Page MenuHome GnuPG
Feed All Stories

Jul 4 2018

werner added a subtask for T4022: too-large User ID packets result in dropping an entire certificate: T4036: gnupg 2.2.9 release.
Jul 4 2018, 10:17 AM · gnupg, Bug Report
werner committed rG01cd66f9faf1: gpg: Ignore too large user ids during import. (authored by werner).
gpg: Ignore too large user ids during import.
Jul 4 2018, 10:15 AM
werner committed rG60e7e102a153: indent: Fix indentation of read_block in g10/import.c (authored by werner).
indent: Fix indentation of read_block in g10/import.c
Jul 4 2018, 10:15 AM
werner claimed T4022: too-large User ID packets result in dropping an entire certificate.
Jul 4 2018, 9:20 AM · gnupg, Bug Report
werner closed T3810: UI workshop as Wontfix.

We didn't found the time to organize it. There will be a OpenPGP summit this fall organized by Patrick, though

Jul 4 2018, 9:19 AM · Documentation, gnupg, UI, Verein
werner added a subtask for T4014: when verifying signatures, gpg and gpgv should ensure signing capabilities: T4036: gnupg 2.2.9 release.
Jul 4 2018, 9:16 AM · gpgv, gnupg, Bug Report
werner added a parent task for T4036: gnupg 2.2.9 release: T4014: when verifying signatures, gpg and gpgv should ensure signing capabilities.
Jul 4 2018, 9:16 AM · Release Info, gnupg
werner added a parent task for T4036: gnupg 2.2.9 release: T4018: gpg --with-colons --show-keys does not show revocation certificates.
Jul 4 2018, 9:15 AM · Release Info, gnupg
werner added a subtask for T4018: gpg --with-colons --show-keys does not show revocation certificates: T4036: gnupg 2.2.9 release.
Jul 4 2018, 9:15 AM · gnupg, Bug Report
werner closed T4018: gpg --with-colons --show-keys does not show revocation certificates as Resolved.

Will be released with 2.2.9

Jul 4 2018, 9:13 AM · gnupg, Bug Report
werner committed rG214b0077264e: gpg: Extra check for sign usage when verifying a data signature. (authored by werner).
gpg: Extra check for sign usage when verifying a data signature.
Jul 4 2018, 9:11 AM
werner committed rGef50fdf82a45: gpg: Extra check for sign usage when verifying a data signature. (authored by werner).
gpg: Extra check for sign usage when verifying a data signature.
Jul 4 2018, 9:11 AM
werner closed T4014: when verifying signatures, gpg and gpgv should ensure signing capabilities as Resolved.

Fix will also go into 2.2.9

Jul 4 2018, 9:10 AM · gpgv, gnupg, Bug Report
aheinecke added a comment to T3999: automatically turn on/offer encryption if recipients' keys are known.

changing to testing is our marker for "done in code but not fully tested / released". It helps to keep an overview of the issues which are "done" for the next release.

Jul 4 2018, 9:09 AM · gpgol, Feature Request
JJworx added a comment to T3999: automatically turn on/offer encryption if recipients' keys are known.

Hi Andre,

Jul 4 2018, 8:51 AM · gpgol, Feature Request
werner added a comment to T4044: HTTP proxy not honoured.

Do you have Tor or the Tor Browser running? Dirmngr will use them instead of a direct or proxy network connection. Di disable this behaviour put

no-use-tor

into dirmngr.conf. If that is not the case we need some more debug info. Put

log-file SOMEFILE
verbose
debug network,dns

into dirmngr.conf and post the log file (or send privately to wk@gnupg.org mentioning T4044 in the subject - no HTML please).

Jul 4 2018, 8:44 AM · Bug Report, gpg4win
aheinecke added a comment to T4038: Kleopatra: Improve handling of MDC errors.

We have two cases:

  1. No MDC with a "modern" cipher algo
Jul 4 2018, 8:33 AM · kleopatra, gpg4win, gpgme
aheinecke changed the status of T3999: automatically turn on/offer encryption if recipients' keys are known from Open to Testing.

This is implemented now and can be turned of in the new config dialog.

Jul 4 2018, 8:17 AM · gpgol, Feature Request
aheinecke changed the status of T4041: Kleopatra: Fix S/MIME file extension for armored files from Open to Testing.

ASCII Armored CMS files now also use p7m and p7s this is already handled gracefully by Kleopatra and does not require us to register new filetypes.

Jul 4 2018, 8:16 AM · gpg4win, kleopatra
gniibe committed rC9660c3fafd73: RFC-8439 was published. (authored by gniibe).
RFC-8439 was published.
Jul 4 2018, 7:27 AM
aheinecke committed rW5934b8a468c5: Update sponsors for first half of 2018 (authored by aheinecke).
Update sponsors for first half of 2018
Jul 4 2018, 7:13 AM

Jul 3 2018

werner raised the priority of T4052: Cannot generate NIST-P or Brainpool-P subkeys without explicitly specifying the algorithm from Wishlist to Low.
Jul 3 2018, 6:27 PM · gnupg, Bug Report
aheinecke added a comment to D463: Add ctx flag for auto-key-locate.

I find this better then a new "KEYLIST_MODE_WKD" as it is more flexible and this flexibility with context flags is currently our thing anyway.

Jul 3 2018, 6:07 PM
tookmund triaged T4052: Cannot generate NIST-P or Brainpool-P subkeys without explicitly specifying the algorithm as Wishlist priority.

This is really minor, just wanted to report it so it did not get forgotten.

Jul 3 2018, 6:06 PM · gnupg, Bug Report
tookmund created T4052: Cannot generate NIST-P or Brainpool-P subkeys without explicitly specifying the algorithm.
Jul 3 2018, 6:05 PM · gnupg, Bug Report
aheinecke created D463: Add ctx flag for auto-key-locate.
Jul 3 2018, 6:03 PM
aheinecke added a revision to T2917: --locate-key should re-fetch key via WKD if it is expired: D463: Add ctx flag for auto-key-locate.
Jul 3 2018, 6:03 PM · gnupg (gpg22), Bug Report
aheinecke committed rO61956b72ebf4: Remove now unused WinAPI dialog resource (authored by aheinecke).
Remove now unused WinAPI dialog resource
Jul 3 2018, 4:35 PM
aheinecke committed rO541333d406df: Change addion-options to use external dialog (authored by aheinecke).
Change addion-options to use external dialog
Jul 3 2018, 4:35 PM
aheinecke committed rGTOd6f0ca99b4d3: First working implementation of the config dialog (authored by aheinecke).
First working implementation of the config dialog
Jul 3 2018, 4:11 PM
aheinecke added a comment to T4048: Wrong/stupid result with decryption of sent maisl when reopening them in the sent-directory in outlook 2007.

I don't think that this was ever working the Outlook 2007 code has been pretty much unchanged since 2013.
According to T1137 a workaround seems to be to enable the S/MIME Support in GpgOL.

Jul 3 2018, 3:13 PM · Bug Report, gpg4win
Togok added a comment to T4048: Wrong/stupid result with decryption of sent maisl when reopening them in the sent-directory in outlook 2007.

Thanks very much for your help! Could you please tell me the latest version, that is running without any mistakes on outlook 2007?

Jul 3 2018, 3:08 PM · Bug Report, gpg4win
aheinecke closed T4048: Wrong/stupid result with decryption of sent maisl when reopening them in the sent-directory in outlook 2007 as Wontfix.

Outlook 2007 is no longer supported. Neither by Microsoft nor by GpgOL. Sorry for that. But the 2010 and later GpgOL had a completely different codebase and we had to remove the support at some point.

Jul 3 2018, 2:30 PM · Bug Report, gpg4win
aheinecke created T4051: Gpg4win: Installer does not kill processes in silent mode.
Jul 3 2018, 2:23 PM · gpg4win
mkrambach committed rMa52ec87d4063: js: fixing Key import/export test (authored by mkrambach).
js: fixing Key import/export test
Jul 3 2018, 12:52 PM
werner closed T1173: gpg has no easy way to view the reason and description of revocation sigs as Resolved.

Backport done. To be released with 2.2.9.

Jul 3 2018, 12:34 PM · gnupg, Debian, Feature Request
werner committed rG04fb76684d8b: gpg: Print revocation reason for "rev" records. (authored by werner).
gpg: Print revocation reason for "rev" records.
Jul 3 2018, 12:33 PM
werner committed rGa8e24addcc4e: gpg: Print revocation reason for "rvs" records. (authored by werner).
gpg: Print revocation reason for "rvs" records.
Jul 3 2018, 12:33 PM
werner committed rG5c67ee160d49: gpg: Let --show-keys print revocation certificates. (authored by werner).
gpg: Let --show-keys print revocation certificates.
Jul 3 2018, 12:33 PM
werner triaged T4050: GnuPG fails to decrypt file encrypted with more than one password with any password but the first as High priority.
Jul 3 2018, 11:38 AM · gnupg (gpg22)
Volker Krause <vkrause@kde.org> committed rKLEOPATRA3fdec6a03369: Remove dead code (authored by Volker Krause <vkrause@kde.org>).
Remove dead code
Jul 3 2018, 8:45 AM
gniibe triaged T4047: Memory leak in function buf_to_sig as Normal priority.

Fixed in master and 2.2 branch.

Jul 3 2018, 2:22 AM · Bug Report
gniibe committed rG2809be1f97a4: g10: Fix memory leak for PKT_signature. (authored by gniibe).
g10: Fix memory leak for PKT_signature.
Jul 3 2018, 2:22 AM
gniibe added a comment to T4047: Memory leak in function buf_to_sig.

I found two more cases. Those are included in the fix.

Jul 3 2018, 2:16 AM · Bug Report
gniibe committed rG996febbab21e: g10: Fix memory leak for PKT_signature. (authored by gniibe).
g10: Fix memory leak for PKT_signature.
Jul 3 2018, 2:16 AM
gniibe closed T3900: Memory leak in check_sig_and_print as Resolved.
Jul 3 2018, 2:14 AM · gnupg (gpg22), Bug Report

Jul 2 2018

werner committed rG8a915cd9faf0: agent: New commands PUT_SECRET and GET_SECRET. (authored by werner).
agent: New commands PUT_SECRET and GET_SECRET.
Jul 2 2018, 9:44 PM
kallisti5 added a comment to T3894: re-evaluate default randomness choices during key generation on GNU/Linux platforms.

User input, anything to solve the lack of entropy on servers would be *great*. We have a bunch of buildbot workers we would *love* to have sign their artifacts... however we end up (unsuccessfully) doing stupid things like this to try and drive up entropy as a non-root user:

Jul 2 2018, 8:46 PM · libgcrypt, gnupg
werner triaged T4049: BUG in gpa - MUST everytime save private key to harddisk to export it as Normal priority.

I am not sure what you mean by “keybundle”. Is is a single keyblock or a selection of multiple keyblocks?

Jul 2 2018, 8:46 PM · Feature Request, gpa
werner committed rG58baf40af641: common: New function percent_data_escape. (authored by werner).
common: New function percent_data_escape.
Jul 2 2018, 8:35 PM
werner committed rG3978df943dc7: agent: Fix segv running in --server mode (authored by werner).
agent: Fix segv running in --server mode
Jul 2 2018, 8:35 PM
aheinecke committed rW56aed0f4de59: Make it optional to install native-messaging (authored by aheinecke).
Make it optional to install native-messaging
Jul 2 2018, 6:24 PM
anarcat added a comment to T3894: re-evaluate default randomness choices during key generation on GNU/Linux platforms.

Looking at the table in random(7) it seems clear to me that what we want to just invoke getrandom() with no arguments. This blocks until the kernel's PRNG has been adequately seeded, but once seeded it doesn't block, while still pulling from an unbreakably-strong PRNG. this is the best-of-both-worlds situation that we want.

Changing the GnuPG long-term (and short-term) key generation techniques to use this approach might require coordination with gcrypt. gcrypt's gcry_random_level currently has GCRY_WEAK_RANDOM and GCRY_STRONG_RANDOM and GCRY_VERY_STRONG_RANDOM, which doesn't represent the nuance described above.

One approach might be to just have gcrypt on Linux treat all values of gcry_random_level the same, and use getrandom() for all of them.

Jul 2 2018, 5:24 PM · libgcrypt, gnupg
dkg added a comment to T3894: re-evaluate default randomness choices during key generation on GNU/Linux platforms.

ping again…

Jul 2 2018, 4:47 PM · libgcrypt, gnupg
aheinecke committed rGTOff7b019525e4: Add first version of gpgol config page (authored by aheinecke).
Add first version of gpgol config page
Jul 2 2018, 3:54 PM
justus created T4050: GnuPG fails to decrypt file encrypted with more than one password with any password but the first in the S1 Public space.
Jul 2 2018, 1:47 PM · gnupg (gpg22)
Laurent Montel <montel@kde.org> committed rKLEOPATRA28c431086c5c: Fix warning (authored by Laurent Montel <montel@kde.org>).
Fix warning
Jul 2 2018, 1:36 PM
aspiargue updated the task description for T4049: BUG in gpa - MUST everytime save private key to harddisk to export it.
Jul 2 2018, 11:59 AM · Feature Request, gpa
aspiargue created T4049: BUG in gpa - MUST everytime save private key to harddisk to export it.
Jul 2 2018, 11:56 AM · Feature Request, gpa
aheinecke committed rKLEOPATRA72651cddbc43: Use qapplication path for uniqueservice test (authored by aheinecke).
Use qapplication path for uniqueservice test
Jul 2 2018, 11:55 AM
aheinecke committed rKLEOPATRA0e134c68dd2e: Don't use c++ file as test data (authored by aheinecke).
Don't use c++ file as test data
Jul 2 2018, 11:55 AM
wiktor-k added a comment to T3910: Kleopatra: Direct way to WKD Lookup a key.

Ha, I wish e-mail-like searches would be done using only WKD with no fallbacks to keyservers... that way keys would be "more verified"... but I understand it may be not practical :)

Jul 2 2018, 11:39 AM · Restricted Project, kleopatra
aheinecke added a comment to T2917: --locate-key should re-fetch key via WKD if it is expired.

Maybe a first step would be a "KEYLIST_MODE_WKD" which sets "auto-key-locate clear,nodefault,wkd" (Would be nice for T3910 ) or just a ctx_flag "auto-key-locate" so that the caller can decide?

Jul 2 2018, 11:13 AM · gnupg (gpg22), Bug Report
aheinecke added a comment to T3887: Kleopatra: Not finishing commands.

I'm pretty sure that the running command ist the reloadkeyscommand.

Jul 2 2018, 11:09 AM · Bug Report, gpg4win, kleopatra
aheinecke committed rKLEOPATRA99f03add3ed0: Improve NetKey card error handling (authored by aheinecke).
Improve NetKey card error handling
Jul 2 2018, 10:51 AM
aheinecke committed rKLEOPATRA0f1576aca7d4: Fix crash if netkeycard has no pinstates (authored by aheinecke).
Fix crash if netkeycard has no pinstates
Jul 2 2018, 10:51 AM
werner raised the priority of T2917: --locate-key should re-fetch key via WKD if it is expired from Normal to High.
Jul 2 2018, 10:39 AM · gnupg (gpg22), Bug Report
gniibe claimed T4047: Memory leak in function buf_to_sig.

Good catch. Thank you.

Jul 2 2018, 9:35 AM · Bug Report
gniibe committed rG1aacd1247193: libdns: For SOCKS connection, just fails. (authored by gniibe).
libdns: For SOCKS connection, just fails.
Jul 2 2018, 4:38 AM
gniibe committed rGcca92ca53489: libdns: For SOCKS connection, just fails. (authored by gniibe).
libdns: For SOCKS connection, just fails.
Jul 2 2018, 4:38 AM

Jul 1 2018

Togok created T4048: Wrong/stupid result with decryption of sent maisl when reopening them in the sent-directory in outlook 2007.
Jul 1 2018, 10:25 PM · Bug Report, gpg4win
BenM committed rM5bca49975063: python bindings: scheming serpents (authored by BenM).
python bindings: scheming serpents
Jul 1 2018, 9:07 PM
BenM committed rM789ea1b01988: python bindings: gpg.core (authored by BenM).
python bindings: gpg.core
Jul 1 2018, 8:08 PM
Laurent Montel <montel@kde.org> committed rKLEOPATRAc57634fb196e: fix warning (authored by Laurent Montel <montel@kde.org>).
fix warning
Jul 1 2018, 5:34 PM
jukivili committed rC59c4e344eec6: Add hash_buffer and hash_buffers for SHA-224, SHA-385, SHA3 and BLAKE2 (authored by jukivili).
Add hash_buffer and hash_buffers for SHA-224, SHA-385, SHA3 and BLAKE2
Jul 1 2018, 4:44 PM
jukivili committed rCb136703ea0dd: Add hash_buffer and hash_buffers pointers to message digest spec (authored by jukivili).
Add hash_buffer and hash_buffers pointers to message digest spec
Jul 1 2018, 4:44 PM
jukivili committed rC8a44c55d2fb7: Clean-up implementation selection for SHA1 and SHA2 (authored by jukivili).
Clean-up implementation selection for SHA1 and SHA2
Jul 1 2018, 4:44 PM
jukivili committed rCa15c1def7e0f: AES: setup cipher object bulk routines with optimized versions (authored by jukivili).
AES: setup cipher object bulk routines with optimized versions
Jul 1 2018, 4:44 PM
jukivili committed rCca21a24808ef: Pass cipher object pointer to setkey functions (authored by jukivili).
Pass cipher object pointer to setkey functions
Jul 1 2018, 4:44 PM
jukivili committed rC233e2049a2cc: Access cipher mode routines through routine pointers (authored by jukivili).
Access cipher mode routines through routine pointers
Jul 1 2018, 4:44 PM
jukivili committed rCb6e6ace32444: Add fast path for _gcry_fips_is_operational (authored by jukivili).
Add fast path for _gcry_fips_is_operational
Jul 1 2018, 4:44 PM
jukivili committed rC87d8caa47e00: Add separate handlers for CBC-CTS variant (authored by jukivili).
Add separate handlers for CBC-CTS variant
Jul 1 2018, 4:44 PM
jukivili committed rCf5168091c193: Avoid division by spec->blocksize in cipher mode handlers (authored by jukivili).
Avoid division by spec->blocksize in cipher mode handlers
Jul 1 2018, 4:44 PM
jukivili committed rC2a94bdfc0538: tests/basic: silence GCC-8 warning (authored by jukivili).
tests/basic: silence GCC-8 warning
Jul 1 2018, 4:44 PM
jukivili committed rCa69021535b47: Fix CBC-CTS+CBC-MAC flag check (authored by jukivili).
Fix CBC-CTS+CBC-MAC flag check
Jul 1 2018, 4:44 PM

Jun 30 2018

catenacyber created T4047: Memory leak in function buf_to_sig.
Jun 30 2018, 6:16 PM · Bug Report

Jun 29 2018

Laurent Montel <montel@kde.org> committed rKLEOPATRA33930f4d01e1: GIT_SILENT: Time to increase version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Time to increase version
Jun 29 2018, 7:10 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRAd456050ec376: GIT_SILENT: Prepare 5.8.3 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare 5.8.3
Jun 29 2018, 7:07 AM
BenM committed rM35e29e139534: m4 update: python 3.7 (authored by BenM).
m4 update: python 3.7
Jun 29 2018, 6:58 AM
BenM committed rM43a2b5754571: python bindings: python 3.7 (authored by BenM).
python bindings: python 3.7
Jun 29 2018, 6:58 AM
gniibe closed T2986: Can not access keyserver without the standard-resolver option as Resolved.

The cause is: ! in nsswitch.conf
This was fixed (2.2 branch) by rGd4c0187dd931: libdns: Hack to skip negation term. for GnuPG in Jan 2017.
I found it was fixed in the original libdns, and this fix is merged into rG20c289606f89: libdns: Sync to upstream. to GnuPG.

Jun 29 2018, 1:57 AM · Bug Report, gnupg

Jun 28 2018

werner triaged T4046: GnuPG fails to verify signatures that have a issuer fingerprint but no issuer subpacket as Normal priority.
Jun 28 2018, 9:11 PM · gnupg (gpg22)
justus added a comment to T4046: GnuPG fails to verify signatures that have a issuer fingerprint but no issuer subpacket.

Attaching files is gone, but here they are inline:

Jun 28 2018, 4:57 PM · gnupg (gpg22)
justus created T4046: GnuPG fails to verify signatures that have a issuer fingerprint but no issuer subpacket in the S1 Public space.
Jun 28 2018, 4:52 PM · gnupg (gpg22)
justus placed T2986: Can not access keyserver without the standard-resolver option up for grabs.
Jun 28 2018, 4:15 PM · Bug Report, gnupg
aheinecke updated subscribers of T4044: HTTP proxy not honoured.

Werner please give an opinion / triage.

Jun 28 2018, 3:30 PM · Bug Report, gpg4win
marcogaio created T4044: HTTP proxy not honoured.
Jun 28 2018, 2:37 PM · Bug Report, gpg4win
BenM committed rM6aec7d6e4a51: docs: python bindings howto (authored by BenM).
docs: python bindings howto
Jun 28 2018, 10:53 AM
BenM committed rM48174b2bcc31: whitespace police: (authored by BenM).
whitespace police:
Jun 28 2018, 10:53 AM
BenM committed rMa7ccdc51efd8: python bindings examples (authored by BenM).
python bindings examples
Jun 28 2018, 10:53 AM