Page MenuHome GnuPG
Feed Advanced Search

Oct 7 2022

werner committed rG64002ffdfc17: po: Fix wrong LF in the German translation (authored by werner).
po: Fix wrong LF in the German translation
Oct 7 2022, 9:54 AM
werner added a member for Contributor: manonfgoo.
Oct 7 2022, 9:39 AM
werner added a comment to T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey.

[Merging didn't work]

Oct 7 2022, 9:37 AM · gnupg24, gnupg (gpg23), scd, Feature Request
werner reopened T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey as "Open".
Oct 7 2022, 9:36 AM · gnupg24, gnupg (gpg23), scd, Feature Request
werner reopened T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey, a subtask of T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys), as Open.
Oct 7 2022, 9:36 AM · yubikey, Feature Request
werner added a parent task for T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey: T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys).
Oct 7 2022, 9:36 AM · gnupg24, gnupg (gpg23), scd, Feature Request
werner added a subtask for T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys): T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey.
Oct 7 2022, 9:36 AM · yubikey, Feature Request
werner merged T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey into T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys).
Oct 7 2022, 9:35 AM · yubikey, Feature Request
werner merged task T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey into T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys).
Oct 7 2022, 9:35 AM · gnupg24, gnupg (gpg23), scd, Feature Request
werner merged T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey into T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys).
Oct 7 2022, 9:34 AM · yubikey, Feature Request
werner merged task T5790: Cannot use "Retired Cert Key Mgm [1-20]” Slots on YubiKey into T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys).
Oct 7 2022, 9:34 AM · gnupg24, gnupg (gpg23), scd, Feature Request

Oct 6 2022

werner triaged T6229: Include ability to use any/all of the keys stored on YubiKey's PIV applet ("retired" keys) as Low priority.

The other key slots are claimed to be used for expired or archived keys as you rightfully mention. We need to figure out the real world semantic behind this before we can repurpose such keys.

Oct 6 2022, 6:44 PM · yubikey, Feature Request
werner committed rG7ccd489aa2e5: wkd: New command --mirror for gpg-wks-client. (authored by werner).
wkd: New command --mirror for gpg-wks-client.
Oct 6 2022, 6:40 PM
werner accepted rCa6a6e94027ab: random: Get maximum 32B of entropy at once in FIPS Mode.

That's more than sufficient. Thanks.

Oct 6 2022, 3:07 PM

Oct 5 2022

werner closed T6142: On Windows, gpg 2.3.7 thinks the certificates of major keyservers have expired as Resolved.
Oct 5 2022, 4:20 PM · workaround, gnupg, Keyserver, Bug Report
werner closed T6142: On Windows, gpg 2.3.7 thinks the certificates of major keyservers have expired, a subtask of T5882: Cross signing certificate in X.509 support, as Resolved.
Oct 5 2022, 4:20 PM
werner committed rK4b7d9cd4a018: Detect a possible overflow directly in the TLV parser. (authored by werner).
Detect a possible overflow directly in the TLV parser.
Oct 5 2022, 4:12 PM
werner committed rG7a01e806eac4: dirmngr: Support paged LDAP mode for KS_GET (authored by werner).
dirmngr: Support paged LDAP mode for KS_GET
Oct 5 2022, 3:16 PM
werner committed rKe11e17620189: Post release updates (authored by werner).
Post release updates
Oct 5 2022, 2:17 PM
werner committed rKd3c1e063d708: Release 1.6.1 (authored by werner).
Release 1.6.1
Oct 5 2022, 2:17 PM

Oct 4 2022

werner added a comment to rCa6a6e94027ab: random: Get maximum 32B of entropy at once in FIPS Mode.

A minor clarification in the code comment would be enough. Something like: Some non-standard kernel return only 32 bytes of strong entropy to satisfy current FIPS requirements.

Oct 4 2022, 9:05 PM
werner added a comment to T6097: SC-HSM 4K Compatibility.

Yes, that's probably right. I talked to the vendor and they were nice enough to send us specs and samples. However, without a strong business case support for these cards we can't prioritize this work.

Oct 4 2022, 9:01 PM · Bug Report
werner closed T6226: Native PKCS#11 support, by attaching any module/library, without having to use workarounds (alternative gpg-agent etc.) as Wontfix.

Most PCKS#11 drivers are proprietary software which do not fit well into a free software system. Thus we avoid them. And of course we provide pcksc#11 support: Install Scute. There are no workarounds like alternative gpg-agent's - those things don't work reliable and are not supported.

Oct 4 2022, 8:57 PM · Feature Request
werner closed T6225: Gpg4win 4.0.3 and GnuPG 2.3.7 cannot use OpenPGP Card with ECC Keys as Resolved.

This is a duplicate of T6070. Please wait for gnupg 2.3.8

Oct 4 2022, 8:46 PM
werner committed rG4de98d4468f3: dirmngr: New options --first and --next for KS_GET. (authored by werner).
dirmngr: New options --first and --next for KS_GET.
Oct 4 2022, 12:59 PM
werner moved T6219: Ensure minimum key length for KDF in FIPS mode from Backlog to Ready for release on the FIPS board.
Oct 4 2022, 11:09 AM · libgcrypt, FIPS, Bug Report
werner added a comment to rCa6a6e94027ab: random: Get maximum 32B of entropy at once in FIPS Mode.

Why is that not stated in my man page which knows about kernel 3.19? Is that a regression or a RedHat specific patch?

Oct 4 2022, 9:15 AM

Sep 30 2022

werner committed rG3390951ffd69: gpg: Show just keyserver and port with --send-keys. (authored by werner).
gpg: Show just keyserver and port with --send-keys.
Sep 30 2022, 4:42 PM

Sep 29 2022

werner committed rG11aa5a93a754: dirmngr: Minor fix for baseDN fallback. (authored by werner).
dirmngr: Minor fix for baseDN fallback.
Sep 29 2022, 4:01 PM
werner committed rG2e22184ba5ac: gpg: Avoid to emit a compliance mode line if libgcrypt is non-compliant. (authored by werner).
gpg: Avoid to emit a compliance mode line if libgcrypt is non-compliant.
Sep 29 2022, 3:17 PM
werner committed rG46f9b0071f54: gpg: Fix assertion failure due to errors in encrypt_filter. (authored by werner).
gpg: Fix assertion failure due to errors in encrypt_filter.
Sep 29 2022, 3:17 PM
werner committed rGa51067a21f68: gpg: Make --require-compliance work for -se (authored by werner).
gpg: Make --require-compliance work for -se
Sep 29 2022, 3:17 PM
werner changed the status of T6221: When encrypting, gpg claims DE_VS compliance with non-compliant gcrypt from Open to Testing.

Indeed, the status line should not be emitted in this case. Thanks.

Sep 29 2022, 2:17 PM · gnupg (gpg22), Bug Report
werner committed rG07c6743148d4: gpg: Avoid to emit a compliance mode line if libgcrypt is non-compliant. (authored by werner).
gpg: Avoid to emit a compliance mode line if libgcrypt is non-compliant.
Sep 29 2022, 2:17 PM
werner added a project to T6223: GPGME incorrectly parses the signature class in SIG_CREATED status lines: Feature Request.

Let's don't forget that we need to have a sig_class replacement.

Sep 29 2022, 10:42 AM · Feature Request, gpgme, Bug Report
werner committed rMb1e5f3b18310: core: Fix SIG_CREATED status parsing for 0x1F sigs (authored by werner).
core: Fix SIG_CREATED status parsing for 0x1F sigs
Sep 29 2022, 10:10 AM
werner added a comment to T6223: GPGME incorrectly parses the signature class in SIG_CREATED status lines.

This is not easy to fix because it would break the GPGME API. Here
are the values we can expect:

Sep 29 2022, 9:32 AM · Feature Request, gpgme, Bug Report
werner triaged T6223: GPGME incorrectly parses the signature class in SIG_CREATED status lines as Normal priority.

I assume this is gpgme master. Please write proper bug reports.

Sep 29 2022, 8:30 AM · Feature Request, gpgme, Bug Report
werner added a project to T6221: When encrypting, gpg claims DE_VS compliance with non-compliant gcrypt: gnupg (gpg22).

Justus, you should know how to write a proper bug report. Please do that and don't just paste some more or less random output here with just hint that Libgcrypt is not compliant. tia.

Sep 29 2022, 8:28 AM · gnupg (gpg22), Bug Report
werner closed T6222: gpg --faked-system-time "$(date +%s)!" doesn't work as Wontfix.

This is a debug option; I see no use case for this.

Sep 29 2022, 8:22 AM · gnupg, Bug Report
werner triaged T6224: Mirror internal LDAP to a WKD as Normal priority.
Sep 29 2022, 8:21 AM · Restricted Project, Feature Request, gnupg (gpg23)

Sep 28 2022

werner committed rG536b5cd66305: dirmngr: Fix lost flags during LDAP upload (authored by werner).
dirmngr: Fix lost flags during LDAP upload
Sep 28 2022, 3:44 PM
werner committed rG1b0c17dfab50: gpg: Silence some diagnostics. (authored by werner).
gpg: Silence some diagnostics.
Sep 28 2022, 3:44 PM
werner committed rGd7a0df4478ec: doc: Typo fix in a comment. (authored by werner).
doc: Typo fix in a comment.
Sep 28 2022, 3:42 PM
werner committed rG32ce7ac0c674: dirmngr: Fix lost flags during LDAP upload (authored by werner).
dirmngr: Fix lost flags during LDAP upload
Sep 28 2022, 3:42 PM
werner added a comment to T6220: gpg --full-generate-key does not use max RSA keysize when --enable-large-rsa is set.

Add --expert and use a decent version of GnuPG. 2.2 is our long term support branch and is not the current stable production version (which is 2.3.7)

Sep 28 2022, 10:23 AM · g10code (gnupg-2.2), gnupg, Bug Report
werner added a comment to T6218: Using Yubikey with GnuPG+scdaemon and PKCS11 over pcscd errors.

Actually we developed PIV support to allow the use of PIV X.509 certificates and OpenPGP keys with Yubikeys. In fact, GnuPG is able to switch between the Yubikey PIV and OpenPGP applications on-the-fly while keeping their PIN verification states.

Sep 28 2022, 10:22 AM · gnupg24, scute, scd, Bug Report
werner committed rGd65a0335e5cb: dirmngr: New server flag "areconly" (A-record-only) (authored by werner).
dirmngr: New server flag "areconly" (A-record-only)
Sep 28 2022, 9:56 AM
werner committed rG6300035ba17b: dirmngr: New server flag "areconly" (A-record-only) (authored by werner).
dirmngr: New server flag "areconly" (A-record-only)
Sep 28 2022, 9:46 AM
werner closed T6220: gpg --full-generate-key does not use max RSA keysize when --enable-large-rsa is set as Wontfix.

Sorry, this as been discussed ad nausea. We try our best to help people not to use useless and harmful (e.g. performance of the WoT) algorithm choices.

Sep 28 2022, 9:17 AM · g10code (gnupg-2.2), gnupg, Bug Report

Sep 26 2022

werner added a comment to T6218: Using Yubikey with GnuPG+scdaemon and PKCS11 over pcscd errors.

Yes, I meant to use Scute as pkcsc11 module for pam_pkcs11. Thanks for explaining more verbosely what I meant.

Sep 26 2022, 7:59 PM · gnupg24, scute, scd, Bug Report
werner triaged T6217: sha3: wrong results for large inputs as Normal priority.
Sep 26 2022, 7:36 PM · libgcrypt, FIPS, Bug Report
werner added a comment to T6217: sha3: wrong results for large inputs.

My poor old laptop - its RAM will now have a hard time to run the huge tests ;-)

Sep 26 2022, 3:57 PM · libgcrypt, FIPS, Bug Report
werner committed rGacabbc0078d8: dirmngr: Support gpgMailbox for mode MAILSUB and MAILEND. (authored by werner).
dirmngr: Support gpgMailbox for mode MAILSUB and MAILEND.
Sep 26 2022, 2:43 PM
werner committed rG1b2ac21c4cf7: gpg: Don't consider unknown keys as non-compliant while decrypting. (authored by werner).
gpg: Don't consider unknown keys as non-compliant while decrypting.
Sep 26 2022, 2:43 PM
werner added a comment to T6047: Dirmngr - LDAP Schema V2 not used when Base DN is specified.

BTW, I have also in mind to use an AD entry to figure out the used keyserver. It turned out that people don't like to modify the schema of their AD but instead use a separate LDS.

Sep 26 2022, 9:41 AM · LDAP, dirmngr, gnupg (gpg23), Feature Request
werner triaged T6218: Using Yubikey with GnuPG+scdaemon and PKCS11 over pcscd errors as Normal priority.

There is a reason why pcsc-shared is not the default ;-). Please try using Scute (best the t6002 branch until it has been merged) as pkcs#11 provider instead of pam_pkcs11. And you should of course use the stable version of GnuPG and not the LTS (2.2).

Sep 26 2022, 8:14 AM · gnupg24, scute, scd, Bug Report

Sep 22 2022

werner removed a project from T5889: Declaration of 'struct timespec' in npth-1.6 conflicts with some versions of MinGW: Unknown Object (Project).
Sep 22 2022, 11:05 AM · npth, Bug Report
werner removed a project from T4491: Compile error in nPth's t-fork.c on Solaris 11.3 i86pc: Unknown Object (Project).
Sep 22 2022, 11:05 AM · npth, Bug Report
werner removed a project from T5572: gnupg1: Missing extern-inline.m4 for gl_EXTERN_INLINE: Unknown Object (Project).
Sep 22 2022, 11:04 AM · gnupg (gpg14)
werner removed a project from T5832: Kleopatra: Make OpenPGP certificate generation (with default settings) accessible: Unknown Object (Project).
Sep 22 2022, 11:04 AM · kleopatra, Restricted Project
werner removed a project from T5843: Kleopatra: Make certificate details accessible: Unknown Object (Project).
Sep 22 2022, 11:04 AM · kleopatra, Restricted Project
werner removed a project from T5864: Kleopatra: Configure min and max values for validity in Newcertificatewizard: Unknown Object (Project).
Sep 22 2022, 11:04 AM · kleopatra, Restricted Project
werner removed a project from T5892: t-cms-parser test program in libksba-1.6.0 needs to open files in binary mode for MS-Windows: Unknown Object (Project).
Sep 22 2022, 11:04 AM · libksba, Bug Report
werner removed a project from T5903: Kleopatra: Add refresh button in certificatedetails : Unknown Object (Project).
Sep 22 2022, 11:04 AM · backport, kleopatra, Restricted Project
werner removed a project from T5916: Kleopatra: Change Add E-Mail to add name and E-Mail and remove advanced mode: Unknown Object (Project).
Sep 22 2022, 11:04 AM · Restricted Project, kleopatra
werner removed a project from T5934: Kleopatra: Change the default/primary User ID: Unknown Object (Project).
Sep 22 2022, 11:04 AM · Restricted Project, gpg4win, kleopatra, Feature Request
werner removed a project from T6026: Kleopatra: Make the main toolbar in the main window accessible: Unknown Object (Project).
Sep 22 2022, 11:04 AM · kleopatra, Restricted Project
werner removed a project from T5945: Kleopatra: Recipient input briefly shows error until lookup is completed: Unknown Object (Project).
Sep 22 2022, 11:03 AM · Restricted Project, kleopatra
werner removed a project from T5951: gpgme: Add support for refreshing OpenPGP keys: Unknown Object (Project).
Sep 22 2022, 11:03 AM · gpgme, Restricted Project
werner removed a project from T5956: Kleopatra: Disable backup secret key for smartcards: Unknown Object (Project).
Sep 22 2022, 11:03 AM · kleopatra, Restricted Project
werner removed a project from T5958: Kleopatra: Change passphrase is enabled even when it is impossible: Unknown Object (Project).
Sep 22 2022, 11:03 AM · Restricted Project, kleopatra
werner removed a project from T5969: Kleopatra: Support large magnification for OpenPGP certificate generation: Unknown Object (Project).
Sep 22 2022, 11:03 AM · kleopatra, Restricted Project
werner removed a project from T6036: Kleopatra: Show focus indicator for (text) labels that got focus: Unknown Object (Project).
Sep 22 2022, 11:03 AM · kleopatra, Restricted Project
werner removed a project from T6046: Kleopatra: Make certifying certificates accessible: Unknown Object (Project).
Sep 22 2022, 11:03 AM · kleopatra, Restricted Project
werner removed a project from T6057: Kleopatra: Add option to disable automatic extraction of tar archives: Unknown Object (Project).
Sep 22 2022, 11:02 AM · Restricted Project, kleopatra
werner changed the status of T5933: libgcrypt: Simply use BSS (not secure heap) for DRBG instance from Open to Testing.
Sep 22 2022, 11:02 AM · backport, FIPS, libgcrypt
werner changed the status of T5683: Deprecation of gpg-error-config from Open to Testing.
Sep 22 2022, 11:02 AM · gpgrt
werner changed the status of T5919: libgcrypt tests/basic.c and tests/keygen.c occasionally fail with "error generating RSA key: Number is not prime" from Open to Testing.
Sep 22 2022, 11:02 AM · backport, FIPS, libgcrypt, Bug Report
werner changed the status of T5891: EOPNOTSUPP is not defined in mingw.org's MinGW, fails compilation of libgcrypt-1.10.0 from Open to Testing.
Sep 22 2022, 11:02 AM · backport, libgcrypt, Bug Report
werner changed the status of T5811: libgcrypt: Remove random-daemon (server side) from Open to Testing.
Sep 22 2022, 11:01 AM · libgcrypt
werner changed the status of T5822: libgcrypt: Remove GCRYCTL_ENABLE_M_GUARD support (was: _gcry_private_malloc returns 4-byte alignment memory when use_m_guard==1) from Open to Testing.
Sep 22 2022, 11:01 AM · Bug Report, libgcrypt
werner changed the status of T5914: libassuan: Introduce use of gpgrt_get_syscall_clamp, no use of system_hooks for nPTH from Open to Testing.
Sep 22 2022, 11:01 AM · Feature Request, libassuan
werner changed the status of T5918: Disable RSA PKCS #1.5 encryption in FIPS mode from Open to Testing.
Sep 22 2022, 11:01 AM · backport, libgcrypt, FIPS, Bug Report
werner changed the status of T5922: libgpg-error: gpgrt_log_get_fd always returns -1 even if it's not tcp/socket., a subtask of T5921: No sharing of log_fd between child process, from Open to Testing.
Sep 22 2022, 11:01 AM · Bug Report, gnupg (gpg23)
werner changed the status of T5922: libgpg-error: gpgrt_log_get_fd always returns -1 even if it's not tcp/socket. from Open to Testing.
Sep 22 2022, 11:01 AM · Bug Report, gpgrt
werner changed the status of T5973: libgcrypt: Minor test issues reported by coverity from Open to Testing.
Sep 22 2022, 11:01 AM · backport, patch, libgcrypt, Bug Report
werner changed the status of T5976: libgcrypt build failure on HPPA 1.1 (./.libs/libgcrypt.so: undefined reference to `__udiv_qrnnd') from Open to Testing.
Sep 22 2022, 11:00 AM · backport, hppa, libgcrypt, Gentoo, Bug Report
werner removed a project from T5708: Kleopatra: Configure expiration date default in config: Unknown Object (Project).
Sep 22 2022, 10:59 AM · kleopatra, g10code, Restricted Project
werner removed a project from T5579: libksba parallel build error (windows): Unknown Object (Project).
Sep 22 2022, 10:59 AM · libksba, Bug Report
werner removed a project from T5543: pinentry-qt: Accessibility switch to repeat on enter: Unknown Object (Project).
Sep 22 2022, 10:59 AM · pinentry, Restricted Project
werner removed a project from T4160: ed488 support: Unknown Object (Project).
Sep 22 2022, 10:59 AM · gnupg24, gnupg (gpg23), Feature Request
werner removed a project from T4013: Certificate requests generated from Ed25519 keys are not compliant with draft-ietf-curdle-pkix: Unknown Object (Project).
Sep 22 2022, 10:59 AM · S/MIME, Feature Request, libksba
werner changed the status of T5748: Adding poll/ppoll to NPTH, a subtask of T2385: support more than 1024 fds., from Open to Testing.
Sep 22 2022, 10:58 AM · gpgrt, Feature Request, gpgme
werner changed the status of T5748: Adding poll/ppoll to NPTH from Open to Testing.
Sep 22 2022, 10:58 AM · npth, Feature Request
werner changed the status of T5817: libgcrypt: Add Balloon KDF from Open to Testing.
Sep 22 2022, 10:58 AM · libgcrypt, Feature Request
werner changed the status of T5890: EOPNOTSUPP is not defined in mingw.org's MinGW, fails compilation of libgpg-error-1.44 from Open to Testing.
Sep 22 2022, 10:58 AM · gpgrt, Bug Report
werner changed the status of T5215: gnugp1: Fix build errors with gcc-10 from Open to Testing.
Sep 22 2022, 10:58 AM · gnupg (gpg14), patch, Bug Report
werner changed the status of T4873: Enable AES GCM in FIPS mode from Open to Testing.
Sep 22 2022, 10:57 AM · FIPS, libgcrypt, Feature Request
werner changed the status of T4873: Enable AES GCM in FIPS mode, a subtask of T5870: libgcrypt: AEAD API for FIPS 140 (in future), from Open to Testing.
Sep 22 2022, 10:57 AM · Feature Request, FIPS, libgcrypt