Page MenuHome GnuPG
Feed Advanced Search

Nov 2 2021

werner committed rGf0162afb6b6f: common: New function substitute_envvars. (authored by werner).
common: New function substitute_envvars.
Nov 2 2021, 9:26 PM
werner committed rG152f0281552f: dns: Make reading resolv.conf more robust. (authored by gniibe).
dns: Make reading resolv.conf more robust.
Nov 2 2021, 9:26 PM
werner added a comment to T1621: Support multiple cards (not just readers).

Tehre has never been an option "shared-access" in GnuPG. At least not in upstream. In general we suggest the use of the interal ccid driver, but if you want PC/SC you need to use disable-ccid-driver. This is because 2.3 does not feature an automatic fallback to PC/SC anymore. Using pcsc-shared with OpenPGP cards can lead to surprising effects. You may want to try Scute as PCKSC#11 access module.

Nov 2 2021, 8:54 AM · gnupg, Feature Request
werner closed T5674: Place dirmngr.service and gpg-agent.service in session.slice as Wontfix.

Actually we do not really support the systemd thing and it is likeley that the support in GnuPG will eventually be removed again. You may want to contact the Debian maintainer, who took responsibility for all systemd things.

Nov 2 2021, 8:48 AM · Feature Request

Oct 31 2021

werner committed rEb1790f4cc71f: argparse: Add support to read values from the Windows Registry. (authored by werner).
argparse: Add support to read values from the Windows Registry.
Oct 31 2021, 7:53 PM
werner committed rE2a32501a561a: core: new internal function _gpgrt_w32_reg_get_string. (authored by werner).
core: new internal function _gpgrt_w32_reg_get_string.
Oct 31 2021, 7:53 PM

Oct 29 2021

werner added a comment to T5673: Using empty passphrase key pair, gpg2.2.9 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .

Does the key have a passsphrase or somehow the empty string as passphrase?
If you don't use lookback mode: does the pinentry pop up?

Oct 29 2021, 6:49 PM · gnupg (gpg22), Bug Report
werner added a comment to T5673: Using empty passphrase key pair, gpg2.2.9 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .

(I edited the report to make it readable, but did not yet looked at it in detail)
I wonder why you are using a decent libgcrypt but a 3 years old GnuPG version?

Oct 29 2021, 12:08 PM · gnupg (gpg22), Bug Report
werner updated the task description for T5673: Using empty passphrase key pair, gpg2.2.9 fails to decrypt with error "No secret key" on a gpg1.4/2.0 keyring format even though the secret keys migration was successful .
Oct 29 2021, 12:05 PM · gnupg (gpg22), Bug Report

Oct 27 2021

werner updated the task description for T5672: Kleopatra: Improve Kleopatras detection of keyservers.
Oct 27 2021, 4:21 PM · Restricted Project, scd, kleopatra
werner triaged T5672: Kleopatra: Improve Kleopatras detection of keyservers as High priority.
Oct 27 2021, 4:18 PM · Restricted Project, scd, kleopatra
werner triaged T5607: Fingerprint signing fails with 'gpg: signing failed: No secret key' as Low priority.

Sure there are logs, see the options log-file and debug in the man pages.
To sign using specific subkey or the main key, use the fingerprint of the key and append an exclamation mark.
For example

Oct 27 2021, 1:12 PM · Support, Info Needed, gnupg (gpg22)
werner changed the status of T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory from Open to Testing.

I think we can close this bug. The warning will now only be printed as part of the the regression test and after all it is just a warning.

Oct 27 2021, 1:02 PM · gnupg (gpg23), MacOS, Bug Report
werner added a parent task for T5671: (MYPROC_SELF_EXE): Support illumos and Solaris: T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.
Oct 27 2021, 12:58 PM · Bug Report
werner added a subtask for T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory: T5671: (MYPROC_SELF_EXE): Support illumos and Solaris.
Oct 27 2021, 12:58 PM · gnupg (gpg23), MacOS, Bug Report
werner closed T5671: (MYPROC_SELF_EXE): Support illumos and Solaris as Resolved.

Will go into 2.3.4 which will also silence the noise of not being able to read it. The major reason for this code is to allow building an AppImage.

Oct 27 2021, 12:57 PM · Bug Report
werner committed rG50e43af3f108: common: Support MYPROC_SELF_EXE for Solaris (authored by werner).
common: Support MYPROC_SELF_EXE for Solaris
Oct 27 2021, 12:55 PM
werner added a comment to T5671: (MYPROC_SELF_EXE): Support illumos and Solaris.

Thanks for the patch. That is sufficent. I added you to the Contributor group, though.

Oct 27 2021, 12:52 PM · Bug Report
werner added a member for Contributor: omnios.
Oct 27 2021, 12:51 PM

Oct 25 2021

werner added a comment to T5670: gpgconf --query-swdb incorrectly handles pre-release version numbers.

The thing is that any n.m.k-something version should behave versionwise the same as n.m.k. That is okay, because beta versions etc are not considered to be released. This is required to allow testing beta version _before_ doing the release.

Oct 25 2021, 11:14 PM · gpg4win, Bug Report
werner reassigned T5523: jitter entropy RNG update from werner to gniibe.
Oct 25 2021, 11:25 AM · FIPS, libgcrypt
werner edited projects for T5512: Implement service indicators, added: Feature Request; removed Bug Report.

We are currently using "implict" service indicators but eventually we may change Libgcrypt to support explicit indicators.

Oct 25 2021, 11:23 AM · Feature Request, FIPS, libgcrypt
werner lowered the priority of T5512: Implement service indicators from High to Normal.
Oct 25 2021, 11:20 AM · Feature Request, FIPS, libgcrypt

Oct 22 2021

werner committed rG918e9218002b: gpg: Fix printing of binary notations. (authored by werner).
gpg: Fix printing of binary notations.
Oct 22 2021, 4:34 PM
werner committed rG62f838ea1fca: gpg: Fix printing of binary notations. (authored by werner).
gpg: Fix printing of binary notations.
Oct 22 2021, 4:27 PM
werner added a comment to T5667: gpg(v) prints the human-readable form of notations to the status-fd.

Thanks.

Oct 22 2021, 3:42 PM · Bug Report
werner updated subscribers of T5574: Doubled characters in Windows console output.
Oct 22 2021, 3:04 PM · gnupg, Windows, Bug Report
werner added a project to T5574: Doubled characters in Windows console output: Info Needed.

@Reiner: Any news; were you able to run the the command with redirection to some file?

Oct 22 2021, 3:03 PM · gnupg, Windows, Bug Report
werner moved T5650: Check problems with gpgconf and global config files from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 22 2021, 12:25 PM · Restricted Project, gnupg (gpg22)
werner moved T5650: Check problems with gpgconf and global config files from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 22 2021, 12:24 PM · Restricted Project, gnupg (gpg22)
werner changed the status of T5650: Check problems with gpgconf and global config files from Open to Testing.
Oct 22 2021, 12:22 PM · Restricted Project, gnupg (gpg22)
werner committed rG5e3eea4b738c: gpgconf: create local option file even if a global file exists. (authored by werner).
gpgconf: create local option file even if a global file exists.
Oct 22 2021, 12:22 PM

Oct 20 2021

werner committed rG4cb44914b57a: common: Silence warning from unix_rootdir on systems w/o /proc (authored by werner).
common: Silence warning from unix_rootdir on systems w/o /proc
Oct 20 2021, 5:10 PM
werner committed rGe293da3b2149: common,w32: Do not always print "Garbled console data" warning. (authored by werner).
common,w32: Do not always print "Garbled console data" warning.
Oct 20 2021, 5:10 PM
werner added a comment to T5667: gpg(v) prints the human-readable form of notations to the status-fd.

So what is your bug report? Note that the NOTATION_FLAGS are only printed for human readable or critical notations.

Oct 20 2021, 4:26 PM · Bug Report
werner lowered the priority of T5546: Kleopatra: After importing the first pubkey for a card from LDAP the keylistview is not refreshed from Normal to Low.

Lets downgrade the priority and keep it open in case we get reports from customers. The other option would be to replicate this here using our AD demo network. But that is a bit time consuming.

Oct 20 2021, 12:26 PM · scd, Info Needed, Restricted Project, kleopatra
werner closed T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys. as Resolved.

Yes, but it is more complicated to do because you need to download a binary version of the keys and check that they are authentic. Most users don't known it. Anyway, I meanwhile created a Brainpool release sign key and new VSD releases are signed with that. The override option does not really harm, but we can close this bug due to the new release key.

Oct 20 2021, 12:21 PM · gnupg (gpg22), Restricted Project
werner added a parent task for T5653: de-vs and GnuPG 2.3.3 error: T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant.
Oct 20 2021, 12:18 PM · Restricted Project, gnupg (gpg23), kleopatra
werner added a subtask for T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant: T5653: de-vs and GnuPG 2.3.3 error.
Oct 20 2021, 12:18 PM · Restricted Project, kleopatra
werner reassigned T5362: Kleopatra: Add warning in compliance mode if gnupg version is not compliant from aheinecke to ikloecker.
Oct 20 2021, 12:16 PM · Restricted Project, kleopatra
werner triaged T5666: Create dropdown box for the reader-port option. as Normal priority.
Oct 20 2021, 11:05 AM · Restricted Project, kleopatra, Feature Request
werner added a comment to T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’.

Okay, any thing else missing in nPth?

Oct 20 2021, 8:37 AM · npth, Bug Report

Oct 19 2021

werner added a comment to T5662: Kleopatra: Show a list of detected card readers.

Yeah, that will be helpful. Thanks. FWIW GnuPG 2.2.32 also lists PC/SC readers and not just the Linux default of CCID readers.

Oct 19 2021, 5:35 PM · Restricted Project, kleopatra, Feature Request
werner triaged T5663: Kleopatra's "Check for updates" does not work as Normal priority.

Version check is a data leak anyway and thus often disabled. Thus I don't see a risk for high value targets.

Oct 19 2021, 2:59 PM · Restricted Project, gpg4win, kleopatra
werner added a comment to T5662: Kleopatra: Show a list of detected card readers.

Just to be sure: Can you c+p the strings?

Oct 19 2021, 2:25 PM · Restricted Project, kleopatra, Feature Request
werner assigned T5664: npth-1.6: error: unknown type name ‘pthread_rwlock_t’ to gniibe.

Hello @gniibe, you did the last work on nPTh. Would you be so kind and look into this?

Oct 19 2021, 1:06 PM · npth, Bug Report

Oct 18 2021

werner claimed T3204: Include documentation for technicians in Gpg4win that matches the packaged versions of GnuPG, GPGME.
Oct 18 2021, 4:42 PM · gpgweb, Windows, Documentation, gpg4win
werner added a comment to T3204: Include documentation for technicians in Gpg4win that matches the packaged versions of GnuPG, GPGME.

I would prefer to store legacy manuals on the web server. That is the easier solution.

Oct 18 2021, 4:42 PM · gpgweb, Windows, Documentation, gpg4win
werner added a comment to T5661: Symmetric only encryption with Kleopatra.

Cool. Thanks.

Oct 18 2021, 1:18 PM · Restricted Project, Feature Request, kleopatra
werner added a comment to T5645: RSA/DSA keygen modification for FIPS/ACVP testing.

( No need to certify the DSA things)

Oct 18 2021, 11:16 AM · libgcrypt, FIPS, Bug Report
werner moved T5645: RSA/DSA keygen modification for FIPS/ACVP testing from Next to Ready for release on the FIPS board.
Oct 18 2021, 11:15 AM · libgcrypt, FIPS, Bug Report
werner moved T5617: fips: Check library integrity before running selftests from Next to Ready for release on the FIPS board.
Oct 18 2021, 11:14 AM · FIPS, libgcrypt, Bug Report

Oct 17 2021

werner added a comment to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.

Urgs, I already implemented this:

Oct 17 2021, 6:46 PM · gnupg (gpg23), MacOS, Bug Report
werner added a comment to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory.

On macOS _NSGetExecutablePath could be used, but iiuc this requires linking against dyld. For other OSes we would also need more code. I doubt that this makes a lot of sense these days; but we should come up with a solution, even if that means we need an envvar to specify the location of that open gpgconf.ctl file.

Oct 17 2021, 6:41 PM · gnupg (gpg23), MacOS, Bug Report

Oct 16 2021

werner closed T5660: Second key decrypts messages it shouldn't as Resolved.

That looks like a support question. Please ask on a mailing list for help. Sorry, we can't do individual support here.

Oct 16 2021, 4:23 PM · Support

Oct 15 2021

werner triaged T5661: Symmetric only encryption with Kleopatra as High priority.
Oct 15 2021, 4:37 PM · Restricted Project, Feature Request, kleopatra
werner committed rD16f1d665623b: web: Fix old signature key URL (authored by werner).
web: Fix old signature key URL
Oct 15 2021, 12:30 PM
werner committed rDe2d4c796af58: web: Publish new signature key (authored by werner).
web: Publish new signature key
Oct 15 2021, 12:13 PM

Oct 14 2021

werner added a comment to T5652: Show the GnuPG version in Kleopatra.

Even better. Thanks,

Oct 14 2021, 8:03 PM · Restricted Project, gpg4win, Feature Request, kleopatra
werner added a comment to T5652: Show the GnuPG version in Kleopatra.

A way to get the output of "gpgconf --show-versions" might also be useful. Actually this command could be used to get the versions.

Oct 14 2021, 1:30 PM · Restricted Project, gpg4win, Feature Request, kleopatra
werner assigned T5652: Show the GnuPG version in Kleopatra to ikloecker.
Oct 14 2021, 1:29 PM · Restricted Project, gpg4win, Feature Request, kleopatra
werner triaged T5657: dirmngr: libdns sends malformed dns requests as Normal priority.
Oct 14 2021, 1:26 PM · Info Needed, Bug Report, dns, dirmngr
werner added a comment to T5657: dirmngr: libdns sends malformed dns requests.

dots are not allowed in hostnames.

Oct 14 2021, 1:25 PM · Info Needed, Bug Report, dns, dirmngr

Oct 13 2021

werner updated the task description for T5565: Release GnuPG 2.3.3.
Oct 13 2021, 8:23 PM · gnupg (gpg23), Release Info
werner committed rG773b8fbbe915: gpg: New option --override-compliance-check (authored by werner).
gpg: New option --override-compliance-check
Oct 13 2021, 5:39 PM
werner committed rGfb26e144adfd: gpg: New option --override-compliance-check (authored by werner).
gpg: New option --override-compliance-check
Oct 13 2021, 5:27 PM
werner added projects to T5656: Error emitted: gpg: error reading symlink '/proc/curproc/file': No such file or directory: MacOS, gnupg (gpg23).

We now require a way to get the actual image of a process. For macOS the BSD method is used and we obviously need to find another way for macOS.

Oct 13 2021, 5:03 PM · gnupg (gpg23), MacOS, Bug Report
werner triaged T5655: In -de-vs mode it is not possible so verify sigs with Ed25519 release keys. as High priority.
Oct 13 2021, 3:01 PM · gnupg (gpg22), Restricted Project
werner triaged T5621: No '%ProgramData%\GNU', '%ProgramData%\GNU\etc', '%ProgramData%\GNU\etc\gnupg' or '%ProgramData%\GNU\etc\gnupg\trusted-certs' or '%ProgramData%\GNU\etc\gnupg\extra-certs' get created after setup as Normal priority.
Oct 13 2021, 8:29 AM · Documentation, Not A Bug, gpg4win
werner committed rDa4f6a3a9040b: web: Release announcement for GnuPG 2.3.3 (authored by werner).
web: Release announcement for GnuPG 2.3.3
Oct 13 2021, 8:23 AM

Oct 12 2021

werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2021q4/000466.html on T5565: Release GnuPG 2.3.3.
Oct 12 2021, 7:44 PM · gnupg (gpg23), Release Info
werner committed rDdbefe28fc81d: swdb: Release GnuPG 2.3.3 (authored by werner).
swdb: Release GnuPG 2.3.3
Oct 12 2021, 6:20 PM
werner closed T5405: Release GnuPG 2.3.2 as Resolved.

The new bugs have been fixed in 2.3.3; see T5565.

Oct 12 2021, 6:17 PM · gnupg (gpg23), Release Info
werner closed T5565: Release GnuPG 2.3.3 as Resolved.
Oct 12 2021, 6:16 PM · gnupg (gpg23), Release Info
werner updated the task description for T5654: Release GnuPG 2.3.4.
Oct 12 2021, 6:15 PM · gnupg (gpg23), Release Info
werner committed rGd7d26eff851a: Post release updates (authored by werner).
Post release updates
Oct 12 2021, 6:11 PM
werner committed rG9470d0338364: Release 2.3.3 (authored by werner).
Release 2.3.3
Oct 12 2021, 6:11 PM
werner committed rG10f52f9bf3bc: speedo: Put the keyboxd into the Windows installer (authored by werner).
speedo: Put the keyboxd into the Windows installer
Oct 12 2021, 6:11 PM
werner committed rGbcd5feec0e91: tests: New way to make use of gpgconf.ctl in tests. (authored by werner).
tests: New way to make use of gpgconf.ctl in tests.
Oct 12 2021, 6:11 PM
werner triaged T5654: Release GnuPG 2.3.4 as Low priority.
Oct 12 2021, 6:09 PM · gnupg (gpg23), Release Info
werner triaged T5653: de-vs and GnuPG 2.3.3 error as Normal priority.
Oct 12 2021, 4:56 PM · Restricted Project, gnupg (gpg23), kleopatra
werner triaged T5652: Show the GnuPG version in Kleopatra as Normal priority.
Oct 12 2021, 4:44 PM · Restricted Project, gpg4win, Feature Request, kleopatra
werner added a comment to T5634: Failure with: make DESTDIR=xxx install .

I won't anymore follow the path of first doing a test install. That is way to hairy in respect to "make distcheck". Change is already in my working directory.

Oct 12 2021, 2:38 PM · Bug Report
werner added a comment to T5590: OpenPGP: Curve 448, modernize?.

Is that really required? Should we wait what the conlusion of the WG will be?

Oct 12 2021, 2:35 PM · rationale, gnupg, OpenPGP
werner added a comment to T5616: asn1-parse.y:861:20: error: 'yytoknum' undeclared.

Bison used to be the de-facto standard yacc ;-)

Oct 12 2021, 2:33 PM · toolchain, libksba, Bug Report
werner added a comment to T5644: Heuristic for default reader detection.

On my new Windows 10 laptop I see a "Windows Hello for Business 1". Thus put everything with "Windows Hello" at the end of the list or skip unless a reader-port is set. IIRC there are device with "virtual" or "Virtual" in their name, they don't make sense for us either. I would also put devices with "SCM" or "Identiv" to the top of the list. In particular the substrings "SPR532" seems to identify the Identiv SPR332 which is what we use here and actualay a suggested reader for GnUPG VS-Desktop.

Oct 12 2021, 8:44 AM · Restricted Project, Feature Request, gnupg (gpg22)

Oct 11 2021

werner raised the priority of T5616: asn1-parse.y:861:20: error: 'yytoknum' undeclared from Normal to High.

Thanks for your findings. I recall that I read this in the announcement and cursed about this new tendency in GNU to break long standing APIs.

Oct 11 2021, 5:49 PM · toolchain, libksba, Bug Report
werner renamed T5649: Issue better error message for invalid OpenPGP RSA keys from GnuPG randomly generates invalid RSA signatures if secret key has P > Q. to Issue better error message for invalid OpenPGP RSA keys.
Oct 11 2021, 5:45 PM · gnupg24, OpenPGP, Feature Request
werner triaged T5649: Issue better error message for invalid OpenPGP RSA keys as Normal priority.

OpenPGP requires the P < U property and gpg does also. In some parts of the GnuPG we re-calculate the CRT parameters but not in these code paths. Right, a better error message would be appropriate. I'll turn this into a feature request.

Oct 11 2021, 5:45 PM · gnupg24, OpenPGP, Feature Request
werner triaged T5650: Check problems with gpgconf and global config files as High priority.
Oct 11 2021, 5:39 PM · Restricted Project, gnupg (gpg22)
werner closed T5648: UPLOAD Keyserver / Kleopatra Gpg4win-3.1.16 Kleopatra as Resolved.

Please ask on a mailing list etc. This is a bug tracker and pnly very few people are reading your report.

Oct 11 2021, 8:45 AM · Support
werner closed T5647: UPLOAD Keyserver as Invalid.
Oct 11 2021, 8:42 AM
werner committed rGcf29c7dec0e8: Do not build keyxboxd if sqlite has been disabled. (authored by werner).
Do not build keyxboxd if sqlite has been disabled.
Oct 11 2021, 7:54 AM
werner committed rG257632f58d92: build: Let the release target also sign the wixlib. (authored by werner).
build: Let the release target also sign the wixlib.
Oct 11 2021, 7:54 AM

Oct 10 2021

werner closed T5632: gpg-agent 2.3.2 conflicts with pcscd as Resolved.
Oct 10 2021, 7:04 PM · Not A Bug, yubikey, scd, gnupg (gpg23)
werner closed T3412: gpg-agent manual page says to always add GPG_TTY to `.bashrc` as Resolved.
Oct 10 2021, 7:02 PM · Not A Bug, gnupg
werner closed T5539: Key generation on OpenPGP Version 3.4 card fails as Resolved.

As long as we can't replicate this, it does not make sense to keep this bug open. Please re-open it if you run into it again in a replicatable way.

Oct 10 2021, 6:59 PM · can't replicate, OpenPGP, scd, Bug Report, gpg4win
werner closed T5613: GpgEX does not use CSIDL_LOCAL_APPDATA as Resolved.

Fixed in gpgex 1.0.8

Oct 10 2021, 6:53 PM · Windows, kleopatra, gpgex
werner closed T5622: 'HKLM\Software\GNU\GnuPG' registry key does not already exist after end of setup, but users might expect to find it as Resolved.
Oct 10 2021, 6:49 PM · Not A Bug, gpg4win
werner closed T5621: No '%ProgramData%\GNU', '%ProgramData%\GNU\etc', '%ProgramData%\GNU\etc\gnupg' or '%ProgramData%\GNU\etc\gnupg\trusted-certs' or '%ProgramData%\GNU\etc\gnupg\extra-certs' get created after setup as Resolved.

Sure they don't get created - they are optional.

Oct 10 2021, 6:48 PM · Documentation, Not A Bug, gpg4win