diff --git a/doc/README.en.txt b/doc/README.en.txt index 997cb67e..640cf1c8 100644 --- a/doc/README.en.txt +++ b/doc/README.en.txt @@ -1,145 +1,142 @@ ;; README.en.txt -*- coding: latin-1; -*- ;; This is the README installed with Gpg4win. Lines with a ; in the first ;; column are considered a comment and not included in the actually ;; installed version. Certain keywords are replaced by the Makefile; ;; those words are enclosed by exclamation marks. English README file for Gpg4win =============================== This is Gpg4win, version !VERSION! (!BUILD_ISODATE!). Content: 1. Important notes 2. Changes 3. Additional notes 4. Version history 5. Version numbers of included software 6. Legal notices 1. Important notes ================== At release date, the English version of the ebook `Gpg4win Compendium` has not been updated for Gpg4win 3, but still is useful as documentation of some general background how to use the product. You will find it on your system (depending on the version of Windows) or online at https://www.gpg4win.org/doc/en/gpg4win-compendium.html Note that the German version 4.0.0 is up-to-date and only available as pdf. Please read the section `3. Additional notes` of this README before you start working with Gpg4win. The Compendium has more hints for manual or automated installation. System requirements ------------------- Gpg4win runs on Windows versions 7 or newer (up to Windows 10). Both 32 and 64bit systems are supported. If you have at least Windows XP, some parts of Gpg4win can be used, but are not officially supported. The Outlook plugin GpgOL is compatible with Microsoft Outlook 2010, 2013 and 2016 (both 32 and 64bit) and supports transporting emails via SMTP/IMAP and MS Exchange Server (version 2010 or newer). With Gpg4win version 3.1.2 Outlook 2003 and 2007 support was removed for security reasons. (See https://www.gpg4win.org/system-requirements.html for updates.) 2. Changes ========== Included Gpg4win components in version !VERSION! are: !COMPONENTS! New in Gpg4win version !VERSION! (!BUILD_ISODATE!) ----------------------------------------- -- GpgOL: Eine Möglichkeit das Klartext auf den Server synchronisiert - wurde ist behoben. Dies konnte passieren wenn man Mails - gleichzeitig in der Nachrichtenliste angeschaut hat und dabei - die Mail auch im eigenen Fenster geöffnet und geschlossen hat. - (T4622 T4621) - -- GnuPG: Fremde Signaturen von den öffentlichen Keyservern werden - nun ignoriert. Dies wurde nötig da ein Denial of Service mit - gefälschten Signaturen durchgeführt wird. Das alte verhalten - kann weiter verwendet werden wenn - keyserver-options no-self-sigs-only,no-import-clean - der gpg.conf hinzugefügt wird. (T4607) - Eine alternative für die öffentlichen Keyserver wird unter: - https://wiki.gnupg.org/WKD beschrieben. - -- GnuPG: Auf Version 2.2.17 aktualisiert. - (Siehe: https://gnupg.org für die Neuigkeiten.) +- GpgOL: Fixed a possible plaintext leak to the + mail server, which could occur when opening and closing mails + while the mail was also visible in the message list. (T4622 T4621) + +- GnuPG: Ignore all key-signatures received from keyservers. This + change is required to mitigate a DoS due to keys flooded with + faked key-signatures. The old behaviour can be achieved by adding + keyserver-options no-self-sigs-only,no-import-clean + to your gpg.conf. (T4607) + See: https://wiki.gnupg.org/WKD for an alternative to the + keyservers. + +- GnuPG: Updated to Version 2.2.17. + (See: https://gnupg.org for News.) 3. Additional notes =================== - GpgOL * Crypto mails forwarded as attachment are not properly handled. * Integrated Microsoft only OLE Objects are not supported. * Localization is only complete for Dutch, German and Portugese. - General * For 3.2 we plan to, optionally, further automate GpgOL. This would set the GnuPG-Option: trust-model tofu+pgp As this is not properly handled everywhere (especially Kleopatra's file verification dialog) this is not default. You can add it manually to your gpg.conf. The trust-model is already supported by GpgOL. 4. Version history ================== Listed below are the changes as recorded in the source distribution's NEWS file. An up-to-date list of changes is also available at: https://www.gpg4win.org/change-history.html !NEWSFILE! 5. Version numbers of included software ======================================= !VERSIONINFO! 6. Legal notices pertaining to the individual packets ===================================================== Gpg4win consist of several independently developed packages, available under different licensing conditions. Most of these packages however are available under or compatible to the GNU General Public License (GNU GPL). Common to all is that they are Free Software, which means they can be used without restrictions, may be studied, modified and that modifications may be distributed. If the source files (i.e. gpg4win-src-x.y.z.exe) are distributed along with the binaries and the use of the GNU GPL has been pointed out, distribution is possible under many circumstances. What follows is a list of copyright statements. !PKG-COPYRIGHT! ***end of file ***