Page MenuHome GnuPG

kleopatraProject
ActivePublic

Details

Description

a GUI for GNU PG among other things

Recent Activity

Yesterday

timegrid moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from QA to vsd-3.3.7 on the vsd33 board.
Thu, Apr 16, 12:54 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
timegrid added a comment to T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely.

Looks good to me on vsd-3.3.7-beta90.9 @ win10:

Thu, Apr 16, 12:53 PM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ebo moved T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely from WiP to QA on the vsd33 board.
Thu, Apr 16, 11:22 AM · vsd33 (vsd-3.3.7), gpgme, Bug Report, gpd5x, vsd34, S/MIME, kleopatra
ebo closed T7639: Kleopatra: Version information sometimes not shown. as Resolved.

It is also shown in gpd-5.0.2:

Thu, Apr 16, 9:40 AM · vsd33 (vsd-3.3.3), Bug Report, gpd5x, kleopatra
ebo closed T7678: Kleopatra: revoked UIDs should not be offered for signing and they should be labeled consistently as Resolved.
Thu, Apr 16, 9:28 AM · vsd33 (vsd-3.3.3), Bug Report, kleopatra

Wed, Apr 15

ebo updated the task description for T7717: Location of qt-application config files.
Wed, Apr 15, 2:28 PM · gpd5x (gpd-5.0.0), Windows, kleopatra, vsd34, okular

Tue, Apr 14

timegrid merged task T7954: Kleopatra: Highlight focused cell in tables into T8219: Kleopatra: Focus in tables is not visible.
Tue, Apr 14, 3:08 PM · a11y, gpd5x, kleopatra
timegrid merged T7954: Kleopatra: Highlight focused cell in tables into T8219: Kleopatra: Focus in tables is not visible.
Tue, Apr 14, 3:08 PM · a11y, gpd5x, kleopatra
timegrid added a comment to T8219: Kleopatra: Focus in tables is not visible.

I once creates this task, which is probably a duplicate now: T7954: Kleopatra: Highlight focused cell in tables

Tue, Apr 14, 2:59 PM · a11y, gpd5x, kleopatra
ikloecker added a comment to T7980: Draft: Kleopatra: Add long KeyID to recipient listing (ADSK related).

In general, we don't show the key IDs. User ID + creation date will almost always uniquely identify all keys. (And only the fingerprint truly identifies a key anyway.)

Tue, Apr 14, 2:41 PM · needs discussion, gpd5x, kleopatra
ebo added a comment to T7212: Problems with certificate colors / styles.

Seems I forgot to note that icon removal works when resetting to defaults. And the VSD related Categories are no longer shown in Gpg4win. Tested now with Gpg4win 5.0.2, but I believe it was already ok in 5.0.0.

Tue, Apr 14, 2:19 PM · vsd34, gpd5x, kleopatra, Bug Report
ebo added a comment to T7334: Kleopatra: ADSK shown as "unknown recipient".

If Tobias remembered correctly, then https://dev.gnupg.org/T7334#193396 still needs to be implemented.

Tue, Apr 14, 2:02 PM · gpd5x, kleopatra
ebo placed T7334: Kleopatra: ADSK shown as "unknown recipient" up for grabs.
Tue, Apr 14, 2:00 PM · gpd5x, kleopatra
ebo added a project to T7980: Draft: Kleopatra: Add long KeyID to recipient listing (ADSK related): needs discussion.
Tue, Apr 14, 1:59 PM · needs discussion, gpd5x, kleopatra
ebo removed a project from T7814: Kleopatra: Save status of checkbox "Encrypt for others": gpd5x.
Tue, Apr 14, 1:54 PM · kleopatra
ebo removed a project from T6425: improve pinentry behavior and texts in smart card context : needs discussion.
Tue, Apr 14, 1:52 PM · kleopatra, gpd5x, gnupg24 (gnupg-2.4.5), scd, Bug Report

Mon, Apr 13

ebo updated the task description for T8219: Kleopatra: Focus in tables is not visible.
Mon, Apr 13, 4:28 PM · a11y, gpd5x, kleopatra
ebo triaged T8219: Kleopatra: Focus in tables is not visible as Normal priority.
Mon, Apr 13, 4:15 PM · a11y, gpd5x, kleopatra
ebo added a project to T7540: Kleopatra: Wrong tab order in smart card window: a11y.
Mon, Apr 13, 3:27 PM · a11y, needs discussion, gpd5x, kleopatra
ebo added a comment to T7540: Kleopatra: Wrong tab order in smart card window.

ok, neither is a no-brainer, i see. But I would vote for the left to right order, i.e. the alternative you mention. This has the advantage that the card type is listed on the left side with which one can maybe better identify the card. In my example the type is "Yubico OpenPGP-v.3.4-card", I do not see the info that it is a Yubikey anywhere else. Therefore a blind user will only get that info up front if the left side is read first.

Mon, Apr 13, 3:27 PM · a11y, needs discussion, gpd5x, kleopatra
ebo updated the task description for T7212: Problems with certificate colors / styles.
Mon, Apr 13, 12:11 PM · vsd34, gpd5x, kleopatra, Bug Report

Wed, Apr 8

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe. EncryptionResult has a list of invalid recipients and I've changed the code to show the Retry dialog only if there's at least one invalid recipient.

Wed, Apr 8, 2:03 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Your suggestion sounds ok to me, maybe with a slight change for the message: "Failed to encrypt the notepad because at least on certificate could not be validated."

Wed, Apr 8, 1:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

I tried to add the list of invalid recipients to the message box, but it seems that gpgsm stops the validation of the certificates at the first invalid recipient. I got only the first Bob certificate reported as invalid recipient when I tried to encrypt to both Bob certificates so that it doesn't make sense to list the (incomplete) list of invalid recipients. It also means that Kleopatra cannot update the invalid recipient certificates because it knows only of one invalid certificate.

Wed, Apr 8, 12:18 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ideally the certificate would change, but Kleopatra has no idea that this certificate turned out to be not valid. In fact, Kleopatra doesn't even know that the encryption failed because of some certificate. It could have failed for any other reason (e.g. full disk). Kleopatra only knows that an error occurred and offers to retry with lower security. (I looked at GpgOL and it does the same.)

Wed, Apr 8, 10:50 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo updated subscribers of T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

yes, basically it's what we want.

Wed, Apr 8, 9:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Tue, Apr 7

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Current implementation for the case of an S/MIME certificate which turns out to be invalid when it's used for encryption. Is that what we want?

Tue, Apr 7, 5:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mon, Mar 30

timegrid renamed T8193: Add a workflow to force encryption/signature with invalid or expired certificates from Draft: Add a workflow to force encryption/signature with invalid or expired certificates to Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 1:16 PM · gnupg, Feature Request, gpgol, kleopatra
ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:57 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker triaged T8201: Kleopatra: Optionally, allow encryption with invalid or expired certificates as Normal priority.
Mon, Mar 30, 11:54 AM · gpd5x, Feature Request, kleopatra
ikloecker added a subtask for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker removed a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker renamed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Kleopatra: Use GPGME_ENCRYPT_ALWAYS_TRUST to Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:38 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mon, Mar 30, 11:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a parent task for T6559: GPGSM: "always trust like override" or "force" option: T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mon, Mar 30, 11:31 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project

Fri, Mar 27

ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Before making subtickets for each application: I wonder if it is not all Kleopatra anyway? Isn't the security approval dialog basically Kleopatra?

Fri, Mar 27, 3:23 PM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

The equivalent for invalid S/MIME certificates are not-certified *PGP certificates.
(Valid/invalid are not ideal as technical terms as they have a broad general meaning, too. I hope my usage here is correct ;-) It is what I gathered from an explanation given by Werner.)

Fri, Mar 27, 3:07 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid certs (as stated in the status column in Kleopatra) are mainly S/MIME certs (e.g. with missing root cert, CRL check failed, etc). I haven't seen invalid pgp certs yet (might be e.g. very old ones with missing self signature).

Fri, Mar 27, 12:38 PM · gnupg, Feature Request, gpgol, kleopatra
ebo renamed T8193: Add a workflow to force encryption/signature with invalid or expired certificates from Draft: Add a workflow to force encryption/signature with invalid/expired/disabled certificates to Draft: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:49 AM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid and expired are different cases.

Fri, Mar 27, 11:37 AM · gnupg, Feature Request, gpgol, kleopatra
werner added a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Fri, Mar 27, 11:14 AM · gnupg, Feature Request, gpgol, kleopatra
werner added a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:14 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
werner claimed T8076: Kleopatra: Unable to completely delete key with secret subkeys and offline-primary key.
Fri, Mar 27, 11:07 AM · gnupg26, gpd5x, kleopatra, Bug Report
ebo added a project to T8116: Draft: Kleopatra: For S/MIME verification do not use "fingerprint" in messages: needs discussion.
Fri, Mar 27, 10:01 AM · needs discussion, gpd5x, kleopatra

Thu, Mar 26

timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Issue 1) should be implemented as already described (on error -> dialog to retry with "always trust" flag)

Thu, Mar 26, 3:33 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid triaged T8193: Add a workflow to force encryption/signature with invalid or expired certificates as Normal priority.
Thu, Mar 26, 3:31 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid edited projects for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted", added: needs discussion; removed Info Needed.

@ebo and me talked about this and T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST. We think, it's best to have a short meeting to discuss further changes.

Thu, Mar 26, 12:57 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
tfry added a comment to T7650: Kleopatra: Limit width of KMessageBoxes.

Patch was merged upstream (KF 6.25): 332678d8a4f635d6938eb3e9ec03d845aa89697a

Thu, Mar 26, 11:11 AM · gpd5x, gpgpass, kleopatra