Your message dated Fri, 02 Nov 2018 22:02:08 +0000
with message-id <[email protected]>
and subject line Bug#906545: fixed in gnupg2 2.1.18-8~deb9u3
has caused the Debian Bug report #906545,
regarding gnupg 2.1 (in stretch) fails to fetch some ECC keys
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
906545: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=906545
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: gnupg
Version: 2.1.18-8~deb9u2
Severity: normal
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Dear Maintainer,
I'm trying to use my stretch box to caff sign the keys from DebConf18.
But I find that almost all ECC keys failed, except Niibe-san's one.
I digged a bit and find the reason is that caff fails to fetch those
ECC keys.
In order to avoid importing keys to the keyring, the following sample
use the caff's gnupghome directory.
Bad case:
$ GNUPGHOME=~/.caff/gnupghome gpg -v --recv-keys 0x86B2250DBAC0ABC0
gpg: data source: https://176.9.147.41:443
gpg: armor header: Version: SKS 1.1.6
gpg: armor header: Comment: Hostname: keyserver.ntzwrk.org
gpg: pub ed25519/0x86B2250DBAC0ABC0 2016-08-23 Shen-Ta Hsieh (謝昇達)
<[email protected]>
gpg: key 0x86B2250DBAC0ABC0: no subkey for subkey binding signature
gpg: key 0x86B2250DBAC0ABC0: no subkey for key binding
gpg: key 0x86B2250DBAC0ABC0: no subkey for subkey binding signature
gpg: key 0x86B2250DBAC0ABC0: no subkey for key binding
gpg: key 0x86B2250DBAC0ABC0: no user ID for key signature packet of
class 13
gpg: key 0x86B2250DBAC0ABC0: no user ID for signature
gpg: Total number processed: 1
Good case:
$ GNUPGHOME=~/.caff/gnupghome gpg -v --recv-keys 0xE267B052364F028D
gpg: data source: https://176.9.147.41:443
gpg: armor header: Version: SKS 1.1.6
gpg: armor header: Comment: Hostname: keyserver.ntzwrk.org
gpg: pub ed25519/0xE267B052364F028D 2015-08-12 NIIBE Yutaka
<[email protected]>
gpg: key 0xE267B052364F028D: invalid subkey binding
gpg: key 0xE267B052364F028D: "NIIBE Yutaka <[email protected]>"
gpg: Total number processed: 1
And I confirm above issue cannot be reproduced under gnugp 2.2
(sid version).
So maybe this can be fixed for the stretch/stable version?
Thanks!
Cheers,
Roger
- -- System Information:
Debian Release: 9.5
APT prefers stable-updates
APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)
Kernel: Linux 4.16.0-0.bpo.2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8),
LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
Versions of packages gnupg depends on:
ii gnupg-agent 2.1.18-8~deb9u2
ii libassuan0 2.4.3-2
ii libbz2-1.0 1.0.6-8.1
ii libc6 2.24-11+deb9u3
ii libgcrypt20 1.7.6-2+deb9u3
ii libgpg-error0 1.26-2
ii libksba8 1.3.5-2
ii libreadline7 7.0-3
ii libsqlite3-0 3.16.2-5+deb9u1
ii zlib1g 1:1.2.8.dfsg-5
Versions of packages gnupg recommends:
ii dirmngr 2.1.18-8~deb9u2
pn gnupg-l10n <none>
Versions of packages gnupg suggests:
pn parcimonie <none>
pn xloadimage <none>
- -- no debconf information
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECjKtvoA5m+cWOFnspHhrDacDNKgFAlt35mYACgkQpHhrDacD
NKitAQ//dkW9MndEKdLq5RaVfxGcUsowzw6fOP6vsVs49TAe8JC2aTl1Q/ogNoQM
2nUACsq6TZVcH2Z0Cm8RCTDk6MqWPEc0jEDglG+1RXXhh4KvDeXsycGAa+tBKmd4
Y4SIg6pil7XSrsVQp065xYnec98CVRiFLQzxlr86s/GksKsT7bMwaOT7BxrK4ItW
/OY7tOc3AI1E05tXrw1OcU2mdLMMhC8N9938dFVQtev7eYaYD+lfzjYA6YZ90kEx
9f1rb4UMyEcPIe/HReoU+3a7rWdbRot83ANogGjs0oxyOis+5/OagMRVWrHd25JJ
TVTrkcRpYAeiVnraPm1DWZaY1p3pVTK9k3xlzocI+jFCD/NxJCCiuX2D4emiD37+
2mRep34NaeWWsBySawLwLAbxXGyZBX2z8U5ZTgEnYRyrNkLnDLVKgWl5bmeIgtdw
gXvRJibMRRHR5IUB4hE0ragsa4a4HTPobHkCJYL77AIA+rHkKIxu5KMfxqbnHNL8
KDccw0jgk7BzMS3RL9hEnf1BdJKEYJqklG1BK9vr1HgpmWpute2L0eCe0zVLCeDS
ysnFAsUTq75xc3Mqh7QUCAwlM6mZq45qD31sU4epJN6PyBLp193AMr3galyc4KGx
wAF0yTiJwtGqr1X+7lWwYs7ZHeQA2ZBLpcN+yY6EJER+8r/ybJ0=
=HgPq
-----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---
Source: gnupg2
Source-Version: 2.1.18-8~deb9u3
We believe that the bug you reported is fixed in the latest version of
gnupg2, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Daniel Kahn Gillmor <[email protected]> (supplier of updated gnupg2
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 05 Oct 2018 15:43:38 -0500
Source: gnupg2
Binary: gnupg-agent scdaemon gpgsm gnupg gnupg2 gpgv gpgv2 dirmngr gpgv-udeb
gpgv-static gpgv-win32 gnupg-l10n
Architecture: source
Version: 2.1.18-8~deb9u3
Distribution: stretch
Urgency: medium
Maintainer: Debian GnuPG Maintainers <[email protected]>
Changed-By: Daniel Kahn Gillmor <[email protected]>
Description:
dirmngr - GNU privacy guard - network certificate management service
gnupg - GNU privacy guard - a free PGP replacement
gnupg-agent - GNU privacy guard - cryptographic agent
gnupg-l10n - GNU privacy guard - localization files
gnupg2 - GNU privacy guard - a free PGP replacement (dummy transitional pa
gpgsm - GNU privacy guard - S/MIME version
gpgv - GNU privacy guard - signature verification tool
gpgv-static - minimal signature verification tool (static build)
gpgv-udeb - minimal signature verification tool (udeb)
gpgv-win32 - GNU privacy guard - signature verification tool (win32 build)
gpgv2 - GNU privacy guard - signature verification tool (dummy transition
scdaemon - GNU privacy guard - smart card support
Closes: 862682 878952 906545
Changes:
gnupg2 (2.1.18-8~deb9u3) stretch; urgency=medium
.
* block trivial access to scdaemon memory (Closes: #878952)
* Update crypto defaults for 2018 (new keys are RSA 3072, prefer AES256)
* d/control: move Vcs*: to salsa
* dirmngr: implement querying nameservers over IPv6 (Closes: #862682)
* use DEP-14 branch naming
* refresh patches
* backport --no-symkey-cache
* backport improved import and export filtering
* backport display of revocation certificates
* backport stripping unusable subkey material during export-minimal
* backport fix to make --dry-run work when listing secret keys
* backport fix showing secret keys when listing keys
* backport fix to clean keys before importing (Closes: #906545)
Checksums-Sha1:
9349ce6a6042f28e4a2f43d5c067d00c153d94b2 2537 gnupg2_2.1.18-8~deb9u3.dsc
d978051d77fd5662d7871302032d52c4e93090e4 117913
gnupg2_2.1.18-8~deb9u3.debian.tar.bz2
cab1d1310a2a623100c73995bf22850d607a8ad8 16460
gnupg2_2.1.18-8~deb9u3_amd64.buildinfo
Checksums-Sha256:
d4665c6bef3eab1a65a94492358529ba62d3976f8b955e3502da057a94d6f126 2537
gnupg2_2.1.18-8~deb9u3.dsc
d2525b74bf703b5aefc66b9d029f330ec316e0aa35b54710b132e3754144ac67 117913
gnupg2_2.1.18-8~deb9u3.debian.tar.bz2
37a1ced8a677b38a924cceae2a397caa7584117aa810c7c512a84bc3cb0f0c77 16460
gnupg2_2.1.18-8~deb9u3_amd64.buildinfo
Files:
8a221a7db97255d5cf0e1039fcbb9b76 2537 utils optional gnupg2_2.1.18-8~deb9u3.dsc
2ad5655de4465eb4f561416f35d9d22b 117913 utils optional
gnupg2_2.1.18-8~deb9u3.debian.tar.bz2
1052f072b1418bf0a4037078f6b08508 16460 utils optional
gnupg2_2.1.18-8~deb9u3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQTTaP514aqS9uSbmdJsHx7ezFD6UwUCW9Z1vwAKCRBsHx7ezFD6
U6xcAP9+/KiRlHoWQaegRiesleaRLAEKJo4QSv7VPClatHW3uAD+KS2VjT/j0pkB
wWau8iOW+BdTKdxkzNDgXQtpNQ7YkAE=
=nkaZ
-----END PGP SIGNATURE-----
--- End Message ---