Re: get OpenPGP pubkeys authenticated using German personal ID

2023-06-14 Thread Andre Heinecke via Gnupg-users
Hi, On Wednesday, 31 May 2023 16:55:05 CEST Bernhard Reiter wrote: > https://pgp.governikus.de/?lang=EN > > """ > Governikus provides the online service for authenticating your OpenPGP key on > behalf of the German Federal Office for Information Security (BSI). This > online service compares

Re: En-/Decryption speed for large files (GnuPG and Gpg4win)

2023-01-17 Thread Andre Heinecke via Gnupg-users
Hi, On Sunday 15 January 2023 10:52:23 CET Christoph Klassen wrote: > When I was testing the decryption I also tried "gpg --decrypt > test_file.gpg" (without output file) with the 10 GB file and it took 8 > minutes and 47 seconds. I was wondering why it took longer when GnuPG > didn't need to

[Announce] GnuPG 2.3.7 released

2022-07-11 Thread Andre Heinecke via Gnupg-users
provide signature files for all tarballs and binary versions. The keys are also signed by the long term keys of their respective owners. Current releases are signed by one or more of these four keys: rsa3072 2017-03-17 [expires: 2027-03-15] 5B80 C575 4298 F0CB 55D8 ED6A BCEF 7E29 4B09 2E28 A

Re: Protect email experience not Subject:s (hypothesis, draft)

2021-02-01 Thread Andre Heinecke via Gnupg-users
Hi, On Friday 29 January 2021 17:52:25 CET Bernhard Reiter wrote: > for many months now, my feeling is growing that > > encrypted subject headers in emails > shift the security balance in the wrong direction. I share that feeling. My goal that encrypted mails do not feel much different

Re: how to use WKD with python3?

2020-06-03 Thread Andre Heinecke via Gnupg-users
Hi, I'll try to answer this even though I don't completely know how to do it in python, but I know how it's done in C / C++. On Wednesday 3 June 2020 12:52:46 CEST Ludwig Reiter wrote: > how do I get public keys over WKD with python3/gpgme? you can do a keylist with KEYLIST_MODE_LOCATE for a

Re: [openpgp-email] Invitation to the 5th OpenPGP Email Summit

2019-09-09 Thread Andre Heinecke via Gnupg-users
Hi, On Sunday 8 September 2019 13:40:55 CEST Patrick Brunschwig wrote: > Up to now, I only got 12 replies. > > *Reminder: Please send me a mail if you plan to come* The GnuPG e.V. would cover the costs for privateers, those of you that do not work for OpenPGP-Email at your Job, again. Just

Re: GnuPG 2.2.8 -- Trouble Decrypting using PowerShell script

2018-10-24 Thread Andre Heinecke
n to GnuPG if this helped to solve your problem. :-) Best Regards, Andre Heinecke -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wag

Re: Get notation value through --with-colons interface

2018-10-09 Thread Andre Heinecke
Hi, On Monday, October 8, 2018 8:42:01 PM CEST Wiktor Kwapisiewicz via Gnupg-users wrote: > Is there any way to access it via API-like interface? GPGME does: gpg --with-colons --list-options show-sig-subpackets=\"20,26\" \ --list-sigs 6C8857E0D8E8F074 Best Regards, And

Re: converting gpg files into PEM and certification change confusion

2018-10-02 Thread Andre Heinecke
both use > the same algorithms. Oh! I would personally be very interested in that. I was asked this in Support and so far have answered -> Impossible. Any hints / documentation on how to achive this? Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevat

Re: cannot decrypt file symmetric encrypted

2018-08-06 Thread Andre Heinecke
entry program so that it does not start or you are acidentally using a dummy / test pinentry which provides the wrong passphrase. -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Ko

Re: dirmngr cygwin resolv.conf

2018-07-04 Thread Andre Heinecke
#endif in a central place would be appropiate. As the same policy is implicitly already applied for the much more important MSVC Windows target. There is one maintained way to get gnupg on windows. Cross compile it with mingw-w64 and run it natively. Best Regards, Andre -- Andre Heinecke | ++49-541-

Re: How in Windows batch script generate Unattended key? option --batch

2018-06-07 Thread Andre Heinecke
r.baz" you can run: gpg --yes --pinentry-mode loopback --passphrase '' --quick-gen-key f...@bar.baz Best Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: F

Re: smartcards and GPGME

2018-05-14 Thread Andre Heinecke
ementation: https://git.gnupg.org/cgi-bin/gitweb.cgi?p=gpa.git;a=blob;f=src/cm-openpgp.c Alternatively instead of wrapping gpg (and using the complicated edit interface) you could also wrap "gpg-connect-agent" and issue commands to scdaemon through that. Best Regards, Andre -- A

Re: Hi , request help on a problem with gnupg that gpg decryption does not return after creating the decrypted file

2018-05-13 Thread Andre Heinecke
o specify directly which home directory (the directory with the keys etc.) should be used. Best Regards, Andre Heinecke -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koorm

Re: Can not decrypt and verify CD's

2018-04-30 Thread Andre Heinecke
No, the error is that the file is not encrypted to your private key. Changing the passphrase won't help. Kleopatra 3.1.0 should show an improved error and show you to which keys it is actually encrypted. Alternatively you can open the command line (cmd.exe) and call "gpg --decrypt "

Re: Speedo build error on GnuPG 2.2.6

2018-04-17 Thread Andre Heinecke
est Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner signature.asc Description: This is a digitally s

Re: GnuPG usage for automatic remote decryption

2018-04-06 Thread Andre Heinecke
orwarding ). The GnuPG on the remote machine connects to a local Gpg- Agent. This allows me to SSH to a remote machine, do crypto there with secret keys that live on my local machine / security tokens. And I only need to enter the passphrase on the local machine. Best Regards, Andre -- Andre

Re: Followup: gpgme_set_passphrase_cb not working...

2018-03-23 Thread Andre Heinecke
ld be to use some kind of fake pinentry (see the tests in GPGME) and configure that in the gpg-agent.conf. But you are probably better of bundling a 2.1 / 2.2 Version of GnuPG with your Application. Best Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation

Re: Dirmngr fails to communicate with keyservers (W32 binaries for GnuPG 2.1.22)

2017-07-31 Thread Andre Heinecke
h the message "keyserver send failed: Resource temporarily > > unavailable". > > > > In the event the dirmngr from 2.1.21 is already running, the operation > > succeeds. Yes, slipped our testing. We are working on it: https://dev.gnupg.org/T3318 Regard

Re: How to NOT gnutar files during encryption?

2017-07-19 Thread Andre Heinecke
ncrypt. FWIW Kleopatra would have automatically chosen a filename like archive.tar.gpg so your client must have manually changed that to have some kind of zip extension. On the other hand you could extend your process to also accept tarballs ;-) Regards, Andre -- Andre Heinecke | ++49-541-3350

Hosting a Web Key Directory

2016-10-27 Thread Andre Heinecke
testuse...@test.gnupg.org │ sub cv25519 2016-07-15 [E] └ [Makefile] https://hg.intevation.de/gnupg/wkd-tools/raw-file/default/Makefile.example -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 1899

Re: Agent forwarding failure when the socketdir was autodeleted

2016-10-05 Thread Andre Heinecke
before the channel that runs any shell or other interactive behavior. > > I really think this ought to be handled in OpenSSH. Exactly. I wrote a mail to openssh-unix-dev as you suggested to ask about that. Let's see :-) Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http

Re: Agent forwarding failure when the socketdir was autodeleted

2016-10-04 Thread Andre Heinecke
h socket forwarding. This is a bit clunky to use. I've tried placing files in that folder, or to set up permissions to 000 for the gnupg folder (so that gnupg itself does not use it) but to no avail. It's still removed when disconnecting and the next connect will fail. Regards, Andre -- And

Re: Why GnuPG encrypted file has no icon?

2016-10-04 Thread Andre Heinecke
d be Keys, signed data, detached signatures, etc.. so to bind them to an application the application would have to detect what a file is and handle it appropiately. This is done now by Kleopatra. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH,

Agent forwarding failure when the socketdir was autodeleted

2016-10-04 Thread Andre Heinecke
would happily update the wiki with a solution. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner signature.asc

Re: Side-By-Side Installation: Gpg4win and gnuPG

2016-07-11 Thread Andre Heinecke
testhome --expert --full-gen-key would generate you a key in c:\testhome Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reite

Obtaining SSH Key format from OpenPGP public certificate without gpgkey2ssh

2016-01-07 Thread Andre Heinecke
to provide it? (Assuming the person has my public key and without gpgkey2ssh) I think this use case is one of the nice features you get by associating an OpenPGP key with SSH Authentication and I would miss it if gpgkey2ssh is removed. Regards, Andre -- Andre Heinecke | ++49-541-335083-262

Re: TOFU for GnuPG

2015-11-03 Thread Andre Heinecke
key 58BD45EC. It has. So you can assume the new Key is also valid for that UID. Any new UID's on this key will have to be treated as first contact ID's. If the new key has less UID's I don't see a problem at all. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.d

Re: TOFU for GnuPG

2015-11-03 Thread Andre Heinecke
Hi, On Tuesday 03 November 2015 16:34:39 you wrote: > At Tue, 03 Nov 2015 16:10:24 +0100, > > Andre Heinecke wrote: > > Don't we need to lookup the new key anyway to make validity decisions? > > Until then we assume "Unknown" trust. > > In the verify cas

Re: TOFU for GnuPG

2015-10-30 Thread Andre Heinecke
ld key and GnuPG can detect that and not show a warning about it? This would also solve the problem that some users may have multiple keys with the same UID's which are both valid. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer G

Re: Installing gpg2/commads?

2015-10-29 Thread Andre Heinecke
modify the destination directory. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner signature.asc Description: This is a dig

Re: GnuPG modern can't genereate keys on my Windows

2015-09-02 Thread Andre Heinecke
Hi, On Monday, August 31, 2015 07:07:03 PM Andre Heinecke wrote: > If I use the pinentry-basic included in the gnupg-w32 installer I get the > "No pinentry" error. > So it looks like pinentry-basic also has a Problem on Windows > 8.1 This was a problem in my test setup.

Re: GnuPG modern can't genereate keys on my Windows

2015-08-31 Thread Andre Heinecke
; and get an EOF error after I entered the > password. I can confirm your Problem. Even without full-gen-key or any special options. I've opened an issue for this: https://bugs.gnupg.org/gnupg/issue2085 Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevat

Re: GnuPG modern can't genereate keys on my Windows

2015-08-31 Thread Andre Heinecke
ntry-basic also has a Problem on Windows > 8.1 I've not reported a bug for this but I keep it in mind. (The issues are likely related) Works fine on Windows 7 though, curious. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17

Re: GnuPG modern can't genereate keys on my Windows

2015-08-31 Thread Andre Heinecke
ug ;-) ) 2010 I guess is slightly different as it has the "No Pinentry" Problem so I've left that out. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer:

Re: operating on remote files (Windows) using a UNC

2015-07-14 Thread Andre Heinecke
stumbled upon this also once. You need to use forward slashes instead of backslashes for gnupg to work with UNC paths e.g.: gpg2 --decrypt //remote.machine/encrypted.gpg Works. -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück

Re: AES-NI, symmetric key generation

2015-03-10 Thread Andre Heinecke
/cgi-bin/gitweb.cgi?p=gpg4win.git;a=blob;f=src/Makefile.am Look for gpg4win_pkg_package_configure (e.g. gpg4win_pkg_libgcrypt_configure) Also is there any option to turn hardware acceleration on or off at runtime? No. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http

Re: [Announce] GnuPG 2.1.1 released

2014-12-20 Thread Andre Heinecke
Hi, On Saturday 20 December 2014 12:21:08 Werner Koch wrote: Thus I do not think that Authenticate would harm even given that it is possible to buy the private key for an existing Authenticode certificate. I actually love authenticode. It means that you can do some steps to get to the

Re: GPG tool for Windows Embeddd Compact 7

2014-02-21 Thread Andre Heinecke
. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner ___ Gnupg-users mailing

Re: GPG tool for Windows Embeddd Compact 7

2014-02-20 Thread Andre Heinecke
-snapshots/gpg-ce-dev-190111-src.zip And a signed sha1sums file in: http://files.kolab.org/local/windows-ce/gpg-snapshots/ Maybe it works, maybe not. Have fun -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B

Re: Building Pinentry for Windows

2013-10-25 Thread Andre Heinecke
into the src directory of mxe. Godspeed, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner

Re: Building pinentry on Windows 7

2013-10-23 Thread Andre Heinecke
on a debian wheezy system. Regards, Andre -- Andre Heinecke | ++49-541-335083-262 | http://www.intevation.de/ Intevation GmbH, Neuer Graben 17, 49074 Osnabrück | AG Osnabrück, HR B 18998 Geschäftsführer: Frank Koormann, Bernhard Reiter, Dr. Jan-Oliver Wagner PKG := pinentry $(PKG)_IGNORE