Page MenuHome GnuPG
Feed All Stories

Feb 12 2015

aheinecke set Version to master on T1838: Dirmngr ldap CRL checks leave zombie dirmngr_ldap processes (2.1.x).
Feb 12 2015, 5:04 PM · Duplicate, gnupg, Bug Report, dirmngr
aheinecke claimed T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra.
Feb 12 2015, 4:56 PM · uiserver, kleopatra, gpgol, Bug Report
acastong added a comment to T1832: gpg --send-keys fails silently if keyserver unavailable.

To reproduce using version 2.0.26 (on Windows):

  1. Set your keyserver to something invalid (ie. put the following line in your

gpg.conf, without any other keyserver entries:

keyserver hkp://invalid.gnupg.net

  1. Try to retrieve the key 82058954 (from john doe) from the server: gpg --recv-keys 82058954

This should report that no key has been found. What it *should* report is that
there was a communication problem with the servier.

  1. Revert to a vali keyserver destination in your gpg.conf

keyserver hkp://keys.gnupg.net

  1. Perform the recv operation again, it should successfully load the key gpg --recv-keys 82058954
  1. Reset your server to an invali value and perform the following operation: gpg --send-keys 82058954

The application will with the message that it is sending the key to
invalid.gnupg.net, wnen in fact it is not

Feb 12 2015, 12:56 PM · gnupg (gpg14), backport, Bug Report, gnupg
kjathome added projects to T1837: GPGOL causes Outlook to crash: gpgol, Bug Report.
Feb 12 2015, 12:56 PM · Bug Report, gpgol
kjathome set Version to 1.2.1 on T1837: GPGOL causes Outlook to crash.
Feb 12 2015, 12:56 PM · Bug Report, gpgol
kjathome added a comment to T1837: GPGOL causes Outlook to crash.

Feb 12 2015, 12:56 PM · Bug Report, gpgol

Feb 11 2015

werner renamed T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra from gpg4win: Localization "Bis" instead of "To" to gpg4win: Localization "Bis" instead of "To" in Kleopatra.
Feb 11 2015, 7:00 PM · uiserver, kleopatra, gpgol, Bug Report
werner added projects to T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra: kleopatra, uiserver.
Feb 11 2015, 7:00 PM · uiserver, kleopatra, gpgol, Bug Report
werner added a comment to T1835: [doc] Another use case for --show-session-key.

Good point. I added your suggestion to master.

Feb 11 2015, 12:22 PM · gnupg
werner added a project to T1831: Remove gpgkey2ssh, source and build target: Stalled.
Feb 11 2015, 12:16 PM · gnupg, Feature Request
werner added a comment to T1831: Remove gpgkey2ssh, source and build target.

This will eventually be done but not right now. I keep this bug report as a
reminder.

I granted you permissions to edit other bug reports. However, this patch is not
required.

Feb 11 2015, 12:16 PM · gnupg, Feature Request
werner closed T1830: Use https for links in documentation. as Resolved.
Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a project to T1830: Use https for links in documentation.: gnupg.
Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a comment to T1830: Use https for links in documentation..

I just changed the remaining http references to gnupg.org to https (on master).
Thanks.
Changing them in coments and in the outdated FAQ does not make sense.

Feb 11 2015, 12:13 PM · gnupg, Feature Request
werner added a project to T1833: Add support for JSON output: Won't Fix.
Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request
werner closed T1833: Add support for JSON output as Resolved.
Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request
werner added a comment to T1833: Add support for JSON output.

Nope. See my comments at
https://lists.gnupg.org/pipermail/gnupg-users/2015-February/052401.html

Feb 11 2015, 12:00 PM · Won't Fix, gnupg, Feature Request
werner added a project to T1829: Excessive memory use on --import of crafted file: In Progress.
Feb 11 2015, 11:58 AM · backport, gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1829: Excessive memory use on --import of crafted file.

master (2.1) already has limits for such cases and would thus return better
error message. Those will be backported to 1.4 and 2.0. However, for 2.1 your
test case does not work because PGP-2 formats are not anymore supported in 2.1.

Feb 11 2015, 11:58 AM · backport, gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1832: gpg --send-keys fails silently if keyserver unavailable.

I can't repeat that with the current version from the GIT repositories. Can you
please give an example best using --recv-key.

Feb 11 2015, 11:53 AM · gnupg (gpg14), backport, Bug Report, gnupg
werner added a project to T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7: In Progress.
Feb 11 2015, 11:43 AM · Bug Report, gnupg
werner added a comment to T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7.

Thanks for the new test vector. This has already been fixed in master and those
fixes will be ported back to 2.0 and 1.4.

In general I would suggest to use at least the latest released version or even
better the respective GIT HEAD for fuzzing work.

Feb 11 2015, 11:43 AM · Bug Report, gnupg
werner added a project to T1836: gpg-agent --no-detach breaks pinentry-curses, pinentry-tty: pinentry.
Feb 11 2015, 11:38 AM · Too Old, Info Needed, Bug Report, pinentry

Feb 9 2015

MattG added a project to T1836: gpg-agent --no-detach breaks pinentry-curses, pinentry-tty: Bug Report.
Feb 9 2015, 3:58 PM · Too Old, Info Needed, Bug Report, pinentry

Feb 8 2015

elyagsod added a project to T1835: [doc] Another use case for --show-session-key: gnupg.
Feb 8 2015, 12:42 PM · gnupg

Feb 7 2015

JodieC added a comment to T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7.

Feb 7 2015, 10:47 PM · Bug Report, gnupg
JodieC added projects to T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7: gnupg, Bug Report.
Feb 7 2015, 10:47 PM · Bug Report, gnupg
JodieC set Version to 2.0.22 on T1834: Excessive CPU use on --import of fuzzed file - 0069f7d7.
Feb 7 2015, 10:47 PM · Bug Report, gnupg
xvilka added projects to T1833: Add support for JSON output: Feature Request, gnupg.
Feb 7 2015, 10:31 PM · Won't Fix, gnupg, Feature Request
acastong added projects to T1832: gpg --send-keys fails silently if keyserver unavailable: gnupg, Bug Report.
Feb 7 2015, 7:13 PM · gnupg (gpg14), backport, Bug Report, gnupg
acastong set Version to 2.0.26 on T1832: gpg --send-keys fails silently if keyserver unavailable.
Feb 7 2015, 7:13 PM · gnupg (gpg14), backport, Bug Report, gnupg
Jan-Oliver_Wagner added a comment to T1831: Remove gpgkey2ssh, source and build target.

Feb 7 2015, 3:21 PM · gnupg, Feature Request
Jan-Oliver_Wagner added projects to T1831: Remove gpgkey2ssh, source and build target: Feature Request, gnupg.
Feb 7 2015, 3:21 PM · gnupg, Feature Request
Jan-Oliver_Wagner added a comment to T1830: Use https for links in documentation..

D282: 546_0001-Use-https-for-links-in-documentation.patch

Feb 7 2015, 2:35 PM · gnupg, Feature Request
Jan-Oliver_Wagner added a project to T1830: Use https for links in documentation.: Feature Request.
Feb 7 2015, 2:33 PM · gnupg, Feature Request

Feb 6 2015

JodieC added a comment to T1829: Excessive memory use on --import of crafted file.

Feb 6 2015, 3:19 AM · backport, gnupg (gpg14), Bug Report, gnupg
JodieC set Version to 2.0.22 on T1829: Excessive memory use on --import of crafted file.
Feb 6 2015, 3:19 AM · backport, gnupg (gpg14), Bug Report, gnupg
JodieC added projects to T1829: Excessive memory use on --import of crafted file: gnupg, Bug Report.
Feb 6 2015, 3:19 AM · backport, gnupg (gpg14), Bug Report, gnupg

Feb 5 2015

elfindreams added a comment to T1828: card-edit/fetch assumes signing key is master key and fails if not.

Here is the latter half of the output of --card-status in it's entirety...

The URL is listed, as for the signature key, that is the crux of the
problem... it shouldn't care about what the fingerprint of the signature key
when retrieving the public key when the signature key is a subkey as you
can't retrieve just the public key of the subkey, you need to retrieve the
public key of the master key that contains that subkey.

Note below how key 757C0180 is the master key and in the error message in
the op it is looking for AEB99527 which is the signing subkey.

Name of cardholder: John Tennyson
Language prefs ...: en
Sex ..............: male
URL of public key :
https://gist.githubusercontent.com/aelana/0cde322d66206ea5fb90/raw/1cc31e99f
bdb5a75e4104fe597794ec3dccd6bc4/gistfile1.txt
Login data .......: elfindreams
Signature PIN ....: forced
Key attributes ...: 2048R 2048R 2048R
Max. PIN lengths .: 127 127 127
PIN retry counter : 3 3 3
Signature counter : 0
Signature key ....: 85D5 A0DA 4EC2 B038 128F 9D88 4791 2162 AEB9 9527

created ....: 2015-02-03 21:18:19

Encryption key....: 3AD4 1BA6 47B9 1AA3 89CD C29E A6CF 5D5D CADC 0F35

created ....: 2015-02-03 21:18:48

Authentication key: D61E 29B6 9784 15A9 CEFE 08F4 6AD2 1E6C C40C A003

created ....: 2015-02-03 21:19:08

General key info..: pub 2048R/AEB99527 2015-02-03 Elvish Wanderer
<aelana@elfindreams.com>
sec# 4096R/757C0180 created: 2015-02-03 expires: 2015-11-30
ssb> 2048R/AEB99527 created: 2015-02-03 expires: 2015-11-30

card-no: 0006 03362156

ssb> 2048R/CADC0F35 created: 2015-02-03 expires: 2015-11-30

card-no: 0006 03362156

ssb> 2048R/C40CA003 created: 2015-02-03 expires: 2015-11-30

card-no: 0006 03362156
Feb 5 2015, 2:54 PM · Bug Report, gnupg
werner added a comment to T1828: card-edit/fetch assumes signing key is master key and fails if not.

What did you put into the URL field of your card and what is the first
fingerprint:

gpg --card-status | grep ^URL
gpg --card-status | grep '^Signature key'
Feb 5 2015, 12:06 PM · Bug Report, gnupg

Feb 4 2015

elfindreams set Version to 2.0.26 on T1828: card-edit/fetch assumes signing key is master key and fails if not.
Feb 4 2015, 4:29 PM · Bug Report, gnupg
elfindreams added projects to T1828: card-edit/fetch assumes signing key is master key and fails if not: gnupg, Bug Report.
Feb 4 2015, 4:29 PM · Bug Report, gnupg
werner added a project to T1818: gnupg fails (buffer overflow detected) to encrypt archive when called from duplicity: Info Needed.
Feb 4 2015, 9:24 AM · Info Needed, gnupg, gnupg (gpg14), Bug Report, Debian
werner added projects to T1827: Allow to batch up key refreshs in dirmngr: dirmngr, Feature Request, gnupg.
Feb 4 2015, 9:23 AM · gnupg, Feature Request, dirmngr

Feb 3 2015

rb added a comment to T1826: Cannot decrypt (PGP-MIME) message from Enigmail.

Feb 3 2015, 11:30 AM · Feature Request, gpg4win, gpgol
rb added projects to T1826: Cannot decrypt (PGP-MIME) message from Enigmail: gpgol, Bug Report.
Feb 3 2015, 11:29 AM · Feature Request, gpg4win, gpgol
rb removed a project from T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra: gpg4win.
Feb 3 2015, 11:23 AM · uiserver, kleopatra, Bug Report, gpgol
rb added a project to T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra: gpgol.
Feb 3 2015, 11:23 AM · uiserver, kleopatra, Bug Report, gpgol

Feb 2 2015

werner added projects to T1825: Add a re-encrypt to additional key: Feature Request, gnupg.
Feb 2 2015, 6:32 PM · gpd5x (gpd-5.0.0), gnupg26, Feature Request
rb added a project to T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra: gpg4win.
Feb 2 2015, 5:55 PM · uiserver, kleopatra, Bug Report, gpgol
rb added a comment to T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra.

Feb 2 2015, 5:51 PM · uiserver, kleopatra, Bug Report, gpgol
rb added a project to T1824: gpg4win: Localization "Bis" instead of "To" in Kleopatra: Bug Report.
Feb 2 2015, 5:51 PM · uiserver, kleopatra, Bug Report, gpgol

Jan 29 2015

werner closed T1822: gpg --list-config --with-colons output is broken in 2.1.1 as Resolved.
Jan 29 2015, 9:19 AM · Bug Report
werner added a comment to T1822: gpg --list-config --with-colons output is broken in 2.1.1.

Fixed with commit d8eea25

Jan 29 2015, 9:19 AM · Bug Report

Jan 28 2015

werner added a comment to T1823: parse-packet.c DoS using badly encoded MPIs..

Fixed for 2.1 with 382ba4b.Should be backported to 2.0 and 1.4.

Jan 28 2015, 8:49 PM · Bug Report, gnupg
werner added a project to T1823: parse-packet.c DoS using badly encoded MPIs.: backport.
Jan 28 2015, 8:49 PM · Bug Report, gnupg
werner added projects to T1823: parse-packet.c DoS using badly encoded MPIs.: In Progress, gnupg, Bug Report.
Jan 28 2015, 8:32 PM · Bug Report, gnupg
dkg added a comment to T1822: gpg --list-config --with-colons output is broken in 2.1.1.

Jason Donenfeld has a patch for this:

http://thread.gmane.org/gmane.comp.encryption.gpg.devel/19654

Jan 28 2015, 5:14 PM · Bug Report
dkg added a project to T1822: gpg --list-config --with-colons output is broken in 2.1.1: Bug Report.
Jan 28 2015, 5:11 PM · Bug Report
dkg set Version to 2.1.1 on T1822: gpg --list-config --with-colons output is broken in 2.1.1.
Jan 28 2015, 5:11 PM · Bug Report
werner lowered the priority of T1821: cannot specify secret key to decrypt msg with multiple recipients from Normal to Wishlist.
Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg
werner removed a project from T1821: cannot specify secret key to decrypt msg with multiple recipients: Bug Report.
Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg
werner added projects to T1821: cannot specify secret key to decrypt msg with multiple recipients: Feature Request, Won't Fix.
Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg
werner added a comment to T1821: cannot specify secret key to decrypt msg with multiple recipients.

You have the problem only if hidden recipients are used. With 2.1 you
may use this option:

  --try-secret-key name

    For hidden recipients GPG needs to know the keys to use for trial
    decryption.  The key set with --default-key is always tried first,
    but this is often not sufficient.  This option allows to set more
    keys to be used for trial decryption.  Although any valid user-id
    specifica- tion may be used for name it makes sense to use at
    least the long keyid to avoid ambiguities.  Note that gpg-agent
    might pop up a pinentry for a lot keys to do the trial decryption.
    If you want to stop all further trial decryption you may use
    close-window button instead of the cancel button.

This won't be backported to 2.0.

Jan 28 2015, 11:23 AM · Won't Fix, Feature Request, gnupg
werner closed T1820: error sending to agent: No passphrase given (empty password) as Invalid.
Jan 28 2015, 11:10 AM · Bug Report, gnupg
werner removed a project from T1820: error sending to agent: No passphrase given (empty password): Bug Report.
Jan 28 2015, 11:10 AM · Bug Report, gnupg
werner lowered the priority of T1820: error sending to agent: No passphrase given (empty password) from Unbreak Now! to Normal.
Jan 28 2015, 11:10 AM · Bug Report, gnupg
werner added a comment to T1820: error sending to agent: No passphrase given (empty password).

This is not a bug. You need to install a Pinentry and adjust for the changes in
2.1. Please check with ArchLinux or ask at gnupg-users.

Jan 28 2015, 11:10 AM · Bug Report, gnupg

Jan 27 2015

werner added a comment to T1780: check failure -- FAIL: pipeconnect.

Can you please lookup the description or the symbol for the ERRNO value 141 ?
find /usr/include -name errno.h | xargs grep 141
might reveal it.

Jan 27 2015, 5:29 PM · Info Needed, Bug Report, libassuan
werner added a project to T1780: check failure -- FAIL: pipeconnect: Info Needed.
Jan 27 2015, 5:29 PM · Info Needed, Bug Report, libassuan
tanner set Version to 2.0.26 on T1821: cannot specify secret key to decrypt msg with multiple recipients.
Jan 27 2015, 5:00 PM · Won't Fix, Feature Request, gnupg
tanner added projects to T1821: cannot specify secret key to decrypt msg with multiple recipients: gnupg, Bug Report.
Jan 27 2015, 5:00 PM · Won't Fix, Feature Request, gnupg
C0NPAQ added projects to T1820: error sending to agent: No passphrase given (empty password): gnupg, Bug Report.
Jan 27 2015, 1:37 PM · Bug Report, gnupg
C0NPAQ set Version to 2.1.1-1 (archlinux 64bit) on T1820: error sending to agent: No passphrase given (empty password).
Jan 27 2015, 1:37 PM · Bug Report, gnupg
werner added a comment to T1817: Changing expiration on subkeys breaks subkeys.

But the secret subkeys are not used. Or well, the keyflags should be taken from
the public key. That might not always be the case - in particular not if you
re-create the public key from the secret key.

You can of course repair it using 2.1 because there --export-secret-key takes
the public key and only adds the secret parameters.

Jan 27 2015, 12:27 PM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
jas added a comment to T1817: Changing expiration on subkeys breaks subkeys.

What's not clear to me if it is possible to recover a private key that is
damaged this way? If you change expiration with 1.4, the self-signatures are
lost and some key flags are changed. Is it possible to recover from that? That
is the problem I'm concerned with -- if it isn't possible to recover, it seems
people end up with damaged secret subkeys after changing expiration date on a
subkey with gnupg 1.4/2.0.

Jan 27 2015, 11:54 AM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
werner added a project to T1817: Changing expiration on subkeys breaks subkeys: Stalled.
Jan 27 2015, 9:09 AM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
werner added projects to T1817: Changing expiration on subkeys breaks subkeys: maybe, gnupg (gpg14).
Jan 27 2015, 9:09 AM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
werner removed a project from T1817: Changing expiration on subkeys breaks subkeys: Won't Fix.
Jan 27 2015, 9:09 AM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
werner added a comment to T1817: Changing expiration on subkeys breaks subkeys.

I just verified that it is not a problem in 2.1.

I am not sure whether it makes sense to fix it in 1.4 given that it is easier to
change it with 2.1, export and import it then to 1.4. I feel it is better to
use my time to fix some missing export options in 2.1

Jan 27 2015, 9:08 AM · Won't Fix, gnupg (gpg20), gnupg (gpg14), Bug Report, gnupg
werner added projects to T1818: gnupg fails (buffer overflow detected) to encrypt archive when called from duplicity: gnupg (gpg14), gnupg.
Jan 27 2015, 8:42 AM · Info Needed, gnupg, gnupg (gpg14), Bug Report, Debian

Jan 26 2015

werner added a comment to T1064: gpgsm: manual page misses to document options.

Should be fixed by commit 017c6f8fba9ae141a46084d6961ba60c4230f97a
on 2014-06-24.

Jan 26 2015, 2:59 PM · backport, gnupg, Debian, Feature Request
werner closed T1064: gpgsm: manual page misses to document options as Resolved.
Jan 26 2015, 2:59 PM · backport, gnupg, Debian, Feature Request
werner removed a project from T1715: warn when primary key expiration updated without encryption-capable subkey: In Progress.
Jan 26 2015, 2:57 PM · backport, Bug Report, gnupg
werner closed T1715: warn when primary key expiration updated without encryption-capable subkey as Resolved.
Jan 26 2015, 2:57 PM · backport, Bug Report, gnupg
werner added a comment to T1715: warn when primary key expiration updated without encryption-capable subkey.

Backported to 2.0: commit 2424028.

Jan 26 2015, 2:57 PM · backport, Bug Report, gnupg
werner added a comment to T1811: Own key's validity gets set from ultimate to undef when signing a key that signed you.

All release tags are signed.

Signed commits are a bit cumbersome becuase I would have to insert the smartcard
for all commits. Signing with my on-disk standard key would be possible, though.

Jan 26 2015, 8:59 AM · gnupg, Bug Report

Jan 23 2015

js added a comment to T1811: Own key's validity gets set from ultimate to undef when signing a key that signed you.

Ok, I'll give it a try with 09e8f35d3808d6e49f891360c341aae3869e8650 this weekend.

Regarding https: Yes, this is more security, even though only slightly as you will have
to trust CAs. Without it, an attacker could just give you a different repo and you'd
never notice if you don't compare commit checksums with someone else. Then again, that
someone else could also get the wrong repo, because your government decided that
everybody should get a backdoor'd GPG. With https, you also need to get a valid
certificate that's in the CAs. That's not helping against a government wanting to
backdoor GPG, but it at least helps against script kiddies and the like.

Speaking about signed commits and tags: Why not do that? I tried it with git and it
works great.

Jan 23 2015, 10:02 AM · gnupg, Bug Report

Jan 22 2015

werner closed T1599: pressing the [x] button sends a key to the key server instead of cancelling the send. as Resolved.
Jan 22 2015, 6:11 PM · Bug Report, gpa
werner added a comment to T1599: pressing the [x] button sends a key to the key server instead of cancelling the send..

Fixed with commit 071ed43. Will go into 0.9.8.

Sorry for delaying it for so long.

Jan 22 2015, 6:11 PM · Bug Report, gpa
aheinecke removed a project from T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet): Restricted Project.
Jan 22 2015, 6:03 PM · Bug Report, gnupg
aheinecke added a comment to T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet).

Works for me now. Thanks again. -> resolved.

Jan 22 2015, 6:03 PM · Bug Report, gnupg
aheinecke closed T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet) as Resolved.
Jan 22 2015, 6:03 PM · Bug Report, gnupg
werner closed T1602: Manual page and --help output discrepancies as Resolved.
Jan 22 2015, 5:53 PM · gnupg, Feature Request
werner added a comment to T1602: Manual page and --help output discrepancies.

Okay, that took long :-(: commit da4db172 - will go into 2.1.2.

    I added options shown with --help but missing in the man page.
    However, --help won't show everything listed in the man age and
    frankly there are even more options not listed anywhere (to see them
    use --dump-options).

I also kept one British translation ;-)
Thanks for the report.

Jan 22 2015, 5:53 PM · gnupg, Feature Request
werner added a comment to T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet).

s/GPG-2/PGP-2/ of course

Jan 22 2015, 5:23 PM · Bug Report, gnupg
werner added a comment to T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet).

Tt is not really corrupted. There are just GPG-2 keys at the wrong place.

Well, some keys are duplicated but I do not think that this created the test case.
The reason for the duplication might be 1.4.12 which may not include the latest
locking code.

Jan 22 2015, 5:23 PM · Bug Report, gnupg
werner added a comment to T1811: Own key's validity gets set from ultimate to undef when signing a key that signed you.

Regarding git: An https:// access is not in any way safer - it only hides what
you are doing on the remote repo. The security from git is due to the chain of
hashes. Thus if you see a full commit id you can be sure that we are talking
about the very same code.

Right, I could have given the full commit id, but that won't help either because
you should not trust this bug tracker. The only reliabale task is by starting
from a signed commit or tag and review all code up to there.
Fortunately any tmapering with git.gnupg.org would soon trigger a lot of
complains from people pulling updates and checking commit ids.

Jan 22 2015, 5:17 PM · gnupg, Bug Report
werner added a comment to T1811: Own key's validity gets set from ultimate to undef when signing a key that signed you.

Okay, I was able to replicate your test case with an older gpg version. I am not
sure which version that was, though. I would need to bisect to find it.

However, with the latest version (commit 09e8f35d3808d6e49f891360c341aae3869e8650)
the problem has gone.

Jan 22 2015, 5:12 PM · gnupg, Bug Report
aheinecke claimed T1816: Corrupted pubring causes long loop in gnupg (keydb_search failed: Invalid packet).
Jan 22 2015, 4:46 PM · Bug Report, gnupg