Page MenuHome GnuPG
Feed All Stories

Jan 7 2021

werner added a comment to T5218: keytocard does not remove secret key as documented.

The listing shows that the private keys are stored on a card ("sec>", "ssb>"). Why do you think you can still export more than a stub key? If I export a test key (just the primary key in this case) and run "gpg --show-keys" on the exported file I get the expected "sec>" marker. Looking with --list-packets at it we get:

Jan 7 2021, 6:30 PM · Windows, gnupg (gpg22)
Chris91 added a comment to T5218: keytocard does not remove secret key as documented.

The exact commands given and the output. Adding -v is always helpful.

Jan 7 2021, 6:04 PM · Windows, gnupg (gpg22)
Chris91 added a comment to T5218: keytocard does not remove secret key as documented.

Hi, I'm the user that reported this bug.

Jan 7 2021, 6:03 PM · Windows, gnupg (gpg22)
werner moved T4873: Enable AES GCM in FIPS mode from For 1.9 to FIPS on the libgcrypt board.
Jan 7 2021, 5:59 PM · FIPS, libgcrypt, Feature Request
aheinecke committed rKLEOPATRA6c003a0b714c: Bump Kleopatra version (authored by aheinecke).
Bump Kleopatra version
Jan 7 2021, 4:25 PM
aheinecke committed rWb3b32a63160f: Update GpgOL to 2.4.9 (authored by aheinecke).
Update GpgOL to 2.4.9
Jan 7 2021, 4:16 PM
aheinecke committed rW4aadad9b1763: Update scute and kde-l10n (authored by aheinecke).
Update scute and kde-l10n
Jan 7 2021, 4:16 PM
ikloecker added a comment to T5219: scd: Generating CSR for SigG NetKey card key fails.

do_sign() calls find_fid_by_keyref() which does a switch_application(). So, I think the SigG application should already be active. But, yes, please have a look at it.

Jan 7 2021, 4:11 PM · gnupg24, eIDAS, gnupg (gpg23), scd
jgentil added a comment to T5084: Using GPGWin 3.1.13, Putty fails to load the private key from a YubiKey.

I'm also getting this same error with GPG4Win 3.1.14.

Jan 7 2021, 4:10 PM · gnupg, ssh, Bug Report, gpg4win
werner committed rD434ee46ce41c: swdb: Release Scute 1.7.0 (authored by werner).
swdb: Release Scute 1.7.0
Jan 7 2021, 4:09 PM
werner closed T5224: Release Scute 1.7.0 as Resolved.
Jan 7 2021, 4:00 PM · Release Info, scute
werner updated the task description for T5224: Release Scute 1.7.0.
Jan 7 2021, 4:00 PM · Release Info, scute
werner committed rSebfb69d8d7b4: Post release updates (authored by werner).
Post release updates
Jan 7 2021, 3:56 PM
werner committed rS2488e12aa478: Release 1.7.0 (authored by werner).
Release 1.7.0
Jan 7 2021, 3:56 PM
werner committed rS9961bd1e094f: Minor fixes for a release (authored by werner).
Minor fixes for a release
Jan 7 2021, 3:56 PM
aheinecke committed rO7ee52ab041ab: po: Auto update po files (authored by aheinecke).
po: Auto update po files
Jan 7 2021, 3:39 PM
aheinecke committed rO6f1990002efa: po: Update german translation (authored by aheinecke).
po: Update german translation
Jan 7 2021, 3:39 PM
aheinecke committed rO262dbfd2ccf5: Update news for gpgol-2.4.9 (authored by aheinecke).
Update news for gpgol-2.4.9
Jan 7 2021, 3:39 PM
aheinecke committed rOda532296d6fb: Do not add a full keylist if no key is selected (authored by aheinecke).
Do not add a full keylist if no key is selected
Jan 7 2021, 3:39 PM
aheinecke committed rOfa5fac22228a: Minor fix to a localized string (authored by aheinecke).
Minor fix to a localized string
Jan 7 2021, 3:39 PM
werner created T5224: Release Scute 1.7.0.
Jan 7 2021, 3:20 PM · Release Info, scute
werner added a comment to T5221: gpgconf: auto-key-import and include-key-block dont have proper values.

Description and translation domain were swapped in 2.2.

Jan 7 2021, 1:28 PM · gnupg
werner committed rGff30fcd3dc78: gpgconf: Fix description of two new options. (authored by werner).
gpgconf: Fix description of two new options.
Jan 7 2021, 1:24 PM
werner added a comment to T5218: keytocard does not remove secret key as documented.

On Thu, 7 Jan 2021 09:56, bernhard (Bernhard Reiter) said:

Jan 7 2021, 1:20 PM · Windows, gnupg (gpg22)
aheinecke created T5221: gpgconf: auto-key-import and include-key-block dont have proper values.
Jan 7 2021, 12:14 PM · gnupg
werner added a comment to T5219: scd: Generating CSR for SigG NetKey card key fails.

We need to switch to the SigG application. Shall I look at it?

Jan 7 2021, 12:04 PM · gnupg24, eIDAS, gnupg (gpg23), scd
werner added a member for libgcrypt: werner.
Jan 7 2021, 11:44 AM
werner moved T4951: Support point compression in Libgcrypt from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:42 AM · Feature Request, libgcrypt
werner moved T5195: Incorrect HWCAP2 check for AArch32 from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:42 AM · libgcrypt, backport, Bug Report
werner added a comment to T5195: Incorrect HWCAP2 check for AArch32.

Do we need to backport to 1.8?

Jan 7 2021, 11:42 AM · libgcrypt, backport, Bug Report
werner moved T5182: libgcrypt self tests for FIPS 140 from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:41 AM · Restricted Project, libgcrypt
werner moved T4293: Add dedicated X25519 function to Libcgrypt from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:40 AM · Restricted Project, libgcrypt
werner moved T4873: Enable AES GCM in FIPS mode from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:40 AM · FIPS, libgcrypt, Feature Request
werner moved T4294: Release Libgcrypt 1.9.0 from Backlog to For 1.9 on the libgcrypt board.
Jan 7 2021, 11:40 AM · Release Info, libgcrypt
ikloecker closed T5220: Kleopatra: Setting the initial SigG PIN fails as Resolved.
Jan 7 2021, 11:33 AM · kleopatra
werner added a comment to T4964: ecc: Discrepancy of handling MPI for the interpretation of signed and unsigned.

Do we really need this for 1.9?

Jan 7 2021, 11:33 AM · libgcrypt
werner claimed T4926: Add API to map a curve name to its canonical OID..
Jan 7 2021, 11:30 AM · Feature Request, libgcrypt
werner added a comment to T4951: Support point compression in Libgcrypt.

What is the state of this bug? Reading is implemented - do we really need writing (maybe to support certain smartcards)?

Jan 7 2021, 11:29 AM · Feature Request, libgcrypt
ikloecker committed rKLEOPATRA62420a1fba1f: Show the nicer display serial number for NetKey cards (authored by ikloecker).
Show the nicer display serial number for NetKey cards
Jan 7 2021, 11:28 AM
ikloecker committed rKLEOPATRA2b5f5b4b88e4: Use ChangePinCommand also for setting the initial NetKey PINs (authored by ikloecker).
Use ChangePinCommand also for setting the initial NetKey PINs
Jan 7 2021, 11:28 AM
ikloecker committed rKLEOPATRAf5d3e32497de: Fix setting initial SigG PIN (authored by ikloecker).
Fix setting initial SigG PIN
Jan 7 2021, 11:28 AM
werner closed T4914: libgcrypt ECC regression for the use case in GNUNET as Resolved.
Jan 7 2021, 11:25 AM · Restricted Project, libgcrypt
werner edited projects for T4822: mlock requires privilege, added: FAQ; removed Bug Report.

It is possible to disable the mlock thingy and if that is not wanted the application should be modified to be suid(root) during Libgcrypt initialization - this is actually how we handle this in GnuPG. Or maybe I don't understand the bug described here. It seems to be more of a support question.

Jan 7 2021, 11:22 AM · FAQ, Solaris, libgcrypt
werner closed T4499: Asan finding in libgcrypt as Wontfix.

For security and auditing reasons a Libgcrypt SO may not be "unloaded".

Jan 7 2021, 11:16 AM · libgcrypt
werner added a subtask for T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297): T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner added a parent task for T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452): T4486: Add AEAD mode AES-SIV to libgcrypt (RFC 5297).
Jan 7 2021, 11:04 AM · Feature Request, libgcrypt
werner closed T4304: gcry_control (GCRYCTL_INIT_SECMEM, 16384, 0) failed: General error as Wontfix.
Jan 7 2021, 11:02 AM · Legacy OS, Fedora, libgcrypt, Bug Report
werner set the color for Legacy OS to Pink.
Jan 7 2021, 11:02 AM
werner changed the status of T4293: Add dedicated X25519 function to Libcgrypt from Testing to Open.

gcry_ecc_get_algo_keylen has been added with commit a658c9ccc2c741f40b0b5cdbcd184cfb9a841d17 but documentation is missing.

Jan 7 2021, 10:58 AM · Restricted Project, libgcrypt
bernhard added a comment to T5218: keytocard does not remove secret key as documented.

The user reported to

Jan 7 2021, 10:56 AM · Windows, gnupg (gpg22)
werner closed T4274: Fail selftests when checksum file is missing in FIPS mode only as Resolved.
Jan 7 2021, 10:52 AM · Restricted Project, libgcrypt, Bug Report
bernhard updated the task description for T5218: keytocard does not remove secret key as documented.
Jan 7 2021, 10:52 AM · Windows, gnupg (gpg22)
ikloecker created T5220: Kleopatra: Setting the initial SigG PIN fails.
Jan 7 2021, 10:45 AM · kleopatra
ikloecker added a comment to T5129: Kleopatra: Generate S/MIME CSR for NetKey card key.

Generating a CSR for the standard NetKey card signing key works now, but generating a CSR for the SigG NetKey card key fails (T5219).

Jan 7 2021, 10:37 AM · kleopatra
ikloecker added a parent task for T5219: scd: Generating CSR for SigG NetKey card key fails: T5129: Kleopatra: Generate S/MIME CSR for NetKey card key.
Jan 7 2021, 10:35 AM · gnupg24, eIDAS, gnupg (gpg23), scd
ikloecker added a subtask for T5129: Kleopatra: Generate S/MIME CSR for NetKey card key: T5219: scd: Generating CSR for SigG NetKey card key fails.
Jan 7 2021, 10:35 AM · kleopatra
ikloecker created T5219: scd: Generating CSR for SigG NetKey card key fails.
Jan 7 2021, 10:35 AM · gnupg24, eIDAS, gnupg (gpg23), scd
werner added a comment to T5218: keytocard does not remove secret key as documented.

Please describe exactly what you did so that we can replicate this.

Jan 7 2021, 10:04 AM · Windows, gnupg (gpg22)
werner committed rCb66dba37b4ee: doc: Add missing OIDs to the list of supported curves (authored by werner).
doc: Add missing OIDs to the list of supported curves
Jan 7 2021, 9:55 AM
werner closed T3220: Missing curve documentation as Resolved.

Thanks. I added the OIDs and the missing curves. To go into 1.9

Jan 7 2021, 9:54 AM · patch, libgcrypt, Bug Report
bernhard created T5218: keytocard does not remove secret key as documented.
Jan 7 2021, 9:54 AM · Windows, gnupg (gpg22)
gniibe committed rC9d9cebb61240: Add CMAC selftest. (authored by gniibe).
Add CMAC selftest.
Jan 7 2021, 9:26 AM
aheinecke committed rW75e2cb24b091: Use KF5_HOST_TOOLING to avoid patching KConfig (authored by aheinecke).
Use KF5_HOST_TOOLING to avoid patching KConfig
Jan 7 2021, 9:23 AM
werner lowered the priority of T1303: Please support GCRYSEXP_FMT_BASE64 from Normal to Wishlist.
Jan 7 2021, 9:14 AM · Feature Request, libgcrypt
gniibe added a comment to T5189: update Chinese translation.

D520 is accepted by me.
If you will have another fixes, please go ahead.
Or else, I'll commit the change to master of GnuPG.

Jan 7 2021, 8:21 AM · gnupg
gniibe accepted D520: gnupg po: Fix Simplified Chinese Translation.
Jan 7 2021, 8:19 AM

Jan 6 2021

rupor-github added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

I wrote https://github.com/rupor-github/win-gpg-agent to simplify usage on Windows until this issue is resolved - it handles various edge cases on Windows.

Jan 6 2021, 7:25 PM · Not A Bug, workaround, gnupg24, Windows, ssh
cbiedl added a comment to T5215: gnugp1: Fix build errors with gcc-10.

Okay. Now since configure.ac is already touching CFLAGS, it seemed like a good place to add that additional option here. All this is guarded by a test for GCC, and since clang mimics that behaviour, it works for them as well.

Jan 6 2021, 5:42 PM · gnupg (gpg14), patch, Bug Report
aheinecke committed rWbbf5ae28bdb8: Patch kconfig to allow overriding the executable (authored by aheinecke).
Patch kconfig to allow overriding the executable
Jan 6 2021, 4:25 PM
aheinecke committed rW00eb34022bd8: Update KDE Frameworks to 5.77 (authored by aheinecke).
Update KDE Frameworks to 5.77
Jan 6 2021, 4:25 PM
aheinecke committed rW924790caade2: Fix qmake in toolchain file (authored by aheinecke).
Fix qmake in toolchain file
Jan 6 2021, 4:25 PM
werner added a comment to T5215: gnugp1: Fix build errors with gcc-10.

Take care: gpg is also used on platforms with proprietary compilers which don't support -f options. Thus you need to limit this to gcc.

Jan 6 2021, 4:03 PM · gnupg (gpg14), patch, Bug Report
cbiedl added a comment to T5215: gnugp1: Fix build errors with gcc-10.

After some more checking: LLVM-11 introduced the same behaviour in that regard, but appearently not a pragma/attribute to override this: https://releases.llvm.org/11.0.0/tools/clang/docs/ReleaseNotes.html

Jan 6 2021, 3:55 PM · gnupg (gpg14), patch, Bug Report
ikloecker committed rG7eef40cc1143: I meant "SHA-2 digests" in the previous commit. (authored by ikloecker).
I meant "SHA-2 digests" in the previous commit.
Jan 6 2021, 3:06 PM
ikloecker closed T5184: scd: Generating CSR for NetKey card key fails as Resolved.
Jan 6 2021, 12:22 PM · scd
ikloecker closed T5184: scd: Generating CSR for NetKey card key fails, a subtask of T5129: Kleopatra: Generate S/MIME CSR for NetKey card key, as Resolved.
Jan 6 2021, 12:22 PM · kleopatra
ikloecker committed rG8fe976d5b9a0: scd:nks: Add support for signing plain SHA-3 digests. (authored by ikloecker).
scd:nks: Add support for signing plain SHA-3 digests.
Jan 6 2021, 12:21 PM
aheinecke committed rWadbac241d3d2: Remove obsolete patch for libgpg-error (authored by aheinecke).
Remove obsolete patch for libgpg-error
Jan 6 2021, 12:03 PM
aheinecke added a comment to rKLEOPATRA4e8afe8036ac: Handle tag preferences with kconfig compiler.

This reminds me that I should check if kconfig_compiler nowadays supports cross compiling or add that. Back when I started cross compiling kleopatra in 2015 I was lazy and patched in the generated kconfig files. I never really saw the advantage of them but yeah it's more KDEish to use them.

Jan 6 2021, 10:49 AM
aheinecke changed the status of T4184: Outlook 2013 Appointments vanish when send as a E-Mail from Open to Testing.

This works now with 0c1bd9076958e584820fadf997ca7d8a248b6888 but needs more testing before this can be relased. It will probably be part of a Gpg4win-4 beta.

Jan 6 2021, 10:29 AM · gpgol, Bug Report, gpg4win
aheinecke committed rOceaf9a6c09ba: Fix draft encryption for async crypt in OOM (authored by aheinecke).
Fix draft encryption for async crypt in OOM
Jan 6 2021, 9:58 AM
bobwxc updated the diff for D520: gnupg po: Fix Simplified Chinese Translation.
Jan 6 2021, 8:54 AM
gniibe added inline comments to D520: gnupg po: Fix Simplified Chinese Translation.
Jan 6 2021, 2:40 AM

Jan 5 2021

ikloecker committed rKLEOPATRA35f24bc67d5d: Fix build with gpgme < 1.15.0 (authored by ikloecker).
Fix build with gpgme < 1.15.0
Jan 5 2021, 6:47 PM
ikloecker committed rKLEOPATRA66efcb74b419: Fix build with gpgme < 1.14.1 (authored by ikloecker).
Fix build with gpgme < 1.14.1
Jan 5 2021, 6:36 PM
ikloecker committed rKLEOPATRA2fe6ffd20762: Make filtering by tags (and display of tags) work in key selection (authored by ikloecker).
Make filtering by tags (and display of tags) work in key selection
Jan 5 2021, 6:02 PM
ikloecker committed rKLEOPATRA021cd34fe098: Fix display of tags in key details for secret keys (authored by ikloecker).
Fix display of tags in key details for secret keys
Jan 5 2021, 6:02 PM
ikloecker committed rKLEOPATRA2c35da3ddbcf: Use domain term "tag[s]" instead of "remark[s]" as much as possible (authored by ikloecker).
Use domain term "tag[s]" instead of "remark[s]" as much as possible
Jan 5 2021, 6:02 PM
ikloecker committed rKLEOPATRA4e8afe8036ac: Handle tag preferences with kconfig compiler (authored by ikloecker).
Handle tag preferences with kconfig compiler
Jan 5 2021, 6:02 PM
ikloecker committed rKLEOPATRA4b6f8f4b5a01: Do not disable tag support if Tags column is disabled/not shown (authored by ikloecker).
Do not disable tag support if Tags column is disabled/not shown
Jan 5 2021, 6:02 PM
ikloecker closed T3580: GPGME: Keylist mode sigs combined with secret does not work (anymore?) as Resolved.
Jan 5 2021, 5:54 PM · gpgme
ikloecker committed rM5137d7fc214d: core: Make listing of signatures work if only secret keys are listed (authored by ikloecker).
core: Make listing of signatures work if only secret keys are listed
Jan 5 2021, 5:49 PM
ikloecker claimed T3580: GPGME: Keylist mode sigs combined with secret does not work (anymore?).

Taking since I ran into this problem while working on T5174. In Kleopatra, if one opens the certificate details of one's own keys (i.e. secret key is available), then the tags vanish from the key list.

Jan 5 2021, 5:08 PM · gpgme
werner added a comment to T3505: Port GPGME's Python bindings to Windows.

The C++, CL, Javascript and QT Bindings are all written by hand.

Jan 5 2021, 4:06 PM · Feature Request, gpgme, Python
aheinecke committed rO28b05072198e: Handle protected-headers also on multipart parts (authored by aheinecke).
Handle protected-headers also on multipart parts
Jan 5 2021, 3:51 PM
aheinecke committed rOe81efc2bffa6: Change crypto state names to be descriptive (authored by aheinecke).
Change crypto state names to be descriptive
Jan 5 2021, 3:51 PM
aheinecke committed rO097606999554: Another statename change (authored by aheinecke).
Another statename change
Jan 5 2021, 3:51 PM
aheinecke committed rOd120e866e04e: Unify WantsSend states to CryptFinished (authored by aheinecke).
Unify WantsSend states to CryptFinished
Jan 5 2021, 3:51 PM
aheinecke committed rO93be368dc258: Fix broken encryptSignStart invocation. (authored by aheinecke).
Fix broken encryptSignStart invocation.
Jan 5 2021, 3:51 PM
aheinecke committed rOc67dda95eec6: Remove NeedsFirstAfterWrite state (authored by aheinecke).
Remove NeedsFirstAfterWrite state
Jan 5 2021, 3:51 PM