Page MenuHome GnuPG
Feed All Stories

Jan 27 2018

AladW reopened T2986: Can not access keyserver without the standard-resolver option as "Open".

I can reproduce this issue with gpg 2.2.4, systemd-resolved and Arch Linux. Unlike the original reporter, I do not have 127.0.0.1 in my /etc/resolv.conf. I do however have it in /etc/hosts.

Jan 27 2018, 2:09 PM · Bug Report, gnupg
Laurent Montel <montel@kde.org> committed rKLEOPATRA5f862c5333df: Use remove directly (authored by Laurent Montel <montel@kde.org>).
Use remove directly
Jan 27 2018, 10:23 AM
patrick closed T3760: --recv-keys of multiple keys yields misleading output if one of the requested keyIDs is not available on the requested server as Invalid.
Jan 27 2018, 9:01 AM · Bug Report
patrick added a comment to T3760: --recv-keys of multiple keys yields misleading output if one of the requested keyIDs is not available on the requested server.

It turned out to be a bug in Enigmail. The "," in the key list s wrong.

Jan 27 2018, 9:00 AM · Bug Report
nursoda created T3760: --recv-keys of multiple keys yields misleading output if one of the requested keyIDs is not available on the requested server.
Jan 27 2018, 3:07 AM · Bug Report

Jan 26 2018

werner committed rD5227081f8bc0: verein: URL fix (authored by werner).
verein: URL fix
Jan 26 2018, 3:40 PM
werner committed rDe88b83be6c38: verein: Link to the German translation of the annual accounst 2017 (authored by werner).
verein: Link to the German translation of the annual accounst 2017
Jan 26 2018, 3:21 PM
werner committed rD25761b4696f6: verein: Add links to the annual accounts 2017 (authored by werner).
verein: Add links to the annual accounts 2017
Jan 26 2018, 1:08 PM
onickolay added a comment to T3757: Problem building latest master on macOS: unknown identifier LOCAL_PEERUID in command-ssh.c.

Checked - it builds fine now. Thanks!

Jan 26 2018, 9:59 AM · gpgagent, gnupg (gpg23), MacOS, Bug Report
gniibe changed the status of T3757: Problem building latest master on macOS: unknown identifier LOCAL_PEERUID in command-ssh.c from Open to Testing.

I push my change to master.
Please test.

Jan 26 2018, 3:04 AM · gpgagent, gnupg (gpg23), MacOS, Bug Report
gniibe committed rG660eafa3a9f6: agent: Fix sending connecting process uid to pinentry. (authored by gniibe).
agent: Fix sending connecting process uid to pinentry.
Jan 26 2018, 2:59 AM
gniibe committed rGc2e69a7a8c4b: Merge branch 'STABLE-BRANCH-2-2' into master (authored by gniibe).
Merge branch 'STABLE-BRANCH-2-2' into master
Jan 26 2018, 2:59 AM
gniibe committed rGd7207b39b71d: agent: Fix last commit. (authored by gniibe).
agent: Fix last commit.
Jan 26 2018, 2:46 AM
gniibe committed rG08e686a6a6d5: agent: More fix for get_client_pid for portability. (authored by gniibe).
agent: More fix for get_client_pid for portability.
Jan 26 2018, 2:14 AM

Jan 25 2018

werner committed rG149369a92b44: Merge branch 'STABLE-BRANCH-2-2' into master (authored by werner).
Merge branch 'STABLE-BRANCH-2-2' into master
Jan 25 2018, 5:05 PM
werner committed rG91a3d15cee32: doc: Note --quick-gen-key as an alias for --quick-generate-key (authored by werner).
doc: Note --quick-gen-key as an alias for --quick-generate-key
Jan 25 2018, 3:21 PM
emanuel committed rWf1958d912098: Web: Updated GnuPG and GPA version. (authored by emanuel).
Web: Updated GnuPG and GPA version.
Jan 25 2018, 11:09 AM
aheinecke added a comment to T3509: GpgOL: Key resolution without Kleopatra or GPA.
  1. Collect all data in OOM, then start a thread to do the encryption.
  2. Do a proof of concept that this actually works and outlook lets us do it with our usual window message async handling.
  3. Update my Keyresolver patches in Libkleo and build a "libkleo-tool" to do the key resolving.
  4. Figure out Window Management / Create a Qt Overlay over the Mail window to block it from closing while encryption happens. This will resolve all bugs related to window mangement of the current key resolution.
Jan 25 2018, 8:53 AM · kleopatra, gpgol, gpg4win
gniibe claimed T3757: Problem building latest master on macOS: unknown identifier LOCAL_PEERUID in command-ssh.c.

Thanks for testing master.
No, it's not typo, in my opinion.
The line was added as if it's LOCAL_PEERUID, but there is no such a thing in XNU, but there is LOCAL_PEERUUID which is for UUID.

Jan 25 2018, 4:19 AM · gpgagent, gnupg (gpg23), MacOS, Bug Report

Jan 24 2018

neurohenry added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

Regarding truncation, it seems draft of the RFC has some contradicting statements. In "5.2.2. {5.2.2} Version 3 Signature Packet Format" it says:

Jan 24 2018, 7:41 PM · Bug Report
wltjr added a comment to T2905: EFL-based pinentry.

Your welcome, I can remake another unified patch if need be. I was starting to prepare things to be a stand alone fork. Did an initial .travis.yml file, and initial stuff for Coverity. Though never did get a build uploaded to Coverity. Not sure if you have ever run pinentry through Coverity or other GnuPG stuff, may be a good idea just to see if it catches anything.

Jan 24 2018, 7:35 PM · pinentry, Feature Request
werner closed T3717: I am tired of errors like Connection Closed in DNS, Server Indicated a Failure, No Keyserver Available, and Not Enabled when trying to do something with a keyserver as Invalid.

I close this bug - if you can provide the log files please feel free to reopen.

Jan 24 2018, 7:30 PM · Info Needed, Bug Report
werner raised the priority of T2905: EFL-based pinentry from Normal to High.

Thanks for the long explanation. I think it should go into pinentry proper. I will have a closer look on it.

Jan 24 2018, 7:27 PM · pinentry, Feature Request
werner closed T3758: Configuring with --disable-optimization doesn't disable optimizations as Wontfix.

That might be the case. I suggest to use

Jan 24 2018, 7:20 PM · Bug Report, gnupg (gpg22)
stm added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

Please note that Section 13.6 of RFC 4880 says:

Jan 24 2018, 7:07 PM · Bug Report
werner added a comment to T3759: Compile test fails, Libassuan v2.5.1 - Ubuntu 14.04 - fdpassing[7693]: assuan_pipe_connect failed: End of file.

Are you sure that you are runtime linking to the same libgpg-error version you used for the build?

Jan 24 2018, 7:03 PM · Info Needed, libassuan, Bug Report
werner added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

This would then be a 1024 bit DSA key according to the DSA-2 specification. Back when DSA was introduced to PGP the specs did not specify a truncation. Maybe because there were no hash algorithms larger than 160 bits at that time.

Jan 24 2018, 6:51 PM · Bug Report
werner committed rGdb7661b5a297: gpg: New maintainer option --debug-set-iobuf-size. (authored by werner).
gpg: New maintainer option --debug-set-iobuf-size.
Jan 24 2018, 6:45 PM
werner committed rGbfc118164445: iobuf: Increase the size of the buffer. Add iobuf_set_buffer_size. (authored by werner).
iobuf: Increase the size of the buffer. Add iobuf_set_buffer_size.
Jan 24 2018, 6:45 PM
neurohenry added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

Actually, I was using rightmost 160 bits of hash instead of leftmost. Key below also uses DSA/1024 with SHA256, but I'm using 160 bits from the left and it can be imported correctly

Jan 24 2018, 3:44 PM · Bug Report
werner committed rGff1bdc23d9f1: gpg: Fix AEAD encryption for chunk sizes other than 64 KiB. (authored by werner).
gpg: Fix AEAD encryption for chunk sizes other than 64 KiB.
Jan 24 2018, 1:59 PM
werner committed rG83a15fa88e91: gpg: Rename a variable in decrypt-data for clarity. (authored by werner).
gpg: Rename a variable in decrypt-data for clarity.
Jan 24 2018, 1:59 PM
werner committed rGf3ef8b0dcaed: gpg: New option --chunk-size. (authored by werner).
gpg: New option --chunk-size.
Jan 24 2018, 1:59 PM
jespestana created T3759: Compile test fails, Libassuan v2.5.1 - Ubuntu 14.04 - fdpassing[7693]: assuan_pipe_connect failed: End of file.
Jan 24 2018, 1:56 PM · Info Needed, libassuan, Bug Report
neurohenry added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

Thank you, that's useful.

Jan 24 2018, 12:46 PM · Bug Report
onickolay added a project to T3758: Configuring with --disable-optimization doesn't disable optimizations: Bug Report.
Jan 24 2018, 12:17 PM · Bug Report, gnupg (gpg22)
onickolay created T3758: Configuring with --disable-optimization doesn't disable optimizations in the S1 Public space.
Jan 24 2018, 12:16 PM · Bug Report, gnupg (gpg22)
onickolay created T3757: Problem building latest master on macOS: unknown identifier LOCAL_PEERUID in command-ssh.c.
Jan 24 2018, 12:13 PM · gpgagent, gnupg (gpg23), MacOS, Bug Report
gniibe added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

You can compare your key with a key generated by GnuPG.

Jan 24 2018, 9:13 AM · Bug Report
werner triaged T3755: TLS hostname verification using hostname from DNS instead of supplied hostname as High priority.
Jan 24 2018, 8:47 AM · gnupg (gpg22), dns, dirmngr
werner added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

If you look at the specs of DSA you will see that using SHA-256 truncated to 160 bits is not defined. DSA 1024 uses a 160 bit subgroup and thus SHA-256 would need to be truncated to 160 bits. If you want to look closer at that key the command

Jan 24 2018, 8:45 AM · Bug Report
syscomet added a comment to T3755: TLS hostname verification using hostname from DNS instead of supplied hostname.

Oh. T1447 only referenced SRV records, which is why the CNAME case wasn't handled. So T1447 was fixed completely but T1447 did not cover the full extent of the underlying problem.

Jan 24 2018, 4:00 AM · gnupg (gpg22), dns, dirmngr
syscomet created T3755: TLS hostname verification using hostname from DNS instead of supplied hostname in the S1 Public space.
Jan 24 2018, 3:51 AM · gnupg (gpg22), dns, dirmngr

Jan 23 2018

neurohenry updated the task description for T3754: Problem importing DSA/1024 key signed with SHA256.
Jan 23 2018, 7:43 PM · Bug Report
neurohenry updated the task description for T3754: Problem importing DSA/1024 key signed with SHA256.
Jan 23 2018, 7:43 PM · Bug Report
neurohenry added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

Key signed with SHA1

Jan 23 2018, 7:43 PM · Bug Report
neurohenry added a comment to T3754: Problem importing DSA/1024 key signed with SHA256.

SHA256 key

Jan 23 2018, 7:42 PM · Bug Report
neurohenry updated the task description for T3754: Problem importing DSA/1024 key signed with SHA256.
Jan 23 2018, 7:41 PM · Bug Report
neurohenry created T3754: Problem importing DSA/1024 key signed with SHA256.
Jan 23 2018, 7:40 PM · Bug Report
wltjr added a comment to T2905: EFL-based pinentry.

@werner no problem with re-opening. I closed as it seemed it was not of interest or wanted. I wasn't get any responses like asking why it was left out of 1.1.0 release. To my knowledge other than preferences of GnuPG devs, changes to suit your needs, grabbing, libsecret, etc. It should be good to go without any issues. Thus I was waiting next release, assuming it was already committed . May have confused it with some other PR that was committed. But there should not be any outstanding issues preventing it from inclusion. If there are it was never relayed to me. It should be ready for inclusion, less any requested changes.

Jan 23 2018, 7:26 PM · pinentry, Feature Request
wltjr added a comment to T2905: EFL-based pinentry.

@werner no clue, I thought it was merged in at some point. I could have sworn something happened there. I went on advising others like the TQT interface assuming EFL was already added. I was shocked it was not when release came out and no explanation as to why it was excluded.

Jan 23 2018, 7:20 PM · pinentry, Feature Request
werner committed rG112e02ee89b7: gpg: Copy the AEAD prefs to the user ID struct. (authored by werner).
gpg: Copy the AEAD prefs to the user ID struct.
Jan 23 2018, 12:58 PM
werner committed rG278d87465685: gpg: Clear the symmetric passphrase cache for encrypted session keys. (authored by werner).
gpg: Clear the symmetric passphrase cache for encrypted session keys.
Jan 23 2018, 12:58 PM
werner committed rG9aab9167bca3: gpg: Implement AEAD for SKESK packets. (authored by werner).
gpg: Implement AEAD for SKESK packets.
Jan 23 2018, 12:58 PM
werner committed rGda3015e3c050: gpg: Unify AEAD parameter retrieval. (authored by werner).
gpg: Unify AEAD parameter retrieval.
Jan 23 2018, 12:58 PM
werner awarded rCe8629e535bd0: Add EAX mode a Cup of Joe token.
Jan 23 2018, 9:22 AM
Martin Koller <kollix@aon.at> committed rKLEOPATRAe25ecd1325da: make it compile with clang5 (authored by Martin Koller <kollix@aon.at>).
make it compile with clang5
Jan 23 2018, 8:25 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA216d5243a52f: GIT_SILENT: time to increase version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: time to increase version
Jan 23 2018, 7:05 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA089bc5a0212d: GIT_SILENT: Prepare 5.7.2 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare 5.7.2
Jan 23 2018, 6:45 AM
fogine closed T3752: gpg --card-status does NOT to create secret key stubs as Invalid.

My apologies , after the system upgrade, multiple things around gnupg broke and I got distracted and forgot to check the fetched public key, which somehow didn't contain subkey data.
This particular issue has been resolved by updating upstream public key.
Thank you for your assistance.

Jan 23 2018, 2:36 AM · scd, gnupg (gpg22), Bug Report

Jan 22 2018

jukivili committed rC0b55f349a8b8: Fix use of AVX instructions in Chaha20 SSSE3 implementation (authored by jukivili).
Fix use of AVX instructions in Chaha20 SSSE3 implementation
Jan 22 2018, 9:27 PM
jukivili committed rCbd75f0e89817: doc: fix double "See" in front of reference (authored by jukivili).
doc: fix double "See" in front of reference
Jan 22 2018, 9:27 PM
jukivili committed rCe8629e535bd0: Add EAX mode (authored by jukivili).
Add EAX mode
Jan 22 2018, 9:27 PM
jukivili committed rCcd7ed2e3546b: cipher: constify spec arrays (authored by jukivili).
cipher: constify spec arrays
Jan 22 2018, 9:27 PM
werner committed rG0131d4369a81: gpg: Refactor function encrypt_seskey. (authored by werner).
gpg: Refactor function encrypt_seskey.
Jan 22 2018, 3:58 PM
aheinecke committed rKLEOPATRA8e417cbfd52f: Fix crash if compliance is not known to gnupg (authored by aheinecke).
Fix crash if compliance is not known to gnupg
Jan 22 2018, 3:28 PM
aheinecke committed rKLEOPATRAc69f9ddb2f62: Merge branch 'Applications/17.12' (authored by aheinecke).
Merge branch 'Applications/17.12'
Jan 22 2018, 3:28 PM
aheinecke committed rKLEOPATRAdc7f96943133: Properly bump required libkleo version (authored by aheinecke).
Properly bump required libkleo version
Jan 22 2018, 3:17 PM
aheinecke committed rKLEOPATRAdab67a6764eb: Add CMS support to notepad (authored by aheinecke).
Add CMS support to notepad
Jan 22 2018, 1:08 PM
aheinecke committed rKLEOPATRAad3ead7f70c6: Add sign or enc exclusive mode for Notepad CMS (authored by aheinecke).
Add sign or enc exclusive mode for Notepad CMS
Jan 22 2018, 1:08 PM
aheinecke committed rKLEOPATRAd039879600b6: Automatically add recipients from decryptresult (authored by aheinecke).
Automatically add recipients from decryptresult
Jan 22 2018, 1:08 PM
gniibe committed rG91303b7df9c3: scd: Support KDF Data Object of OpenPGPcard V3.3. (authored by gniibe).
scd: Support KDF Data Object of OpenPGPcard V3.3.
Jan 22 2018, 11:47 AM
gniibe triaged T3752: gpg --card-status does NOT to create secret key stubs as Normal priority.

I use Debian stretch. It works for me with GnuPG 2.2.4.
The stub is created at the time when --card-edit accesses the card.
When I type RET after fetch command, it shows the key information.

Jan 22 2018, 11:34 AM · scd, gnupg (gpg22), Bug Report
gniibe claimed T3752: gpg --card-status does NOT to create secret key stubs .
Jan 22 2018, 11:00 AM · scd, gnupg (gpg22), Bug Report
werner added projects to T3752: gpg --card-status does NOT to create secret key stubs : gnupg (gpg22), scd.
Jan 22 2018, 10:44 AM · scd, gnupg (gpg22), Bug Report
werner triaged T3753: Bad self-signatures and missing subkey usage flags when creating ECDSA/Ed25519 keys in batch mode as Normal priority.

You can't use the curve Ed25519 with ECDSA; you need to use EdDSA, The error checking when using the parameter file does not catch all errors. It should do this of course.

Jan 22 2018, 10:38 AM · gnupg24, Bug Report
chindraba created T3753: Bad self-signatures and missing subkey usage flags when creating ECDSA/Ed25519 keys in batch mode.
Jan 22 2018, 8:07 AM · gnupg24, Bug Report
fogine created T3752: gpg --card-status does NOT to create secret key stubs .
Jan 22 2018, 1:05 AM · scd, gnupg (gpg22), Bug Report

Jan 21 2018

werner committed rG7356d6ec50ea: gpg: Support EAX if for latest Libgcrypt. (authored by werner).
gpg: Support EAX if for latest Libgcrypt.
Jan 21 2018, 5:05 PM
werner committed rG3f4ca85cb0cf: gpg: First take on PKT_ENCRYPTED_AEAD. (authored by werner).
gpg: First take on PKT_ENCRYPTED_AEAD.
Jan 21 2018, 4:41 PM

Jan 20 2018

jukivili committed rC93503c127a52: Add ARMv8/CE acceleration for AES-XTS (authored by jukivili).
Add ARMv8/CE acceleration for AES-XTS
Jan 20 2018, 9:27 PM

Jan 19 2018

cipherpunks added a comment to T3751: man page syntax mentions token "[args]" but then does not define it.

First, there is a documentation bug: args is undefined. It appears at the top of the man page, but nothing in the man page says what an argument is. The man page says --recipient is an "option" (but it's not, it's an argument, and the distinction is important). I broke neomutt recently because I read the GPG man page, which stipulates a particular sequence of tokens and implied that the old commandline was out of order. That is why it's suddenly a problem after 20 yrs.

Jan 19 2018, 5:42 PM · Documentation, Bug Report
werner added a comment to T3751: man page syntax mentions token "[args]" but then does not define it.

Sorry, I don't understand your request. I might missing some context related to the neomutt bug, though. What I can see tehre is that gpg options are used after the option/command to arg delimtyer "--" . That is of course wrong. It might be that mutt uses a special syntax here but I can't remeber that because it is 15 years since I implemented the new crypto layer in mutt. And you should really prefer to use the use_gpgme than the >20 year direct call of gpg.

Jan 19 2018, 4:55 PM · Documentation, Bug Report
cipherpunks created T3751: man page syntax mentions token "[args]" but then does not define it.
Jan 19 2018, 4:08 PM · Documentation, Bug Report
werner closed T3750: Technological unemployment is (almost) here; as Spite.

@aa: this is not a platform to share arbitrary data or fun stuff. Please use some other service for this.

Jan 19 2018, 11:43 AM
aa created T3750: Technological unemployment is (almost) here; in the S1 Public space.
Jan 19 2018, 10:22 AM
werner committed rDf8a54305c4e3: web: Add La Boussole as first privacy training entity. (authored by werner).
web: Add La Boussole as first privacy training entity.
Jan 19 2018, 9:28 AM
werner reopened T2905: EFL-based pinentry as "Open".

Oh yes, I should re-open this because we should keep on tracking the status - either for an included EFL version or an external version.

Jan 19 2018, 8:54 AM · pinentry, Feature Request
werner updated subscribers of T2905: EFL-based pinentry.

I have not followed this bug for the last 6 months and meanwhile @justus and @neal moved on to the pEp company and are not any longer available to work on this. Although, I made the last pinentry release I do no closely follow the development. What I noticed is that we still don't have an EFL based pinentry despite that I explained them several times that I would like to see EFL in pinentry proper. I can't remember what the Mike Blumenkrantz version is or that there have been two pending versions at all. The thread is pretty long and I have note read it in its full length.

Jan 19 2018, 8:53 AM · pinentry, Feature Request
werner closed T3728: error: sign+encrypt failed: unusable public key as Invalid.
Jan 19 2018, 8:29 AM · Support
aheinecke added a comment to T3714: Failing to decrypt due to missing MDC.

I have not checked whether we make this available in the GPGME API

Jan 19 2018, 7:37 AM · FAQ, kleopatra

Jan 18 2018

wltjr added a comment to T2905: EFL-based pinentry.

Proceeding with a fork, and likely will remove other interfaces and just maintain another version of pinentry for EFL. Maybe renamed to pinentry-efl, and only have that and tty and curses interfaces in addition to EFL.

Jan 18 2018, 8:13 PM · pinentry, Feature Request
werner triaged T3748: GPA is stuck if keyring is too big and trust-model is tofu+pgp as High priority.

One of these TOFU bugs. Thanks for the good bug report.

Jan 18 2018, 7:43 PM · TOFU, gnupg (gpg22), gpa
werner added a comment to T3714: Failing to decrypt due to missing MDC.

There can't be an MDC warning if MDC is not used ;-)

Jan 18 2018, 7:37 PM · FAQ, kleopatra
matoid added a comment to T3746: Outlook 2016 - Cannot display signed email in sent folder.
Jan 18 2018, 6:39 PM · Info Needed, gpgol, Bug Report, gpg4win
gouttegd created T3748: GPA is stuck if keyring is too big and trust-model is tofu+pgp in the S1 Public space.
Jan 18 2018, 5:08 PM · TOFU, gnupg (gpg22), gpa
werner committed rGe1e35db510c9: gpg: Fix the use of future-default with --quick-add-key. (authored by werner).
gpg: Fix the use of future-default with --quick-add-key.
Jan 18 2018, 2:22 PM
aheinecke committed rKLEOPATRA3f34d34cf81d: Add revert button to padwidget (authored by aheinecke).
Add revert button to padwidget
Jan 18 2018, 1:58 PM
werner closed T3747: Erroneous algo picked when using quick-add-key and future-default as Resolved.

Well, that was a bit tricky to fix but it has been done and will go into 2.2.5.

Jan 18 2018, 1:46 PM · gnupg (gpg22), Bug Report
aheinecke added a project to T3714: Failing to decrypt due to missing MDC: gnupg.

As far as I can see GnuPG does not emit appropriate status lines:

Jan 18 2018, 1:29 PM · FAQ, kleopatra