Page MenuHome GnuPG
Feed All Stories

Oct 28 2022

werner updated subscribers of T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.
Oct 28 2022, 3:56 PM · Not A Bug, workaround, gnupg24, Windows, ssh
werner added a comment to T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent.

Will go into 2.3.9 and gpg4win 4.0.5

Oct 28 2022, 3:56 PM · Not A Bug, workaround, gnupg24, Windows, ssh
werner closed T1621: Support multiple cards (not just readers) as Resolved.

You are using a somewhat special setup and not what has been tested with gpg (i.e. putty). In particular Cygwin based tools do not interoperate well with non-Cygwin tools.

Oct 28 2022, 3:55 PM · gnupg, Feature Request
werner changed the status of T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address from Open to Testing.
Oct 28 2022, 3:44 PM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner added a comment to T4485: Add AEAD mode AES-GCM-SIV to libgcrypt (RFC 8452).

@jukivili: This has been released with 1.10.0 - shall we close this bug?

Oct 28 2022, 3:42 PM · Feature Request, libgcrypt
werner lowered the priority of T4921: Support import of PKCS#12 encoded ECC private keys. from High to Normal.

Shall we really backport this to 2.2 given that ECC for S/MIME is in most cases a smartcard thing?

Oct 28 2022, 3:38 PM · gnupg22 (gnupg-2.2.42), backport, Feature Request, S/MIME
werner closed T4098: GpgSM: Add ECC support as Resolved.

Has been release quite some time ago (2.3.8 and earlier)

Oct 28 2022, 3:36 PM · gnupg (gpg23), Feature Request, S/MIME
werner added a comment to T4938: Support Signature Card V2.0 (NKS15).

Will be released with 2.3.9

Oct 28 2022, 3:34 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T4938: Support Signature Card V2.0 (NKS15), a subtask of T4098: GpgSM: Add ECC support, as Resolved.
Oct 28 2022, 3:33 PM · gnupg (gpg23), Feature Request, S/MIME
werner closed T4938: Support Signature Card V2.0 (NKS15) as Resolved.
Oct 28 2022, 3:33 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T6252: Support ECC for Netkey cards also in 2.2 as Resolved.
Oct 28 2022, 3:32 PM · gnupg (gpg22), scd, Restricted Project
werner closed T6252: Support ECC for Netkey cards also in 2.2, a subtask of T4938: Support Signature Card V2.0 (NKS15), as Resolved.
Oct 28 2022, 3:32 PM · eIDAS, scd, Feature Request, S/MIME
werner closed T6252: Support ECC for Netkey cards also in 2.2, a subtask of T6253: GpgSM: Backport ECC support to 2.2, as Resolved.
Oct 28 2022, 3:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner changed the status of T6253: GpgSM: Backport ECC support to 2.2, a subtask of T4098: GpgSM: Add ECC support, from Open to Testing.
Oct 28 2022, 3:32 PM · gnupg (gpg23), Feature Request, S/MIME
werner changed the status of T6253: GpgSM: Backport ECC support to 2.2 from Open to Testing.
Oct 28 2022, 3:32 PM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner committed rGb71a14238dd2: gpgsm: Also announce AES256-CBC in signatures. (authored by werner).
gpgsm: Also announce AES256-CBC in signatures.
Oct 28 2022, 3:24 PM
werner committed rG28467f3735f7: sm: Support encryption using ECDH keys. (authored by werner).
sm: Support encryption using ECDH keys.
Oct 28 2022, 3:22 PM
werner committed rGfd0ddf26990d: gpgsm: New compatibility flag "allow-ecc-encr". (authored by werner).
gpgsm: New compatibility flag "allow-ecc-encr".
Oct 28 2022, 3:22 PM
werner committed rGaa397fdcdb21: gpgsm: Also announce AES256-CBC in signatures. (authored by werner).
gpgsm: Also announce AES256-CBC in signatures.
Oct 28 2022, 3:22 PM
werner committed rGd770715e1574: gpgsm: Allow ECC encryption keys with just keyAgreement specified. (authored by werner).
gpgsm: Allow ECC encryption keys with just keyAgreement specified.
Oct 28 2022, 12:18 PM
werner committed rG1cdb67d41a41: gpgsm: Use macro constants for cert_usage_p. (authored by werner).
gpgsm: Use macro constants for cert_usage_p.
Oct 28 2022, 12:18 PM
werner committed rG934bbe67c2c0: scd: Use APP_LEARN_FLAG_KEYPAIRINFO with more apps. (authored by werner).
scd: Use APP_LEARN_FLAG_KEYPAIRINFO with more apps.
Oct 28 2022, 12:18 PM
werner committed rG7ed523ca1332: scd:nks: Support non-ESIGN signing with the Signature Card v2 (authored by werner).
scd:nks: Support non-ESIGN signing with the Signature Card v2
Oct 28 2022, 12:18 PM
werner committed rG12d3b16729b7: scd: Use app_get_slot at more places. (authored by werner).
scd: Use app_get_slot at more places.
Oct 28 2022, 12:18 PM
werner committed rG6fa4143284ef: doc: Make uploading of 2.2 manuals easier (authored by werner).
doc: Make uploading of 2.2 manuals easier
Oct 28 2022, 12:18 PM
ikloecker added a comment to T6149: Kleopatra: Fix (accessibility) issues found while testing with NVDA.
  1. In the Certify dialog the "Advanced" expander lacks a focus indicator.
Oct 28 2022, 12:18 PM · kleopatra, Restricted Project
werner added a comment to T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address.

Fixed for master but not yet tested.

Oct 28 2022, 11:21 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner committed rG0ef54e644f19: gpg: Fix trusted introducer for user-ids with only the mbox. (authored by werner).
gpg: Fix trusted introducer for user-ids with only the mbox.
Oct 28 2022, 11:21 AM
ikloecker added a comment to T6149: Kleopatra: Fix (accessibility) issues found while testing with NVDA.
  1. In the Certificate Details dialog NVDA does not read the labels associated to the key properties when a property gets focus, e.g. it reads the expiration date, but it does not read the label "Valid until".
Oct 28 2022, 11:09 AM · kleopatra, Restricted Project
ikloecker updated subscribers of T6262: Kleopatra: Remove info buttons from Certify dialog.

@aheinecke What do you think about this?

Oct 28 2022, 11:06 AM · Restricted Project, kleopatra
ikloecker created T6262: Kleopatra: Remove info buttons from Certify dialog.
Oct 28 2022, 11:05 AM · Restricted Project, kleopatra
ikloecker committed rPf9e9cdae9b14: qt: Remove focus indication by text selection (authored by ikloecker).
qt: Remove focus indication by text selection
Oct 28 2022, 11:05 AM
ikloecker committed rP9fbecc223cf1: build: Prepare building a Qt6 version of pinentry (authored by ikloecker).
build: Prepare building a Qt6 version of pinentry
Oct 28 2022, 11:05 AM
ikloecker committed rPedc17d497d67: qt: Use same focus indication for labels as Kleopatra (authored by ikloecker).
qt: Use same focus indication for labels as Kleopatra
Oct 28 2022, 11:05 AM
ikloecker committed rP2fa1883d9449: build: Remove unused defines (authored by ikloecker).
build: Remove unused defines
Oct 28 2022, 11:05 AM
ikloecker committed rPda3144a702ac: qt4: Add missing qt4.m4 to tarball (authored by ikloecker).
qt4: Add missing qt4.m4 to tarball
Oct 28 2022, 11:05 AM
ikloecker changed the status of T5863: pinentry-qt: Further improve the accessibility, a subtask of T5845: Kleopatra: Accessibility for file encryption, from Open to Testing.
Oct 28 2022, 10:49 AM · kleopatra, Restricted Project
ikloecker changed the status of T5863: pinentry-qt: Further improve the accessibility from Open to Testing.

This is now ready for testing.

Oct 28 2022, 10:49 AM · pinentry, Restricted Project
werner added a comment to T5542: w32: Values under HKLM ignored if HKCU entry for GnuPG exists.

Is this still an issue or is the new gpgconf -X feature sufficient to detect this case?

Oct 28 2022, 10:00 AM · Windows, gnupg, Restricted Project
werner added a comment to T5778: Wish to add a generic comment or hint to encrypted data.

An outer signature or even a new packet to sign the list of encrypted session keys might also be an option which does not disturb older implementations.

Oct 28 2022, 9:54 AM · gnupg, Restricted Project
werner added a comment to T6081: MSI: Check for GnuPT on installation.

Is that still required wit the new gpgme global flag "inst-type"?

Oct 28 2022, 9:50 AM · Restricted Project, gpg4win
werner moved T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner moved T6252: Support ECC for Netkey cards also in 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg (gpg22), scd, Restricted Project
werner moved T6253: GpgSM: Backport ECC support to 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg22 (gnupg-2.2.42), Restricted Project, Feature Request, S/MIME
werner moved T1235: adding automatic refresh-key from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Oct 28 2022, 9:48 AM · gnupg26, gnupg22, Restricted Project, Feature Request
werner raised the priority of T1235: adding automatic refresh-key from Normal to High.
Oct 28 2022, 9:48 AM · gnupg26, gnupg22, Restricted Project, Feature Request
werner committed rG7aaedfb10767: gpg: Import stray revocation certificates. (authored by werner).
gpg: Import stray revocation certificates.
Oct 28 2022, 9:31 AM
werner lowered the priority of T4612: Add spare space to the keybox to always allow the import of revocations. from Normal to Low.
Oct 28 2022, 9:19 AM · gnupg24, gnupg (gpg23), Bug Report
gniibe committed rGed6eb9019248: agent: Automatically convert to extended key format by KEYATTR. (authored by gniibe).
agent: Automatically convert to extended key format by KEYATTR.
Oct 28 2022, 7:53 AM
gniibe committed rAf85726db8568: fdpassing using pipe works on Windows. (authored by gniibe).
fdpassing using pipe works on Windows.
Oct 28 2022, 5:21 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEOd6ac6d9eb7c9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 28 2022, 4:16 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAde82a4bf39d6: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 28 2022, 4:15 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO3ae3c9dbf2f6: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Oct 28 2022, 3:54 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA373f22ceef88: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Oct 28 2022, 3:53 AM

Oct 27 2022

ikloecker changed the status of T4429: Kleopatra: Offer to generate ECC keys on Smartcards which support it from Open to Testing.

Ready for testing

Oct 27 2022, 6:06 PM · Restricted Project, kleopatra
gniibe committed rA905369a8dfee: testing fdpassing. (authored by gniibe).
testing fdpassing.
Oct 27 2022, 12:37 PM
aheinecke added a subtask for T6259: Kleopatra: Improve startup performance : T4067: Kleopatra, performance: Create a system to use binary resources for i18n.
Oct 27 2022, 12:05 PM · vsd32 (vsd-3.2.0), gnupg, kleopatra, Restricted Project
aheinecke added a parent task for T4067: Kleopatra, performance: Create a system to use binary resources for i18n: T6259: Kleopatra: Improve startup performance .
Oct 27 2022, 12:05 PM · gpg4win, kleopatra
ikloecker added a comment to T6260: gpgconf: Analyze timing on Windows.

Would running the different --list-options in parallel make sense? Or would the block each other?

Oct 27 2022, 11:42 AM · gnupg, kleopatra, Restricted Project
aheinecke triaged T6261: Kleopatra / QGPGME: Use --no-auto-check-trustdb for initial keylisting as Normal priority.
Oct 27 2022, 10:58 AM · gpgme, kleopatra, Restricted Project
aheinecke triaged T6260: gpgconf: Analyze timing on Windows as Normal priority.
Oct 27 2022, 10:54 AM · gnupg, kleopatra, Restricted Project
aheinecke lowered the priority of T6259: Kleopatra: Improve startup performance from High to Normal.
Oct 27 2022, 10:41 AM · vsd32 (vsd-3.2.0), gnupg, kleopatra, Restricted Project
aheinecke added a comment to T4066: Kleopatra, performance: Use icons as a resource.

The issue with rWe06c325a9a29 was that it linked in all breeze icons and nowadays would also link in all breeze-dark icons. Which increased the size of Kleopatra so much that there was no performance gain and the fallbacks were still checked. This might require a fix in Qt / Kiconloader not to use fallbacks and also to only resource up the subset of icons which we actually use and package.

Oct 27 2022, 10:40 AM · vsd32 (vsd-3.2.0), gpg4win, kleopatra
aheinecke added a parent task for T4066: Kleopatra, performance: Use icons as a resource: T6259: Kleopatra: Improve startup performance .
Oct 27 2022, 10:38 AM · vsd32 (vsd-3.2.0), gpg4win, kleopatra
aheinecke added a subtask for T6259: Kleopatra: Improve startup performance : T4066: Kleopatra, performance: Use icons as a resource.
Oct 27 2022, 10:38 AM · vsd32 (vsd-3.2.0), gnupg, kleopatra, Restricted Project
aheinecke triaged T6259: Kleopatra: Improve startup performance as High priority.
Oct 27 2022, 10:38 AM · vsd32 (vsd-3.2.0), gnupg, kleopatra, Restricted Project
aheinecke closed T4081: GPGME performance: Allow single component gpg-conf loads as Resolved.

In QGPGME which is used by GpgOL and Kleopatra we have solved this by loading the configuration only once and then reusing it. I see no need to change something in gpgconf here.

Oct 27 2022, 10:26 AM · gpg4win, gpgme
gniibe added a comment to T6249: gpgrt: spawn functions.

@werner - having another argument might be useful. Indeed, pthread_atfork has three callback functions as its arguments (prepare, parent, and child).

Oct 27 2022, 10:12 AM · gnupg, libassuan, gpgrt
gniibe awarded T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance) a Yellow Medal token.
Oct 27 2022, 9:31 AM · libgcrypt, Feature Request
werner awarded T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance) a Cup of Joe token.
Oct 27 2022, 8:46 AM · libgcrypt, Feature Request
werner added a comment to T6249: gpgrt: spawn functions.

I general I agree.

Oct 27 2022, 8:44 AM · gnupg, libassuan, gpgrt
werner triaged T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent as Normal priority.
Oct 27 2022, 8:27 AM · gnupg, Documentation, ssh
werner triaged T6255: --list-keys output truncated and loops repeatedly as Low priority.

There is a utility named kbxutil which can be sued to dump the pubring.kbx file without any post-processing by gpg. I would check whether there are any other keys after the VideoLAN key. iirc, kbxutil ist not commonly installed; you may need to build the software yourself or copy the pubring.kbx to Linux and check it here.

Oct 27 2022, 8:26 AM · gnupg24, Windows, gnupg (gpg23), can't replicate, Bug Report
gniibe added a comment to T6249: gpgrt: spawn functions.

To have clear semantics, I propose a change to gpgrt_spawn_process_fd (calling SPAWN_CB, instead of AFTER_FORK_CB, and give it return value), and exporting gpgrt_close_all_fds to users.

Oct 27 2022, 7:55 AM · gnupg, libassuan, gpgrt
jukivili closed T6242: libgcrypt: optimize ECB? (as it may be used to estimate library crypto performance) as Resolved.
Oct 27 2022, 5:07 AM · libgcrypt, Feature Request
gniibe added a comment to T6249: gpgrt: spawn functions.

By the commit rE43c1e85fe29a: spawn: Expose spawn functions., spawn functions are exposed now. The API is compatible to the one of internal functions in GnuPG master (2.3).
Semantics is not well-defined portably for:

  • gpgrt_spawn_process: EXCEPT only makes sense in POSIX. User could expect that the API does closing all fds except fds specified by EXCEPT in POSIX.
  • gpgrt_spawn_process_fd: AFTER_FORK_CB only makes sense in POSIX. User could specify the callback so that it can control sigmask, envvar, open/close/dup-ing file descriptors, making sure releasing some resources beforehand, etc.
Oct 27 2022, 4:11 AM · gnupg, libassuan, gpgrt
l10n daemon script <scripty@kde.org> committed rKLEOPATRA98a6953c63ff: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Oct 27 2022, 4:08 AM
gniibe committed rEd3baa17065cb: Fix the comment for _gpgrt_spawn_process_fd, it's a variant. (authored by gniibe).
Fix the comment for _gpgrt_spawn_process_fd, it's a variant.
Oct 27 2022, 4:04 AM
gniibe committed rE43c1e85fe29a: spawn: Expose spawn functions. (authored by gniibe).
spawn: Expose spawn functions.
Oct 27 2022, 4:04 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA02ff92889be8: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Oct 27 2022, 3:50 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA5fc3fe8e9c62: GIT_SILENT made messages (after extraction) (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT made messages (after extraction)
Oct 27 2022, 2:47 AM

Oct 26 2022

jukivili committed rCeab1caae7bd5: sha3-avx512: fix for "x32" target (authored by jukivili).
sha3-avx512: fix for "x32" target
Oct 26 2022, 9:05 PM
jukivili committed rCd078a928f5c6: twofish: accelerate XTS and ECB modes (authored by jukivili).
twofish: accelerate XTS and ECB modes
Oct 26 2022, 9:05 PM
jukivili committed rCb50b7ea5caba: serpent: fix compiler warning on 32-bit ARM (authored by jukivili).
serpent: fix compiler warning on 32-bit ARM
Oct 26 2022, 9:05 PM
jukivili committed rC8a1fe5f78f9f: serpent: accelerate XTS and ECB modes (authored by jukivili).
serpent: accelerate XTS and ECB modes
Oct 26 2022, 9:05 PM
jukivili committed rC14f39993d632: sm4: accelerate ECB (for benchmarking) (authored by jukivili).
sm4: accelerate ECB (for benchmarking)
Oct 26 2022, 9:05 PM
jukivili committed rC6475d0915ffe: camellia: accelerate ECB (for benchmarking) (authored by jukivili).
camellia: accelerate ECB (for benchmarking)
Oct 26 2022, 9:05 PM
jukivili committed rCa43e03ef842b: sm4: fix lookup-table prefetching (authored by jukivili).
sm4: fix lookup-table prefetching
Oct 26 2022, 9:05 PM
jukivili committed rC7c1aa4c9452a: rijndael-vaes: align asm functions (authored by jukivili).
rijndael-vaes: align asm functions
Oct 26 2022, 9:05 PM
jukivili committed rC84f3d41acb23: rijndael: add ECB acceleration (for benchmarking purposes) (authored by jukivili).
rijndael: add ECB acceleration (for benchmarking purposes)
Oct 26 2022, 9:05 PM
jukivili committed rCbf5ec001dfcb: mpi/longlong: update powerpc macros from GCC (authored by jukivili).
mpi/longlong: update powerpc macros from GCC
Oct 26 2022, 9:05 PM
jukivili committed rC4b1cb76e3587: hwf-x86: enable VPGATHER usage for AMD CPUs with AVX512 (authored by jukivili).
hwf-x86: enable VPGATHER usage for AMD CPUs with AVX512
Oct 26 2022, 9:05 PM
jukivili committed rCc0f85e0c8657: sha512-avx512: enable only on Intel CPUs for now (authored by jukivili).
sha512-avx512: enable only on Intel CPUs for now
Oct 26 2022, 9:05 PM
werner committed rM1c9694f8d50b: core: New global flags "inst-type". (authored by werner).
core: New global flags "inst-type".
Oct 26 2022, 12:12 PM
aheinecke committed rKLEOPATRA37815c17b226: Clarify error message for invalid compliance (authored by aheinecke).
Clarify error message for invalid compliance
Oct 26 2022, 11:41 AM
gniibe changed the status of T6002: scute w/ gpg23: Support multiple cards/tokens, major update with KEYGRIP from Open to Testing.
Oct 26 2022, 9:24 AM · Feature Request, scute
gniibe changed the status of T3883: Add Win32-OpenSSH support to gpg-agent's ssh-agent from Open to Testing.
Oct 26 2022, 9:24 AM · Not A Bug, workaround, gnupg24, Windows, ssh
gniibe committed rCb095ea755973: hmac,hkdf: Check the HMAC key length in FIPS mode. (authored by Jakuje).
hmac,hkdf: Check the HMAC key length in FIPS mode.
Oct 26 2022, 8:45 AM
gniibe added a reverting change for rC857e6f467d0f: kdf:pkdf2: Require longer input when FIPS mode.: rC47db7fe3a0c3: Revert "kdf:pkdf2: Require longer input when FIPS mode.".
Oct 26 2022, 8:45 AM
gniibe committed rC47db7fe3a0c3: Revert "kdf:pkdf2: Require longer input when FIPS mode." (authored by Jakuje).
Revert "kdf:pkdf2: Require longer input when FIPS mode."
Oct 26 2022, 8:45 AM