Page MenuHome GnuPG
Feed All Stories

Feb 27 2018

werner added a comment to T3065: dirmngr: proxy issues with dnslookup causing failure.

@Ainahir thanks for the info. However, your problem might be different because you are on Windows and not on Linux.
Please use for dirmngr --debug=ipc,dns instead of --debug-level=guru

Feb 27 2018, 3:44 PM · gnupg (gpg22), dns, dirmngr
werner added a comment to T3774: Failure to decrypt AEAD-encrypted files in some rare cases.

Here is a file

created using the fixed gpg version. I have a lot more of these test files; I can tar them up and provide them here. They are too lareg to go into the repo or the tarball. The files are all uncompressed and consists of ~ characters.

Feb 27 2018, 2:51 PM · gnupg, Bug Report
Ainahir reopened T3065: dirmngr: proxy issues with dnslookup causing failure as "Open".

same behavior on gpg 2.2.1

Feb 27 2018, 2:34 PM · gnupg (gpg22), dns, dirmngr
BenM committed rDf9098f2c036f: Resizing image (authored by BenM).
Resizing image
Feb 27 2018, 2:15 PM
werner committed rGb703ba725dad: gpg: Rename cipher.c to cipher-cfb.c (authored by werner).
gpg: Rename cipher.c to cipher-cfb.c
Feb 27 2018, 2:11 PM
werner committed rGebb0fcf6e0bd: gpg: Fix corner cases in AEAD encryption. (authored by werner).
gpg: Fix corner cases in AEAD encryption.
Feb 27 2018, 2:11 PM
aheinecke committed rW3d1a1b30e2b8: Add gpg4win-tools package (authored by aheinecke).
Add gpg4win-tools package
Feb 27 2018, 1:42 PM
aheinecke added a comment to T3814: Bug general.

Could you please try on the command line. (If you don't know how, see: https://www.wikihow.com/Open-the-Command-Prompt-in-Windows )

Feb 27 2018, 12:21 PM · Info Needed, Bug Report, gpg4win
Xavier97206 created T3814: Bug general.
Feb 27 2018, 11:22 AM · Info Needed, Bug Report, gpg4win
werner added a comment to rM59fe3f26c1ca: core: Support non-thread-safe getenv..

The problem is still that other - non-gpgme threads - can still use getenv and friends without us noticing that. But I see no solution for this. In any case this code is the best we can do.

Feb 27 2018, 11:18 AM
gniibe committed rM59fe3f26c1ca: core: Support non-thread-safe getenv. (authored by gniibe).
core: Support non-thread-safe getenv.
Feb 27 2018, 10:51 AM
aheinecke committed rGTO23cd403e8e78: Fix exit of overlay window (authored by aheinecke).
Fix exit of overlay window
Feb 27 2018, 9:38 AM
aheinecke committed rGTO461d97bdd509: Add missing overlay files (authored by aheinecke).
Add missing overlay files
Feb 27 2018, 9:38 AM
federico.chiacchiaretta added a comment to T3802: GpgOL fails to decrypt email sent from Evolution/Apple Mail via Office365.

Hi aheinecke,
I did some tests with 2.0.7-beta10 and still found some issues.
The message I attached as a test case in previous comment is now properly handled, I see no "signature.asc" attachment and message is correctly tagged as trusted sender; this test message was sent from Evolution and I sent it to myself (sorry for not pointing this out before).

Feb 27 2018, 9:33 AM · gpgol, Bug Report, gpg4win
aheinecke changed the status of T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox, a subtask of T3742: Gpg4win 3.1.0, from Open to Testing.
Feb 27 2018, 7:12 AM · gpg4win
aheinecke changed the status of T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox from Open to Testing.

My test works now with this commit.

Feb 27 2018, 7:12 AM · gpgol
aheinecke added a subtask for T3742: Gpg4win 3.1.0: T3802: GpgOL fails to decrypt email sent from Evolution/Apple Mail via Office365.
Feb 27 2018, 7:10 AM · gpg4win
aheinecke added a parent task for T3802: GpgOL fails to decrypt email sent from Evolution/Apple Mail via Office365: T3742: Gpg4win 3.1.0.
Feb 27 2018, 7:10 AM · gpgol, Bug Report, gpg4win
aheinecke committed rO456cdf6165ef: Check first for view before accessing selection (authored by aheinecke).
Check first for view before accessing selection
Feb 27 2018, 7:09 AM
aheinecke added a subtask for T3742: Gpg4win 3.1.0: T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox.
Feb 27 2018, 7:08 AM · gpg4win
aheinecke added a parent task for T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox: T3742: Gpg4win 3.1.0.
Feb 27 2018, 7:08 AM · gpgol
lovetox created T3813: GPGME error: "invalid crypto engine" in the MSYS2 version.
Feb 27 2018, 12:23 AM · Python, gpgme, Bug Report

Feb 26 2018

aheinecke added a comment to T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox.

I think the problem is with the selction change event. When we query for selection item (1) we trigger an itemLoad event which apparently causes this behavior. I've disabled everything else in our event handling code so we don't touch the mail at all (non crypto mails we never touch much).

Feb 26 2018, 5:17 PM · gpgol
aheinecke created T3812: GpgOL: Blocks sending mails from outbox if a mail is selected in outbox.
Feb 26 2018, 5:06 PM · gpgol
aheinecke added a comment to T3802: GpgOL fails to decrypt email sent from Evolution/Apple Mail via Office365.

Thanks for the test and the example mail. Should also be fixed now.
While testing I also noticed that the sender email address was also not parsed correctly for these kind of mails and added some code to fix that.

Feb 26 2018, 4:59 PM · gpgol, Bug Report, gpg4win
aheinecke committed rO14d0e2d9d1e0: Fix multipart/signed detection if ms-tnef wrapped (authored by aheinecke).
Fix multipart/signed detection if ms-tnef wrapped
Feb 26 2018, 4:56 PM
aheinecke committed rO7700f5da2744: Add some more sender address lookups (authored by aheinecke).
Add some more sender address lookups
Feb 26 2018, 4:56 PM
werner added a member for Verein: MuckiSG.
Feb 26 2018, 3:07 PM
werner created T3811: New website design.
Feb 26 2018, 12:14 PM · gpgweb, Verein
werner added members for Verein: gouttegd, guilhem, syscomet.
Feb 26 2018, 12:07 PM
werner added a member for Verein: bernhard.
Feb 26 2018, 12:05 PM
werner removed a member for Verein: marcus.
Feb 26 2018, 12:04 PM
werner added a member for Verein: gollo.
Feb 26 2018, 12:04 PM
werner closed T3075: Campaign 2017 as Wontfix.
Feb 26 2018, 12:04 PM · g10code, Verein
werner closed T3335: Find a new Treasurer for the Verein as Resolved.

Hello Andre.

Feb 26 2018, 12:03 PM · Verein
werner changed the edit policy for T3810: UI workshop.
Feb 26 2018, 12:02 PM · Documentation, gnupg, UI, Verein
werner set the color for UI to Orange.
Feb 26 2018, 11:57 AM
cdeibert renamed T3809: Unable to move a signed and/or encrypted email to .pst, when Outlook Reading Pane is enabled from Unable to move a signed email to .pst, when Outlook Reading Pane is enabled to Unable to move a signed and/or encrypted email to .pst, when Outlook Reading Pane is enabled .
Feb 26 2018, 11:49 AM · Duplicate, gpgol, Bug Report
cdeibert created T3809: Unable to move a signed and/or encrypted email to .pst, when Outlook Reading Pane is enabled .
Feb 26 2018, 11:49 AM · Duplicate, gpgol, Bug Report
werner triaged T3808: Unable to safely delete IDs with shared secret keys as Normal priority.
Feb 26 2018, 9:48 AM · Feature Request
cvhc edited projects for T3808: Unable to safely delete IDs with shared secret keys, added: Feature Request; removed Bug Report.

Ok, I understand it. Project tag changed :)

Feb 26 2018, 9:18 AM · Feature Request
werner added a comment to T3808: Unable to safely delete IDs with shared secret keys.

GnuPG stores key in a protocol independent manner. This allows to use the same key material for ssh, X.509 and OpenPGP - if you want that. A side effect is that it is possible to use the same key material also for several subkeys. Note that, unless you use --yes, gpg-agent will issue an additional prompt to request confirmation of secret key deletion. It even will show a warning if gpg-agent knows that the key is used for ssh. The thing here is that gpg-agent is picky about accidentely deleting a secret key. In general this is better than the other way.

Feb 26 2018, 9:03 AM · Feature Request
cvhc created T3808: Unable to safely delete IDs with shared secret keys.
Feb 26 2018, 8:42 AM · Feature Request
gniibe closed T3201: KDF DO support enhancement, a subtask of T3152: KDF DO support in OpenPGP card, as Resolved.
Feb 26 2018, 8:00 AM · scd
gniibe closed T3201: KDF DO support enhancement as Resolved.

It's in GnuPG 2.2.4, now.

Feb 26 2018, 8:00 AM · gnupg (gpg22), scd
gniibe closed T3787: Signature prompt has negated logic regarding `--only-sign-text-ids` as Resolved.
Feb 26 2018, 7:59 AM · gnupg (gpg22), Bug Report
gniibe closed T3757: Problem building latest master on macOS: unknown identifier LOCAL_PEERUID in command-ssh.c as Resolved.
Feb 26 2018, 7:59 AM · gpgagent, gnupg (gpg23), MacOS, Bug Report
gniibe closed T3778: NetBSD: scdaemon should be killed when its parent (gpg-agent) is going to shutdown as Resolved.
Feb 26 2018, 7:59 AM · gnupg, Bug Report
gniibe closed T3576: Open PGP SmartCard V2.1 - decryption error: ERR 100663364 Missing item in object <SCD> as Resolved.

It's a bug in the OpenPGP card implementation.
I put an entry in Wiki: https://wiki.gnupg.org/SmartCard#Known_Bug.28s.29_of_OpenPGPcard

Feb 26 2018, 7:58 AM · Info Needed, scd, Bug Report
gniibe closed T3508: GPG 2.2.2 not recognizing card reader under Linux as Resolved.
Feb 26 2018, 7:54 AM · scd, Bug Report
Laurent Montel <montel@kde.org> committed rKLEOPATRA705a5ef20fe6: GIT_SILENT: Prepare 5.7.3 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare 5.7.3
Feb 26 2018, 7:23 AM
BenM committed rM8da63fdee5e7: Merge branch 'ben/python-docs-01' (authored by BenM).
Merge branch 'ben/python-docs-01'
Feb 26 2018, 4:10 AM
BenM committed rMc58f61e92226: WS removal (authored by BenM).
WS removal
Feb 26 2018, 4:10 AM
BenM committed rM6f2e2e0f150d: LaTeX headers (authored by BenM).
LaTeX headers
Feb 26 2018, 3:57 AM
gniibe committed rA6c736325c028: Silence two minor warning on Windows. (authored by gniibe).
Silence two minor warning on Windows.
Feb 26 2018, 3:52 AM
BenM committed rM8a2d7b8c2412: Merge branch 'ben/gitsettings' of ben/gitignored (authored by BenM).
Merge branch 'ben/gitsettings' of ben/gitignored
Feb 26 2018, 3:05 AM

Feb 25 2018

werner committed rD14956d3f716f: verein: Make the frontpage more serious and link the beitragsordnung. (authored by werner).
verein: Make the frontpage more serious and link the beitragsordnung.
Feb 25 2018, 8:32 PM
BenM committed rDda754fde9eb9: Merge branch 'master' of ssh+git://playfair.gnupg.org/git/gnupg-doc (authored by BenM).
Merge branch 'master' of ssh+git://playfair.gnupg.org/git/gnupg-doc
Feb 25 2018, 7:52 AM
BenM committed rDb276fa44402f: Oops ... (authored by BenM).
Oops ...
Feb 25 2018, 7:52 AM

Feb 24 2018

onickolay added a comment to T3774: Failure to decrypt AEAD-encrypted files in some rare cases.

I found another issue in current master of GnuPG. Probably you already noticed it - when GnuPG AEAD-encrypts input which is a multiple of chunk size, then incorrect chunk number is used in the last block (+1)
The same happens for decryption.
Here is debug output of 128-byte input decryption with 64-byte chunk len:

gpg: DBG: nonce: D0 33 CD AC B5 54 07 66 2C 5C 55 7F A9 F2 EF
gpg: DBG: authdata: D4 01 07 02 00 00 00 00 00 00 00 00 00
gpg: DBG: nonce: D0 33 CD AC B5 54 07 66 2C 5C 55 7F A9 F2 EE
gpg: DBG: authdata: D4 01 07 02 00 00 00 00 00 00 00 00 01
gpg: DBG: nonce: D0 33 CD AC B5 54 07 66 2C 5C 55 7F A9 F2 ED
gpg: DBG: authdata: D4 01 07 02 00 00 00 00 00 00 00 00 02
gpg: DBG: eof seen: holdback buffer has the tags.
gpg: DBG: nonce: D0 33 CD AC B5 54 07 66 2C 5C 55 7F A9 F2 EC
gpg: DBG: authdata: D4 01 07 02 00 00 00 00 00 00 00 00 03 00 00 00 00 00 00 00 80
Feb 24 2018, 3:22 PM · gnupg, Bug Report
onickolay added a comment to T3774: Failure to decrypt AEAD-encrypted files in some rare cases.

Hi Werner,
Looks like there is a problem on my side, I miscalculated data length (0x240 while it should be 0x280).
Other then this values are the same:

Feb 24 2018, 12:27 PM · gnupg, Bug Report
werner triaged T3807: Mandatory OpenPGP Primary Key Binding Signature (sigclass 0x19) as Low priority.
Feb 24 2018, 12:16 PM · Documentation, gnupg
stm created T3807: Mandatory OpenPGP Primary Key Binding Signature (sigclass 0x19).
Feb 24 2018, 9:44 AM · Documentation, gnupg

Feb 23 2018

werner added a comment to T3774: Failure to decrypt AEAD-encrypted files in some rare cases.

Can you help me and tell me the AD for the last and the final chunk?
My current values are:

Feb 23 2018, 5:13 PM · gnupg, Bug Report
werner added projects to T3806: error accessing ldaps key server (TLS vs. STARTTLS): dirmngr, LDAP.
Feb 23 2018, 11:06 AM · Too Old, LDAP, dirmngr, Bug Report
werner set the icon for LDAP to Tag.
Feb 23 2018, 11:05 AM
werner triaged T3805: Poor style: Redundant condition * 5 as Wishlist priority.

I will eventually look at this. However, sometimes the reason for such conditions can be documentation purposes. Thanks for pointing out.

Feb 23 2018, 11:03 AM · Bug Report
werner closed T3795: Failure to decrypt file, encrypted with multiple passwords as Wontfix.

With AEAD we can immediately check whether the correct passphrase is used. With CFB we can't do that and thus the checking is delayed until we can do the bulk encryption using the session key. At that point it is too late to check for other keys - well we could record that all and try again but that would make the code pretty complicate.

Feb 23 2018, 11:00 AM · Bug Report, gnupg
werner committed rGcbc7bacf2ff9: gpg: Try to mitigate the problem of wrong CFB symkey passphrases. (authored by werner).
gpg: Try to mitigate the problem of wrong CFB symkey passphrases.
Feb 23 2018, 10:56 AM
jpi created T3806: error accessing ldaps key server (TLS vs. STARTTLS).
Feb 23 2018, 10:36 AM · Too Old, LDAP, dirmngr, Bug Report
dcb created T3805: Poor style: Redundant condition * 5.
Feb 23 2018, 10:14 AM · Bug Report
werner added a comment to rGcf006cbf7338: doc: Clarify -export-secret-key-p12.

It was fixed with commit 641aae78 _after_ 2.2.5. Will eventually be merged into master.

Feb 23 2018, 10:08 AM
bernhard added a comment to rGcf006cbf7338: doc: Clarify -export-secret-key-p12.

@werner sorry for asking again, I may be missing something: just saw that you've marked my comment for line 259 as "done". But in master and gnupg-2.2.5 I still see the sentence as
Export the private key and the certificate identified by @var{key-id} in using the PKCS#12 format. which does not pass my English parser. :)

Feb 23 2018, 8:28 AM
gniibe committed rA35aad6b5d53b: Fix previous commit. (authored by gniibe).
Fix previous commit.
Feb 23 2018, 1:50 AM
dkg added a comment to T3804: --export-options export-minimal,export-clean includes multiple subkey binding signatures when only one is necessary.

This is similar to T3622, but it's not the same thing.

Feb 23 2018, 12:28 AM · gnupg (gpg22)
dkg created T3804: --export-options export-minimal,export-clean includes multiple subkey binding signatures when only one is necessary in the S1 Public space.
Feb 23 2018, 12:28 AM · gnupg (gpg22)

Feb 22 2018

tjarosch added a comment to T1621: Support multiple cards (not just readers).

I also struggled to get two cards running at the same time. Host system is Fedora 26 with gnupg 2.2.4.

Feb 22 2018, 11:59 PM · gnupg, Feature Request
werner closed T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6 as Resolved.

Will go into 2.2.6

Feb 22 2018, 8:55 PM · gnupg (gpg22), dirmngr, Bug Report
werner committed rGecfc4db3a2f8: dirmngr: Handle failures related to missing IPv6 gracefully (authored by mgorny).
dirmngr: Handle failures related to missing IPv6 gracefully
Feb 22 2018, 8:54 PM
werner added a project to T3331: gpg: Address family not supported by protocol if kernel doesn't support ipv6: gnupg (gpg22).
Feb 22 2018, 8:42 PM · gnupg (gpg22), dirmngr, Bug Report
olf awarded T3800: Kleopatra: Create and check checksums with <filename>.<checksum extension> a Like token.
Feb 22 2018, 7:17 PM · gpg4win, kleopatra
werner committed rD94c69b9eee9d: web: Release info for 2.2.5 and move old news entries (authored by werner).
web: Release info for 2.2.5 and move old news entries
Feb 22 2018, 7:16 PM
werner committed rG641aae783e46: doc: Fix recently introduced typo in gpgsm.texi. (authored by werner).
doc: Fix recently introduced typo in gpgsm.texi.
Feb 22 2018, 4:45 PM
werner committed rG7853190cfe29: build: Update swdb tags and include release info from 2.2.5 (authored by werner).
build: Update swdb tags and include release info from 2.2.5
Feb 22 2018, 4:43 PM
werner committed rG20539ea5cad1: Merge branch 'STABLE-BRANCH-2-2' (authored by werner).
Merge branch 'STABLE-BRANCH-2-2'
Feb 22 2018, 4:43 PM
werner committed rDd658ab86b59a: swdb: Release gnupg 2.2.5 (authored by werner).
swdb: Release gnupg 2.2.5
Feb 22 2018, 4:25 PM
werner committed rG59ee87aae874: Post release updates. (authored by werner).
Post release updates.
Feb 22 2018, 4:17 PM
werner committed rG9581a65ccc10: Release 2.2.5 (authored by werner).
Release 2.2.5
Feb 22 2018, 4:17 PM
werner committed rGb375d50ee4ce: gpg: Don't let gpg return failure on an invalid packet in a keyblock. (authored by werner).
gpg: Don't let gpg return failure on an invalid packet in a keyblock.
Feb 22 2018, 2:29 PM
bernhard added a comment to rGcf006cbf7338: doc: Clarify -export-secret-key-p12.

It makes --export-secret-key-p12 the recommended way to transport a privat CMS key. (fine, if this is, what was intended).
(Note that there is a typo in line 259).

Feb 22 2018, 2:19 PM
werner claimed T3803: dirmngr issues malformed DNS queries.
Feb 22 2018, 2:11 PM · dns, dirmngr, Bug Report
federico.chiacchiaretta added a comment to T3802: GpgOL fails to decrypt email sent from Evolution/Apple Mail via Office365.

I just tested version 2.0.7-beta8 x64 and I can confirm the bug is fixed, GpgOL can decrypt messages properly. Messages also appear to be properly signed.

Feb 22 2018, 11:11 AM · gpgol, Bug Report, gpg4win
werner closed T3065: dirmngr: proxy issues with dnslookup causing failure as Invalid.

No more info received - assuming this has been fixed after 1.2.20

Feb 22 2018, 11:01 AM · gnupg (gpg22), dns, dirmngr
werner closed T1967: GnuPG should select a key for signing without trying to use missing subkeys as Resolved.

Will go into 2.2.5

Feb 22 2018, 10:56 AM · gnupg (gpg22), Feature Request
werner committed rG88e766d3915c: g10: Select a secret key by checking availability under gpg-agent. (authored by gniibe).
g10: Select a secret key by checking availability under gpg-agent.
Feb 22 2018, 10:52 AM
werner claimed T1967: GnuPG should select a key for signing without trying to use missing subkeys.
Feb 22 2018, 10:51 AM · gnupg (gpg22), Feature Request
aheinecke committed rO325b90573a18: Fix WKS-Confirm mail detection (authored by aheinecke).
Fix WKS-Confirm mail detection
Feb 22 2018, 10:41 AM
werner triaged T3622: --export-options export-minimal,export-clean includes unusable subkeys as Normal priority.
Feb 22 2018, 10:37 AM · Feature Request, gnupg (gpg22)
werner triaged T3773: private subkeys are never deleted on non-master instances as Low priority.
Feb 22 2018, 10:33 AM · Info Needed, OpenPGP, gnupg (gpg22), Bug Report
werner committed rGcf006cbf7338: doc: Clarify -export-secret-key-p12 (authored by werner).
doc: Clarify -export-secret-key-p12
Feb 22 2018, 10:31 AM