Page MenuHome GnuPG
Feed All Stories

Thu, Jan 19

werner removed a project from T5837: gpg-card: Authenticate to PIV applet with non-3DES card management key: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, scd, Feature Request
werner removed a project from T5897: Fix MinGW compilation error with 'struct _stat32' in common/sysutils.c from gnupg-2.3.4: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, toolchain, Feature Request, patch
werner removed a project from T5930: Use the FIPS-compatible digest&sign API: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, FIPS, Feature Request
werner removed a project from T5964: gnupg should use the KDFs implemented in libgcrypt: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, FIPS, libgcrypt, Feature Request
werner removed a project from T5995: Better prompt with SETKEYDESC: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, ssh, gpgagent, scd
werner removed a project from T6020: Make %-expandos available for --default-keyserver-url: gnupg (gpg23).
Thu, Jan 19, 4:47 PM · gnupg24, Feature Request, Keyserver
werner removed a project from T5998: Extend gpg-check-patter to return a description: gnupg (gpg23).
Thu, Jan 19, 4:46 PM · gnupg24, Feature Request, Restricted Project, gpgagent
werner removed a project from T6014: Failed to search on certificate server. The error returned was: Syntax error in URI.: gnupg (gpg23).
Thu, Jan 19, 4:46 PM · gnupg24, dirmngr, Bug Report
werner removed a project from T6023: Check how GnuPG handles several keys from WKD: gnupg (gpg23).
Thu, Jan 19, 4:46 PM · gnupg24, g10, common, Documentation, wkd
werner removed a project from T6040: Allow embedding preferred keyserver URL in signatures: gnupg (gpg23).
Thu, Jan 19, 4:46 PM · gnupg24, Feature Request, Keyserver
werner removed a project from T6052: gnupg2 tpm2d tests do not work: gnupg (gpg23).
Thu, Jan 19, 4:46 PM · gnupg24, Tests, TPM, Bug Report
werner removed a project from T6191: FIPS: Supporting running FIPS enabled machine: gnupg (gpg23).
Thu, Jan 19, 4:45 PM · gnupg24, FIPS, Bug Report
werner removed a project from T6254: Warn in --recv-keys verbose output that no keys have been imported: gnupg (gpg23).
Thu, Jan 19, 4:45 PM · gnupg24, Keyserver, Bug Report
werner removed a project from T6135: Agent, P15: Insert Smartcard query uses serial number instead of $DISPSERIALNO: gnupg (gpg23).
Thu, Jan 19, 4:45 PM · gnupg24, backport, scd
werner removed a project from T6145: USB device detection by scdaemon: gnupg (gpg23).
Thu, Jan 19, 4:45 PM · gnupg24, scd
werner removed a project from T6179: gnupg 2.3.7 broke YubiKey support: DBG: Curve with OID not supported: 2b06010401da470f01: gnupg (gpg23).
Thu, Jan 19, 4:44 PM · gnupg24, scd, Bug Report
werner removed a project from T6212: The ssh keys are no longer returned in the order from control file after T5996: gnupg (gpg23).
Thu, Jan 19, 4:44 PM · gnupg24, ssh, Feature Request
werner removed a project from T6218: Using Yubikey with GnuPG+scdaemon and PKCS11 over pcscd errors: gnupg (gpg23).
Thu, Jan 19, 4:44 PM · gnupg24, scute, scd, Bug Report
werner removed a project from T6235: Problem editing Expiration Time: gnupg (gpg23).
Thu, Jan 19, 4:44 PM · gnupg24, Feature Request
werner removed a project from T6250: GPG-Agent doesn't work properly with smart cards and ed25519 keys and SSH Agent: gnupg (gpg23).
Thu, Jan 19, 4:44 PM · gnupg24, Documentation, ssh
werner edited projects for T4921: Support import of PKCS#12 encoded ECC private keys., added: gnupg22; removed gnupg (gpg22).
Thu, Jan 19, 4:42 PM · gnupg22, backport, Feature Request, S/MIME
werner closed T6067: dirmngr 2.2 does not ask keyservers for fingerprints, a subtask of T5741: dirmngr does not ask keyservers for fingerprints, as Resolved.
Thu, Jan 19, 4:41 PM · Restricted Project, dirmngr
werner closed T6067: dirmngr 2.2 does not ask keyservers for fingerprints as Resolved.
Thu, Jan 19, 4:41 PM · gnupg (gpg22), Restricted Project, dirmngr
werner closed T6067: dirmngr 2.2 does not ask keyservers for fingerprints, a subtask of T6042: Cannot search on keyserver from kleopatra 3.1.22 inside an AppImage of GnuPG Desktop or GnuPG VS Desktop, as Resolved.
Thu, Jan 19, 4:41 PM · AppImage, gpg4win, Bug Report
werner closed T6238: regexp for trust signature domain restriction does not work if key only has an e-mail address as Resolved.
Thu, Jan 19, 4:41 PM · backport, gnupg (gpg22), Bug Report, Restricted Project
werner closed T6244: GnuPG: GnuPG 2.2.40 LTS FTBFS against new Libgpg-error 1.46 as Resolved.
Thu, Jan 19, 4:40 PM · Windows, gnupg (gpg22), Bug Report
werner moved T6263: Allow OCB encryption in 2.2 from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Thu, Jan 19, 4:39 PM · gnupg22, Restricted Project, Feature Request
werner moved T6263: Allow OCB encryption in 2.2 from Backlog to QA on the gnupg22 board.
Thu, Jan 19, 4:39 PM · gnupg22, Restricted Project, Feature Request
werner edited projects for T6263: Allow OCB encryption in 2.2, added: gnupg22; removed gnupg (gpg22).
Thu, Jan 19, 4:39 PM · gnupg22, Restricted Project, Feature Request
werner closed T4394: Use I/O callbacks in gpgtar as Resolved.

Release quite some time ago.

Thu, Jan 19, 4:38 PM · gnupg (gpg22), gpgtar
werner edited projects for T5795: Kleopatra reader selection and quoting, added: gnupg22; removed gnupg (gpg22).
Thu, Jan 19, 4:37 PM · gnupg22, Restricted Project, kleopatra
werner edited projects for T6253: GpgSM: Backport ECC support to 2.2, added: gnupg22; removed gnupg (gpg22).
Thu, Jan 19, 4:35 PM · gnupg22, Restricted Project, Feature Request, S/MIME
werner moved T6253: GpgSM: Backport ECC support to 2.2 from Backlog to For next release on the gnupg (gpg22) board.
Thu, Jan 19, 4:34 PM · gnupg22, Restricted Project, Feature Request, S/MIME
werner committed rGe28b6c301d0b: doc: Revert last change the gpg --unwrap description (authored by werner).
doc: Revert last change the gpg --unwrap description
Thu, Jan 19, 4:31 PM
ebo created T6350: Kleopatra: disable trust change on not certified keys.
Thu, Jan 19, 4:31 PM · kleopatra, Restricted Project
werner moved T6332: GPG: Extend / rework "is_file_compressed" from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Thu, Jan 19, 4:22 PM · gnupg22, gnupg24, Restricted Project
werner moved T6332: GPG: Extend / rework "is_file_compressed" from WiP to QA on the gnupg22 board.
Thu, Jan 19, 4:21 PM · gnupg22, gnupg24, Restricted Project
werner moved T6348: gpgtar: Error when using --status-fd from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Thu, Jan 19, 4:21 PM · gnupg, Restricted Project
werner committed rG6df8a513dc04: common: Detect PNG and JPEG file formats. (authored by werner).
common: Detect PNG and JPEG file formats.
Thu, Jan 19, 4:19 PM
werner committed rGce8ffd71b724: gpg: Detect already compressed data also when using a pipe. (authored by werner).
gpg: Detect already compressed data also when using a pipe.
Thu, Jan 19, 4:19 PM
werner committed rGca822a233999: common: Replace all assert in iobuf by log_assert. (authored by werner).
common: Replace all assert in iobuf by log_assert.
Thu, Jan 19, 4:19 PM
werner committed rG417e8588f3ef: gpgtar: Make --status-fd option for fds > 2 work (authored by werner).
gpgtar: Make --status-fd option for fds > 2 work
Thu, Jan 19, 4:19 PM
werner edited projects for T1825: Add a re-encrypt to additional key, added: gnupg24; removed gnupg.
Thu, Jan 19, 3:32 PM · gnupg24, Feature Request
aheinecke added a comment to T6332: GPG: Extend / rework "is_file_compressed".

Great! But as mentioned I would like to have a setting in Kleo to explicitly disable compression, GPGME_ENCRYPT_NO_COMPRESS. But that is a different task.

Thu, Jan 19, 12:16 PM · gnupg22, gnupg24, Restricted Project
werner committed rG9a50be0d05c9: common: Detect PNG and JPEG file formats. (authored by werner).
common: Detect PNG and JPEG file formats.
Thu, Jan 19, 11:28 AM
werner edited projects for T6334: Remove or explain sha1sum in announcement mails, added: dev.gnupg.org; removed gnupg24.
Thu, Jan 19, 10:55 AM · dev.gnupg.org, Feature Request
werner changed the status of T6332: GPG: Extend / rework "is_file_compressed" from Open to Testing.
Thu, Jan 19, 10:54 AM · gnupg22, gnupg24, Restricted Project
werner moved T6332: GPG: Extend / rework "is_file_compressed" from Backlog to WiP on the gnupg22 board.
Thu, Jan 19, 10:54 AM · gnupg22, gnupg24, Restricted Project
werner edited projects for T6332: GPG: Extend / rework "is_file_compressed", added: gnupg24, gnupg22; removed gnupg.
Thu, Jan 19, 10:54 AM · gnupg22, gnupg24, Restricted Project
werner committed rG227c78ce0e4d: wkd: Let gpg-wks-client --supported print some diagnostics. (authored by werner).
wkd: Let gpg-wks-client --supported print some diagnostics.
Thu, Jan 19, 10:53 AM
werner added a comment to T6332: GPG: Extend / rework "is_file_compressed".

The compression check currently detects bzip2, gzip, zip, pkzip, and PDF. This also covers common document formats like odt and docx. We may add some more detection in the future. However, for large files you usually know their type and thus you better use "-z0" for already compressed data or "-z-1" if you want to force compression (may be for PDFs which often can be a shrinked to 80% or so).

Thu, Jan 19, 10:49 AM · gnupg22, gnupg24, Restricted Project
werner committed rG60963d98cfd8: gpg: Detect already compressed data also when using a pipe. (authored by werner).
gpg: Detect already compressed data also when using a pipe.
Thu, Jan 19, 10:48 AM
werner committed rG94ae43be3636: common: Replace all assert by log_assert. (authored by werner).
common: Replace all assert by log_assert.
Thu, Jan 19, 10:48 AM
werner closed T6349: need to add the judgment of invalid handles in _gcry_md_ctl? as Wontfix.

Sorry, but we can't check all parameters. Why only check that one and not the others or invalid values for ctx. You may do such checks in an interactive environment but not for a general library.

Thu, Jan 19, 9:27 AM · libgcrypt

Wed, Jan 18

bigmomma added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

So here is a redacted CLI-dump of the exact sequence I'm describing in my post. This is with untweaked keys and gpg 2.2.40 and a factory-reset yubikey.

Wed, Jan 18, 6:30 PM · Support, gnupg, OpenPGP
ikloecker added a comment to T4066: Kleopatra, performance: Use icons as a resource.

The timestamp problem may be fixed by moving the line

File ${prefix}/share/icons/breeze/icon-theme.cache

(and any other lines installing an icon-theme.cache) at the end of inst-breeze-icons.nsi (or the corresponding inst-*.nsi file).

Wed, Jan 18, 6:09 PM · gpg4win, kleopatra
ikloecker added a comment to T4066: Kleopatra, performance: Use icons as a resource.

I just learned that

Qt will make use of GTK's icon-theme.cache if present to speed up the lookup.

https://doc.qt.io/qt-5/qicon.html#fromTheme

Wed, Jan 18, 6:01 PM · gpg4win, kleopatra
aheinecke added a comment to T4066: Kleopatra, performance: Use icons as a resource.

So on Linux, this looks quite differently.

Wed, Jan 18, 4:53 PM · gpg4win, kleopatra
aheinecke claimed T6344: Kleopatra, GPG: AboutData ctor on Windows takes too long.

I would like to take this on myself by creating a gpgversioninfo class which will have signal / slot based API for both the SWDB Query and the version checks, both currently delay the startup too much.

Wed, Jan 18, 4:29 PM · kleopatra, Restricted Project
bigmomma added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

So in case this was not clear... What I'm describing is very similar to the original description, but it is "inverted" - the untweaked key works flawlessly (import and decryption) except for keytocard. And the tweaked key can't be imported - either "Bad Secret Key" or asking for passphrase.

Wed, Jan 18, 3:38 PM · Support, gnupg, OpenPGP
aheinecke added a comment to T6259: Kleopatra: Improve startup performance .

I am somehwat confused, my symantec system got faster. But there are some things like "Symantec Insight" which will whitelist often used files and applications, also signed files might get preferred treatment. I tried to get this slower by disabling the "Insight" and changing the "Bloodhound behavior" to agressive... So timings might not be comparable. I should probably do tests ohne without restarting my systems for a good comparison.

Wed, Jan 18, 3:36 PM · gnupg, kleopatra, Restricted Project
bigmomma added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

@onickolay Yes, I have. I have used --check-cv25519-bits and it said that it needs patching. I then did --fix-cv25519-bits and exported the key. Looking at the CV25519 private-key bytes produced by my code and by RNP, I confirmed that they did the exact same transformation.
When trying to re-import the exported key into gpg, I got the "Bad Secret Key" error again

Wed, Jan 18, 3:27 PM · Support, gnupg, OpenPGP
onickolay added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

@bigmomma Just for a quick check - did you try to use RNP's CLI command --edit-key --fix-cv25519-bits, as it's not clear from the message?

Wed, Jan 18, 3:17 PM · Support, gnupg, OpenPGP
bigmomma added a comment to T5464: Failure to import Curve25519 ECDH secret subkey to the GnupG..

Hi! I would like to chime in on this issue as I am having some weird problems with a CV25519 sub-key and after stumbling upon this thread, I think it is related to this.
Unfortunately, I can't post the key material here, because it is my actual encryption private-key.

Wed, Jan 18, 3:12 PM · Support, gnupg, OpenPGP
bernhard updated subscribers of T6297: PyPI GPG package.

Yes I am an admin on the https://pypi.org/project/gpg/ package.

Wed, Jan 18, 2:27 PM · gpgme
aheinecke moved T6338: kleo: Japanese Translation from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Wed, Jan 18, 12:23 PM · Restricted Project, kleopatra, Bug Report
aheinecke changed the status of T6338: kleo: Japanese Translation, a subtask of T6337: libkleo: Japanese Translation, from Open to Testing.
Wed, Jan 18, 12:23 PM · kleopatra, Bug Report
aheinecke changed the status of T6338: kleo: Japanese Translation from Open to Testing.

Commited with revision 1642622.

Wed, Jan 18, 12:23 PM · Restricted Project, kleopatra, Bug Report
aheinecke closed T6337: libkleo: Japanese Translation as Resolved.

I am closing this now, as we now should have complete kleopatra translation and can just move one of them to testing.

Wed, Jan 18, 12:21 PM · kleopatra, Bug Report
zhengxiaoxiaoGithub added a comment to T6349: need to add the judgment of invalid handles in _gcry_md_ctl?.

Wed, Jan 18, 11:10 AM · libgcrypt
zhengxiaoxiaoGithub created T6349: need to add the judgment of invalid handles in _gcry_md_ctl?.
Wed, Jan 18, 11:09 AM · libgcrypt
werner changed the status of T6348: gpgtar: Error when using --status-fd from Open to Testing.

This can be easily tested using

Wed, Jan 18, 10:47 AM · gnupg, Restricted Project
werner changed the status of T6348: gpgtar: Error when using --status-fd, a subtask of T6342: GPGME/Kleopatra: Extend gpgme to use gpgtar, from Open to Testing.
Wed, Jan 18, 10:47 AM · Restricted Project, gpgme, kleopatra
werner moved T6348: gpgtar: Error when using --status-fd from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Wed, Jan 18, 10:45 AM · gnupg, Restricted Project
werner committed rGf79d9b9310cf: gpgtar: Make --status-fd option for fds > 2 work (authored by werner).
gpgtar: Make --status-fd option for fds > 2 work
Wed, Jan 18, 10:43 AM
werner triaged T6297: PyPI GPG package as Low priority.
Wed, Jan 18, 10:19 AM · gpgme
werner updated subscribers of T6297: PyPI GPG package.

No more logs. My understaning is that the pypi ownershipof the project has been transferred to @bernhard

Wed, Jan 18, 10:18 AM · gpgme
aheinecke moved T6259: Kleopatra: Improve startup performance from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Wed, Jan 18, 10:17 AM · gnupg, kleopatra, Restricted Project
aheinecke moved T6346: Kleopatra: Run self test only at the first start on windows from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Wed, Jan 18, 10:17 AM · kleopatra, Restricted Project
ikloecker triaged T6348: gpgtar: Error when using --status-fd as High priority.
Wed, Jan 18, 9:57 AM · gnupg, Restricted Project
ikloecker closed T6347: gpgtar needs to support a few more general command line args to be usable by gpgme, a subtask of T6342: GPGME/Kleopatra: Extend gpgme to use gpgtar, as Resolved.
Wed, Jan 18, 9:50 AM · Restricted Project, gpgme, kleopatra
ikloecker closed T6347: gpgtar needs to support a few more general command line args to be usable by gpgme as Resolved.

Instead of using --enable-special-filenames and a separate FD the list of files is now passed to gpgtar's stdin. Similarly, we read from gpgtar's stderr instead of using a separate --logger-fd.

Wed, Jan 18, 9:50 AM · gnupg, Restricted Project
l10n daemon script <scripty@kde.org> committed rLIBKLEO76696297f10b: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Wed, Jan 18, 3:16 AM

Tue, Jan 17

aheinecke merged T4180: Kleopatra: Crash when decrypting large archives into T5478: Kleopatra: Performance problems decrypting and encrypting large Archives.
Tue, Jan 17, 1:18 PM · Restricted Project, gpgme, kleopatra
aheinecke merged task T4180: Kleopatra: Crash when decrypting large archives into T5478: Kleopatra: Performance problems decrypting and encrypting large Archives.
Tue, Jan 17, 1:18 PM · Bug Report, kleopatra, gpg4win
aheinecke added a comment to T4180: Kleopatra: Crash when decrypting large archives.

I am pretty sure that this was related to issues we found when analyzing another crash / hang with Kleopatra. In T5478 we are currently reworking how we handle archives completely. This will fix this issue, too.

Tue, Jan 17, 1:18 PM · Bug Report, kleopatra, gpg4win
aheinecke merged T5475: Kleopatra: Crash when decrypting large archives into T5478: Kleopatra: Performance problems decrypting and encrypting large Archives.
Tue, Jan 17, 1:17 PM · Restricted Project, gpgme, kleopatra
aheinecke merged task T5475: Kleopatra: Crash when decrypting large archives into T5478: Kleopatra: Performance problems decrypting and encrypting large Archives.
Tue, Jan 17, 1:17 PM · kleopatra
aheinecke added a comment to T5475: Kleopatra: Crash when decrypting large archives.

I am pretty sure that this was the issue we had analyzed with QProcess. Where the fix will be T5478 that will rework how Kleo handles archives altogether.

Tue, Jan 17, 1:16 PM · kleopatra
aheinecke closed T4823: Test Yubikey's support for ed25519 as Resolved.

I am very sure that this is resolved and we support that in Kleopatra.

Tue, Jan 17, 1:10 PM · gnupg24, gnupg (gpg23), yubikey
gniibe committed rPTHbd356d823944: POSIX: Don't include unused symbols in the version control. (authored by gniibe).
POSIX: Don't include unused symbols in the version control.
Tue, Jan 17, 11:39 AM
gniibe accepted D564: Remove non-symbol npth_sigmask/npth_sigwait.
Tue, Jan 17, 5:59 AM
gniibe added a comment to D564: Remove non-symbol npth_sigmask/npth_sigwait.

Thank you for the patch.

Tue, Jan 17, 5:59 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO9512f2a50333: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Jan 17, 5:05 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA2c33d00bb581: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Jan 17, 4:59 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA5cc49a4557fc: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Tue, Jan 17, 4:46 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO3506c84bf526: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Jan 17, 3:40 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA39570895fa7d: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Tue, Jan 17, 3:36 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA3f7f73b3d084: SVN_SILENT made messages (.desktop file) - always resolve ours (authored by l10n daemon script <scripty@kde.org>).
SVN_SILENT made messages (.desktop file) - always resolve ours
Tue, Jan 17, 3:03 AM

Mon, Jan 16

MaskRay added reviewers for D564: Remove non-symbol npth_sigmask/npth_sigwait: gniibe, werner.
Mon, Jan 16, 8:00 PM