Page MenuHome GnuPG
Feed Advanced Search

Apr 21 2022

werner committed rDb80f45cf8363: swdb: GnuPG 2.3.5 (authored by werner).
swdb: GnuPG 2.3.5
Apr 21 2022, 6:20 PM
werner set External Link to https://lists.gnupg.org/pipermail/gnupg-announce/2022q2/000472.html on T5743: Release GnuPG 2.3.5.
Apr 21 2022, 6:17 PM · Release Info, gnupg (gpg23)
werner closed T5743: Release GnuPG 2.3.5 as Resolved.
Apr 21 2022, 5:59 PM · Release Info, gnupg (gpg23)
werner committed rGa4b25bcfe1f9: Release 2.3.5 (authored by werner).
Release 2.3.5
Apr 21 2022, 5:54 PM
werner committed rG60fc743da4bf: Post release updates (authored by werner).
Post release updates
Apr 21 2022, 5:54 PM
werner triaged T5937: Release GnuPG 2.3.6 as Low priority.
Apr 21 2022, 5:53 PM · Release Info, gnupg (gpg23)
werner committed rGaec972732e97: speedo: Fix authenticode signing (authored by werner).
speedo: Fix authenticode signing
Apr 21 2022, 2:21 PM
werner committed rGb400ad267539: po: Auto update (authored by werner).
po: Auto update
Apr 21 2022, 2:21 PM
werner committed rG9b297a9d44b7: dirmngr: Fix Makefile (authored by werner).
dirmngr: Fix Makefile
Apr 21 2022, 2:21 PM
werner added a project to T5935: scd: SSH emulation of gpg-agent doesn't work well with sntrup761x25519-sha512@openssh.com: gnupg (gpg23).
Apr 21 2022, 7:35 AM · workaround, gnupg (gpg23), ssh, Bug Report, scd
werner triaged T5935: scd: SSH emulation of gpg-agent doesn't work well with sntrup761x25519-sha512@openssh.com as Normal priority.
Apr 21 2022, 7:35 AM · workaround, gnupg (gpg23), ssh, Bug Report, scd

Apr 20 2022

werner committed rG89dc9f1e6916: dirmngr: Changes to the linking order. (authored by werner).
dirmngr: Changes to the linking order.
Apr 20 2022, 6:49 PM
werner committed rGac08517723e2: po: Update German translation (authored by werner).
po: Update German translation
Apr 20 2022, 6:49 PM
werner committed rS2b22ff55d1c0: Hack to all using Scute for osslsigncode. (authored by werner).
Hack to all using Scute for osslsigncode.
Apr 20 2022, 6:01 PM
werner committed rG22fef189b111: w32: Do no use Registry item DefaultLogFile for the main tools. (authored by werner).
w32: Do no use Registry item DefaultLogFile for the main tools.
Apr 20 2022, 3:49 PM
werner committed rG3b48465ef9a2: build: Fix makedist target in m4. (authored by werner).
build: Fix makedist target in m4.
Apr 20 2022, 3:49 PM
werner committed rG24ab4f933fe1: po: Update German translation (authored by werner).
po: Update German translation
Apr 20 2022, 9:28 AM
werner committed rGa5faaf8bee43: w32: Do no use Registry item DefaultLogFile for the main tools. (authored by werner).
w32: Do no use Registry item DefaultLogFile for the main tools.
Apr 20 2022, 9:28 AM
werner closed T5813: Locating Keys via WKD with gpg4win fails with unknown error. as Resolved.
Apr 20 2022, 8:51 AM · wkd, gpg4win, Bug Report
werner triaged T5881: Not all keys available in Security approval window as Normal priority.
Apr 20 2022, 8:48 AM · Bug Report, gpgol
werner triaged T5909: Make use of the LDAP revoked attribute as Normal priority.
Apr 20 2022, 8:46 AM · Feature Request, LDAP, OpenPGP, gpgme, dirmngr
werner triaged T5918: Disable RSA PKCS #1.5 encryption in FIPS mode as High priority.
Apr 20 2022, 8:45 AM · backport, libgcrypt, FIPS, Bug Report
werner triaged T5933: libgcrypt: Simply use BSS (not secure heap) for DRBG instance as Normal priority.

Full ack.

Apr 20 2022, 8:45 AM · backport, FIPS, libgcrypt

Apr 19 2022

werner committed rW551b3832bb6c: msi: Get Perl regex right (authored by werner).
msi: Get Perl regex right
Apr 19 2022, 6:02 PM

Apr 14 2022

werner committed rG74f9e3e6c498: Prepare NEWS for the next release (authored by werner).
Prepare NEWS for the next release
Apr 14 2022, 3:47 PM
werner closed T5599: Make gpg use the helpers baked into its AppImage as Resolved.

Seems we can close this bug.

Apr 14 2022, 3:14 PM · gnupg, Restricted Project, Feature Request
werner closed T5599: Make gpg use the helpers baked into its AppImage, a subtask of T5598: AppImage of gpg, as Resolved.
Apr 14 2022, 3:14 PM · AppImage, gnupg, Restricted Project, Feature Request
werner archived gnupg (gpg20).
Apr 14 2022, 3:06 PM
werner closed T1954: Password too long as Resolved.
Apr 14 2022, 3:05 PM · Info Needed, gnupg (gpg20), Bug Report, gnupg
werner closed T5235: Delays in dirmngr http connections on Windows as Resolved.

We have not seen this problem anymore in recent versions. Thus closing.

Apr 14 2022, 3:02 PM · can't replicate, dirmngr, ntbtls, Windows, gnupg (gpg22)
werner closed T5639: dirmngr uses the wrong Let's encrypt chain as Resolved.

We have a solulion for this bug. For further improvements we will use T5882.

Apr 14 2022, 2:00 PM · gnupg (gpg22), dirmngr
werner closed T5639: dirmngr uses the wrong Let's encrypt chain, a subtask of T5882: Cross signing certificate in X.509 support, as Resolved.
Apr 14 2022, 2:00 PM
werner closed T5809: Expire subkey violates assertion "! sig->hashed" as Resolved.
  • Fixed in 2.3
  • assert replaced by a fatal error message
Apr 14 2022, 1:57 PM · Unknown Object (Project), gnupg (gpg22), Bug Report
werner committed rG41fb46007e65: gpg: Replace an assert by a log_fatal. (authored by werner).
gpg: Replace an assert by a log_fatal.
Apr 14 2022, 1:56 PM
werner committed rGc8c71fc7161b: gpg: Replace an assert by a log_fatal. (authored by werner).
gpg: Replace an assert by a log_fatal.
Apr 14 2022, 1:54 PM
werner triaged T5927: gpg: quick-gen-key and quick-add-uid require --check-trustdb to make trust in user ids "ultimate" as Low priority.

Printing a note as we do in --edit-key is a good idea.

Apr 14 2022, 1:44 PM · Feature Request, gnupg, Bug Report
werner triaged T5930: Use the FIPS-compatible digest&sign API as Normal priority.

Passing fds etc adds complex extra code to gpg-agent. This was not the original design goal, although we violated this anyway by have some OpenPGP specific code there. This needs more thinking. Due to our internal use of OCB we can't make it FIPS compliant without large changes.

Apr 14 2022, 1:42 PM · FIPS, Feature Request
werner triaged T5931: OpenSSH 8.9, 9.0, and 9.1 can't authenticate with gpg-agent and usb token (Gnuk >= 1.2.16 is required) as High priority.

I have not yet tested OpenSSH 9 and thus the patch to master is here just as a test. Please better use gnupg 2.3 (stable) instead of 2.2 (LTS) because it is unlikely that we will backport all this new ssh stuff.

Apr 14 2022, 12:36 PM · gnupg24, workaround, Documentation, gnupg (gpg23), ssh, gpgagent
werner committed rG46d62d80a2b8: ssh: Returned faked response for the new session-bind extension. (authored by werner).
ssh: Returned faked response for the new session-bind extension.
Apr 14 2022, 12:33 PM
werner committed rGdd727ec968af: scd: Renamed a constant in ccid-driver.c (authored by werner).
scd: Renamed a constant in ccid-driver.c
Apr 14 2022, 10:27 AM
werner committed rG58532fe56c33: scd: Minor code reorganization (authored by werner).
scd: Minor code reorganization
Apr 14 2022, 10:25 AM
werner committed rGc4b14be48fe9: scd: Fix memory leak in ccid-driver. (authored by werner).
scd: Fix memory leak in ccid-driver.
Apr 14 2022, 10:25 AM
werner committed rG6294ae282da1: scd: Minor code reorganization (authored by werner).
scd: Minor code reorganization
Apr 14 2022, 10:16 AM
werner committed rG8ac92f0e807a: scd: Fix memory leak in ccid-driver. (authored by werner).
scd: Fix memory leak in ccid-driver.
Apr 14 2022, 10:16 AM
werner committed rG61038be8134c: tests: Fix warning in common/t-ssh-utils.c (authored by werner).
tests: Fix warning in common/t-ssh-utils.c
Apr 14 2022, 10:15 AM
werner renamed T5273: Release Gpg4win 4.x.x from Release Gpg4win 4 to Release Gpg4win 4.x.x.
Apr 14 2022, 8:49 AM · Restricted Project, gpg4win, Release Info

Apr 13 2022

werner updated the task description for T5703: Release GnuPG 2.2.34.
Apr 13 2022, 2:37 PM · Release Info, gnupg (gpg22)
werner triaged T5928: Release GnuPG 2.2.35 as Low priority.
Apr 13 2022, 2:23 PM · Release Info, gnupg (gpg22)
werner committed rGe99670f944bc: scd:p15: Improve the PIN prompt for Genua cards. (authored by werner).
scd:p15: Improve the PIN prompt for Genua cards.
Apr 13 2022, 1:59 PM
werner committed rG44ec383cdec0: scd:p15: Support for GeNUA cards. (authored by werner).
scd:p15: Support for GeNUA cards.
Apr 13 2022, 1:59 PM
werner committed rG80cf64c65155: scd:p15: Add basic support for AET JCOP cards. (authored by werner).
scd:p15: Add basic support for AET JCOP cards.
Apr 13 2022, 1:59 PM
werner committed rG29fd80581867: scd:p15: Prepare AODF parsing for other authentication types. (authored by werner).
scd:p15: Prepare AODF parsing for other authentication types.
Apr 13 2022, 1:59 PM
werner committed rG618aa8689a9b: scd:p15: Improve the PIN prompt for Genua cards. (authored by werner).
scd:p15: Improve the PIN prompt for Genua cards.
Apr 13 2022, 1:09 PM
werner committed rG0dcc24985235: scd: Support for GeNUA cards. (authored by werner).
scd: Support for GeNUA cards.
Apr 13 2022, 1:09 PM
werner committed rG137e59a6a5c5: sm: Print diagnostic about CRL problems due to Tor mode. (authored by werner).
sm: Print diagnostic about CRL problems due to Tor mode.
Apr 13 2022, 1:09 PM

Apr 12 2022

werner committed rW96dc7a876820: msi: Ignore 2nd level subdirs named misc. (authored by werner).
msi: Ignore 2nd level subdirs named misc.
Apr 12 2022, 1:02 PM

Apr 11 2022

werner added a comment to T5920: libassuan: Don't inherit handles for Windows.

We once figured that we should use this for gpgme, where we use a helper to close handles. We have not yet found the time to do this and frankly "never change a running system" ;-) We also still support Windows XP SP3 with GnuPG for users with air-gaped machines. Not sure whether this is still justified, though.

Apr 11 2022, 9:28 AM

Apr 9 2022

werner added a comment to T5927: gpg: quick-gen-key and quick-add-uid require --check-trustdb to make trust in user ids "ultimate".

The reason for this is probably that we expect that several UIDs are added and running a check-trustdb for eachleads to some extra waiting time.

Apr 9 2022, 3:11 PM · Feature Request, gnupg, Bug Report

Apr 8 2022

werner committed rG198fad9fc1f3: doc: Typo fix in comment (authored by werner).
doc: Typo fix in comment
Apr 8 2022, 4:09 PM
werner committed rG8945f1aedfd7: gpg: Remove restrictions for the name part of a user-id. (authored by werner).
gpg: Remove restrictions for the name part of a user-id.
Apr 8 2022, 4:09 PM
werner committed rGca3e46a587f6: tpm: Fix recently introduced syntax error (authored by werner).
tpm: Fix recently introduced syntax error
Apr 8 2022, 4:09 PM

Apr 7 2022

werner added a comment to T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high).

Updated the copy on our mirror as welll as the gpg4win and swdb packages files.

Apr 7 2022, 11:45 AM · gnupg (gpg22), CVE, gpg4win
werner committed rWa7d49129a241: packages: Update zlib to 1.2.12 (authored by werner).
packages: Update zlib to 1.2.12
Apr 7 2022, 11:42 AM
werner committed rDf7cdcbd7057e: swdb: Updated mirrored zlib to 1.2.12 (authored by werner).
swdb: Updated mirrored zlib to 1.2.12
Apr 7 2022, 11:39 AM
werner committed rW35bb72337710: packages: Update gpgrt and ntbtls (authored by werner).
packages: Update gpgrt and ntbtls
Apr 7 2022, 11:37 AM
werner committed rT660c2f89dc38: Post release updates (authored by werner).
Post release updates
Apr 7 2022, 11:21 AM
werner committed rT802494e014c8: Release 0.3.1 (authored by werner).
Release 0.3.1
Apr 7 2022, 11:21 AM
werner committed rDa727cc944ce8: swdb: gpgrt 1.45 and ntbtls 0.3.1 (authored by werner).
swdb: gpgrt 1.45 and ntbtls 0.3.1
Apr 7 2022, 11:08 AM
werner closed T5802: Release libgpg-error 1.45 as Resolved.
Apr 7 2022, 10:52 AM · Release Info, gpgrt
werner reopened T5923: Release Libgpg-error 1.46 as "Open".
Apr 7 2022, 10:51 AM · Release Info, gpgrt
werner closed T5923: Release Libgpg-error 1.46 as Resolved.
Apr 7 2022, 10:49 AM · Release Info, gpgrt
werner committed rE038d34656f5b: Post release updates (authored by werner).
Post release updates
Apr 7 2022, 10:46 AM
werner committed rEff3b2ea8858a: Merge branch 'master' of ssh+git://playfair.gnupg.org/git/libgpg-error (authored by werner).
Merge branch 'master' of ssh+git://playfair.gnupg.org/git/libgpg-error
Apr 7 2022, 10:46 AM
werner committed rEdbac537e5e86: Release 1.45 (authored by werner).
Release 1.45
Apr 7 2022, 10:46 AM
werner triaged T5923: Release Libgpg-error 1.46 as Low priority.
Apr 7 2022, 10:39 AM · Release Info, gpgrt
werner triaged T5919: libgcrypt tests/basic.c and tests/keygen.c occasionally fail with "error generating RSA key: Number is not prime" as Normal priority.

The set_bit is obvious but we should cross check with the specs. In the non-fips mode we also try w/o a limit.

Apr 7 2022, 10:04 AM · backport, FIPS, libgcrypt, Bug Report

Apr 6 2022

werner committed rDb6d49e1b67e5: verein: fix links. (authored by werner).
verein: fix links.
Apr 6 2022, 9:18 AM

Apr 5 2022

werner lowered the priority of T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) from Unbreak Now! to High.

The fix is from 2018 but was not picked up widely; see
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531

Apr 5 2022, 12:14 PM · gnupg (gpg22), CVE, gpg4win
werner added a comment to T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high).

Sorry, that was a misunderstanding. My fault.

Apr 5 2022, 11:43 AM · gnupg (gpg22), CVE, gpg4win
werner reopened T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) as "Open".
Apr 5 2022, 11:39 AM · gnupg (gpg22), CVE, gpg4win

Apr 4 2022

werner closed T5886: Mutt PGP Error: "Could not decrypt PGP message" & "Could not copy message" on Ubuntu machine but works on macOS machine as Resolved.

In fact, decent 2.2 versions (>=2.2.21) have the ability to decrypt AEAD packets - this has been implemented exactly for the case that some things get wrong at the user site. But we can't change old versions - we are not the Sirius Computer Corporation. I close this ticket because we can can't do anything if you are not able/willing to update to the latest version of the respective branch. Sorry.

Apr 4 2022, 6:43 AM · gnupg, Support

Apr 1 2022

werner triaged T5915: Allow Registry configuration of GpgEX as Normal priority.
Apr 1 2022, 11:38 AM · Restricted Project, Feature Request, gpgex

Mar 31 2022

werner assigned T5913: libgcrypt: bug fix for PPC bulk AES-GCM acceleratieration, missing HWF_PPC_ARCH_3_10 in HW feature to jukivili.
Mar 31 2022, 10:46 PM · ppc, libgcrypt
werner added a comment to T4924: pinentry: pinentry-curses doesn't allow to set no password or weak passwords on 80 char width and smaller terminals.

There is also the very simple pinentry-tty

Mar 31 2022, 8:07 PM · pinentry, Bug Report
werner committed rW1094535c379e: Ignore the Standard/etc directory in make-msi.pl (authored by werner).
Ignore the Standard/etc directory in make-msi.pl
Mar 31 2022, 4:30 PM
werner committed rC35a7409dcf29: random:drbg: Fix the behavior for child process. (authored by gniibe).
random:drbg: Fix the behavior for child process.
Mar 31 2022, 9:27 AM
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

I don't like it either but the browser vendors don't like SRV records.

Mar 31 2022, 9:03 AM · wkd, gpg4win, Bug Report

Mar 30 2022

werner committed rT08c1622944da: Allow ephemeral ECDSA cipher suites. (authored by werner).
Allow ephemeral ECDSA cipher suites.
Mar 30 2022, 8:39 PM
werner committed rTa95b108c6cfd: Make X25519 support depend on the Libgcrypt version (authored by werner).
Make X25519 support depend on the Libgcrypt version
Mar 30 2022, 8:39 PM
werner committed rTc08cc859a930: Post release updates (authored by werner).
Post release updates
Mar 30 2022, 8:39 PM
werner committed rT97a5cdaedbe9: Release 0.3.0 (authored by werner).
Release 0.3.0
Mar 30 2022, 8:39 PM
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

I still think that redirecting to another catch-all domain is contrary to the original goal and weakens the security model. We need to see what we can do about this.

Mar 30 2022, 6:07 PM · wkd, gpg4win, Bug Report
werner closed T5910: CVE-2018-25032 for zlib <=1.2.11 (CVSS 8.1 high) as Resolved.

Not in the way it is used by gpg. See T5880

Mar 30 2022, 6:04 PM · gnupg (gpg22), CVE, gpg4win
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

The ECDHE_ECDSA suites are not yet implemented in ntbtls and thus we can't agree on a common cipher suite. Will be solved in the next Windows version.

Mar 30 2022, 3:35 PM · wkd, gpg4win, Bug Report
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

Are you using 2.3.4 also on Windows?

Mar 30 2022, 12:15 PM · wkd, gpg4win, Bug Report
werner created T5909: Make use of the LDAP revoked attribute.
Mar 30 2022, 11:49 AM · Feature Request, LDAP, OpenPGP, gpgme, dirmngr
werner closed T5907: bench-slope missing brainpool curves in master branch as Resolved.

see rC67b36154f88e for master.

Mar 30 2022, 9:07 AM · libgcrypt, Bug Report
werner committed rC67b36154f88e: tests: Add brainpoolP256r1 to bench-slope. (authored by werner).
tests: Add brainpoolP256r1 to bench-slope.
Mar 30 2022, 9:06 AM
werner added a comment to T5907: bench-slope missing brainpool curves in master branch.

Will add it. The reason I added Brainpool was due to a question on the performacne between Brainpool and other NIST.

Mar 30 2022, 9:03 AM · libgcrypt, Bug Report

Mar 28 2022

werner committed rD6698ad8b26a9: web: Release info for libgcrypt 1.10.1 (authored by werner).
web: Release info for libgcrypt 1.10.1
Mar 28 2022, 4:50 PM