Page MenuHome GnuPG
Feed All Stories

Aug 10 2022

werner committed rM7e2ef54b9c07: Post release updates (authored by werner).
Post release updates
Aug 10 2022, 3:33 PM
werner committed rM26ff163bd691: Release 1.18.0 (authored by werner).
Release 1.18.0
Aug 10 2022, 3:33 PM
werner committed rM9ee74b68e688: tests: Make t-edit-sign more robust. (authored by werner).
tests: Make t-edit-sign more robust.
Aug 10 2022, 3:33 PM
werner closed T6129: Yubikey 5C 'not available: card error' regression as Resolved.

We are currently investigating another problem with a new feature. Thus things are delayed. Hopefully we get a new release this month (or at least a new gnupg 2.3 version to install on top of gpg4win).

Aug 10 2022, 2:59 PM · Bug Report, gpg4win
tigernero added a comment to T6129: Yubikey 5C 'not available: card error' regression.

Is it possible to have a gpg4win ETA that fixes this bug? thank you

Aug 10 2022, 1:43 PM · Bug Report, gpg4win
tigernero created T6129: Yubikey 5C 'not available: card error' regression.
Aug 10 2022, 1:42 PM · Bug Report, gpg4win
ikloecker committed rM5d91182c955d: qt: Add missing include (authored by ikloecker).
qt: Add missing include
Aug 10 2022, 12:00 PM
werner updated the task description for T5872: Release GPGME 1.17.1.
Aug 10 2022, 11:04 AM · Release Info, gpgme
werner triaged T6128: Release GPGME 1.18.0 as Normal priority.
Aug 10 2022, 11:03 AM · Release Info, gpgme
ikloecker committed rM99c1b14470f2: doc: Update NEWS (authored by ikloecker).
doc: Update NEWS
Aug 10 2022, 10:15 AM

Aug 9 2022

ikloecker changed the status of T5934: Kleopatra: Change the default/primary User ID from Open to Testing.

The option to flag a user ID as the primary user ID is now available in the Certificate Details dialog as button below the user ID table and as context menu entry of the user ID table.

Aug 9 2022, 3:56 PM · Restricted Project, gpg4win, kleopatra, Feature Request
ikloecker closed T5938: gpgme++: Add support for setting the primary user ID as Resolved.
Aug 9 2022, 3:51 PM · gpgme, Restricted Project, Feature Request
ikloecker closed T5938: gpgme++: Add support for setting the primary user ID, a subtask of T5934: Kleopatra: Change the default/primary User ID, as Resolved.
Aug 9 2022, 3:51 PM · Restricted Project, gpg4win, kleopatra, Feature Request
ikloecker closed T6126: gpg: Support specifiying user ID to set as primary as UID hash for --quick-set-primary-uid as Resolved.
Aug 9 2022, 3:51 PM · gnupg (gpg23), Restricted Project, Feature Request
ikloecker closed T6126: gpg: Support specifiying user ID to set as primary as UID hash for --quick-set-primary-uid, a subtask of T5938: gpgme++: Add support for setting the primary user ID, as Resolved.
Aug 9 2022, 3:51 PM · gpgme, Restricted Project, Feature Request
ikloecker committed rKLEOPATRAda3aef1bf1ef: Add support for flagging a user ID as the primary user ID (authored by ikloecker).
Add support for flagging a user ID as the primary user ID
Aug 9 2022, 3:49 PM
ikloecker committed rG2cbb5760d758: gpg: Emit an ERROR status if --quick-set-primary-uid fails (authored by ikloecker).
gpg: Emit an ERROR status if --quick-set-primary-uid fails
Aug 9 2022, 2:55 PM
ikloecker committed rG82c53efd6365: gpg: Look up user ID to mark as primary by UID hash (authored by ikloecker).
gpg: Look up user ID to mark as primary by UID hash
Aug 9 2022, 2:55 PM
ikloecker committed rMdb7d79063f57: qt: Add job to set the primary user ID of OpenPGP keys (authored by ikloecker).
qt: Add job to set the primary user ID of OpenPGP keys
Aug 9 2022, 2:53 PM
ikloecker committed rM125867f268f2: cpp: Add support for gpgme_op_set_uid_flag (authored by ikloecker).
cpp: Add support for gpgme_op_set_uid_flag
Aug 9 2022, 2:53 PM
aheinecke added a project to T4779: GpgSM: "Invalid Object" error when importing .p12 certs with wrong passphrase: Restricted Project.

I am adding the gpgcom tag as this causes support problems because we do not really know if it is an invalid object with the correct passphrase or if just the passphrase is incorrect.

Aug 9 2022, 12:15 PM · gnupg24 (gnupg-2.4.3), Restricted Project, gnupg (gpg23), S/MIME
Jakuje created T6127: FIPS 140-3 final review comments.
Aug 9 2022, 11:25 AM · FIPS, libgcrypt, Bug Report
werner added a comment to T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF.

Should go into 1.10 too

Aug 9 2022, 11:12 AM · backport, libgcrypt, FIPS
werner added a project to T6039: FIPS: Allow salt=NULL (or shorter salt) for HKDF: backport.
Aug 9 2022, 11:11 AM · backport, libgcrypt, FIPS
ikloecker moved T6126: gpg: Support specifiying user ID to set as primary as UID hash for --quick-set-primary-uid from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Aug 9 2022, 8:53 AM · gnupg (gpg23), Restricted Project, Feature Request
ikloecker claimed T5938: gpgme++: Add support for setting the primary user ID.
Aug 9 2022, 8:53 AM · gpgme, Restricted Project, Feature Request
ikloecker claimed T5934: Kleopatra: Change the default/primary User ID.
Aug 9 2022, 8:53 AM · Restricted Project, gpg4win, kleopatra, Feature Request
l10n daemon script <scripty@kde.org> committed rKLEOPATRA50cae383aa92: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Aug 9 2022, 4:48 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA9e61cc4377da: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Aug 9 2022, 4:13 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA83baac67caf4: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Aug 9 2022, 3:45 AM
gniibe committed rMf8d99bb9e4a7: python: Don't call __del__ from __exit__ method. (authored by gniibe).
python: Don't call __del__ from __exit__ method.
Aug 9 2022, 3:01 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA8e2d969de3fc: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Aug 9 2022, 2:48 AM
gniibe added a comment to T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

Indeed, you are right. The object created by with can be valid even after the context (when referenced by another object).

Aug 9 2022, 1:52 AM · Python, gpgme, Bug Report

Aug 8 2022

jap added a comment to T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

Not sure if that is the complete fix - if you do something like:

with gpg.Context(...) as context:
    ...
... cause an exception after the context has been closed ...

then context will still be a valid reference to the gpg.Context instance, and may cause segfaults when something tries to access things inside it (f.e. for serialisation).
I like your previous solution with the accessor checks, because that actually fixes the issue.
Stylistically, maybe __del__ should just be renamed to cleanup or free, and then make sure to call that function from both __exit__ and __del__.

Aug 8 2022, 1:14 PM · Python, gpgme, Bug Report
ikloecker triaged T6126: gpg: Support specifiying user ID to set as primary as UID hash for --quick-set-primary-uid as Normal priority.
Aug 8 2022, 12:28 PM · gnupg (gpg23), Restricted Project, Feature Request
gniibe added a comment to T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

I think the fix should be something like this:

diff --git a/lang/python/src/core.py b/lang/python/src/core.py
index 81f961d9..95fd0cba 100644
--- a/lang/python/src/core.py
+++ b/lang/python/src/core.py
@@ -1189,8 +1189,9 @@ class Context(GpgmeWrapper):
     def __enter__(self):
         return self
Aug 8 2022, 10:54 AM · Python, gpgme, Bug Report
gniibe added a comment to T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

@jap Thank you.

Aug 8 2022, 10:04 AM · Python, gpgme, Bug Report
ikloecker closed T5569: pinentry qt4 fails to compile in pinentry 1.2.0 as Resolved.

Should be fixed. A copy of an older version of pinentry's source code that can be built with Q4 is now included and will result in a pinentry-qt4 executable. Note that while we won't break this pinentry intentionally we won't maintain it either.

Aug 8 2022, 9:58 AM · Bug Report, pinentry
jap added a comment to T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

Can confirm, we've been running into this as well, but never filed a bug report. Our solution is to have this in our codebase:

Aug 8 2022, 9:02 AM · Python, gpgme, Bug Report
mlaurent committed rLIBKLEO971e0320ba93: GIT_SILENT: Prepare 5.21.0 (authored by mlaurent).
GIT_SILENT: Prepare 5.21.0
Aug 8 2022, 7:11 AM
mlaurent committed rKLEOPATRA118a7682bea4: GIT_SILENT: Prepare 5.21.0 (authored by mlaurent).
GIT_SILENT: Prepare 5.21.0
Aug 8 2022, 7:10 AM

Aug 5 2022

ikloecker committed rP0cb17ea14e53: qt4: Add recipe for container for testing build for Qt4 (authored by ikloecker).
qt4: Add recipe for container for testing build for Qt4
Aug 5 2022, 7:54 PM
ikloecker committed rP825819b754f5: qt4: Make it compile with Qt 4.8.7 and without C++11 (authored by ikloecker).
qt4: Make it compile with Qt 4.8.7 and without C++11
Aug 5 2022, 7:54 PM
ikloecker committed rP08a7391fc024: qt,qt4: Separate build of pinentry with Qt5 and Qt4 (authored by ikloecker).
qt,qt4: Separate build of pinentry with Qt5 and Qt4
Aug 5 2022, 7:54 PM
ikloecker committed rP70388f18958c: qt4: Add old copy of source code of pinentry-qt for building with Qt4 (authored by ikloecker).
qt4: Add old copy of source code of pinentry-qt for building with Qt4
Aug 5 2022, 7:54 PM
mlaurent committed rKLEOPATRA853d80b54a9d: Remove duplicate includes (authored by mlaurent).
Remove duplicate includes
Aug 5 2022, 7:42 PM
ikloecker added a comment to T6115: Kleopatra: On "revoke certification" do not offer keys which did not certify that certificate.

Note to self: T6100: Kleopatra: Make revocation of certifications accessible may be obsolete when the improvements are completed because then the dialog will most likely be gone.

Aug 5 2022, 4:21 PM · Restricted Project, kleopatra
ikloecker committed rKLEOPATRA4d0cdb960690: Add missing include (authored by ikloecker).
Add missing include
Aug 5 2022, 4:18 PM
ikloecker added a comment to T6115: Kleopatra: On "revoke certification" do not offer keys which did not certify that certificate.

If the user cannot revoke any of the certifications of the selected key or user IDs, then we now inform the user about this instead of showing the dilaog.

Aug 5 2022, 4:14 PM · Restricted Project, kleopatra
ikloecker committed rKLEOPATRAe3bdb94add48: Modernize the check that the user IDs belong to the key (authored by ikloecker).
Modernize the check that the user IDs belong to the key
Aug 5 2022, 4:08 PM
ikloecker committed rKLEOPATRA19286cc1d152: Check if there are any certifications the user can revoke (authored by ikloecker).
Check if there are any certifications the user can revoke
Aug 5 2022, 4:08 PM
ikloecker committed rKLEOPATRA82d5bbb89358: Add helper to check that a user ID belongs to a key (authored by ikloecker).
Add helper to check that a user ID belongs to a key
Aug 5 2022, 4:08 PM
ikloecker committed rKLEOPATRAddaf31d30632: Log a warning if the signatures are not available (authored by ikloecker).
Log a warning if the signatures are not available
Aug 5 2022, 4:08 PM
ikloecker committed rLIBKLEO2fa5e706bb8f: Bump library version (authored by ikloecker).
Bump library version
Aug 5 2022, 4:00 PM
ikloecker committed rLIBKLEO807d2eacd385: Add helper to check if all elements in a range satify a predicate (authored by ikloecker).
Add helper to check if all elements in a range satify a predicate
Aug 5 2022, 4:00 PM
ikloecker claimed T6115: Kleopatra: On "revoke certification" do not offer keys which did not certify that certificate.
Aug 5 2022, 2:37 PM · Restricted Project, kleopatra
werner added a comment to T6002: scute w/ gpg23: Support multiple cards/tokens, major update with KEYGRIP.

Firefox nicely shows the 3 NIST certificates from my Telesec card but not the important Brainpool certificate for eIDAS. It turns out that Firefox does not support Brainpool, despite that a patch has been provided 8 years ago. See https://bugzilla.mozilla.org/show_bug.cgi?id=943639 . Thus there is currently no way to use LibreOffice or Okular to signe PDFs because they rely on NSS.

Aug 5 2022, 2:06 PM · Feature Request, scute
mlaurent committed rLIBKLEO1496aa438ae7: GIT_SILENT: prepare 5.21.0 (authored by mlaurent).
GIT_SILENT: prepare 5.21.0
Aug 5 2022, 1:38 PM
ikloecker changed the status of T6121: Kleopatra: add name suggestion for revocation certificate from Open to Testing.

We now propose "<fingerprint>.rev" in the last used export directory as file name. This is the same file name as for the revocation certificates that gpg automatically writes to the openpgp-revocs.d folder when a new OpenPGP key is generated.

Aug 5 2022, 12:55 PM · Restricted Project, kleopatra
ikloecker committed rKLEOPATRA16cf9a3b0b41: Make overwrite confirmation look more like the Qt one (authored by ikloecker).
Make overwrite confirmation look more like the Qt one
Aug 5 2022, 12:54 PM
ikloecker committed rKLEOPATRA6a79624cfea7: Do not ask twice for confirmation to overwrite existing file (authored by ikloecker).
Do not ask twice for confirmation to overwrite existing file
Aug 5 2022, 12:54 PM
ikloecker committed rKLEOPATRAfd3b57277708: Propose a file name for the generated revocation certificate (authored by ikloecker).
Propose a file name for the generated revocation certificate
Aug 5 2022, 12:54 PM
ikloecker committed rKLEOPATRA9994a362d621: Add/use common helper for persisting the last used export directory (authored by ikloecker).
Add/use common helper for persisting the last used export directory
Aug 5 2022, 12:54 PM
ikloecker committed rKLEOPATRA47e4f93d8280: Store last used export directory in state config (authored by ikloecker).
Store last used export directory in state config
Aug 5 2022, 12:54 PM
ikloecker committed rKLEOPATRA0479937b7a29: Store the full path if path references a directory (authored by ikloecker).
Store the full path if path references a directory
Aug 5 2022, 12:54 PM
aheinecke committed rW311b2e25648e: Update kleopatra (authored by aheinecke).
Update kleopatra
Aug 5 2022, 12:24 PM
aheinecke committed rKLEOPATRAe8c91dbd0914: Fix another c++20 initializer (authored by aheinecke).
Fix another c++20 initializer
Aug 5 2022, 12:23 PM
aheinecke committed rW17845573cf71: Update kde-l10n (authored by aheinecke).
Update kde-l10n
Aug 5 2022, 11:44 AM
aheinecke committed rWaba0445195aa: Update Kleopatra to latest master (authored by aheinecke).
Update Kleopatra to latest master
Aug 5 2022, 11:44 AM
aheinecke committed rKLEOPATRA1af932cfb542: Move c++20 initializers out of for statement (authored by aheinecke).
Move c++20 initializers out of for statement
Aug 5 2022, 11:41 AM
aheinecke committed rKLEOPATRA36cbbf748e52: Fix debug output for base directory detection (authored by aheinecke).
Fix debug output for base directory detection
Aug 5 2022, 11:41 AM
ikloecker claimed T6121: Kleopatra: add name suggestion for revocation certificate .
Aug 5 2022, 11:04 AM · Restricted Project, kleopatra
aheinecke triaged T6125: GpgOL: Print warning when incompatible Addins are detected as Normal priority.
Aug 5 2022, 8:21 AM · Restricted Project, gpgol
gniibe moved T5438: gpgme_op_keylist_from_data_start ignores GPGME_KEYLIST_MODE_SIGS from For a future release to QA for next release on the gpgme board.
Aug 5 2022, 8:12 AM · gpgme (gpgme 1.23.x), OpenPGP, Bug Report
gniibe moved T5825: [gpgme] [python] possible dangling reference to passphrase from Backlog to Python stuff on the gpgme board.
Aug 5 2022, 8:10 AM · patch, gpgme, Bug Report
gniibe moved T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python) from Backlog to Python stuff on the gpgme board.
Aug 5 2022, 8:10 AM · Python, gpgme, Bug Report
gniibe claimed T6060: segfault (NULL-pointer) when inspecting gpg Context after exception (python).

The SEGV was due to access to gpgme library after self.wrapped is set to None in the __del__ function.

Aug 5 2022, 8:04 AM · Python, gpgme, Bug Report
gniibe added a comment to T5825: [gpgme] [python] possible dangling reference to passphrase.

The commit is: rMb2f224a471fe: python: Reset passphrase callback correctly..

Aug 5 2022, 7:59 AM · patch, gpgme, Bug Report
gniibe committed rM180899c7c313: python: Don't access gpgme with wrapped=None. (authored by gniibe).
python: Don't access gpgme with wrapped=None.
Aug 5 2022, 7:59 AM
gniibe committed rMb2f224a471fe: python: Reset passphrase callback correctly. (authored by jap).
python: Reset passphrase callback correctly.
Aug 5 2022, 4:10 AM
gniibe claimed T5825: [gpgme] [python] possible dangling reference to passphrase.

Thank you for the patch. You are right.

Aug 5 2022, 4:09 AM · patch, gpgme, Bug Report

Aug 4 2022

werner added a project to T6123: Gpg Encryption and Signing - infinite Loop: Support.
Aug 4 2022, 9:01 PM · Support, gpgagent, gpg4win, Bug Report
werner awarded T6122: GnuPG: misleading error message keytocard a Cup of Joe token.
Aug 4 2022, 6:22 PM · Bug Report, gnupg (gpg22)
ikloecker added a comment to T5951: gpgme: Add support for refreshing OpenPGP keys.

I have kept a backup copy of a WKDRefreshJob locally. ;-) But that's stuff for a different task.

Aug 4 2022, 3:56 PM · gpgme, Restricted Project
aheinecke added a comment to T5951: gpgme: Add support for refreshing OpenPGP keys.

Thanks, the update button this is now more what I think is expected. Still I am not sure if removing it completely was neccessary, well we have it in the history now. Because I see the need to also update via WKD. Currently we only update from there if a key is expired but we would never see revocations. That is a problem that we will need some solution for at some point. But yeah in that case calling it "RefreshOpenPGPKeysJob" would be a misleading API Name anyhow. So its probably good that you removed it before the upcoming release.

Aug 4 2022, 3:34 PM · gpgme, Restricted Project
aheinecke lowered the priority of T6124: Gpg Encryption and Signing - infinite Loop from High to Low.

Still, the first thing you should do is to update to a recent version, the version you are on is about 3 years old. See https://gpg4win.org for the most recent version. Then add --verbose and --debug ipc to your command so we can maybe see more what it does.

Aug 4 2022, 3:29 PM · Info Needed
ikloecker added a comment to T6122: GnuPG: misleading error message keytocard.

Looks good. After entering a wrong passphrase three times Kleopatra now reports

Moving the key to the card failed: Bad passphrase
Aug 4 2022, 3:08 PM · Bug Report, gnupg (gpg22)
mariamihaela triaged T6124: Gpg Encryption and Signing - infinite Loop as High priority.
Aug 4 2022, 2:00 PM · Info Needed
mariamihaela added a comment to T6123: Gpg Encryption and Signing - infinite Loop.

Please reopen my issue. This is a serious issue that we encounter and do not have any explication.

Aug 4 2022, 1:55 PM · Support, gpgagent, gpg4win, Bug Report
mariamihaela added a comment to T6123: Gpg Encryption and Signing - infinite Loop.

Hi!
No, it's not waiting for the password. This was a 2 times error happening on our server.
We already provided the password but it was hung. We entered different things but it won't make anything.
I can tell you it doesn't wait for anything because we tested the same command on 2 different machines. On one machine it was hung, on another it worked.

Aug 4 2022, 1:54 PM · Support, gpgagent, gpg4win, Bug Report
ikloecker closed T6123: Gpg Encryption and Signing - infinite Loop as Invalid.

gpg was waiting for the passphrase for the signing key to be provided via stdin.

Aug 4 2022, 1:46 PM · Support, gpgagent, gpg4win, Bug Report
ikloecker changed the status of T5951: gpgme: Add support for refreshing OpenPGP keys from Open to Testing.

See T5903: Kleopatra: Add refresh button in certificatedetails for the corresponding Kleopatra task. Kleopatra now uses the good old ReceiveKeysJob for doing a key refresh from the configured key server. The RefreshOpenPGPKeysJob has been removed.

Aug 4 2022, 1:40 PM · gpgme, Restricted Project
ikloecker changed the status of T5951: gpgme: Add support for refreshing OpenPGP keys, a subtask of T5903: Kleopatra: Add refresh button in certificatedetails , from Open to Testing.
Aug 4 2022, 1:40 PM · backport, kleopatra, Restricted Project
ikloecker added a comment to T5903: Kleopatra: Add refresh button in certificatedetails .

For an OpenPGP key, Update now performs a simple "retrieve key" operation for the existing key, i.e. it refreshes the key with the public key found on the configured key server.

Aug 4 2022, 1:36 PM · backport, kleopatra, Restricted Project
mariamihaela created T6123: Gpg Encryption and Signing - infinite Loop.
Aug 4 2022, 1:25 PM · Support, gpgagent, gpg4win, Bug Report
werner added a project to T6122: GnuPG: misleading error message keytocard: Restricted Project.
Aug 4 2022, 12:46 PM · Bug Report, gnupg (gpg22)
werner committed rGf2a81e374501: gpg: Fix wrong error message for keytocard. (authored by werner).
gpg: Fix wrong error message for keytocard.
Aug 4 2022, 12:46 PM
werner added a comment to T6122: GnuPG: misleading error message keytocard.

With my patch I see the expected status message:

Aug 4 2022, 12:43 PM · Bug Report, gnupg (gpg22)
werner committed rG189102ac17dc: gpg: Fix wrong error message for keytocard. (authored by werner).
gpg: Fix wrong error message for keytocard.
Aug 4 2022, 12:43 PM
ikloecker committed rMc3b183831db5: qt: Remove job for refreshing OpenPGP keys (authored by ikloecker).
qt: Remove job for refreshing OpenPGP keys
Aug 4 2022, 12:32 PM