Page MenuHome GnuPG

Feature RequestExperimental
ActivePublic

Members

  • This project does not have any members.
  • View All

Recent Activity

Yesterday

pl13 moved T8221: gpgsm: emit more details when failing to check a crl from a crlDP from Backlog to WIP on the vsd34 board.
Tue, Apr 14, 1:08 PM · gpd5x, vsd34, Feature Request
pl13 moved T8221: gpgsm: emit more details when failing to check a crl from a crlDP from Backlog to WIP on the gpd5x board.
Tue, Apr 14, 1:07 PM · gpd5x, vsd34, Feature Request
pl13 triaged T8221: gpgsm: emit more details when failing to check a crl from a crlDP as Wishlist priority.
Tue, Apr 14, 9:18 AM · gpd5x, vsd34, Feature Request

Wed, Apr 8

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe. EncryptionResult has a list of invalid recipients and I've changed the code to show the Retry dialog only if there's at least one invalid recipient.

Wed, Apr 8, 2:03 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Your suggestion sounds ok to me, maybe with a slight change for the message: "Failed to encrypt the notepad because at least on certificate could not be validated."

Wed, Apr 8, 1:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

I tried to add the list of invalid recipients to the message box, but it seems that gpgsm stops the validation of the certificates at the first invalid recipient. I got only the first Bob certificate reported as invalid recipient when I tried to encrypt to both Bob certificates so that it doesn't make sense to list the (incomplete) list of invalid recipients. It also means that Kleopatra cannot update the invalid recipient certificates because it knows only of one invalid certificate.

Wed, Apr 8, 12:18 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ideally the certificate would change, but Kleopatra has no idea that this certificate turned out to be not valid. In fact, Kleopatra doesn't even know that the encryption failed because of some certificate. It could have failed for any other reason (e.g. full disk). Kleopatra only knows that an error occurred and offers to retry with lower security. (I looked at GpgOL and it does the same.)

Wed, Apr 8, 10:50 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo updated subscribers of T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

yes, basically it's what we want.

Wed, Apr 8, 9:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Tue, Apr 7

ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Current implementation for the case of an S/MIME certificate which turns out to be invalid when it's used for encryption. Is that what we want?

Tue, Apr 7, 5:01 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
werner added a project to T8209: Replace GnuPG's name-value impl by the one from GpgRT: Feature Request.
Tue, Apr 7, 4:54 PM · Feature Request, gnupg26
werner changed the status of T7593: Check the trustlist de-vs flag in the per key compliance check from Open to Testing.
Tue, Apr 7, 3:14 PM · gpd5x, gnupg26, vsd, Feature Request
werner changed the status of T7593: Check the trustlist de-vs flag in the per key compliance check, a subtask of T5079: Add compliance flag to trustlist.txt, from Open to Testing.
Tue, Apr 7, 3:14 PM · gnupg22 (gnupg-2.2.45), gnupg24 (gnupg-2.4.1), Restricted Project, Feature Request
werner moved T7593: Check the trustlist de-vs flag in the per key compliance check from Backlog to WIP on the gnupg26 board.
Tue, Apr 7, 2:51 PM · gpd5x, gnupg26, vsd, Feature Request

Mon, Mar 30

timegrid renamed T8193: Add a workflow to force encryption/signature with invalid or expired certificates from Draft: Add a workflow to force encryption/signature with invalid or expired certificates to Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 1:16 PM · gnupg, Feature Request, gpgol, kleopatra
ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:57 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker triaged T8201: Kleopatra: Optionally, allow encryption with invalid or expired certificates as Normal priority.
Mon, Mar 30, 11:54 AM · gpd5x, Feature Request, kleopatra
ikloecker added a subtask for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:39 AM · gnupg, Feature Request, gpgol, kleopatra
ikloecker removed a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Mon, Mar 30, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker renamed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Kleopatra: Use GPGME_ENCRYPT_ALWAYS_TRUST to Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 30, 11:38 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker removed a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mon, Mar 30, 11:31 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a parent task for T6559: GPGSM: "always trust like override" or "force" option: T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Mon, Mar 30, 11:31 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project

Fri, Mar 27

ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Before making subtickets for each application: I wonder if it is not all Kleopatra anyway? Isn't the security approval dialog basically Kleopatra?

Fri, Mar 27, 3:23 PM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

The equivalent for invalid S/MIME certificates are not-certified *PGP certificates.
(Valid/invalid are not ideal as technical terms as they have a broad general meaning, too. I hope my usage here is correct ;-) It is what I gathered from an explanation given by Werner.)

Fri, Mar 27, 3:07 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid certs (as stated in the status column in Kleopatra) are mainly S/MIME certs (e.g. with missing root cert, CRL check failed, etc). I haven't seen invalid pgp certs yet (might be e.g. very old ones with missing self signature).

Fri, Mar 27, 12:38 PM · gnupg, Feature Request, gpgol, kleopatra
ebo renamed T8193: Add a workflow to force encryption/signature with invalid or expired certificates from Draft: Add a workflow to force encryption/signature with invalid/expired/disabled certificates to Draft: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:49 AM · gnupg, Feature Request, gpgol, kleopatra
ebo added a comment to T8193: Add a workflow to force encryption/signature with invalid or expired certificates.

Invalid and expired are different cases.

Fri, Mar 27, 11:37 AM · gnupg, Feature Request, gpgol, kleopatra
werner triaged T8195: Add option --ignore-expiration to gpg and gpgsm as Normal priority.
Fri, Mar 27, 11:17 AM · gnupg26, Feature Request
werner added a parent task for T8193: Add a workflow to force encryption/signature with invalid or expired certificates: T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Fri, Mar 27, 11:14 AM · gnupg, Feature Request, gpgol, kleopatra
werner added a subtask for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T8193: Add a workflow to force encryption/signature with invalid or expired certificates.
Fri, Mar 27, 11:14 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Thu, Mar 26

timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Issue 1) should be implemented as already described (on error -> dialog to retry with "always trust" flag)

Thu, Mar 26, 3:33 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
timegrid triaged T8193: Add a workflow to force encryption/signature with invalid or expired certificates as Normal priority.
Thu, Mar 26, 3:31 PM · gnupg, Feature Request, gpgol, kleopatra
timegrid edited projects for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted", added: needs discussion; removed Info Needed.

@ebo and me talked about this and T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST. We think, it's best to have a short meeting to discuss further changes.

Thu, Mar 26, 12:57 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Wed, Mar 25

ikloecker placed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" up for grabs.
Wed, Mar 25, 10:04 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Tue, Mar 24

timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Ticket for the hang on file encryption: T8187: Kleopatra: File encryption with invalid S/MIME certificate hangs indefinitely

Tue, Mar 24, 11:39 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

According to Werner, that should be:

Tue, Mar 24, 11:07 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
werner triaged T8185: gpg --dry-run --yes --quick-generate-key writes key to GNUPGHOME/private-keys-v1.d as Normal priority.
Tue, Mar 24, 11:05 AM · Feature Request, gnupg
werner edited projects for T8185: gpg --dry-run --yes --quick-generate-key writes key to GNUPGHOME/private-keys-v1.d, added: Feature Request; removed Bug Report.
--dry-run
        Don't make any changes (this is not completely implemented).
Tue, Mar 24, 11:05 AM · Feature Request, gnupg
werner renamed T8186: gpgsm: Add an attribute with version information to signatures from gpgsm: Add an atrtibute with version information to signatures to gpgsm: Add an attribute with version information to signatures.
Tue, Mar 24, 11:03 AM · Feature Request, S/MIME, gnupg26
werner triaged T8186: gpgsm: Add an attribute with version information to signatures as Normal priority.
Tue, Mar 24, 11:02 AM · Feature Request, S/MIME, gnupg26
timegrid added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Maybe those smime certs will do:

Tue, Mar 24, 10:23 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo removed a parent task for T6559: GPGSM: "always trust like override" or "force" option: T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Tue, Mar 24, 10:08 AM · gnupg24 (gnupg-2.4.4), gpgme (gpgme 1.23.x), gnupg22 (gnupg-2.2.42), Feature Request, gpgol, S/MIME, kleopatra, Restricted Project
ebo added a parent task for T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": T6701: GpgOL: Use GPGME_ENCRYPT_ALWAYS_TRUST.
Tue, Mar 24, 10:07 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a project to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted": Info Needed.

It needs to be clarified which kind of errors should be handled and which kind of S/MIME certificates should be allowed to be used for encryption:

  • Valid certificates where the CRL check (or OCSP check?) fails
  • Invalid certificates (e.g. because of incomplete chain/missing CA)
  • Expired certificates
Tue, Mar 24, 9:34 AM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra

Mon, Mar 23

ikloecker moved T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted" from Backlog to WIP on the gpd5x board.
Mon, Mar 23, 3:28 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker claimed T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".
Mon, Mar 23, 3:28 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ikloecker added a comment to T6702: Kleopatra: Offer retry of S/MIME encryption if encryption failed with "not trusted".

Do we have a test certificate for this? The certificate in T6702#176845 is expired.

Mon, Mar 23, 3:02 PM · needs discussion, gpd5x, vsd34, Feature Request, kleopatra
ebo removed a project from T6986: Refresh/update OpenPGP keys should check WKD: needs discussion.

To clarify, the state in Kleopatra Ingo described a year ago has changed, with T7579: Kleopatra: improve menu items the refresh option in the Tools menu was removed. Both actions to update certificates - in the context menu and in the details - are/work the same.

Mon, Mar 23, 9:53 AM · gnupg26, Bug Report, Feature Request
ikloecker removed projects from T6986: Refresh/update OpenPGP keys should check WKD: gpd5x, kleopatra.

Removing kleopatra tag since Kleopatra already does what's requested.

Mon, Mar 23, 9:05 AM · gnupg26, Bug Report, Feature Request