mastodontech.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Offen für alle (über 16) und bereitgestellt von Markus'Blog

Serverstatistik:

1,4 Tsd.
aktive Profile

#gnupg

2 Beiträge2 Beteiligte0 Beiträge heute
Sandro :nixos: :verified_gay:<p>GnuPG is an awful piece of software!</p><p>`gnupg --list-keys sandro` does not display expired subkeys and extending a key via `gpg --edit-key sandro` does not extend the subkey.</p><p>I want the hour of my life back!</p><p><a href="https://c3d2.social/tags/gnupg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gnupg</span></a> <a href="https://c3d2.social/tags/gpg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gpg</span></a> <a href="https://c3d2.social/tags/gpgsucks" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gpgsucks</span></a></p>
Heiko<p>I sent a rather lengthy email to the "gnupg-devel" mailing list, about the governance and development of the <a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> standard (and <a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a>'s fork of the specification that is branded "<a href="https://floss.social/tags/LibrePGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LibrePGP</span></a>")</p><p><a href="https://lists.gnupg.org/pipermail/gnupg-devel/2025-September/036064.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">lists.gnupg.org/pipermail/gnup</span><span class="invisible">g-devel/2025-September/036064.html</span></a></p>
AskUbuntu<p>How to fix signature verification errors when running sudo apt update <a href="https://ubuntu.social/tags/apt" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>apt</span></a> <a href="https://ubuntu.social/tags/updates" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>updates</span></a> <a href="https://ubuntu.social/tags/repository" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>repository</span></a> <a href="https://ubuntu.social/tags/gnupg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gnupg</span></a></p><p><a href="https://askubuntu.com/q/1555845/612" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">askubuntu.com/q/1555845/612</span><span class="invisible"></span></a></p>
Debacle<p><span class="h-card" translate="no"><a href="https://mas.to/@evgandr" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>evgandr</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.bsd.cafe/@mms" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mms</span></a></span> <span class="h-card" translate="no"><a href="https://mastodon.social/@lhp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>lhp</span></a></span></p><p>(setq epg-pinentry-mode 'loopback)</p><p>changed my life!</p><p>It worked immediately for me, without the gpg-agent settings</p><p>allow-emacs-pinentry<br>allow-loopback-pinentry</p><p>and without restarting the agent or <a href="https://framapiaf.org/tags/Emacs" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Emacs</span></a>…</p><p><a href="https://framapiaf.org/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://framapiaf.org/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a></p>
DD9JN<p>We getting closer to a <a href="https://social.darc.de/tags/gpg4win" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gpg4win</span></a> 5 release. 😀 Here is a new Beta version:</p><p><a href="https://files.gpg4win.org/Beta/gpg4win-5.0.0-beta369/gpg4win-5.0.0-beta369.exe" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">files.gpg4win.org/Beta/gpg4win</span><span class="invisible">-5.0.0-beta369/gpg4win-5.0.0-beta369.exe</span></a></p><p>featuring <a href="https://social.darc.de/tags/kleopatra" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kleopatra</span></a> and <a href="https://social.darc.de/tags/okular" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>okular</span></a> updates and comes of course with the fresh <a href="https://social.darc.de/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> version 2.5.12</p>
GnuPG<p>Back from the summer, <a href="https://mstdn.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> 2.5.12 is now ready for production usage.<br>And this includes the post-quantum cryptography encryption (<a href="https://mstdn.social/tags/PQC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PQC</span></a>) support which is the main feature of the 2.5 series. (Okay, there is also better support for 64bit Windows.)</p><p>So give it a spin or point your favourite GNU/Linux distribution to it for packaging. </p><p><a href="https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/000497.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">lists.gnupg.org/pipermail/gnup</span><span class="invisible">g-announce/2025q3/000497.html</span></a></p><p><a href="https://mstdn.social/tags/EndtoEndCrypto" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EndtoEndCrypto</span></a> <a href="https://mstdn.social/tags/LibrePGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LibrePGP</span></a> <a href="https://mstdn.social/tags/OpenPGPv4" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGPv4</span></a><br><a href="https://mstdn.social/tags/FreeSoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FreeSoftware</span></a></p>
DD9JN<p>The <a href="https://social.darc.de/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> project is pleased to announce the availability of a new GnuPG release:<br>Version 2.5.12. This release adds new features and fixes two<br>regressions.</p><p>Note that this 2.5 series is fully supported and thus ready for<br>production use. </p><p><a href="https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/date.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">lists.gnupg.org/pipermail/gnup</span><span class="invisible">g-announce/2025q3/date.html</span></a></p>
Heiko<p>I just released version 0.1.6 of oct-git, a simple tool for Git signing and verification with <a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> cards</p><p><a href="https://crates.io/crates/openpgp-card-tool-git" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">crates.io/crates/openpgp-card-</span><span class="invisible">tool-git</span></a></p><p>This is a maintenance release: It updates the libraries that oct-git builds on (in particular <span class="h-card" translate="no"><a href="https://mastodon.social/@rpgp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rpgp</span></a></span>), but doesn't add new functionality.</p><p>However, with this update there is now a straightforward path to automated updating of OpenPGP certificates (aka public keys) from keyservers. I look forward to implementing that soon.</p><p><a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://floss.social/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a> <a href="https://floss.social/tags/Git" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Git</span></a> <a href="https://floss.social/tags/HSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HSM</span></a></p>
0xKaishakunin<p>Could someone with a recent <a href="https://mastodon.social/tags/NitroKey" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NitroKey</span></a> please confirm that it supports <a href="https://mastodon.social/tags/BSI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSI</span></a> <a href="https://mastodon.social/tags/Brainpool" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Brainpool</span></a> 512 <a href="https://mastodon.social/tags/ECC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ECC</span></a> as <a href="https://mastodon.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://mastodon.social/tags/smartcard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>smartcard</span></a> <a href="https://mastodon.social/tags/pqc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>pqc</span></a></p>
DD9JN<p>We just re-posted our last blog entry from <a href="https://social.darc.de/tags/gnupg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gnupg</span></a>.com how also to the regualr block at @GnuPG.org . Thus if you are interested in upstream Debian style packages for GnuPG and all supporting libraries please check out:</p><p><a href="https://gnupg.org/blog/20250827-new-repository.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">gnupg.org/blog/20250827-new-re</span><span class="invisible">pository.html</span></a></p>
Heiko<p>I edited and (slightly) expanded yesterday's thread about inspecting <a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> certificate status with <span class="h-card" translate="no"><a href="https://mastodon.social/@rpgp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rpgp</span></a></span> into a blog article:</p><p><a href="https://openpgp.foo/posts/2025-08-certificate-status/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">openpgp.foo/posts/2025-08-cert</span><span class="invisible">ificate-status/</span></a></p><p><a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://floss.social/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a> <a href="https://floss.social/tags/RustLang" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>RustLang</span></a> <a href="https://floss.social/tags/CLI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CLI</span></a></p>
Heiko<p>I just released version 0.6.6 of rpgpie, an experimental high level API for <span class="h-card" translate="no"><a href="https://mastodon.social/@rpgp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rpgp</span></a></span>:</p><p><a href="https://crates.io/crates/rpgpie" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crates.io/crates/rpgpie</span><span class="invisible"></span></a></p><p>Since a few versions, the rpgpie crate ships with the experimental "rpgp" CLI tool, which can inspect certificates (aka "<a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> public keys") in two different ways:</p><p>- "show" prints the internal structure of a certificate without much interpretation<br>- "status" prints a summarized view, which applies OpenPGP validity semantics</p><p>Since this release, "status" can output JSON</p><p>🧵</p><p><a href="https://floss.social/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a> <a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a></p>
AskUbuntu<p>Kubuntu distro integrity and authenticity checks <a href="https://ubuntu.social/tags/kubuntu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>kubuntu</span></a> <a href="https://ubuntu.social/tags/gnupg" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>gnupg</span></a> <a href="https://ubuntu.social/tags/signature" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>signature</span></a> <a href="https://ubuntu.social/tags/checksums" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>checksums</span></a></p><p><a href="https://askubuntu.com/q/1554945/612" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">askubuntu.com/q/1554945/612</span><span class="invisible"></span></a></p>
Menel :xmpp:Total verrückt,<br>Ich sende alle meine Emails immer mit pgp-Key im Anhang, so passiv aggressiv an alle.<br>Bisher hat das nie irgendwo was bewirkt, die einzige Reaktion bisher war, daß jemand sagt, dass der eine Anhang von mir nicht geöffnet werden konnte.. .<br>Aber da schreibe ich meinem Arbeitgeber mal wieder und plötzlich so eine automatische <i>verschlüsselte</i> Mail :catrave:<br><br>Da ist man mal ein Jahr nicht da und dann: Hyper modern 🤯<br><br><a href="https://snikket.de/social?t=pgp" class="mention hashtag" rel="nofollow noopener" target="_blank">#pgp</a> <a href="https://snikket.de/social?t=gnupg" class="mention hashtag" rel="nofollow noopener" target="_blank">#gnupg</a> <a href="https://snikket.de/social?t=verschlusselung" class="mention hashtag" rel="nofollow noopener" target="_blank">#verschlusselung</a> <a href="https://snikket.de/social?t=email" class="mention hashtag" rel="nofollow noopener" target="_blank">#email</a> <a href="https://snikket.de/social?t=e" class="mention hashtag" rel="nofollow noopener" target="_blank">#e</a>-mail <a href="https://snikket.de/social?t=thunderbird" class="mention hashtag" rel="nofollow noopener" target="_blank">#thunderbird</a> <a href="https://snikket.de/social?t=krh" class="mention hashtag" rel="nofollow noopener" target="_blank">#krh</a> <a href="https://snikket.de/social?t=hannover" class="mention hashtag" rel="nofollow noopener" target="_blank">#Hannover</a> <a href="https://snikket.de/social?t=regionhannover" class="mention hashtag" rel="nofollow noopener" target="_blank">#RegionHannover</a><br><br>
scy<p>me, opening a new terminal tab: From all the things I've scripted so far, this has got to have one of the best effort-to-usefulness factors ever.</p><p><a href="https://codeberg.org/scy/dotfiles/commit/9ef269f86356d80e53f6e7bbde9d85b65a21525f" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">codeberg.org/scy/dotfiles/comm</span><span class="invisible">it/9ef269f86356d80e53f6e7bbde9d85b65a21525f</span></a></p><p><a href="https://chaos.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> <a href="https://chaos.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> <a href="https://chaos.social/tags/GPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GPG</span></a> <a href="https://chaos.social/tags/shell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>shell</span></a> <a href="https://chaos.social/tags/dotfiles" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dotfiles</span></a></p>
Net Gremlin 🚴🏻 🐧 🇩🇪<p><span class="h-card" translate="no"><a href="https://zirk.us/@eibart" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>eibart</span></a></span> Für solche Usecases nutze ich <span class="h-card" translate="no"><a href="https://mastodon.xyz/@nextcloud" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>nextcloud</span></a></span> - beim Selfhosting weiß man auch, wo die Daten sind.</p><p>Bei Services wie eben z.B. WeTransfer die Daten *immer* verschlüsseln. <a href="https://mastodon.ip6.li/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> ist dafür gut geeignet. Dann lernt deren KI eben PGP verschlüsselte Daten.</p>
Heiko<p>New blog article: "Using a second <a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> card for my primary key"</p><p><a href="https://openpgp.foo/posts/2025-07-a-second-card/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">openpgp.foo/posts/2025-07-a-se</span><span class="invisible">cond-card/</span></a></p><p>This is a rather niche article, but I hope it will still contain some bits of interest, for at least some readers 🤓.</p><p>In it, I import my primary OpenPGP key onto a second OpenPGP card hardware device, and use the device to issue a third-party certification with rsop-oct.</p><p>I also outline some background and tradeoffs around different OpenPGP card setup.</p><p><a href="https://floss.social/tags/HSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>HSM</span></a> <a href="https://floss.social/tags/OpenPGPcard" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGPcard</span></a> <a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a></p>
Heiko<p>I just released version 0.1.3 of rsop-oct, a stateless <a href="https://floss.social/tags/OpenPGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenPGP</span></a> ("SOP") CLI tool for use with OpenPGP card hardware devices:</p><p><a href="https://crates.io/crates/rsop-oct/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">crates.io/crates/rsop-oct/</span><span class="invisible"></span></a></p><p>Like its sibling project <a href="https://floss.social/tags/rsop" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rsop</span></a>, rsop-oct is based on <span class="h-card" translate="no"><a href="https://mastodon.social/@rpgp" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>rpgp</span></a></span></p><p>This update adds support for the SOP command 'certify-userid'.</p><p>This allows issuing certifications (aka "third-party signatures") over identities in other people's OpenPGP certificates, directly with an OpenPGP card device.</p><p>For more on <a href="https://floss.social/tags/SOP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SOP</span></a>, see <a href="https://datatracker.ietf.org/doc/draft-dkg-openpgp-stateless-cli/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">datatracker.ietf.org/doc/draft</span><span class="invisible">-dkg-openpgp-stateless-cli/</span></a></p><p><a href="https://floss.social/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a> <a href="https://floss.social/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a></p>
DD9JN<p><a href="https://social.darc.de/tags/GnuPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GnuPG</span></a> 2.5.9 has been released along with a new <a href="https://social.darc.de/tags/Gpg4win" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Gpg4win</span></a> beta. And - for the first time - we now publish packages for <a href="https://social.darc.de/tags/Debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Debian</span></a>, <a href="https://social.darc.de/tags/Devuan" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Devuan</span></a>, and <a href="https://social.darc.de/tags/Ubuntu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ubuntu</span></a> . </p><p>See <a href="https://lists.gnupg.org/pipermail/gnupg-announce/2025q3/000495.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">lists.gnupg.org/pipermail/gnup</span><span class="invisible">g-announce/2025q3/000495.html</span></a></p>
Gemischtwahnladen<p>Wollte grad (nach Jahren) mal wieder ne <a href="https://punkstodon.de/tags/PGP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PGP</span></a>-Verschlüsselung für meine Mails einrichten. Nun hat <a href="https://punkstodon.de/tags/Thunderbird" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Thunderbird</span></a> ja inzwischen <a href="https://punkstodon.de/tags/GNUPG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GNUPG</span></a> und das sieht ja auch alles ganz toll aus, aber was mich als alter <a href="https://punkstodon.de/tags/Enigmail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Enigmail</span></a> User irritiert, ist das Ding mit der (fehlenden) Passphrase. Also wie ich das verstehe wird die ja (für alle Mailaccounts!?) ersetzt durch das Thunderbird-Masterpasswort. So weit so naja... Aber würde die Mails auch weiterhin gern auffm Handy abrufen (<a href="https://punkstodon.de/tags/K9" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>K9</span></a>). Da gibts dann n Addon, soweit hab ich das schon gesehen, aber ist dann das Masterpasswort auch da meine Passphrase? Danke schonmal für Tipps...</p>