Re: Global Deb/XP keys from Deb partition ?

2006-03-02 Thread Alphax
Adam Bogacki wrote:
> Hi, having seen a reverse example at 
> 
> http://lists.gnupg.org/pipermail/gnupg-users/2003-July/019421.html
> 
> I attempted
> 
> Tux:~# /usr/bin/gpg
> gpg: Go ahead and type your message ...
> gpg --armor --export mykey > mykey.asc
> 
> .. where it hung.
> 

Running gpg with no arguments assumes that you're either going to type
something to sign/encrypt (followed by ^D) or paste a signed/encrypted
blob which it will verify/decrypt. You need:

# gpg --armor --export mykey > mykey.asc

HTH,
-- 
Alphax  |   /"\
Encrypted Email Preferred   |   \ / ASCII Ribbon Campaign
OpenPGP key ID: 0xF874C613  |X   Against HTML email & vCards
http://tinyurl.com/cc9up|   / \


signature.asc
Description: OpenPGP digital signature
___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


eudora, windows xp, and gpg

2006-03-02 Thread Karl Berry
Greetings,

A colleague is stuck using Windows (XP), and prefers Eudora (she has
version 6.2.3.4, which I believe is the latest) to read mail.  She only
needs to decrypt occasional gpg/pgp-signed messages.  Any advice on the
easiest way to do this would be gratefully received.

I found the Eudora plugin as part of the Windows Privacy Tools at
http://winpt.sourceforge.net/en/, but the last release was apparently in
2003, which somewhat worries me with such a new version of Eudora.  And
the "tray" idea worries me.  We don't need or want any UI or any screen
real estate to be used; all that's needed is email decryption.

I'd rather use GPG, but I also looked for PGP versions, and was rather
dismayed at the array of products out there.  Pretty much all of them
claim to work with Eudora and XP, but it is hard to know which "really"
work, without messing up anything else, etc.  If anyone has any
experiences on that front, I'd be grateful to hear those as well.

Thanks,
Karl

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: eudora, windows xp, and gpg

2006-03-02 Thread John Clizbe
Karl Berry wrote:
> Greetings,
> 
> A colleague is stuck using Windows (XP), and prefers Eudora (she has
> version 6.2.3.4, which I believe is the latest) to read mail.  She only
> needs to decrypt occasional gpg/pgp-signed messages.  Any advice on the
> easiest way to do this would be gratefully received.
> 
> I found the Eudora plugin as part of the Windows Privacy Tools at
> http://winpt.sourceforge.net/en/, but the last release was apparently in
> 2003, which somewhat worries me with such a new version of Eudora.  And
> the "tray" idea worries me.  We don't need or want any UI or any screen
> real estate to be used; all that's needed is email decryption.
> 
> I'd rather use GPG, but I also looked for PGP versions, and was rather
> dismayed at the array of products out there.  Pretty much all of them
> claim to work with Eudora and XP, but it is hard to know which "really"
> work, without messing up anything else, etc.  If anyone has any
> experiences on that front, I'd be grateful to hear those as well.

For only occasional use, the current window or clipboard functionality found in
WinPT[1] or GPGshell[2] should suffice.

At that level of use, PGP Freeware will also do the job.

I'm a bit biased, but many folks on Windows platforms are using GnuPG with
Thunderbird and the Enigmail extension. Enigmail is to be merged into the
Mozilla trunk source and will be enabled out-of-the box in SeaMonkey 1.1. Who
knows it might even make its way into Thunderbird 2.0.

Sorry I can't be of more specific help with Eudora, but I've only used it on a
Kyocera 7135 PDA/Phone.

Regards,

-John

[1] http://winpt.sourceforge.net/en/
[2] http://www.jumaros.de/rsoft/index.html

-- 
John P. Clizbe  Inet:   John (a) Mozilla-Enigmail.org
You can't spell fiasco without SCO. PGP/GPG KeyID: 0x608D2A10/0x18BB373A
"what's the key to success?"/ "two words: good decisions."
"what's the key to good decisions?" /  "one word: experience."
"how do i get experience?"  / "two words: bad decisions."

"Just how do the residents of Haiku, Hawai'i hold conversations?"



signature.asc
Description: OpenPGP digital signature
___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: Ohhhh jeeee: ... this is a bug (getkey.c:2079:merge_selfsigs)

2006-03-02 Thread Sergi Blanch i Torné
A Dimarts 28 Febrer 2006 05:39, David Shaw va escriure:
> On Mon, Feb 27, 2006 at 10:34:10AM +0100, Phil Pennock wrote:
> > Is this a known issue, fixed in 1.4.3?
> > There's nothing obviously dealing with it in
> > 
> > http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/trunk/cipher/ChangeLog?rev=
> >4003&view=markup>
> >
> > % gpg --version
> > gpg (GnuPG) 1.4.2.1-ecc0.1.6
>
> This is a heavily patched GnuPG release.  Did you try this on the
> official version?

Please Phil, could you send more details to reproduce the bug? Like key 
generation, and specially if this 0xC9541FB2 key is over elliptics. In 
anyway, neither in ElGamal/DSA key over a patched gpg you can forget this is 
experimental.

/Sergi.

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


[GPGOL] wrapping

2006-03-02 Thread Remco Post
Hi all,

I've read that there has been some discussion on outlook breaking pgp
signatures with gpgol because of line-wrapping. So I was thinking,
wouldn't it be possible to do the line-wrapping in the sign/encrypt
stage? Find out somehow what the setting for line-wrapping is and do the
line-wrapping in gpgol? Or, alternatly, pick 76, the outlook default...

This way, there is no reason for outlook to mess with the message after
signing, and it is possible for non-outlook clients to correctly verify
the signature...

-- 
Met vriendelijke groeten,

Remco Post

SARA - Reken- en Netwerkdiensten  http://www.sara.nl
High Performance Computing  Tel. +31 20 592 3000Fax. +31 20 668 3167
PGP Key fingerprint = 6367 DFE9 5CBC 0737 7D16  B3F6 048A 02BF DC93 94EC

"I really didn't foresee the Internet. But then, neither did the
computer industry. Not that that tells us very much of course - the
computer industry didn't even foresee that the century was going to
end." -- Douglas Adams

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: Ohhhh jeeee: ... this is a bug (getkey.c:2079:merge_selfsigs)

2006-03-02 Thread Phil Pennock
On 2006-03-01 at 19:10 +0100, Sergi Blanch i Torné wrote:
> Ok, in this case (David correct me if i am wrong) it look like there was 
> something broke in the pubring that was fixed when you ran 
> '--update-trustdb' (over an unpatched binary).

Makes sense, although I'm curious as to what, and how it might have been
recoverable.

> Now you haven't any problem. All works fine? I, also, download this key in my 
> pubring without problems.

Everything appears to, yes.

> I remark: this ecc patch is _experimental_, use it carefully!

Thanks.  In this case, because there had been recent-ish core MPI
changes which David had provided one patch for, I assumed that this was
core gnupg and not anything touched by the Gentoo patches.  Silly me,
Gentoo patches touch _everything_.  ;^)

I thought that the ECC patch just provided eliptic-curve crypto, so for
keys using normal sigs, it wouldn't have any effect; I'm rather
surprised that a keyring problem could be caused by it.

Thanks,
-Phil

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: eudora, windows xp, and gpg

2006-03-02 Thread Two Sank
Karl, I have been using Winpt on W2000 in conjunction with Eudora without 
problems. I have not heard of problems with Windows XP. You are right, the 
sourceforge version is out of date. Timo Shultz seems to maintain it separately 
for some reason. Try http://wald.intevation.org/projects/winpt/
  The latest version there is dated 24 February 2006 which should be recent 
enough for you.

However, Winpt no longer includes the Eudora plug in.
The Eudora plugin is quite old (Nov 2003) but seems to work fine for me. That 
you have to get from 
http://eudoragpg.sourceforge.net/ver2.0/en/download/index.html and unzip into 
the Eudora plugins directory. Of course GPG has to be installed first to work.

The latest version of Eudora for Windows (as opposed to MAC) is 7.0.1 but don't 
worry Winpt seems to work with V 6.2 OK.

Winpt is a gui to manage GPG which it accesses through the command line. You 
need GPG at or later than 1.4.2 I believe. If you don't wish to import/export 
keys, sign keys etc etc then don't run Winput and no real estate will be taken. 
You can always run GPG from the cmd window ;-)  Running winpt shows a small key 
in the bottom right tray. Unless you put Winput in your startup folder, it will 
not appear. It is not necessary to run Winpt to use the Eudora plugin, they are 
unrelated.  Any other questions?


___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: Ohhhh jeeee: ... this is a bug (getkey.c:2079:merge_selfsigs)

2006-03-02 Thread Sergi Blanch i Torné
Right now, I don't know if the root problem came from the patch. As you say 
this patch only add mathematical and cryptographic functions to provide 
elliptic curves over finite fields.

I run a patched binary usually. I trust in it, but always I have rings backup. 
There is _not knowed_ bugs, but it is a relative new code that need more 
hack, and also it will receive improvements.

Thank you to use the patch and never doubt to ask.

/Sergi.

A Dijous 02 Març 2006 16:21, Phil Pennock va escriure:
> On 2006-03-01 at 19:10 +0100, Sergi Blanch i Torné wrote:
> > Ok, in this case (David correct me if i am wrong) it look like there was
> > something broke in the pubring that was fixed when you ran
> > '--update-trustdb' (over an unpatched binary).
>
> Makes sense, although I'm curious as to what, and how it might have been
> recoverable.
>
> > Now you haven't any problem. All works fine? I, also, download this key
> > in my pubring without problems.
>
> Everything appears to, yes.
>
> > I remark: this ecc patch is _experimental_, use it carefully!
>
> Thanks.  In this case, because there had been recent-ish core MPI
> changes which David had provided one patch for, I assumed that this was
> core gnupg and not anything touched by the Gentoo patches.  Silly me,
> Gentoo patches touch _everything_.  ;^)
>
> I thought that the ECC patch just provided eliptic-curve crypto, so for
> keys using normal sigs, it wouldn't have any effect; I'm rather
> surprised that a keyring problem could be caused by it.
>
> Thanks,
> -Phil


___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


can't get perl's cpan to 'behave' when using gpg ...

2006-03-02 Thread OpenMacNews
-BEGIN PGP SIGNED MESSAGE-
Hash: RIPEMD160

hi all,

i've gnupg 1.4.2.1 built/installed from src on OSX 10.4.5.

when using perl's CPAN, gpg is used for module signature checking.

to that end, cpan's Config.pm includes:

  'gpg' => q[/usr/local/bin/gpg],


i've configured my gpg to use keyrings/perms of "userA".

from shell, i typically run as userA.

however, cpan is often run as a different user, with superuser perms.

when i run cpan as userB to install modules i get warning such as:

gpg: WARNING: unsafe ownership on homedir `/Users/userA/gpg_homedir'
gpg: WARNING: unsafe ownership on homedir `/Users/userA/gpg_homedir'
Signature for
/usr/ports/cpan_build/sources/authors/id/O/OL/OLAF/CHECKSUMS ok


before running cpan, i see:

% ls -al /Users/userA/gpg_homedir
total 408
drwx-- 12 userA wheel408 Mar  2 12:00 .
drwxr-xr-x 12 userA wheel408 Nov 11 20:46 ..
-rw---  1 userA wheel   1437 Feb 24 21:11 gpg.conf
-rw---  1 userA wheel 123269 Feb 24 21:11 pubring.gpg
-rw---  1 userA wheel600 Feb 24 21:11 random_seed
-rw---  1 userA wheel  14546 Feb 24 21:11 secring.gpg
-rw---  1 userA wheel   3650 Feb 24 21:11 trustdb.gpg


but AFTER running cpan as userB i see:

% ls -al /Users/userA/gpg_homedir
total 408
drwx-- 12 userA wheel408 Mar  2 12:00 .
drwxr-xr-x 12 userA wheel408 Nov 11 20:46 ..
-rw---  1 userA wheel   1437 Feb 24 21:11 gpg.conf
-rw---  1 userB wheel 124965 Mar  2 11:37 pubring.gpg
-rw---  1 userB wheel600 Mar  2 11:51 random_seed
-rw---  1 userA wheel  14546 Feb 24 21:11 secring.gpg
-rw---  1 userB wheel   3920 Mar  2 11:37 trustdb.gpg

note that CPAN is, apparently, changing user ownership on pubring,
random_seed and trustdb !?

how/where do i:

(a) prevent cpan from making changes to my gpg files' ownership?
(b) force cpan to exec gpg as userA -- my typical/intended user?


i've changed the Config.pm entry to:

  'gpg' => q[sudo -u userA /usr/local/bin/gpg],

alas, to no avail.  same symptoms/warnings/etc.

suggestions are appreciated!

cheers,

richard


- --

/"\
\ /  ASCII Ribbon Campaign
 X   against HTML email, vCards
/ \  & micro$oft attachments

[GPG] OpenMacNews at gmail dot com
fingerprint: 50C9 1C46 2F8F DE42 2EDB  D460 95F7 DDBD 3671 08C6
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.2.1 (Darwin)

iEYEAREDAAYFAkQHUYwACgkQlffdvTZxCMYcuwCfUZoXxIIwnimEpyTDgO/CQ5PF
fHIAoKct+QtwFrD8Ub5YOGYat8RdLrVb
=lAHG
-END PGP SIGNATURE-


___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users