aboutsummaryrefslogtreecommitdiffstats
Commit message (Collapse)AuthorAgeFilesLines
...
* doc fixesWerner Koch2002-02-142-5/+2
|
* * pkclist.c (check_signatures_trust): Always print the warning forWerner Koch2002-02-143-9/+17
| | | | | | | | unknown and undefined trust. Removed the did_add cruft. Reported by Janusz A. Urbanowicz. * g10.c: New option --no-use-agent. Hmmm, is this a a good name? --do-not-use-agent seems a bit to long.
* * random.c (mix_pool): Removed the failsafe stuff again. It makesWerner Koch2002-02-142-15/+6
| | | | | the code more complicate and may give the path to more bugs.
* Bug fix - properly handle user IDs with colons (":") in them while HKPDavid Shaw2002-02-122-5/+36
| | | | | searching.
* * random.c (add_randomness): Xor new data into the pool and notWerner Koch2002-02-102-2/+29
| | | | | | | | | | just copy it. This avoids any choosen input attacks which are not serious in our setting because an outsider won't be able to mix data in and even then we keep going with a PRNG. Thanks to Stefan Keller for pointing this out. * random.c (mix_pool): Carry an extra failsafe_digest buffer around to make the function more robust.
* For --sig-policy-url and --cert-policy-url, clarify what is a sig and whatDavid Shaw2002-02-1012-39/+118
| | | | | | | | | | | | | | | | | | | | | | is a cert. A sig has sigclass 0x00, 0x01, 0x02, or 0x40, and everything else is a cert. Add a "nrlsign" for nonrevocable and local key signatures. Add a --no-force-mdc to undo --force-mdc. Add a knob to force --disable-mdc/--no-disable-mdc. Off by default, of course, but is used in --pgp2 and --pgp6 modes. Allow specifying multiple users in the "Enter the user ID" loop. Enter a blank line to stop. Show each key+id as it is added. It is not illegal (though possibly silly) to have multiple policy URLs in a given signature, so print all that are present. More efficient implementation of URL-ifying code for --search on an HKP keyserver.
* Allow policy URLs with %-expandos in them. This allows policy URLs likeDavid Shaw2002-02-057-100/+179
| | | | | | | | | "http://notary.jabberwocky.com/keysign/%K" to create a per-signature policy URL. Use the new generic %-handler for the photo ID stuff as well. Display policy URLs and notations during signature generation if --show-policy-url/--show-notation is set.
* Workaround for the pksd and OKS keyserver bug that calculates v4 RSADavid Shaw2002-02-043-4/+48
| | | | | | | | keyids as if they were v3. The workaround/hack is to fetch both the v4 (e.g. 99242560) and v3 (e.g. 68FDDBC7) keyids. This only happens for key refresh while using the HKP scheme and the refresh-add-fake-v3-keyids keyserver option must be set. This should stay off by default.
* Bug fix - do not append keys to each other when --sending more than one.David Shaw2002-02-042-1/+6
|
* Split "--set-policy-url" into "--cert-policy-url" and "--sig-policy-url"David Shaw2002-02-035-8/+42
| | | | | | so the user can set different policies for key and data signing. For backwards compatibility, "--set-policy-url" sets both, as before.
* * g10.c (main): --gen-random --armor does now output a base64Werner Koch2002-01-302-2/+23
| | | | | encoded string.
* --pgp6 flag. This is not nearly as involved as --pgp2. In short, itDavid Shaw2002-01-295-69/+105
| | | | | | | | turns off force_mdc, turns on no_comment, escape_from, and force_v3_sigs, and sets compression to 1. It also restricts the user to IDEA (if present), 3DES, CAST5, MD5, SHA1, and RIPEMD160. See the comments above algo_available() for lots of discussion on why you would want to do this.
* Do not cache fdopened fds on close.David Shaw2002-01-272-3/+7
|
* More comments about when to use IDEA in keygen.cDavid Shaw2002-01-274-8/+31
| | | | | | | | | | When key signing with multiple keys at the same time, make sure each key gets the sigclass prompt Close the iobuf and FILE before trying to reap the child process to encourage the child to exit Disable cache-on-close of the fd iobuf (shouldn't all fd iobufs not be cached?)
* Added the missing file.Timo Schulz2002-01-261-0/+8
|
* Registry file for W32.Timo Schulz2002-01-261-0/+4
|
* * gpg.sgml: A few words about --gpg-agent-info and GPG_AGENT_INFO.Werner Koch2002-01-263-16/+83
|
* UpdatesWerner Koch2002-01-263-2/+5
|
* * g10.c, options.h: New option --gpg-agent-infoWerner Koch2002-01-266-8/+50
| | | | | | | | * passphrase.c (agent_open): Let it override the environment info. * seckey-cert.c (check_secret_key): Always try 3 times when the agent is enabled. * options.skel: Describe --use-agent.
* * README.W32: Modify the filename because now the .exe extensionTimo Schulz2002-01-252-2/+7
| | | | | is automatically added to the binary.
* Only check preferences against keys with v4 self sigs as v3 sigs have noDavid Shaw2002-01-244-15/+26
| | | | | | | prefs Only put in the fake IDEA preference with --pgp2 mode Print "Expired" for expired but good signatures.
* Cosmetic: don't present a RSA signing key as a "keypair" which can be 768David Shaw2002-01-233-3/+21
| | | | | | | bits long (as RSA minimum is 1024) Allow IDEA as a fake preference for v3 keys with v3 selfsigs when verifying that a cipher is in preferences while decrypting
* Some compatibility polish for PGP2. Add a fake IDEA preference for v3David Shaw2002-01-229-17/+94
| | | | | | | | keys (this is in the RFC), so that they can be (sometimes) used along OpenPGP keys. Do not force using IDEA on an OpenPGP key, as this may violate its prefs. Also, revise the help text for the sig class explanation.
* * passphrase.c (passphrase_to_dek): Add tryagain_text arg to beWerner Koch2002-01-2010-30/+101
| | | | | | | | | | | | | | used with the agent. Changed all callers. (agent_get_passphrase): Likewise and send it to the agent * seckey-cert.c (do_check): New arg tryagain_text. (check_secret_key): Pass the string to do_check. * keygen.c (ask_passphrase): Set the error text is required. * keyedit.c (change_passphrase): Ditto. * passphrase.c (agent_open): Disable opt.use_agent in case of a problem with the agent. (agent_get_passphrase): Ditto. (passphrase_clear_cache): Ditto.
* Removed debugging outputWerner Koch2002-01-192-2/+2
|
* * passphrase.c (agent_open): Add support for the new Assuan basedWerner Koch2002-01-192-170/+357
| | | | | | | gpg-agent. New arg to return the used protocol version. (agent_get_passphrase): Implemented new protocol here. (passphrase_clear_cache): Ditto.
* New command --decrypt-files.Timo Schulz2002-01-156-41/+111
| | | | | Some fixes.
* Fixed some typos.Timo Schulz2002-01-122-29/+59
|
* Add documentation for --{no-}ask-cert-expire and --{no-}ask-sig-expireDavid Shaw2002-01-112-14/+60
| | | | | | | Revise --expire (it doesn't switch on the expiration prompt any longer) Revise --default-check-level to be clearer as to what makes a good key check before signing
* Move idea_cipher_warn to misc.c so gpgv.c doesn't need a stubDavid Shaw2002-01-096-95/+77
| | | | | | | | Remove get_temp_dir (it's in exec.c now) Allow --delete-key (now --delete-keys, though --delete-key still works) to delete multiple keys in one go. This applies to --delete-secret-key(s) and --delete-secret-and-public-key(s) as well
* New code for encode_crypt_files.Timo Schulz2002-01-094-13/+37
|
* Added missing include file.Timo Schulz2002-01-092-0/+7
|
* Better description for --encrypt-files.Timo Schulz2002-01-082-1/+5
|
* * g10.c (main): Must register the secring for encryption becauseWerner Koch2002-01-082-2/+8
| | | | | | it is needed to figure out the default recipient. Reported by Roger Sondermann.
* * secmem.c (print_warn): Print a pointer to the FAQ.Werner Koch2002-01-082-2/+10
|
* * DETAILS: Removed the comment that unattended key generation isWerner Koch2002-01-082-8/+10
| | | | | experimental. It is now a standard feature.
* fix off-by-one in building attribute subpacketsDavid Shaw2002-01-068-19/+106
| | | | | | | | | | change default compression to 1 add ask-sig-expire and ask-cert-expire (--expert was getting absurdly overloaded) permit v3 subkeys use --expert to protect adding multiple photo ids and adding photos to a v3 key
* * argparse.c (default_strusage): Set default copyright date to 2002.Werner Koch2002-01-052-1/+5
|
* * g10.c (main): Do not register the secret keyrings for certainWerner Koch2002-01-053-79/+92
| | | | | | | | commands. * keydb.c (keydb_add_resource): Use access to test for keyring existence. This avoids cached opened files which are bad under RISC OS.
* Hmm, this is a build file, should not be in the CVSWerner Koch2002-01-051-43/+173
|
* typo fixWerner Koch2002-01-051-0/+4
|
* typo fixWerner Koch2002-01-051-2/+2
|
* NEWS update about filesize/partial-length change in symmetric messagesDavid Shaw2002-01-042-0/+8
|
* Use one-pass packets even if it's a v3 key making the signatureDavid Shaw2002-01-044-27/+51
| | | | | | | Warn with pgp2 and non-detached signatures Use the actual filesize rather than partial length packets in symmetric messages (see ChangeLog or NEWS for discussion).
* Minor tweaks: remove --no-default-check-level, don't cache child tempfilesDavid Shaw2002-01-034-10/+19
| | | | | and simpler code in keyserver
* New command (encrypt-files).Timo Schulz2002-01-036-1/+40
|
* set filetype of Makefile correctlyStefan Bellon2002-01-022-0/+3
|
* used different char types for RISC OSStefan Bellon2002-01-021-0/+9
|
* moved util.h include downwardsStefan Bellon2002-01-021-1/+1
|
* invalidate close cacheStefan Bellon2002-01-021-2/+7
|