Page MenuHome GnuPG

needs discussionPolicy
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

Needs to be discussed…

Recent Activity

Wed, Apr 8

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe. EncryptionResult has a list of invalid recipients and I've changed the code to show the Retry dialog only if there's at least one invalid recipient.

Wed, Apr 8, 2:03 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Your suggestion sounds ok to me, maybe with a slight change for the message: "Failed to encrypt the notepad because at least on certificate could not be validated."

Wed, Apr 8, 1:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

I tried to add the list of invalid recipients to the message box, but it seems that gpgsm stops the validation of the certificates at the first invalid recipient. I got only the first Bob certificate reported as invalid recipient when I tried to encrypt to both Bob certificates so that it doesn't make sense to list the (incomplete) list of invalid recipients. It also means that Kleopatra cannot update the invalid recipient certificates because it knows only of one invalid certificate.

Wed, Apr 8, 12:18 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ideally the certificate would change, but Kleopatra has no idea that this certificate turned out to be not valid. In fact, Kleopatra doesn't even know that the encryption failed because of some certificate. It could have failed for any other reason (e.g. full disk). Kleopatra only knows that an error occurred and offers to retry with lower security. (I looked at GpgOL and it does the same.)

Wed, Apr 8, 10:50 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo updated subscribers of T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

yes, basically it's what we want.

Wed, Apr 8, 9:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Tue, Apr 7

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Current implementation for the case of an S/MIME certificate which turns out to be invalid when it's used for encryption. Is that what we want?

Tue, Apr 7, 5:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mon, Mar 30

ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:57 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a subtask for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker removed a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker renamed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Kleopatra: Use GPGME_ENCRYPT_ALWAYS_TRUST to Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:38 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mon, Mar 30, 11:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Fri, Mar 27

ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Before making subtickets for each application: I wonder if it is not all Kleopatra anyway? Isn't the security approval dialog basically Kleopatra?

Fri, Mar 27, 3:23 PM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

The equivalent for invalid S/MIME certificates are not-certified *PGP certificates.
(Valid/invalid are not ideal as technical terms as they have a broad general meaning, too. I hope my usage here is correct ;-) It is what I gathered from an explanation given by Werner.)

Fri, Mar 27, 3:07 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid updated the task description for T8190: GpgOL: Encrypt/Sign issues using S/MIME certs with invalid crlDP.
Fri, Mar 27, 1:16 PM · needs discussion, Bug Report, gpd5x, gpgol
timegrid updated the task description for T8190: GpgOL: Encrypt/Sign issues using S/MIME certs with invalid crlDP.
Fri, Mar 27, 1:14 PM · needs discussion, Bug Report, gpd5x, gpgol
ebo added a project to T8190: GpgOL: Encrypt/Sign issues using S/MIME certs with invalid crlDP: needs discussion.

feedback of @mmontkowski needed

Fri, Mar 27, 1:01 PM · needs discussion, Bug Report, gpd5x, gpgol
timegrid added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid certs (as stated in the status column in Kleopatra) are mainly S/MIME certs (e.g. with missing root cert, CRL check failed, etc). I haven't seen invalid pgp certs yet (might be e.g. very old ones with missing self signature).

Fri, Mar 27, 12:38 PM · gnupg, Feature Request, gpgol, kleopatra
ebo renamed T8193: Add a workflow to force encryption/signature with invalid or expired certificates from Draft: Add a workflow to force encryption/signature with invalid/expired/disabled certificates to Draft: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:49 AM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid and expired are different cases.

Fri, Mar 27, 11:37 AM · gnupg, Feature Request, gpgol, kleopatra
werner added a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Fri, Mar 27, 11:14 AM · gnupg, Feature Request, gpgol, kleopatra
werner added a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:14 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a project to T8116: Draft: Kleopatra: For S/MIME verification do not use "fingerprint" in messages: needs discussion.
Fri, Mar 27, 10:01 AM · needs discussion, gpd5x, kleopatra

Thu, Mar 26

timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Issue 1) should be implemented as already described (on error -> dialog to retry with "always trust" flag)

Thu, Mar 26, 3:33 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid triaged T8193: Add a workflow to force encryption/signature with invalid or expired certificates as Normal priority.
Thu, Mar 26, 3:31 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid edited projects for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted", added: needs discussion; removed Info Needed.

@ebo and me talked about this and T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST. We think, it's best to have a short meeting to discuss further changes.

Thu, Mar 26, 12:57 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mon, Mar 23

ikloecker removed projects from T6986: Refresh/update OpenPGP keys should check WKD: gpd5x, kleopatra.

Removing kleopatra tag since Kleopatra already does what's requested.

Mon, Mar 23, 9:05 AM · gnupg26, Bug Report, Feature Request
ebo added a project to T6986: Refresh/update OpenPGP keys should check WKD: needs discussion.
Mon, Mar 23, 8:41 AM · gnupg26, Bug Report, Feature Request

Fri, Mar 20

gniibe changed the status of T6425: improve pinentry behavior and texts in smart card context from Open to Testing.

Pushed the last change: rG2239f687bb14: scd:openpgp: UI improvement for use of PIN-entry.

Fri, Mar 20, 5:01 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report

Thu, Mar 19

ikloecker moved T7212: Problems with certificate colors / styles from Backlog to WIP on the vsd34 board.
Thu, Mar 19, 4:47 PM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
ikloecker changed the status of T7212: Problems with certificate colors / styles from Open to Testing.
Thu, Mar 19, 4:46 PM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
ikloecker added a comment to T7212: Problems with certificate colors / styles.

Backported for VSD 3.4

Thu, Mar 19, 4:44 PM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
ebo added a comment to T7212: Problems with certificate colors / styles.

The remaining open points of this ticket will be "won't fix" for now. When we plan to change something here, we should open new tickets, this one got confusing.

Thu, Mar 19, 4:24 PM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
gniibe added a comment to T6425: improve pinentry behavior and texts in smart card context .

This is a bit larger change (of UI improvement):

Thu, Mar 19, 6:55 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report

Wed, Mar 18

ikloecker added a project to T7540: Kleopatra: Wrong tab order in smart card window: needs discussion.
Wed, Mar 18, 10:28 AM · needs discussion, gpd5x, kleopatra
ikloecker placed T8154: Kleopatra: Adjust folder name in archive decryption feedback for single folder content up for grabs.
Wed, Mar 18, 10:25 AM · vsd34, gpd5x, kleopatra
ikloecker moved T8154: Kleopatra: Adjust folder name in archive decryption feedback for single folder content from WIP to Backlog on the gpd5x board.

It's not that simple. The user could have decrypted multiple archives. Showing an additional message box after all decrypted archives have been moved to the final destination somehow doesn't feel right. And what if an archive and a regular file were decrypted? Should the additional message box also show the final destination of the regular file? I think this needs more thought.

Wed, Mar 18, 10:21 AM · vsd34, gpd5x, kleopatra

Tue, Mar 17

ebo added a project to T7212: Problems with certificate colors / styles: vsd34.

added vsd34 for the resetting of the defaults

Tue, Mar 17, 10:21 AM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report

Mon, Mar 16

ikloecker added a comment to T7212: Problems with certificate colors / styles.

Filter 16 is the new filter for valid certificates. The problem could be that the version you tested did not yet have this filter.

Mon, Mar 16, 5:14 PM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report

Mar 13 2026

ebo added a comment to T7212: Problems with certificate colors / styles.

@ikloecker I'd like it if we could backport the resetting of the preferences to vsd34.

Mar 13 2026, 11:42 AM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
ebo added a comment to T7212: Problems with certificate colors / styles.

Font selection dialog lets the user choose a font size, which is then not respected - can we disable selecting the font size?

Mar 13 2026, 11:21 AM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report
ebo added a project to T7212: Problems with certificate colors / styles: needs discussion.
Mar 13 2026, 10:04 AM · vsd34, needs discussion, gpd5x, kleopatra, Bug Report

Mar 10 2026

gniibe added a comment to T6425: improve pinentry behavior and texts in smart card context .

I was wrong. gpg (scdaemon) needed to be fixed with more changes for the interaction with pinentry.

Mar 10 2026, 6:37 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report

Mar 9 2026

ebo added a comment to T6425: improve pinentry behavior and texts in smart card context .

I thought Gniibe's comment meant that gpg does report the errors now correctly…
So what is still to be done in gpg?

Mar 9 2026, 9:49 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report
ikloecker added a comment to T6425: improve pinentry behavior and texts in smart card context .

I don't think that anything of this can be changed in Kleopatra or even gpgme. Kleopatra relies on proper error codes by gpg.

Mar 9 2026, 9:45 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report

Mar 6 2026

ebo edited projects for T7502: Kleopatra: Import secret key dialog improvement, added: gpd5x (gpd-5.0.2); removed gpd5x.

I've created the ticket above for Q2, we need to discuss how to follow up Q1 and Q3 next week.

Mar 6 2026, 2:23 PM · gpd5x (gpd-5.0.2), vsd34, kleopatra
bernhard added a comment to T8059: Gpg4win: Change bug report address to a Gpg4win-specific address.

We should also change the "donate" button to Gpg4win then and the text to "voluntary payment".

Mar 6 2026, 2:20 PM · needs discussion, gpd5x, kleopatra, gpg4win
ebo added projects to T6425: improve pinentry behavior and texts in smart card context : kleopatra, needs discussion.

I guess those things need to be changed in Kleopatra after @gniibe made the changes in scd. I'll add a Kleo tag for discussion, as we should probably make several tickets from this.

Mar 6 2026, 10:43 AM · needs discussion, kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report
timegrid closed T6793: Cleanup temporary files / dirs with decrypted content as Resolved.

Ok, thanks. Closing the mail in Mailviewer will remove all temporary opened attachment files, so I'll set this to resolved.

Mar 6 2026, 8:11 AM · gpd5x, kleopatra