object (Project)
werner added a comment to T6464: No error message if PIN wrong on keytocard.

Shall we change log_* functions also emit message to console, when file/socket is specified?

Fri, Feb 13, 10:55 AM · Unknown Object (Project)
werner added a comment to T8094: libgcrypt: EC least leak failure.

Any hints where to find the actual crypto code which uses libgcrypt?

Fri, Feb 13, 10:16 AM · Info Needed, libgcrypt, Bug Report
werner closed T8101: Upgrade of local (portable) installation failed as Invalid.

I'm surprised that nobody did detect these problems during the long beta phase...

Fri, Feb 13, 9:52 AM · Bug Report, gpg4win
werner closed T8101: Upgrade of local (portable) installation failed, a subtask of T8100: Kleopatra does not start on Windows Server 2016, as Invalid.
Fri, Feb 13, 9:52 AM · kleopatra, Bug Report, gpg4win, gpd5x, qt

Thu, Feb 12

werner committed rGPA196faca458d6: Release 0.11.1 (authored by werner).
Release 0.11.1
Thu, Feb 12, 3:09 PM
werner committed rGPA780fd3940c73: Post release updates (authored by werner).
Post release updates
Thu, Feb 12, 3:09 PM
werner added a parent task for T8101: Upgrade of local (portable) installation failed: T8100: Kleopatra does not start on Windows Server 2016.
Thu, Feb 12, 1:18 PM · Bug Report, gpg4win
werner added a subtask for T8100: Kleopatra does not start on Windows Server 2016: T8101: Upgrade of local (portable) installation failed.
Thu, Feb 12, 1:18 PM · kleopatra, Bug Report, gpg4win, gpd5x, qt
werner added a comment to T8101: Upgrade of local (portable) installation failed.

Please do not use the portable installation - it is dangerous to use it. We will eventually remove this option.

Thu, Feb 12, 1:18 PM · Bug Report, gpg4win
werner committed rDe535913d916d: Add missing marker flag in previous commit (authored by werner).
Add missing marker flag in previous commit
Thu, Feb 12, 12:10 PM
werner added a comment to T8103: gpa: relase new version please.

I also updated the software page. Thanks for the hint.

Thu, Feb 12, 11:51 AM · gpa
werner committed rD606f291fb8fb: web: Update the GPA software page (authored by werner).
web: Update the GPA software page
Thu, Feb 12, 11:51 AM
werner committed rD06e9a11c51c1: swdb: gpa 0.11.1 (authored by werner).
swdb: gpa 0.11.1
Thu, Feb 12, 11:50 AM
werner closed T8103: gpa: relase new version please as Resolved.

Done. See T7449

Thu, Feb 12, 11:28 AM · gpa
werner added a comment to T7449: Release GPA 0.11.

Noteworthy changes in version 0.11.1 (2026-02-12)

Thu, Feb 12, 11:26 AM · Release Info, gpa
werner claimed T8103: gpa: relase new version please.
Thu, Feb 12, 11:16 AM · gpa
werner lowered the priority of T8045: Stack-based buffer overflow in TPM2 `PKDECRYPT` from Unbreak Now! to Normal.
Thu, Feb 12, 11:14 AM · gnupg26, CVE, TPM, Bug Report
werner committed rGc0f9ca47f064: tools:gpg-authcode-sign.sh: Keep the log file on success. (authored by werner).
tools:gpg-authcode-sign.sh: Keep the log file on success.
Thu, Feb 12, 11:06 AM

Wed, Feb 11

werner committed rG2dde9ddf56fe: dirmngr: Let KS_SEARCH print all uid records for a key. (authored by werner).
dirmngr: Let KS_SEARCH print all uid records for a key.
Wed, Feb 11, 4:32 PM

Tue, Feb 10

werner committed rG86baca6e62b3: gpgscm: New operator "*long-time-t?" to detect proper time_t systems. (authored by werner).
gpgscm: New operator "*long-time-t?" to detect proper time_t systems.
Tue, Feb 10, 3:40 PM
werner triaged T8084: ctype(3) API use as Low priority.
Tue, Feb 10, 11:50 AM · NetBSD, gnupg, Bug Report
werner added a comment to T8097: AppImage ships Kleopatra icon in two different variants.

Won't fix for vsd3x

Tue, Feb 10, 11:50 AM · AppImage, Installer, kleopatra
werner triaged T8097: AppImage ships Kleopatra icon in two different variants as Normal priority.
Tue, Feb 10, 11:49 AM · AppImage, Installer, kleopatra
werner committed rW33707dbc0eab: Update libpng to 1.6.55 to due CVE-2026-25646. (authored by werner).
Update libpng to 1.6.55 to due CVE-2026-25646.
Tue, Feb 10, 11:46 AM
werner committed rWc739b47d05eb: msi: Yet another Perl syntax fix. (authored by werner).
msi: Yet another Perl syntax fix.
Tue, Feb 10, 11:33 AM
werner triaged T8094: libgcrypt: EC least leak failure as Low priority.

According to the ML @gniibe tried to replicate the problem without success.

Tue, Feb 10, 10:53 AM · Info Needed, libgcrypt, Bug Report

Mon, Feb 9

werner added a comment to T8096: GnuPG: quick-key-manipulation regression test FTBFS-2038.

Is that on a 32 bit machine or 64? The latter would be a problem for 32 bit with 32 bit time-t I'd say: we won't fix it.

Mon, Feb 9, 4:15 PM · Bug Report
werner added a comment to T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.

At least for an expired data signature I would suggest to have an info button to further expliah this. Maybe to a FAQ or KB article. The case is too rare that we should not discuss endlessly the pros and cons of expiring signatures. I hope that Kleo does not provide an option to crerate such a signature.

Mon, Feb 9, 3:30 PM · Bug Report, gpd5x, kleopatra
werner added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

Your fix is okay.

Mon, Feb 9, 10:13 AM · S/MIME, Bug Report, vsd34, kleopatra
werner added a project to T8084: ctype(3) API use: NetBSD.

AFAICS all conditions are protected by isascii(3) which

Mon, Feb 9, 9:49 AM · NetBSD, gnupg, Bug Report
werner triaged T8091: Kleopatra: Add kyber choices for x25519/x448 as Low priority.

Physical experiment feature support should better not be widely used.

Mon, Feb 9, 9:41 AM · gpd5x, PQC, Feature Request, kleopatra
werner triaged T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation as Low priority.
Mon, Feb 9, 9:40 AM · Feature Request, PQC, gnupg26
werner added a comment to T8092: GnuPG: Add algorithm info for all kyber choices on certificate generation.

Although it is technicall possible to use all combinations, we should limit in the menu them to those as listed above. Too many algorithms pose an interop problem. Thus we provide brainpool because it is required in Germany and the two IETF curves for the general internet (for those who are playing mitigation against against physical experiments).

Mon, Feb 9, 9:40 AM · Feature Request, PQC, gnupg26

Tue, Feb 3

werner added a comment to T7509: gpg4win: Make the AppImage build work with the new Docker-based build script.

With the recent changes to the build system the current version numbers for the Beta versions of the MSI packages are 4.0.90.<somenumber> for VSD, 5.0.90.xxx for GPD and Gpg4win. Thus we override the standard micro version with 90 to indicate beta versions. Obviously this will require to de-install a MSI beta version before installing the regular version. But we are somewhat constraint by the Windows versioning scheme.

Tue, Feb 3, 10:00 PM · gpd5x, AppImage, gpg4win
werner triaged T8083: Kleopatra: Use blue icon for Gpg4win and GPD as Normal priority.
Tue, Feb 3, 5:14 PM · gpg4win, Feature Request, kleopatra, gpd5x
werner closed T8071: libgrcypt 1.12.0: SmartOS (Solaris) build problem as Resolved.

Will go into 1.12.1

Tue, Feb 3, 4:43 PM · Solaris, Bug Report, libgcrypt
werner closed T8069: libgcrypt: NetBSD m68k as Resolved.

Thanks. Will go int the next version.

Tue, Feb 3, 4:43 PM · NetBSD, Feature Request, libgcrypt
werner committed rCbcae119ea592: mpi: Add configuration for NetBSD m68k (authored by werner).
mpi: Add configuration for NetBSD m68k
Tue, Feb 3, 4:42 PM
werner assigned T8073: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=summary Internal Server Error to fmg.
Tue, Feb 3, 4:39 PM · gpgweb
werner committed rW1d3323c2d48b: msi: Detect files which should not be in the source. (authored by werner).
msi: Detect files which should not be in the source.
Tue, Feb 3, 4:22 PM
werner committed rWa0d0ee0e5d75: msi: Use gnupg-vsd as program data folder for vsd 4.x (authored by werner).
msi: Use gnupg-vsd as program data folder for vsd 4.x
Tue, Feb 3, 4:03 PM
werner committed rW58b16cdb679b: Improve version numbering. (authored by werner).
Improve version numbering.
Tue, Feb 3, 4:03 PM
werner added projects to T8082: Kleopatra does not use the correct gpgconf: gpd5x, vsd34.
Tue, Feb 3, 3:45 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
werner triaged T8082: Kleopatra does not use the correct gpgconf as High priority.
Tue, Feb 3, 3:04 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
werner committed rEc58e004f004a: build: Introduce autogen.rc variable autogen_use_force (authored by werner).
build: Introduce autogen.rc variable autogen_use_force
Tue, Feb 3, 11:50 AM
werner committed rW162bbc164aa1: Remove support for GnuPG 2.4 (authored by werner).
Remove support for GnuPG 2.4
Tue, Feb 3, 10:15 AM
werner committed rWd76f3ed93cdc: Help to detect a forgotten ./autogen.sh --force. (authored by werner).
Help to detect a forgotten ./autogen.sh --force.
Tue, Feb 3, 10:15 AM

Mon, Feb 2

werner committed rGc86374ea7756: gpgconf: Show /proc/self/exe with -V and -X (authored by werner).
gpgconf: Show /proc/self/exe with -V and -X
Mon, Feb 2, 7:02 PM
werner added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Take care: Too many attributes (color, font) are bad style.

Mon, Feb 2, 5:08 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
werner triaged T8078: GpgAgent: trustlist.txt still requires LF on the last line as Low priority.

Oh yeah, the mentioned patch is bogus because it assumes that fgets has already set the eof flag while reading the last line. This seems not to be the case.

Mon, Feb 2, 3:46 PM · Bug Report, gpgagent, gnupg26
werner triaged T8076: Kleopatra: Unable to completely delete key with secret subkeys and "offline" primary key as Normal priority.
Mon, Feb 2, 12:08 PM · gnupg26, gpd5x, kleopatra, Bug Report
werner added a project to T8073: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=summary Internal Server Error: gpgweb.
Mon, Feb 2, 10:38 AM · gpgweb
werner added a comment to T8073: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gnupg.git;a=summary Internal Server Error.

AI scraper DoS --- sorry, we had to shut it down.

Mon, Feb 2, 10:37 AM · gpgweb
werner removed a member for g10code: TobiasFella.
Mon, Feb 2, 9:45 AM

Sun, Feb 1

werner added projects to T8069: libgcrypt: NetBSD m68k: Feature Request, NetBSD.
Sun, Feb 1, 2:14 PM · NetBSD, Feature Request, libgcrypt
werner added projects to T8071: libgrcypt 1.12.0: SmartOS (Solaris) build problem: Bug Report, Solaris.
Sun, Feb 1, 2:13 PM · Solaris, Bug Report, libgcrypt

Fri, Jan 30

werner committed rG987c6a398a95: scd:p15: Add support for D-Trust Card 6.1/6.4 (authored by hamarituc).
scd:p15: Add support for D-Trust Card 6.1/6.4
Fri, Jan 30, 3:32 PM
werner committed rGeb4a805de46f: scd: allow to query FCP when selecting an application (authored by hamarituc).
scd: allow to query FCP when selecting an application
Fri, Jan 30, 3:32 PM
werner committed rC65998903f6d1: Bumb version number to prepare the 1.10 branch (authored by werner).
Bumb version number to prepare the 1.10 branch
Fri, Jan 30, 10:44 AM
werner committed rC5d1da2c61981: kdf: Improve new KDF API. (authored by gniibe).
kdf: Improve new KDF API.
Fri, Jan 30, 10:44 AM
werner committed rC005fbb863a7a: Merge branch 'master' into LIBGCRYPT-1.10-BRANCH (authored by werner).
Merge branch 'master' into LIBGCRYPT-1.10-BRANCH
Fri, Jan 30, 10:44 AM
werner committed rC2ef408ba09e9: build: Fix accidental SO number bump. (authored by werner).
build: Fix accidental SO number bump.
Fri, Jan 30, 10:44 AM
werner committed rC72e104d7686d: Merge branch 'master' into LIBGCRYPT-1.10-BRANCH (authored by werner).
Merge branch 'master' into LIBGCRYPT-1.10-BRANCH
Fri, Jan 30, 10:44 AM
werner committed rCe4ab2147f3e2: Release 1.10.0 (authored by werner).
Release 1.10.0
Fri, Jan 30, 10:44 AM
werner committed rCf33510d93b1c: Merge branch 'master' into LIBGCRYPT-1.10-BRANCH (authored by werner).
Merge branch 'master' into LIBGCRYPT-1.10-BRANCH
Fri, Jan 30, 10:44 AM