Page MenuHome GnuPG
Feed All Stories

Feb 3 2018

jukivili committed rCffdc6f3623a0: Fix incorrect counter overflow handling for GCM (authored by jukivili).
Fix incorrect counter overflow handling for GCM
Feb 3 2018, 1:38 PM
onickolay added a comment to T3774: Failure to decrypt AEAD-encrypted files in some rare cases.

Feb 3 2018, 11:56 AM · gnupg, Bug Report
onickolay created T3774: Failure to decrypt AEAD-encrypted files in some rare cases.
Feb 3 2018, 11:55 AM · gnupg, Bug Report
marklundeberg created T3773: private subkeys are never deleted on non-master instances.
Feb 3 2018, 3:53 AM · Info Needed, OpenPGP, gnupg (gpg22), Bug Report
werner triaged T3770: heap buffer overflow in iobuf.c as Unbreak Now! priority.
Feb 3 2018, 1:30 AM · g10, Bug Report

Feb 2 2018

dkg created T3772: gpg-zip fails with recipient names that have whitespace in them.
Feb 2 2018, 11:47 PM · gpgtar, Bug Report
ralfbergs created T3771: Strange GUI artefacts left after sending email.
Feb 2 2018, 7:13 PM · gpgol, Bug Report
jfe created T3770: heap buffer overflow in iobuf.c.
Feb 2 2018, 4:28 PM · g10, Bug Report
wiz added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

I'm confused. I've just now retested, and I get further with BSD make (there is another problem when importing the keys into the test keyring, where it the error is ignored with GNU make but the build fails with BSD make) but that is not what I want to focus on.

Feb 2 2018, 4:03 PM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
dams50 added a comment to T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size.

Our HSM is a certified FIPS 140-2, sec level3, hardware module, exposing a PKCS#11 v2.30 spec compliant API.

Feb 2 2018, 3:29 PM · gnupg (gpg14)
hs updated the task description for T3769: GPG messages with empty content / not decrypted in Outlook 2010.
Feb 2 2018, 3:26 PM · Bug Report, gpg4win
hs renamed T3769: GPG messages with empty content / not decrypted in Outlook 2010 from GPG messages with empty cotent / not decrypted in Outlook 2010 to GPG messages with empty content / not decrypted in Outlook 2010.
Feb 2 2018, 3:25 PM · Bug Report, gpg4win
hs created T3769: GPG messages with empty content / not decrypted in Outlook 2010.
Feb 2 2018, 3:24 PM · Bug Report, gpg4win
werner added a comment to T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size.

What kind of hardware token?

Feb 2 2018, 2:38 PM · gnupg (gpg14)
Laurent Montel <montel@kde.org> committed rKLEOPATRA7d6d053aa175: Use QLatin1String (authored by Laurent Montel <montel@kde.org>).
Use QLatin1String
Feb 2 2018, 2:01 PM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAdbf73d0c72fe: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Feb 2 2018, 7:16 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAa61ed4c2d377: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Feb 2 2018, 5:25 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAc1a84d3aa3e4: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Feb 2 2018, 3:33 AM

Feb 1 2018

dams50 updated the task description for T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size.
Feb 1 2018, 7:45 PM · gnupg (gpg14)
dams50 edited projects for T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size, added: gnupg (gpg14); removed gnupg (gpg23).
Feb 1 2018, 7:44 PM · gnupg (gpg14)
dams50 updated the task description for T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size.
Feb 1 2018, 7:41 PM · gnupg (gpg14)
dams50 created T3768: Decryption of RSA public key encrypted session key packet fails when encrypted session key packet length is not equal to RSA key modulus size in the S1 Public space.
Feb 1 2018, 7:40 PM · gnupg (gpg14)
kristianf added a comment to T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6.

The patch is available in our downstream bugtracker as attachment to https://bugs.gentoo.org/646194

Feb 1 2018, 2:16 PM · gnupg (gpg22), dirmngr, Bug Report
mgorny added a comment to T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6.

This can easily be solved by adding two more cases to handle_send_request_error(): for GPG_ERR_EADDRNOTAVAIL (that's IPv6 disabled via procfs) and GPG_ERR_EAFNOSUPPORT (that's missing kernel support). Normally I'd submit a patch but I don't care enough to jump through all the hoops just to get two-line change in.

Feb 1 2018, 1:40 PM · gnupg (gpg22), dirmngr, Bug Report
Valodim added a comment to T3766: GnuPG should reject keys that are subkeys of itself.

Sorry, I don't understand. Can you describe your use case in more detail?

Feb 1 2018, 12:47 PM · gnupg (gpg22), Feature Request
werner committed rG303310d05e70: gpg: Rename a misnomed arg in open_outfile. (authored by werner).
gpg: Rename a misnomed arg in open_outfile.
Feb 1 2018, 12:28 PM
werner committed rG26c900a8f09d: Add a new OpenPGP card vendor. (authored by werner).
Add a new OpenPGP card vendor.
Feb 1 2018, 12:28 PM
werner committed rGf98e193c8425: gpg: Update list of card vendors from master (authored by werner).
gpg: Update list of card vendors from master
Feb 1 2018, 12:28 PM
werner added a comment to T3766: GnuPG should reject keys that are subkeys of itself.

You have a token with one spare key which you want to use for encryption and certification. And being able to replace the encryption subkey eventually.

Feb 1 2018, 9:28 AM · gnupg (gpg22), Feature Request
werner triaged T3767: simplify sharing dirmngr's across multiple GNUPGHOMEs as High priority.

Originally dirmngr was designed to be a system service for the reason that CRLs are not user specific. However, the majority of systems today are used by a single user and thus we dropped that feature when integrating dirmngr into gnupg.

Feb 1 2018, 9:26 AM · Documentation, Feature Request, gnupg, dirmngr

Jan 31 2018

Valodim added a comment to T3766: GnuPG should reject keys that are subkeys of itself.

a key that is signed as its own subkey, in a construct where the key and subkey have the same fingerprint? what ever could be a valid use case for such a scenario?

Jan 31 2018, 8:06 PM · gnupg (gpg22), Feature Request
dkg created T3767: simplify sharing dirmngr's across multiple GNUPGHOMEs in the S1 Public space.
Jan 31 2018, 7:56 PM · Documentation, Feature Request, gnupg, dirmngr
werner triaged T3751: man page syntax mentions token "[args]" but then does not define it as Low priority.

Come on, it is in daily use for 15 years. MUA which can't handle MIME at all but PGP are still able to decrypt PGP/MIME. That is why ME specified PGP/MIME this way.

Jan 31 2018, 7:26 PM · Documentation, Bug Report
jukivili claimed T3764: AES-GCM bug for len(IV) != 96.
Jan 31 2018, 7:02 PM · libgcrypt, Bug Report
aheinecke committed rW6cbe26503970: Update libkleo tarball (authored by aheinecke).
Update libkleo tarball
Jan 31 2018, 6:40 PM
werner added a comment to T3348: gpgsm: should default to --disable-crl-checks.

--use-tor does not avoid it because the CRL-DP can be made unique for each certificate. Depending on the verification model a CRL or OCSP lookup is necessary for correct evalution of a signature (shell model as used for qualified signature). This is why we in gpg honor-keyserver-url is not enabled by default; the keyserver URL take from the key is the OpenPGP counterpart of the CRL-DP.

Jan 31 2018, 6:11 PM · gpgme, gnupg, S/MIME
werner triaged T3766: GnuPG should reject keys that are subkeys of itself as Normal priority.

I can't see why this should be out-of-spec. In fact I did this my self several times to create keys from other keys.

Jan 31 2018, 6:03 PM · gnupg (gpg22), Feature Request
dkg added a comment to T3348: gpgsm: should default to --disable-crl-checks.

it is the decision of the user to use such a certificate.

Jan 31 2018, 5:04 PM · gpgme, gnupg, S/MIME
Valodim added a comment to T3766: GnuPG should reject keys that are subkeys of itself.

uploaded the offending key for reference:

Jan 31 2018, 4:27 PM · gnupg (gpg22), Feature Request
Valodim created T3766: GnuPG should reject keys that are subkeys of itself.
Jan 31 2018, 4:26 PM · gnupg (gpg22), Feature Request
aheinecke committed rO26b931937fe1: Fix inline responses by making them sync (authored by aheinecke).
Fix inline responses by making them sync
Jan 31 2018, 1:23 PM
aheinecke committed rOee673d23ae83: Fix window modality of encryption (authored by aheinecke).
Fix window modality of encryption
Jan 31 2018, 1:23 PM
aheinecke committed rO3ed205e7f9d9: Reactivate T3656 workaround (authored by aheinecke).
Reactivate T3656 workaround
Jan 31 2018, 1:23 PM
werner added a comment to T3348: gpgsm: should default to --disable-crl-checks.

The implemented X.509 profiles require that the status of a certificate is to be checked. CRLs are also not looked up for each verification but only once during their lifetime. Some CA have unreasonable short lifetimes for their CRL but it is the decision of the user to use such a certificate.

Jan 31 2018, 9:47 AM · gpgme, gnupg, S/MIME
werner closed T3765: Remove my account as Resolved.

I disabled your account but the I won't delete any comments of yours. They are considered to be in the public domain (see welcome page) and are parts of other bug reports. Thanks for those comments.

Jan 31 2018, 9:38 AM · dev.gnupg.org
dexolabs created T3765: Remove my account.
Jan 31 2018, 7:41 AM · dev.gnupg.org

Jan 30 2018

dkg added a comment to T3348: gpgsm: should default to --disable-crl-checks.

Additionally, we might want some sort of delayed or batched CRL-checking that doesn't block signature verification with another network interaction, but would protect the user against future problems.

Jan 30 2018, 5:46 PM · gpgme, gnupg, S/MIME
aheinecke committed rOc52f7ed9456a: Implement MIME Sign in the new way (authored by aheinecke).
Implement MIME Sign in the new way
Jan 30 2018, 3:51 PM
aheinecke committed rOf622470a3a29: Make MIME encrypt work in the new way (authored by aheinecke).
Make MIME encrypt work in the new way
Jan 30 2018, 3:21 PM
aheinecke committed rOe789048f47fc: Make inline encryption work in the new way (authored by aheinecke).
Make inline encryption work in the new way
Jan 30 2018, 2:22 PM
aheinecke committed rOe133064eb799: Continue work on async encrypt (authored by aheinecke).
Continue work on async encrypt
Jan 30 2018, 2:22 PM
gniibe created T3764: AES-GCM bug for len(IV) != 96.
Jan 30 2018, 12:14 PM · libgcrypt, Bug Report
aheinecke committed rObec715ab3f57: First steps for async encryption handling (authored by aheinecke).
First steps for async encryption handling
Jan 30 2018, 11:55 AM
aheinecke added a subtask for T3742: Gpg4win 3.1.0: T3761: Kleopatra: Crash After Verifying Detached Signature.
Jan 30 2018, 8:16 AM · gpg4win
aheinecke added a parent task for T3761: Kleopatra: Crash After Verifying Detached Signature: T3742: Gpg4win 3.1.0.
Jan 30 2018, 8:16 AM · gpg4win, kleopatra, Bug Report
aheinecke changed the status of T3761: Kleopatra: Crash After Verifying Detached Signature from Open to Testing.

Ah under Linux we ran into an assert which made finding the problem easy. The bug was introduced by the fix for T3602. Will be fixed in the next release. Apologies for the inconvenience.

Jan 30 2018, 8:16 AM · gpg4win, kleopatra, Bug Report
aheinecke committed rKLEOPATRAdb1f931c2254: Fix assert when there is no workdir in decverify (authored by aheinecke).
Fix assert when there is no workdir in decverify
Jan 30 2018, 8:14 AM
aheinecke committed rKLEOPATRA665d4946373f: Fix refresh command error msgs (authored by aheinecke).
Fix refresh command error msgs
Jan 30 2018, 8:14 AM
aheinecke claimed T3761: Kleopatra: Crash After Verifying Detached Signature.

Thanks for your report. I tried this several times. Could not reproduce it at first but I could get it to crash sometimes. Even without GpgEX just by double clicking the signature file.

Jan 30 2018, 7:54 AM · gpg4win, kleopatra, Bug Report
gniibe added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

Thanks for your additional suggestion. I pushed the change.

Jan 30 2018, 4:37 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
gniibe committed rM59fcabbdf537: Fix for BSD Make. (authored by gniibe).
Fix for BSD Make.
Jan 30 2018, 12:26 AM

Jan 29 2018

werner triaged T3763: ECDH - encryption with obfuscated size of the symmetric key as Low priority.
Jan 29 2018, 11:03 PM · OpenPGP, gnupg (gpg23)
neurohenry renamed T3763: ECDH - encryption with obfuscated size of the symmetric key from ECDH - encryption with obfuscated key to ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:26 PM · OpenPGP, gnupg (gpg23)
neurohenry closed T3754: Problem importing DSA/1024 key signed with SHA256 as Invalid.
Jan 29 2018, 10:23 PM · Bug Report
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:22 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:21 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:21 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:20 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:19 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:14 PM · OpenPGP, gnupg (gpg23)
neurohenry updated the task description for T3763: ECDH - encryption with obfuscated size of the symmetric key.
Jan 29 2018, 10:12 PM · OpenPGP, gnupg (gpg23)
neurohenry created T3763: ECDH - encryption with obfuscated size of the symmetric key in the S1 Public space.
Jan 29 2018, 10:07 PM · OpenPGP, gnupg (gpg23)
al_b added a comment to T3761: Kleopatra: Crash After Verifying Detached Signature.

Confirming this bug in Gpg4win version 3.0.3 (previous version was OK).

Jan 29 2018, 8:31 PM · gpg4win, kleopatra, Bug Report
resipsa created T3762: Outlook 2016 - file/print error.
Jan 29 2018, 8:24 PM · gpgol, gpg4win, Bug Report
gouttegd added a comment to T3748: GPA is stuck if keyring is too big and trust-model is tofu+pgp.

I did a few more tests and here are some more observations:

Jan 29 2018, 12:00 PM · TOFU, gnupg (gpg22), gpa
wiz added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

For qt: adding /usr/pkg/qt5/bin to the path makes the build succeed. I think you should take a look at the build rules though, since it seems that it wants to execute the header file if "moc" is not found.

Jan 29 2018, 11:59 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
gniibe added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

For BSD Make issue, please try:

Jan 29 2018, 11:47 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
gniibe committed rMbbb5e70e7e85: Fix compile error message. (authored by gniibe).
Fix compile error message.
Jan 29 2018, 11:40 AM
gniibe added a comment to T3376: gpgme: add missing getenv_r() support.

Ah, yes. Will do. Thank you for reminder.

Jan 29 2018, 11:29 AM · patch, gpgme
bernhard committed rW77880110fbb2: web: Cleanup: Removes deactivated sections. (authored by bernhard).
web: Cleanup: Removes deactivated sections.
Jan 29 2018, 11:19 AM
bernhard committed rW5c48dde66bef: web: updates some links to https (authored by bernhard).
web: updates some links to https
Jan 29 2018, 11:19 AM
gniibe changed the status of T3207: FASTWIPE_T undefined from Open to Testing.

Thanks for the report.
Fixed in master.

Jan 29 2018, 11:15 AM · Restricted Project, ntbtls, Bug Report
gniibe committed rT0b56e5c076ae: Fix wipemem.h for other architectures. (authored by gniibe).
Fix wipemem.h for other architectures.
Jan 29 2018, 11:13 AM
Jawsh created T3761: Kleopatra: Crash After Verifying Detached Signature.
Jan 29 2018, 11:09 AM · gpg4win, kleopatra, Bug Report
gniibe added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

For the latter, I think it requires path to moc, which may be like /usr/pkg/qt5. Please add it to your PATH. Then, retry from configure

Jan 29 2018, 11:04 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
bernhard committed rW04a91af8ae6a: web: improves news links to 3.0.3 (authored by bernhard).
web: improves news links to 3.0.3
Jan 29 2018, 10:53 AM
wiz added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

Using BSD make on git head of gpgme, I see

Jan 29 2018, 10:37 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
wiz added a comment to T3376: gpgme: add missing getenv_r() support.

Thank you. I think you can update the comment below the implementation now ("/* FIXME: Implement this when we have the specification for it. */) and the #error line.

Jan 29 2018, 10:29 AM · patch, gpgme
bernhard added a comment to T3725: jabber.quux.de certificate ran out 2018-01-09.

Still open.

Jan 29 2018, 8:42 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA9213fd678e63: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Jan 29 2018, 6:50 AM
gniibe closed T3376: gpgme: add missing getenv_r() support as Resolved.

Fixed in rM37d62e9d0f68: core: Implement _gpgme_getenv for NetBSD..

Jan 29 2018, 5:54 AM · patch, gpgme
l10n daemon script <scripty@kde.org> committed rKLEOPATRA977679b01e05: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Jan 29 2018, 5:08 AM
gniibe added a comment to T3056: gpgme-1.8.0: test failures on NetBSD.

Other problems are fixed. Please test. It works for me on NetBSD 7.0.2.

Jan 29 2018, 4:09 AM · gpgme (gpgme 1.23.x), gpgagent, gnupg (gpg23)
gniibe committed rM58130b97f658: tests: Fix for NetBSD. (authored by gniibe).
tests: Fix for NetBSD.
Jan 29 2018, 4:06 AM
gniibe committed rM37d62e9d0f68: core: Implement _gpgme_getenv for NetBSD. (authored by gniibe).
core: Implement _gpgme_getenv for NetBSD.
Jan 29 2018, 3:56 AM
gniibe committed rG64aa98c8a055: tests: Fix for NetBSD with __func__. (authored by gniibe).
tests: Fix for NetBSD with __func__.
Jan 29 2018, 1:38 AM

Jan 27 2018

werner committed rGf8e868d9dfb6: dirmngr: Improve assuan error comment for cmd keyserver. (authored by werner).
dirmngr: Improve assuan error comment for cmd keyserver.
Jan 27 2018, 7:55 PM
AladW added a comment to T2986: Can not access keyserver without the standard-resolver option.

I just thought that going by your comment on Sat, Jan 27, 5:29 PM that you would use libdns, instead of resolv.conf directly. Maybe I understood that comment wrong.

Jan 27 2018, 5:44 PM · Bug Report, gnupg
werner added a comment to T2986: Can not access keyserver without the standard-resolver option.

dirmngr looks into /.etc/resolv.conf and does not know anything about systemd specific things (nor do I). Thus having a symlink seems to be an appropriate solution.

Jan 27 2018, 5:29 PM · Bug Report, gnupg
AladW added a comment to T2986: Can not access keyserver without the standard-resolver option.

Note that it works as expected if I symlink /run/systemd/resolve/stub-resolv.conf to /etc/resolv.conf. Other programs appear to not require this change.

Jan 27 2018, 2:29 PM · Bug Report, gnupg