Page MenuHome GnuPG
Feed All Stories

Jun 21 2021

TRex58 added a comment to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.

Hi,
The site now shows: "NET::ERR_CERT_DATE_INVALID" and I have a limited access to the web page.
Thanks for you explanation. However, I now so few about gnupg, thus I'm not sure I cannot add test cases, probably not. I'll see later if we have to provide on AIX a behavior different than the one of RedHat. Meanwhile, about your last proposal, yes it would be very useful to detect the case, print a warning, and skip the test. That would be helpful. Moreover, if the test deals with smartcards, we do not have on AIX, thus this test is very probably not useful in our environment.

Jun 21 2021, 7:40 PM · gnupg, Fedora, libgcrypt, Bug Report
werner triaged T5503: Add APIs to sign (and encrypt?) with a specific subkey as Normal priority.
Jun 21 2021, 5:16 PM · gpgme, Feature Request
werner added a comment to T5491: Console output failure with no-unicode font: GnuPG 2.2.28 is not working with »encrypt-to« in gpg.conf without specifying another recipient..

Please run

Jun 21 2021, 5:16 PM · gnupg (gpg22), Windows, Bug Report
gahr created T5503: Add APIs to sign (and encrypt?) with a specific subkey.
Jun 21 2021, 5:09 PM · gpgme, Feature Request
werner added a comment to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.

The thing is that I added a test for a new function which uses standard curves of Libgcrypt. But here we are again at the RedHat mess: They support the NIST curves but they removed support for Brainpool curves. Both are very similiar curves just different parameters. Brainpool is just in Europe out of fear that the NIST curves are rigged by the the NSA. Now, why RedHat removed Brainpool is probably just a legal dept thing who didn't have a clue. The tin foil hats probably see a different reason.

Jun 21 2021, 5:00 PM · gnupg, Fedora, libgcrypt, Bug Report
TRex58 added a comment to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.
  • a patch change within scd/apdu.c dealing with a call of: pcsc_connect() since code has changed between the 2 versions: may this be the cause of the failure? (Edited: hummm this patch seems no more required. And I have the same failure without it).
Jun 21 2021, 4:40 PM · gnupg, Fedora, libgcrypt, Bug Report
TRex58 added a comment to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.

Hi Werner,

Jun 21 2021, 4:30 PM · gnupg, Fedora, libgcrypt, Bug Report
Alexander Lohnau <alexander.lohnau@gmx.de> committed rKLEOPATRA86365f336731: Install kleopatra_config_gnupgsystem in pim/kcms/kleopatra namespace (authored by Alexander Lohnau <alexander.lohnau@gmx.de>).
Install kleopatra_config_gnupgsystem in pim/kcms/kleopatra namespace
Jun 21 2021, 3:03 PM
werner added a comment to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.

Supported curves should be listed by

gpg --list-config --with-colons curve
Jun 21 2021, 2:47 PM · gnupg, Fedora, libgcrypt, Bug Report
werner added projects to T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1: libgcrypt, Fedora, gnupg.

I am not sure about Fedora, but RedHat used to remove ECC support from Libgcrypt; GnuPG requires these curves. As long as you don't use ECC you things will work despite of this failed test. The test is new to check and does not anticipate a broken Libgcrypt.

Jun 21 2021, 2:44 PM · gnupg, Fedora, libgcrypt, Bug Report
TRex58 created T5502: gnupg 2.2.28 : test t-sexputil fails on Fedora 33 and AIX 7.1.
Jun 21 2021, 2:29 PM · gnupg, Fedora, libgcrypt, Bug Report
werner triaged T5501: "Remove my account" does not anymore work as Normal priority.
Jun 21 2021, 1:50 PM · dev.gnupg.org
ikloecker moved T5336: Kleopatra: Add expiry for certifications in certify dialog from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jun 21 2021, 10:59 AM · kleopatra, Restricted Project
ikloecker changed the status of T5465: Kleopatra: Improve configuration of LDAP servers for X.509 from Open to Testing.
Jun 21 2021, 10:58 AM · Restricted Project, kleopatra
ikloecker moved T5465: Kleopatra: Improve configuration of LDAP servers for X.509 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jun 21 2021, 10:58 AM · Restricted Project, kleopatra
ikloecker created T5500: gpgme: Test t-idiomatic.py fails with Python 3.8.
Jun 21 2021, 10:54 AM · Python, gpgme, Bug Report
ikloecker committed rMab1d4ef58079: Update NEWS. (authored by ikloecker).
Update NEWS.
Jun 21 2021, 10:54 AM
werner updated the task description for T5225: Release GPGME 1.15.1.
Jun 21 2021, 10:29 AM · Release Info, gpgme
werner triaged T5499: Release GPGME 1.16.0 as Normal priority.
Jun 21 2021, 10:28 AM · Release Info, gpgme
werner updated the task description for T5482: Release GnuPG 2.2.28.
Jun 21 2021, 9:37 AM · Release Info, gnupg (gpg22)
werner triaged T5498: Release GnuPG 2.2.29 as Normal priority.
Jun 21 2021, 9:37 AM · Release Info, gnupg (gpg22)
werner added a comment to T5482: Release GnuPG 2.2.28.

Regression for keyserver search by mail address: T5497

Jun 21 2021, 9:35 AM · Release Info, gnupg (gpg22)
werner changed the status of T5497: v2.2.28 fails to locate-key from keyserver by email: Invalid user ID from Open to Testing.

Replicated and fixed. Thanks for the report.

Jun 21 2021, 9:33 AM · Bug Report
werner committed rGd5126efd895b: dirmngr: Fix regression in KS_GET for mail address pattern. (authored by werner).
dirmngr: Fix regression in KS_GET for mail address pattern.
Jun 21 2021, 9:32 AM
werner committed rGadf7bfba5ddc: dirmngr: Fix regression in KS_GET for mail address pattern. (authored by werner).
dirmngr: Fix regression in KS_GET for mail address pattern.
Jun 21 2021, 9:31 AM
Sanmilie added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

In fact, the trigger is not yubikey but the pcsc-shared flag... If the pcsc-shared flag is enabled, you do check for interference because you are in shared condition. It is not really a race condition because you can put the driver in transaction mode. It’s more a turn-by-turn games but you can lose the card context status between turn.
If you lock the patch only for yubikey I’m not able to test with my device. You can add my manufacturer ID in the test please.

Jun 21 2021, 8:51 AM · yubikey, Bug Report, scd
werner claimed T5497: v2.2.28 fails to locate-key from keyserver by email: Invalid user ID.
Jun 21 2021, 8:35 AM · Bug Report
gniibe added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

Thank you for your explanation.

Jun 21 2021, 6:16 AM · yubikey, Bug Report, scd
gniibe requested review of D534: scdaemon patch to support some situation with PCSC_SHARED (not all).
Jun 21 2021, 6:10 AM · yubikey, scd
gniibe committed rE220a427b4f99: build: Fix --disable-threads. (authored by gniibe).
build: Fix --disable-threads.
Jun 21 2021, 6:10 AM
gniibe claimed T5495: libgpg-error: build failure without threads.

Thank you for your report.
I pushed the fix.

Jun 21 2021, 5:20 AM · Bug Report
Sanmilie added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

It's not a device is a card. NXP P71 security chips on the card in the 250Kb Rom with GlobalPlateform 2.1.1 It is not possible for a card to change CCID by applet. Card depends of reader CCID. When the card is on NFC readers, the FIDO applet is accessible not when it is on contact readers. But, when I am in NFC FIDO share the CCID. For the user point of view having multiple card for each applet is a bad thing to devices for one user. User search presently for multipurpose devices. DOOR, Login, Email-crypt, ledger. Actually for app is not recommended to use a reader in exclusive mode. By designs the card is stateless and for memory management deselect applet free mem from other applet. Presently in the best case the card has 144-255 KB of eeprom and 2k or ram.

Jun 21 2021, 4:43 AM · yubikey, Bug Report, scd
gniibe added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

If your token/card is not Yubikey and when it is possible to improve your token/card implementation, I would suggest not follow what Yubikey does for multiple applications; No multiple applications, but each feature with independent access (card+CCID, another card+different CCID, FIDO+HID, ...).

Jun 21 2021, 2:08 AM · yubikey, Bug Report, scd

Jun 20 2021

paz created T5497: v2.2.28 fails to locate-key from keyserver by email: Invalid user ID.
Jun 20 2021, 7:33 PM · Bug Report
werner activated P5 bak.
Jun 20 2021, 6:16 PM · Feature Request
werner activated P7 X25519 the ugly way.
Jun 20 2021, 6:16 PM
werner activated P10 Slow dirmngr.
Jun 20 2021, 6:15 PM
werner activated P11 (An Untitled Masterwork).
Jun 20 2021, 6:15 PM
werner activated P13 (An Untitled Masterwork).
Jun 20 2021, 6:15 PM
werner restored Image Macro "ilovetrains".
Jun 20 2021, 6:14 PM
werner renamed Image Macro "ripfernmeldegeheimnis" from ripfernmeldege to ripfernmeldegeheimnis.
Jun 20 2021, 6:14 PM
werner restored Image Macro "ripfernmeldegeheimnis".
Jun 20 2021, 6:13 PM
werner restored Image Macro "dancewithme".
Jun 20 2021, 6:13 PM
Fred23 archived P5 bak.
Jun 20 2021, 6:02 PM · Feature Request
Fred23 archived P7 X25519 the ugly way.
Jun 20 2021, 6:01 PM
Fred23 archived P10 Slow dirmngr.
Jun 20 2021, 6:01 PM
Fred23 archived P11 (An Untitled Masterwork).
Jun 20 2021, 6:01 PM
Fred23 archived P13 (An Untitled Masterwork).
Jun 20 2021, 6:01 PM
Fred23 disabled Image Macro "ilovetrains".
Jun 20 2021, 5:48 PM
Fred23 renamed Image Macro "ripfernmeldegeheimnis" from ripfernmeldegeheimnis to ripfernmeldege.
Jun 20 2021, 5:46 PM
Fred23 disabled Image Macro "ripfernmeldegeheimnis".
Jun 20 2021, 5:46 PM
Fred23 disabled Image Macro "dancewithme".
Jun 20 2021, 5:43 PM
einar77 committed rKLEOPATRA81b62b78fb97: Remove unneeded parent from function call (authored by einar77).
Remove unneeded parent from function call
Jun 20 2021, 11:32 AM
Sanmilie added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

i'am not able to test... i can't build for win32. i have some trouble with my mingw32 installation and the miss match with library for build a functional version of gnupg for win32.
seem missing dll after make install folder. do you have instruction to setup dev environment for build win32 binary ? I use a ubuntu with minwg32. ntbtls seem missing ksba but libksba is already install verion 1.6.0 other project detect correctly ksba. it's seem is a little bit complicated juste for building scd project. a make it working correctly on windows environements.

Jun 20 2021, 11:09 AM · yubikey, Bug Report, scd
einar77 committed rKLEOPATRAe47545a386ff: Fix previous commit (copy/paste is bad) (authored by einar77).
Fix previous commit (copy/paste is bad)
Jun 20 2021, 10:42 AM
einar77 committed rKLEOPATRA5e9d402be380: Yet another place with deprecated API (authored by einar77).
Yet another place with deprecated API
Jun 20 2021, 10:36 AM
einar77 committed rKLEOPATRAc498da690d9b: Fix build with deprecated API disabled (authored by einar77).
Fix build with deprecated API disabled
Jun 20 2021, 10:28 AM

Jun 19 2021

Saturneric created T5496: [Problem Report] Add a new Cross-Platform Frontend Software for gnupg to the List.
Jun 19 2021, 10:19 PM · Info Needed, Not A Bug
ffontaine updated the task description for T5495: libgpg-error: build failure without threads.
Jun 19 2021, 8:33 PM · Bug Report
ffontaine created T5495: libgpg-error: build failure without threads.
Jun 19 2021, 8:32 PM · Bug Report
jukivili committed rC9c12226c31d4: mpi/ec: small optimization for ec_mulm_25519 (authored by jukivili).
mpi/ec: small optimization for ec_mulm_25519
Jun 19 2021, 3:33 PM
jukivili committed rC9722da5bfc4a: mpi/longlong.h: fix missing macro parameter parentheses (authored by jukivili).
mpi/longlong.h: fix missing macro parameter parentheses
Jun 19 2021, 3:33 PM
jukivili committed rCccfa9f2c1427: mpi/ec: small optimization for ec_mulm_448 (authored by jukivili).
mpi/ec: small optimization for ec_mulm_448
Jun 19 2021, 3:33 PM
jukivili committed rCa0871a1e817f: tests/t-mpi-point: add NIST curve multiplication test vectors (authored by jukivili).
tests/t-mpi-point: add NIST curve multiplication test vectors
Jun 19 2021, 3:33 PM
jukivili committed rC57cf83834bc0: tests/bench-slope: add ECC benchmarking (authored by jukivili).
tests/bench-slope: add ECC benchmarking
Jun 19 2021, 3:33 PM
jukivili committed rCb53abf7905e0: tests/benchmark: add benchmark for Ed448 (authored by jukivili).
tests/benchmark: add benchmark for Ed448
Jun 19 2021, 3:33 PM
Saturneric closed T5489: GpgME Built by mingw64 didn’t seem to correctly recognize the configuration information provided by gpgconf as Resolved.
Jun 19 2021, 2:49 PM · gpgme, Bug Report
Saturneric added a comment to T5489: GpgME Built by mingw64 didn’t seem to correctly recognize the configuration information provided by gpgconf .

The problem has been solved by me, but this and the problem are still very strange.

Jun 19 2021, 2:48 PM · gpgme, Bug Report
Sanmilie added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

Ok i have seen a problem with a double check here

Jun 19 2021, 7:26 AM · yubikey, Bug Report, scd

Jun 18 2021

werner triaged T5494: gpg-agent doesn't support security-key (sk) key types as Low priority.

ggp-agent has no support for U2F and it can't work with these key types. Given that Yubikeys also have proper keys (even eddsa) I doubt that we will implement support for ecdsa-sk OpenSSH feature any time soon,

Jun 18 2021, 11:31 PM · gnupg24, gnupg (gpg23), Feature Request, ssh
svenschwermer updated the task description for T5494: gpg-agent doesn't support security-key (sk) key types.
Jun 18 2021, 7:50 PM · gnupg24, gnupg (gpg23), Feature Request, ssh
svenschwermer created T5494: gpg-agent doesn't support security-key (sk) key types.
Jun 18 2021, 7:48 PM · gnupg24, gnupg (gpg23), Feature Request, ssh
werner committed rG029924a46e08: scd:p15: Add pre-check for ascii-numeric PINs. (authored by werner).
scd:p15: Add pre-check for ascii-numeric PINs.
Jun 18 2021, 6:07 PM
Sanmilie added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

Ok, I test this, this seem can be corrected 90% of all possible interference with another application on multi-applet smartcard in shared readers context. I left you the feel back when have tested… thank for the prompt response.

Jun 18 2021, 6:05 PM · yubikey, Bug Report, scd
werner committed rG7a8545c91b09: scd:p15: Handle cards with bad encoded path objects. (authored by werner).
scd:p15: Handle cards with bad encoded path objects.
Jun 18 2021, 5:46 PM
werner committed rG544ec7872aed: scd:p15: Add basic support for AET JCOP cards. (authored by werner).
scd:p15: Add basic support for AET JCOP cards.
Jun 18 2021, 5:46 PM
werner committed rG44f977d0e332: scd: Improve reading of binary records. (authored by werner).
scd: Improve reading of binary records.
Jun 18 2021, 5:46 PM
ikloecker committed rM5340bb7ccfa7: qt: Add missing } (authored by ikloecker).
qt: Add missing }
Jun 18 2021, 12:34 PM
gniibe added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

For the problem of external application switch, please test this:

diff --git a/scd/app-common.h b/scd/app-common.h
index dffe1200d..d6e6f4c0a 100644
--- a/scd/app-common.h
+++ b/scd/app-common.h
@@ -194,6 +194,8 @@ struct app_ctx_s {
                       void *pincb_arg);
     gpg_error_t (*with_keygrip) (app_t app, ctrl_t ctrl, int action,
                                  const char *keygrip_str, int capability);
+    gpg_error_t (*check_aid) (app_t app, ctrl_t ctrl,
+                              const unsigned char *aid, size_t aidlen);
   } fnc;
 };
Jun 18 2021, 4:58 AM · yubikey, Bug Report, scd
gniibe added a comment to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied.

Here is the reference to GID specification:
https://docs.microsoft.com/en-us/previous-versions/windows/hardware/design/dn642100(v=vs.85)?redirectedfrom=MSDN

Jun 18 2021, 3:56 AM · yubikey, Bug Report, scd
l10n daemon script <scripty@kde.org> committed rLIBKLEO997bce992d96: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Jun 18 2021, 3:22 AM
gniibe added a project to T5484: SCDaemon Not reselect applet and reauthenticate when the card send Security Not Sastisfied: yubikey.

Let me add the tag "yubikey".
I think that it could be solved in different level, if I were the device manufacturer; And it would give users the best solution.

Jun 18 2021, 3:16 AM · yubikey, Bug Report, scd

Jun 17 2021

Reiner added a comment to T5491: Console output failure with no-unicode font: GnuPG 2.2.28 is not working with »encrypt-to« in gpg.conf without specifying another recipient..

Hello Mr. Koch,

Jun 17 2021, 11:45 PM · gnupg (gpg22), Windows, Bug Report
bernhard updated the task description for T5493: Attachment1.pgp not offered for saving in an email from Symantec Encryption Desktop (PGP).
Jun 17 2021, 3:45 PM · gpgol
bernhard created T5493: Attachment1.pgp not offered for saving in an email from Symantec Encryption Desktop (PGP).
Jun 17 2021, 3:41 PM · gpgol
ikloecker committed rKLEOPATRAb906d4a037c8: Adapt to changed interface of directory services widget (authored by ikloecker).
Adapt to changed interface of directory services widget
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRAd53003d9bd59: Disable configuration of directory services if qgpgme is too old (authored by ikloecker).
Disable configuration of directory services if qgpgme is too old
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRA94310000dc00: Fix reset of Reset and Apply buttons after loading of module (authored by ikloecker).
Fix reset of Reset and Apply buttons after loading of module
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRA6936f79fd94e: Add input field for OpenPGP keyserver (authored by ikloecker).
Add input field for OpenPGP keyserver
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRA956ad28ba068: Initialize all pointers in-class (authored by ikloecker).
Initialize all pointers in-class
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRAdf01e87be274: Put list of X.509 directory services into a group box (authored by ikloecker).
Put list of X.509 directory services into a group box
Jun 17 2021, 12:48 PM
ikloecker committed rKLEOPATRA892e607f5192: Use name as header for the config modules (authored by ikloecker).
Use name as header for the config modules
Jun 17 2021, 12:48 PM
ikloecker committed rLIBKLEO49c1ed8a6f49: Add dialog for configuring an LDAP directory service (aka keyserver) (authored by ikloecker).
Add dialog for configuring an LDAP directory service (aka keyserver)
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEOfcbb856d0619: Disable configuration of directory services if qgpgme is too old (authored by ikloecker).
Disable configuration of directory services if qgpgme is too old
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEO64562c70af00: For GnuPG <2.2.28 add hint that GnuPG 2.2.28 is required (authored by ikloecker).
For GnuPG <2.2.28 add hint that GnuPG 2.2.28 is required
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEO24849531ce13: Bump library version (authored by ikloecker).
Bump library version
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEOc4e986687b36: Rewrite configuration of directory services for X.509 (authored by ikloecker).
Rewrite configuration of directory services for X.509
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEO585582b8d347: Support additional/unknown keyserver flags (authored by ikloecker).
Support additional/unknown keyserver flags
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEO4d26770b165e: Differentiate default connection from explicit plain connection (authored by ikloecker).
Differentiate default connection from explicit plain connection
Jun 17 2021, 12:29 PM
ikloecker committed rLIBKLEO56eb8edb51cf: Remove OpenPGP keyserver from widget (authored by ikloecker).
Remove OpenPGP keyserver from widget
Jun 17 2021, 12:29 PM