Page MenuHome GnuPG
Feed Advanced Search

Apr 13 2022

werner triaged T5928: Release GnuPG 2.2.35 as Low priority.
Apr 13 2022, 2:23 PM · Release Info, gnupg (gpg22)
werner committed rGe99670f944bc: scd:p15: Improve the PIN prompt for Genua cards. (authored by werner).
scd:p15: Improve the PIN prompt for Genua cards.
Apr 13 2022, 1:59 PM
werner committed rG44ec383cdec0: scd:p15: Support for GeNUA cards. (authored by werner).
scd:p15: Support for GeNUA cards.
Apr 13 2022, 1:59 PM
werner committed rG80cf64c65155: scd:p15: Add basic support for AET JCOP cards. (authored by werner).
scd:p15: Add basic support for AET JCOP cards.
Apr 13 2022, 1:59 PM
werner committed rG29fd80581867: scd:p15: Prepare AODF parsing for other authentication types. (authored by werner).
scd:p15: Prepare AODF parsing for other authentication types.
Apr 13 2022, 1:59 PM
werner committed rG618aa8689a9b: scd:p15: Improve the PIN prompt for Genua cards. (authored by werner).
scd:p15: Improve the PIN prompt for Genua cards.
Apr 13 2022, 1:09 PM
werner committed rG0dcc24985235: scd: Support for GeNUA cards. (authored by werner).
scd: Support for GeNUA cards.
Apr 13 2022, 1:09 PM
werner committed rG137e59a6a5c5: sm: Print diagnostic about CRL problems due to Tor mode. (authored by werner).
sm: Print diagnostic about CRL problems due to Tor mode.
Apr 13 2022, 1:09 PM

Apr 12 2022

werner committed rW96dc7a876820: msi: Ignore 2nd level subdirs named misc. (authored by werner).
msi: Ignore 2nd level subdirs named misc.
Apr 12 2022, 1:02 PM

Apr 11 2022

werner added a comment to T5920: libassuan: Don't inherit handles for Windows.

We once figured that we should use this for gpgme, where we use a helper to close handles. We have not yet found the time to do this and frankly "never change a running system" ;-) We also still support Windows XP SP3 with GnuPG for users with air-gaped machines. Not sure whether this is still justified, though.

Apr 11 2022, 9:28 AM

Apr 9 2022

werner added a comment to T5927: gpg: quick-gen-key and quick-add-uid require --check-trustdb to make trust in user ids "ultimate".

The reason for this is probably that we expect that several UIDs are added and running a check-trustdb for eachleads to some extra waiting time.

Apr 9 2022, 3:11 PM · Feature Request, gnupg, Bug Report

Apr 8 2022

werner committed rG198fad9fc1f3: doc: Typo fix in comment (authored by werner).
doc: Typo fix in comment
Apr 8 2022, 4:09 PM
werner committed rG8945f1aedfd7: gpg: Remove restrictions for the name part of a user-id. (authored by werner).
gpg: Remove restrictions for the name part of a user-id.
Apr 8 2022, 4:09 PM
werner committed rGca3e46a587f6: tpm: Fix recently introduced syntax error (authored by werner).
tpm: Fix recently introduced syntax error
Apr 8 2022, 4:09 PM

Apr 7 2022

werner added a comment to T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high).

Updated the copy on our mirror as welll as the gpg4win and swdb packages files.

Apr 7 2022, 11:45 AM · gnupg (gpg22), CVE, gpg4win
werner committed rWa7d49129a241: packages: Update zlib to 1.2.12 (authored by werner).
packages: Update zlib to 1.2.12
Apr 7 2022, 11:42 AM
werner committed rDf7cdcbd7057e: swdb: Updated mirrored zlib to 1.2.12 (authored by werner).
swdb: Updated mirrored zlib to 1.2.12
Apr 7 2022, 11:39 AM
werner committed rW35bb72337710: packages: Update gpgrt and ntbtls (authored by werner).
packages: Update gpgrt and ntbtls
Apr 7 2022, 11:37 AM
werner committed rT660c2f89dc38: Post release updates (authored by werner).
Post release updates
Apr 7 2022, 11:21 AM
werner committed rT802494e014c8: Release 0.3.1 (authored by werner).
Release 0.3.1
Apr 7 2022, 11:21 AM
werner committed rDa727cc944ce8: swdb: gpgrt 1.45 and ntbtls 0.3.1 (authored by werner).
swdb: gpgrt 1.45 and ntbtls 0.3.1
Apr 7 2022, 11:08 AM
werner closed T5802: Release libgpg-error 1.45 as Resolved.
Apr 7 2022, 10:52 AM · Release Info, gpgrt
werner reopened T5923: Release Libgpg-error 1.46 as "Open".
Apr 7 2022, 10:51 AM · Release Info, gpgrt
werner closed T5923: Release Libgpg-error 1.46 as Resolved.
Apr 7 2022, 10:49 AM · Release Info, gpgrt
werner committed rE038d34656f5b: Post release updates (authored by werner).
Post release updates
Apr 7 2022, 10:46 AM
werner committed rEff3b2ea8858a: Merge branch 'master' of ssh+git://playfair.gnupg.org/git/libgpg-error (authored by werner).
Merge branch 'master' of ssh+git://playfair.gnupg.org/git/libgpg-error
Apr 7 2022, 10:46 AM
werner committed rEdbac537e5e86: Release 1.45 (authored by werner).
Release 1.45
Apr 7 2022, 10:46 AM
werner triaged T5923: Release Libgpg-error 1.46 as Low priority.
Apr 7 2022, 10:39 AM · Release Info, gpgrt
werner triaged T5919: libgcrypt tests/basic.c and tests/keygen.c occasionally fail with "error generating RSA key: Number is not prime" as Normal priority.

The set_bit is obvious but we should cross check with the specs. In the non-fips mode we also try w/o a limit.

Apr 7 2022, 10:04 AM · backport, FIPS, libgcrypt, Bug Report

Apr 6 2022

werner committed rDb6d49e1b67e5: verein: fix links. (authored by werner).
verein: fix links.
Apr 6 2022, 9:18 AM

Apr 5 2022

werner lowered the priority of T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) from Unbreak Now! to High.

The fix is from 2018 but was not picked up widely; see
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531

Apr 5 2022, 12:14 PM · gnupg (gpg22), CVE, gpg4win
werner added a comment to T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high).

Sorry, that was a misunderstanding. My fault.

Apr 5 2022, 11:43 AM · gnupg (gpg22), CVE, gpg4win
werner reopened T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) as "Open".
Apr 5 2022, 11:39 AM · gnupg (gpg22), CVE, gpg4win

Apr 4 2022

werner closed T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine as Resolved.

In fact, decent 2.2 versions (>=2.2.21) have the ability to decrypt AEAD packets - this has been implemented exactly for the case that some things get wrong at the user site. But we can't change old versions - we are not the Sirius Computer Corporation. I close this ticket because we can can't do anything if you are not able/willing to update to the latest version of the respective branch. Sorry.

Apr 4 2022, 6:43 AM · gnupg, Support

Apr 1 2022

werner triaged T5915: Allow Registry configuration of GpgEX as Normal priority.
Apr 1 2022, 11:38 AM · Restricted Project, Feature Request, gpgex

Mar 31 2022

werner assigned T5913: libgcrypt: bug fix for PPC bulk AES-GCM acceleratieration, missing HWF_PPC_ARCH_3_10 in HW feature to jukivili.
Mar 31 2022, 10:46 PM · ppc, libgcrypt
werner added a comment to T4924: pinentry: pinentry-curses doesn't allow to set no password or weak passwords on 80 char width and smaller terminals.

There is also the very simple pinentry-tty

Mar 31 2022, 8:07 PM · pinentry, Bug Report
werner committed rW1094535c379e: Ignore the Standard/etc directory in make-msi.pl (authored by werner).
Ignore the Standard/etc directory in make-msi.pl
Mar 31 2022, 4:30 PM
werner committed rC35a7409dcf29: random:drbg: Fix the behavior for child process. (authored by gniibe).
random:drbg: Fix the behavior for child process.
Mar 31 2022, 9:27 AM
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

I don't like it either but the browser vendors don't like SRV records.

Mar 31 2022, 9:03 AM · wkd, gpg4win, Bug Report

Mar 30 2022

werner committed rT08c1622944da: Allow ephemeral ECDSA cipher suites. (authored by werner).
Allow ephemeral ECDSA cipher suites.
Mar 30 2022, 8:39 PM
werner committed rTa95b108c6cfd: Make X25519 support depend on the Libgcrypt version (authored by werner).
Make X25519 support depend on the Libgcrypt version
Mar 30 2022, 8:39 PM
werner committed rTc08cc859a930: Post release updates (authored by werner).
Post release updates
Mar 30 2022, 8:39 PM
werner committed rT97a5cdaedbe9: Release 0.3.0 (authored by werner).
Release 0.3.0
Mar 30 2022, 8:39 PM
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

I still think that redirecting to another catch-all domain is contrary to the original goal and weakens the security model. We need to see what we can do about this.

Mar 30 2022, 6:07 PM · wkd, gpg4win, Bug Report
werner closed T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) as Resolved.

Not in the way it is used by gpg. See T5880

Mar 30 2022, 6:04 PM · gnupg (gpg22), CVE, gpg4win
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

The ECDHE_ECDSA suites are not yet implemented in ntbtls and thus we can't agree on a common cipher suite. Will be solved in the next Windows version.

Mar 30 2022, 3:35 PM · wkd, gpg4win, Bug Report
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

Are you using 2.3.4 also on Windows?

Mar 30 2022, 12:15 PM · wkd, gpg4win, Bug Report
werner created T5909: Make use of the LDAP revoked attribute.
Mar 30 2022, 11:49 AM · Feature Request, LDAP, OpenPGP, gpgme, dirmngr
werner closed T5907: bench-slope missing brainpool curves in master branch as Resolved.

see rC67b36154f88e for master.

Mar 30 2022, 9:07 AM · libgcrypt, Bug Report
werner committed rC67b36154f88e: tests: Add brainpoolP256r1 to bench-slope. (authored by werner).
tests: Add brainpoolP256r1 to bench-slope.
Mar 30 2022, 9:06 AM
werner added a comment to T5907: bench-slope missing brainpool curves in master branch.

Will add it. The reason I added Brainpool was due to a question on the performacne between Brainpool and other NIST.

Mar 30 2022, 9:03 AM · libgcrypt, Bug Report

Mar 28 2022

werner committed rD6698ad8b26a9: web: Release info for libgcrypt 1.10.1 (authored by werner).
web: Release info for libgcrypt 1.10.1
Mar 28 2022, 4:50 PM
werner closed T5810: Release Libgcrypt 1.10.1 as Resolved.
Mar 28 2022, 4:43 PM · libgcrypt, Release Info
werner committed rD52655a0e8f23: swdb: Libgcrypt 1.10.2 (authored by werner).
swdb: Libgcrypt 1.10.2
Mar 28 2022, 4:25 PM
werner closed T5902: GnuPG dirmngr sends incorrect l parameter to a WKD server as Resolved.

Good idea. Thanks. Goes onto 2.3 and 2.2

Mar 28 2022, 4:15 PM · dirmngr, gnupg, wkd, Bug Report
werner committed rG3b251c8366cf: dirmngr: Escape more characters in WKD requests. (authored by werner).
dirmngr: Escape more characters in WKD requests.
Mar 28 2022, 4:15 PM
werner committed rG435861b9fb8c: dirmngr: Escape more characters in WKD requests. (authored by werner).
dirmngr: Escape more characters in WKD requests.
Mar 28 2022, 4:13 PM
werner triaged T5905: Release Libgcrypt 1.10.2 as Low priority.
Mar 28 2022, 3:44 PM · Release Info, libgcrypt
werner committed rG253fcb97775b: gpg: Remove EAX from the preference list. (authored by werner).
gpg: Remove EAX from the preference list.
Mar 28 2022, 3:27 PM
werner committed rC951b7d987cdb: doc: Typo and grammar fixes. (authored by werner).
doc: Typo and grammar fixes.
Mar 28 2022, 8:30 AM
werner committed rC26ac5e30018f: hash: Add more OIDs. (authored by werner).
hash: Add more OIDs.
Mar 28 2022, 8:30 AM
werner committed rCec656616bbbb: build: Improve sign-release traget (authored by werner).
build: Improve sign-release traget
Mar 28 2022, 8:30 AM
werner added a comment to T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine.

Use a gpg 2.3 version:

Mar 28 2022, 12:00 AM · gnupg, Support

Mar 25 2022

werner closed T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine as Resolved.
  • No we can't because current GnuPG 2.2 versions are able to decrypt such AEAD data.
Mar 25 2022, 7:37 PM · gnupg, Support
werner committed rG90caa7ad598b: dirmngr: Workaround for a certain broken LDAP URL (authored by werner).
dirmngr: Workaround for a certain broken LDAP URL
Mar 25 2022, 1:36 PM
werner renamed T5885: Better message than "Inappropriate ioctl for device" for tty pinentries from gpg --import of secret key from stdin fails confusingly to Better message than "Inappropriate ioctl for device" for tty pinentries.
Mar 25 2022, 1:30 PM · Feature Request, pinentry, gnupg
werner triaged T5898: Two fixes for the gnupg-2.3.4 test suite when running on MS-Windows as Normal priority.
Mar 25 2022, 1:28 PM · Windows, gnupg (gpg23), Bug Report
werner triaged T5894: Various issues with system headers and _WIN32_WINNT value in MinGW build of gnupg-2.3.4 as Normal priority.
Mar 25 2022, 1:27 PM · gnupg, Feature Request
werner added a comment to T5895: Fix an error in w32_try_mkdir from gnupg-2.3.4.

See also T5537 and commit rG7d1215cb9cba2 for 2.2.

Mar 25 2022, 1:26 PM · Bug Report
werner committed rG0f03bdcd2e61: common,w32: Fix early home dir creation. (authored by werner).
common,w32: Fix early home dir creation.
Mar 25 2022, 1:24 PM
werner closed T5895: Fix an error in w32_try_mkdir from gnupg-2.3.4 as Resolved.

There is actually a much easier fix here. Thanks for pointing out the problem. For histroical reasons we have several places where we create the homedir.

Mar 25 2022, 1:24 PM · Bug Report
werner edited projects for T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine, added: gnupg; removed Mutt.

Packet 20 is the new AEAD packet which GnuPG 2.3 can generate and does generate if all recipients have new keys generated with such a versions. However, the version of gpg you use now does not support AEAD and thus fails.

Mar 25 2022, 12:04 AM · gnupg, Support

Mar 24 2022

werner lowered the priority of T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine from Unbreak Now! to Normal.
Mar 24 2022, 11:53 PM · gnupg, Support

Mar 23 2022

werner closed T5896: Honor HOME envfironment variable on MS-Windows in gnupg-2.3.4 as Wontfix.

Sorry, HOME and ~/ are not standard on Windows and applying your patch may break existing installations.

Mar 23 2022, 3:22 PM · Bug Report

Mar 22 2022

werner triaged T5897: Fix MinGW compilation error with 'struct _stat32' in common/sysutils.c from gnupg-2.3.4 as Normal priority.

Turned into a feature request because native building on Windows is not supported.

Mar 22 2022, 11:49 AM · gnupg24, toolchain, Feature Request, patch
werner triaged T5899: Fix compilation of dirmngr with mingw.org's MinGW as Normal priority.
Mar 22 2022, 11:43 AM · patch, Feature Request, Windows, toolchain
werner triaged T5900: add npth socket test case as Low priority.
Mar 22 2022, 11:42 AM · Tests, npth, Feature Request
werner committed rGce69d55f70a1: gpgtar: New option --with-log (authored by werner).
gpgtar: New option --with-log
Mar 22 2022, 10:23 AM
werner committed rGed53d41b4c46: gpgtar: New option --with-log (authored by werner).
gpgtar: New option --with-log
Mar 22 2022, 10:20 AM
werner added projects to T5898: Two fixes for the gnupg-2.3.4 test suite when running on MS-Windows: gnupg (gpg23), Windows.
Mar 22 2022, 7:45 AM · Windows, gnupg (gpg23), Bug Report
werner added a comment to T5899: Fix compilation of dirmngr with mingw.org's MinGW.

The original plan was to source copy dns.c from upstream and thus we tried to avoid any changes. Unfortunately we never achieved to push things upstream and thus our own changes got it. Eventually we will cleanup the code and use our own framework.

Mar 22 2022, 7:44 AM · patch, Feature Request, Windows, toolchain

Mar 21 2022

werner moved T5273: Release Gpg4win 4.x.x from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Mar 21 2022, 11:02 PM · Restricted Project, gpg4win, Release Info
werner added a comment to T5778: Wish to add a generic comment or hint to encrypted data.

Using an armor header would allow for this. But well, this blows up the data and frankly, I fear that it can lead to unexpected side effects. Better to use a respective file name or MIME header.

Mar 21 2022, 11:02 PM · gnupg, Restricted Project
werner moved T4729: WKD via http_proxy does not work if DNS is broken/unavailable from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Mar 21 2022, 10:56 PM · gnupg (gpg22), Restricted Project, dns, dirmngr
werner changed the status of T4729: WKD via http_proxy does not work if DNS is broken/unavailable from Open to Testing.
Mar 21 2022, 10:56 PM · gnupg (gpg22), Restricted Project, dns, dirmngr
werner committed rG6d30fb6940d5: dirmngr: Make WKD_GET work even for servers not handling SRV RRs. (authored by werner).
dirmngr: Make WKD_GET work even for servers not handling SRV RRs.
Mar 21 2022, 10:41 PM
werner added a comment to T4729: WKD via http_proxy does not work if DNS is broken/unavailable.

Actually this is pretty obvious; we better ignore such misbehaving servers.

Mar 21 2022, 10:40 PM · gnupg (gpg22), Restricted Project, dns, dirmngr
werner committed rG92c8ae720e69: dirmngr: Make WKD_GET work even for servers not handling SRV RRs. (authored by werner).
dirmngr: Make WKD_GET work even for servers not handling SRV RRs.
Mar 21 2022, 10:40 PM
werner triaged T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine as Low priority.
Mar 21 2022, 6:29 PM · gnupg, Support
werner changed the status of T4394: Use I/O callbacks in gpgtar from Open to Testing.

No need for callbacks actually. We can do it in a simpler way. See commit rGe5ef5e3b914d5c8f0b841b078b164500ea157804

Mar 21 2022, 1:27 PM · gnupg (gpg22), gpgtar
werner committed rGd431feb3077f: gpgtar: Finally use a pipe for decryption. (authored by werner).
gpgtar: Finally use a pipe for decryption.
Mar 21 2022, 1:22 PM
werner committed rGe5ef5e3b914d: gpgtar: Finally use a pipe for decryption. (authored by werner).
gpgtar: Finally use a pipe for decryption.
Mar 21 2022, 1:22 PM
werner added a comment to T5884: dotlock is not perfect (errornously remove .lock as stale lockfile).

That would be bad for unattended use cases. Recording the time the lock file was created might be a solution. Then cleanup only after 15 minutes or so.

Mar 21 2022, 8:37 AM · Bug Report, gnupg (gpg23)
werner triaged T5887: gpgme_data_identify() function prototype not as documented as Normal priority.
Mar 21 2022, 7:45 AM · Documentation, gpgme, Bug Report

Mar 18 2022

werner added a comment to T5885: Better message than "Inappropriate ioctl for device" for tty pinentries.

Is your GPG_TTY set so that pinentry can find the right tty?

Mar 18 2022, 5:36 PM · Feature Request, pinentry, gnupg
werner edited projects for T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine, added: Support, Mutt; removed Bug Report.

Sorry, without detailed output of gpg we can't help you here. This is definitely not a GnuPG bug because too many people are using mutt and gnupg. You should also "set crypt_use_gpgme" -it works far better.

Mar 18 2022, 5:32 PM · gnupg, Support
werner committed rG449d2fbcde63: common: New function map_static_strings (authored by werner).
common: New function map_static_strings
Mar 18 2022, 2:23 PM
werner committed rG8631d4cfe251: gpg: Allow decryption of symencr even for non-compliant cipher. (authored by werner).
gpg: Allow decryption of symencr even for non-compliant cipher.
Mar 18 2022, 2:23 PM
werner committed rG06b70daa505d: gpg: Print info about the used AEAD algorithm in the compliance msg. (authored by werner).
gpg: Print info about the used AEAD algorithm in the compliance msg.
Mar 18 2022, 2:23 PM