Page MenuHome GnuPG
Feed All Stories

May 16 2019

werner added a comment to T4505: SM, W32: GPGSM hangs up the GnuPG System.

That was obvious. rG6fc5df1e10129f3171d80cf731f310b9e8d97c26 fixes this.

May 16 2019, 2:00 PM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
werner committed rG6fc5df1e1012: kbx: Fix an endless loop under Windows due to an incomplete fix. (authored by werner).
kbx: Fix an endless loop under Windows due to an incomplete fix.
May 16 2019, 1:57 PM
aheinecke committed rKLEOPATRA2e5b420cb634: Fix copy&paste error that breaks gpg process calls (authored by aheinecke).
Fix copy&paste error that breaks gpg process calls
May 16 2019, 1:36 PM
aheinecke reopened T4505: SM, W32: GPGSM hangs up the GnuPG System as "Open".

When doing a "gpgsm --with-validation -k foo" (assuming you have a cert foo) gpgsm now goes into a loop and prints the certficates that match "foo" over and over again. I have not tested if it was caused by this change but I think it is likely.

May 16 2019, 1:15 PM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
aheinecke removed a subtask for T4505: SM, W32: GPGSM hangs up the GnuPG System: T4509: Release GnuPG 2.2.16.
May 16 2019, 1:12 PM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
aheinecke removed a parent task for T4509: Release GnuPG 2.2.16: T4505: SM, W32: GPGSM hangs up the GnuPG System.
May 16 2019, 1:12 PM · Release Info, gnupg (gpg22)
aheinecke claimed T4517: de-mail and GPG with Smart Card no decryption.

Smartcard support is a big advantage of using the GnuPG backend and it should work of course.

May 16 2019, 1:12 PM · Bug Report, gpg4win
werner claimed T4334: gpg "showphoto" not creating temp file on Windows 10.
May 16 2019, 12:44 PM · gpg4win, Windows, gnupg (gpg22), Bug Report
werner closed T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad, a subtask of T4509: Release GnuPG 2.2.16, as Resolved.
May 16 2019, 12:28 PM · Release Info, gnupg (gpg22)
werner closed T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad as Resolved.

Fixed in amster and 2.2:

May 16 2019, 12:28 PM · gnupg (gpg22)
werner committed rG3a28706cfd96: gpgconf: Before --launch check that the config file is fine. (authored by werner).
gpgconf: Before --launch check that the config file is fine.
May 16 2019, 12:27 PM
werner committed rG50c2f76ae65d: gpgconf: Before --launch check that the config file is fine. (authored by werner).
gpgconf: Before --launch check that the config file is fine.
May 16 2019, 12:26 PM
werner claimed T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad.
May 16 2019, 10:53 AM · gnupg (gpg22)
werner triaged T4511: dirmngr error logs claim that HTTP GET requests are percent-escaped, but they are not as Wishlist priority.

This requires too much changes and does not reflect the reality. It actually makes debugging harder for us.

May 16 2019, 10:52 AM · Bug Report, dirmngr
werner closed T4516: use https: links internally where possible instead of http:// in libgcrypt source as Wontfix.

I pulled that branch with the commit w/o problems. However, as noted on your commit I won't apply that because it does not make any sense to change boilerplate blurbs for just an additional 's'. Nobody really uses that and browser can try to use https first. Sorry, there are more important things around.

May 16 2019, 10:50 AM · libgcrypt
werner created T4518: Kleopatra: Changes log-file tcp://IPADDR to tcp:\\IPADDR.
May 16 2019, 10:24 AM · Restricted Project, Windows, kleopatra
aheinecke removed a parent task for T4509: Release GnuPG 2.2.16: T4389: Gpg4win 3.1.8.
May 16 2019, 9:51 AM · Release Info, gnupg (gpg22)
aheinecke removed a subtask for T4389: Gpg4win 3.1.8: T4509: Release GnuPG 2.2.16.
May 16 2019, 9:51 AM · gpg4win, Release Info
blades added a comment to T4301: Handling multiple subkeys on two SmartCards.

Helo and forgive me for the ignorance, Iam a new.
I subscribed to this topic because I need a fix like that, I have 2 yubikeys with same subkeys...
Now how is possible to install from master; It's about a debian based distro. Also, when this will be pushed for updates via apt-get;
Thank you.

May 16 2019, 9:51 AM · Restricted Project, gnupg, scd, Bug Report
aheinecke added a parent task for T4509: Release GnuPG 2.2.16: T4389: Gpg4win 3.1.8.
May 16 2019, 9:51 AM · Release Info, gnupg (gpg22)
aheinecke added a subtask for T4389: Gpg4win 3.1.8: T4509: Release GnuPG 2.2.16.
May 16 2019, 9:50 AM · gpg4win, Release Info
aheinecke removed a subtask for T4509: Release GnuPG 2.2.16: T4389: Gpg4win 3.1.8.
May 16 2019, 9:50 AM · Release Info, gnupg (gpg22)
aheinecke removed a parent task for T4389: Gpg4win 3.1.8: T4509: Release GnuPG 2.2.16.
May 16 2019, 9:50 AM · gpg4win, Release Info
aheinecke added a subtask for T4509: Release GnuPG 2.2.16: T4389: Gpg4win 3.1.8.
May 16 2019, 9:50 AM · Release Info, gnupg (gpg22)
aheinecke added a parent task for T4389: Gpg4win 3.1.8: T4509: Release GnuPG 2.2.16.
May 16 2019, 9:50 AM · gpg4win, Release Info
aheinecke added a parent task for T4509: Release GnuPG 2.2.16: T4505: SM, W32: GPGSM hangs up the GnuPG System.
May 16 2019, 9:50 AM · Release Info, gnupg (gpg22)
aheinecke added a subtask for T4505: SM, W32: GPGSM hangs up the GnuPG System: T4509: Release GnuPG 2.2.16.
May 16 2019, 9:50 AM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
aheinecke closed T4505: SM, W32: GPGSM hangs up the GnuPG System as Resolved.

I imported 39 certificate files at once with Kleopatra with about 700 certificates and it worked. Took a long time though so It would be nice if Kleopatra would show a progess indicator or some indication that the import is running. But this is a different issue.

May 16 2019, 9:49 AM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
gniibe merged task T2898: Option to ignore card serial number (to be able to use backup tokens containing same subkeys) into T4301: Handling multiple subkeys on two SmartCards.
May 16 2019, 9:26 AM · gnupg, Feature Request
gniibe merged T2898: Option to ignore card serial number (to be able to use backup tokens containing same subkeys) into T4301: Handling multiple subkeys on two SmartCards.
May 16 2019, 9:26 AM · Restricted Project, gnupg, scd, Bug Report
gniibe changed the status of T2898: Option to ignore card serial number (to be able to use backup tokens containing same subkeys) from Open to Testing.

Feature supported in master.

May 16 2019, 9:26 AM · gnupg, Feature Request
gniibe changed the status of T2898: Option to ignore card serial number (to be able to use backup tokens containing same subkeys), a subtask of T2291: Smartcard interaction improvement (was: Shadowed private key design (for smartcard)), from Open to Testing.
May 16 2019, 9:26 AM · Restricted Project, Feature Request, gnupg
gniibe edited projects for T4301: Handling multiple subkeys on two SmartCards, added: scd, gnupg; removed Info Needed.
May 16 2019, 9:22 AM · Restricted Project, gnupg, scd, Bug Report
gniibe abandoned D451: agent: Fix S2K calibration..
May 16 2019, 9:20 AM
gniibe commandeered D451: agent: Fix S2K calibration..

The change is adopted. To close this patch, I take over.

May 16 2019, 9:19 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA867182bb508a: Port some deprecated methods (authored by Laurent Montel <montel@kde.org>).
Port some deprecated methods
May 16 2019, 9:01 AM
werner committed rG79c99921e359: scd: Remove unused cruft from GnuPG 1.x (authored by werner).
scd: Remove unused cruft from GnuPG 1.x
May 16 2019, 8:25 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA50a029c55ded: Port QCombobox deprecated method (authored by Laurent Montel <montel@kde.org>).
Port QCombobox deprecated method
May 16 2019, 8:22 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA94099a2747eb: Port deprecated method (authored by Laurent Montel <montel@kde.org>).
Port deprecated method
May 16 2019, 8:17 AM
gniibe committed rGdc35b25195e5: agent,scd: Scan and load all public keys for availability. (authored by gniibe).
agent,scd: Scan and load all public keys for availability.
May 16 2019, 3:11 AM
gniibe changed the status of T4301: Handling multiple subkeys on two SmartCards from Open to Testing.
May 16 2019, 1:58 AM · Restricted Project, gnupg, scd, Bug Report

May 15 2019

catenacyber accepted rG1cd2aca03b88: build: Update m4/iconv.m4..

Great :-)
This was a change (fixing file descriptor leaks in iconv.m4) that I needed to do for building fuzzing
https://github.com/google/oss-fuzz/blob/master/projects/gnupg/fuzzgnupg.diff#L178

May 15 2019, 5:40 PM
Blubberbub added a comment to T4456: gpgme repeatedly segfaults claws-mail after update to 1.13.0.

I patched version 1.13.0 with that commit and installed the patched version on Monday. It appears to have fixed the problem.

May 15 2019, 4:19 PM · gpgme (gpgme 1.23.x), Bug Report
JW-D created T4517: de-mail and GPG with Smart Card no decryption.
May 15 2019, 4:18 PM · Bug Report, gpg4win
aheinecke added a comment to T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).

Or a better tl;dr; When you send mails without "inline" option everything is fine and standardized. The problem is that the old version of GpgOL that your college uses is too stupid to handle this ;-)

May 15 2019, 2:40 PM · Feature Request, gpg4win, gpgol
aheinecke added a comment to T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).

Yes your colleague should or basically needs to upgrade. 2.2.3 is very outdated. There are security issues that were fixed by then etc.

May 15 2019, 2:38 PM · Feature Request, gpg4win, gpgol
AlexD added a comment to T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).

Hi,

What client does your colleague use so that you have to use PGP/Inline?

That format where the attachment is it's own PGP Encrypted file is very problematic. You basically have mutliple signature and encryption states. An attacker can easily remove or add attachments to the message. The attachment name is leaked. etc. Also see: https://wiki.gnupg.org/PgpPartitioned

Our opinion is that if you really _have_ to use PGP/Inline that you must do so manually using Kleopatra's notepad and Encrypted files.

I am a bit unsure if I just close this as "Wontfix" or move it to Wishlist. I think for now I go with Wishlist but do not expect that feature soon. At least until maybe some really important use case comes up.

Anyway, thanks for your feedback. It is always valuable to know what users would like to have.

Best Regards,
Andre

May 15 2019, 10:26 AM · Feature Request, gpg4win, gpgol
gniibe added a comment to T4301: Handling multiple subkeys on two SmartCards.

It's complicated to have a good solution, because we need to change assumption (serial number identifies keys).

May 15 2019, 10:20 AM · Restricted Project, gnupg, scd, Bug Report
gniibe committed rG1091f22511e1: agent: Support scdaemon operation using KEYGRIP. (authored by gniibe).
agent: Support scdaemon operation using KEYGRIP.
May 15 2019, 10:15 AM
gniibe committed rG01730529f208: scd: Don't put newline at the end of status. (authored by gniibe).
scd: Don't put newline at the end of status.
May 15 2019, 10:15 AM
werner closed T3972: 100% CPU usage endles loop of gpg --list-keys as Resolved.
May 15 2019, 9:41 AM · gnupg (gpg22)
werner edited projects for T4436: gpgsm refuses to encrypt with failure to check CRL, added: gnupg; removed gnupg (gpg22), Bug Report.

Will give you more detailed info about your certificate. For even more details use --dump-chain instead of --list-chain.

May 15 2019, 9:39 AM · gnupg, S/MIME
werner added a parent task for T4334: gpg "showphoto" not creating temp file on Windows 10: T4509: Release GnuPG 2.2.16.
May 15 2019, 9:25 AM · gpg4win, Windows, gnupg (gpg22), Bug Report
werner added a subtask for T4509: Release GnuPG 2.2.16: T4334: gpg "showphoto" not creating temp file on Windows 10.
May 15 2019, 9:25 AM · Release Info, gnupg (gpg22)
werner added a parent task for T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad: T4509: Release GnuPG 2.2.16.
May 15 2019, 9:24 AM · gnupg (gpg22)
werner added a subtask for T4509: Release GnuPG 2.2.16: T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad.
May 15 2019, 9:24 AM · Release Info, gnupg (gpg22)
werner merged T4248: gpg-agent: Rare unresponsiveness after importing a secret S/MIME cert on Windows into T4505: SM, W32: GPGSM hangs up the GnuPG System.
May 15 2019, 9:22 AM · Restricted Project, gpgol, S/MIME, gpg4win, Windows
werner merged task T4248: gpg-agent: Rare unresponsiveness after importing a secret S/MIME cert on Windows into T4505: SM, W32: GPGSM hangs up the GnuPG System.
May 15 2019, 9:22 AM · S/MIME, gnupg (gpg22), gpgagent, gpg4win
werner closed T4466: Clean up --keyserver documentation in gpg(1) as Resolved.

Thanks

May 15 2019, 9:20 AM · Keyserver, gnupg (gpg22), dirmngr, Documentation
werner committed rG0d669a360c6e: doc: Do not mention gpg's deprecated --keyserver option. (authored by werner).
doc: Do not mention gpg's deprecated --keyserver option.
May 15 2019, 9:20 AM
werner committed rG42adb56e660a: doc: Do not mention gpg's deprecated --keyserver option. (authored by werner).
doc: Do not mention gpg's deprecated --keyserver option.
May 15 2019, 9:19 AM
werner claimed T4466: Clean up --keyserver documentation in gpg(1).
May 15 2019, 9:06 AM · Keyserver, gnupg (gpg22), dirmngr, Documentation
werner closed T4490: --export-secret-keys fails with unusually-created secret key as Resolved.

Applied to master and 2.2. Thanks.

May 15 2019, 9:04 AM · ssh, gnupg (gpg22)
werner committed rG9c704d9d4633: gpg: enable OpenPGP export of cleartext keys with comments (authored by dkg).
gpg: enable OpenPGP export of cleartext keys with comments
May 15 2019, 9:03 AM
werner committed rG392e59a3d487: gpg: enable OpenPGP export of cleartext keys with comments (authored by dkg).
gpg: enable OpenPGP export of cleartext keys with comments
May 15 2019, 9:03 AM
werner closed T4508: gnupg1: digest-preference not honoured, a subtask of T4509: Release GnuPG 2.2.16, as Resolved.
May 15 2019, 8:55 AM · Release Info, gnupg (gpg22)
werner closed T4508: gnupg1: digest-preference not honoured as Resolved.
May 15 2019, 8:55 AM · gnupg (gpg22), Bug Report
werner closed T4496: gpgconf --launch ignores --homedir arguments as Resolved.

Right, that was missing. Fixed for master and 2.2. Noet that for kill and reload we added this already in 2016.

May 15 2019, 8:54 AM · Bug Report, gnupg (gpg22)
werner committed rG31e26037bd72: gpgconf: Support --homedir for --launch. (authored by werner).
gpgconf: Support --homedir for --launch.
May 15 2019, 8:53 AM
werner committed rGa4be077abdbf: gpgconf: Support --homedir for --launch. (authored by werner).
gpgconf: Support --homedir for --launch.
May 15 2019, 8:53 AM
werner committed rG6e041b7b356c: sm: Add a couple of debug calls to the keydb module. (authored by werner).
sm: Add a couple of debug calls to the keydb module.
May 15 2019, 8:53 AM
gniibe committed rG62c29af63203: scd: Fix return value for KEYINFO command. (authored by gniibe).
scd: Fix return value for KEYINFO command.
May 15 2019, 8:46 AM
aheinecke lowered the priority of T4515: GpgOL 2.3.3 - Attachment Problem (Encryption) from High to Wishlist.

What client does your colleague use so that you have to use PGP/Inline?

May 15 2019, 8:33 AM · Feature Request, gpg4win, gpgol
werner triaged T4497: gpgconf should report clearer errors when it knows that a given daemon's config file is bad as Normal priority.
May 15 2019, 8:32 AM · gnupg (gpg22)
werner raised a concern with rC0df498e81fd3: use https instead of cleartext http where possible.

No, that is excessive. If the license blurb will ever be change this can be done but not just because of changing a single letter.

May 15 2019, 8:09 AM
werner added a comment to rC0df498e81fd3: use https instead of cleartext http where possible.

Sorry, I will revert this.

May 15 2019, 8:04 AM
werner added a comment to T4506: OpenPGP Key Certification Forgeries.

Attacks always get better and thus mitigation based on uncommon jpeg UATs would help only for a short time.
Maybe having a SHA-1 warning in 2.2 is also needed.

May 15 2019, 8:02 AM · gnupg (gpg22)
gniibe committed rPTH575573b5b63e: Limit exposing rwlock API on GNU/Linux. (authored by gniibe).
Limit exposing rwlock API on GNU/Linux.
May 15 2019, 7:20 AM
gniibe added a comment to T4506: OpenPGP Key Certification Forgeries.

Sorry, I have read the short paper wrongly. I misunderstood as if a forged key could be made using existing key.

May 15 2019, 4:45 AM · gnupg (gpg22)
gniibe changed the status of T4491: Compile error in nPth's t-fork.c on Solaris 11.3 i86pc from Open to Testing.

While I think that building with GCC 4 on Solaris 11/12 is minor issue, requirement of newer POSIX API (on GNU/Linux) would be a bit serious issue.
I pushed my change to fix this.

May 15 2019, 3:12 AM · npth, Bug Report

May 14 2019

dkg committed rC0df498e81fd3: use https instead of cleartext http where possible (authored by dkg).
use https instead of cleartext http where possible
May 14 2019, 10:43 PM
dkg added a comment to T4516: use https: links internally where possible instead of http:// in libgcrypt source.

(hm, i'm pushing apparently successfully to playfair.gnupg.org:/git/libgcrypt.git but it is not showing up here. if you want to fetch this patch, you can also find it on the http-to-https branch at https://gitlab.com/dkg/libgcrypt.git

May 14 2019, 10:35 PM · libgcrypt
dkg created T4516: use https: links internally where possible instead of http:// in libgcrypt source.
May 14 2019, 10:30 PM · libgcrypt
werner added a comment to T4499: Asan finding in libgcrypt.

I would prefer not to fix that. I did some experiments on replacing all the runtime parsed ECC constants by static data. Adding the other constants will then be simple.

May 14 2019, 8:19 PM · libgcrypt
werner committed rG49b236af0ecb: kbx: Fix deadlock in gpgsm on Windows due to a sharing violation. (authored by werner).
kbx: Fix deadlock in gpgsm on Windows due to a sharing violation.
May 14 2019, 7:07 PM
jukivili added a comment to T4499: Asan finding in libgcrypt.

I've prepared patch for statically defining mpiutil contants, but I can leave it out and not push to master.

May 14 2019, 6:38 PM · libgcrypt
werner committed rG22e274f839f9: sm: Change keydb code to use the keybox locking. (authored by werner).
sm: Change keydb code to use the keybox locking.
May 14 2019, 4:52 PM
werner raised the priority of T4490: --export-secret-keys fails with unusually-created secret key from Normal to High.
May 14 2019, 4:39 PM · ssh, gnupg (gpg22)
dkg added a comment to T4511: dirmngr error logs claim that HTTP GET requests are percent-escaped, but they are not.

I think you are saying that dirmngr receives the query term as escaped data in the assuan connection from the dirmngr client (typically, gpg, which itself decides how to percent-escape what it feeds into libassuan).

May 14 2019, 4:10 PM · Bug Report, dirmngr
sdaoden added a comment to T4508: gnupg1: digest-preference not honoured.

Oh, ah. Ok. I do not read c't no more since about 2005. They are busy people and lead into the right direction.

May 14 2019, 3:29 PM · gnupg (gpg22), Bug Report
Laurent Montel <montel@kde.org> committed rKLEOPATRAc27a1e35c8ee: GIT_SILENT: time to update version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: time to update version
May 14 2019, 1:37 PM
Laurent Montel <montel@kde.org> committed rLIBKLEO1789b39009ab: GIT_SILENT: time to update version (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: time to update version
May 14 2019, 1:20 PM
AlexD added a project to T4515: GpgOL 2.3.3 - Attachment Problem (Encryption): gnupg (gpg23).
May 14 2019, 12:42 PM · Feature Request, gpg4win, gpgol
AlexD changed the visibility for T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).
May 14 2019, 12:26 PM · Feature Request, gpg4win, gpgol
AlexD updated the task description for T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).
May 14 2019, 12:23 PM · Feature Request, gpg4win, gpgol
AlexD renamed T4515: GpgOL 2.3.3 - Attachment Problem (Encryption) from GpgOL 2.3.3 - Attachmet Problem (Encryption) to GpgOL 2.3.3 - Attachment Problem (Encryption).
May 14 2019, 12:22 PM · Feature Request, gpg4win, gpgol
AlexD changed the visibility for T4515: GpgOL 2.3.3 - Attachment Problem (Encryption).
May 14 2019, 12:21 PM · Feature Request, gpg4win, gpgol
werner renamed T4500: Option --use-embedded-filename does not work as expect from GnuPG Producing a Warning in Error(?) to Option --use-embedded-filename does not work as expect.
May 14 2019, 11:57 AM · gnupg (gpg22), Bug Report
werner triaged T4500: Option --use-embedded-filename does not work as expect as Normal priority.

There is actually a problem with --use-embedded-filename. Given that the option his highly dangerous to use we have not tested this for ages. We will see what you we can about it.

May 14 2019, 11:57 AM · gnupg (gpg22), Bug Report
aheinecke added a comment to T4505: SM, W32: GPGSM hangs up the GnuPG System.

The last lines that the process currently holding wrote in the log:

May 14 2019, 11:30 AM · Restricted Project, gpgol, S/MIME, gpg4win, Windows