pkgsrc-Changes archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: CVS commit: pkgsrc/security/gnupg2
Hi,
Thomas Klausner <wiz%netbsd.org@localhost> writes:
> Hi!
>
> Yes, I had already started an upstream discussion, but probably due to
> the weekend, there was no real feedback yet.
>
> I've downgraded the package for now.
I have some more information.
The following patch seems minimal patch to fix my problem.
So I think that build_mode1003_sexp() has bad bahavior.
--- g10/import.c.orig 2026-09-22 09:20:47.000000000 +0000
+++ g10/import.c
@@ -3159,12 +3159,14 @@ transfer_secret_keys (ctrl_t ctrl, struct import_stats
}
use_mode1003 = 1;
}
+#if 0
else if (!ski->is_protected)
{
/* The key is not protected. Build a mode1003 format here. */
err = build_mode1003_sexp (pk, &tmpsexp);
use_mode1003 = 1;
}
+#endif
else
err = build_classic_transfer_sexp (pk, &tmpsexp);
And switch() in line 2696 of g10/import.c may have wrong value.
In my case, Ed25519 should be in case PUBKEY_ALGO_ED25519, I believe.
However it goes another case. (I have forgotten to the value, sorry.)
I am not on gnupg-dev mailing list now.
I will subscribe it.
Thank you.
> Thomas
>
>
> On Sun, Sep 27, 2026 at 11:09:30PM +0100, Ryo ONODERA wrote:
>> Hi,
>>
>> It seems that GnuPG 2.5.24 does not import Ed25519 keys like 2.5.22.
>> In ~/gnupg/private-keys-v1.d, S expression format keys uses OID,
>> "1.3.6.1.4.1.11591.15.1" instead of algorithm name like Ed25519.
>> I have no idea about what really intended, however this change
>> prevents `gpg --show-session-key PGPMIME.eml`
>> and configure of pkgsrc/mail/notmuch.
>>
>> If you already have a solution, could you please revert
>> pkgsrc/security/gnupg to 2.5.22?
>>
>> Thank you.
>>
>> On Sat, Sep 26, 2026 at 6:47 PM Thomas Klausner <wiz%netbsd.org@localhost> wrote:
>> >
>> > Module Name: pkgsrc
>> > Committed By: wiz
>> > Date: Sat Sep 26 09:47:55 UTC 2026
>> >
>> > Modified Files:
>> > pkgsrc/security/gnupg2: Makefile distinfo
>> >
>> > Log Message:
>> > gnupg2: update to 2.5.24.
>> >
>> > Noteworthy changes in version 2.5.24 (2026-09-23)
>> > -------------------------------------------------
>> >
>> > * Bug fixes:
>> >
>> > - scd: Fix for regression in 2.5.23 related to the new Nitrokey
>> > detection. [T8331]
>> >
>> > Release-info: https://dev.gnupg.org/T8425
>> >
>> > Noteworthy changes in version 2.5.23 (2026-09-22)
>> > -------------------------------------------------
>> >
>> > * New and extended features:
>> >
>> > - gpg: New option --allow-9980 to enable the processing of RFC-9980
>> > specified data structures. The use of this option is only
>> > recommended if external policy requirements demand the use of
>> > these governmental approved specification. PGP folks requiring
>> > some PQC resistance should keep on using the standard LibrePGP
>> > Kyber algorithm introduced 2 years ago. [rG6803ce215c]
>> >
>> > - gpg: In 9980 mode support PQC encryption using ML-KEM (aka Kyber)
>> > with X448, X25519, Brainpool, or NIST curves as specified by
>> > RFC-9980 et al.
>> >
>> > - gpg: In 9980 mode support ED25519 and X25519 as specified by
>> > RFC-9580 under the names "ietf27" and "ietf27".
>> >
>> > - gpg: Add experimental support for a --compliance=fips mode to use
>> > GCM for bulk encryption. [rG05c271f45a]
>> >
>> > - scd: Add Nitrokey 3 to pcsc-shared interference detection.
>> > [T8331]
>> >
>> > * Bug fixes:
>> >
>> > - gpgsm: Fix an exploitable printf bug when using the debug option
>> > "--debug x509". [rGe6d92ff7af]
>> >
>> > - dirmngr: Make the LDAP upload flags also work for KS_SEARCH.
>> > [T7866]
>> >
>> > - dirmngr: Fix OOB read in DNS CERT record parser. [T8464]
>> >
>> > - scd: Fix OOB access in DO parsing of faulty cards. [T8465]
>> >
>> > * Other changes:
>> >
>> > - dirmngr: Add a mitigation for badly configured web key
>> > directories. [rGbc7686ad7c]
>> >
>> > - New option --debug-no-libgcrypt for gpg, gpgsm, and agent. This
>> > debug option is useful to avoid cluttering other debug output
>> > with libgcrypt generated debug details.
>> >
>> > - gpg: New --list-options "debug-show-sexp" to print a secret key
>> > as an s-expression. [rG1e0261fe50]
>> >
>> > Release-info: https://dev.gnupg.org/T8425
>> >
>> >
>> > To generate a diff of this commit:
>> > cvs rdiff -u -r1.180 -r1.181 pkgsrc/security/gnupg2/Makefile
>> > cvs rdiff -u -r1.100 -r1.101 pkgsrc/security/gnupg2/distinfo
>> >
>> > Please note that diffs are not public domain; they are subject to the
>> > copyright notices on the relevant files.
>> >
>>
>>
>> --
>> Ryo ONODERA // ryo%tetera.org@localhost
>> PGP fingerprint = 82A2 DC91 76E0 A10A 8ABB FD1B F404 27FA C7D1 15F3
--
Ryo ONODERA // ryo%tetera.org@localhost
PGP fingerprint = 82A2 DC91 76E0 A10A 8ABB FD1B F404 27FA C7D1 15F3
Home |
Main Index |
Thread Index |
Old Index