pkgsrc-Changes archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: CVS commit: pkgsrc/security/gnupg2



Hi!

Yes, I had already started an upstream discussion, but probably due to
the weekend, there was no real feedback yet.

I've downgraded the package for now.
 Thomas


On Sun, Sep 27, 2026 at 11:09:30PM +0100, Ryo ONODERA wrote:
> Hi,
> 
> It seems that GnuPG 2.5.24 does not import Ed25519 keys like 2.5.22.
> In ~/gnupg/private-keys-v1.d, S expression format keys uses OID,
> "1.3.6.1.4.1.11591.15.1" instead of algorithm name like Ed25519.
> I have no idea about what really intended, however this change
> prevents `gpg --show-session-key PGPMIME.eml`
> and configure of pkgsrc/mail/notmuch.
> 
> If you already have a solution, could you please revert
> pkgsrc/security/gnupg to 2.5.22?
> 
> Thank you.
> 
> On Sat, Sep 26, 2026 at 6:47 PM Thomas Klausner <wiz%netbsd.org@localhost> wrote:
> >
> > Module Name:    pkgsrc
> > Committed By:   wiz
> > Date:           Sat Sep 26 09:47:55 UTC 2026
> >
> > Modified Files:
> >         pkgsrc/security/gnupg2: Makefile distinfo
> >
> > Log Message:
> > gnupg2: update to 2.5.24.
> >
> > Noteworthy changes in version 2.5.24 (2026-09-23)
> > -------------------------------------------------
> >
> >  * Bug fixes:
> >
> >    - scd: Fix for regression in 2.5.23 related to the new Nitrokey
> >      detection.  [T8331]
> >
> >  Release-info: https://dev.gnupg.org/T8425
> >
> > Noteworthy changes in version 2.5.23 (2026-09-22)
> > -------------------------------------------------
> >
> >  * New and extended features:
> >
> >    - gpg: New option --allow-9980 to enable the processing of RFC-9980
> >      specified data structures.  The use of this option is only
> >      recommended if external policy requirements demand the use of
> >      these governmental approved specification.  PGP folks requiring
> >      some PQC resistance should keep on using the standard LibrePGP
> >      Kyber algorithm introduced 2 years ago.  [rG6803ce215c]
> >
> >    - gpg: In 9980 mode support PQC encryption using ML-KEM (aka Kyber)
> >      with X448, X25519, Brainpool, or NIST curves as specified by
> >      RFC-9980 et al.
> >
> >    - gpg: In 9980 mode support ED25519 and X25519 as specified by
> >      RFC-9580 under the names "ietf27" and "ietf27".
> >
> >    - gpg: Add experimental support for a --compliance=fips mode to use
> >      GCM for bulk encryption.  [rG05c271f45a]
> >
> >    - scd: Add Nitrokey 3 to pcsc-shared interference detection.
> >      [T8331]
> >
> >  * Bug fixes:
> >
> >    - gpgsm: Fix an exploitable printf bug when using the debug option
> >      "--debug x509".  [rGe6d92ff7af]
> >
> >    - dirmngr: Make the LDAP upload flags also work for KS_SEARCH.
> >      [T7866]
> >
> >    - dirmngr: Fix OOB read in DNS CERT record parser.  [T8464]
> >
> >    - scd: Fix OOB access in DO parsing of faulty cards.  [T8465]
> >
> >  * Other changes:
> >
> >    - dirmngr: Add a mitigation for badly configured web key
> >      directories.  [rGbc7686ad7c]
> >
> >    - New option --debug-no-libgcrypt for gpg, gpgsm, and agent.  This
> >      debug option is useful to avoid cluttering other debug output
> >      with libgcrypt generated debug details.
> >
> >    - gpg: New --list-options "debug-show-sexp" to print a secret key
> >      as an s-expression.  [rG1e0261fe50]
> >
> >  Release-info: https://dev.gnupg.org/T8425
> >
> >
> > To generate a diff of this commit:
> > cvs rdiff -u -r1.180 -r1.181 pkgsrc/security/gnupg2/Makefile
> > cvs rdiff -u -r1.100 -r1.101 pkgsrc/security/gnupg2/distinfo
> >
> > Please note that diffs are not public domain; they are subject to the
> > copyright notices on the relevant files.
> >
> 
> 
> -- 
> Ryo ONODERA // ryo%tetera.org@localhost
> PGP fingerprint = 82A2 DC91 76E0 A10A 8ABB  FD1B F404 27FA C7D1 15F3



Home | Main Index | Thread Index | Old Index