Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | * configure.ac: Allow the DNS stuff to work on OSX by trying the | David Shaw | 2006-03-18 | 2 | -3/+28 | |
| | | | | | Apple-specific BIND_8_COMPAT. | |||||
* | * keyserver.c (keyserver_import_cert): Handle the IPGP CERT type for | David Shaw | 2006-03-17 | 3 | -24/+43 | |
| | | | | | | | both the fingerprint alone, and fingerprint+URL cases. * getkey.c (get_pubkey_byname): Minor cleanup. | |||||
* | * cert.c (get_cert): Handle the fixed IPGP type with fingerprint. | David Shaw | 2006-03-16 | 5 | -19/+71 | |
| | ||||||
* | * keyserver-internal.h, keyserver.c (keyserver_import_pka): Use the | David Shaw | 2006-03-14 | 4 | -31/+61 | |
| | | | | | | | | | | | | same API as the other auto-key-locate fetchers. * getkey.c (get_pubkey_byname): Use the fingerprint of the key that we actually fetched. This helps prevent problems where the key that we fetched doesn't have the same name that we used to fetch it. In the case of CERT and PKA, this is an actual security requirement as the URL might point to a key put in by an attacker. By forcing the use of the fingerprint, we won't use the attacker's key here. | |||||
* | * keyserver-internal.h, keyserver.c (keyserver_spawn, keyserver_work, | David Shaw | 2006-03-14 | 4 | -26/+40 | |
| | | | | | | keyserver_import_cert, keyserver_import_name, keyserver_import_ldap): Pass fingerprint info through. | |||||
* | * main.h, import.c (import_one): Optionally return the fingerprint of | David Shaw | 2006-03-14 | 4 | -26/+43 | |
| | | | | | | the key being imported. (import_keys_internal, import_keys_stream, import): Change all callers. | |||||
* | * sig-check.c (signature_check2): Print the backsig warning when there | David Shaw | 2006-03-12 | 3 | -8/+20 | |
| | | | | | | | | | is no backsig present. Give a URL for more information. * keyedit.c (menu_backsign): Small tweak to work properly with keys originally generated with older GnuPGs that included comments in the secret keys. | |||||
* | * samplekeys.asc: Update 99242560 to have a signing subkey backsig. | David Shaw | 2006-03-11 | 2 | -1840/+1873 | |
| | ||||||
* | * gpg.sgml: Clarify new notation delete feature. | David Shaw | 2006-03-09 | 2 | -2/+8 | |
| | ||||||
* | * build-packet.c (string_to_notation): Add ability to indicate a notation | David Shaw | 2006-03-09 | 3 | -39/+85 | |
| | | | | | | | | to be deleted with a '-' prefix. * keyedit.c (menu_set_notation): Use it here to allow deleting a notation marked with '-'. This works with either "-notation" or "-notation=value". | |||||
* | keep on walking towards rc3 | Werner Koch | 2006-03-09 | 29 | -15107/+15974 | |
| | ||||||
* | Updatedgnupg-1.4.3rc2 | Werner Koch | 2006-03-09 | 3 | -68/+108 | |
| | ||||||
* | Preparing for an RC23 | Werner Koch | 2006-03-09 | 6 | -18/+29 | |
| | ||||||
* | * gpg.sgml: Document "notation". | David Shaw | 2006-03-09 | 2 | -6/+17 | |
| | ||||||
* | * keyedit.c (menu_set_notation): New function to set notations on | David Shaw | 2006-03-09 | 2 | -4/+250 | |
| | | | | | | | self-signatures. (keyedit_menu): Call it here. (tty_print_notations): Helper. (show_prefs): Show notations in "showpref". | |||||
* | * mainproc.c (get_pka_address), keylist.c (show_notation): Remove | David Shaw | 2006-03-09 | 3 | -92/+64 | |
| | | | | | duplicate code by using notation functions. | |||||
* | * argparse.c (default_strusage): Update copyright year to 2006. | David Shaw | 2006-03-09 | 2 | -2/+6 | |
| | ||||||
* | * packet.h, build-packet.c (sig_to_notation), keygen.c | David Shaw | 2006-03-09 | 4 | -8/+20 | |
| | | | | | | (keygen_add_notations): Provide printable text for non-human-readable notation values. | |||||
* | * packet.h, build-packet.c (sig_to_notation), keygen.c | David Shaw | 2006-03-08 | 4 | -6/+15 | |
| | | | | | | (keygen_add_notations): Tweak to handle non-human-readable notation values. | |||||
* | * options.h, sign.c (mk_notation_policy_etc), gpg.c (add_notation_data): | David Shaw | 2006-03-08 | 9 | -117/+275 | |
| | | | | | | | | | | Use it here for the various notation commands. * packet.h, main.h, keygen.c (keygen_add_notations), build-packet.c (string_to_notation, sig_to_notation) (free_notation): New "one stop shopping" functions to handle notations and start removing some code duplication. | |||||
* | * options.h, mainproc.c (check_sig_and_print), gpg.c (main): | David Shaw | 2006-03-08 | 6 | -14/+27 | |
| | | | | | | | | | pka-lookups, not pka-lookup. * options.h, gpg.c (main), keyedit.c [cmds], sig-check.c (signature_check2): Rename "backsign" to "cross-certify" as a more accurate name. | |||||
* | * NEWS: Note CERT retrieval. Tweak PKA and backsig language to match | David Shaw | 2006-03-08 | 2 | -14/+17 | |
| | | | | | current code. | |||||
* | * gpg.sgml: Rename backsigs to cross-certification (backsigs is just | David Shaw | 2006-03-07 | 2 | -17/+28 | |
| | | | | | shorthand). Document max-cert-size. | |||||
* | * gpg.sgml: Document new way of enabling the PKA functions. Some minor | David Shaw | 2006-03-07 | 2 | -79/+71 | |
| | | | | | other cleanups. | |||||
* | * options.h, gpg.c (main, parse_trust_model), pkclist.c | David Shaw | 2006-03-07 | 6 | -50/+23 | |
| | | | | | | | (check_signatures_trust), mainproc.c (check_sig_and_print, pka_uri_from_sig), trustdb.c (init_trustdb): Some tweaks to PKA so that it is a verify-option now. | |||||
* | * NEWS: Note --auto-key-locate and that keyservers can handle binary data | David Shaw | 2006-03-07 | 2 | -5/+20 | |
| | | | | | now. | |||||
* | More tests added; make distcheck works | Werner Koch | 2006-03-07 | 33 | -7805/+8146 | |
| | ||||||
* | * gpg.sgml: Document --auto-key-locate. | David Shaw | 2006-03-07 | 2 | -5/+47 | |
| | ||||||
* | * sign.c (make_keysig_packet): Don't use MD5 for a RSA_S key as that | David Shaw | 2006-03-07 | 2 | -3/+5 | |
| | | | | | is not a PGP 2.x algorithm. | |||||
* | * mainproc.c (proc_compressed): "Uncompressed" is not a valid compression | David Shaw | 2006-03-06 | 2 | -1/+8 | |
| | | | | | algorithm. | |||||
* | Stricter test of allowed signature packet compositions. | Werner Koch | 2006-03-06 | 7 | -123/+299 | |
| | | | | | There is still one problem to solve. | |||||
* | Fixed problem with PGP2 style signatures and mutilple plaintext data | Werner Koch | 2006-03-06 | 5 | -40/+74 | |
| | ||||||
* | Replaced an assert and fixed batch mode issue in cardglue. | Werner Koch | 2006-03-05 | 6 | -14/+43 | |
| | ||||||
* | * gpgkeys_ldap.c (main): Fix build problem with non-OpenLDAP LDAP | David Shaw | 2006-03-03 | 2 | -5/+15 | |
| | | | | | libraries that have TLS. | |||||
* | * getkey.c (parse_auto_key_locate): Error if the user selects "cert" or | David Shaw | 2006-03-01 | 3 | -10/+20 | |
| | | | | | | | | | "pka" when those features are disabled. * misc.c (has_invalid_email_chars): Fix some C syntax that broke the compilers on SGI IRIX MIPS and Compaq/DEC OSF/1 Alpha. Noted by Nelson H. F. Beebe. | |||||
* | * configure.ac: Fix accidental enabling of SHA-384/512. Noted by Nelson | David Shaw | 2006-03-01 | 2 | -1/+6 | |
| | | | | | H. F. Beebe. | |||||
* | * options.skel: Document auto-key-locate and give a pointer to Simon | David Shaw | 2006-02-27 | 2 | -0/+29 | |
| | | | | | Josefsson's page for CERT. | |||||
* | * gpg.sgml: Document new --keyserver syntax. | David Shaw | 2006-02-25 | 2 | -9/+17 | |
| | ||||||
* | * keydb.h, getkey.c (release_akl), gpg.c (main): Add | David Shaw | 2006-02-24 | 8 | -27/+114 | |
| | | | | | | | | | | | | | | | --no-auto-key-locate. * options.h, gpg.c (main): Keep track of each keyserver registered so we can match on them later. * keyserver-internal.h, keyserver.c (cmp_keyserver_spec, keyserver_match), gpgv.c: New. Find a keyserver that matches ours and return its spec. * getkey.c (get_pubkey_byname): Use it here to get the per-keyserver options from an earlier keyserver. | |||||
* | * keyserver.c (parse_keyserver_options): Only change max_cert if it is | David Shaw | 2006-02-24 | 2 | -1/+4 | |
| | | | | | used. | |||||
* | * options.c, gpg.c (main), keyserver.c (keyserver_spawn): No special | David Shaw | 2006-02-23 | 4 | -26/+19 | |
| | | | | | | treatment of include-revoked, include-subkeys, and try-dns-srv. These are keyserver features, and GPG shouldn't get involved here. | |||||
* | * ksutil.c (init_ks_options): Default include-revoked and include-subkeys | David Shaw | 2006-02-23 | 2 | -0/+7 | |
| | | | | | to on, as gpg isn't doing this any longer. | |||||
* | * keyserver.c (parse_keyserver_uri, add_canonical_option): Always append | David Shaw | 2006-02-23 | 2 | -3/+7 | |
| | | | | | options to the list, as ordering may be significant to the user. | |||||
* | * gpg.c (add_notation_data): Fix reversed logic for isascii check when | David Shaw | 2006-02-23 | 2 | -1/+4 | |
| | | | | | adding notations. Noted by Christian Biere. | |||||
* | * options.h, keyserver.c (add_canonical_option): New. | David Shaw | 2006-02-23 | 4 | -20/+54 | |
| | | | | | | | (parse_keyserver_options): Moved from here. (parse_keyserver_uri): Use it here so each keyserver can have some private options in addition to the main keyserver-options (e.g. per-keyserver auth). | |||||
* | * options.h, keyserver-internal.h, keyserver.c (keyserver_import_name), | David Shaw | 2006-02-22 | 6 | -9/+45 | |
| | | | | | | getkey.c (free_akl, parse_auto_key_locate, get_pubkey_byname): The obvious next step: allow arbitrary keyservers in the auto-key-locate list. | |||||
* | * gpgkeys_hkp.c (get_name): A GETNAME query turns exact=on to cut down on | David Shaw | 2006-02-22 | 2 | -0/+8 | |
| | | | | | odd matches. | |||||
* | * options.h, keyserver.c (parse_keyserver_options): Remove | David Shaw | 2006-02-22 | 3 | -7/+9 | |
| | | | | | | auto-cert-retrieve as it is no longer meaningful. Add max-cert-size to allow users to pick a max key size retrieved via CERT. | |||||
* | * options.h, gpg.c (main), mainproc.c (check_sig_and_print), keyserver.c | David Shaw | 2006-02-22 | 5 | -10/+19 | |
| | | | | | | (keyserver_opts): Rename auto-pka-retrieve to honor-pka-record to be consistent with honor-keyserver-url. | |||||
* | * options.h, keydb.h, g10.c (main), getkey.c (parse_auto_key_locate): | David Shaw | 2006-02-22 | 5 | -64/+139 | |
| | | | | | | Parse a list of key access methods. (get_pubkey_byname): Walk the list here to try and retrieve keys we don't have locally. |