Page MenuHome GnuPG
Feed All Stories

Jun 15 2018

gniibe claimed T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1.

I tested on Debian with local dnsmasq. For usual setting, no problem.
If /etc/resolv.conf has nameserver 127.0.0.1 and the service by dnsmasq somehow stops, and we have another nameserver nameserver somewhere-not-local the issues/19 matters.

Jun 15 2018, 2:38 AM · dirmngr, gnupg

Jun 14 2018

werner triaged T4024: "Clean" does not remove superseded subkey signatures as Normal priority.
Jun 14 2018, 7:36 PM · gnupg
werner triaged T4025: `gpg --with-sig-list --show-keys` does not show all the signature packets from stdin as Low priority.

--shows-keys is not a debug command to show the inetrnals of an OpenPGP message. It does the same as creating an empty homedir, importing the keys and running -k. Thus there is no way to get to the internals of an OpenPGP messages.

Jun 14 2018, 7:34 PM
dkg created T4025: `gpg --with-sig-list --show-keys` does not show all the signature packets from stdin in the S1 Public space.
Jun 14 2018, 5:23 PM
dkg added a comment to T4024: "Clean" does not remove superseded subkey signatures.

i'm having trouble just assembling the two signatures over the subkey with 2.2.8 in a single homedir. in particular, when i try to do the following with a new, clean test GNUPGHOME, then i see only one signature on the subkeys afterward:

Jun 14 2018, 4:56 PM · gnupg
stm added a comment to T4022: too-large User ID packets result in dropping an entire certificate.

I've made the parsing less strict in LibTMCG: https://github.com/HeikoStamer/libtmcg/commit/be7963b33cf8bace9d031074521acc4e89930d33

Jun 14 2018, 4:34 PM · gnupg, Bug Report
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

thanks, that works for me. I look forward to seeing the patches :)

Jun 14 2018, 4:11 PM · gnupg, Bug Report
provka created T4024: "Clean" does not remove superseded subkey signatures in the S1 Public space.
Jun 14 2018, 4:08 PM · gnupg
werner closed T4023: gnupg 2.2.8 make errors as Resolved.

See T4012 for a patch to build with an older libgpg-error.

Jun 14 2018, 3:57 PM · Bug Report
fulanoperez created T4023: gnupg 2.2.8 make errors.
Jun 14 2018, 3:06 PM · Bug Report
mkrambach committed rM3cd428ba442f: js: import result feedback (authored by mkrambach).
js: import result feedback
Jun 14 2018, 2:50 PM
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

Although "certificate" is used for OpenPGP revocations, it is technically a signature.

Jun 14 2018, 2:36 PM · gnupg, Bug Report
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

can you let me know what you're planning so i can plan my work on enigmail?

Jun 14 2018, 2:26 PM · gnupg, Bug Report
thomas added a comment to T11: test 1 - please ignore.

test after system upgrades

Jun 14 2018, 1:27 PM · Trash, Feature Request
mkrambach committed rM3c783bd09ce5: js: add verify and signature parsing (authored by mkrambach).
js: add verify and signature parsing
Jun 14 2018, 12:17 PM
werner committed rD73c278e7b09f: web: typo fix (authored by werner).
web: typo fix
Jun 14 2018, 10:26 AM
werner triaged T4022: too-large User ID packets result in dropping an entire certificate as High priority.
Jun 14 2018, 8:07 AM · gnupg, Bug Report
dkg created T4022: too-large User ID packets result in dropping an entire certificate.
Jun 14 2018, 6:28 AM · gnupg, Bug Report
gniibe committed rG3e6ad302eaf3: libdns: Sync to upstream. (authored by gniibe).
libdns: Sync to upstream.
Jun 14 2018, 6:20 AM
gniibe committed rG5b40338f1276: dirmngr: Fix recursive resolver mode. (authored by gniibe).
dirmngr: Fix recursive resolver mode.
Jun 14 2018, 6:20 AM
olf added a comment to T4016: Libgcrypt release 1.8.3.

Thanks.
So what I remembered was 1 year and 1 month off the real EOL date.

Jun 14 2018, 1:21 AM · Release Info, CVE, libgcrypt

Jun 13 2018

werner committed rD969e129dbd6b: web: Release info for libgcrypt 1.8.3 (authored by werner).
web: Release info for libgcrypt 1.8.3
Jun 13 2018, 6:38 PM
werner closed T4011: CVE-2018-0495 as Resolved.
Jun 13 2018, 6:33 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

Here is our announcement: https://lists.gnupg.org/pipermail/gnupg-announce/2018q2/000426.html

Jun 13 2018, 6:32 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

https://www.nccgroup.trust/us/our-research/technical-advisory-return-of-the-hidden-number-problem/

Jun 13 2018, 5:40 PM · CVE, libgcrypt
werner committed rP779b8e6df7d2: core: Add info about tty mode etc to 'getinfo ttyinfo' (authored by werner).
core: Add info about tty mode etc to 'getinfo ttyinfo'
Jun 13 2018, 5:18 PM
mkrambach committed rMaed402c5d572: js: getDefaultKey and verify fix (authored by mkrambach).
js: getDefaultKey and verify fix
Jun 13 2018, 3:23 PM
mkrambach committed rMd0fc4ded58f4: js: less confusing icons for test/Demo extension (authored by mkrambach).
js: less confusing icons for test/Demo extension
Jun 13 2018, 3:23 PM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

thus far every packet type has been a three-letter string, right? I'm looking at "Field 1" in doc/DETAILS. adding a 4-letter packet type seems like it could be trouble if someone has done the dumb thing of assuming the field is fixed-length.

Jun 13 2018, 2:49 PM · gnupg, Bug Report
gniibe added a comment to T4011: CVE-2018-0495.

Informed Debian security team about our change of libgcrypt.

Jun 13 2018, 1:02 PM · CVE, libgcrypt
werner changed the visibility for T4011: CVE-2018-0495.
Jun 13 2018, 12:40 PM · CVE, libgcrypt
werner added a comment to T4011: CVE-2018-0495.

A new installer for GnuPG with Libgcrypt 1.8.3 is now available.

Jun 13 2018, 12:38 PM · CVE, libgcrypt
werner committed rD9689413979fa: swdb: New gnupg w32 installer with latest Libgcrypt (authored by werner).
swdb: New gnupg w32 installer with latest Libgcrypt
Jun 13 2018, 12:25 PM
gniibe abandoned D460: Make sure the key for signature has capable for CERT.

Change done and pushed already.

Jun 13 2018, 11:49 AM
werner added a comment to T4011: CVE-2018-0495.

Releases are now available. Next task is to build a new GnuPG Windows installer.

Jun 13 2018, 10:40 AM · CVE, libgcrypt
werner closed T4016: Libgcrypt release 1.8.3 as Resolved.

1.8.3 and 1.7.10 are now released. Announcement will follow later the day.

Jun 13 2018, 10:39 AM · Release Info, CVE, libgcrypt
werner closed T4016: Libgcrypt release 1.8.3, a subtask of T4011: CVE-2018-0495, as Resolved.
Jun 13 2018, 10:39 AM · CVE, libgcrypt
werner committed rC0d51ea9b88b6: Add NEWS from the 1.8 and 1.7 branches. (authored by werner).
Add NEWS from the 1.8 and 1.7 branches.
Jun 13 2018, 10:37 AM
werner committed rC2ace21b1a8e4: Post release updates. (authored by werner).
Post release updates.
Jun 13 2018, 10:25 AM
werner committed rCff8f7e53ce6b: Release 1.7.10 (authored by werner).
Release 1.7.10
Jun 13 2018, 10:25 AM
werner committed rC3caf35a49cb6: Fix incorrect counter overflow handling for GCM (authored by jukivili).
Fix incorrect counter overflow handling for GCM
Jun 13 2018, 10:17 AM
werner committed rC6dd0cf0744db: ecc: Improve gcry_mpi_ec_curve_point (authored by werner).
ecc: Improve gcry_mpi_ec_curve_point
Jun 13 2018, 10:17 AM
werner committed rC3600e1224f6c: mpi: New internal function _gcry_mpi_cmpabs. (authored by werner).
mpi: New internal function _gcry_mpi_cmpabs.
Jun 13 2018, 10:17 AM
werner committed rC528a06b48389: AES-KW: fix in-place encryption (authored by smueller_chronox.de).
AES-KW: fix in-place encryption
Jun 13 2018, 10:17 AM
werner committed rD823e9076f87a: swdb: Libgcrypt 1.8.3 (authored by werner).
swdb: Libgcrypt 1.8.3
Jun 13 2018, 10:06 AM
werner committed rC6ca6344429e5: Post release updates (authored by werner).
Post release updates
Jun 13 2018, 10:01 AM
werner committed rC5600d2d6b236: Release 1.8.3 (authored by werner).
Release 1.8.3
Jun 13 2018, 10:01 AM
Eagle_Erwin committed rO11b39fb70f14: Update Dutch translation. (authored by Eagle_Erwin).
Update Dutch translation.
Jun 13 2018, 9:08 AM
gniibe added a comment to T4011: CVE-2018-0495.

Pushed fixes to the repository at 16:00+0900 (09:00+0200). It's 0700Z.

Jun 13 2018, 9:05 AM · CVE, libgcrypt
gniibe committed rC9be06c6b2e5c: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe committed rC9010d1576e27: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe committed rC325ab0b312e6: ecc: Add blinding for ECDSA. (authored by gniibe).
ecc: Add blinding for ECDSA.
Jun 13 2018, 9:00 AM
gniibe added a comment to T4011: CVE-2018-0495.

In master, it's

commit 9010d1576e278a4274ad3f4aa15776c28f6ba965
Author: NIIBE Yutaka <gniibe@fsij.org>
Date:   Wed Jun 13 15:28:58 2018 +0900
Jun 13 2018, 8:59 AM · CVE, libgcrypt
gniibe updated the task description for T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:09 AM · dirmngr, gnupg
gniibe renamed T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1 from dirmngr/dns.c issue with dnsmasq to dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:08 AM · dirmngr, gnupg
werner updated the task description for T4016: Libgcrypt release 1.8.3.
Jun 13 2018, 8:07 AM · Release Info, CVE, libgcrypt
werner added a comment to T4016: Libgcrypt release 1.8.3.

1.8.3 has not yet been released and thus there is no NEWS entries and there can't be a 1.8.3 tag. You are right that the README still says 1.7. I'll fix that for 1.8.3. Why do you think maintenance of 1.7 stopped; the AUTHORS file and the new EOL statements on the download page say that we are going to maintain it until 2019-06-30.

Jun 13 2018, 8:06 AM · Release Info, CVE, libgcrypt
gniibe created T4021: dirmngr: dirmngr/dns.c issue with 127.0.0.1.
Jun 13 2018, 8:02 AM · dirmngr, gnupg
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

What about another record type for standalone revocations, something line "rev0" or "revx"? This would solve the problem on how to distinguish merged revocation signatures (ie with a preceding "pub") from standalone revocations.

Jun 13 2018, 7:58 AM · gnupg, Bug Report
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

can i get a confirmation that the options you're considering for --with-colons --show-keys when confronted with a revocation certificate will be either:

Jun 13 2018, 12:16 AM · gnupg, Bug Report

Jun 12 2018

RAmbidge added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

@tinkerwolf This is weird... I've reinstalled my PC from scratch with an initial account set as local, and was able to set up GPG4Win perfectly fine for the first time on my PC (as I did in the VM). So, set up a VM with an initial account set up from an online account. GPG4Win started up fine... I am now really confused!! Somewhere within the getting set up with an online account, something has to be happening that interferes with dirmngr..
Will investigate further.

Jun 12 2018, 11:24 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

@RAmbidge are you able to further test this by using a VM with a MS account? I don't have the means right now, or I'd do it myself.

Jun 12 2018, 4:18 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
werner committed rGcb52eb76b3ba: Some preparations to eventuallt use gpgrt_argparse. (authored by werner).
Some preparations to eventuallt use gpgrt_argparse.
Jun 12 2018, 4:13 PM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

By "dummy pub line" I think you're proposing output that looks something like this instead of just the rev: line.:

Jun 12 2018, 3:47 PM · gnupg, Bug Report
aheinecke committed rW057c37ca1d87: Update libkleo kleopatra and kde-l10n (authored by aheinecke).
Update libkleo kleopatra and kde-l10n
Jun 12 2018, 2:24 PM
aheinecke committed rOe9839bebf322: po: Update portugese translation (authored by aheinecke).
po: Update portugese translation
Jun 12 2018, 2:15 PM
werner committed rG440472663d60: Require libgpg-error 1.29 and remove internal logging functions. (authored by werner).
Require libgpg-error 1.29 and remove internal logging functions.
Jun 12 2018, 1:45 PM
aheinecke committed rO2d63f5839887: po: Update german translation (authored by aheinecke).
po: Update german translation
Jun 12 2018, 1:41 PM
werner updated subscribers of T4011: CVE-2018-0495.

Publication is planned for the 13th, 1500Z

Jun 12 2018, 1:12 PM · CVE, libgcrypt
werner added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

As long as we don't check the signature we don't need the pubkey. That would make it actually easier becuase we have only one case and not 3 or more (bad signature, no pubkey, etc).

Jun 12 2018, 1:10 PM · gnupg, Bug Report
tinkerwolf added a comment to T3381: dirmngr won't start on Windows 10 with admin level account.

That actually makes sense, because it works fine on my laptop, where it's been a local account from the start, but it's broken on my desktop where it was originally a MS account, but is now local.

Jun 12 2018, 12:44 PM · libassuan, Restricted Project, gpg4win, dirmngr, Windows, Bug Report
aheinecke committed rO28a7464d13c0: Remove engine.c from potfiles (authored by aheinecke).
Remove engine.c from potfiles
Jun 12 2018, 11:19 AM
aheinecke committed rOc02b9f60f970: Auto update po files (authored by aheinecke).
Auto update po files
Jun 12 2018, 11:19 AM
aheinecke committed rO30f7ea667190: Remove removed bitmaps from extra dist (authored by aheinecke).
Remove removed bitmaps from extra dist
Jun 12 2018, 11:19 AM
aheinecke committed rKLEOPATRA9956e1ce8820: Bump patch version (authored by aheinecke).
Bump patch version
Jun 12 2018, 11:10 AM
aheinecke closed T3978: GpgOL: Problem with automatic resolution of ambigous keys as Resolved.

Fixed with https://commits.kde.org/libkleo/79f0cb79817e44b4eab864c573740c1501e796bd

Jun 12 2018, 11:07 AM · Bug Report, gpgol
aheinecke closed T3978: GpgOL: Problem with automatic resolution of ambigous keys, a subtask of T3925: Gpg4win 3.1.2, as Resolved.
Jun 12 2018, 11:07 AM · gpg4win
aheinecke committed rWf95ad3988662: Update gpgme and gnupg for testing (authored by aheinecke).
Update gpgme and gnupg for testing
Jun 12 2018, 10:06 AM
aheinecke committed rKLEOPATRA199c7cd53841: Change icon to open selection dlg in lineedit (authored by aheinecke).
Change icon to open selection dlg in lineedit
Jun 12 2018, 10:05 AM
gniibe renamed T4004: Curve25519 for Zeitcontrol card from Curve22519 for Zeitcontrol card to Curve25519 for Zeitcontrol card.
Jun 12 2018, 9:51 AM · Feature Request, scd
gniibe committed rG92d3dc9e1933: g10: Fix enum_secret_keys for card keys. (authored by gniibe).
g10: Fix enum_secret_keys for card keys.
Jun 12 2018, 9:22 AM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

Revocation certificates consist of *only* the revocation packet, right? Claiming that the revocation cert contains more than the revocation packet (when it doesn't) seems more troubling from an API perspective than just telling people to expect a single rev: line if they are looking at a revocation certificate.

Jun 12 2018, 9:12 AM · gnupg, Bug Report
werner closed T4019: --export-filter drop-subkey filter type should have usage option property as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Feature Request
werner closed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as Resolved.
Jun 12 2018, 9:09 AM · gnupg, Bug Report
werner committed rGfe621cc64b13: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:06 AM
aheinecke created T4020: GnuPG: Add Error or Warning if a --passphrase option is used without pinentry-mode loopback.
Jun 12 2018, 9:05 AM · gpg4win, gnupg
werner committed rGe8f439e05474: gpg: Do not import revocations with --show-keys. (authored by werner).
gpg: Do not import revocations with --show-keys.
Jun 12 2018, 9:05 AM
werner committed rG86b64876bef0: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 9:05 AM
dkg added a comment to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).

thanks for looking into this so quickly. where is your patch? i don't see it on the master branch yet.

Jun 12 2018, 9:05 AM · gnupg, Bug Report
werner claimed T4018: gpg --with-colons --show-keys does not show revocation certificates.

That will be a bit of work. We can't list a standalone key yet because the the key listing code expects a public or secret key as first packet. Further it would be advisable to insert a dummy "pub" key record before the "rev" record because the advise as always been to use "pub" or "sec" as start of a key keyblock.

Jun 12 2018, 9:02 AM · gnupg, Bug Report
gniibe committed rG8f99299a54a0: card: Fix memory leak for fetch-url sub command. (authored by gniibe).
card: Fix memory leak for fetch-url sub command.
Jun 12 2018, 8:55 AM
dkg added a comment to T4018: gpg --with-colons --show-keys does not show revocation certificates.

ee1fc420fb9741b2cfaea6fa820a00be2923f514 contains a proposed fix for this.

Jun 12 2018, 8:50 AM · gnupg, Bug Report
dkg committed rGee1fc420fb97: gpg: Print revocation certificate details when showing with-colons. (authored by dkg).
gpg: Print revocation certificate details when showing with-colons.
Jun 12 2018, 8:48 AM
werner added projects to T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`): gnupg, backport.

Thanks for reporting and your patch. However, I used a different way to solve this bug.

Jun 12 2018, 8:46 AM · gnupg, Bug Report
werner triaged T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`) as High priority.
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner claimed T4017: `gpg --show-keys` can modify the keyring (it is not actually the same as `--dry-run --import-options import-show --import`).
Jun 12 2018, 8:24 AM · gnupg, Bug Report
werner triaged T4018: gpg --with-colons --show-keys does not show revocation certificates as High priority.
Jun 12 2018, 8:22 AM · gnupg, Bug Report
werner triaged T4019: --export-filter drop-subkey filter type should have usage option property as Normal priority.

Thanks. Pushed to master. I think it should also go into 2.2.

Jun 12 2018, 8:21 AM · gnupg, Feature Request
werner committed rG2ddfb5bef920: gpg: Add new usage option for drop-subkey filters. (authored by dkg).
gpg: Add new usage option for drop-subkey filters.
Jun 12 2018, 8:19 AM
dkg added a comment to T4019: --export-filter drop-subkey filter type should have usage option property.

I've just pushed e037657edaf0b3ee9d2e30f6fe3edf6879976472 on the fix-T4019 branch

Jun 12 2018, 6:49 AM · gnupg, Feature Request