Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-19 Thread Werner Koch
On Fri, 14 Oct 2016 21:47, d...@fifthhorseman.net said: >> In a new temp directory do: >> >> GNUPGHOME=$(pwd) gpg-agent --daemon gpg . >> >> Or whatever you want to run under gpg-agent's control. This has been >> there for ages. > > fwiw, this doesn't work (and actually returns an error) if

Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-18 Thread Daniel Kahn Gillmor
On Tue 2016-10-18 07:44:43 -0400, Ian Jackson wrote: > Daniel Kahn Gillmor writes ("Re: [pkg-gnupg-maint] Bug#840669: Bug#840669: > Beware of leftover gpg-agent processes"): >> On Sat 2016-10-15 11:21:29 -0400, Ian Jackson wrote: >> > 1. gnupg1-compatible authorisation lifetime: >> >> I believe t

Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-18 Thread Ian Jackson
Daniel Kahn Gillmor writes ("Re: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes"): > On Sat 2016-10-15 11:21:29 -0400, Ian Jackson wrote: > > 1. gnupg1-compatible authorisation lifetime: > > I believe this is a deliberate change in semantics from the upstream > G

Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-17 Thread Daniel Kahn Gillmor
On Sat 2016-10-15 11:21:29 -0400, Ian Jackson wrote: > 1. gnupg1-compatible authorisation lifetime: I believe this is a deliberate change in semantics from the upstream GnuPG project. In particular, authorization for the use of secret key material is now the responsibility of the gpg-agent. This

Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-15 Thread Ian Jackson
Lots of this discussion has been focusing on the test suite process leak problem. But there are actually three separate use cases which need something along the lines of my proposal; two of which are regressions from gnupg1. 1. gnupg1-compatible authorisation lifetime: Command line use of gpg b

Bug#840669: [pkg-gnupg-maint] Bug#840669: Bug#840669: Beware of leftover gpg-agent processes

2016-10-14 Thread Daniel Kahn Gillmor
On Fri 2016-10-14 15:18:40 -0400, Werner Koch wrote: > On Fri, 14 Oct 2016 19:17, ijack...@chiark.greenend.org.uk said: > >> authorisations, if the user types in a passphrase) have a lifetime >> limited by that of the gpg process which started the agent. > > In a new temp directory do: > > GNUPGHO