Page MenuHome GnuPG
Feed Advanced Search

Dec 21 2020

werner created T5191: Release libgpg-error 1.40.
Dec 21 2020, 10:01 AM · Release Info, gpgrt

Dec 20 2020

werner added a comment to T5190: g10 Compiler error .

OS, Compiler, any configure options?

Dec 20 2020, 2:37 PM · AIX, toolchain, gnupg
werner raised the priority of T5190: g10 Compiler error from High to Needs Triage.
Dec 20 2020, 2:37 PM · AIX, toolchain, gnupg
werner raised the priority of T4702: Deadline for the GnuPG 2.3.0 release from Normal to High.
Dec 20 2020, 2:35 PM · Restricted Project, gpg4win, gnupg

Dec 18 2020

werner committed rE4b09c8c2023d: core: Fix the "ignore" meta command of the argparser. (authored by werner).
core: Fix the "ignore" meta command of the argparser.
Dec 18 2020, 6:00 PM
werner committed rG8a2e5025eb0f: gpg: Fix --trusted-key with fingerprint arg. (authored by werner).
gpg: Fix --trusted-key with fingerprint arg.
Dec 18 2020, 5:10 PM
werner added a comment to T5188: gpg-card: "Unblock and set new a PIN" asks for Admin PIN instead of Reset Code.

"unblock and set a new PIN" might not be the best description given that we have an "unblock" command to let the user unblock the own PIN using hist reset code. But yes, it is expected that it asks for the Admin PIN.

Dec 18 2020, 12:34 PM
werner committed rG15bfd189c07e: dirmngr: Do not block threads in LDAP keyserver calls. (authored by werner).
dirmngr: Do not block threads in LDAP keyserver calls.
Dec 18 2020, 12:01 PM
werner committed rG355e2992c043: dirmngr: Do not block threads in LDAP keyserver calls. (authored by werner).
dirmngr: Do not block threads in LDAP keyserver calls.
Dec 18 2020, 11:57 AM
werner committed rG9e8d299e183d: Merge branch 'wk/stable-2.2-global-options' into STABLE-BRANCH-2-2 (authored by werner).
Merge branch 'wk/stable-2.2-global-options' into STABLE-BRANCH-2-2
Dec 18 2020, 11:30 AM
werner committed rG9b886adba4f8: dirmngr: Fix backport of the new option parser from 2.3 (authored by werner).
dirmngr: Fix backport of the new option parser from 2.3
Dec 18 2020, 11:23 AM
werner edited projects for T5187: i am not able to key pair, added: Support; removed Bug Report, gpg4win.
Dec 18 2020, 10:22 AM · Support
werner closed T5187: i am not able to key pair as Invalid.

For support please use one of the community resources (see gpg4win.org) and read the manula (compedium) or one of the hundreds of HOWTO floating in the net.

Dec 18 2020, 10:21 AM · Support

Dec 17 2020

werner committed rG4a3836e2b2f9: gpg: New AKL method "ntds" (authored by werner).
gpg: New AKL method "ntds"
Dec 17 2020, 6:26 PM
werner committed rG1194e4f7e2df: dirmngr: Support "ldap:///" for the current AD user. (authored by werner).
dirmngr: Support "ldap:///" for the current AD user.
Dec 17 2020, 6:26 PM
werner committed rG559efd23e936: gpg: New AKL method "ntds" (authored by werner).
gpg: New AKL method "ntds"
Dec 17 2020, 6:23 PM
werner committed rG776bef74c778: dirmngr: Support "ldap:///" for the current AD user. (authored by werner).
dirmngr: Support "ldap:///" for the current AD user.
Dec 17 2020, 6:23 PM
werner committed rGc75fd7553290: dirmngr: Allow LDAP searches via fingerprint. (authored by werner).
dirmngr: Allow LDAP searches via fingerprint.
Dec 17 2020, 11:20 AM
werner committed rGc28cb5282b14: dirmngr: Store all version 2 schema attributes. (authored by werner).
dirmngr: Store all version 2 schema attributes.
Dec 17 2020, 11:20 AM
werner committed rGac8ece92662d: dirmngr: Support the new Active Directory schema (authored by werner).
dirmngr: Support the new Active Directory schema
Dec 17 2020, 11:20 AM
werner committed rG0e88c73bc94f: dirmngr: Do not store the useless pgpSignerID in the LDAP. (authored by werner).
dirmngr: Do not store the useless pgpSignerID in the LDAP.
Dec 17 2020, 11:20 AM
werner committed rGe47de8538200: dirmngr: Fix adding keys to an LDAP server. (authored by werner).
dirmngr: Fix adding keys to an LDAP server.
Dec 17 2020, 11:20 AM
werner committed rG2cadcce3e877: dirmngr: Allow LDAP searches via fingerprint. (authored by werner).
dirmngr: Allow LDAP searches via fingerprint.
Dec 17 2020, 10:23 AM
werner committed rG2b06afbf260f: dirmngr: Finalize Active Directory LDAP Schema (authored by werner).
dirmngr: Finalize Active Directory LDAP Schema
Dec 17 2020, 10:23 AM

Dec 15 2020

werner committed rG2c6bb03cfb56: dirmngr: Remove superfluous attribute from the LDAP schema. (authored by werner).
dirmngr: Remove superfluous attribute from the LDAP schema.
Dec 15 2020, 3:50 PM
werner committed rGa2434ccabdd1: dirmngr: Store all version 2 schema attributes. (authored by werner).
dirmngr: Store all version 2 schema attributes.
Dec 15 2020, 3:50 PM

Dec 14 2020

werner committed rGe9ddd61fe979: dirmngr: Support the new Active Directory schema (authored by werner).
dirmngr: Support the new Active Directory schema
Dec 14 2020, 7:48 PM
werner committed rGcc056eb534c1: dirmngr: Do not store the useless pgpSignerID in the LDAP. (authored by werner).
dirmngr: Do not store the useless pgpSignerID in the LDAP.
Dec 14 2020, 7:48 PM
werner committed rG37a899d0e4fd: dirmngr: Fix adding keys to an LDAP server. (authored by werner).
dirmngr: Fix adding keys to an LDAP server.
Dec 14 2020, 7:48 PM
werner set Due Date to Mar 31 2021, 12:00 AM on T4294: Release Libgcrypt 1.9.0.
Dec 14 2020, 1:21 PM · Release Info, libgcrypt
werner added a comment to T4563: gpg-agent fails to sign request of PKISSH.

I do not think that we should support a fork of openssh right now. If we would support it we are bound to maintain that for years - this is not a good idea.

Dec 14 2020, 10:09 AM · Feature Request, gpgagent

Dec 12 2020

werner closed T5180: PKA export uses algorithm number for "ECDSA Curve P-384 with SHA-384" instead of "Ed25519" for "Ed25519/Ec25519" keys as Invalid.

PKA is dead but anyway: What you see is a record from a DNS zone file which has a specific semantic. The 14 for example means that 20 bytes follow.

Dec 12 2020, 1:28 PM · Bug Report
werner triaged T5179: add export-filter based on user ID calculated validity as Normal priority.
Dec 12 2020, 1:26 PM · gnupg24, gnupg (gpg23), Feature Request

Dec 11 2020

werner added a comment to T5177: GPG WKD lookup does not send correct SNI.

Than put something into the TXT - it does not matter and is only used to break the wildcard.

Dec 11 2020, 10:41 AM · FAQ, wkd
werner added a comment to T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client.

Hartmut, please read Andre's mail again - we can't do anything about it if Outlook considers an extra delay of 20ms as too slow.

Dec 11 2020, 10:07 AM · Support, gpg4win
werner closed T5178: scdaemon will throw "app_decipher failed" if "gpg --card-status" not issued beforehand as Resolved.

See the release info over at T5052 which notes the problem. See T5140 for details and update to 2.2.25.

Dec 11 2020, 10:04 AM · Duplicate, gnupg

Dec 10 2020

werner closed T5177: GPG WKD lookup does not send correct SNI as Resolved.

From the specs:

Dec 10 2020, 4:28 PM · FAQ, wkd
werner added a comment to T5177: GPG WKD lookup does not send correct SNI.

If you configure the subdomain in the DNS this will be used. Thus get a cert for it. The old method should not be used and thus if the openpgpkey subdomain exists gpg concludes that the admin is aware of the new scheme.

Dec 10 2020, 2:48 PM · FAQ, wkd
werner triaged T5176: Problem with Office 365 GnuPG Outlook addin, Outlook reports not to be primary Mail client as Normal priority.
Dec 10 2020, 11:41 AM · Support, gpg4win
werner edited projects for T5177: GPG WKD lookup does not send correct SNI, added: Support, wkd; removed Bug Report.
Dec 10 2020, 11:39 AM · FAQ, wkd
werner added a comment to T5177: GPG WKD lookup does not send correct SNI.

Nope, of course SNI is used. You problem is a different one. For example no root certificate, a server configured to allow only TLS 1.3, or a not supported algorithm. Decent versions of GnuPG print some hints if run with -v. BTW, an easier way to test is to use "gpg --locate-external-key" which basically does the same you did.

Dec 10 2020, 11:39 AM · FAQ, wkd
werner triaged T5173: GPA Could not show link as Normal priority.
Dec 10 2020, 11:32 AM · gpa, Windows, Bug Report
werner added projects to T5173: GPA Could not show link: Windows, gpa.
Dec 10 2020, 11:32 AM · gpa, Windows, Bug Report

Dec 9 2020

werner added a comment to T5172: GPA crashes in the pubkey preferences "use advanced mode" switching.

Sorry, I can' reproduce thus. What kind of key is causing the crash?

Dec 9 2020, 12:09 PM · gpa, Bug Report, gpg4win
werner committed rGc7c88648b71b: wks-client: Improve an error message (authored by werner).
wks-client: Improve an error message
Dec 9 2020, 11:57 AM

Dec 7 2020

werner closed T5169: gpg: Clarify output as Wontfix.

Sorry, no. Although the output of --list-packets should not be parsed and is subject to change with each versions we know that ppl do it anyway and things start to break. Even when we added lines starting with the usual comment sign (#) to indicate the offset of the packet, we received quite some bug reports. Thus such chnages will only be done when they are really needed. For all other the rule is still: Use the source, Luke.

Dec 7 2020, 7:50 PM · Bug Report
werner placed T5141: GnuPG: Make quick-gen-key work for keys on PIV cards up for grabs.
Dec 7 2020, 11:45 AM · gnupg (gpg23)
werner assigned T5166: gpg --quick-gen-key userid card fails on first run resp. for unknown key to gniibe.
Dec 7 2020, 11:23 AM

Dec 6 2020

werner added projects to T5167: GnuPG 2.25 still have problems related to Yubikey NEO.: scd, ssh, yubikey, gnupg (gpg22).

There is no caching for smardcard PINs. Once a key (or group of keys) on a hard has been used (i.e. PIN entered). that key can be used as long as the card has not been reset or powered-down. No rule without exception: Some cards may require that a PIN entry is required for each crypto operation. For example the OpenPGP card (which is implemented on a Yubikey) does this for the signing key but not for the authentication (ssh) key. To disable this for the signing key you use the "forcesig" command of gpg --card-edit.

Dec 6 2020, 5:00 PM · gnupg (gpg22), yubikey, ssh, scd, Bug Report
werner closed T5168: New computer, can't decrypt as Resolved.

Select your key in the certificate view, click right, select "Backup Secret keys ...", store to a file. Then copy that file in a secure why (USB stick etc) to the new box, import it there.

Dec 6 2020, 4:50 PM · Support, gpg4win

Dec 4 2020

werner added a comment to T4788: System wide configuration of the GnuPG system.

And I also did a backport to 2.2 :-) See rGa028f24136a062f55408a5fec84c6d31201b2143

Dec 4 2020, 12:21 PM · gnupg (gpg23), Feature Request, gpg4win, g10code
werner committed rGa028f24136a0: Backport of the new option parser from 2.3 (authored by werner).
Backport of the new option parser from 2.3
Dec 4 2020, 12:18 PM
werner added a comment to T5157: libgcrypt: ARM64 Builds on macOS fail.

We should not do this.

Dec 4 2020, 12:17 PM · toolchain, MacOS, libgcrypt, Bug Report

Dec 2 2020

werner committed rG63ed2054a1f3: kbx: Better error message in case of a crippled Libgcrypt. (authored by werner).
kbx: Better error message in case of a crippled Libgcrypt.
Dec 2 2020, 11:15 AM
werner committed rGacafa695e1e7: kbx: Better error message in case of a crippled Libgcrypt. (authored by werner).
kbx: Better error message in case of a crippled Libgcrypt.
Dec 2 2020, 11:14 AM
werner added a reviewer for D512: Adds Microsoft Edge (Chromium) browser support: aheinecke.
Dec 2 2020, 9:07 AM
werner added a comment to D513: Support macOS build with SIP by using posix_spawn in tests/random.

Given that this is limited to macOS I have neither objections for 1.8 nor for master

Dec 2 2020, 9:04 AM
werner added a comment to T5163: Cannot import NIST-P521 key to OpenPGP v3.3 smart card.

You better wipe ecc_d_padded or use xtrymalloc_secure.

Dec 2 2020, 8:45 AM · Restricted Project, gnupg, scd, Bug Report

Dec 1 2020

werner added a comment to T5159: make check fails for libgcrypt on Apple Silicon / ARM Mac.

Put

extern char **environ;

after the the include directives.

Dec 1 2020, 8:51 PM · Restricted Project, MacOS, libgcrypt, Bug Report
werner added projects to T5163: Cannot import NIST-P521 key to OpenPGP v3.3 smart card: Bug Report, scd, gnupg (gpg22).
Dec 1 2020, 8:49 PM · Restricted Project, gnupg, scd, Bug Report
werner committed rG4f9ac5dac093: doc: Add parameters for batch generation of ECC keys. (authored by Jens Meißner <meissner@b1-systems.de>).
doc: Add parameters for batch generation of ECC keys.
Dec 1 2020, 10:02 AM
werner committed rGa3f95a29b97d: doc: Add parameters for batch generation of ECC keys. (authored by Jens Meißner <meissner@b1-systems.de>).
doc: Add parameters for batch generation of ECC keys.
Dec 1 2020, 9:59 AM
werner created T5162: Import problem due to disabled brainpool curves.
Dec 1 2020, 9:35 AM · Bug Report, libgcrypt, gnupg (gpg22)
werner added a comment to T5141: GnuPG: Make quick-gen-key work for keys on PIV cards.

Go ahead (but w/o the /*if (keytime*)*/ line ;-)

Dec 1 2020, 9:11 AM · gnupg (gpg23)
werner added a comment to T5159: make check fails for libgcrypt on Apple Silicon / ARM Mac.

The problem is that posix_spawn is not portable enough for libgcrypt. It is really time that we move the spawn functions from gnupg to gpgrt so that we can use them also in Libgcrypt.

Dec 1 2020, 9:08 AM · Restricted Project, MacOS, libgcrypt, Bug Report

Nov 30 2020

werner updated subscribers of T5141: GnuPG: Make quick-gen-key work for keys on PIV cards.
Nov 30 2020, 3:31 PM · gnupg (gpg23)
werner added a comment to T5141: GnuPG: Make quick-gen-key work for keys on PIV cards.

The error comes form using READKEY which is processed by gpg-agent. At this time the agent does not yet know the stub key and thus returns ENOENT. At the places before we used "SCD READKEY" which works directly with scdameon and does not need a stub file. We need to review the new(?) way of creating stub files, describe that and then fix this by either making sure tha the stub key is created first or that we use SCD READKEY there too.

Nov 30 2020, 3:30 PM · gnupg (gpg23)
werner committed rG806547d9d243: scd:nks: Minor additions to the basic IDLM application support. (authored by werner).
scd:nks: Minor additions to the basic IDLM application support.
Nov 30 2020, 10:19 AM
werner added a subtask for T5159: make check fails for libgcrypt on Apple Silicon / ARM Mac: T5157: libgcrypt: ARM64 Builds on macOS fail.
Nov 30 2020, 8:47 AM · Restricted Project, MacOS, libgcrypt, Bug Report
werner added a parent task for T5157: libgcrypt: ARM64 Builds on macOS fail: T5159: make check fails for libgcrypt on Apple Silicon / ARM Mac.
Nov 30 2020, 8:47 AM · toolchain, MacOS, libgcrypt, Bug Report

Nov 29 2020

werner added a comment to T5157: libgcrypt: ARM64 Builds on macOS fail.

Why the hell do they that? The standard compiler on a system is called cc which may translated to whatever the system installs for it. gcc is a specific implementation with certain properties. Di you try CC=clang to override this?

Nov 29 2020, 4:41 PM · toolchain, MacOS, libgcrypt, Bug Report
werner added a comment to T5157: libgcrypt: ARM64 Builds on macOS fail.

You say that you build using clang but the log shows that you invoke gcc.

Nov 29 2020, 1:22 PM · toolchain, MacOS, libgcrypt, Bug Report
werner added projects to T5157: libgcrypt: ARM64 Builds on macOS fail: libgcrypt, MacOS, toolchain.
Nov 29 2020, 1:21 PM · toolchain, MacOS, libgcrypt, Bug Report
werner closed T5158: E-Mails will not be decrypted as Resolved.
Nov 29 2020, 1:19 PM · Support

Nov 27 2020

werner closed T4427: Windows 10 update KB4489899 stops gpg-agent launching as Resolved.

No more problems reported, so I assume like @aheinecke that it has been resolved in Windows.

Nov 27 2020, 6:36 PM · Info Needed, Windows, gpgagent, Bug Report
werner claimed T4398: Rework Console and command line handling on Windows.
Nov 27 2020, 6:33 PM · Feature Request, gnupg (gpg23)
werner closed T5038: UTF-8 handling in the command line, a subtask of T4398: Rework Console and command line handling on Windows, as Resolved.
Nov 27 2020, 6:33 PM · Feature Request, gnupg (gpg23)
werner closed T5038: UTF-8 handling in the command line as Resolved.

This has been fixed for Unix on 2.2 and 2.3. The command line fix for Windows is a larger thing already tracked by T4398.

Nov 27 2020, 6:33 PM · gnupg
werner closed T5038: UTF-8 handling in the command line, a subtask of T1514: charset weirdness with non-ascii User IDs under non-UTF-8 locales, as Resolved.
Nov 27 2020, 6:33 PM · Bug Report, gnupg
werner renamed T4398: Rework Console and command line handling on Windows from Rework Console handling on Windows to Rework Console and command line handling on Windows.
Nov 27 2020, 6:31 PM · Feature Request, gnupg (gpg23)
werner closed T1514: charset weirdness with non-ascii User IDs under non-UTF-8 locales as Resolved.

We changed the fallback to utf-8 in 2.2 and 2.3 and thus this bug can be closed. On Windows there is still the problem with the command line. However, this is better tracked with T5038 and its related tasks.

Nov 27 2020, 6:30 PM · Bug Report, gnupg
werner added a parent task for T5038: UTF-8 handling in the command line: T4398: Rework Console and command line handling on Windows.
Nov 27 2020, 6:26 PM · gnupg
werner added a subtask for T4398: Rework Console and command line handling on Windows: T5038: UTF-8 handling in the command line.
Nov 27 2020, 6:26 PM · Feature Request, gnupg (gpg23)
werner removed a project from T5038: UTF-8 handling in the command line: backport.
Nov 27 2020, 6:23 PM · gnupg
werner added a comment to T5150: scd: For NetKey cards READKEY with keygrip fails.

Regarding a backport I think that I will eventually backport all app-*c to stable by source copying them. We have a quite stable internal API and thus it is easier to keep at least the card specific code in sync. I did some local work in this directory some time ago.

Nov 27 2020, 5:54 PM · backport, gnupg (gpg23), scd
werner committed rG7d7a50ba7231: common: Fix fallback handling to utf-8. (authored by gniibe).
common: Fix fallback handling to utf-8.
Nov 27 2020, 5:49 PM
werner lowered the priority of T3392: keyserver default should include pool onionbalance hkp://jirk5u4osbsr34t5.onion from Normal to Wishlist.
Nov 27 2020, 5:39 PM · Keyserver, Feature Request, dirmngr
werner committed rGad469609b101: card: Let the APDU command prints a description of the status word. (authored by werner).
card: Let the APDU command prints a description of the status word.
Nov 27 2020, 11:28 AM
werner committed rG0e34683a6c4b: scd: New getinfo sub-command apdu_strerror. (authored by werner).
scd: New getinfo sub-command apdu_strerror.
Nov 27 2020, 11:28 AM
werner committed rG5804db1a13d2: card: Netkey improvement for passwd. (authored by werner).
card: Netkey improvement for passwd.
Nov 27 2020, 10:01 AM
werner added a project to T4614: GPG: Cancel on pinpad hangs decryption process for 20 seconds: backport.
Nov 27 2020, 7:58 AM · backport, Restricted Project, scd, gnupg

Nov 26 2020

werner added a comment to T5155: GPGol: Will work for one user and not another on the same machine. Windows 10 Outlook 2016 GPGOL 2.4.8 (gpg4win-3.1.14).

Recall that each user has their own keys and configuration. This seems to be a general question on how to use GpgOL. Please use the help resources listed at gpg4win.org instead of this bug tracker.

Nov 26 2020, 9:13 PM · Bug Report
werner reopened T4004: Curve25519 for Zeitcontrol card as "Open".
Nov 26 2020, 5:08 PM · Feature Request, scd
werner added a comment to T4004: Curve25519 for Zeitcontrol card.

You are right, the new 3.4 cards support brainpool curves in addition to the nist curves.

Nov 26 2020, 5:08 PM · Feature Request, scd
werner created T5156: Automatically dismiss the popup 'please insert card with S/N...'.
Nov 26 2020, 5:04 PM · scd, gnupg
werner added a comment to T5100: OpenPGP app overwrites Yubikey serial number.

Sorry, I realized this myself this morning and did couple of fixes. rG7113263a00d8 does this all however I forgot to mention the bug number.

Nov 26 2020, 4:55 PM · Restricted Project, gnupg, scd, yubikey, kleopatra
werner committed rG7113263a00d8: agent: Fix YK s/n and prettify the request card prompt for Yubikeys (authored by werner).
agent: Fix YK s/n and prettify the request card prompt for Yubikeys
Nov 26 2020, 3:58 PM
werner committed rG764c69a841ab: scd: Add special serialno compare for OpenPGP cards. (authored by werner).
scd: Add special serialno compare for OpenPGP cards.
Nov 26 2020, 12:18 PM
werner committed rGd784e763495c: scd: Do not try to use a non-enabled app after card switching. (authored by werner).
scd: Do not try to use a non-enabled app after card switching.
Nov 26 2020, 12:18 PM
werner added a project to T5150: scd: For NetKey cards READKEY with keygrip fails: backport.
Nov 26 2020, 7:55 AM · backport, gnupg (gpg23), scd