summaryrefslogtreecommitdiffstats
path: root/g10 (follow)
Commit message (Collapse)AuthorAgeFilesLines
* Fix regression in gpg's mail address parsing.Werner Koch2011-04-257-10/+20
| | | | | | Since 2009-12-08 gpg was not able to find email addresses indicated by a leading '<'. This happened when I merged the user id classification code of gpgsm and gpg.
* 2011-04-20 Marcus Brinkmann <mb@g10code.com>Marcus Brinkmann2011-04-202-1/+6
| | | | | * keylist.c (list_keyblock_colon): Use get_ownertrust_info, not get_ownertrust (which lead to binary zeroes in the output!).
* Detect premature EOF while parsing corrupted key packets.Werner Koch2011-03-282-17/+31
| | | | | | | | | | | This helps in the case of an unknown key algorithm with a corrupted packet which claims a longer packet length. This used to allocate the announced packet length and then tried to fill it up without detecting an EOF, thus taking quite some time. IT is easy to fix, thus we do it. However, there are many other ways to force gpg to use large amount of resources; thus as before it is strongly suggested that the sysadm uses ulimit do assign suitable resource limits to the gpg process. Suggested by Timo Schulz.
* Make use of gcry_kdf_derive.Werner Koch2011-03-102-77/+24
| | | | | | Factoring common code out is always a Good Thing. Also added a configure test to print an error if gcry_kdf_derive is missing in Libgcrypt.
* Require libgcrypt 1.5Werner Koch2011-03-083-18/+6
| | | | | | | | Without Libgcrypt 1.5 is was not possible to use ECC keys. ECC is major new feature and thus it does not make sense to allow building with an older Libgcrypt without supporting ECC. Also fixed a few missing prototypes.
* Print the secret keyinfo stuff with --card-status again.Werner Koch2011-03-033-65/+79
|
* Minor code cleanups.Werner Koch2011-03-033-8/+10
| | | | | | | * keyid.c (hash_public_key): Remove shadowing NBITS. * misc.c (pubkey_nbits): Replace GCRY_PK_ by PUBKEY_ALGO_. (get_signature_count): Remove warning.
* Fix faulty gcc warningsWerner Koch2011-03-032-6/+10
|
* Fix usage of SHA-2 algorithm with OpenPGP cards.Werner Koch2011-03-023-148/+5
| | | | | | | This was a regression in 2.1 introduced due to having the agent do the signing in contrast to the old "SCD PKSIGN" command which accesses the scdaemon directly and passed the hash algorithm. The hash algorithm is used by app-openpgp.c only for a sanity check.
* Add ECC import regression tests and fixed a regression.Werner Koch2011-02-102-16/+17
| | | | | | The import test imports the keys as needed and because they are passphrase protected we now need a pinentry script to convey the passphrase to gpg-agent.
* Replace printf by es_printf in keyserver.cWerner Koch2011-02-092-27/+28
| | | | This is similar to the change in keylist.c and elsewhere.
* Add finger support to dirmngr.Werner Koch2011-02-083-26/+89
| | | | | | | | | | | | | The basic network code from http.c is used for finger. This keeps the network related code at one place and we are able to use the somewhat matured code form http.c. Unfortunately I had to enhance the http code for more robustness and probably introduced new bugs. Test this code using gpg --fetch-key finger:wk@g10code.com (I might be the last user of finger ;-)
* Fix ECDSA 521 bit signing.Werner Koch2011-02-072-15/+20
| | | | | This fix also allows the creation and use of an 521 bit ECDH key which used to fail while creating the binding signature.
* Nuked almost all trailing white space.post-nuke-of-trailing-wsWerner Koch2011-02-0454-926/+906
| | | | | | | | We better do this once and for all instead of cluttering all future commits with diffs of trailing white spaces. In the majority of cases blank or single lines are affected and thus this change won't disturb a git blame too much. For future commits the pre-commit scripts checks that this won't happen again.
* Removed deprecated SIGEXPIRED status line.Werner Koch2011-02-042-2/+5
|
* Fix test for gcry_pk_get_curve.Werner Koch2011-02-032-1/+4
| | | | | Add a compatibility fixes for the non-curve case. Remove -lber from the dirmngr link line.
* Add a DECRYPTION_INFO status.Werner Koch2011-02-032-25/+36
| | | | | | | DECRYPTION_INFO <mdc_method> <sym_algo> Print information about the symmetric encryption algorithm and the MDC method. This will be emitted even if the decryption fails.
* Relax mailbox name checking. Fixes bug#1315.Werner Koch2011-02-032-41/+43
|
* Extend algo selection menu.Werner Koch2011-02-033-42/+75
| | | | | | | This allows to add an ECC key and to set the capabilities of an ECDSA key. Fix printing of the ECC algorithm when creating a signature.
* Finished ECC integration.Werner Koch2011-02-035-191/+219
| | | | | | | | | | | | Wrote the ChangeLog 2011-01-13 entry for Andrey's orginal work modulo the cleanups I did in the last week. Adjusted my own ChangeLog entries to be consistent with that entry. Nuked quite some trailing spaces; again sorry for that, I will better take care of not saving them in the future. "git diff -b" is useful to read the actual changes ;-). The ECC-INTEGRATION-2-1 branch can be closed now.
* Compute the fingerprint for ECDH only on demand.Werner Koch2011-02-024-79/+90
| | | | | This also fixes a failed assertion when using a v3 key where the fingerprint size is not 20.
* Sample ECC keys and message do now work.Werner Koch2011-02-029-252/+504
| | | | | | | | Import and export of secret keys does now work. Encryption has been fixed to be compatible with the sample messages. This version tests for new Libgcrypt function and thus needs to be build with a new Libgcrypt installed.
* Move OpenPGP OID helpers to common/.Werner Koch2011-01-313-205/+3
| | | | | | | This is needed so that the agent will be able to export and import OpenPGP secret keys. Add test case. Removed unused function.
* Fixed the ECC interface to Libgcrypt to be ABI compatible with the previous ↵Werner Koch2011-01-317-144/+115
| | | | | | | | | | | | | | | | version. Quite some changes were needed but in the end we have less code than before. Instead of trying to do everything with MPIs and pass them back and forth between Libgcrypt and GnuPG, we know use the S-expression based interface and make heavy use of our opaque MPI feature. Encryption, decryption, signing and verification work with self-generared keys. Import and export does not yet work; thus it was not possible to check the test keys at https://sites.google.com/site/brainhub/pgpecckeys .
* Reworked the ECC changes to better fit into the Libgcrypt API.Werner Koch2011-01-3110-356/+613
| | | | | See ChangeLog for details. Key generation, signing and verification works. Encryption does not yet work. Requires latest Libgcrypt changes.
* Function name cleanupsWerner Koch2011-01-267-141/+142
| | | | Also nuked some trailing spaces.
* Started with some code cleanups in ECDH.Werner Koch2011-01-255-136/+158
| | | | | | The goal is to have the ECDH code more uniform with the other algorithms. Also make error messages and variable names more similar to other places.
* More ECDH code cleanupsWerner Koch2011-01-254-101/+72
|
* Editorial cleanups of keygen.cWerner Koch2011-01-256-254/+163
| | | | | Also fixed a regression introduced by me in pubkey_enc.c. Added extra checks. Removed unused code.
* Merge branch 'master' into ECC-INTEGRATION-2-1Werner Koch2011-01-2412-924/+1352
|\
| * All standard keyserver commands are now using dirmngr.Werner Koch2011-01-206-694/+300
| |
| * Keyserver search and get basically works again.Werner Koch2011-01-187-305/+749
| |
| * Initial code checking for backup - not yet working.Werner Koch2011-01-109-58/+436
| |
* | Fix regression introduced by "editing only change".Werner Koch2011-01-241-1/+1
| | | | | | | | Signing and verification using a new key works again.
* | Truncate the DSA hash; fixes regression.Werner Koch2011-01-213-7/+8
| | | | | | | | Removed left over debug code.
* | Make most of the selftests work.Werner Koch2011-01-213-19/+8
| | | | | | | | | | Note that there is still a problem with tests/openpgp/sigs.test while using the option --digest-algo SHA256.
* | Editorial changes and allow building with old libgcrypts.Werner Koch2011-01-2117-706/+801
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Changed order of some conditional to make to put the special case into the true branch. Indentation changes. Minor other changes to make the ECC code more similar to the rest of our code. It builds but many sefltests still fail. Need to fix that before using it with an ECDH enabled libgcrypt. [/] 2011-01-21 Werner Koch <wk@g10code.com> * configure.ac: Need Libgcrypt 1.4.6 due to AESWRAP. (HAVE_GCRY_PK_ECDH): Add new test. [agent/] 2011-01-21 Werner Koch <wk@g10code.com> * cvt-openpgp.c (GCRY_PK_ECDH) [!HAVE_GCRY_PK_ECDH]: New. [include/] 2011-01-21 Werner Koch <wk@g10code.com> * cipher.h (GCRY_PK_USAGE_CERT): Remove compatibility macros because we now require libgcrypt 1.4.6. (GCRY_PK_ECDH): Add replacement.
* | Fixed key generation with P-521. Confirmed that signature generation and ↵Andrey Jivsov2011-01-131-2/+2
| | | | | | | | verification work.
* | 'g10/gpg2 --encrypt --debug 15 -r ecdsa -a -o _e.asc _' and 'g10/gpg2 ↵Andrey Jivsov2011-01-116-131/+73
| | | | | | | | | | | | | | | | --debug 15 _e.asc', as well as decoding of an old message posted on https://sites.google.com/site/brainhub/pgpecckeys work. This is the milestone 2 that brings in ECDH support from http://code.google.com/p/gnupg-ecc/source/detail?r=15 . This corresponds to the commit 899386826c85f1e757e75bcc5d5b2159d05676a0 in libgcrypt
* | Milestone: Data signing/verification and key signing/verification work with ↵Andrey Jivsov2011-01-071-1/+1
| | | | | | | | ECDSA.
* | Integrating http://code.google.com/p/gnupg-ecc/source/detail?r=15 .Andrey Jivsov2011-01-0623-153/+1370
|/ | | | | | | | | | The following works: gpg2 --gen-key (ECC) gpg2 --list-keys gpg2 --list-packets ~/.gnupg/pubring.gpg gpg2 --list-packets <private key from http://sites.google.com/site/brainhub/pgpecckeys> ECDH doesn't work yet as the code must be re-written to adjust for gpg-agent refactoring.
* Change last change. Does now work.Werner Koch2010-12-092-4/+19
|
* Change dirmngr timer under W32CE.Werner Koch2010-12-092-0/+23
| | | | | Fix trustdb open problem under W32CE.
* s/AES/AES128/ in diagnostics and --list-configWerner Koch2010-12-022-1/+5
|
* Change stack size for Wince.Werner Koch2010-11-235-69/+96
| | | | | | Allow for a longer agent atartup under wince. Print gpg output via estream.
* Smartcard related updatesWerner Koch2010-11-179-298/+237
|
* * pkclist.c (select_algo_from_prefs): Make sure the scores can'tDavid Shaw2010-10-292-17/+43
| | | | | | | | | | | | overflow when picking an algorithm (not a security issue since we can't pick something not present in all preference lists, but we might pick something that isn't scored first choice). * pkclist.c (select_algo_from_prefs): Slightly improve the handling of MD5 in preference lists. Instead of replacing MD5 with SHA-1, just remove MD5 from the list altogether, and let the next-highest ranked algorithm be chosen.
* Better support unsigned time_tWerner Koch2010-10-273-7/+17
|
* Re-implemented GPG's --passwd command and improved it.Werner Koch2010-10-267-221/+183
|
* Remove cruft.Werner Koch2010-10-216-34/+28
| | | | | Make --gen-revoke work