Page MenuHome GnuPG

S/MIMEProject
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Recent Activity

Mon, Feb 9

ikloecker changed the status of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038 from Open to Testing.

Okay, then I set the ticket to Testing.

Mon, Feb 9, 7:24 PM · S/MIME, Bug Report, vsd34, kleopatra
werner added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

Your fix is okay.

Mon, Feb 9, 10:13 AM · S/MIME, Bug Report, vsd34, kleopatra

Fri, Feb 6

ebo triaged T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038 as High priority.
Fri, Feb 6, 10:10 AM · S/MIME, Bug Report, vsd34, kleopatra

Thu, Feb 5

ikloecker claimed T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 3:26 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker updated subscribers of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

@werner: Shall we backport the fix to the gpgme-1.24-branch or do we just add a patch to gpg4win's gpg4win-4-branch and/or vsd-3.3-branch?

Thu, Feb 5, 3:24 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

I have verified (by locally applying the change to a Gpg4win 4 build) that ifdef'ing-out the above hack for Windows builds fixes the display issue.

Thu, Feb 5, 3:20 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

The capping of the date seems to be caused by this workaround/hack in gpgme's _gpgme_parse_timestamp

/* Fixme: We would better use a configure test to see whether
   mktime can handle dates beyond 2038. */
if (sizeof (time_t) <= 4 && year >= 2038)
  return (time_t)2145914603; /* 2037-12-31 23:23:23 */
Thu, Feb 5, 2:27 PM · S/MIME, Bug Report, vsd34, kleopatra
mmontkowski closed T7836: GpgOL: Both disable and prefer S/MIME does not work as Invalid.

The problem resulted from a split up key (one for encryption and one for signing) Resulting in no SMIME encryption key found for one recipient and thus falling back to OpenPGP.

Thu, Feb 5, 2:24 PM · S/MIME, gpgol
timegrid created T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 1:52 PM · S/MIME, Bug Report, vsd34, kleopatra

Wed, Feb 4

ebo renamed T6152: Allow giving context to gpg-agent from Text for Import of S/MIME certificates to Allow giving context to gpg-agent.
Wed, Feb 4, 11:56 AM · gnupg26, Feature Request, S/MIME
ebo edited projects for T6152: Allow giving context to gpg-agent, added: gnupg26; removed gnupg, Restricted Project.
Wed, Feb 4, 11:53 AM · gnupg26, Feature Request, S/MIME

Tue, Feb 3

timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

The display in Okular is independent from Kleopatra, so dropping it in Kleopatra should be fine.
If a QES certificate is available, Okular should highlight and add a filter for them (which is currently not working, see T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures)

Tue, Feb 3, 1:34 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

I currently have a slight preference to drop bold and go with normal font. Werner would be ok with that, too.

Tue, Feb 3, 1:17 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid assigned T7836: GpgOL: Both disable and prefer S/MIME does not work to mmontkowski.

a) Here's a log anyway (ignore it, if decryption does always work):

Tue, Feb 3, 12:31 PM · S/MIME, gpgol
timegrid updated subscribers of T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

@svuorela said, QES certs shouldn't be required to be on a smartcard.

Tue, Feb 3, 12:20 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Using an icon for QES certificates isn't that easy because we use an icon for smartcard certificates and any list item can have at most one icon. Moreover, QES certificates are very like stored on a smartcard (isn't that even a requirement?), i.e. an icon clash is basically guaranteed.

Tue, Feb 3, 11:49 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

In T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures I had the impression, that some hint is useful for signing operations. Probably not so much in general.

Tue, Feb 3, 11:04 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Highlighting QES is mostly useful for Okular, I guess.
Maybe use a symbol with a pen? That should be self-explanatory.

Tue, Feb 3, 10:44 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo triaged T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys as Normal priority.
Tue, Feb 3, 10:40 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid added a project to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys: needs discussion.
Tue, Feb 3, 10:30 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra

Mon, Feb 2

ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

This overloading of "bold" for "my certificates", "qualified certificates" and "trusted root certificates" seems to exist since two decades. I stopped digging into ancient history at the commit that added the hard-coded default filters.

Mon, Feb 2, 5:40 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
werner added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Take care: Too many attributes (color, font) are bad style.

Mon, Feb 2, 5:08 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo updated the task description for T7836: GpgOL: Both disable and prefer S/MIME does not work.
Mon, Feb 2, 5:07 PM · S/MIME, gpgol
ebo added a comment to T7836: GpgOL: Both disable and prefer S/MIME does not work.

a) "Prefer S/MIME" only applies to encryption, not decryption. If you do not want to decrypt with GpgOL you have to disable S/MIME in GpgOL.

Mon, Feb 2, 4:47 PM · S/MIME, gpgol
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Well, the qual flag should only be set for CAs dedicated to certifying QES certificates. And those should by definition be signature certificates only, afaik.

Mon, Feb 2, 3:32 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid created T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.
Mon, Feb 2, 2:48 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra

Fri, Jan 30

timegrid closed T8053: GpgSM: `log-file` is ignored as Invalid.

Ah, thanks for the pointer, I did not expect gpgsm to behave differently here. Then it's probably intentional and I'll close this as invalid.

Fri, Jan 30, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26
pl13 added a comment to T8053: GpgSM: `log-file` is ignored.

The gnupg manual (page 113) mentions:

Fri, Jan 30, 10:30 AM · gpd5x, Bug Report, S/MIME, gnupg26

Thu, Jan 29

timegrid added a comment to T6152: Allow giving context to gpg-agent.

Current state in gpg4win-5.0.0:

Thu, Jan 29, 4:09 PM · gnupg26, Feature Request, S/MIME
ebo lowered the priority of T6516: Kleopatra: Indicate CRL check failure when validating certificates from Normal to Low.
Thu, Jan 29, 3:45 PM · gpd5x, S/MIME, kleopatra

Mon, Jan 26

timegrid added a comment to T8053: GpgSM: `log-file` is ignored.

There's no other configuration, this happens with a clean gnupghome with one smime cert + root cert and the above gpgsm.conf (output on stdin/stderr):

Mon, Jan 26, 11:18 AM · gpd5x, Bug Report, S/MIME, gnupg26

Fri, Jan 23

werner added a comment to T8053: GpgSM: `log-file` is ignored.

Please run with --debug 0 which should show you which confiration files are read in which order. Is there anything in a common.conf file? A log-file statement tehre would overwrite the command line option.

Fri, Jan 23, 9:16 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid created T8053: GpgSM: `log-file` is ignored.
Fri, Jan 23, 2:28 PM · gpd5x, Bug Report, S/MIME, gnupg26
timegrid changed the edit policy for T6677: GPGSM: Add support for cert extension 2.5.29.36 Policy Constraints.
Fri, Jan 23, 11:19 AM · Feature Request, gnupg26, S/MIME

Wed, Jan 21

ebo raised the priority of T8019: gpg does not print warning about untrusted key when verifying signatures made by expired (and untrusted) keys from Normal to High.

setting to High as we need this for T7790

Wed, Jan 21, 11:40 AM · Feature Request, S/MIME, OpenPGP, gnupg26
werner closed T8032: libksba: Input validation for DER encoded INTEGER as Wontfix.
Wed, Jan 21, 10:39 AM · S/MIME, libksba, Bug Report
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

The "ca" root cert is not on the ldap, if that matters

Wed, Jan 21, 10:23 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from GnuPG: S/MIME certificate is imported on ldap search to Keyboxd: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:14 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

some other certificates, but I guess those are from other tests

Wed, Jan 21, 10:08 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a project to T8048: Keyboxd: S/MIME certificate is imported on ldap search: Bug Report.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid renamed T8048: Keyboxd: S/MIME certificate is imported on ldap search from Kleopatra: S/MIME certificate is imported on ldap search to GnuPG: S/MIME certificate is imported on ldap search.
Wed, Jan 21, 10:00 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

It also happens on CLI:

Wed, Jan 21, 9:59 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

With Gpg4win 5.0.0 the LISTKEYS after the server lookup lists the (ephemeral?) ca@gnupg.test certificate and (!) the bob@gnupg.test certificate (and some other certificates, but I guess those are from other tests).

Wed, Jan 21, 9:52 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. VSD 3.3.4
Wed, Jan 21, 9:45 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  1. Gpg4win 5.0.0
Wed, Jan 21, 9:44 AM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x

Tue, Jan 20

timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.
  • gpg4win 5.0.0 @ win11
Tue, Jan 20, 2:59 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
ikloecker added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

gpgme logs (also of vsd-3.3.4) will be useful.

Tue, Jan 20, 2:47 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
werner added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

I have not checked but I guess that the certificate is marked as ephemeal and kleopatra either lists ephemeral certificates or the ephemeral flag got removed to to a validation process,

Tue, Jan 20, 2:43 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid added a comment to T8048: Keyboxd: S/MIME certificate is imported on ldap search.

Note: This does not happen on vsd-3.3.4

Tue, Jan 20, 2:37 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x
timegrid created T8048: Keyboxd: S/MIME certificate is imported on ldap search.
Tue, Jan 20, 1:56 PM · keyboxd, Bug Report, gnupg26, S/MIME, LDAP, gpd5x