Page MenuHome GnuPG
Feed All Stories

Apr 3 2019

werner committed rG2b1135cf920c: scd: New standard attributes $ENCRKEYID and $SIGNKEYID. (authored by werner).
scd: New standard attributes $ENCRKEYID and $SIGNKEYID.
Apr 3 2019, 3:33 PM
werner committed rGec6a6779236a: gpg: Allow decryption using PIV cards. (authored by werner).
gpg: Allow decryption using PIV cards.
Apr 3 2019, 3:33 PM
gray created T4447: Fix addition of new GPG keys to LDAP.
Apr 3 2019, 11:27 AM · gnupg (gpg23), patch, LDAP, dirmngr, Bug Report
werner committed rG1f688e0d1dba: gpg: Avoid endless loop if a card's serial number can't be read. (authored by werner).
gpg: Avoid endless loop if a card's serial number can't be read.
Apr 3 2019, 11:26 AM
gray created D475: Fix addition of new GPG keys to LDAP.
Apr 3 2019, 11:19 AM
ap4y added a comment to T4009: POLDI: Support for EC (nist, brainpool, at least).

I implemented support for ECC and DSA public keys in poldi. Tested with ECC (curve 25519) key on Gnuk smartcard (Nitrokey Start).

Apr 3 2019, 11:07 AM · poldi, Feature Request
werner committed rGbcca3acb87c3: card: Allow card selection with LIST. (authored by werner).
card: Allow card selection with LIST.
Apr 3 2019, 11:04 AM
werner committed rG2d3392c147a2: gpg: Print modern style key info for non-decryptable keys. (authored by werner).
gpg: Print modern style key info for non-decryptable keys.
Apr 3 2019, 11:04 AM

Apr 2 2019

werner committed rGa480182f9d7e: gpg: Allow direct key generation from card with --full-gen-key. (authored by werner).
gpg: Allow direct key generation from card with --full-gen-key.
Apr 2 2019, 6:57 PM
werner committed rGf95222604382: common: Extend function pubkey_algo_string. (authored by werner).
common: Extend function pubkey_algo_string.
Apr 2 2019, 6:57 PM
dkg created T4446: please add --quick-revoke-subkey.
Apr 2 2019, 5:41 PM · Restricted Project, gnupg24, Feature Request
werner committed rGcb2065967465: scd: Add dummy option --application-priority. (authored by werner).
scd: Add dummy option --application-priority.
Apr 2 2019, 1:32 PM
werner committed rG48e7977709b6: dirmngr: Improve domaininfo cache update algorithm. (authored by werner).
dirmngr: Improve domaininfo cache update algorithm.
Apr 2 2019, 1:32 PM
werner committed rG0a30ce036a61: dirmngr: Better error code for http status 413. (authored by werner).
dirmngr: Better error code for http status 413.
Apr 2 2019, 1:32 PM
werner committed rGe100ace7f8a7: dirmngr: Improve domaininfo cache update algorithm. (authored by werner).
dirmngr: Improve domaininfo cache update algorithm.
Apr 2 2019, 1:23 PM
aheinecke committed rW4ae7f364f519: Minor update of pkg-copyright for 2019 (authored by aheinecke).
Minor update of pkg-copyright for 2019
Apr 2 2019, 8:35 AM
aheinecke committed rW358c291f558f: web: Update license pages (authored by aheinecke).
web: Update license pages
Apr 2 2019, 8:35 AM

Apr 1 2019

jukivili placed T4425: libgcrypt relocation error on aarch64 up for grabs.

I think commit https://git.gnupg.org/cgi-bin/gitweb.cgi?p=libgcrypt.git;a=commit;h=09c27280cc09798d15369b3a143036b7ab5ddd69 should be backported to 1.8 branch of libgcrypt.

Apr 1 2019, 9:16 PM · asm, libgcrypt, Bug Report
robbat2 added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

HTTP/1.1 spec, RFC 7230, Section 5.4, paragraph 2:
https://tools.ietf.org/html/rfc7230#section-5.4

Apr 1 2019, 8:24 PM · Keyserver, dns, dirmngr, Bug Report
werner added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

Please be so kind and point me to the specs stating that you should put the IP address into Host:

Apr 1 2019, 8:01 PM · Keyserver, dns, dirmngr, Bug Report
werner committed rG9ed1aa56c4bb: sm: Show the usage flags when generating a key from a card. (authored by werner).
sm: Show the usage flags when generating a key from a card.
Apr 1 2019, 7:59 PM
werner committed rGe47524c34a2a: gpg: Prepare card code to allow other than OpenPGP cards. (authored by werner).
gpg: Prepare card code to allow other than OpenPGP cards.
Apr 1 2019, 7:59 PM
werner committed rG0fad61de159a: gpg: New card function agent_scd_keypairinfo. (authored by werner).
gpg: New card function agent_scd_keypairinfo.
Apr 1 2019, 7:59 PM
werner committed rG334b16b868e7: gpg: Remove two unused card related functions. (authored by werner).
gpg: Remove two unused card related functions.
Apr 1 2019, 6:35 PM
werner committed rG3a4534d82682: gpg: Remove unused arg in a card related function. (authored by werner).
gpg: Remove unused arg in a card related function.
Apr 1 2019, 6:35 PM
robbat2 added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

It's up to GPG to send the Host header that shows the user's intent.

Apr 1 2019, 6:20 PM · Keyserver, dns, dirmngr, Bug Report
dkg committed rG5b1b5be65f34: NEWS: correct typo in header (authored by dkg).
NEWS: correct typo in header
Apr 1 2019, 4:36 PM
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

Here's an ugly hack to make this work (patch based on v2.2.15).

Apr 1 2019, 2:24 PM · Restricted Project, Feature Request, gnupg
werner added a comment to T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.

So in short you want:

  1. Allow to specify a keyserver by IP without any DNS lookups.
  2. When connecting via IP use the IP address for Host:.
Apr 1 2019, 12:55 PM · Keyserver, dns, dirmngr, Bug Report
aheinecke committed rKLEOPATRAc591cb20edfe: Persist expand state in keytreevie (authored by aheinecke).
Persist expand state in keytreevie
Apr 1 2019, 11:11 AM
werner closed T4268: Provide a method to build a simple WKD server filestructure on Windows as Resolved.
Apr 1 2019, 10:58 AM · wkd, Windows
werner created T4445: New feature to list keys signed by a certain key..
Apr 1 2019, 10:56 AM · gnupg24, Feature Request, gnupg (gpg23)
werner triaged T4443: IPv6 address with scope not accepted as keyserver as Normal priority.
Apr 1 2019, 10:24 AM · gnupg24, dirmngr, dns, Bug Report
bernhard added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

@werner
It is good practive to open a public ticket for many projects, because otherwise the XMPP users don't know if the fact is already known, reported or being worked on. Alternatively: Let us document the procedure in public what someone should do, if the xmpp server ist down or the certificate is expired. What is that procedure?

Apr 1 2019, 10:24 AM
werner closed T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29 as Resolved.

Right, no need to open a ticket. Jens has no account here anyway.

Apr 1 2019, 10:22 AM
aheinecke added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

I gave the usual ping. Yes I'm note sure why it's not automated. Our jabber server is hosted by a volunteer so it is not in our hands.

Apr 1 2019, 8:47 AM
bernhard added a comment to T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.

As it ran out again before this issue got officially closed, I'll reopen it with an extended title.
Wasn't the idea to automate this somehow? >:)

Apr 1 2019, 8:39 AM
bernhard renamed T4352: jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29 from jabber.quux.de certificate ran out 2019-01-28 to jabber.quux.de certificate ran out 2019-01-28 and 2019-03-29.
Apr 1 2019, 8:38 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA6440f4564f7f: Merge remote-tracking branch 'origin/Applications/19.04' (authored by Laurent Montel <montel@kde.org>).
Merge remote-tracking branch 'origin/Applications/19.04'
Apr 1 2019, 7:47 AM
Laurent Montel <montel@kde.org> committed rKLEOPATRA453056d826c8: Convert to camelcase include (authored by Laurent Montel <montel@kde.org>).
Convert to camelcase include
Apr 1 2019, 7:47 AM

Mar 31 2019

robbat2 created T4444: dirmngr fails with keyservers specified by IP without rDNS; reported as dead host or uses wrong Host header.
Mar 31 2019, 10:35 PM · Keyserver, dns, dirmngr, Bug Report
robbat2 created T4443: IPv6 address with scope not accepted as keyserver.
Mar 31 2019, 9:41 PM · gnupg24, dirmngr, dns, Bug Report
jukivili committed rCced7508c857c: blowfish: add three rounds parallel handling to generic C implementation (authored by jukivili).
blowfish: add three rounds parallel handling to generic C implementation
Mar 31 2019, 9:13 PM
jukivili committed rC4ec566b3689e: cast5: add three rounds parallel handling to generic C implementation (authored by jukivili).
cast5: add three rounds parallel handling to generic C implementation
Mar 31 2019, 9:13 PM
jukivili committed rC8a0e68be1020: cast5: read Kr four blocks at time and shift for current round (authored by jukivili).
cast5: read Kr four blocks at time and shift for current round
Mar 31 2019, 9:13 PM
jukivili committed rC0fe918fa897c: Add helper function for adding value to cipher block (authored by jukivili).
Add helper function for adding value to cipher block
Mar 31 2019, 9:13 PM

Mar 30 2019

jukivili committed rCefd700e31dc8: Optimize OCB set_key and set_nonce (authored by jukivili).
Optimize OCB set_key and set_nonce
Mar 30 2019, 5:02 PM
jukivili committed rCeacbd59b1333: AES-NI/OCB: Optimize last and first key XORing (authored by jukivili).
AES-NI/OCB: Optimize last and first key XORing
Mar 30 2019, 5:02 PM
jukivili committed rCe924ce456d57: AES-NI/OCB: Perform checksumming inline with encryption (authored by jukivili).
AES-NI/OCB: Perform checksumming inline with encryption
Mar 30 2019, 5:02 PM
jukivili committed rCb82dbbedf027: AES-NI/OCB: Use stack for temporary storage (authored by jukivili).
AES-NI/OCB: Use stack for temporary storage
Mar 30 2019, 5:02 PM
jukivili committed rCcabeebfc1179: tests/basic: add large buffer testing for ciphers (authored by jukivili).
tests/basic: add large buffer testing for ciphers
Mar 30 2019, 5:02 PM
jukivili committed rC049376470b31: chacha20-poly1305: fix wrong en/decryption on large input buffers (authored by jukivili).
chacha20-poly1305: fix wrong en/decryption on large input buffers
Mar 30 2019, 5:02 PM
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

@vsrinu26f No worries, looks like we are on the same page :)

Mar 30 2019, 10:06 AM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Sorry i think i blabbered without understanding context.

Mar 30 2019, 10:00 AM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

I wish gnupg natively supports creating backup cards. To be able to import
private key material to do another keyto card. And every time it moves that
to card and removes from gnupg.

Mar 30 2019, 9:46 AM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

For exactly same key material on tokens. Just before writing first token
backup .gnupg folder or export all key info. Do key to card. Delete .gnupg
folder and restore from backup and keytocard second token.

Mar 30 2019, 9:39 AM · Restricted Project, Feature Request, gnupg

Mar 29 2019

werner committed rG21b674097442: dirmngr: Better for error code for http status 413. (authored by werner).
dirmngr: Better for error code for http status 413.
Mar 29 2019, 2:23 PM
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

Both tokens should have same material.

Mar 29 2019, 1:38 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

On the other hand if we want to track which token is used by having multiple unexpired signing subkeys and each token have its own subkey is a possible usecase where multiple admins have the tokens.

Mar 29 2019, 1:28 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

I think if we have to update one token then we have to update backup token as well if moved to new subkey.

Mar 29 2019, 1:21 PM · Restricted Project, Feature Request, gnupg
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

@vsrinu26f Yes I'm using subkeys with YubiKey.

Mar 29 2019, 1:17 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

Sorry, ignore my comment if there is something with subkeys and you are
already using latest gnupg.

Mar 29 2019, 1:11 PM · Restricted Project, Feature Request, gnupg
vsrinu26f added a comment to T3416: gpg should select available signing key on card (even with -u option).

This is already implemented by yutaka.

Mar 29 2019, 1:05 PM · Restricted Project, Feature Request, gnupg
FrederickZh added a comment to T3416: gpg should select available signing key on card (even with -u option).

Sorry for jumping in out of the blue but the idea of automatically selecting the available signing key sounds also very appealing to me.

Mar 29 2019, 9:29 AM · Restricted Project, Feature Request, gnupg
aheinecke closed T4442: Kleopatra fails to encrypt a directory as Resolved.

With the downstream report: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=925952 I resolve this here.

Mar 29 2019, 9:05 AM · Bug Report
aheinecke added a comment to T4442: Kleopatra fails to encrypt a directory.

Thanks for the report. This was fixed with: https://cgit.kde.org/libkleo.git/commit/?id=8a94ac0835f0cff8908943d2a630a003a3429220 which I backported to Applications 18.12 which is the current stable release. But debian needs to add this patch. I'll report a debian bug and link it here.

Mar 29 2019, 8:48 AM · Bug Report
Laurent Montel <montel@kde.org> committed rKLEOPATRAa2e109286dd0: Merge remote-tracking branch 'origin/Applications/19.04' (authored by Laurent Montel <montel@kde.org>).
Merge remote-tracking branch 'origin/Applications/19.04'
Mar 29 2019, 7:25 AM

Mar 28 2019

werner added a comment to T4437: CCID card reader stopped working.

Good that it works again for you.

Mar 28 2019, 5:53 PM · Gentoo, scd, gnupg (gpg22), Bug Report
werner closed T671: card context shared between callers as Wontfix.

I don't anymore think that it makes sense to fix it. Further there is no cache for PINs; that is entirely up to the card.

Mar 28 2019, 5:49 PM · scd, Bug Report, gnupg
werner committed rG97feef8ee94a: scd: New option --application-priority. (authored by werner).
scd: New option --application-priority.
Mar 28 2019, 5:39 PM
dilfridge closed T4437: CCID card reader stopped working as Invalid.

This was most likely a (chipcard) hardware issue. It went away after polishing the contact pads for a bit. Possibly my laptop reader applies more force...

Mar 28 2019, 3:18 PM · Gentoo, scd, gnupg (gpg22), Bug Report
werner committed rG80c069b5e1ad: card: For passwd add a PIV menu and make the OpenPGP menu optional. (authored by werner).
card: For passwd add a PIV menu and make the OpenPGP menu optional.
Mar 28 2019, 2:46 PM
justus created T4442: Kleopatra fails to encrypt a directory.
Mar 28 2019, 11:48 AM · Bug Report
aheinecke closed T4055: mkportable fails with unhelpful error if the path is not at least 4 chars long as Resolved.
Mar 28 2019, 11:27 AM · gpg4win
aheinecke committed rWfa573722e66e: Fix mkportable for short target dir names (authored by aheinecke).
Fix mkportable for short target dir names
Mar 28 2019, 11:23 AM
werner committed rG2f761251c573: card: Allow "yubikey disable" only for Yubikey-5 and later. (authored by werner).
card: Allow "yubikey disable" only for Yubikey-5 and later.
Mar 28 2019, 11:00 AM
aheinecke closed T4138: GpgOL: encryption reported to freeze the windows explorer as Resolved.

No more reports about this in a while.

Mar 28 2019, 10:30 AM · gpg4win, Bug Report, gpgol
aheinecke closed T4438: Kleopatra: 3.1.6 external gpg process calls call gpgsm instead as Resolved.

Fixed with 3.1.7

Mar 28 2019, 10:28 AM · gpg4win, kleopatra
werner added projects to T4437: CCID card reader stopped working: gnupg (gpg22), scd, Gentoo.
Mar 28 2019, 10:21 AM · Gentoo, scd, gnupg (gpg22), Bug Report
aheinecke renamed T4389: Gpg4win 3.1.8 from Gpg4win 3.1.7 to Gpg4win 3.1.8.
Mar 28 2019, 10:09 AM · gpg4win, Release Info
aheinecke closed T4441: Installer quarantined by Symantec as Invalid.

False positives happen from time to time with various Anti Virus Software. We have it as a FAQ in the wiki:
https://wiki.gnupg.org/Gpg4win/AntiVirusSoftware

Mar 28 2019, 10:09 AM · Bug Report, gpg4win
svish created T4441: Installer quarantined by Symantec.
Mar 28 2019, 10:00 AM · Bug Report, gpg4win
aheinecke committed rW3cacbd36af26: Add links to mail announcement (authored by aheinecke).
Add links to mail announcement
Mar 28 2019, 9:41 AM
aheinecke committed rD067d82757312: swdb: Release Ggp4win-3.1.7 (authored by aheinecke).
swdb: Release Ggp4win-3.1.7
Mar 28 2019, 9:39 AM
aheinecke committed rW02983d6677c1: Release Gpg4win-3.1.7 (authored by aheinecke).
Release Gpg4win-3.1.7
Mar 28 2019, 9:36 AM
aheinecke committed rW08844a7b5ca7: Post release version bump (authored by aheinecke).
Post release version bump
Mar 28 2019, 9:32 AM
aheinecke committed rWf015bcc4d352: Fix mkportable-full (authored by aheinecke).
Fix mkportable-full
Mar 28 2019, 9:32 AM
aheinecke committed rW972365f2bcc7: Fix regressions from 3.1.6 (authored by aheinecke).
Fix regressions from 3.1.6
Mar 28 2019, 9:32 AM
aheinecke created T4440: GPA: Crash on keygen in Gpg4win-3.1.6.
Mar 28 2019, 8:33 AM · gpg4win, gpa, gpgme
aheinecke updated the task description for T4439: GPA: Failure to start with Gpg4win 3.1.6.
Mar 28 2019, 8:31 AM · gpg4win, gpa, gpgme
aheinecke created T4439: GPA: Failure to start with Gpg4win 3.1.6.
Mar 28 2019, 8:31 AM · gpg4win, gpa, gpgme
Laurent Montel <montel@kde.org> committed rKLEOPATRA05de7ee4d5a6: GIT_SILENT: Prepare 5.11.0 (authored by Laurent Montel <montel@kde.org>).
GIT_SILENT: Prepare 5.11.0
Mar 28 2019, 7:58 AM
khanhnd.vn added a comment to T4428: Would like to use our card with Kleopatra tool.

Thanks so much your helps.
With new version 3.1.6, I can generate key on Kleopatra tool and use key stored in smartcard.

Mar 28 2019, 3:39 AM · scd, OpenPGP, Bug Report, gpg4win
dilfridge added a comment to T4437: CCID card reader stopped working.

The same chipcard works still fine in a different (type of) reader / machine.

Mar 28 2019, 1:33 AM · Gentoo, scd, gnupg (gpg22), Bug Report

Mar 27 2019

aheinecke committed rM4a4680f8901e: core, w32: Fix format string errors on windows (authored by aheinecke).
core, w32: Fix format string errors on windows
Mar 27 2019, 5:47 PM
werner committed rG5a3055eb722e: scd: Support reading the Yubikey 4 firmware version. (authored by werner).
scd: Support reading the Yubikey 4 firmware version.
Mar 27 2019, 5:36 PM
aheinecke committed rM19a4c4daa2cf: core: Fix assuan logger-fd hack for windows (authored by aheinecke).
core: Fix assuan logger-fd hack for windows
Mar 27 2019, 4:15 PM
aheinecke committed rKLEOPATRA9250d0292646: Bump Version to 3.1.7 (authored by aheinecke).
Bump Version to 3.1.7
Mar 27 2019, 3:14 PM
aheinecke committed rKLEOPATRAbf9aab0b567d: Fix copy&paste error that breaks gpg process calls (authored by aheinecke).
Fix copy&paste error that breaks gpg process calls
Mar 27 2019, 2:51 PM
aheinecke renamed T4438: Kleopatra: 3.1.6 external gpg process calls call gpgsm instead from Kleopatra: 3.1.6 failure to refesh OpenPGP keys to Kleopatra: 3.1.6 external gpg process calls call gpgsm instead.
Mar 27 2019, 2:51 PM · gpg4win, kleopatra