Page MenuHome GnuPG
Feed All Stories

Feb 2 2022

werner committed rGe058d15d2d56: gpgconf: Return the compliance_de_vs item. (authored by werner).
gpgconf: Return the compliance_de_vs item.
Feb 2 2022, 8:42 PM
netchild created T5814: gpg-agent can't find existing 'pinentry', searches 'Pinentry' (uppercase'P') instead.
Feb 2 2022, 8:32 PM · Not A Bug, Bug Report
werner added a comment to T5691: Release libgcrypt 1.10.0.

it will be but we first prefer to do some final tests with that version. Feel free to also test. Either this or the next micro version will eventually be announced.

Feb 2 2022, 8:16 PM · FIPS, Release Info, libgcrypt
marv added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

@gniibe Thanks a bunch for the quick fix!

Feb 2 2022, 8:03 PM · gpgrt, Bug Report
jukivili committed rCd480db6e6c80: hwf-arm: add detection of ARMv8 crypto extension by toolchain config (authored by jukivili).
hwf-arm: add detection of ARMv8 crypto extension by toolchain config
Feb 2 2022, 5:57 PM
carlocab added a comment to T5691: Release libgcrypt 1.10.0.

Hi there, is this the new stable version of libgcrypt? Apologies if this is the wrong place to ask; I just couldn’t find any other release announcement for 1.10.0.

Feb 2 2022, 5:09 PM · FIPS, Release Info, libgcrypt
aheinecke committed rW890ec8a7fa00: appimage: Add xcb-util-devel package to docker (authored by aheinecke).
appimage: Add xcb-util-devel package to docker
Feb 2 2022, 3:48 PM
aheinecke committed rW042908416ea3: appimage: Refresh kconfigwidgets patch (authored by aheinecke).
appimage: Refresh kconfigwidgets patch
Feb 2 2022, 3:48 PM
aheinecke committed rW6aa4730c09bb: Update Kleopatra to latest snapshot (authored by aheinecke).
Update Kleopatra to latest snapshot
Feb 2 2022, 3:24 PM
aheinecke committed rW481b4839161f: Add note in README about cmake in buster (authored by aheinecke).
Add note in README about cmake in buster
Feb 2 2022, 3:24 PM
aheinecke committed rW4b3e006f3972: appimage: Add -xcb to qt configure (authored by aheinecke).
appimage: Add -xcb to qt configure
Feb 2 2022, 3:24 PM
aheinecke committed rW445725d4a1df: appimage: Update patches for appimage (authored by aheinecke).
appimage: Update patches for appimage
Feb 2 2022, 3:24 PM
aheinecke committed rW3821027d2445: Fix typo in gen-frameworks.sh (authored by aheinecke).
Fix typo in gen-frameworks.sh
Feb 2 2022, 3:24 PM
aheinecke committed rKLEOPATRA8cc6819da237: Add compatibility for older kcfg versions (authored by aheinecke).
Add compatibility for older kcfg versions
Feb 2 2022, 3:22 PM
mieth added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

After further testing: The error does not occur if WKD is implemented directly under the respective domain.
The behavior of GnuPG differs between Windows and other platforms. However, it is not clear to me which version is behaving incorrectly. But it seems clear that there is no compatibility with the instructions at https://keys.openpgp.org/about/usage#wkd-as-a-service under Windows. (However this may concern another project.)

Feb 2 2022, 2:11 PM · wkd, gpg4win, Bug Report
mieth added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

The server in the testcase is wkd.keys.openpgp.org which is referred with CNAME via the DNS. Referring to https://www.ssllabs.com/ssltest/analyze.html?d=wkd.keys.openpgp.org it shoud support TLS 1.2

Feb 2 2022, 1:19 PM · wkd, gpg4win, Bug Report
werner added a comment to T5813: Locating Keys via WKD with gpg4win fails with unknown error..

Check that the server does not prohibit TLS 1.2 - a few server admins allow only TLS 1.3 for whatever security threats they have in mind.

Feb 2 2022, 1:00 PM · wkd, gpg4win, Bug Report
aheinecke committed rOa907038d04d4: Fix draft re-encryption (authored by aheinecke).
Fix draft re-encryption
Feb 2 2022, 11:06 AM
mieth created T5813: Locating Keys via WKD with gpg4win fails with unknown error..
Feb 2 2022, 10:52 AM · wkd, gpg4win, Bug Report
Jakuje added a watcher for FIPS: Jakuje.
Feb 2 2022, 10:30 AM
aheinecke shifted T5812: GpgOL: Draft encryption after modification no longer works from the Restricted Space space to the S1 Public space.
Feb 2 2022, 9:08 AM · gpgol, Restricted Project
aheinecke triaged T5812: GpgOL: Draft encryption after modification no longer works as Unbreak Now! priority.
Feb 2 2022, 9:02 AM · gpgol, Restricted Project
gniibe committed rCd918d8aee279: Remove random-daemon server and util. (authored by gniibe).
Remove random-daemon server and util.
Feb 2 2022, 3:47 AM
gniibe triaged T5811: libgcrypt: Remove random-daemon (server side) as Normal priority.
Feb 2 2022, 3:41 AM · libgcrypt
gniibe closed T5706: libgcrypt: random: Remove the feature getting randomness from random daemon as Resolved.
Feb 2 2022, 3:36 AM · libgcrypt
gniibe closed T5714: tests: Do not run tests for algorithms that are not built-in as Resolved.
Feb 2 2022, 3:35 AM · libgcrypt, Bug Report
gniibe closed T5720: The libgpg-error is using old inet_addr() unconditionally as Resolved.
Feb 2 2022, 3:35 AM · gpgrt, Bug Report
gniibe closed T5740: gpg error check fails as Resolved.
Feb 2 2022, 3:33 AM · gpgrt, Bug Report
gniibe closed T5797: New API for modern password hash function as Resolved.
Feb 2 2022, 3:32 AM · Feature Request, libgcrypt
gniibe closed T5637: Use poll for libgcrypt (support more than 1024 fds), a subtask of T2385: support more than 1024 fds., as Resolved.
Feb 2 2022, 3:31 AM · gpgrt, Feature Request, gpgme
gniibe closed T5637: Use poll for libgcrypt (support more than 1024 fds) as Resolved.
Feb 2 2022, 3:31 AM · libgcrypt, Feature Request
gniibe closed T5752: libgcrypt: Adding aes-wrap-pad (RFC5649) support as Resolved.
Feb 2 2022, 3:30 AM · Feature Request, libgcrypt
gniibe committed rGb2cedc108d5c: gpg: Fix for -Wformat when using uint64_t. (authored by gniibe).
gpg: Fix for -Wformat when using uint64_t.
Feb 2 2022, 3:16 AM
gniibe closed T5540: Update fipsdrv and cavs_driver.pl as Resolved.
Feb 2 2022, 1:25 AM · FIPS, libgcrypt
gniibe closed T5600: Provide module name/version API for FIPS 140-3 as Resolved.
Feb 2 2022, 1:25 AM · libgcrypt, FIPS, Bug Report
gniibe closed T5512: Implement service indicators as Resolved.
Feb 2 2022, 1:24 AM · Feature Request, FIPS, libgcrypt
gniibe closed T5759: Rename rndlinux module to rndoldlinux, a subtask of T5692: New entropy gatherer using the genentropy system call., as Resolved.
Feb 2 2022, 1:23 AM · libgcrypt, FIPS
gniibe closed T5759: Rename rndlinux module to rndoldlinux as Resolved.
Feb 2 2022, 1:23 AM · libgcrypt, FIPS
gniibe closed T5747: Provide a way to request non-FIPS service in FIPS mode as Resolved.
Feb 2 2022, 1:23 AM · Feature Request, FIPS, libgcrypt
gniibe closed T5665: libgcrypt : Restrict message digest use for FIPS 140-3 as Resolved.
Feb 2 2022, 1:22 AM · FIPS, Bug Report, libgcrypt
gniibe closed T5636: Run integrity checks + selftests from library constructor in FIPS as Resolved.
Feb 2 2022, 1:22 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5692: New entropy gatherer using the genentropy system call. as Resolved.
Feb 2 2022, 1:22 AM · libgcrypt, FIPS
gniibe closed T4894: FIPS: RSA/DSA/ECDSA are missing hashing operation as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt, Feature Request
gniibe closed T5710: FIPS: disable DSA for FIPS as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5723: libgcrypt: Remove random-fips.c as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5523: jitter entropy RNG update as Resolved.
Feb 2 2022, 1:21 AM · FIPS, libgcrypt
gniibe closed T5541: Envvar LIBGCRYPT_FORCE_FIPS_MODE as Resolved.
Feb 2 2022, 1:20 AM · Feature Request, FIPS, libgcrypt
gniibe closed T5550: Fix check_binary_integrity as Resolved.
Feb 2 2022, 1:20 AM · FIPS, libgcrypt
gniibe closed T5508: Allow hardware optimizations in FIPS as Resolved.
Feb 2 2022, 1:20 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5244: libgcrypt: Restrict MD5 use as Resolved.
Feb 2 2022, 1:19 AM · Bug Report, FIPS, libgcrypt
gniibe closed T5520: Fix tests in FIPS mode as Resolved.
Feb 2 2022, 1:18 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5617: fips: Check library integrity before running selftests as Resolved.
Feb 2 2022, 1:17 AM · FIPS, libgcrypt, Bug Report
gniibe closed T5645: RSA/DSA keygen modification for FIPS/ACVP testing as Resolved.
Feb 2 2022, 1:16 AM · libgcrypt, FIPS, Bug Report
gniibe moved T5512: Implement service indicators from Next to Ready for release on the FIPS board.
Feb 2 2022, 1:15 AM · Feature Request, FIPS, libgcrypt
gniibe moved T5691: Release libgcrypt 1.10.0 from Next to Ready for release on the FIPS board.
Feb 2 2022, 1:15 AM · FIPS, Release Info, libgcrypt

Feb 1 2022

werner committed rD87c005211f03: swdb: Libgcrypt 1.10.0 non-public release (authored by werner).
swdb: Libgcrypt 1.10.0 non-public release
Feb 1 2022, 10:11 PM
werner committed rCdd99ef53d9ee: Prepare master for future work (authored by werner).
Prepare master for future work
Feb 1 2022, 9:56 PM
werner changed the status of T5691: Release libgcrypt 1.10.0 from Open to Testing.
Feb 1 2022, 9:49 PM · FIPS, Release Info, libgcrypt
werner triaged T5810: Release Libgcrypt 1.10.1 as Low priority.
Feb 1 2022, 9:38 PM · libgcrypt, Release Info
erlandm added a comment to T5809: Expire subkey violates assertion "! sig->hashed".

Here is the output of --list-packets of the offending key, anonymised:

  1. off=0 ctb=99 tag=6 hlen=3 plen=418 :public key packet: version 4, algo 17, created 985690138, expires 0 pkey[0]: [1024 bits] pkey[1]: [160 bits] pkey[2]: [1024 bits] pkey[3]: [1023 bits] keyid: <KEY_ID>
  2. off=421 ctb=b4 tag=13 hlen=2 plen=35 :user ID packet: "XXXXXXXXXXXXX"
  3. off=458 ctb=88 tag=2 hlen=2 plen=120 :signature packet: algo 17, keyid <KEY_ID> version 4, created 1629537425, md5len 0, sigclass 0x13 digest algo 2, begin of digest a8 22 hashed subpkt 33 len 21 (issuer fpr v4 <XXXXXXXXXXXXXX><KEY_ID>) hashed subpkt 2 len 4 (sig created 2021-08-21) hashed subpkt 27 len 1 (key flags: 23) hashed subpkt 11 len 4 (pref-sym-algos: 9 8 7 2) hashed subpkt 21 len 5 (pref-hash-algos: 8 9 10 11 2) hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1) hashed subpkt 30 len 1 (features: 01) hashed subpkt 23 len 1 (keyserver preferences: 80) subpkt 16 len 8 (issuer key ID <KEY_ID>) data: [158 bits] data: [159 bits]
  4. off=580 ctb=b9 tag=14 hlen=3 plen=525 :public sub key packet: version 4, algo 16, created 985690139, expires 0 pkey[0]: [2048 bits] pkey[1]: [2 bits] pkey[2]: [2046 bits] keyid: YYYYYYYYYYYYYYY
  5. off=1108 ctb=88 tag=2 hlen=2 plen=63 :signature packet: algo 17, keyid <KEY_ID> version 3, created 985690139, md5len 5, sigclass 0x18 digest algo 2, begin of digest 94 e5 data: [159 bits] data: [156 bits]
Feb 1 2022, 4:52 PM · Restricted Project, gnupg (gpg22), Bug Report
werner added a project to T5809: Expire subkey violates assertion "! sig->hashed": gnupg (gpg22).
Feb 1 2022, 4:24 PM · Restricted Project, gnupg (gpg22), Bug Report
werner added a comment to T5809: Expire subkey violates assertion "! sig->hashed".

This code

Feb 1 2022, 4:23 PM · Restricted Project, gnupg (gpg22), Bug Report
werner committed rG57d546674d08: dirmngr: Avoid initial delay on the first keyserver access. (authored by werner).
dirmngr: Avoid initial delay on the first keyserver access.
Feb 1 2022, 4:06 PM
werner committed rGdde88897e2c5: dirmngr: Avoid initial delay on the first keyserver access. (authored by werner).
dirmngr: Avoid initial delay on the first keyserver access.
Feb 1 2022, 4:02 PM
werner committed rGd426ed66ac04: gpg: Set --verbose and clear --quiet in debug mode. (authored by werner).
gpg: Set --verbose and clear --quiet in debug mode.
Feb 1 2022, 3:21 PM
werner committed rG623a427b0cb6: sm: Partly revert last commit. (authored by werner).
sm: Partly revert last commit.
Feb 1 2022, 3:21 PM
werner committed rG51edea995d35: gpg,sm: Set --verbose and clear --quiet in debug mode. (authored by werner).
gpg,sm: Set --verbose and clear --quiet in debug mode.
Feb 1 2022, 3:18 PM
erlandm updated the task description for T5809: Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:05 PM · Restricted Project, gnupg (gpg22), Bug Report
erlandm renamed T5809: Expire subkey violates assertion "! sig->hashed" from Expire subkey violates asserion "! sig->hashed" to Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:04 PM · Restricted Project, gnupg (gpg22), Bug Report
erlandm created T5809: Expire subkey violates assertion "! sig->hashed".
Feb 1 2022, 3:03 PM · Restricted Project, gnupg (gpg22), Bug Report
pmgdeb added a comment to T5806: Error codes in rsa.c:generate_fips().

Thanks, Werner. This was originally reported by Alejandro Masino.

Feb 1 2022, 2:44 PM · libgcrypt, Bug Report
aheinecke committed rW6a738876e5c2: Also sign additional files for NSIS package (authored by aheinecke).
Also sign additional files for NSIS package
Feb 1 2022, 1:35 PM
aheinecke committed rWde70a2f074fb: Update Kleopatra and dependencies (authored by aheinecke).
Update Kleopatra and dependencies
Feb 1 2022, 1:35 PM
gniibe committed rE433aba9e778e: build,tests: Fix detection of have_lock_optimization. (authored by gniibe).
build,tests: Fix detection of have_lock_optimization.
Feb 1 2022, 2:30 AM
gniibe added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Pushed the change in rE433aba9e778e: build,tests: Fix detection of have_lock_optimization..

Feb 1 2022, 2:20 AM · gpgrt, Bug Report
gniibe added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

@marv Thank you for your report.

Feb 1 2022, 1:33 AM · gpgrt, Bug Report

Jan 31 2022

ikloecker moved T5808: gpgme: Add support for importing keys given by key id from a keyserver from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 31 2022, 4:08 PM · gpgme, Restricted Project
ikloecker triaged T5808: gpgme: Add support for importing keys given by key id from a keyserver as Normal priority.
Jan 31 2022, 4:08 PM · gpgme, Restricted Project
marv added a comment to T5699: libgpg-error 1.43 fails t-lock-single-thread test on x86_64 with musl and macOS.

Hey gniibe,

Jan 31 2022, 4:06 PM · gpgrt, Bug Report
werner closed T5806: Error codes in rsa.c:generate_fips() as Resolved.

Thanks

Jan 31 2022, 1:31 PM · libgcrypt, Bug Report
werner committed rC217bf0a0e7be: rsa: Fix regression in not returning an error for prime generation. (authored by werner).
rsa: Fix regression in not returning an error for prime generation.
Jan 31 2022, 12:54 PM
werner triaged T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries as Normal priority.
Jan 31 2022, 12:42 PM · Feature Request, gpg4win
ikloecker moved T5805: Kleopatra or GnuPG: Auto retrieve signers key from Restricted Project Column to Restricted Project Column on the Restricted Project board.
Jan 31 2022, 11:58 AM · gnupg, kleopatra, Restricted Project
gniibe committed rCcb9df21fcbb0: cipher: Initialize values not to confuse static analyzers (authored by Jakuje).
cipher: Initialize values not to confuse static analyzers
Jan 31 2022, 11:24 AM
gniibe committed rC904e168bdb2a: random: Avoid dereference of the ec before checking for NULL (authored by Jakuje).
random: Avoid dereference of the ec before checking for NULL
Jan 31 2022, 11:24 AM
gniibe committed rCd2003618e6bf: fips: Remove unused assignment (authored by Jakuje).
fips: Remove unused assignment
Jan 31 2022, 11:24 AM
gniibe committed rC0f38e6a877f1: cipher: Remove dead code in for the siv mode (authored by Jakuje).
cipher: Remove dead code in for the siv mode
Jan 31 2022, 11:24 AM
bernhard created T5807: Extend Authenticode signatures to more (all) Gpg4win binaries and libraries .
Jan 31 2022, 10:49 AM · Feature Request, gpg4win
aheinecke reassigned T5805: Kleopatra or GnuPG: Auto retrieve signers key from werner to ikloecker.

As this hinders the trusted-introducer setup in Keyserver centric deployments we should treat this with high priority.

Jan 31 2022, 10:05 AM · gnupg, kleopatra, Restricted Project
gniibe committed rC77512c510bf7: kdf: Fix computation by big-endian machine. (authored by gniibe).
kdf: Fix computation by big-endian machine.
Jan 31 2022, 5:08 AM
gniibe committed rC7dc488ae036a: ciper/blake2: Make sure to clean up the stack. (authored by gniibe).
ciper/blake2: Make sure to clean up the stack.
Jan 31 2022, 2:03 AM
gniibe added projects to T5797: New API for modern password hash function: Feature Request, Restricted Project.
Jan 31 2022, 1:22 AM · Feature Request, libgcrypt

Jan 30 2022

jukivili committed rC409f69167983: kdf/argon2: use BLAKE2b hash_buffers function instead of _gcry_md_* (authored by jukivili).
kdf/argon2: use BLAKE2b hash_buffers function instead of _gcry_md_*
Jan 30 2022, 11:30 PM
jukivili committed rC54369c66bedd: kdf: handle errors from thread dispatch/wait functions (authored by jukivili).
kdf: handle errors from thread dispatch/wait functions
Jan 30 2022, 11:30 PM
jukivili committed rC03a0eedefe3e: tests/t-kdf: few changes to pthread example and fix win32/win64 builds (authored by jukivili).
tests/t-kdf: few changes to pthread example and fix win32/win64 builds
Jan 30 2022, 11:30 PM
jukivili committed rCc5aead8aebc7: Rename KDF job functions and function types (authored by jukivili).
Rename KDF job functions and function types
Jan 30 2022, 11:30 PM

Jan 29 2022

pmgdeb created T5806: Error codes in rsa.c:generate_fips().
Jan 29 2022, 2:07 PM · libgcrypt, Bug Report
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAb997ef60255c: GIT_SILENT Upgrade release service version to 21.12.2. (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Upgrade release service version to 21.12.2.
Jan 29 2022, 12:27 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRA9aeae3ef75be: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Jan 29 2022, 12:27 AM
Heiko Becker <heiko.becker@kde.org> committed rKLEOPATRAfec935205dea: GIT_SILENT Update Appstream for new release (authored by Heiko Becker <heiko.becker@kde.org>).
GIT_SILENT Update Appstream for new release
Jan 29 2022, 12:27 AM