Page MenuHome GnuPG
Feed All Stories

Fri, May 16

dkg added a comment to T5993: gpg should reject compressed packets outside of messages.

For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

Fri, May 16, 4:12 PM · Feature Request, gnupg
timegrid created T7658: Okular: Problems with smime signatures.
Fri, May 16, 4:00 PM · Bug Report, gpd5x, okular
werner closed T5993: gpg should reject compressed packets outside of messages as Resolved.
Fri, May 16, 2:46 PM · Feature Request, gnupg
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

(The commits had a wrong bug it in their message)

Fri, May 16, 2:44 PM · Feature Request, gnupg
werner committed rG23ccad05c680: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
Fri, May 16, 2:40 PM
werner committed rG8e529f922194: gpg: Do not allow compressed key packets on import. (authored by werner).
gpg: Do not allow compressed key packets on import.
Fri, May 16, 2:33 PM
werner committed rG645cf7d8fc25: Revert "w32: On socket nonce mismatch close the socket." (authored by werner).
Revert "w32: On socket nonce mismatch close the socket."
Fri, May 16, 2:33 PM
werner committed rGfcac10357e6d: gpg: Remove unused variable. (authored by werner).
gpg: Remove unused variable.
Fri, May 16, 2:33 PM
CarlSchwan committed rOJcbd05b4cbc1d: Rework networking (authored by CarlSchwan).
Rework networking
Fri, May 16, 2:22 PM
CarlSchwan committed rOJe2e5593cf61c: Fix typo (authored by CarlSchwan).
Fix typo
Fri, May 16, 2:22 PM
werner added a comment to T5993: gpg should reject compressed packets outside of messages.

It might be useful to have samples of compressed keys:

Fri, May 16, 2:20 PM · Feature Request, gnupg
werner committed rEcda4789a9f7d: Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET (authored by werner).
Time for a new error code; this time GPG_ERR_UNEXPECTED_PACKET
Fri, May 16, 12:48 PM
TobiasFella added a comment to T7650: Kleopatra: Limit width of KMessageBoxes.

Apparently KMessageBoxes do actually wrap, just at a larger width than we'd have expected. Lowering this width should be a trivial patch that we could do locally, if we want to

Fri, May 16, 12:09 PM · gpd5x, gpgpass, kleopatra
werner updated subscribers of T5993: gpg should reject compressed packets outside of messages.

No, we can't do much about this. It has always been easy to create compression bombs and the more relevant thing here is compressed signed or encrypted data. Or just compressed mails. The patch by @DemiMarie is way to complicated for what it wants to achieve and actually breaks existing use cases. For example Poppler uses GnuPG comment packets to lower its own attack surface by leaving all OpenPGP handling to gpg. The patch (or at least the version we noticed in Fedora and Debian) entirely breaks this use.

Fri, May 16, 12:04 PM · Feature Request, gnupg
timegrid created T7657: Kleopatra: Refresh OpenPGP Certificates doesn't respect WKD setting.
Fri, May 16, 11:19 AM · Feature Request, gpd5x, kleopatra
CarlSchwan committed rOJ76d54c30297d: Generate manifest.xml at runtime (authored by CarlSchwan).
Generate manifest.xml at runtime
Fri, May 16, 11:03 AM
CarlSchwan committed rOJ18f0bb7e0efa: Reencrypt in a seperate folder (authored by CarlSchwan).
Reencrypt in a seperate folder
Fri, May 16, 10:15 AM
CarlSchwan committed rOJ674254aebf70: Display name of folder to reencrypt (authored by CarlSchwan).
Display name of folder to reencrypt
Fri, May 16, 10:15 AM
CarlSchwan committed rOJd668b9750efb: reencryption: Display logs and reencryption state in a dialog (authored by CarlSchwan).
reencryption: Display logs and reencryption state in a dialog
Fri, May 16, 10:15 AM
timegrid created T7656: Kleopatra: Wrong update suggestion from 5.0.0 to 4.4.0.
Fri, May 16, 9:25 AM · Bug Report, gpd5x, kleopatra
gniibe committed rG40cfa71281db: common: Add KEM constants for NIST curves. (authored by gniibe).
common: Add KEM constants for NIST curves.
Fri, May 16, 7:08 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRAa88aff617ab1: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, May 16, 5:25 AM
l10n daemon script <scripty@kde.org> committed rMTP9a5f0d29218e: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, May 16, 3:49 AM
l10n daemon script <scripty@kde.org> committed rLIBKLEO00921c0a63e9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, May 16, 3:46 AM
l10n daemon script <scripty@kde.org> committed rKLEOPATRA67a3d0167d91: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Fri, May 16, 3:44 AM

Thu, May 15

werner added a comment to T7634: libgcrypt's test t-thread-local fails to link on some platforms..

Also pushed to 1.11

Thu, May 15, 9:48 PM · NetBSD, libgcrypt, Bug Report
werner committed rDba2663cda232: swdb: gpgol 2.6.1 (authored by werner).
swdb: gpgol 2.6.1
Thu, May 15, 4:08 PM
werner committed rO2ed92385c1d9: Post release updates (authored by werner).
Post release updates
Thu, May 15, 4:03 PM
werner committed rO4a9196cbb492: Release 2.6.1 (authored by werner).
Release 2.6.1
Thu, May 15, 4:03 PM
mmontkowski committed rO6cb4ccf4d8db: Handle filtered READ events (authored by mmontkowski).
Handle filtered READ events
Thu, May 15, 3:43 PM
werner committed rObda9f5afc8e6: Handle non mail items in inbox events (authored by mmontkowski).
Handle non mail items in inbox events
Thu, May 15, 3:43 PM
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: show a progress window when update a certificate to Kleopatra: show a progress window when updating a certificate.
Thu, May 15, 3:07 PM · gpd5x, kleopatra
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: Trying to update a certificate takes too much time if there is no network to Kleopatra: show a progress window when update a certificate.
Thu, May 15, 3:07 PM · gpd5x, kleopatra
ebo added a comment to T7495: Kleopatra: Improve success message on keyserver upload.

Hej thinks that she would expect the dialog to show which certificates were uploaded.
I think if we want to do that, we should make a new ticket for it. Here we wanted the easy quick fix.

Thu, May 15, 2:42 PM · kleopatra, gpd5x
TobiasFella changed the status of T7495: Kleopatra: Improve success message on keyserver upload from Open to Testing.
Thu, May 15, 1:33 PM · kleopatra, gpd5x
CarlSchwan added a comment to T7654: store app files in AppDate/Local/gpgol-web.

This is not really easy to change, since the proposed paths doesn't match QStandardPath

Thu, May 15, 1:13 PM · gpgol2
m <meik.michalke@gnupg.com> committed rOJb0eec451de48: updated README.md (authored by m <meik.michalke@gnupg.com>).
updated README.md
Thu, May 15, 1:12 PM
werner added a comment to D556: Disallow compressed signatures and certificates.

Way too complicate and thus has a high risk of regression,

Thu, May 15, 11:58 AM
TobiasFella committed rKLEOPATRA0484fe5985be: Improve success message for key upload (authored by TobiasFella).
Improve success message for key upload
Thu, May 15, 11:22 AM
TobiasFella changed the status of T7652: Kleopatra: Add plural in verification messages for multiple signatures from Open to Testing.
Thu, May 15, 11:22 AM · gpd5x, kleopatra
TobiasFella committed rKLEOPATRA73ca288b2ef5: Use plural when verifying multiple signatures from the same file (authored by TobiasFella).
Use plural when verifying multiple signatures from the same file
Thu, May 15, 11:15 AM
TobiasFella committed rKLEOPATRA94bafa83d1fc: Apply 1 suggestion(s) to 1 file(s) (authored by TobiasFella).
Apply 1 suggestion(s) to 1 file(s)
Thu, May 15, 11:12 AM
ikloecker committed rLIBKLEO0270587fe3cb: Use new startCreate overload (authored by ikloecker).
Use new startCreate overload
Thu, May 15, 10:05 AM
ikloecker committed rGPGMEQT1a063ce9332e: Remove long obsolete feature checks (authored by ikloecker).
Remove long obsolete feature checks
Thu, May 15, 10:00 AM
ikloecker committed rGPGMEQT3032aee35248: Modernize interface of QuickJob::startCreate and ::startAddSubkey (authored by ikloecker).
Modernize interface of QuickJob::startCreate and ::startAddSubkey
Thu, May 15, 10:00 AM
ikloecker committed rGPGMEPPee85d38a2f9e: Remove long obsolete feature checking API (authored by ikloecker).
Remove long obsolete feature checking API
Thu, May 15, 9:57 AM
ikloecker committed rGPGMEPP9200517f23c5: Remove deprecated functions and types (authored by ikloecker).
Remove deprecated functions and types
Thu, May 15, 9:57 AM
ikloecker committed rGPGMEPPd3559c8abcfe: Add CreationFlags and simplify API of createKey and createSubkey (authored by ikloecker).
Add CreationFlags and simplify API of createKey and createSubkey
Thu, May 15, 9:57 AM
ikloecker committed rGPGMEPP8b853b09d542: New decrypt flag DecryptListOnly (authored by ikloecker).
New decrypt flag DecryptListOnly
Thu, May 15, 9:57 AM
hej added a comment to T7581: Draft: Kleopatra: Create Group key.

"Geheimen Team-Schlüssel zum internen Teilen abspeichern." is grammatically correct, but it sound very formal and clunky for a UI tooltip. It lacks clarity, therefore I suggest:

Thu, May 15, 9:31 AM · Feature Request, gpd5x, kleopatra
ikloecker added a comment to T7655: Kleopatra: show a progress window when updating a certificate.

It's pretty much impossible to speed up the situation of unavailable network because network access typically uses long timeouts because networks can be notoriously slow to respond. The only thing we can do is show a progress window so that the users know that Kleopatra is actually doing something.

Thu, May 15, 9:11 AM · gpd5x, kleopatra
l10n daemon script <scripty@kde.org> committed rKLEOPATRA107e52b24cf9: GIT_SILENT Sync po/docbooks with svn (authored by l10n daemon script <scripty@kde.org>).
GIT_SILENT Sync po/docbooks with svn
Thu, May 15, 3:44 AM
gniibe committed rC0bd4c77be6e0: mpi:ec: Least leak with k^(-1) for ECDSA. (authored by gniibe).
mpi:ec: Least leak with k^(-1) for ECDSA.
Thu, May 15, 2:51 AM
gniibe committed rCaa089ec89bad: mpi:ec: Use ec_mulm_lli in _gcry_mpi_ec_get_affine. (authored by gniibe).
mpi:ec: Use ec_mulm_lli in _gcry_mpi_ec_get_affine.
Thu, May 15, 2:51 AM
gniibe changed the status of T7648: Decryption to a Ky768_Cv25519 key does not work if the Cv25519 key is on a token from Open to Testing.
Thu, May 15, 1:54 AM · PQC, Bug Report
gniibe closed T7621: libgpg-error: __non_string for GCC 15 or later, a subtask of T7617: libgcrypt: Add __nonstring__ attribute for data for GCC 15 or later, as Resolved.
Thu, May 15, 1:51 AM · libgcrypt, Bug Report
gniibe closed T7621: libgpg-error: __non_string for GCC 15 or later as Resolved.
Thu, May 15, 1:51 AM · gpgrt, Bug Report

Wed, May 14

ikloecker committed rKLEOPATRAb1f3736de7ed: Use Error::isError() to check if an error occurred (authored by ikloecker).
Use Error::isError() to check if an error occurred
Wed, May 14, 5:34 PM
ikloecker committed rKLEOPATRA10b618703d74: Include QGpgME/Debug for QDebug operator for GpgME::Error (authored by ikloecker).
Include QGpgME/Debug for QDebug operator for GpgME::Error
Wed, May 14, 5:34 PM
ikloecker committed rKLEOPATRAd4f777ffa137: Remove long obsolete feature check (authored by ikloecker).
Remove long obsolete feature check
Wed, May 14, 5:34 PM
werner committed rW0929cd3b6783: Rename packages.common to packages.list (authored by werner).
Rename packages.common to packages.list
Wed, May 14, 4:16 PM
werner committed rW383eb8586161: Update Okular for gnupg >= 2.4 to the correct version. (authored by werner).
Update Okular for gnupg >= 2.4 to the correct version.
Wed, May 14, 4:07 PM
werner committed rWe42e2d1d6037: Merge branch 'gpg4win-5-branch' (authored by werner).
Merge branch 'gpg4win-5-branch'
Wed, May 14, 3:58 PM
werner committed rW14ee2719e291: Merge branch 'gpg4win-5-branch' (authored by werner).
Merge branch 'gpg4win-5-branch'
Wed, May 14, 3:56 PM
ebo renamed T7655: Kleopatra: show a progress window when updating a certificate from Kleopatra: Trying to update a certificat takes too much time if there is no network to Kleopatra: Trying to update a certificate takes too much time if there is no network.
Wed, May 14, 3:55 PM · gpd5x, kleopatra
ebo triaged T7655: Kleopatra: show a progress window when updating a certificate as Normal priority.
Wed, May 14, 3:55 PM · gpd5x, kleopatra
m.eik triaged T7654: store app files in AppDate/Local/gpgol-web as Normal priority.
Wed, May 14, 3:45 PM · gpgol2
m.eik renamed T7613: GpgOL/Web shows wrong path to manifest in Gpg4Win from Gpg4Win is missing GpgOL/Web's manifest file to GpgOL/Web shows wrong path to manifest in Gpg4Win.
Wed, May 14, 3:41 PM · gpgol2
werner committed rDeffa3ea5e36e: Improve the make rules to upload sbdb.lst. (authored by werner).
Improve the make rules to upload sbdb.lst.
Wed, May 14, 3:35 PM
werner committed rD35d7563176ce: swdb: gnupg 2.4.8 (authored by werner).
swdb: gnupg 2.4.8
Wed, May 14, 3:33 PM
ebo updated the task description for T7636: Kleopatra: Handle not available keyserver or WKD when updating a certificate.
Wed, May 14, 3:24 PM · gpd5x, kleopatra
werner committed rGd48b26a2f6c7: Post release updates. (authored by werner).
Post release updates.
Wed, May 14, 3:05 PM
werner committed rG6f39568ae655: Release 2.4.8 (authored by werner).
Release 2.4.8
Wed, May 14, 3:05 PM
werner closed T6594: Okular: Proper about data customization as Resolved.

We have updated patches for long in the gpg4win repo and thus I close this bug.

Wed, May 14, 3:02 PM · Restricted Project, okular
ebo renamed T7636: Kleopatra: Handle not available keyserver or WKD when updating a certificate from Draft: Kleopatra: Handle not available keyserver or WKD when updating a certificate to Kleopatra: Handle not available keyserver or WKD when updating a certificate.
Wed, May 14, 2:48 PM · gpd5x, kleopatra
TobiasFella moved T7652: Kleopatra: Add plural in verification messages for multiple signatures from Backlog to WIP on the gpd5x board.
Wed, May 14, 1:10 PM · gpd5x, kleopatra
TobiasFella claimed T7652: Kleopatra: Add plural in verification messages for multiple signatures.
Wed, May 14, 1:10 PM · gpd5x, kleopatra
TobiasFella committed rKLEOPATRA52b8abf71c7a: Use plural when verifying multiple signatures from the same file (authored by TobiasFella).
Use plural when verifying multiple signatures from the same file
Wed, May 14, 1:10 PM
ebo updated the task description for T7495: Kleopatra: Improve success message on keyserver upload.
Wed, May 14, 12:40 PM · kleopatra, gpd5x
werner added a comment to T7589: Unable to export SSH keys for ED25519 keys generate on a SmartCard.

Using the primary key for ssh was not intended and thus not tested. I have not yet found the time too look closer at your report. Just one remark:

Wed, May 14, 12:32 PM · gnupg, ssh, Bug Report
TobiasFella committed rKLEOPATRA6a26951194e6: Improve success message for key upload (authored by TobiasFella).
Improve success message for key upload
Wed, May 14, 12:31 PM
TobiasFella moved T7495: Kleopatra: Improve success message on keyserver upload from Backlog to WIP on the gpd5x board.
Wed, May 14, 12:30 PM · kleopatra, gpd5x
TobiasFella committed rKLEOPATRA16e1b9dda0d3: Improve success message for key upload (authored by TobiasFella).
Improve success message for key upload
Wed, May 14, 12:30 PM
werner added a project to T7589: Unable to export SSH keys for ED25519 keys generate on a SmartCard: gnupg.
Wed, May 14, 12:07 PM · gnupg, ssh, Bug Report
TobiasFella changed the status of T7580: Kleopatra: Add a dialog window to the disable/enable certificate action, a subtask of T7216: Kleopatra: Integrate "disabled" feature from gpg, from Open to Testing.
Wed, May 14, 11:59 AM · Feature Request, kleopatra
TobiasFella changed the status of T7580: Kleopatra: Add a dialog window to the disable/enable certificate action from Open to Testing.
Wed, May 14, 11:59 AM · gpd5x, kleopatra
ebo renamed T7616: Kleopatra: add test to check connectivity from Draft: Kleopatra: add test to check connectivity to Kleopatra: add test to check connectivity.
Wed, May 14, 11:58 AM · gpd5x, Feature Request, kleopatra
ebo updated the task description for T7616: Kleopatra: add test to check connectivity.
Wed, May 14, 11:53 AM · gpd5x, Feature Request, kleopatra
TobiasFella committed rKLEOPATRAe3687a8bd666: Show warning when disabling certificate (authored by TobiasFella).
Show warning when disabling certificate
Wed, May 14, 11:52 AM
TobiasFella committed rKLEOPATRA07f33fc1840d: Remove linebreak (authored by TobiasFella).
Remove linebreak
Wed, May 14, 11:51 AM
TobiasFella committed rKLEOPATRA5b3ffbd0e037: Use proper name (authored by TobiasFella).
Use proper name
Wed, May 14, 11:51 AM
TobiasFella committed rKLEOPATRA8c7659ad0393: Change para to newline (authored by TobiasFella).
Change para to newline
Wed, May 14, 11:51 AM
TobiasFella committed rKLEOPATRA3dc182c3abe0: Update message (authored by TobiasFella).
Update message
Wed, May 14, 11:51 AM
TobiasFella committed rKLEOPATRA412abaa9ef1c: Use actual filter name (authored by TobiasFella).
Use actual filter name
Wed, May 14, 11:51 AM
TobiasFella committed rKLEOPATRA45ea52dcb594: Show warning when disabling certificate (authored by TobiasFella).
Show warning when disabling certificate
Wed, May 14, 11:51 AM
TobiasFella committed rLIBKLEOe25bfe8051f8: Add id for disabled filter (authored by TobiasFella).
Add id for disabled filter
Wed, May 14, 11:41 AM
ebo updated the task description for T7616: Kleopatra: add test to check connectivity.
Wed, May 14, 11:34 AM · gpd5x, Feature Request, kleopatra
ebo added a comment to T7581: Draft: Kleopatra: Create Group key.

Tooltip: Save this secret key to share with other team members.
dt. Menüeintrag: Geheimen Team-Schlüssel speichern
Tooltip: Geheimen Schlüssel speichern und mit Team teilen.

Wed, May 14, 11:21 AM · Feature Request, gpd5x, kleopatra
ikloecker committed rM15ae7da74bc4: Treat empty algorithm the same way as unset algorithm (authored by ikloecker).
Treat empty algorithm the same way as unset algorithm
Wed, May 14, 11:18 AM
ebo updated the task description for T7579: Draft: Kleopatra: improve menu items.
Wed, May 14, 10:48 AM · kleopatra, gpd5x