Page MenuHome GnuPG

vsd34Project
ActivePublic

Milestones

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Recent Activity

Sun, Apr 26

werner shifted T8210: Kleopatra: LPE issue on Windows from the Restricted Space space to the S1 Public space.
Sun, Apr 26, 6:45 PM · vsd34, gpd5x, kleopatra, Security, Bug Report
werner triaged T8210: Kleopatra: LPE issue on Windows as Normal priority.
Sun, Apr 26, 6:45 PM · vsd34, gpd5x, kleopatra, Security, Bug Report

Thu, Apr 23

ebo added projects to T8210: Kleopatra: LPE issue on Windows: gpd5x, vsd34.

As I'd like to have it in vsd34, I'll set that tag (and of course gpd5x, too)

Thu, Apr 23, 3:09 PM · vsd34, gpd5x, kleopatra, Security, Bug Report

Tue, Apr 21

ikloecker changed the status of T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Open to Testing.

Implemented for the Notepad and Sign/Encrypt Files. Can be tested with the certificates in T6702#216065.

Tue, Apr 21, 4:33 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Thu, Apr 16

timegrid moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from QA to vsd-3.3.7 on the vsd33 board.
Thu, Apr 16, 12:54 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
timegrid added a comment to T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely.

Looks good to me on vsd-3.3.7-beta90.9 @ win10:

Thu, Apr 16, 12:53 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ebo moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from WiP to QA on the vsd33 board.
Thu, Apr 16, 11:22 AM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra

Wed, Apr 15

ebo updated the task description for T7717: Location of qt-application config files.
Wed, Apr 15, 2:28 PM · gpd5x (gpd-5.0.0), Windows, kleopatra, vsd34, okular
timegrid updated the task description for T8226: GpgOL: Last image in mail signature shown as attachment in mails with no attachments.
Wed, Apr 15, 11:38 AM · vsd34, gpgol
timegrid triaged T8226: GpgOL: Last image in mail signature shown as attachment in mails with no attachments as Low priority.
Wed, Apr 15, 11:33 AM · vsd34, gpgol

Tue, Apr 14

ebo added a comment to T7212: Problems with certificate colors / styles.

Seems I forgot to note that icon removal works when resetting to defaults. And the VSD related Categories are no longer shown in Gpg4win. Tested now with Gpg4win 5.0.2, but I believe it was already ok in 5.0.0.

Tue, Apr 14, 2:19 PM · vsd34, gpd5x, kleopatra, Bug Report
pl13 moved T8221: gpgsm: emit more details when failing to check a crl from a crlDP from Backlog to WIP on the vsd34 board.
Tue, Apr 14, 1:08 PM · gpd5x, vsd34, Feature Request
pl13 moved T8221: gpgsm: emit more details when failing to check a crl from a crlDP from Backlog to WIP on the gpd5x board.
Tue, Apr 14, 1:07 PM · gpd5x, vsd34, Feature Request
pl13 triaged T8221: gpgsm: emit more details when failing to check a crl from a crlDP as Wishlist priority.
Tue, Apr 14, 9:18 AM · gpd5x, vsd34, Feature Request

Mon, Apr 13

ebo updated the task description for T7212: Problems with certificate colors / styles.
Mon, Apr 13, 12:11 PM · vsd34, gpd5x, kleopatra, Bug Report

Wed, Apr 8

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe. EncryptionResult has a list of invalid recipients and I've changed the code to show the Retry dialog only if there's at least one invalid recipient.

Wed, Apr 8, 2:03 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Your suggestion sounds ok to me, maybe with a slight change for the message: "Failed to encrypt the notepad because at least on certificate could not be validated."

Wed, Apr 8, 1:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

I tried to add the list of invalid recipients to the message box, but it seems that gpgsm stops the validation of the certificates at the first invalid recipient. I got only the first Bob certificate reported as invalid recipient when I tried to encrypt to both Bob certificates so that it doesn't make sense to list the (incomplete) list of invalid recipients. It also means that Kleopatra cannot update the invalid recipient certificates because it knows only of one invalid certificate.

Wed, Apr 8, 12:18 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ideally the certificate would change, but Kleopatra has no idea that this certificate turned out to be not valid. In fact, Kleopatra doesn't even know that the encryption failed because of some certificate. It could have failed for any other reason (e.g. full disk). Kleopatra only knows that an error occurred and offers to retry with lower security. (I looked at GpgOL and it does the same.)

Wed, Apr 8, 10:50 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo updated subscribers of T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

yes, basically it's what we want.

Wed, Apr 8, 9:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Tue, Apr 7

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Current implementation for the case of an S/MIME certificate which turns out to be invalid when it's used for encryption. Is that what we want?

Tue, Apr 7, 5:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mar 30 2026

timegrid moved T8161: Invalid MimeType Related instead of Mixed from Backlog to WIP on the vsd34 board.
Mar 30 2026, 2:31 PM · vsd34, gpd5x, gpgol
ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mar 30 2026, 11:57 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mar 30 2026, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mar 30 2026, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker renamed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Kleopatra: Use GPGME_ENCRYPT_ALWAYS_TRUST to Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mar 30 2026, 11:38 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mar 30 2026, 11:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mar 27 2026

werner added a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mar 27 2026, 11:14 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
werner added a comment to T7843: GpgOL: Empty OpenPGP mails with "Read as plain" activated.

Not a good idea. Because then the user will open it with the browser and the browser loads all kind of additional data including drive-by malware. If HTML *mail* is shown by a MUA no links should be followed to keep information and the fact that it was read confidential.

Mar 27 2026, 11:05 AM · vsd34, vsd, gpgol

Mar 26 2026

timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Issue 1) should be implemented as already described (on error -> dialog to retry with "always trust" flag)

Mar 26 2026, 3:33 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid edited projects for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted", added: needs discussion; removed Info Needed.

@ebo and me talked about this and T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST. We think, it's best to have a short meeting to discuss further changes.

Mar 26 2026, 12:57 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mar 25 2026

ikloecker placed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" up for grabs.
Mar 25 2026, 10:04 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a project to T8161: Invalid MimeType Related instead of Mixed: vsd34.
Mar 25 2026, 9:32 AM · vsd34, gpd5x, gpgol

Mar 24 2026

ikloecker changed the status of T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from Open to Testing.
Mar 24 2026, 4:47 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from Backlog to WiP on the vsd33 board.
Mar 24 2026, 4:37 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker added a project to T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely: vsd33.

I have added the fix as patch for VSD 3.3 because the commits that introduced this regression were also added as patches for VSD 3.3.

Mar 24 2026, 4:36 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker added a comment to T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely.

This is a regression that was introduced with T7759: Kleopatra: Notepad encryption with S/MIME fails.

Mar 24 2026, 4:25 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from Backlog to QA for next release on the gpgme board.
Mar 24 2026, 4:07 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from Backlog to WIP on the vsd34 board.

Fixed. For VSD 3.4 this will also be fixed if gpgme is updated.

Mar 24 2026, 4:07 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker added a project to T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely: gpgme.

This is a bug in gpgme. gpgsm_assuan_simple_command only reads a single line before waiting for more data although there is a second line (ERR ...) ready to be read. gpgsm never sends more data because it has already sent its full answer. So gpgme waits forever.

Mar 24 2026, 3:44 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ikloecker claimed T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely.
Mar 24 2026, 2:28 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ticket for the hang on file encryption: T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely

Mar 24 2026, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid triaged T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely as Normal priority.
Mar 24 2026, 11:38 AM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

According to Werner, that should be:

Mar 24 2026, 11:07 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe those smime certs will do:

Mar 24 2026, 10:23 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mar 24 2026, 10:07 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a project to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": Info Needed.

It needs to be clarified which kind of errors should be handled and which kind of S/MIME certificates should be allowed to be used for encryption:

  • Valid certificates where the CRL check (or OCSP check?) fails
  • Invalid certificates (e.g. because of incomplete chain/missing CA)
  • Expired certificates
Mar 24 2026, 9:34 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mar 23 2026

ikloecker moved T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Backlog to WIP on the gpd5x board.
Mar 23 2026, 3:28 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mar 23 2026, 3:28 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Do we have a test certificate for this? The certificate in T6702#176845 is expired.

Mar 23 2026, 3:02 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra