Re: Houston, we have a problem

2017-09-21 Thread Ángel
On 2017-09-21 at 23:37 +0200, Stefan Claas wrote: > Long ago when we had a discussion here on the Mailing List on > how to prevent unwanted signatures i made a proposal that > signing someone's public key should work similar to revocation > certificates. If you would like to sign my pub key you had

Re: Safe transfer via USB devices

2017-10-09 Thread Ángel
On 2017-10-09 at 18:05 +, listo factor wrote: > Use a USB floppy disk reader/writer and shred the floppies with > cleartext after the use. Writing sensitive cleartext to USB flash > "drives" that could potentially fall into the adversary's hands should > be avoided. What is generally used i

Re: Downloading the same key results in different files

2017-12-10 Thread Ángel
On 2017-12-08 at 13:37 -0500, Healer64 via Gnupg-users wrote: > Hi, as keyserver spoofing and poisoning has been a concern, I decided > to test it by downloading the same key from the same keyserver at > different times and from different locations. > > > > When I exported the resulting keys usi

Re: Decrypting file - Private key issue

2018-10-19 Thread Ángel
On 2018-10-15 at 20:41 -0700, fel wrote: > I'm trying to decrypt a file that I encrypted for myself. However gpg doesn't > seem to recognize the correct private key. > > Here is the output of gpg --list-secret-keys > > sec 2048R/69258CF8 2015-09-17 > uid user > ssb 2048R/EA3

Re: How to start gnupg?

2018-12-04 Thread Ángel
On 2018-12-01 at 22:33 +, John Broyles wrote: > I just installed gnupg software from source. (...) I typed sudo apt > install gnupg When you say that you are installing a software from source, it usually means that you downloaded the source code (usually a tgz) and compiled it yourself. As y

Re: a minimal version of PGP/GPG for the Win32/64 bits for command line

2018-12-07 Thread Ángel
On 2018-12-07 at 13:04 +0100, Jan Kamracki wrote: > Hello! > > > I need a GPG/PGP version running from the command line for Win32/64 > bits. > Something like PGP5i. > I wanted to generate a pair of keys and send someone a gpg.exe/pgp.exe > + public key, so that he could encrypt a file without any

Re: Importing keys into GnuPG 2.2 series

2018-12-13 Thread Ángel
On 2018-12-13 at 13:40 -0900, justina colmena via Gnupg-users wrote: > MAIN QUESTION: Is this a pinentry-curses problem with the tty over > ssh, or is it an actual key incompatibility issue? Looks like a pinentry issue. I guess you are using some non-alphanumerical characters in the passphrase? My

Re: showphoto

2019-01-21 Thread Ángel
On 2019-01-19 at 11:09 -0500, Jerry wrote: > gpg> showphoto > Displaying jpeg photo ID of size 88074 for key 3873063887DEC564 (uid 3) > > After a few seconds, an error message pops up on the screen. > > C:\Users\Gerard\AppData\Local\Temp\gpg-62cno9\87DEC564.jpg contains an > invalid path. > > I

Re: NIST 800-57 compatible unattended encryption?

2019-01-21 Thread Ángel
You are missing another point, which is that -in addition to the gpg.conf client preferences- the keys you are encrypting to have preferences, too. In fact, it is noted in the SE answer you linked: > Per default, GnuPG will read the recipient's algorithm preferences and > take the first algorithm

Re: Ok this is a stupid questions

2019-02-25 Thread Ángel
ng that gpg is ok with what was provided). Cheers Ángel ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Question about the security of the GnuPG Agent with regard to cryptographic material scrubbing

2019-02-26 Thread Ángel
On 2019-02-26 at 11:02 +0200, Ciprian Dorin Craciun wrote: > Hello all! > > Given the recent survey in password managers security [1], which > concluded with their failure to properly sanitize / scrub the > sensitive data (i.e. "master key") in "running locked state", I was > wondering how does Gn

Re: Generating revocation certificate

2019-04-10 Thread Ángel
On 2019-04-06 at 21:30 +0200, Peter Lebbing wrote: > This was all quite an ordeal for Debian to get right, there are a lot of > subtleties to deal with. I really think your best bet is to get that "2" > suffix in your muscle memory for when you use the command line. Why should I need to remember t

Re: Generating revocation certificate

2019-04-11 Thread Ángel
On 2019-04-11 at 10:24 +0200, Peter Lebbing wrote: > Depending on how the utility calls "gpg", it might be affected by your > alias and end up calling "gpg2". Nope. ☺ Kindly note that it is being added as a shell alias. The alias will only be expanded on an interactive shell¹ This causes that eve

Re: How to prevent passphrase-caching from within a gpgme-based Python script?

2019-04-16 Thread Ángel
On 2019-04-12 at 07:12 -0400, Kynn Jones wrote: > Hi everyone! > > The following short Python script takes three command-line arguments: > a passphrase, an input path, and an output path. Then it uses the > passphrase to decrypt the contents of the input path, and puts the > decrypted content in

Re: Is limit-card-insert-tries a working option?

2019-06-02 Thread Ángel
I would say, why are you encrypting to the three subkeys? In your original mail this stood up: > The annoyance comes from the pinentry prompt I'm using with the gpg > agent. When needing to refresh the cache, the agent prompts me > multiple times to insert my other smart cards before it reaches t

Re: Some thoughts on the future of OpenPGP and GnuPG

2019-07-02 Thread Ángel
On 2019-07-01 at 18:32 +0200, karel-v_g--- via Gnupg-users wrote: > Hello! > Just right now I have read about a security vulnerability in the PGP > keyservers, Note: that's a problem with the keyservers and key distribution, not with PGP itself. (...) > So my question as a user with a need for

Re: keyserver-options: self-sigs-only, import-clean, import-minimal

2019-07-02 Thread Ángel
On 2019-07-02 at 12:24 +0200, Werner Koch via Gnupg-users wrote: > > My opinion: make "keyserver-options import-clean" the default and > make it internally never import any unknown signatures. > > Sorry, this is a catch-22. We need the key to verify the signature. I don't think so. You can have

Re: SKS Keyserver Network Under Attack

2019-07-03 Thread Ángel
On 2019-07-02 at 10:01 +0200, Wiktor Kwapisiewicz wrote: > > It is a real shame that a decentralized Hagrid isn't really > >possible, though, at least to my understanding. It's quite the > >limitation for GnuPG. > > Decentralized non-identity information hagrid could still be > possible. > It's j

Re: Third-Party Confirmation signature?

2019-07-10 Thread Ángel
On 2019-07-09 at 15:55 -0500, Daniel Roesler via Gnupg-users wrote: > While adding the ability for 0x50 signatures would be nice, I would > still like to explore ways of users self-limiting signatures within > the existing gpg command line, since most users will be just using > whatever version is

Re: Essay on PGP as it is used today

2019-07-19 Thread Ángel
On 2019-07-18 at 12:13 +1000, raf wrote: > At work, when a client insists on email, and I (or the law) > insist on encryption, I provide them with instructions for > installing 7-zip and send them an AES-256 encrypted zip or 7z > file as an attachment. It's the simplest thing I could think > of tha

Re: Fresh certificate marked as expired / messed-up certificate chain pulling expired root cert in gpgsm

2019-07-21 Thread Ángel
On 2019-07-20 at 20:07 +0200, Dr. Thomas Orgis wrote: > The chain in the imported new key & cert file how it should be: > > 4. Thomas Orgis (me) signed by DFN-Verein Global Issuing CA > 3. DFN-Verein Global Issuing CA signed by DFN-Verein Certification Authority 2 > 2. DFN-Verein Certification Aut

tool to encrypt millions of files in unsupervised mode (was: Need to implement a gpg/gpg2-compatible tool...)

2019-07-26 Thread Ángel
On 2019-07-25 at 16:59 -0400, Kynn Jones via Gnupg-users wrote: > In other words, I would love to use a single-purpose tool that is to > AES256-encryption/decryption what, for example, gzip is to > compression/decompression. > > Unfortunately, I have not been able to hit upon such a tool, which I

Re: Generating bitwise identical keyrings with GnuPG 1 + 2

2019-09-05 Thread Ángel
On 2019-08-18 at 08:24 +0200, Mihai Moldovan wrote: > So, to summarize, if I process a keyring file generated by gpg 2.2 > with a 1.4 binary, i.e., read-in the former, export all keys and > import it again, gpg 1.4 generates exactly the same file as it would > when importing the keys directly. I'm

Re: Forward entire gnupg $HOME

2019-09-09 Thread Ángel
On 2019-09-05 at 08:59 +0200, john doe wrote: > On 9/4/2019 10:41 PM, Andre Klärner wrote: > > I usually use my workstation to do everything, but since I can't access my > > mailbox via NFS anymore (different story), I resorted to sshing into my > > email server, and doing all the mailing needs rig

Re: multiple recipients encryption and decryption in gpgsm

2019-11-27 Thread Ángel
On 2019-11-26 at 17:51 +, Yves T via Gnupg-users wrote: > Dears, > > A client uses gpgsm with multiple recipient options. The first option > refers to his own certificate, the second option to the recipients > certificate. > The receiving end has trouble decrypting the file. Output mentions >

Re: Batch generate keys without revocation cert?

2020-01-23 Thread Ángel
On 2020-01-23 at 17:32 +0100, Jonathan Cross via Gnupg-users wrote: > Hello, > I would like to batch generate keys, but *not* have a revocation cert > generated. > I do not see an option for this, how can it be done? > > > Thanks, Jonathan Hello Jonathan See if this helps https://www.gnupg.or

Re: Passphrase and Key Structure

2020-01-26 Thread Ángel
On 2020-01-17 at 06:47 -0700, Mark wrote: > I was wondering what effect changing the passphrase has on the keys. Not > only the keygrip file but also on the exported copy of it that can be > used with other programs. If you change the passphrase, do you need to > re-backup those keygrip files and r

Re: Encrypted GPG files

2020-02-20 Thread Ángel
On 2020-02-20 at 12:53 +, fredrik.a.lindstrom--- via Gnupg-users wrote: > Hi all, > > We receive PGP encrypted files from several external parties that uses > many different tools to create PGP files and I have noticed a > difference between these files that cumbers me. > > We never (well a

Re: File permissions issue while doing GPG encypt and decrypt

2020-04-15 Thread Ángel
On 2020-04-09 at 10:38 +0530, nithin reddy via Gnupg-users wrote: > Hi All, > > > We are using GnuPG 2.0.14 in CentOS linux servers. We are able to try > to encrypt and decrypt the files as a root user. Now we are facing > issues with the normal users who are trying to encrypt a file. > > > Exa

Re: Restoring keyring from backup fails

2020-04-23 Thread Ángel
On 2020-04-20 at 23:15 -0400, Robert J. Hansen wrote: > > Any ideas what might be the cause, or how I can find out what's wrong? > > GnuPG 2.2 changed the way it stores public and private keys. If your > old installation was GnuPG 2.0 and the new one is 2.2, that might > explain things. The fix

Re: Restoring keyring from backup fails

2020-04-25 Thread Ángel
On 2020-04-25 at 00:20 +0200, Mike Grunweg wrote: > Am 24.04.20 um 03:57 schrieb Ángel: > > On 2020-04-20 at 23:15 -0400, Robert J. Hansen wrote: > >>> Any ideas what might be the cause, or how I can find out what's wrong? > >> GnuPG 2.2 changed the way it store

Re: Passphrase window freezes my DE's panel - is this a bug?

2020-04-27 Thread Ángel
First of all, you have created three threads about it. When you reply to an email, you need to actually reply that mail. Just using the same subject does not make the email get into the thread (could you imagine the threads for emails title "Bug"?). I am replying to the original thread, and glossi

Re: Maximum keypair length...

2020-05-09 Thread Ángel
On 2020-05-08 at 13:27 -0400, Barry Smith via Gnupg-users wrote: > Understand that I am suggesting the creation of a set of keys, one per > day, less than 33 keys, generated by one central admin. > > Second, i am looking to export the "sec" file for each calender day > key... so that EACH group mem

Re: Comparison of RSA vs elliptical keys

2020-05-16 Thread Ángel
On 2020-05-16 at 22:49 +0200, Stefan Claas wrote: > out of curiosity, you signed the reply with two sub keys, but > what makes the signature so large, the hash algo used? I must > admit I have never seen such a large signature before. It is quite large, indeed. This Radix 64 block of 12375 bytes c

Re: FW: gpg-agent connection errors

2020-05-21 Thread Ángel
On 2020-05-20 at 18:22 +, Kent A. Larsen wrote: > I've adding logging to our gpg-agent.conf file, and when these errors > occur the gpg-agent log file has the following error: > 2020-05-18 09:36:07 gpg-agent[3800] error binding socket to '\\Neofs1 > \Userapps\Apps\GnuPG\Keys\S.gpg-agent': Unkno

Re: "just invent something..."

2020-05-21 Thread Ángel
Given the number of people that still manage to create (and distribute) their keys with glaring mistakes, such as misspelling their own domain name/tld, or providing a key which doesn't match their email address. Too many people is sending and receiving openpgp emails by actually encrypting the co

Re: "just invent something..."

2020-05-23 Thread Ángel
On 2020-05-23 at 12:30 -0400, Robert J. Hansen wrote: > > - The trust in the correspondent's public key is established only > > by comparing the key fingerprint derived programmatically from the > > locally stored key-file and a copy independently obtained from > > the owner. The only identificatio

Re: MacOSX help - beginner installation, first time

2020-05-24 Thread Ángel
On 2020-05-23 at 03:42 -0400, Cyrus Segura via Gnupg-users wrote: > Hi everyone, > > > I'm new to GnuPG. I'm trying to install it for MacOSX, and I have a > beginner's question. > > > ***Do I need to verify more information about the validity of GnuPG > if: > > > 1.) The SHA-256 checksum on m

Re: "just invent something..."

2020-05-24 Thread Ángel
On 2020-05-24 at 00:14 -0400, Robert J. Hansen wrote: > > I see a big hole in the validation part. The steps providex are > > validating the offline identity but not matching it to the certificate > > uid. > > Correct, and that's by design. > > There is no -- *NO* -- generally understood meaning

Re: "just invent something..."

2020-05-25 Thread Ángel
erature, these figures are normally called > "black knights". Thanks for the insight! Best Ángel ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: As a fan of GnuPG ...

2020-06-20 Thread Ángel
On 2020-06-18 at 16:54 +0200, Stefan Claas wrote: > charlie derr wrote: > > > Is getting those first 5 characters into the output of this string > > really that amazing? Or am i missing something significant about what > > the rest of the seemingly random characters represent? > > Well, it is jus

Re: Traveling without a secret key

2020-07-08 Thread Ángel
On 2020-07-08 at 23:24 +0200, Stefan Claas wrote: > Ryan McGinnis via Gnupg-users wrote: > > > The thing is, if you can't remember a string of random words, are you > > likely to remember a string 20 random letters, numbers, > > and characters? Generally, if your non-randomly-generated password

Re: Decryption stalling after SIGINT

2020-07-08 Thread Ángel
On 2020-07-07 at 18:05 -0500, Andrew Pennebaker via Gnupg-users wrote: > Hello, > > > I am seeing some strange behavior with gpg --decrypt . I had to > lookup a password recently, and so naturally pressed Control+C to > cancel the prompt. However, when gpg terminated, it did not fully > cleanup t

Re: Accidentally deleted ~/.gnupg/pubring.gpg

2020-07-10 Thread Ángel
On 2020-07-09 at 10:19 +0200, Werner Koch via Gnupg-users wrote: > If you know the fingerprint it is of course easy to find the creation > date; that are at worst a mere 710 million hashes (from 1998 to now). > it is just that we don't have the tooling. To make things easier I > will > probably st

Re: Yubikey : ed25519 signing failed

2020-07-30 Thread Ángel
On 2020-07-29 at 11:26 +0200, Julien Escario via Gnupg-users wrote: > Hello, > It seems I found a bug in ed25519 key yubikey's support. > > Long story short : > * Generate a ed25519 Gnupg key and 3 subkeys > * Generate an ed25519 ssh key pair (SSH authority) > * Generate a SSH certificate by signi

Re: Protecting encryption server

2020-07-30 Thread Ángel
On 2020-07-28 at 18:22 -0700, Ayoub Misherghi via Gnupg-users wrote: > Before that happens. I am coding a prototype right now that is not going > to be inadequate; but all this will help me arrive at a better > understanding, help demonstrate basic ideas and hopefully prepare me and > others for

Re: "encrypted with 1 passphrase"

2020-07-31 Thread Ángel
On 2020-07-29 at 10:20 -0700, Ayoub Misherghi via Gnupg-users wrote: > A gpg says "encrypted with 1 passphrase". Are there situations where a > message > > gets encrypted with multiple passphrases? GnuPG seems to only support encrypting with a single passphrase, but the OpenPGP format supports m

Re: Subkeys export to Security Token fails: Secret key available.

2020-08-07 Thread Ángel
On 2020-08-07 at 08:33 +0200, Thomas Schneider wrote: > All subkeys are marked as Stub which is correct because the keys have > been exported before. > However now the keys don't exist anymore on the keycard. > > Can you please advise how to fix this issue? > > THX You had some "full" keys (publ

Re: Subkeys export to Security Token fails: Secret key available.

2020-08-08 Thread Ángel
> Am 8. August 2020 02:05:44 MESZ schrieb "Ángel": > You had some "full" keys (public+private part). Then "moved" them to > the > Yubikey, so the private part was now in the yubikey, and locally you > left just a stub

Re: gnupg --fetch-key problems

2020-08-30 Thread Ángel
On 2020-08-30 at 20:12 +0200, Björn Jacke via Gnupg-users wrote: > A rule that forbids HTTP 1.0 requests is not uncommon these days. In > order to make gpg users' experience better I suggest that gnupg > should not use HTTP 1.0 but at least HTTP 1.1 and also send a user > agent header. Actually I t

Re: Recovering private keys in a friend's GPG installation

2020-09-30 Thread Ángel
On 2020-09-21 at 12:58 -0400, Andrew Engelbrecht via Gnupg-users wrote: > My best guess is that these 3 keys are associated with some older > private keys, and were merely left behind. If there is a way to check > the fingerprint of the keys they belong to, and to import them, that > would be super

Re: Five volunteers needed (EU .... Are you sure that this is really advantageous?

2020-10-08 Thread Ángel
On 2020-10-06 at 12:34 +0200, Stefan Claas wrote: > Mark Fernandes wrote: > > Hello Mark, > > [...] > > > Hello Stefan. Forgive my ignorance, but I'm failing to see the > > significant > > benefit of such a method. Is what you are proposing similar to > > sending an > > encrypted message on CD

Re: Five volunteers needed (EU .... Are you sure that this is really advantageous?

2020-10-13 Thread Ángel
On 2020-10-11 at 17:41 +0200, Stefan Claas wrote: > > I had not set a password, so that the recipients can play with it. > With a password set the NFC tag can not be written to. > Bob may be expecting to receive the safe, read-only NFC tag from Alice, but Eve might have replaced it with a malici

Re: GPG Decrypt Error based on a timeout function?

2020-12-17 Thread Ángel
On 2020-12-17 at 11:28 -0800, Dave via Gnupg-users wrote: > Good Day, > This very novice would appreciate some help. > > My situation: > > I have a Raspberry Pi 4 computer running the Raspberry Operating > System (Raspbian GNU/Linux [buster], Version ID=10) at my home. I > need it to send

Re: Does GPG Ever Store RSA Secret Keys On The Disk In Plain?

2020-12-17 Thread Ángel
On 2020-12-16 at 14:47 -0500, Novak Boškov wrote: > Hell everyone, > > On this link is the following statement: > > To help safeguard your key, GnuPG does not store your raw private > > key on disk. Instead it encrypts it using a symmetric encryption > > algorithm. > However, I'm not entirely cle

Re: GPG Decrypt Error based on a timeout function?

2020-12-18 Thread Ángel
On 2020-12-18 at 10:25 -0800, Dave via Gnupg-users wrote: > Angel, > Yes, I want the script to run unattended, which the gpg process is > not the right method, as you say: " you could configure the gpg > password in the script, but then that would be roughly equivalent to > the email account pass

Re: Plan B - Who carries the torch?

2021-01-04 Thread Ángel
ith) or in parallel (i.e. always signing everything with both keys). It would be nice to have a way to attach a new, modern, key to a backwards-compatible key, but that seems hard to construct (the fingerprint would *not* cover the new key, or otherwise, you would need to (ab)use an ignored portion of

Re: Binding of an encryption key to an e-mail address

2021-01-09 Thread Ángel
On 2021-01-09 at 11:44 +0100, Annie Yousar via Gnupg-users wrote: > How to create a signature packet over K, A1 and E1 signed with K in > GnuPG? Hello Ann The best way would probably be to use two pgp keys: (K1, A1, E1) and (K2, A2, E2) You could have two keys (K, A1, E1) and (K, A2, E2) and sel

Re: WKD for GitHub pages

2021-01-09 Thread Ángel
On 2021-01-09 at 14:37 +0100, Stefan Claas via Gnupg-users wrote: > I believe GitHub is doing it right, because it is a > valid option according to their SSL cert data, and Werner simply > overlooked this option. It is not. A certificate for *.github.io doesn't cover openpgpkey.sac001.github.io S

Re: WKD for GitHub pages

2021-01-10 Thread Ángel
On 2021-01-09 at 23:40 +0100, Stefan Claas via Gnupg-users wrote: > Well, I wish Werner would chime in, because what I really don't > understand why do we have two options, instead of one and why is the > advanced method the first one to be checked, if we have as first one > the direct method, whic

Re: WKD for GitHub pages

2021-01-10 Thread Ángel
On 2021-01-10 at 18:47 +0100, Stefan Claas via Gnupg-users wrote: > Can you tell me/us in laymen terms how this works with gnupg.org? > > openpgpkey.gnupg.org has address 217.69.77.222 > openpgpkey.gnupg.org has IPv6 address 2001:aa8:fff1:100::22 > > Regards > Stefan Sure. Let's suppose you want

Re: WKD for GitHub pages

2021-01-11 Thread Ángel
On 2021-01-11 at 16:36 +0100, Stefan Claas wrote: > On Sun, Jan 10, 2021 at 11:22 PM Ángel wrote: > > On 2021-01-10 at 18:47 +0100, Stefan Claas wrote: > > > Can you tell me/us in laymen terms how this works with gnupg.org? > > > > Sure. Let's suppose you wan

Re: WKD proper behavior on fetch error

2021-01-13 Thread Ángel
On 2021-01-13 at 10:12 +0100, Neal H. Walfield wrote: > I'd like to clarify what Sequoia is doing (wrong). > (...) Hello Neal Thanks for chiming in and explaining the steps taken by sequoia. I'll try to re-focus this subthread back on the initial topic of your email. > The I-D says "Only if

Re: WKD proper behavior on fetch error

2021-01-15 Thread Ángel
On 2021-01-15 at 07:56 +0100, Stefan Claas via Gnupg-users wrote: > Don't you think when GitHub, a major player, would have an invalid > SSL cert, that maybe one of the millions programmers there would not > have contacted GitHub, like I did, and say hey GithHub you serve > the global community and

Re: WKD proper behavior on fetch error

2021-01-15 Thread Ángel
On 2021-01-15 at 20:34 +0100, Stefan Claas via Gnupg-users wrote: > If you or someone else set's up a web server, for a big organisation > or for yourself, you simple put in the .well-known folder some > content which would look most likely then like this: > > http://domain.tld/.well-known/etc...

Re: WKD proper behavior on fetch error

2021-01-16 Thread Ángel
On 2021-01-16 at 02:32 +0100, Stefan Claas via Gnupg-users wrote: > Do I understand you correctly that if one uses now a subdomain > like https://keys.300baud.de/.well-known/etc ... this would work No. keys.300baud.de would work only for em...@keys.300baud.de However, for em...@300baud.de, you ca

Re: WKD proper behavior on fetch error

2021-01-16 Thread Ángel
On 2021-01-16 at 02:20 +0100, Stefan Claas wrote: > On Sat, Jan 16, 2021 at 1:45 AM raf wrote: > > > But there is no certificate that covers that sub-sub-domain. > > That's why browsers complain if you go to > > https://openpgpkey.sac001.github.io/. > > A quick question, if you don't mind. Why do

Re: WKD proper behavior on fetch error

2021-01-17 Thread Ángel
On 2021-01-17 at 10:48 +0100, Erich Eckner wrote: > Hi all, > > On Thu, 14 Jan 2021, Werner Koch via Gnupg-users wrote: > > > On Thu, 14 Jan 2021 01:47, Ángel said: > > > >> I understand this to mean it as "only use the direct method if the > >>

Re: WKD proper behavior on fetch error

2021-01-17 Thread Ángel
On 2021-01-17 at 00:28 +0100, Stefan Claas wrote: > On Sun, Jan 17, 2021 at 12:09 AM raf wrote: > > What you refer to as "proper" is just the direct method. > > That's only half of the WKD protocol. There is also the > > advanced method. Both methods together comprise the WKD > > protocol. > > And

Re: WKD proper behavior on fetch error

2021-01-17 Thread Ángel
On 2021-01-17 at 16:28 +0100, Stefan Claas wrote: > sorry, but simply said I discovered now that a second major and > trusted > contender, Mailvelope supported by BSI and audited, works also as > sequoia-pgp does. Werner and his (shrinking in numbers) supporters > should think now what do to, inste

Re: WKD proper behavior on fetch error

2021-01-18 Thread Ángel
* However, an attack where your DNS server returned a fake NXDOMAIN would be very hard to detect. Best regards Ángel ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

The meaning of /.well-known/ (was: WKD Checker)

2021-01-18 Thread Ángel
On 2021-01-18 at 17:12 +0100, Stefan Claas via Gnupg-users wrote: > Neal, maybe you and your team, as professionals, can explain > what the .well-kown folder in a Web root is good for, because > it is not only used for WKD and it is also used by many many > apps, for verification purposes, like one

Re: Re: WKD proper behavior on fetch error

2021-01-18 Thread Ángel
On 2021-01-17 at 23:43 +, Stefan Claas via Gnupg-users wrote: > I encountered only one MITM attack a couple of years ago so far, from an > SKS user. He was a retired police officer from Austria, who contacted me. > But what you say I was thinking about as well. My proposal was to include > in t

Re: WKD proper behavior on fetch error

2021-01-19 Thread Ángel
On 2021-01-19 at 19:29 +0100, Stefan Claas wrote: > Example: Mallory sitting in the United States likes to prepare > a list (without my consent) and published on a U.S. site, > so that like SKS key server dumps the whole world can > obtain a list of all openpgpkey subdomains. So far so good. > > M

Re: gpg: error retrieving 'er...@eckner.net' via WKD: Connection closed in DNS

2021-01-19 Thread Ángel
On 2021-01-19 at 17:24 +0100, Erich Eckner via Gnupg-users wrote: > What can cause a "Connection closed in DNS" error? (Maybe the error > message can be improved: Doesn't dns use udp by default, which is > connectionless?) I think it means dns.c returned DNS_ECONNFIN [1], which gets converted to

Re: WKD proper behavior on fetch error

2021-01-19 Thread Ángel
Hello all First, I agree with Neal in considering there is a privacy leak in using WKD (with no analysis/mitigations). dkg has already provided an excelent explanation about this, and seems material directly usable into the Security Considerations section. As noted, the openpgpkey server sysad

ctf-like WKD challenge (was: WKD proper behavior on fetch error)

2021-01-20 Thread Ángel
On 2021-01-20 at 08:08 +0100, Stefan Claas via Gnupg-users wrote: > On Wed, Jan 20, 2021 at 12:41 AM Ángel wrote: > > > A list of all (well, most) openpgpkey subdomains can be easily > > created. > > Yes and I believe that what Neal and you (in your new posting) have &

Re: Please tackle the Right Thing

2021-01-20 Thread Ángel
On 2021-01-20 at 20:29 +0100, André Colomb wrote: > Hi all, > > after some more thought I came up with a possible wording to clarify > the > fallback behavior. Assuming that an opportunistic approach is > preferred, so the direct method should be used not only based on the > existence of openpgpk

Re: WKD proper behavior on fetch error

2021-01-21 Thread Ángel
mission chain tries > >to compress the certificate. > > Another approach to make the data uncompressable would be to encrypt > the keyring with, say, AES and include the key. Do you mean to compress the returned file with AES? That would be a big change from existing p

Re: make check failed tests

2021-01-22 Thread Ángel
Try running LD_LIBRARY_PATH=$MYPREFIX/lib make check where $MYPREFIX is the value of --prefix that you passed to ./configure or /usr/local (the default) if not provided i.e. LD_LIBRARY_PATH=/usr/local/lib make check Regards Ángel ___ Gnupg-users ma

Re: gpg: error retrieving 'er...@eckner.net' via WKD: Connection closed in DNS

2021-01-22 Thread Ángel
On 2021-01-22 at 18:05 +0100, Erich Eckner via Gnupg-users wrote: > > I was more wondering, why gpg decides to go into "tor mode" on box #2, > when there is actually no tor installed or running. I'm totally happy to > force non-tor mode via config file, but I'm also open to help find the > root

Re: Please tackle the Right Thing

2021-01-22 Thread Ángel
On 2021-01-22 at 22:15 +0100, André Colomb wrote: > Restricting to only the 200 OK status code would probably be fine. I > looked at the other 2xx codes and probably no others would apply to WKD. > Not quite sure about 228 IM Used (not familiar with RFC 3229). > > I tend to disagree regarding th

Re: How to report issues and suggest changes to the Web Key Directory specification [was: Re: Please tackle the Right Thing]

2021-01-28 Thread Ángel
On 2021-01-28 at 17:27 -0500, Daniel Kahn Gillmor via Gnupg-users wrote: > I think you can find a git repo that contains org-mode source here: > > git clone https://dev.gnupg.org/source/gnupg-doc.git > > it's in the misc/id/openpgp-webkey-service folder, and might require a > modified version o

Re: How to report issues and suggest changes to the Web Key Directory specification [was: Re: Please tackle the Right Thing]

2021-01-28 Thread Ángel
On 2021-01-28 at 17:27 -0500, Daniel Kahn Gillmor via Gnupg-users wrote: > I think you can find a git repo that contains org-mode source here: > > git clone https://dev.gnupg.org/source/gnupg-doc.git > > it's in the misc/id/openpgp-webkey-service folder, and might require > a modified version o

Thunderbird reading Werner mail structure about How to report issues and suggest changes to the Web Key Directory specification

2021-01-29 Thread Ángel
On 2021-01-29 at 18:41 +0100, Daniele Nicolodi wrote: > Hello, > > this is only to report that Thunderbird 78.7.0 is unable to make > sense > of the MIME structure of Werner's email and it only visualizes the > mailing list footer as the body of the email. > > I don't know if the issue is with Th

Re: gpg: error retrieving 'er...@eckner.net' via WKD: Connection closed in DNS

2021-03-01 Thread Ángel
On 2021-02-24 at 12:40 +0100, Erich Eckner wrote: > Hi, > > thanks, again, just a minor typo: > > > --use-tor > > --no-use-tor > > > >The option --use-tor switches Dirmngr and thus GnuPG into ``Tor > >mode'' to route all net‐ work access via Tor (an anonymity network). > >Certain o

Re: gpg: [don't know]: invalid packet (ctb=00)

2021-03-02 Thread Ángel
On 2021-02-11 at 18:24 +0100, Charles Moulliard via Gnupg-users wrote: > Hi > > We experience a very weird problem when the following command > is executed on macos using gpg 2.2.27 (installed by homebrew tool). > > (...) > > Do you know what is the problem ("gpg: [don't know]: invalid packet >

Re: gpg: [don't know]: invalid packet (ctb=00)

2021-03-03 Thread Ángel
On 2021-03-03 at 09:17 +0100, Charles Moulliard via Gnupg-users wrote: > As the file was present on the filesystem, I suspect another error > then. Anyway, GPG should report a more user friendly message > explaining what we should investigate to fix it. Of course the file is there. The problem is

Re: New to GnuPG, having some difficulty

2021-03-07 Thread Ángel
On 2021-03-07 at 00:17 +, Mundis wrote: > Hello gnupg-users! Hello Mundis! > I have recently been required to use GnuPG to encrypt messages, and > have been endeavouring to create a master key however I think I have > fumbled. > I created and deleted some keys while I was trying to work it

Re: question - Gnupg compatibility with Symantec

2021-03-09 Thread Ángel
On 2021-03-08 at 15:57 +, Call, Margaret wrote: > Good morning, > > We would like to migrate our Symantec PGP to GNU PGP.. We tested the > system last week with new PGP users and a user that migrated to GNU > from Symantec. We have fixed all bugs except one: > > Our legacy Symantec users

Re: [EXT] Re: gnupg and ssh interaction somehow broken (card reader with pinpad)

2021-03-17 Thread Ángel
On 2021-03-17 at 21:16 +0100, Andreas K. Huettel wrote: > > OK now it's getting very strange. > > On a second PC with the same reader hardware model, the same gpg > version, and > the same chipcard, things work perfectly fine. > > Could this be a hardware defect (i.e., reader was too long in t

Re: Timeout when signing

2021-03-18 Thread Ángel
On 2021-03-18 at 13:57 +, Nick Cripps via Gnupg-users wrote: > Hi, > > I'm trying to encrypt and sign a large file. It takes a while to do > this, and I then do other things while this is happening. It then > completes and presumably asks me for my key passphrase, but I miss > this and it time

Re: [EXT] Best practices for obtaining a new GPG certificate

2021-03-18 Thread Ángel
On 2021-03-18 at 15:15 +0100, john doe via Gnupg-users wrote: > Reading the URLs given by the OP, I see that the GPG FAQ (1) talks > about a default of '2048' but in the latest (2.2.17) release of GPG > it looks like the default is now '3072': > What keysize do you want? (3072) > > > Am I missing

Re: So long, and thanks for all the fish.

2021-03-24 Thread Ángel
It's sad to see someone like you stepping down by a cause such as this. But we cannot but thank you for your support to the project all these years. So long... and thanks for keeping all the Answers. :-) ___ Gnupg-users mailing list Gnupg-users@gnupg.

Re: Add masterkey as subkey to new masterkey

2021-04-10 Thread Ángel
On 2021-04-10 at 04:08 +, Kiara Stankovic wrote: > Hello gnupg-users, > > I want to add my existing master key as a subkey to a new master key. > > I have followed the steps at > https://security.stackexchange.com/questions/32935/migrating-gpg-master-keys-as-subkeys-to-new-master-key > , and

Re: All my Passwords are lost

2021-04-25 Thread Ángel
On 2021-04-25 at 08:41 +, Vincent Pelletier wrote: > On Sat, 24 Apr 2021 15:19:07 -0700, "C.J. Collier" > wrote: > > you could maybe ask a pause admin to decrypt and > > re-encrypt to a key that you own, sending you back the encrypted file. > > Two ideas from a gpg-internal *UN*aware point o

Re: Random_seed File Locking on NFS File System Across Networks/Domains Hangs

2021-04-25 Thread Ángel
On 2021-04-25 at 13:11 +, Charlie Salemi via Gnupg-users wrote: > Would ignoring the file locking on the random_seed file with the -- > no-random-seed-file option cause issues with independent processes > accessing the same keystore at the same time on different servers? > If so, what are thos

Re: GPG NEVER asks for a passphrase

2021-05-29 Thread Ángel
On 2021-05-27 at 10:44 -0500, Steven Dudley via Gnupg-users wrote: > When I encrypt to my NEW key, my *.gpg file is created, I double > click on it, GPG NEVER asks for a passphrase, it just decrypts the > file. > > What is wrong? Starting with the basics: Does your new key have a password set?

Re: [OT] Tutanota security/privacy concerns (was: Re: How would you do that ...)

2021-08-27 Thread Ángel
On 2021-08-27 at 18:35 +, Стефан Васильев via Gnupg-users wrote: > Hi, > > I have not checked again, but can tell you from the past that they > check what web browser you are using, because when you use an anti- > fingerprint add on for your browser and it generates a User Agent > string with

Re: Is it possible to require two private keys to decrypt with gpg?

2022-01-02 Thread Ángel
On 2021-12-26 at 04:47 +0100, Christian Chavez wrote: > Hi! > > I've currently got some sensitive data I'd like to require _two_ gpg > keys for decryption/unlocking. > > As in both are needed (AND operation), not that either can decrypt on > their own (OR operation). > I can only find description

  1   2   >