Page MenuHome GnuPG
Feed All Stories

Sep 5 2022

aheinecke closed T5967: GpgOL: Use kleopatra groups in keyresolver as Resolved.

tested and this works.

Sep 5 2022, 11:05 AM · gpgol, Unknown Object (Project)
aheinecke closed T5989: Kleopatra: Customization Window Title and custom Logo from VERSION file as Resolved.

Tested and this works.

Sep 5 2022, 11:04 AM · kleopatra, Unknown Object (Project)
aheinecke closed T5827: GpgOL: Allow setting HKLM values as override as Resolved.

This is now in

Sep 5 2022, 11:03 AM · gpgol, Unknown Object (Project)
aheinecke closed T4637: GpgOL: Encoding problems in German as Resolved.
Sep 5 2022, 11:03 AM · Unknown Object (Project), gpgol
aheinecke committed rKLEOPATRA005e3f5258f1: Add placeholder for smartcard manual (authored by aheinecke).
Add placeholder for smartcard manual
Sep 5 2022, 11:00 AM
gniibe committed rG7a22f764d518: tools:gpg-auth: Show SSH key comment when asking PIN. (authored by gniibe).
tools:gpg-auth: Show SSH key comment when asking PIN.
Sep 5 2022, 7:49 AM
gniibe abandoned D531: Keep holding READER_LOCK_TABLE and make clear distinction among close/releasing_PCSC_context/nullify_rdrname.
Sep 5 2022, 1:52 AM · gnupg (gpg23), scd
gniibe abandoned D544: Deprecation of random daemon part 1 (remove use of random daemon).
Sep 5 2022, 1:47 AM · libgcrypt

Sep 3 2022

werner resigned from D531: Keep holding READER_LOCK_TABLE and make clear distinction among close/releasing_PCSC_context/nullify_rdrname.
Sep 3 2022, 8:51 PM · gnupg (gpg23), scd
werner closed T6184: zlib version 1.2.12 actually used by GnuPG / Gpg4Win suffers from CVE-2022-37434 / 2 patches are available as Resolved.
Sep 3 2022, 8:48 PM · Not A Bug, kleopatra, gpg4win
ikloecker added a comment to T6184: zlib version 1.2.12 actually used by GnuPG / Gpg4Win suffers from CVE-2022-37434 / 2 patches are available.

inflateGetHeader does not seem to be called by anything from KDE. The only hits are from a copy of zlib included in marble.
https://lxr.kde.org/search?%21v=kf5-qt5&_filestring=&_string=inflateGetHeader

Sep 3 2022, 5:07 PM · Not A Bug, kleopatra, gpg4win
werner reassigned T6184: zlib version 1.2.12 actually used by GnuPG / Gpg4Win suffers from CVE-2022-37434 / 2 patches are available from werner to ikloecker.

Thanks for mentioning this. I looked at the CVE last Sunday and figured that we are not affected. The vulnerable function inflateGetHeader is not used by GnuPG because we don;'t support the gzip format.

Sep 3 2022, 1:21 PM · Not A Bug, kleopatra, gpg4win
werner triaged T6185: `gpg2 --list-keys --with-colons > /dev/full` exits with status 0 as Low priority.

The more relavant error is that there is no status output on failure which is what gpgme uses (due to double forking).

Sep 3 2022, 1:08 PM · Bug Report, gnupg
werner closed T6186: gpgv does not support --exit-on-status-write-error as Resolved.

gpgv returns success iff the signature is valid. That is the whole purpose of this tool.

Sep 3 2022, 1:02 PM · gnupg
DemiMarie created T6186: gpgv does not support --exit-on-status-write-error.
Sep 3 2022, 7:33 AM · gnupg
DemiMarie created T6185: `gpg2 --list-keys --with-colons > /dev/full` exits with status 0.
Sep 3 2022, 6:45 AM · Bug Report, gnupg
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAce04061dccce: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Sep 3 2022, 12:37 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA6cfe353c0ffe: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Sep 3 2022, 12:36 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA3816a889be1f: GIT_SILENT Upgrade release service version to 22.08.1. (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Upgrade release service version to 22.08.1.
Sep 3 2022, 12:36 AM

Sep 2 2022

vitusb added projects to T6184: zlib version 1.2.12 actually used by GnuPG / Gpg4Win suffers from CVE-2022-37434 / 2 patches are available: gnupg, gpg4win.
Sep 2 2022, 6:44 PM · Not A Bug, kleopatra, gpg4win
vitusb created T6184: zlib version 1.2.12 actually used by GnuPG / Gpg4Win suffers from CVE-2022-37434 / 2 patches are available.
Sep 2 2022, 6:43 PM · Not A Bug, kleopatra, gpg4win
ikloecker added a comment to T6183: Kleopatra: on import own public key do not show "certify window" .

Please give a step-by-step description how to reproduce this.

Sep 2 2022, 4:52 PM · Unknown Object (Project), kleopatra
ikloecker added a comment to T6182: Kleopatra: "general error" on wrong PIN input during certification.

I'm asked three times for the passphrase, but otherwise I can confirm this.

Sep 2 2022, 4:48 PM · Unknown Object (Project), kleopatra
ikloecker added a comment to T6180: Kleopatra: "more details" in group edit opens information window in background.

Possible root cause: The S/MIME details window seems to lack a parent.

Sep 2 2022, 4:46 PM · Unknown Object (Project), kleopatra
ikloecker added a comment to T5620: GnuPG, pinentry: Passphrase pattern error / warning does not match new logic.

I have introduced this hint exactly because it's impossible to describe the rules automatically.

Sep 2 2022, 4:28 PM · gnupg, Unknown Object (Project)
ikloecker added a comment to T5620: GnuPG, pinentry: Passphrase pattern error / warning does not match new logic.

These hints are taken from the help.txt file.

Sep 2 2022, 4:28 PM · gnupg, Unknown Object (Project)
ikloecker added a comment to T5620: GnuPG, pinentry: Passphrase pattern error / warning does not match new logic.

gpg-agent passes to pinentry a short and a long hint for the passphrase constraints (see constraints-hint-* in pinentry.texi). If these hints are set, then pinentry shows them even before the user has started to enter a passphrase. The error message can then simply be "Read the hint, stupid!". Just kidding, of course.

Sep 2 2022, 4:27 PM · gnupg, Unknown Object (Project)
ebo created T6183: Kleopatra: on import own public key do not show "certify window" .
Sep 2 2022, 4:12 PM · Unknown Object (Project), kleopatra
werner committed rW60de1223444f: Update to GnuPG 2.2.39 (authored by werner).
Update to GnuPG 2.2.39
Sep 2 2022, 3:48 PM
werner closed T6175: Release GnuPG 2.2.39 as Resolved.
Sep 2 2022, 3:48 PM · gnupg (gpg22), Release Info
werner committed rDa3fffbf3d960: swdb: GnuPG 2.2.39 (authored by werner).
swdb: GnuPG 2.2.39
Sep 2 2022, 3:43 PM
ebo created T6182: Kleopatra: "general error" on wrong PIN input during certification.
Sep 2 2022, 3:43 PM · Unknown Object (Project), kleopatra
werner committed rG268e876ee274: Post release updates (authored by werner).
Post release updates
Sep 2 2022, 3:40 PM
werner committed rG7c2078a680dd: Release 2.2.39 (authored by werner).
Release 2.2.39
Sep 2 2022, 3:40 PM
werner triaged T6181: Release GnuPG 2.2.40 as Low priority.
Sep 2 2022, 3:39 PM · gnupg (gpg22), Release Info
ebo created T6180: Kleopatra: "more details" in group edit opens information window in background.
Sep 2 2022, 3:32 PM · Unknown Object (Project), kleopatra
werner added a comment to T5542: w32: Values under HKLM ignored if HKCU entry for GnuPG exists.

Can you please give a more detailed example with regedit files to demonstrate that?

Sep 2 2022, 3:15 PM · Windows, gnupg, Unknown Object (Project)
werner lowered the priority of T5620: GnuPG, pinentry: Passphrase pattern error / warning does not match new logic from Normal to Low.

Can't we get them from the help.txt file? Putting a tooltip into the pattern file would be an option but needs substantial changes,

Sep 2 2022, 3:13 PM · gnupg, Unknown Object (Project)
werner removed a project from T6135: Agent, P15: Insert Smartcard query uses serial number instead of $DISPSERIALNO: Unknown Object (Project).
Sep 2 2022, 3:08 PM · gnupg24 (gnupg-2.4.3), scd
werner closed T6173: Invalid signing-key when doing a signature-check of GnuPG installer-packages, signed by Werner Koch's signing-key in de-vs Mode (aka VS-NfD Mode) as Resolved.
Sep 2 2022, 3:06 PM · Unknown Object (Project), workaround, gnupg
werner changed the status of T6179: gnupg 2.3.7 broke YubiKey support: DBG: Curve with OID not supported: 2b06010401da470f01 from Open to Testing.
Sep 2 2022, 2:45 PM · gnupg24, scd, Bug Report
werner added a comment to T6179: gnupg 2.3.7 broke YubiKey support: DBG: Curve with OID not supported: 2b06010401da470f01.

Yeah, we known. Fix is rGf34b9147eb3070b see T6070

Sep 2 2022, 2:43 PM · gnupg24, scd, Bug Report
alexk updated alexk.
Sep 2 2022, 2:22 PM
werner added a member for Contributor: alexk.
Sep 2 2022, 2:19 PM
werner added a member for g10code: alexk.
Sep 2 2022, 2:16 PM
alexk updated alexk.
Sep 2 2022, 2:15 PM
werner committed rGfc99ff8aff72: speedo: Authenticode sign two more tools. (authored by werner).
speedo: Authenticode sign two more tools.
Sep 2 2022, 12:06 PM
gniibe committed rG3e5f99e6483d: tools: Fix gpg-auth. (authored by gniibe).
tools: Fix gpg-auth.
Sep 2 2022, 12:06 PM
ikloecker added a comment to T6109: Kleopatra: Better way to show expired subkeys.

We could use single letters or icons (with proper tool tip and accessible name). I'm not sure mentioning the cert usage is that useful.

Sep 2 2022, 11:24 AM · Feature Request, OpenPGP, kleopatra
aheinecke added a comment to T6109: Kleopatra: Better way to show expired subkeys.

Another point where this is very problematic are S/MIME certificates for signing and encryption. While the certificate line edit and the certificate combo box filter the usage, Groups are problematic. If you want to create an encryption group and include one "signing only" certificate the whole group is no longer visible for example in Outlook when encrypting. Both me and Eva thought that S/MIME Groups did not work at all in Outlook because of this.

Sep 2 2022, 10:22 AM · Feature Request, OpenPGP, kleopatra
nazarewk updated the task description for T6179: gnupg 2.3.7 broke YubiKey support: DBG: Curve with OID not supported: 2b06010401da470f01.
Sep 2 2022, 9:56 AM · gnupg24, scd, Bug Report
nazarewk created T6179: gnupg 2.3.7 broke YubiKey support: DBG: Curve with OID not supported: 2b06010401da470f01.
Sep 2 2022, 9:54 AM · gnupg24, scd, Bug Report
werner closed T6176: Crash in ask_for_card as Resolved.

Thanks for testing. I guess I will do a new release.

Sep 2 2022, 8:51 AM · gpgagent, gnupg (gpg22), Bug Report
werner closed T6177: GnuPG mishandles write errors on status fd and stdout as Wontfix.
Sep 2 2022, 8:47 AM · gnupg
werner closed T6178: es_write_sanitized swallows errors as Resolved.

Standard behaviour for stdio functions.

Sep 2 2022, 8:46 AM · Not A Bug, gpgrt
gniibe committed rGd49788ef9f82: tools:gpg-auth: New tool for authentication. (authored by gniibe).
tools:gpg-auth: New tool for authentication.
Sep 2 2022, 7:54 AM
DemiMarie created T6178: es_write_sanitized swallows errors.
Sep 2 2022, 2:20 AM · Not A Bug, gpgrt
DemiMarie created T6177: GnuPG mishandles write errors on status fd and stdout.
Sep 2 2022, 2:15 AM · gnupg

Sep 1 2022

cschramm added a comment to T6176: Crash in ask_for_card.

Applies cleanly and fixes the crash. 👍

Sep 1 2022, 6:06 PM · gpgagent, gnupg (gpg22), Bug Report
werner added a comment to T6176: Crash in ask_for_card.

For master (2.3) the fix is not needed due to another way the code works, but having a more robust function is always good.

Sep 1 2022, 5:47 PM · gpgagent, gnupg (gpg22), Bug Report
werner committed rGcd7570f02efe: common: Make nvc_lookup more robust. (authored by werner).
common: Make nvc_lookup more robust.
Sep 1 2022, 5:45 PM
werner added a comment to T6176: Crash in ask_for_card.

You may try the above commit - if should apply cleanly to 2.2.37.

Sep 1 2022, 5:40 PM · gpgagent, gnupg (gpg22), Bug Report
werner committed rG8c22b00268bf: common: Make nvc_lookup more robust. (authored by werner).
common: Make nvc_lookup more robust.
Sep 1 2022, 5:38 PM
werner added a comment to T6176: Crash in ask_for_card.

You are right. This due to your old binary private key (stubs). Otherwise you would at least have one item ("Key:"). I need to see what do do about the release. Maybe a tool to update the key files would we a good workaround.

Sep 1 2022, 4:04 PM · gpgagent, gnupg (gpg22), Bug Report
werner claimed T6176: Crash in ask_for_card.
Sep 1 2022, 3:53 PM · gpgagent, gnupg (gpg22), Bug Report
werner added a comment to T6176: Crash in ask_for_card.

Oh well, why do I receive such bug reports right after the next release :-(

Sep 1 2022, 3:52 PM · gpgagent, gnupg (gpg22), Bug Report
cschramm created T6176: Crash in ask_for_card.
Sep 1 2022, 3:11 PM · gpgagent, gnupg (gpg22), Bug Report
werner committed rD1c69ef68b81c: Remove the donate button (authored by werner).
Remove the donate button
Sep 1 2022, 1:57 PM
werner closed T6159: Release GnuPG 2.2.38 as Resolved.
Sep 1 2022, 1:54 PM · Release Info, gnupg (gpg22)
werner committed rD1943c5a7ded1: swdb: GnuPG 2.2.38 (authored by werner).
swdb: GnuPG 2.2.38
Sep 1 2022, 1:51 PM
werner committed rW3a688682e8be: Update to GnuPG 2.2.38 (authored by werner).
Update to GnuPG 2.2.38
Sep 1 2022, 1:50 PM
werner committed rG9eb03b722cb6: Post release updates (authored by werner).
Post release updates
Sep 1 2022, 1:36 PM
werner committed rG0b786fde7755: Release 2.2.38 (authored by werner).
Release 2.2.38
Sep 1 2022, 1:36 PM
JoeDoe1000 added a comment to T5926: GPGOL - Leere Nachricht kann nicht signiert werden (empty message email can't be signed or encrypted).

Sorry for the confusion ...
There was no single gpgol-File for deletion.
There were 100.000 other files from other programs.
No idea, why this has interferred with gpgol, but it obviously has.

Sep 1 2022, 10:14 AM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T5926: GPGOL - Leere Nachricht kann nicht signiert werden (empty message email can't be signed or encrypted).

Ok. So I never assumed that you had actually 100 gpgol_enc_number.dat files lying around.

Sep 1 2022, 9:50 AM · gpgol, Bug Report, gpg4win
gniibe committed rGd1490c6df991: po: Update Japanese Translation. (authored by gniibe).
po: Update Japanese Translation.
Sep 1 2022, 7:54 AM
gniibe committed rGc26393a2cb7c: po: Update Japanese Translation. (authored by gniibe).
po: Update Japanese Translation.
Sep 1 2022, 7:49 AM
eliz added a comment to T5897: Fix MinGW compilation error with 'struct _stat32' in common/sysutils.c from gnupg-2.3.4.

Should be OK for mingw.org's MinGW. I cannot test the MinGW64 bits, but I trust that you did.

Sep 1 2022, 7:16 AM · gnupg24, toolchain, Feature Request, patch
gniibe added a comment to T5897: Fix MinGW compilation error with 'struct _stat32' in common/sysutils.c from gnupg-2.3.4.

I encountered this issue of struct stat when compiling for x86_64 of Windows.
I'm considering this patch:

diff --git a/common/sysutils.c b/common/sysutils.c
index c30f9a0ce..bbed309a8 100644
--- a/common/sysutils.c
+++ b/common/sysutils.c
@@ -1237,10 +1237,20 @@ int
 gnupg_stat (const char *name, struct stat *statbuf)
 {
 # ifdef HAVE_W32_SYSTEM
+#  if __MINGW32_MAJOR_VERSION > 3
+    /* mingw.org's MinGW */
+#   define STRUCT_STAT _stat
+#  elif defined(_USE_32BIT_TIME_T)
+    /* MinGW64 for i686 */
+#   define STRUCT_STAT _stat32
+#  else
+    /* MinGW64 for x86_64 */
+#   define STRUCT_STAT _stat64i32
+#  endif
   if (any8bitchar (name))
     {
       wchar_t *wname;
-      struct _stat32 st32;
+      struct STRUCT_STAT st32;
       int ret;
Sep 1 2022, 6:27 AM · gnupg24, toolchain, Feature Request, patch
orbea added a comment to T6136: build failure with slibtool - error: undefined symbol: QGpgME::RevokeKeyJob::staticMetaObject.

Thanks, I really appreciate having this fixed in gpgrt-config! I backported the commit to gentoo and can confirm that fixes the build issue with slibtool.

Sep 1 2022, 4:31 AM · gpgrt, gpgme, Bug Report
gniibe closed T5898: Two fixes for the gnupg-2.3.4 test suite when running on MS-Windows as Resolved.

Thank you for reporting, and sorry for late handling of this report.

Sep 1 2022, 3:26 AM · Windows, gnupg (gpg23), Bug Report

Aug 31 2022

werner updated the task description for T6159: Release GnuPG 2.2.38.
Aug 31 2022, 6:32 PM · Release Info, gnupg (gpg22)
werner updated the task description for T6159: Release GnuPG 2.2.38.
Aug 31 2022, 6:31 PM · Release Info, gnupg (gpg22)
werner triaged T6175: Release GnuPG 2.2.39 as Low priority.
Aug 31 2022, 6:29 PM · gnupg (gpg22), Release Info
werner committed rGea34325c54a2: dirmngr: New option --debug-cache-expired-certs. (authored by werner).
dirmngr: New option --debug-cache-expired-certs.
Aug 31 2022, 6:14 PM
werner committed rG17073c9abcfb: dirmngr: New option --debug-cache-expired-certs. (authored by werner).
dirmngr: New option --debug-cache-expired-certs.
Aug 31 2022, 6:12 PM
werner committed rGa95a31cd2f03: gpg: Add descriptions for --auto-key-import and --include-key-import (authored by werner).
gpg: Add descriptions for --auto-key-import and --include-key-import
Aug 31 2022, 6:07 PM
werner closed T6174: Option --require-comliance does not work in sign+encrypt mode as Resolved.
Aug 31 2022, 5:46 PM · Unknown Object (Project), OpenPGP, Bug Report, gnupg
werner committed rG0b91fa0f13fd: common,w32: Fix an encoding problem of the printed timezone. (authored by werner).
common,w32: Fix an encoding problem of the printed timezone.
Aug 31 2022, 5:33 PM
JoeDoe1000 added a comment to T5926: GPGOL - Leere Nachricht kann nicht signiert werden (empty message email can't be signed or encrypted).

I had a look into my \AppData\Local\Temp and found some 10,000 Files/Folders (nearly 100,000 files in total) with over 10 GB.
After deleting most of them, GPG4WIN 4.0.3 is working!

Aug 31 2022, 4:56 PM · gpgol, Bug Report, gpg4win
werner added a comment to T6173: Invalid signing-key when doing a signature-check of GnuPG installer-packages, signed by Werner Koch's signing-key in de-vs Mode (aka VS-NfD Mode).

Small correction: We don't have replicas of our code signing key. I mistook this with out Authenticode signing key.

Aug 31 2022, 4:55 PM · Unknown Object (Project), workaround, gnupg
werner committed rGe05fb5ca3711: gpg: Emit STATUS_FAILURE for --require-compliance errors (authored by werner).
gpg: Emit STATUS_FAILURE for --require-compliance errors
Aug 31 2022, 3:34 PM
werner committed rGe1169e8f8ac7: scd: Add npth_unprotect/npth_protect for blocking operations. (authored by gniibe).
scd: Add npth_unprotect/npth_protect for blocking operations.
Aug 31 2022, 3:34 PM
werner committed rG14ccabe7f82f: dirmngr: Reject certificate which is not valid into cache. (authored by gniibe).
dirmngr: Reject certificate which is not valid into cache.
Aug 31 2022, 3:34 PM
SPYazdani added a comment to T5926: GPGOL - Leere Nachricht kann nicht signiert werden (empty message email can't be signed or encrypted).

It's strange that the problem only occurs locally on one machine. I set up a test bench and did not experience the same errors as before.

Aug 31 2022, 2:52 PM · gpgol, Bug Report, gpg4win
aheinecke added a comment to T5926: GPGOL - Leere Nachricht kann nicht signiert werden (empty message email can't be signed or encrypted).

Thanks a lot. Due to your log I have tried with a long username and umlauts and a dot in my username. My test name was Längül!ödiföäada.dad which is the longest that Windows allows. But It still works for me. Even if I create one or two gpgol_enc.dat files in %TEMP% It still works:

Aug 31 2022, 2:37 PM · gpgol, Bug Report, gpg4win
werner committed rGaa0c942521d8: gpg: Fix assertion failure due to errors in encrypt_filter. (authored by werner).
gpg: Fix assertion failure due to errors in encrypt_filter.
Aug 31 2022, 1:59 PM
werner committed rG15cf36f6a84d: gpg: Rename a function. (authored by werner).
gpg: Rename a function.
Aug 31 2022, 1:59 PM
werner committed rGf88cb12f8e3c: gpg: Make --require-compliance work for -se (authored by werner).
gpg: Make --require-compliance work for -se
Aug 31 2022, 1:59 PM
werner committed rG5b24c41ba72c: gpg: Very minor cleanup in decrypt_data. (authored by werner).
gpg: Very minor cleanup in decrypt_data.
Aug 31 2022, 1:59 PM