Page MenuHome GnuPG

kleopatraProject
ActivePublic

Details

Description

a GUI for GNU PG among other things

Recent Activity

Yesterday

ikloecker added a comment to T7502: Kleopatra: Import secret key dialog improvement.

If the user clicks the "No, others also use this key" button they get the following dialog

Thu, Feb 5, 4:57 PM · vsd34, gpd5x, kleopatra
ikloecker claimed T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 3:26 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker updated subscribers of T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

@werner: Shall we backport the fix to the gpgme-1.24-branch or do we just add a patch to gpg4win's gpg4win-4-branch and/or vsd-3.3-branch?

Thu, Feb 5, 3:24 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

I have verified (by locally applying the change to a Gpg4win 4 build) that ifdef'ing-out the above hack for Windows builds fixes the display issue.

Thu, Feb 5, 3:20 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker added a comment to T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.

The capping of the date seems to be caused by this workaround/hack in gpgme's _gpgme_parse_timestamp

/* Fixme: We would better use a configure test to see whether
   mktime can handle dates beyond 2038. */
if (sizeof (time_t) <= 4 && year >= 2038)
  return (time_t)2145914603; /* 2037-12-31 23:23:23 */
Thu, Feb 5, 2:27 PM · S/MIME, Bug Report, vsd34, kleopatra
timegrid created T8088: Kleopatra: Displayed S/MIME certificate expiration date capped at 2038.
Thu, Feb 5, 1:52 PM · S/MIME, Bug Report, vsd34, kleopatra
ikloecker changed the status of T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked from Open to Testing.
Thu, Feb 5, 11:33 AM · Bug Report, gpd5x, kleopatra
ikloecker added a comment to T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.

Now an expired signature with certified key is reported like this:

Thu, Feb 5, 11:33 AM · Bug Report, gpd5x, kleopatra
ikloecker added a comment to T6644: GnuPG: Allow non compliant signatures in compliance mode.

It looks like we get a specific "Invalid public key algorithm" error from gpgme so that we can add helpful information with likely reasons to the error message.

Thu, Feb 5, 11:01 AM · vsd, gpd5x, kleopatra, gnupg22
ikloecker changed the status of T8083: Kleopatra: Use blue icon for Gpg4win and GPD from Open to Testing.

The blue Kleopatra icon is now used for the Windows builds of Gpg4win and GPD and for the corresponding AppImages.

Thu, Feb 5, 10:37 AM · gpg4win, Feature Request, kleopatra, gpd5x
ikloecker created T8087: Kleopatra: Wrong or no system tray icon shown for AppImage.
Thu, Feb 5, 10:36 AM · Bug Report, gpd5x, AppImage, kleopatra
ikloecker created T8086: Kleopatra: Wrong or no application window/task bar icon shown for AppImage.
Thu, Feb 5, 10:36 AM · Bug Report, gpd5x, AppImage, kleopatra
ebo added a comment to T6644: GnuPG: Allow non compliant signatures in compliance mode.

I might add that we recently had a customer support contact where they had that error and asked how they could make using their S/MIME certificates work.

Thu, Feb 5, 10:20 AM · vsd, gpd5x, kleopatra, gnupg22
ikloecker renamed T8083: Kleopatra: Use blue icon for Gpg4win and GPD from Kleopatra icon color to Kleopatra: Use blue icon for Gpg4win and GPD.
Thu, Feb 5, 10:08 AM · gpg4win, Feature Request, kleopatra, gpd5x

Wed, Feb 4

ikloecker changed the status of T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked from Testing to Open.
Wed, Feb 4, 9:12 PM · Bug Report, gpd5x, kleopatra
ikloecker moved T8083: Kleopatra: Use blue icon for Gpg4win and GPD from Backlog to WIP on the gpd5x board.
Wed, Feb 4, 2:44 PM · gpg4win, Feature Request, kleopatra, gpd5x
ikloecker moved T8082: Kleopatra does not use the correct gpgconf from Backlog to WIP on the vsd34 board.

Backported for VSD 3.4

Wed, Feb 4, 2:43 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
ikloecker changed the status of T8082: Kleopatra does not use the correct gpgconf from Open to Testing.

Fixed. Kleopatra now looks for programs given as plain name (i.e. without any path) first in the GnuPG installation path (as reported by gpgme) and then next to the kleopatra executable. If the program is found at neither location it is run as-is.

Wed, Feb 4, 2:42 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
ebo added a comment to T8035: Kleopatra: Good signatures are reported as invalid signatures if key is expired or revoked.

For "expired signature with certified key" I believe green with check mark is a too positive. Should be a warning, too.

Wed, Feb 4, 2:18 PM · Bug Report, gpd5x, kleopatra
ikloecker moved T8082: Kleopatra does not use the correct gpgconf from Backlog to WIP on the gpd5x board.
Wed, Feb 4, 11:24 AM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
ebo added a comment to T7502: Kleopatra: Import secret key dialog improvement.

The text is exactly as discussed and I'm OK with the layout, too.

Wed, Feb 4, 11:13 AM · vsd34, gpd5x, kleopatra

Tue, Feb 3

ikloecker claimed T8083: Kleopatra: Use blue icon for Gpg4win and GPD.
Tue, Feb 3, 10:30 PM · gpg4win, Feature Request, kleopatra, gpd5x
ikloecker claimed T8082: Kleopatra does not use the correct gpgconf.
Tue, Feb 3, 10:22 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
werner triaged T8083: Kleopatra: Use blue icon for Gpg4win and GPD as Normal priority.
Tue, Feb 3, 5:14 PM · gpg4win, Feature Request, kleopatra, gpd5x
ikloecker added a comment to T7502: Kleopatra: Import secret key dialog improvement.

Is this wording / layout okay?


Tue, Feb 3, 3:46 PM · vsd34, gpd5x, kleopatra
werner added projects to T8082: Kleopatra does not use the correct gpgconf: gpd5x, vsd34.
Tue, Feb 3, 3:45 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
werner triaged T8082: Kleopatra does not use the correct gpgconf as High priority.
Tue, Feb 3, 3:04 PM · vsd34, gpd5x, gpg4win, Bug Report, gpd, vsd, kleopatra
ikloecker claimed T7502: Kleopatra: Import secret key dialog improvement.
Tue, Feb 3, 1:42 PM · vsd34, gpd5x, kleopatra
timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

The display in Okular is independent from Kleopatra, so dropping it in Kleopatra should be fine.
If a QES certificate is available, Okular should highlight and add a filter for them (which is currently not working, see T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures)

Tue, Feb 3, 1:34 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

I currently have a slight preference to drop bold and go with normal font. Werner would be ok with that, too.

Tue, Feb 3, 1:17 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid updated subscribers of T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

@svuorela said, QES certs shouldn't be required to be on a smartcard.

Tue, Feb 3, 12:20 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Using an icon for QES certificates isn't that easy because we use an icon for smartcard certificates and any list item can have at most one icon. Moreover, QES certificates are very like stored on a smartcard (isn't that even a requirement?), i.e. an icon clash is basically guaranteed.

Tue, Feb 3, 11:49 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker changed the status of T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong from Open to Testing.

Additionally, the de-vs-compliance filters are no longer show in non-compliant installations like Gpg4win.

Tue, Feb 3, 11:42 AM · gpd5x, Bug Report, kleopatra
timegrid added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

In T6632: Okular: Highlight / preselect "nonRepudiation" certificates for qualified signatures I had the impression, that some hint is useful for signing operations. Probably not so much in general.

Tue, Feb 3, 11:04 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker claimed T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong.
Tue, Feb 3, 11:03 AM · gpd5x, Bug Report, kleopatra
ikloecker changed the status of T7950: Kleopatra: Add filter for valid certificates from Open to Testing.

Done and backported for VSD 3.4

Tue, Feb 3, 11:01 AM · Feature Request, vsd34, gpd5x, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Highlighting QES is mostly useful for Okular, I guess.
Maybe use a symbol with a pen? That should be self-explanatory.

Tue, Feb 3, 10:44 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo triaged T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys as Normal priority.
Tue, Feb 3, 10:40 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
timegrid added a project to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys: needs discussion.
Tue, Feb 3, 10:30 AM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo renamed T7950: Kleopatra: Add filter for valid certificates from Kleopatra: Add filter for usable certificates to Kleopatra: Add filter for valid certificates.
Tue, Feb 3, 9:22 AM · Feature Request, vsd34, gpd5x, kleopatra
ikloecker added a comment to T7950: Kleopatra: Add filter for valid certificates.

We decided to still use the term "Valid" (with description/tooltip "Certificates that are neither expired nor revoked (except disabled ones)"). This matches the use of the term "invalid" for expired and revoked certificates as in "Certificates that are invalid because they have expired (except disabled ones)".

Tue, Feb 3, 9:09 AM · Feature Request, vsd34, gpd5x, kleopatra
ikloecker claimed T7950: Kleopatra: Add filter for valid certificates.
Tue, Feb 3, 9:04 AM · Feature Request, vsd34, gpd5x, kleopatra

Mon, Feb 2

ikloecker added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

This overloading of "bold" for "my certificates", "qualified certificates" and "trusted root certificates" seems to exist since two decades. I stopped digging into ancient history at the commit that added the hard-coded default filters.

Mon, Feb 2, 5:40 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
werner added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Take care: Too many attributes (color, font) are bad style.

Mon, Feb 2, 5:08 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ebo triaged T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong as Normal priority.
Mon, Feb 2, 5:05 PM · gpd5x, Bug Report, kleopatra
ikloecker created T8079: Kleopatra: Order of filters with custom id in settings dialog is wrong.
Mon, Feb 2, 4:32 PM · gpd5x, Bug Report, kleopatra
ebo added a comment to T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.

Well, the qual flag should only be set for CAs dedicated to certifying QES certificates. And those should by definition be signature certificates only, afaik.

Mon, Feb 2, 3:32 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra
ikloecker moved T7967: Kleopatra: User specific text on the welcome page. from Backlog to WIP on the vsd34 board.

Backported for VSD 3.4

Mon, Feb 2, 3:22 PM · Feature Request, gpd5x, vsd34, vsd, kleopatra
ikloecker changed the status of T7967: Kleopatra: User specific text on the welcome page. from Open to Testing.

Done. Example (with default text in English and German translation):

[Welcome]
welcome-text[$i]=<h2>Hello, World!</h2>
welcome-text[$i][de]=<h2>Hallo, Welt!</h2>
Mon, Feb 2, 3:13 PM · Feature Request, gpd5x, vsd34, vsd, kleopatra
timegrid created T8077: Kleopatra: Bold appearance for qualified signatures might be confusing for public and non-signing keys.
Mon, Feb 2, 2:48 PM · needs discussion, S/MIME, vsd34, gpd5x, kleopatra