<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-953</id>
	<title>Nabble - GnuPG - Dev</title>
	<updated>2009-12-09T09:04:45Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/GnuPG---Dev-f953.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/GnuPG---Dev-f953.html" />
	<subtitle type="html">GnuPG development and bug tracking.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26713780</id>
	<title>Re: gpgconf --list-dirs correct?</title>
	<published>2009-12-09T09:04:45Z</published>
	<updated>2009-12-09T09:04:45Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt; Why is &amp;quot;libdir&amp;quot; reporting /usr/lib/gnupg ? &amp;nbsp;There is no such directory.
&lt;br&gt;&lt;br&gt;&amp;nbsp; $ ls /usr/local/lib/gnupg
&lt;br&gt;&amp;nbsp; gpg-protect-tool &amp;nbsp;pcsc-wrapper
&lt;br&gt;&lt;br&gt;However, this depends on your system.
&lt;br&gt;&lt;br&gt;&amp;gt; Who is the consumer or the &amp;quot;--list-dirs&amp;quot; output? 
&lt;br&gt;&lt;br&gt;It is basically internal to GnuPG. &amp;nbsp;It is an interface to internal
&lt;br&gt;functions. &amp;nbsp;Don't care about it.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Salam-Shalom,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26713780&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gpgconf---list-dirs-correct--tp26699114p26713780.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26712116</id>
	<title>Re: gpgconf --list-dirs correct?</title>
	<published>2009-12-09T07:29:29Z</published>
	<updated>2009-12-09T07:29:29Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">Werner Koch wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Tue, 08 Dec 2009 14:12:10 -0500, Wyllys Ingersoll wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; The gpgconf --list-dirs command tacks on &amp;quot;gnupg&amp;quot; to the end of
&lt;br&gt;&amp;gt;&amp;gt; the preconfigured libdir and datadir pathnames, is this correct?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Yes. &amp;nbsp;These are the gnupg specific directories.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Salam-Shalom,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;Why is &amp;quot;libdir&amp;quot; reporting /usr/lib/gnupg ? &amp;nbsp;There is no such directory.
&lt;br&gt;I'm just confused because when I ran the &amp;quot;configure&amp;quot; script to build
&lt;br&gt;the package, I specify &amp;quot;--libdir=/usr/lib&amp;quot;. 
&lt;br&gt;&lt;br&gt;Who is the consumer or the &amp;quot;--list-dirs&amp;quot; output? 
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;-Wyllys
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26712116&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gpgconf---list-dirs-correct--tp26699114p26712116.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26708171</id>
	<title>Re: gpgconf --list-dirs correct?</title>
	<published>2009-12-09T02:33:39Z</published>
	<updated>2009-12-09T02:33:39Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">On Tue, 08 Dec 2009 14:12:10 -0500, Wyllys Ingersoll wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; The gpgconf --list-dirs command tacks on &amp;quot;gnupg&amp;quot; to the end of
&lt;br&gt;&amp;gt; the preconfigured libdir and datadir pathnames, is this correct?
&lt;br&gt;&lt;br&gt;Yes. &amp;nbsp;These are the gnupg specific directories.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Salam-Shalom,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26708171&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gpgconf---list-dirs-correct--tp26699114p26708171.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26708169</id>
	<title>Re: Read-only keyring and the keybox</title>
	<published>2009-12-09T02:32:05Z</published>
	<updated>2009-12-09T02:32:05Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt; F.e. &lt;a href=&quot;http://wiki.fsfe.org/Card_howtos/Card_with_subkeys_using_backups&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://wiki.fsfe.org/Card_howtos/Card_with_subkeys_using_backups&lt;/a&gt;&lt;br&gt;&amp;gt; states under &amp;quot;Known problems&amp;quot; that &amp;quot;[...] GPG will look for the first
&lt;br&gt;&amp;gt; key in the keyring to decrypt things.&amp;quot; What a hassle to set up a
&lt;br&gt;&amp;gt; smartcard subsequently.
&lt;br&gt;&lt;br&gt;That is simply not true. &amp;nbsp;An OpenPGP message describes the key to be
&lt;br&gt;used for decrytion by including the long key id in the message. &amp;nbsp;This
&lt;br&gt;keyid is then used to lookup the key. &amp;nbsp;If it happens to be on a
&lt;br&gt;smartcard, the smartcard is used.
&lt;br&gt;&lt;br&gt;The problems you may have is with messages also including keys with
&lt;br&gt;wildcard keyids (--throw-keyids). &amp;nbsp;In that case there is no well
&lt;br&gt;defined order of keys to try. &amp;nbsp;See this comment in g10/mainproc.c:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; /* FIXME: Store this all in a list and process it later so that
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;we can prioritize what key to use. &amp;nbsp;This gives a better user
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;experience if wildcard keyids are used. &amp;nbsp;*/
&lt;br&gt;&lt;br&gt;It has nothing to do with the smartcards.
&lt;br&gt;&lt;br&gt;&amp;gt; Oh, why I'm advocating to use the fingerprint instead of the short
&lt;br&gt;&amp;gt; keyid above: I've come across a case where fetching a key via the
&lt;br&gt;&amp;gt; usual gpg --recv-keys 0xdeadbeef method yielded 2 matching keys (if
&lt;br&gt;&amp;gt; you must know, check for 0x76B8337A on subkeys.pgp.net).
&lt;br&gt;&lt;br&gt;Of course there are duplicated keyids out in th ewild; use the long
&lt;br&gt;keyid in your conf file or - as you say - the fingerprint.
&lt;br&gt;&lt;br&gt;&amp;gt; Needless to say that the wrong key was used in operation (that could
&lt;br&gt;&amp;gt; have been attributed just as well to my setup) but people expect to
&lt;br&gt;&amp;gt; get a single key, not each key matching the shortid format. So, to
&lt;br&gt;&amp;gt; make a rather verbose story short: Please adapt documentation
&lt;br&gt;&amp;gt; accordingly.
&lt;br&gt;&lt;br&gt;I don't understand this. &amp;nbsp;Key selection is matter of the mailer and
&lt;br&gt;not of GPG.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Shalom-Salam,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26708169&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26708169.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26701927</id>
	<title>Re: Read-only keyring and the keybox</title>
	<published>2009-12-08T14:24:06Z</published>
	<updated>2009-12-08T14:24:06Z</updated>
	<author>
		<name>markus reichelt-2</name>
	</author>
	<content type="html">* Werner Koch &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701927&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wk@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; On Sun, 6 Dec 2009 22:00:40 +0100, markus reichelt wrote:
&lt;br&gt;&amp;gt; &amp;gt; While you are at it, would it be possible to also address the
&lt;br&gt;&amp;gt; &amp;gt; issue of using multiple smartcards?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; What do you mean by that? &amp;nbsp;Support for several readers?
&lt;br&gt;&lt;br&gt;That would be nice too. But I think it's more important to be able to
&lt;br&gt;use multiple smartcards per user - with the same reader. 
&lt;br&gt;&lt;br&gt;F.e. &lt;a href=&quot;http://wiki.fsfe.org/Card_howtos/Card_with_subkeys_using_backups&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://wiki.fsfe.org/Card_howtos/Card_with_subkeys_using_backups&lt;/a&gt;&lt;br&gt;states under &amp;quot;Known problems&amp;quot; that &amp;quot;[...] GPG will look for the first
&lt;br&gt;key in the keyring to decrypt things.&amp;quot; What a hassle to set up a
&lt;br&gt;smartcard subsequently.
&lt;br&gt;&lt;br&gt;It would be nice to have some option like &amp;quot;--cardkey fingerprint&amp;quot; to
&lt;br&gt;pass to gnupg in order to achieve that. I realize that a new format
&lt;br&gt;like keybox is not really necessary to accomplish that, but while you
&lt;br&gt;are brainstorming a major pillar of gnupg it's worth mentioning, in
&lt;br&gt;my book.
&lt;br&gt;&lt;br&gt;Maybe it's even as simple as adapting gnupg's check for secret keys
&lt;br&gt;present in the (primary) keyring to just look for a cardreader with
&lt;br&gt;inserted card. Don't know, I haven't dived into the depths of the
&lt;br&gt;source code.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Oh, why I'm advocating to use the fingerprint instead of the short
&lt;br&gt;keyid above: I've come across a case where fetching a key via the
&lt;br&gt;usual gpg --recv-keys 0xdeadbeef method yielded 2 matching keys (if
&lt;br&gt;you must know, check for 0x76B8337A on subkeys.pgp.net).
&lt;br&gt;&lt;br&gt;Needless to say that the wrong key was used in operation (that could
&lt;br&gt;have been attributed just as well to my setup) but people expect to
&lt;br&gt;get a single key, not each key matching the shortid format. So, to
&lt;br&gt;make a rather verbose story short: Please adapt documentation
&lt;br&gt;accordingly.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;left blank, right bald
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26701927&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (853 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26701927/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26701927.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26699114</id>
	<title>gpgconf --list-dirs correct?</title>
	<published>2009-12-08T11:12:10Z</published>
	<updated>2009-12-08T11:12:10Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">&lt;br&gt;The gpgconf --list-dirs command tacks on &amp;quot;gnupg&amp;quot; to the end of
&lt;br&gt;the preconfigured libdir and datadir pathnames, is this correct?
&lt;br&gt;&lt;br&gt;For example:
&lt;br&gt;&lt;br&gt;$ gpgconf --list-dirs
&lt;br&gt;sysconfdir:/usr/etc/gnupg
&lt;br&gt;bindir:/usr/bin
&lt;br&gt;libexecdir:/usr/libexec
&lt;br&gt;libdir:/usr/lib/gnupg
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ^^^^^^
&lt;br&gt;datadir:/usr/share/gnupg
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;^^^^^^
&lt;br&gt;localedir:/usr/share/locale
&lt;br&gt;dirmngr-socket:/var/run/dirmngr/socket
&lt;br&gt;...
&lt;br&gt;&lt;br&gt;-Wyllys Ingersoll
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26699114&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/gpgconf---list-dirs-correct--tp26699114p26699114.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26692625</id>
	<title>Re: new contributor?</title>
	<published>2009-12-08T02:48:34Z</published>
	<updated>2009-12-08T02:48:34Z</updated>
	<author>
		<name>Sergi Blanch i Torné-4</name>
	</author>
	<content type="html">Hi Frédéric,
&lt;br&gt;&lt;br&gt;I thing this thread is better to have it in the gcrypt list. Can I ask
&lt;br&gt;you for some help in the elliptic curve encryption? The implementation
&lt;br&gt;of the future standart [1] is giving me some implementations
&lt;br&gt;headaches.
&lt;br&gt;&lt;br&gt;Also the mathematical primitives over the finite fields can be
&lt;br&gt;optimized because in elliptic curves we use a shorter field, but we
&lt;br&gt;call them many more times.
&lt;br&gt;&lt;br&gt;About how to manage your contribution, I am not the good one to answer
&lt;br&gt;you. As far as I know, you there are some types of agreements that can
&lt;br&gt;help in how will be your contribution.
&lt;br&gt;&lt;br&gt;Finally, only say good luck and book some time to develop!
&lt;br&gt;&lt;br&gt;/Sergi.
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://tools.ietf.org/html/draft-jivsov-openpgp-ecc-03&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tools.ietf.org/html/draft-jivsov-openpgp-ecc-03&lt;/a&gt;&lt;br&gt;&lt;br&gt;2009/12/6 Frédéric Yhuel &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26692625&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yhuelf@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I recently graduate from Grenoble university (France), where I
&lt;br&gt;&amp;gt; attended a M Sc in Mathematics and Cryptology. I would like to
&lt;br&gt;&amp;gt; contribute to GNU PG project, and one of my former teacher told me you
&lt;br&gt;&amp;gt; may need help for the ECDSA test. If it is the case, or if you need
&lt;br&gt;&amp;gt; help somewhere else, please let me know. I will do my best to be
&lt;br&gt;&amp;gt; useful and to not get (too much) in the way.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; BR,
&lt;br&gt;&amp;gt; Frédéric Yhuel
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; PS I've tried to subscribe to gcrypt-devel mailing list, but it seems
&lt;br&gt;&amp;gt; that the sever doesn't accept gmail addresses.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Gnupg-devel mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26692625&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26692625&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/new-contributor--tp26670277p26692625.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26674951</id>
	<title>Re: Read-only keyring and the keybox</title>
	<published>2009-12-07T01:54:23Z</published>
	<updated>2009-12-07T01:54:23Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">On Sun, 6 Dec 2009 22:00:40 +0100, markus reichelt wrote:
&lt;br&gt;&amp;gt; While you are at it, would it be possible to also address the issue
&lt;br&gt;&amp;gt; of using multiple smartcards? 
&lt;br&gt;&lt;br&gt;What do you mean by that? &amp;nbsp;Support for several readers?
&lt;br&gt;&lt;br&gt;&lt;br&gt;Salam-Shalom,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26674951&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26674951.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26670277</id>
	<title>new contributor?</title>
	<published>2009-12-06T14:16:04Z</published>
	<updated>2009-12-06T14:16:04Z</updated>
	<author>
		<name>Frédéric Yhuel</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;I recently graduate from Grenoble university (France), where I
&lt;br&gt;attended a M Sc in Mathematics and Cryptology. I would like to
&lt;br&gt;contribute to GNU PG project, and one of my former teacher told me you
&lt;br&gt;may need help for the ECDSA test. If it is the case, or if you need
&lt;br&gt;help somewhere else, please let me know. I will do my best to be
&lt;br&gt;useful and to not get (too much) in the way.
&lt;br&gt;&lt;br&gt;BR,
&lt;br&gt;Frédéric Yhuel
&lt;br&gt;&lt;br&gt;PS I've tried to subscribe to gcrypt-devel mailing list, but it seems
&lt;br&gt;that the sever doesn't accept gmail addresses.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26670277&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/new-contributor--tp26670277p26670277.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26669581</id>
	<title>Re: Read-only keyring and the keybox</title>
	<published>2009-12-06T13:00:40Z</published>
	<updated>2009-12-06T13:00:40Z</updated>
	<author>
		<name>markus reichelt-2</name>
	</author>
	<content type="html">* Werner Koch &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26669581&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wk@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Complaints about multiple keyrings are an old topic but one we
&lt;br&gt;&amp;gt; eventually need to solve.
&lt;br&gt;&lt;br&gt;While you are at it, would it be possible to also address the issue
&lt;br&gt;of using multiple smartcards? 
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;left blank, right bald
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26669581&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26669581/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26669581.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26657797</id>
	<title>Re: Read-only keyring and the keybox</title>
	<published>2009-12-05T08:53:54Z</published>
	<updated>2009-12-05T08:53:54Z</updated>
	<author>
		<name>Jason Harris</name>
	</author>
	<content type="html">On Fri, Dec 04, 2009 at 03:49:49PM +0100, Werner Koch wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Complaints about multiple keyrings are an old topic but one we
&lt;br&gt;&amp;gt; eventually need to solve. &amp;nbsp;Daniel Leidert recently opened a bug for it
&lt;br&gt;&lt;br&gt;FWIW, I had difficulties with multiple and/or read-only keyrings until
&lt;br&gt;--primary-keyring was introduced, which has been a great improvement.
&lt;br&gt;&lt;br&gt;&amp;gt; These bug reports are sometimes mixing two different issues: The
&lt;br&gt;&amp;gt; debian-keyring and r/o keyrings for other purposes.
&lt;br&gt;&lt;br&gt;&amp;gt; The other issue is that of multiple keyrings. &amp;nbsp;Over the years we tried
&lt;br&gt;&amp;gt; several approaches to get it right but none of them worked reliable.
&lt;br&gt;&amp;gt; The problem is the usual one of keeping two databases in sync.
&lt;br&gt;&amp;gt; Aggravated by the requirement to keep some of them read-only but still
&lt;br&gt;&amp;gt; allowing to update them somehow. &amp;nbsp;Approaches like preferring the
&lt;br&gt;&amp;gt; writable one over the read-only one work in theory but will lead to
&lt;br&gt;&amp;gt; administrative headaches. &amp;nbsp;We will never be sure which keyblock is
&lt;br&gt;&amp;gt; actually used. &amp;nbsp;(I had a similar problem today with VPATH builds where
&lt;br&gt;&lt;br&gt;It is a pain to manually/administratively ensure no key is used from
&lt;br&gt;or kept in multiple keyrings, but that is generally what I have done.
&lt;br&gt;Given that any GPG process should only be using one trustdb.gpg at
&lt;br&gt;a time, I think it is acceptable to merge (in memory) all key material
&lt;br&gt;found in multiple keyrings, recalculate trust/trustdb.gpg &amp;quot;stuff,&amp;quot;
&lt;br&gt;and proceed as though only one keyring held all the key material.
&lt;br&gt;When it is necessary to update a key on disk, the --primary-keyring
&lt;br&gt;or first available writable keyring wins. &amp;nbsp;(Non-exportable data must
&lt;br&gt;remain in the file(s) in which it was found. &amp;nbsp;New non-exportable data
&lt;br&gt;must only be written to --primary-keyring.)
&lt;br&gt;&lt;br&gt;Speeding up finding one or more copies of all desired keys in one
&lt;br&gt;or more keyrings is a separate issue (addressed below).
&lt;br&gt;&lt;br&gt;&amp;gt; What I plan with GnuPG 2.1 is to rework the keyring situation by
&lt;br&gt;&amp;gt; replacing keyrings it with a new format (keybox). &amp;nbsp;This new format
&lt;br&gt;&amp;gt; allows to keep meta data and also will boost key access times. &amp;nbsp;This
&lt;br&gt;&amp;gt; will make it possible to flag keys as read-only or allow updates only
&lt;br&gt;&lt;br&gt;I think metadata is excellent, but GPG will always run into files
&lt;br&gt;holding key material that are themselves marked read-only, no-change,
&lt;br&gt;append-only, etc. at the OS level. &amp;nbsp;Marking all keys in a keybox
&lt;br&gt;file internally as read-only will be accompanied in a belt-and-
&lt;br&gt;suspenders approach by also marking the file unchangeable at the
&lt;br&gt;OS level by users who are sufficiently paranoid.
&lt;br&gt;&lt;br&gt;&amp;gt; with a new options set. &amp;nbsp;I am actually working on 2.1. &amp;nbsp;However,
&lt;br&gt;&amp;gt; before we implement such extravagant feature it will be wetter to
&lt;br&gt;&amp;gt; collect real world use cases. &amp;nbsp;We should do this on gnupg-devel@.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; One such use case might be to automatically import certain keys into
&lt;br&gt;&amp;gt; the keybox for future use. &amp;nbsp;This is basically the idea of reading the
&lt;br&gt;&amp;gt; writable keyring first and only then the read-only ring
&lt;br&gt;&amp;gt; (write-on-demand). &amp;nbsp;The solution I have in mind is to import such
&lt;br&gt;&amp;gt; read-only keys using the established --auth-key-locate feature.
&lt;br&gt;&lt;br&gt;Rather than introducing a new format (keybox) for actual key material
&lt;br&gt;or requiring that separate indices be kept for each keyring
&lt;br&gt;(.gpg and .gpgidx?), why not add the needed metadata to trustdb.gpg
&lt;br&gt;or some other single, suitable (and always-writable) file/database?
&lt;br&gt;&lt;br&gt;When the metadata and actual file sizes and file mtimes match for
&lt;br&gt;all specified keyrings, and the combinations of offset, size/length,
&lt;br&gt;fingerprint, and overall hash match the key(s) found in each file
&lt;br&gt;for all keys being actively used, no further scanning of the specified
&lt;br&gt;key files or updating of the centralized metadata need be done.
&lt;br&gt;&lt;br&gt;(When a file holding key material has changed in any detectable
&lt;br&gt;way (depending on one's threat model), rescan the entire file
&lt;br&gt;and update the central metadata store for that file. &amp;nbsp;(Add a
&lt;br&gt;command-line flag to rescan one or all specified keyrings or
&lt;br&gt;to delete and rebuild all metadata if the file size + file mtime
&lt;br&gt;method is not enough for the sufficiently paranoid.))
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Jason Harris &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp;NIC: &amp;nbsp;JH329, PGP: &amp;nbsp;This _is_ PGP-signed, isn't it?
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657797&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jharris@...&lt;/a&gt; _|_ web: &amp;nbsp;&lt;a href=&quot;http://keyserver.kjsl.com/~jharris/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://keyserver.kjsl.com/~jharris/&lt;/a&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Got photons? &amp;nbsp; (TM), (C) 2004
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657797&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;attachment0&lt;/strong&gt; (322 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26657797/0/attachment0&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26657797.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26643627</id>
	<title>Read-only keyring and the keybox</title>
	<published>2009-12-04T06:49:49Z</published>
	<updated>2009-12-04T06:49:49Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;Complaints about multiple keyrings are an old topic but one we
&lt;br&gt;eventually need to solve. &amp;nbsp;Daniel Leidert recently opened a bug for it
&lt;br&gt;listing several threads in the Debian BTS [1]. &amp;nbsp;Below is my comment.
&lt;br&gt;I'd really like to move forward on this issue. &amp;nbsp;It will be quite some
&lt;br&gt;work. &amp;nbsp;I need to see how fast I can accomplish it while not having a
&lt;br&gt;project to financial backing the development.
&lt;br&gt;&lt;br&gt;&lt;br&gt;These bug reports are sometimes mixing two different issues: The
&lt;br&gt;debian-keyring and r/o keyrings for other purposes.
&lt;br&gt;&lt;br&gt;The debian keyring is afaik used with gpgv and has the special
&lt;br&gt;property that all keys in it are fully trusted. &amp;nbsp;In short: It is a set
&lt;br&gt;of keys only to be used by gpgv. Thus the issue is how to create this
&lt;br&gt;keyring. &amp;nbsp;Currently I suggest to use gpg --export LIST-OF-KEYIDS to
&lt;br&gt;create it. &amp;nbsp;In some distance future a little conversion tool might be
&lt;br&gt;required to convert the OpenPGP transport format for keys into the
&lt;br&gt;database format used by gpgv. &amp;nbsp;The bottom line is that I don't see
&lt;br&gt;that as an issue and the Debian readme seems to support this point of
&lt;br&gt;view.
&lt;br&gt;&lt;br&gt;The other issue is that of multiple keyrings. &amp;nbsp;Over the years we tried
&lt;br&gt;several approaches to get it right but none of them worked reliable.
&lt;br&gt;The problem is the usual one of keeping two databases in sync.
&lt;br&gt;Aggravated by the requirement to keep some of them read-only but still
&lt;br&gt;allowing to update them somehow. &amp;nbsp;Approaches like preferring the
&lt;br&gt;writable one over the read-only one work in theory but will lead to
&lt;br&gt;administrative headaches. &amp;nbsp;We will never be sure which keyblock is
&lt;br&gt;actually used. &amp;nbsp;(I had a similar problem today with VPATH builds where
&lt;br&gt;two different header files, both are created from the same source,
&lt;br&gt;provoked a bug in certain environments - not particular easy to
&lt;br&gt;understand what was going on)
&lt;br&gt;&lt;br&gt;What I plan with GnuPG 2.1 is to rework the keyring situation by
&lt;br&gt;replacing keyrings it with a new format (keybox). &amp;nbsp;This new format
&lt;br&gt;allows to keep meta data and also will boost key access times. &amp;nbsp;This
&lt;br&gt;will make it possible to flag keys as read-only or allow updates only
&lt;br&gt;with a new options set. &amp;nbsp;I am actually working on 2.1. &amp;nbsp;However,
&lt;br&gt;before we implement such extravagant feature it will be wetter to
&lt;br&gt;collect real world use cases. &amp;nbsp;We should do this on gnupg-devel@.
&lt;br&gt;&lt;br&gt;One such use case might be to automatically import certain keys into
&lt;br&gt;the keybox for future use. &amp;nbsp;This is basically the idea of reading the
&lt;br&gt;writable keyring first and only then the read-only ring
&lt;br&gt;(write-on-demand). &amp;nbsp;The solution I have in mind is to import such
&lt;br&gt;read-only keys using the established --auth-key-locate feature.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Shalom-Salam,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;https://bugs.g10code.com/gnupg/issue1129&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://bugs.g10code.com/gnupg/issue1129&lt;/a&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643627&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Read-only-keyring-and-the-keybox-tp26643627p26643627.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26641019</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-04T03:00:42Z</published>
	<updated>2009-12-04T03:00:42Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">On Thu, 03 Dec 2009 10:54:32 +0100, Werner Koch wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; For passphrase protected secret keys, passphrase caching helps to
&lt;br&gt;&amp;gt; avoid delays.
&lt;br&gt;&lt;br&gt;That is of course a wrong statement. &amp;nbsp;Passphrase caching does not help
&lt;br&gt;because the passphrase is cached and not the derived protection key.
&lt;br&gt;&lt;br&gt;In this light a 100ms delay is too long. &amp;nbsp;I sometimes get messages
&lt;br&gt;with wildcard keyids. &amp;nbsp;Thus gpg needs to do a couple of trial
&lt;br&gt;decryption and for say 5 available secret keys, this adds up to 500ms
&lt;br&gt;- definitely too long for quickly browsing your mails.
&lt;br&gt;&lt;br&gt;With gpg-agent we could implement a different way of caching but first
&lt;br&gt;we need to integrate gpg2 better with gpg-agent.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Salam-Shalom,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26641019&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26641019.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633463</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T13:26:01Z</published>
	<updated>2009-12-03T13:26:01Z</updated>
	<author>
		<name>Robert J. Hansen-3</name>
	</author>
	<content type="html">Daniel Kahn Gillmor wrote:
&lt;br&gt;&amp;gt; actually, i think getting as high a count as possible is a good goal,
&lt;br&gt;&amp;gt; based on a few assumptions:
&lt;br&gt;&lt;br&gt;By the same reasoning, everyone should be using RSA-4096 for their keys.
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp;0) we're talking about secret key material, which is to be
&lt;br&gt;&amp;gt; symmetrically-encrypted with the user's passphrase.
&lt;br&gt;&lt;br&gt;Yep.
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp;1) such secret key material is very rarely legitimately transferred
&lt;br&gt;&amp;gt; between machines.
&lt;br&gt;&lt;br&gt;Yep.
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp;2) a delay of 0.1 seconds between passphrase entry and access to the
&lt;br&gt;&amp;gt; secret key is an acceptable delay in the case of legitimate use of the key.
&lt;br&gt;&lt;br&gt;Substitute in &amp;quot;a delay of 0.1 seconds for each encryption/decryption&amp;quot;
&lt;br&gt;and this applies.
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp;3) if the encrypted key is somehow transferred off the machine, we want
&lt;br&gt;&amp;gt; it to be as expensive as possible to brute force the symmetric encryption.
&lt;br&gt;&lt;br&gt;Substitute in &amp;quot;we want it to be as expensive as possible to brute force
&lt;br&gt;the encrypted message&amp;quot; and this applies.
&lt;br&gt;&lt;br&gt;... Of course, not everyone should be using RSA-4096. &amp;nbsp;2k keys are
&lt;br&gt;appropriate for the overwhelming majority of users. &amp;nbsp;The point is not to
&lt;br&gt;get the highest numbers possible. &amp;nbsp;The point is to satisfy the
&lt;br&gt;conditions of the local security policy.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633463&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26633463.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26633211</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T13:05:50Z</published>
	<updated>2009-12-03T13:05:50Z</updated>
	<author>
		<name>Daniel Kahn Gillmor-7</name>
	</author>
	<content type="html">On 12/03/2009 03:48 PM, Robert J. Hansen wrote:
&lt;br&gt;&amp;gt; The point is not to get asymptotically as high a count as possible. &amp;nbsp;The
&lt;br&gt;&amp;gt; point is to get enough of a count to slow down brute forcers.
&lt;br&gt;&lt;br&gt;actually, i think getting as high a count as possible is a good goal,
&lt;br&gt;based on a few assumptions:
&lt;br&gt;&lt;br&gt;&amp;nbsp;0) we're talking about secret key material, which is to be
&lt;br&gt;symmetrically-encrypted with the user's passphrase.
&lt;br&gt;&lt;br&gt;&amp;nbsp;1) such secret key material is very rarely legitimately transferred
&lt;br&gt;between machines.
&lt;br&gt;&lt;br&gt;&amp;nbsp;2) a delay of 0.1 seconds between passphrase entry and access to the
&lt;br&gt;secret key is an acceptable delay in the case of legitimate use of the key.
&lt;br&gt;&lt;br&gt;&amp;nbsp;3) if the encrypted key is somehow transferred off the machine, we want
&lt;br&gt;it to be as expensive as possible to brute force the symmetric encryption.
&lt;br&gt;&lt;br&gt;So i think the machine profiling step (using times, *not* gettimeofday)
&lt;br&gt;to get an acceptable upper-bound is a quite reasonable thing to have in
&lt;br&gt;place by default for key passphrase S2K usage.
&lt;br&gt;&lt;br&gt;I'm not so sure it makes sense for symmetrically-encrypted messages
&lt;br&gt;other than secret key material, though, since the above assumptions
&lt;br&gt;don't necessarily hold.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; --dkg
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26633211&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (909 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26633211/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26633211.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26632970</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T12:48:25Z</published>
	<updated>2009-12-03T12:48:25Z</updated>
	<author>
		<name>Robert J. Hansen-3</name>
	</author>
	<content type="html">Daniel Kahn Gillmor wrote:
&lt;br&gt;&amp;gt; I like the elegance of this solution, but couldn't this calculation be
&lt;br&gt;&amp;gt; confounded by other load on the processor? &amp;nbsp;For example, if i'm
&lt;br&gt;&amp;gt; generating a new key (or changing a passphrase) while also encoding
&lt;br&gt;&amp;gt; video, it would be a shame if gpg were to pick a too-low value.
&lt;br&gt;&lt;br&gt;As you said, there's an easy fix. &amp;nbsp;Why check times/gettimeofday when the
&lt;br&gt;&amp;nbsp;lower-bound method works just as well?
&lt;br&gt;&lt;br&gt;The point is not to get asymptotically as high a count as possible. &amp;nbsp;The
&lt;br&gt;point is to get enough of a count to slow down brute forcers.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26632970&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26632970.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26632859</id>
	<title>Supressing Passphrase messages</title>
	<published>2009-12-03T12:41:44Z</published>
	<updated>2009-12-03T12:41:44Z</updated>
	<author>
		<name>nschroth</name>
	</author>
	<content type="html">On AIX, I am using the following command for decrypting:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;b&gt;/usr/local/bin/gpg --passphrase-file ./.gnupg/passphrase.txt -o ${OUTFILE} -d ${INFILE}&lt;/b&gt;&lt;br&gt;&lt;br&gt;The decryption works fine, but the end-user always sees the following verbage that messes up the screen:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;b&gt;Reading passphrase from file descriptor 3
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; You need a passphrase to unlock the secret key for
&lt;br&gt;&amp;nbsp; &amp;nbsp; user: &amp;quot;`XXXX (comment) &lt;email&gt;&amp;quot; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 1024-bit ELG-E key, ID YYYYY, created 2009-10-19 (main key ID ZZZZZ)&lt;/b&gt;&lt;br&gt;&lt;br&gt;HOW CAN I KEEP THIS FROM DISPLAYING?
&lt;br&gt;I also added &lt;b&gt;&amp;gt; /dev/null 2&amp;gt;&amp;1&lt;/b&gt;&amp;nbsp;to send the text to the bitbucket, but it still displays!!!
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Supressing-Passphrase-messages-tp26632859p26632859.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26629501</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T09:06:03Z</published>
	<updated>2009-12-03T09:06:03Z</updated>
	<author>
		<name>David Shaw</name>
	</author>
	<content type="html">On Dec 3, 2009, at 11:46 AM, Daniel Kahn Gillmor wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On 12/03/2009 10:58 AM, David Shaw wrote:
&lt;br&gt;&amp;gt;&amp;gt; PGP calculates whatever count your computer can do in 1/10 of 
&lt;br&gt;&amp;gt;&amp;gt; a second and uses that. &amp;nbsp;It seems like a reasonable solution to
&lt;br&gt;&amp;gt;&amp;gt; me. &amp;nbsp;If someone explicitly sets a --s2k-count, we'll use what
&lt;br&gt;&amp;gt;&amp;gt; they set. &amp;nbsp;If they don't, we can do the 1/10-second calculation.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I like the elegance of this solution, but couldn't this calculation be
&lt;br&gt;&amp;gt; confounded by other load on the processor? &amp;nbsp;For example, if i'm
&lt;br&gt;&amp;gt; generating a new key (or changing a passphrase) while also encoding
&lt;br&gt;&amp;gt; video, it would be a shame if gpg were to pick a too-low value.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I suppose i'm suggesting that it would be important to check times(2)
&lt;br&gt;&amp;gt; instead of gettimeofday(2) (on POSIX systems, anyway, i dunno about
&lt;br&gt;&amp;gt; win32), but also that it would be good to retain a lower-bound as a
&lt;br&gt;&amp;gt; sanity check (perhaps the current value could be a lower-bound unless
&lt;br&gt;&amp;gt; explicitly specified by the user).
&lt;/div&gt;&lt;br&gt;There will of course be a lower bound (probably should be larger than 65536, actually).
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26629501&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26629501.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26629160</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T08:46:03Z</published>
	<updated>2009-12-03T08:46:03Z</updated>
	<author>
		<name>Daniel Kahn Gillmor-7</name>
	</author>
	<content type="html">On 12/03/2009 10:58 AM, David Shaw wrote:
&lt;br&gt;&amp;gt; PGP calculates whatever count your computer can do in 1/10 of 
&lt;br&gt;&amp;gt; a second and uses that. &amp;nbsp;It seems like a reasonable solution to
&lt;br&gt;&amp;gt; me. &amp;nbsp;If someone explicitly sets a --s2k-count, we'll use what
&lt;br&gt;&amp;gt; they set. &amp;nbsp;If they don't, we can do the 1/10-second calculation.
&lt;br&gt;&lt;br&gt;I like the elegance of this solution, but couldn't this calculation be
&lt;br&gt;confounded by other load on the processor? &amp;nbsp;For example, if i'm
&lt;br&gt;generating a new key (or changing a passphrase) while also encoding
&lt;br&gt;video, it would be a shame if gpg were to pick a too-low value.
&lt;br&gt;&lt;br&gt;I suppose i'm suggesting that it would be important to check times(2)
&lt;br&gt;instead of gettimeofday(2) (on POSIX systems, anyway, i dunno about
&lt;br&gt;win32), but also that it would be good to retain a lower-bound as a
&lt;br&gt;sanity check (perhaps the current value could be a lower-bound unless
&lt;br&gt;explicitly specified by the user).
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; --dkg
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26629160&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (909 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26629160/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26629160.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26628803</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T07:58:02Z</published>
	<updated>2009-12-03T07:58:02Z</updated>
	<author>
		<name>David Shaw</name>
	</author>
	<content type="html">On Dec 3, 2009, at 4:54 AM, Werner Koch wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; I doubt that keeping highly confidential keys on a smartphone is a
&lt;br&gt;&amp;gt; good idea at all. &amp;nbsp;On most devices (notable exception is the Neo
&lt;br&gt;&amp;gt; Freerunner) you don't entirely control the device due to malware and
&lt;br&gt;&amp;gt; the phone system operator's ability to gain access to it.
&lt;br&gt;&lt;br&gt;Not wise, I agree. &amp;nbsp;But people do keep all sorts of stuff on their phone. &amp;nbsp;I seem to recall that the Blackberry has an OpenPGP client that keeps keys locally (if someone knows one way or the other for sure, please jump in).
&lt;br&gt;&lt;br&gt;&amp;gt;&amp;gt; dropping. &amp;nbsp;If 65536 was the right value for 11 years ago, we
&lt;br&gt;&amp;gt;&amp;gt; probably could do with a brief discussion on whether we should raise
&lt;br&gt;&amp;gt;&amp;gt; it for today (and if so, how much).
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I agree. &amp;nbsp;I heard that PGP measures the performance during key
&lt;br&gt;&amp;gt; generation and selects the S2K count depending on that value. &amp;nbsp;Most
&lt;br&gt;&amp;gt; people are using their keys on just one machine and thus it would fit
&lt;br&gt;&amp;gt; their needs. &amp;nbsp;If they are switching to another hardware they can
&lt;br&gt;&amp;gt; easily change the passphrase and thus use a new S2K count.
&lt;br&gt;&lt;br&gt;PGP calculates whatever count your computer can do in 1/10 of a second and uses that. &amp;nbsp;It seems like a reasonable solution to me. &amp;nbsp;If someone explicitly sets a --s2k-count, we'll use what they set. &amp;nbsp;If they don't, we can do the 1/10-second calculation.
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26628803&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26628803.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26623485</id>
	<title>Re: Change s2k count?</title>
	<published>2009-12-03T01:54:32Z</published>
	<updated>2009-12-03T01:54:32Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">On Mon, 30 Nov 2009 10:29:08 -0500, David Shaw wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; There are a number of factors: obviously we must take care with the
&lt;br&gt;&amp;gt; setting here - too high and it can make decrypting with a passphrase
&lt;br&gt;&amp;gt; (either a secret key decryption or a passphrase protected message)
&lt;br&gt;&lt;br&gt;I don't consider the latter a real problem. &amp;nbsp;If you use symmetric only
&lt;br&gt;encryption it is very likely that you are working in a custom
&lt;br&gt;environment which is for example needed to take care about key
&lt;br&gt;management. &amp;nbsp;In that case you can setup a non-default s2k count.
&lt;br&gt;&lt;br&gt;In the rare case that you receive symmetric only message, you got the
&lt;br&gt;key by, say, phone and conveying the key takes some time anyway. &amp;nbsp;Thus
&lt;br&gt;an extra delay on a small device should not be too troublesome.
&lt;br&gt;&lt;br&gt;For passphrase protected secret keys, passphrase caching helps to
&lt;br&gt;avoid delays.
&lt;br&gt;&lt;br&gt;&amp;gt; It could be argued that cell phone usage actually needs the iterated
&lt;br&gt;&amp;gt; hash even more as typing a long high-entropy passphrase is extremely
&lt;br&gt;&amp;gt; difficult on a cell phone.
&lt;br&gt;&lt;br&gt;I doubt that keeping highly confidential keys on a smartphone is a
&lt;br&gt;good idea at all. &amp;nbsp;On most devices (notable exception is the Neo
&lt;br&gt;Freerunner) you don't entirely control the device due to malware and
&lt;br&gt;the phone system operator's ability to gain access to it.
&lt;br&gt;&lt;br&gt;&amp;gt; dropping. &amp;nbsp;If 65536 was the right value for 11 years ago, we
&lt;br&gt;&amp;gt; probably could do with a brief discussion on whether we should raise
&lt;br&gt;&amp;gt; it for today (and if so, how much).
&lt;br&gt;&lt;br&gt;I agree. &amp;nbsp;I heard that PGP measures the performance during key
&lt;br&gt;generation and selects the S2K count depending on that value. &amp;nbsp;Most
&lt;br&gt;people are using their keys on just one machine and thus it would fit
&lt;br&gt;their needs. &amp;nbsp;If they are switching to another hardware they can
&lt;br&gt;easily change the passphrase and thus use a new S2K count.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Shalom-Salam,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26623485&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26623485.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26612586</id>
	<title>Re: [PATCH] - gpgme mkstatus</title>
	<published>2009-12-02T09:07:59Z</published>
	<updated>2009-12-02T09:07:59Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">Werner Koch wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt; gpgme mkstatus should use &amp;quot;gawk&amp;quot; instead of &amp;quot;awk&amp;quot;. &amp;nbsp;On some platforms (Solaris), 
&lt;br&gt;&amp;gt;&amp;gt; awk and gawk are not the same and only 'gawk' will work correctly.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Can you point out the gawk specific suff we use? &amp;nbsp;The script is
&lt;br&gt;&amp;gt; intended to work with a POSIX or other commonly used awk.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Shalom-Salam,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;I get the following error when building with the standard 'awk' (/usr/bin/awk) in 
&lt;br&gt;Solaris:
&lt;br&gt;&lt;br&gt;./mkstatus &amp;lt; ./gpgme.h &amp;gt; status-table.h
&lt;br&gt;awk: syntax error near line 3
&lt;br&gt;awk: bailing out near line 3
&lt;br&gt;&lt;br&gt;The &amp;quot;awk&amp;quot; statement in mkstatus looks like this:
&lt;br&gt;awk '
&lt;br&gt;/GPGME_STATUS_ENTER/ &amp;nbsp; &amp;nbsp; &amp;nbsp;{ okay = 1 }
&lt;br&gt;!okay &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; { next }
&lt;br&gt;/}/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; { exit 0 }
&lt;br&gt;/GPGME_STATUS_[A-Za-z_]*/ { sub (/,/, &amp;quot;&amp;quot;, $1); printf &amp;quot; &amp;nbsp;{ \&amp;quot;%s\&amp;quot;, %s },\n&amp;quot;, substr($1,14), $1 }
&lt;br&gt;' | sort
&lt;br&gt;&lt;br&gt;The standard Solaris awk doesn't like the &amp;quot;!okay&amp;quot; expression.
&lt;br&gt;That is easy enough to fix, change it to &amp;quot;okay == 0&amp;quot; and it doesn't complain.
&lt;br&gt;&lt;br&gt;However, that exposes a larger issue with Solaris /usr/bin/awk - it doesn't support the &amp;quot;sub&amp;quot; 
&lt;br&gt;statement.
&lt;br&gt;&lt;br&gt;Switching to 'gawk' is the easiest fix. &amp;nbsp;
&lt;br&gt;&lt;br&gt;-Wyllys
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26612586&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----gpgme-mkstatus-tp26599959p26612586.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26610327</id>
	<title>Re: [PATCH] - gpgme gpgconf.c</title>
	<published>2009-12-02T05:59:51Z</published>
	<updated>2009-12-02T05:59:51Z</updated>
	<author>
		<name>Marcus Brinkmann</name>
	</author>
	<content type="html">Wyllys Ingersoll wrote:
&lt;br&gt;&amp;gt; There is a minor bug in gpgme/src/gpgconf.c which causes it to fail to compile with
&lt;br&gt;&amp;gt; some compilers. &amp;nbsp;gpgme_conf_arg_release is declared a &amp;quot;void&amp;quot; function but it is 
&lt;br&gt;&amp;gt; currently coded to return the results of _gpgme_conf_arg_release 
&lt;br&gt;&lt;br&gt;Werner put it in, thanks for reporting it.
&lt;br&gt;&lt;br&gt;Marcus
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26610327&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----gpgme-gpgconf.c-tp26599529p26610327.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26605059</id>
	<title>Re: [PATCH] - pinentry secmem/util.c</title>
	<published>2009-12-02T00:14:46Z</published>
	<updated>2009-12-02T00:14:46Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;I removed it:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; * secmem/util.c: Re-indent function names.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (TEMP_FAILURE_RETRY): Remove because it is non-portable.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; (xwrite): Open code the EINTR retry.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;&amp;nbsp; Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26605059&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----pinentry-secmem-util.c-tp26599788p26605059.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26605018</id>
	<title>Re: [PATCH] - pinentry pinentry-curses.c</title>
	<published>2009-12-02T00:06:01Z</published>
	<updated>2009-12-02T00:06:01Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;On Tue, 01 Dec 2009 16:00:40 -0500, Wyllys Ingersoll &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26605018&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Wyllys.Ingersoll@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; pinentry-curses.c has a switch statement that looks for
&lt;br&gt;&amp;gt; characters like &amp;quot;\t&amp;quot; and &amp;quot;\e&amp;quot;, it should use numerical values
&lt;br&gt;&amp;gt; for these constants, different compilers intepret the characters
&lt;br&gt;&amp;gt; differently which results in unexpected behavior.
&lt;br&gt;&lt;br&gt;I agree that \e is a non-standard extension and should be replace.
&lt;br&gt;However \t is a TAB and that is the same on all ASCII based systems.
&lt;br&gt;Right, we don't care about EBCDIC.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Salam-Shalom,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26605018&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----pinentry-pinentry-curses.c-tp26599503p26605018.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26604973</id>
	<title>Re: [PATCH] - gpgme mkstatus</title>
	<published>2009-12-02T00:02:59Z</published>
	<updated>2009-12-02T00:02:59Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt; gpgme mkstatus should use &amp;quot;gawk&amp;quot; instead of &amp;quot;awk&amp;quot;. &amp;nbsp;On some platforms (Solaris), 
&lt;br&gt;&amp;gt; awk and gawk are not the same and only 'gawk' will work correctly.
&lt;br&gt;&lt;br&gt;Can you point out the gawk specific suff we use? &amp;nbsp;The script is
&lt;br&gt;intended to work with a POSIX or other commonly used awk.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Shalom-Salam,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26604973&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----gpgme-mkstatus-tp26599959p26604973.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26599788</id>
	<title>[PATCH] - pinentry secmem/util.c</title>
	<published>2009-12-01T13:03:15Z</published>
	<updated>2009-12-01T13:03:15Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">&lt;br&gt;Attached is a patch for the pinentry secmem/util.c file.
&lt;br&gt;&lt;br&gt;The TEMP_FAILURE_RETRY macro uses &amp;quot;__extension__&amp;quot; which is unsupported
&lt;br&gt;on some compilers and will cause the build to fail. &amp;nbsp;I'm not sure it is
&lt;br&gt;necessary or helpful in the first place.
&lt;br&gt;&lt;br&gt;-Wyllys Ingersoll
&lt;br&gt;&lt;br&gt;&lt;br /&gt;--- secmem/util.c.save	Wed Oct 28 09:42:42 2009
&lt;br&gt;+++ secmem/util.c	Wed Oct 28 09:43:01 2009
&lt;br&gt;@@ -34,11 +34,10 @@
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;#ifndef TEMP_FAILURE_RETRY
&lt;br&gt;&amp;nbsp;#define TEMP_FAILURE_RETRY(expression) \
&lt;br&gt;- &amp;nbsp;(__extension__							 &amp;nbsp; &amp;nbsp; &amp;nbsp;\
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;({ long int __result;						 &amp;nbsp; &amp;nbsp; &amp;nbsp;\
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; do __result = (long int) (expression);				 &amp;nbsp; &amp;nbsp; &amp;nbsp;\
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; while (__result == -1L &amp;&amp; errno == EINTR);			 &amp;nbsp; &amp;nbsp; &amp;nbsp;\
&lt;br&gt;- &amp;nbsp; &amp;nbsp; &amp;nbsp; __result; }))
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp; __result; })
&lt;br&gt;&amp;nbsp;#endif
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;#ifndef HAVE_DOSISH_SYSTEM
&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26599788&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----pinentry-secmem-util.c-tp26599788p26599788.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26599503</id>
	<title>[PATCH] - pinentry pinentry-curses.c</title>
	<published>2009-12-01T13:00:40Z</published>
	<updated>2009-12-01T13:00:40Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">&lt;br&gt;pinentry-curses.c has a switch statement that looks for
&lt;br&gt;characters like &amp;quot;\t&amp;quot; and &amp;quot;\e&amp;quot;, it should use numerical values
&lt;br&gt;for these constants, different compilers intepret the characters
&lt;br&gt;differently which results in unexpected behavior.
&lt;br&gt;&lt;br&gt;Attached is a patch against the source from the pinentry-0.7.6 tarball.
&lt;br&gt;&lt;br&gt;-Wyllys Ingersoll
&lt;br&gt;&lt;br&gt;&lt;br /&gt;--- pinentry/pinentry-curses.c.old	Thu Apr 16 08:06:53 2009
&lt;br&gt;+++ pinentry/pinentry-curses.c	Mon Nov &amp;nbsp;9 08:23:40 2009
&lt;br&gt;@@ -665,7 +665,7 @@
&lt;br&gt;&amp;nbsp; &amp;nbsp;if (has_colors ())
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;{
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;start_color ();
&lt;br&gt;- &amp;nbsp; &amp;nbsp; &amp;nbsp;use_default_colors ();
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; &amp;nbsp;/* use_default_colors (); */
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if (pinentry-&amp;gt;color_so == PINENTRY_COLOR_DEFAULT)
&lt;br&gt;&amp;nbsp;	{
&lt;br&gt;@@ -741,7 +741,7 @@
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;break;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;-	case '\t':
&lt;br&gt;+	case '\011': /* HARD TAB */
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;switch (diag.pos)
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;{
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;case DIALOG_POS_PIN:
&lt;br&gt;@@ -767,11 +767,11 @@
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;}
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;break;
&lt;br&gt;&amp;nbsp; &amp;nbsp;
&lt;br&gt;-	case '\e':
&lt;br&gt;+	case '\005': /* ENQ */
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;done = -2;
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;break;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;-	case '\r':
&lt;br&gt;+	case '\015': /* CR */
&lt;br&gt;&amp;nbsp;	 &amp;nbsp;switch (diag.pos)
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;{
&lt;br&gt;&amp;nbsp;	 &amp;nbsp; &amp;nbsp;case DIALOG_POS_PIN:
&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26599503&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----pinentry-pinentry-curses.c-tp26599503p26599503.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26599959</id>
	<title>[PATCH] - gpgme mkstatus</title>
	<published>2009-12-01T12:57:47Z</published>
	<updated>2009-12-01T12:57:47Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">&lt;br&gt;gpgme mkstatus should use &amp;quot;gawk&amp;quot; instead of &amp;quot;awk&amp;quot;. &amp;nbsp;On some platforms (Solaris), 
&lt;br&gt;awk and gawk are not the same and only 'gawk' will work correctly.
&lt;br&gt;&lt;br&gt;Attached is a patch.
&lt;br&gt;&lt;br&gt;-Wyllys Ingersoll
&lt;br&gt;&lt;br&gt;&lt;br /&gt;--- src/mkstatus.orig	Fri Sep 25 08:22:00 2009
&lt;br&gt;+++ src/mkstatus	Fri Sep 25 08:21:41 2009
&lt;br&gt;@@ -38,7 +38,7 @@
&lt;br&gt;&amp;nbsp;{
&lt;br&gt;&amp;nbsp;EOF
&lt;br&gt;&amp;nbsp;
&lt;br&gt;-awk '
&lt;br&gt;+gawk '
&lt;br&gt;&amp;nbsp;/GPGME_STATUS_ENTER/ &amp;nbsp; &amp;nbsp; &amp;nbsp;{ okay = 1 }
&lt;br&gt;&amp;nbsp;!okay &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; { next }
&lt;br&gt;&amp;nbsp;/}/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; { exit 0 }
&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26599959&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----gpgme-mkstatus-tp26599959p26599959.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26599529</id>
	<title>[PATCH] - gpgme gpgconf.c</title>
	<published>2009-12-01T12:56:03Z</published>
	<updated>2009-12-01T12:56:03Z</updated>
	<author>
		<name>Wyllys Ingersoll</name>
	</author>
	<content type="html">&lt;br&gt;There is a minor bug in gpgme/src/gpgconf.c which causes it to fail to compile with
&lt;br&gt;some compilers. &amp;nbsp;gpgme_conf_arg_release is declared a &amp;quot;void&amp;quot; function but it is 
&lt;br&gt;currently coded to return the results of _gpgme_conf_arg_release 
&lt;br&gt;&lt;br&gt;The patch attached is against the tarball from 1.1.8:
&lt;br&gt;&lt;br&gt;-Wyllys Ingersoll
&lt;br&gt;&amp;nbsp;Sun Microsystems, Inc.
&lt;br&gt;&lt;br&gt;&lt;br /&gt;--- src/gpgconf.c.orig	Wed Sep 23 09:38:36 2009
&lt;br&gt;+++ src/gpgconf.c	Wed Sep 23 09:38:42 2009
&lt;br&gt;@@ -59,7 +59,7 @@
&lt;br&gt;&amp;nbsp;gpgme_conf_arg_release (gpgme_conf_arg_t arg, gpgme_conf_type_t type)
&lt;br&gt;&amp;nbsp;{
&lt;br&gt;&amp;nbsp;#ifdef ENABLE_GPGCONF
&lt;br&gt;- &amp;nbsp;return _gpgme_conf_arg_release (arg, type);
&lt;br&gt;+ &amp;nbsp;_gpgme_conf_arg_release (arg, type);
&lt;br&gt;&amp;nbsp;#endif
&lt;br&gt;&amp;nbsp;}
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26599529&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-PATCH----gpgme-gpgconf.c-tp26599529p26599529.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26576532</id>
	<title>Change s2k count?</title>
	<published>2009-11-30T07:29:08Z</published>
	<updated>2009-11-30T07:29:08Z</updated>
	<author>
		<name>David Shaw</name>
	</author>
	<content type="html">Hi everyone,
&lt;br&gt;&lt;br&gt;The discussion around s2k-count on gnupg-users made me think a bit about our current default there. &amp;nbsp;The default s2k count has been 65536 iterations for (as best I can tell) pretty near the entire lifespan of GnuPG. &amp;nbsp;Certainly it is at least 11 years as I see it in a code checkin from 1998.
&lt;br&gt;&lt;br&gt;There are a number of factors: obviously we must take care with the setting here - too high and it can make decrypting with a passphrase (either a secret key decryption or a passphrase protected message) unacceptably slow. &amp;nbsp;In addition, there are other factors to consider, like uses today that didn't exist as much 11 years ago - slow CPUs in cell phones and the like, which would have a hard time with a large iteration count. &amp;nbsp;Even so, most smartphone processors today are on par with or even faster than the average processor from 1998 (my own phone is roughly 2x faster than my 1998-era computer). &amp;nbsp;It could be argued that cell phone usage actually needs the iterated hash even more as typing a long high-entropy passphrase is extremely difficult on a cell phone.
&lt;br&gt;&lt;br&gt;The bottom line is that the speed of the average processor today is vastly faster than what it was then, and so the cushion against passphrase guessers that the iterated hash was giving us is steadily dropping. &amp;nbsp;If 65536 was the right value for 11 years ago, we probably could do with a brief discussion on whether we should raise it for today (and if so, how much). &amp;nbsp;
&lt;br&gt;&lt;br&gt;David
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26576532&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Change-s2k-count--tp26576532p26576532.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26533598</id>
	<title>Re: SCM dicussion (Re: Where is &gt;libassuan-1.1.0)</title>
	<published>2009-11-26T10:51:09Z</published>
	<updated>2009-11-26T10:51:09Z</updated>
	<author>
		<name>Ingo Krabbe</name>
	</author>
	<content type="html">On Thu, Nov 26, 2009 at 12:05:47PM +0100, Bernhard Reiter wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Am Montag, 23. November 2009 22:51:44 schrieb Ingo Krabbe:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; What is wrong with &lt;a href=&quot;http://cvs.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org&lt;/a&gt;&amp;nbsp;as stated on
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://www.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gnupg.org&lt;/a&gt;&amp;nbsp; (download-&amp;gt;cvs access).
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Some links are missing there: libassuan and libgpg-error as far as I can
&lt;br&gt;&amp;gt; &amp;gt; see now.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The links on cvs.gnupg.org are just shortcusts and not complete, check the 
&lt;br&gt;&amp;gt; selection box on top right of &lt;a href=&quot;http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/&lt;/a&gt;&lt;br&gt;&amp;gt; (An improvement could be to mention that the list of shortcuts is not complete 
&lt;br&gt;&amp;gt; and to point the reader towards the selection box of the fulll version.)
&lt;/div&gt;&lt;br&gt;Yes, thats the one I searched for. Thanks.
&lt;br&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -- 
&lt;br&gt;&amp;gt; Managing Director - Owner: www.intevation.net &amp;nbsp; &amp;nbsp; &amp;nbsp; (Free Software Company)
&lt;br&gt;&amp;gt; Germany Coordinator: fsfeurope.org. Coordinator: www.Kolab-Konsortium.com.
&lt;br&gt;&amp;gt; Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
&lt;br&gt;&amp;gt; Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Gnupg-devel mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26533598&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;i don't do signatures
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26533598&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Where-is-%3Elibassuan-1.1.0-tp26475696p26533598.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26527806</id>
	<title>SCM dicussion (Re: Where is &gt;libassuan-1.1.0)</title>
	<published>2009-11-26T03:05:47Z</published>
	<updated>2009-11-26T03:05:47Z</updated>
	<author>
		<name>Bernhard Reiter</name>
	</author>
	<content type="html">Am Montag, 23. November 2009 22:51:44 schrieb Ingo Krabbe:
&lt;br&gt;&amp;gt; &amp;gt; What is wrong with &lt;a href=&quot;http://cvs.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org&lt;/a&gt;&amp;nbsp;as stated on
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gnupg.org&lt;/a&gt;&amp;nbsp; (download-&amp;gt;cvs access).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Some links are missing there: libassuan and libgpg-error as far as I can
&lt;br&gt;&amp;gt; see now.
&lt;br&gt;&lt;br&gt;The links on cvs.gnupg.org are just shortcusts and not complete, check the 
&lt;br&gt;selection box on top right of &lt;a href=&quot;http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org/cgi-bin/viewcvs.cgi/&lt;/a&gt;&lt;br&gt;(An improvement could be to mention that the list of shortcuts is not complete 
&lt;br&gt;and to point the reader towards the selection box of the fulll version.)
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Managing Director - Owner: www.intevation.net &amp;nbsp; &amp;nbsp; &amp;nbsp; (Free Software Company)
&lt;br&gt;Germany Coordinator: fsfeurope.org. Coordinator: www.Kolab-Konsortium.com.
&lt;br&gt;Intevation GmbH, Osnabrück, DE; Amtsgericht Osnabrück, HRB 18998
&lt;br&gt;Geschäftsführer Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26527806&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (3K) &lt;a href=&quot;http://old.nabble.com/attachment/26527806/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Where-is-%3Elibassuan-1.1.0-tp26475696p26527806.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26486636</id>
	<title>Re: Where is &gt;libassuan-1.1.0</title>
	<published>2009-11-23T13:51:44Z</published>
	<updated>2009-11-23T13:51:44Z</updated>
	<author>
		<name>Ingo Krabbe</name>
	</author>
	<content type="html">On Mon, Nov 23, 2009 at 08:59:00PM +0100, Werner Koch wrote:
&lt;br&gt;&amp;gt; On Mon, 23 Nov 2009 17:12, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26486636&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ikrabbe.ask@...&lt;/a&gt; said:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; svn paths on a central place on gnupg.org, as I failed to find the libassuan one
&lt;br&gt;&amp;gt; &amp;gt; for example and I don't think there is a way to access them, without knowing
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; What is wrong with &lt;a href=&quot;http://cvs.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org&lt;/a&gt;&amp;nbsp;as stated on
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gnupg.org&lt;/a&gt;&amp;nbsp; (download-&amp;gt;cvs access).
&lt;br&gt;&lt;br&gt;Some links are missing there: libassuan and libgpg-error as far as I can see
&lt;br&gt;now.
&lt;br&gt;&lt;br&gt;bye ingo
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26486636&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Where-is-%3Elibassuan-1.1.0-tp26475696p26486636.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26484842</id>
	<title>Re: Where is &gt;libassuan-1.1.0</title>
	<published>2009-11-23T11:59:00Z</published>
	<updated>2009-11-23T11:59:00Z</updated>
	<author>
		<name>Werner Koch</name>
	</author>
	<content type="html">On Mon, 23 Nov 2009 17:12, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26484842&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ikrabbe.ask@...&lt;/a&gt; said:
&lt;br&gt;&lt;br&gt;&amp;gt; Actually there are strong reasons to use git, not just that it might be
&lt;br&gt;&amp;gt; &amp;quot;en-vouge&amp;quot; and its possible to read in all the previously known tags and
&lt;br&gt;&amp;gt; branches in svn or cvs into a new git repository, but finally its your
&lt;br&gt;&lt;br&gt;.. as well as changing the history without any traces left. &amp;nbsp;Anyway, I
&lt;br&gt;won't start a holy war on VCS stuff.
&lt;br&gt;&lt;br&gt;&amp;gt; svn paths on a central place on gnupg.org, as I failed to find the libassuan one
&lt;br&gt;&amp;gt; for example and I don't think there is a way to access them, without knowing
&lt;br&gt;&lt;br&gt;What is wrong with &lt;a href=&quot;http://cvs.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.gnupg.org&lt;/a&gt;&amp;nbsp;as stated on
&lt;br&gt;&lt;a href=&quot;http://www.gnupg.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.gnupg.org&lt;/a&gt;&amp;nbsp; (download-&amp;gt;cvs access).
&lt;br&gt;&lt;br&gt;Shalom-Salam,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;Werner
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Die Gedanken sind frei. &amp;nbsp;Ausnahmen regelt ein Bundesgesetz.
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;Gnupg-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26484842&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Gnupg-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.gnupg.org/mailman/listinfo/gnupg-devel&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Where-is-%3Elibassuan-1.1.0-tp26475696p26484842.html" />
</entry>

</feed>
