2015-02-11 19:48:21 +01:00
|
|
|
Noteworthy changes in version 2.1.3 (unreleased)
|
|
|
|
------------------------------------------------
|
|
|
|
|
2015-02-05 13:58:50 +01:00
|
|
|
* dirmngr: extra-certs and trusted-certs are now always loaded from
|
|
|
|
the sysconfig dir instead of the homedir.
|
|
|
|
|
2015-02-11 19:48:21 +01:00
|
|
|
|
2015-02-11 19:22:25 +01:00
|
|
|
Noteworthy changes in version 2.1.2 (2015-02-11)
|
2014-12-16 17:00:45 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2015-01-21 11:31:20 +01:00
|
|
|
* gpg: The parameter 'Passphrase' for batch key generation works
|
|
|
|
again.
|
|
|
|
|
2015-01-21 12:42:14 +01:00
|
|
|
* gpg: Using a passphrase option in batch mode now has the expected
|
|
|
|
effect on --quick-gen-key.
|
|
|
|
|
2015-02-11 19:22:25 +01:00
|
|
|
* gpg: Improved reporting of unsupported PGP-2 keys.
|
|
|
|
|
|
|
|
* gpg: Added support for algo names when generating keys using
|
|
|
|
--command-fd.
|
|
|
|
|
|
|
|
* gpg: Fixed DoS based on bogus and overlong key packets.
|
|
|
|
|
|
|
|
* agent: When setting --default-cache-ttl the value
|
|
|
|
for --max-cache-ttl is adjusted to be not lower than the former.
|
|
|
|
|
|
|
|
* agent: Fixed problems with the new --extra-socket.
|
|
|
|
|
|
|
|
* agent: Made --allow-loopback-pinentry changeable with gpgconf.
|
|
|
|
|
|
|
|
* agent: Fixed importing of unprotected openpgp keys.
|
|
|
|
|
|
|
|
* agent: Now tries to use a fallback pinentry if the standard
|
|
|
|
pinentry is not installed.
|
|
|
|
|
|
|
|
* scd: Added support for ECDH.
|
|
|
|
|
|
|
|
* Fixed several bugs related to bogus keyrings and improved some
|
|
|
|
other code.
|
|
|
|
|
2014-12-19 13:28:14 +01:00
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
Noteworthy changes in version 2.1.1 (2014-12-16)
|
2014-11-05 16:46:52 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2014-11-21 21:38:00 +01:00
|
|
|
* gpg: Detect faulty use of --verify on detached signatures.
|
|
|
|
|
|
|
|
* gpg: New import option "keep-ownertrust".
|
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* gpg: New sub-command "factory-reset" for --card-edit.
|
|
|
|
|
|
|
|
* gpg: A stub key for smartcards is now created by --card-status.
|
|
|
|
|
2014-11-21 21:38:00 +01:00
|
|
|
* gpg: Fixed regression in --refresh-keys.
|
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* gpg: Fixed regresion in %g and %p codes for --sig-notation.
|
|
|
|
|
2014-11-21 21:38:00 +01:00
|
|
|
* gpg: Fixed best matching hash algo detection for ECDSA and EdDSA.
|
|
|
|
|
|
|
|
* gpg: Improved perceived speed of secret key listisngs.
|
|
|
|
|
|
|
|
* gpg: Print number of skipped PGP-2 keys on import.
|
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* gpg: Removed the option aliases --throw-keyid and --notation-data;
|
|
|
|
use --throw-keyids and --set-notation instead.
|
|
|
|
|
|
|
|
* gpg: New import option "keep-ownertrust".
|
|
|
|
|
|
|
|
* gpg: Skip too large keys during import.
|
|
|
|
|
|
|
|
* gpg,gpgsm: New option --no-autostart to avoid starting gpg-agent or
|
|
|
|
dirmngr.
|
|
|
|
|
|
|
|
* gpg-agent: New option --extra-socket to provide a restricted
|
|
|
|
command set for use with remote clients.
|
|
|
|
|
2014-11-21 21:38:00 +01:00
|
|
|
* gpgconf --kill does not anymore start a service only to kill it.
|
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* gpg-pconnect-agent: Add convenience option --uiserver.
|
|
|
|
|
2014-11-21 21:38:00 +01:00
|
|
|
* Fixed keyserver access for Windows.
|
|
|
|
|
|
|
|
* Fixed build problems on Mac OS X
|
|
|
|
|
|
|
|
* The Windows installer does now install development files
|
|
|
|
|
|
|
|
* More translations (but most of them are not complete).
|
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* To support remotely mounted home directories, the IPC sockets may
|
|
|
|
now be redirected. This feature requires Libassuan 2.2.0.
|
2014-12-03 11:28:10 +01:00
|
|
|
|
2014-12-16 15:53:28 +01:00
|
|
|
* Improved portability and the usual bunch of bug fixes.
|
2014-12-04 10:53:10 +01:00
|
|
|
|
2014-11-05 16:46:52 +01:00
|
|
|
|
2014-11-04 16:28:03 +01:00
|
|
|
Noteworthy changes in version 2.1.0 (2014-11-06)
|
2014-10-03 20:19:08 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2014-11-04 16:28:03 +01:00
|
|
|
This release introduces a lot of changes. Most of them are internal
|
|
|
|
and thus not user visible. However, some long standing behavior has
|
|
|
|
slightly changed and it is strongly suggested that an existing
|
|
|
|
"~/.gnupg" directory is backed up before this version is used.
|
|
|
|
|
|
|
|
A verbose description of the major new features and changes can be
|
|
|
|
found in the file doc/whats-new-in-2.1.txt.
|
2014-10-26 20:07:16 +01:00
|
|
|
|
2014-10-26 12:48:34 +01:00
|
|
|
* gpg: All support for v3 (PGP 2) keys has been dropped. All
|
2014-10-31 10:29:02 +01:00
|
|
|
signatures are now created as v4 signatures. v3 keys will be
|
|
|
|
removed from the keyring.
|
2014-10-26 12:48:34 +01:00
|
|
|
|
|
|
|
* gpg: With pinentry-0.9.0 the passphrase "enter again" prompt shows
|
|
|
|
up in the same window as the "new passphrase" prompt.
|
|
|
|
|
|
|
|
* gpg: Allow importing keys with duplicated long key ids.
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* dirmngr: May now be build without support for LDAP.
|
2014-10-17 15:59:45 +02:00
|
|
|
|
2014-10-03 20:19:08 +02:00
|
|
|
* For a complete list of changes see the lists of changes for the
|
2014-10-26 20:07:16 +01:00
|
|
|
2.1.0 beta versions below. Note that all relevant fixes from
|
|
|
|
versions 2.0.14 to 2.0.26 are also applied to this version.
|
2014-10-03 20:19:08 +02:00
|
|
|
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0-beta864 (2014-10-03)]
|
2014-09-18 16:00:34 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Removed the GPG_AGENT_INFO related code. GnuPG does now
|
|
|
|
always use a fixed socket name in its home directory.
|
2014-10-03 15:45:32 +02:00
|
|
|
|
|
|
|
* gpg: Renamed --gen-key to --full-gen-key and re-added a --gen-key
|
2014-10-26 20:07:16 +01:00
|
|
|
command with less choices.
|
2014-10-03 15:45:32 +02:00
|
|
|
|
|
|
|
* gpg: Use SHA-256 for all signature types also on RSA keys.
|
|
|
|
|
|
|
|
* gpg: Default keyring is now created with a .kbx suffix.
|
|
|
|
|
2014-10-03 20:19:08 +02:00
|
|
|
* gpg: Add a shortcut to the key capabilies menu (e.g. "=e" sets the
|
2014-10-03 15:45:32 +02:00
|
|
|
encryption capabilities).
|
|
|
|
|
|
|
|
* gpg: Fixed obsolete options parsing.
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* Further improvements for the alternative speedo build system.
|
2014-10-03 15:45:32 +02:00
|
|
|
|
2014-09-18 16:00:34 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0-beta834 (2014-09-18)]
|
2014-08-14 17:15:04 +02:00
|
|
|
|
2014-09-18 16:00:34 +02:00
|
|
|
* gpg: Improved passphrase caching.
|
|
|
|
|
|
|
|
* gpg: Switched to algorithm number 22 for EdDSA.
|
|
|
|
|
|
|
|
* gpg: Removed CAST5 from the default preferences.
|
|
|
|
|
|
|
|
* gpg: Order SHA-1 last in the hash preferences.
|
|
|
|
|
|
|
|
* gpg: Changed default cipher for --symmetric to AES-128.
|
|
|
|
|
|
|
|
* gpg: Fixed export of ECC keys and import of EdDSA keys.
|
|
|
|
|
|
|
|
* dirmngr: Fixed the KS_FETCH command.
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* The speedo build system now downloads related packages and works
|
|
|
|
for non-Windows platforms.
|
2014-09-18 16:00:34 +02:00
|
|
|
|
2014-08-14 17:15:04 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0-beta783 (2014-08-14)]
|
2014-06-25 14:33:34 +02:00
|
|
|
|
2014-08-14 17:08:03 +02:00
|
|
|
* gpg: Add command --quick-gen-key.
|
|
|
|
|
|
|
|
* gpg: Make --quick-sign-key promote local key signatures.
|
|
|
|
|
2014-08-14 17:15:04 +02:00
|
|
|
* gpg: Added "show-usage" sub-option to --list-options.
|
2014-08-14 17:08:03 +02:00
|
|
|
|
|
|
|
* gpg: Screen keyserver responses to avoid importing unwanted keys
|
|
|
|
from rogue servers.
|
|
|
|
|
2014-08-12 10:36:30 +02:00
|
|
|
* gpg: Removed the option --pgp2 and --rfc1991 and the ability to
|
|
|
|
create PGP-2 compatible messages.
|
|
|
|
|
2014-08-14 17:08:03 +02:00
|
|
|
* gpg: Removed options --compress-keys and --compress-sigs.
|
|
|
|
|
|
|
|
* gpg: Cap attribute packets at 16MB.
|
|
|
|
|
|
|
|
* gpg: Improved output of --list-packets.
|
|
|
|
|
|
|
|
* gpg: Make with-colons output of --search-keys work again.
|
|
|
|
|
|
|
|
* gpgsm: Auto-create the ".gnupg" directory like gpg does.
|
|
|
|
|
|
|
|
* agent: Fold new passphrase warning prompts into one.
|
|
|
|
|
|
|
|
* scdaemon: Add support for the Smartcard-HSM card.
|
|
|
|
|
|
|
|
* scdaemon: Remove the use of the pcsc-wrapper.
|
|
|
|
|
2014-06-25 14:33:34 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0-beta751 (2014-07-03)]
|
2014-06-25 14:33:34 +02:00
|
|
|
|
|
|
|
* gpg: Create revocation certificates during key generation.
|
|
|
|
|
|
|
|
* gpg: Create exported secret keys and revocation certifciates with
|
|
|
|
mode 0700
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: The validity of user ids is now shown by default. To revert
|
|
|
|
this add "list-options no-show-uid-validity" to gpg.conf.
|
|
|
|
|
|
|
|
* gpg: Make export of secret keys work again.
|
|
|
|
|
2014-06-25 14:33:34 +02:00
|
|
|
* gpg: The output of --list-packets does now print the offset of the
|
|
|
|
packet and information about the packet header.
|
|
|
|
|
|
|
|
* gpg: Avoid DoS due to garbled compressed data packets. [CVE-2014-4617]
|
|
|
|
|
|
|
|
* gpg: Print more specific reason codes with the INV_RECP status.
|
|
|
|
|
|
|
|
* gpg: Cap RSA and Elgamal keysize at 4096 bit also for unattended
|
|
|
|
key generation.
|
|
|
|
|
|
|
|
* scdaemon: Support reader Gemalto IDBridge CT30 and pinpad of SCT
|
|
|
|
cyberJack go.
|
|
|
|
|
|
|
|
* The speedo build system has been improved. It is now also possible
|
|
|
|
to build a partly working installer for Windows.
|
2014-06-05 17:05:33 +02:00
|
|
|
|
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0-beta442 (2014-06-05)]
|
|
|
|
|
|
|
|
* gpg: Changed the format of key listings. To revert to the old
|
|
|
|
format the option --legacy-list-mode is available.
|
2011-12-20 17:10:28 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Add experimental signature support using curve Ed25519 and
|
|
|
|
with a patched Libgcrypt also encryption support with Curve25519.
|
2014-10-26 20:07:16 +01:00
|
|
|
[Update: this encryption support has been removed from 2.1.0 until
|
|
|
|
we have agreed on a suitable format.]
|
2014-06-05 16:20:44 +02:00
|
|
|
|
|
|
|
* gpg: Allow use of Brainpool curves.
|
|
|
|
|
|
|
|
* gpg: Accepts a space separated fingerprint as user ID. This
|
2012-01-06 13:33:10 +01:00
|
|
|
allows to copy and paste the fingerprint from the key listing.
|
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: The hash algorithm is now printed for signature records in key
|
|
|
|
listings.
|
2012-01-25 15:48:01 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Reject signatures made using the MD5 hash algorithm unless the
|
|
|
|
new option --allow-weak-digest-algos or --pgp2 are given.
|
2013-07-03 15:20:25 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Print a warning if the Gnome-Keyring-Daemon intercepts the
|
|
|
|
communication with the gpg-agent.
|
2013-07-03 15:20:25 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: New option --pinentry-mode.
|
2012-02-07 10:20:12 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Fixed decryption using an OpenPGP card.
|
2012-05-24 10:13:39 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Fixed bug with deeply nested compressed packets.
|
2013-02-07 20:37:58 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Only the major version number is by default included in the
|
|
|
|
armored output.
|
scd: Rename 'keypad' to 'pinpad'.
* NEWS: Mention scd changes.
* agent/divert-scd.c (getpin_cb): Change message.
* agent/call-scd.c (inq_needpin): Change the protocol to
POPUPPINPADPROMPT and DISMISSPINPADPROMPT.
* scd/command.c (pin_cb): Likewise.
* scd/apdu.c (struct reader_table_s): Rename member functions.
(check_pcsc_pinpad, pcsc_pinpad_verify, pcsc_pinpad_modify,
check_ccid_pinpad, ccid_pinpad_operation, apdu_check_pinpad
apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/apdu.h (SW_HOST_NO_PINPAD, apdu_check_pinpad)
(apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/iso7816.h (iso7816_check_pinpad): Rename.
* scd/iso7816.c (map_sw): Use SW_HOST_NO_PINPAD.
(iso7816_check_pinpad): Rename.
(iso7816_verify_kp, iso7816_change_reference_data_kp): Follow
the change.
* scd/ccid-driver.h (CCID_DRIVER_ERR_NO_PINPAD): Rename.
* scd/ccid-driver.c (ccid_transceive_secure): Use it.
* scd/app-dinsig.c (verify_pin): Follow the change.
* scd/app-nks.c (verify_pin): Follow the change.
* scd/app-openpgp.c (check_pinpad_request): Rename.
(parse_login_data, verify_a_chv, verify_chv3, do_change_pin): Follow
the change.
* scd/scdaemon.c (oDisablePinpad, oEnablePinpadVarlen): Rename.
* scd/scdaemon.h (opt): Rename to disable_pinpad,
enable_pinpad_varlen.
* tools/gpgconf-comp.c (gc_options_scdaemon): Rename to
disable-pinpad.
2013-02-07 02:07:51 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Do not create a trustdb file if --trust-model=always is used.
|
2014-06-03 21:35:59 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: Protect against rogue keyservers sending secret keys.
|
scd: Rename 'keypad' to 'pinpad'.
* NEWS: Mention scd changes.
* agent/divert-scd.c (getpin_cb): Change message.
* agent/call-scd.c (inq_needpin): Change the protocol to
POPUPPINPADPROMPT and DISMISSPINPADPROMPT.
* scd/command.c (pin_cb): Likewise.
* scd/apdu.c (struct reader_table_s): Rename member functions.
(check_pcsc_pinpad, pcsc_pinpad_verify, pcsc_pinpad_modify,
check_ccid_pinpad, ccid_pinpad_operation, apdu_check_pinpad
apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/apdu.h (SW_HOST_NO_PINPAD, apdu_check_pinpad)
(apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/iso7816.h (iso7816_check_pinpad): Rename.
* scd/iso7816.c (map_sw): Use SW_HOST_NO_PINPAD.
(iso7816_check_pinpad): Rename.
(iso7816_verify_kp, iso7816_change_reference_data_kp): Follow
the change.
* scd/ccid-driver.h (CCID_DRIVER_ERR_NO_PINPAD): Rename.
* scd/ccid-driver.c (ccid_transceive_secure): Use it.
* scd/app-dinsig.c (verify_pin): Follow the change.
* scd/app-nks.c (verify_pin): Follow the change.
* scd/app-openpgp.c (check_pinpad_request): Rename.
(parse_login_data, verify_a_chv, verify_chv3, do_change_pin): Follow
the change.
* scd/scdaemon.c (oDisablePinpad, oEnablePinpadVarlen): Rename.
* scd/scdaemon.h (opt): Rename to disable_pinpad,
enable_pinpad_varlen.
* tools/gpgconf-comp.c (gc_options_scdaemon): Rename to
disable-pinpad.
2013-02-07 02:07:51 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: The format of the fallback key listing ("gpg KEYFILE") is now
|
|
|
|
more aligned to the regular key listing ("gpg -k").
|
scd: Rename 'keypad' to 'pinpad'.
* NEWS: Mention scd changes.
* agent/divert-scd.c (getpin_cb): Change message.
* agent/call-scd.c (inq_needpin): Change the protocol to
POPUPPINPADPROMPT and DISMISSPINPADPROMPT.
* scd/command.c (pin_cb): Likewise.
* scd/apdu.c (struct reader_table_s): Rename member functions.
(check_pcsc_pinpad, pcsc_pinpad_verify, pcsc_pinpad_modify,
check_ccid_pinpad, ccid_pinpad_operation, apdu_check_pinpad
apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/apdu.h (SW_HOST_NO_PINPAD, apdu_check_pinpad)
(apdu_pinpad_verify, apdu_pinpad_modify): Rename.
* scd/iso7816.h (iso7816_check_pinpad): Rename.
* scd/iso7816.c (map_sw): Use SW_HOST_NO_PINPAD.
(iso7816_check_pinpad): Rename.
(iso7816_verify_kp, iso7816_change_reference_data_kp): Follow
the change.
* scd/ccid-driver.h (CCID_DRIVER_ERR_NO_PINPAD): Rename.
* scd/ccid-driver.c (ccid_transceive_secure): Use it.
* scd/app-dinsig.c (verify_pin): Follow the change.
* scd/app-nks.c (verify_pin): Follow the change.
* scd/app-openpgp.c (check_pinpad_request): Rename.
(parse_login_data, verify_a_chv, verify_chv3, do_change_pin): Follow
the change.
* scd/scdaemon.c (oDisablePinpad, oEnablePinpadVarlen): Rename.
* scd/scdaemon.h (opt): Rename to disable_pinpad,
enable_pinpad_varlen.
* tools/gpgconf-comp.c (gc_options_scdaemon): Rename to
disable-pinpad.
2013-02-07 02:07:51 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* gpg: The option--show-session-key prints its output now before the
|
|
|
|
decryption of the bulk message starts.
|
|
|
|
|
|
|
|
* gpg: New %U expando for the photo viewer.
|
|
|
|
|
|
|
|
* gpg,gpgsm: New option --with-secret.
|
|
|
|
|
|
|
|
* gpgsm: By default the users are now asked via the Pinentry whether
|
|
|
|
they trust an X.509 root key. To prohibit interactive marking of
|
|
|
|
such keys, the new option --no-allow-mark-trusted may be used.
|
|
|
|
|
|
|
|
* gpgsm: New commands to export a secret RSA key in PKCS#1 or PKCS#8
|
|
|
|
format.
|
|
|
|
|
|
|
|
* gpgsm: Improved handling of re-issued CA certificates.
|
2013-08-01 11:20:48 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* agent: The included ssh agent does now support ECDSA keys.
|
2013-08-26 17:29:54 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* agent: New option --enable-putty-support to allow gpg-agent on
|
|
|
|
Windows to act as a Pageant replacement with full smartcard support.
|
2013-10-02 09:11:43 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* scdaemon: New option --enable-pinpad-varlen.
|
2013-11-27 09:20:02 +01:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* scdaemon: Various fixes for pinpad equipped card readers.
|
2013-10-11 09:25:58 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* scdaemon: Rename option --disable-pinpad (was --disable-keypad).
|
|
|
|
|
|
|
|
* scdaemon: Better support fo CCID readers. Now, internal CCID
|
|
|
|
driver supports readers with no auto configuration feature.
|
|
|
|
|
|
|
|
* dirmngr: Removed support for the original HKP keyserver which is
|
|
|
|
not anymore used by any site.
|
|
|
|
|
|
|
|
* dirmngr: Improved support for keyserver pools.
|
|
|
|
|
|
|
|
* tools: New option --dirmngr for gpg-connect-agent.
|
|
|
|
|
|
|
|
* The GNU Pth library has been replaced by the new nPth library.
|
|
|
|
|
|
|
|
* Support installation as portable application under Windows.
|
2013-10-11 09:25:58 +02:00
|
|
|
|
2014-06-05 16:20:44 +02:00
|
|
|
* All kind of other improvements - see the git log.
|
2014-06-03 18:57:33 +02:00
|
|
|
|
2011-12-20 17:10:28 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0beta3 (2011-12-20)]
|
2011-03-08 14:00:04 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Fixed regression in the secret key export function.
|
2011-06-16 14:27:33 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Allow generation of card keys up to 4096 bit.
|
2011-04-26 20:33:46 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: Preliminary support for the validation model "steed".
|
2011-07-20 20:49:41 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: Improved certificate creation.
|
2011-08-10 11:47:04 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: Support the SSH confirm flag.
|
2011-12-14 15:42:28 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: New option to select a passphrase mode. The loopback
|
|
|
|
mode may be used to bypass Pinentry.
|
2011-12-14 15:42:28 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: The Assuan commands KILLAGENT and KILLSCD are working again.
|
2011-12-14 15:42:28 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* scdaemon: Does not anymore block after changing a card (regression
|
|
|
|
fix).
|
2011-12-14 15:42:28 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* tools: gpg-connect-agent does now proberly display the help output
|
|
|
|
for "SCD HELP" commands.
|
2011-12-14 15:42:28 +01:00
|
|
|
|
2011-03-08 14:00:04 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0beta2 (2011-03-08)]
|
2010-10-27 09:37:52 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: ECC support as described by draft-jivsov-openpgp-ecc-06.txt
|
|
|
|
[Update: now known as RFC-6637].
|
2010-10-27 09:37:52 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Print "AES128" instead of "AES". This change introduces a
|
|
|
|
little incompatibility for tools using "gpg --list-config". We
|
|
|
|
hope that these tools are written robust enough to accept this new
|
|
|
|
algorithm name as well.
|
2010-11-11 16:07:37 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: New feature to create certificates from a parameter file.
|
|
|
|
Add prompt to the --gen-key UI to create self-signed certificates.
|
2010-12-02 16:49:02 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: TMPDIR is now also honored when creating a socket using
|
|
|
|
the --no-standard-socket option and with symcryptrun's temp files.
|
2010-12-14 20:17:58 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* scdaemon: Fixed a bug where scdaemon sends a signal to gpg-agent
|
|
|
|
running in non-daemon mode.
|
|
|
|
|
|
|
|
* dirmngr: Fixed CRL loading under W32 (bug#1010).
|
2011-01-10 11:37:57 +01:00
|
|
|
|
2011-01-20 15:11:25 +01:00
|
|
|
* Dirmngr has taken over the function of the keyserver helpers. Thus
|
|
|
|
we now have a specified direct interface to keyservers via Dirmngr.
|
2011-03-01 14:42:56 +01:00
|
|
|
LDAP, DNS and mail backends are not yet implemented.
|
2011-01-20 15:11:25 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* Fixed TTY management for pinentries and session variable update
|
|
|
|
problem.
|
2011-03-01 14:42:56 +01:00
|
|
|
|
2010-10-27 09:37:52 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
[Noteworthy changes in version 2.1.0beta1 (2010-10-26)]
|
2009-09-04 19:52:40 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: secring.gpg is not anymore used but all secret key operations
|
|
|
|
are delegated to gpg-agent. The import command moves secret keys
|
|
|
|
to the agent.
|
2009-10-13 21:17:24 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: The OpenPGP import command is now able to merge secret keys.
|
2009-12-02 19:33:59 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Encrypted OpenPGP messages with trailing data (e.g. other
|
|
|
|
OpenPGP packets) are now correctly parsed.
|
2009-12-02 19:33:59 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Given sufficient permissions Dirmngr is started automagically.
|
2009-12-04 20:47:54 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Fixed output of "gpgconf --check-options".
|
2009-12-02 19:33:59 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Removed options --export-options(export-secret-subkey-passwd)
|
|
|
|
and --simple-sk-checksum.
|
2009-12-07 16:52:27 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: New options --try-secret-key.
|
2009-12-10 14:00:30 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpg: Support DNS lookups for SRV, PKA and CERT on W32.
|
2009-12-14 21:12:56 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: The --audit-log feature is now more complete.
|
2010-02-26 19:44:36 +01:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: The default for --include-cert is now to include all
|
|
|
|
certificates in the chain except for the root certificate.
|
2010-05-04 17:21:47 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* gpgsm: New option --ignore-cert-extension.
|
2010-08-16 13:03:43 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* g13: The G13 tool for disk encryption key management has been
|
|
|
|
added.
|
2010-06-09 18:53:51 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: If the agent's --use-standard-socket option is active, all
|
|
|
|
tools try to start and daemonize the agent on the fly. In the past
|
|
|
|
this was only supported on W32; on non-W32 systems the new
|
|
|
|
configure option --disable-standard-socket may now be used to
|
|
|
|
disable this new default.
|
2010-08-20 14:18:38 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* agent: New and changed passphrases are now created with an
|
|
|
|
iteration count requiring about 100ms of CPU work.
|
2010-08-31 17:58:39 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* dirmngr: Dirmngr is now a part of this package. It is now also
|
|
|
|
expected to run as a system service and the configuration
|
|
|
|
directories are changed to the GnuPG name space. [Update: 2.1.0
|
|
|
|
starts dirmngr on demand as user daemon.]
|
2010-09-02 17:11:51 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* Support for Windows CE. [Update: This has not been tested for the
|
|
|
|
2.1.0 release]
|
2010-10-01 22:33:53 +02:00
|
|
|
|
2014-10-26 20:07:16 +01:00
|
|
|
* Numerical values may now be used as an alternative to the
|
|
|
|
debug-level keywords.
|
2010-10-13 17:57:08 +02:00
|
|
|
|
2009-09-04 19:52:40 +02:00
|
|
|
|
2009-09-04 15:38:16 +02:00
|
|
|
Noteworthy changes in version 2.0.13 (2009-09-04)
|
2009-06-17 13:57:24 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2009-07-09 10:52:31 +02:00
|
|
|
* GPG now generates 2048 bit RSA keys by default. The default hash
|
|
|
|
algorithm preferences has changed to prefer SHA-256 over SHA-1.
|
|
|
|
2048 bit DSA keys are now generated to use a 256 bit hash algorithm
|
|
|
|
|
2009-07-07 12:02:41 +02:00
|
|
|
* The envvars XMODIFIERS, GTK_IM_MODULE and QT_IM_MODULE are now
|
|
|
|
passed to the Pinentry to make SCIM work.
|
2009-07-01 20:30:33 +02:00
|
|
|
|
2009-07-09 10:52:31 +02:00
|
|
|
* The GPGSM command --gen-key features a --batch mode and implements
|
|
|
|
all features of gpgsm-gencert.sh in standard mode.
|
2009-06-17 13:57:24 +02:00
|
|
|
|
2009-07-09 10:52:31 +02:00
|
|
|
* New option --re-import for GPGSM's IMPORT server command.
|
2009-07-07 18:52:12 +02:00
|
|
|
|
2009-07-09 16:54:18 +02:00
|
|
|
* Enhanced writing of existing keys to OpenPGP v2 cards.
|
|
|
|
|
|
|
|
* Add hack to the internal CCID driver to allow the use of some
|
|
|
|
Omnikey based card readers with 2048 bit keys.
|
|
|
|
|
2009-08-11 12:56:44 +02:00
|
|
|
* GPG now repeatly asks the user to insert the requested OpenPGP
|
|
|
|
card. This can be disabled with --limit-card-insert-tries=1.
|
|
|
|
|
2009-07-07 12:02:41 +02:00
|
|
|
* Minor bug fixes.
|
|
|
|
|
2009-06-17 13:57:24 +02:00
|
|
|
|
2009-06-17 13:18:26 +02:00
|
|
|
Noteworthy changes in version 2.0.12 (2009-06-17)
|
2009-03-05 20:19:37 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2009-03-06 18:31:27 +01:00
|
|
|
* GPGSM now always lists ephemeral certificates if specified by
|
|
|
|
fingerprint or keygrip.
|
|
|
|
|
|
|
|
* New command "KEYINFO" for GPG_AGENT. GPGSM now also returns
|
|
|
|
information about smartcards.
|
|
|
|
|
2009-03-19 11:21:51 +01:00
|
|
|
* Made sure not to leak file descriptors if running gpg-agent with a
|
2009-06-17 13:18:26 +02:00
|
|
|
command. Restore the signal mask to solve a problem in Mono.
|
2009-03-19 11:21:51 +01:00
|
|
|
|
|
|
|
* Changed order of the confirmation questions for root certificates
|
2009-06-17 13:18:26 +02:00
|
|
|
and store negative answers in trustlist.txt.
|
2009-03-19 08:09:31 +01:00
|
|
|
|
2009-05-13 19:12:00 +02:00
|
|
|
* Better synchronization of concurrent smartcard sessions.
|
2009-03-24 12:40:57 +01:00
|
|
|
|
2009-05-13 19:12:00 +02:00
|
|
|
* Support 2048 bit OpenPGP cards.
|
|
|
|
|
|
|
|
* Support Telesec Netkey 3 cards.
|
2009-03-26 20:27:04 +01:00
|
|
|
|
2009-04-01 12:51:53 +02:00
|
|
|
* The gpg-protect-tool now uses gpg-agent via libassuan. Under
|
|
|
|
Windows the Pinentry will now be put into the foreground.
|
|
|
|
|
2009-05-20 00:39:45 +02:00
|
|
|
* Changed code to avoid a possible Mac OS X system freeze.
|
|
|
|
|
2009-03-05 20:19:37 +01:00
|
|
|
|
2009-03-03 10:02:58 +01:00
|
|
|
Noteworthy changes in version 2.0.11 (2009-03-03)
|
2009-01-12 11:56:52 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2009-02-27 15:36:59 +01:00
|
|
|
* Fixed a problem in SCDAEMON which caused unexpected card resets.
|
2009-02-09 11:25:41 +01:00
|
|
|
|
|
|
|
* SCDAEMON is now aware of the Geldkarte.
|
|
|
|
|
2009-02-27 15:36:59 +01:00
|
|
|
* The SCDAEMON option --allow-admin is now used by default.
|
|
|
|
|
2009-03-03 10:02:58 +01:00
|
|
|
* GPGCONF now restarts SCdaemon if necessary.
|
|
|
|
|
2009-02-12 18:45:40 +01:00
|
|
|
* The default cipher algorithm in GPGSM is now again 3DES. This is
|
|
|
|
due to interoperability problems with Outlook 2003 which still
|
|
|
|
can't cope with AES.
|
2009-01-28 15:18:40 +01:00
|
|
|
|
2009-01-12 11:56:52 +01:00
|
|
|
|
2009-01-12 10:18:27 +01:00
|
|
|
Noteworthy changes in version 2.0.10 (2009-01-12)
|
2008-03-26 12:01:06 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2008-10-29 18:24:27 +01:00
|
|
|
* [gpg] New keyserver helper gpg2keys_kdns as generic DNS CERT
|
|
|
|
lookup. Run with --help for a short description. Requires the
|
|
|
|
ADNS library.
|
2008-04-08 13:04:16 +02:00
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* [gpg] New mechanisms "local" and "nodefault" for --auto-key-locate.
|
2008-04-08 13:04:16 +02:00
|
|
|
Fixed a few problems with this option.
|
2008-03-26 12:01:06 +01:00
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* [gpg] New command --locate-keys.
|
2008-05-07 17:40:36 +02:00
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* [gpg] New options --with-sig-list and --with-sig-check.
|
2008-05-07 17:40:36 +02:00
|
|
|
|
2008-09-29 17:02:55 +02:00
|
|
|
* [gpg] The option "-sat" is no longer an alias for --clearsign.
|
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* [gpg] The option --fixed-list-mode is now implicitly used and obsolete.
|
2008-06-11 10:07:54 +02:00
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* [gpg] New control statement %ask-passphrase for the unattended key
|
|
|
|
generation.
|
2008-06-16 17:48:33 +02:00
|
|
|
|
2008-12-11 18:44:52 +01:00
|
|
|
* [gpg] The algorithm to compute the SIG_ID status has been changed.
|
|
|
|
|
2008-10-29 18:24:27 +01:00
|
|
|
* [gpgsm] Now uses AES by default.
|
2008-06-26 21:09:07 +02:00
|
|
|
|
2008-10-29 18:24:27 +01:00
|
|
|
* [gpgsm] Made --output option work with --export-secret-key-p12.
|
|
|
|
|
|
|
|
* [gpg-agent] Terminate process if the own listening socket is not
|
|
|
|
anymore served by ourself.
|
|
|
|
|
|
|
|
* [scdaemon] Made it more robust on W32.
|
|
|
|
|
|
|
|
* [gpg-connect-agent] Accept commands given as command line arguments.
|
|
|
|
|
|
|
|
* [w32] Initialized the socket subsystem for all keyserver helpers.
|
|
|
|
|
|
|
|
* [w32] The sysconf directory has been moved from a subdirectory of
|
|
|
|
the installation directory to %CSIDL_COMMON_APPDATA%/GNU/etc/gnupg.
|
|
|
|
|
2008-11-11 09:22:06 +01:00
|
|
|
* [w32] The gnupg2.nls directory is not anymore used. The standard
|
2011-02-03 16:31:42 +01:00
|
|
|
locale directory is now used.
|
2008-11-11 09:22:06 +01:00
|
|
|
|
2009-01-12 11:56:52 +01:00
|
|
|
* [w32] Fixed a race condition between gpg and gpgsm in the use of
|
2008-11-20 17:26:40 +01:00
|
|
|
temporary file names.
|
|
|
|
|
2008-12-09 09:58:02 +01:00
|
|
|
* The gpg-preset-passphrase mechanism works again. An arbitrary
|
|
|
|
string may now be used for a custom cache ID.
|
2008-09-03 11:37:32 +02:00
|
|
|
|
2008-09-25 12:06:02 +02:00
|
|
|
* Admin PINs are cached again (bug in 2.0.9).
|
|
|
|
|
|
|
|
* Support for version 2 OpenPGP cards.
|
|
|
|
|
2008-09-29 17:02:55 +02:00
|
|
|
* Libgcrypt 1.4 is now required.
|
|
|
|
|
2008-03-26 12:01:06 +01:00
|
|
|
|
2008-03-26 10:20:40 +01:00
|
|
|
Noteworthy changes in version 2.0.9 (2008-03-26)
|
2008-01-26 23:12:23 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2008-02-13 17:47:14 +01:00
|
|
|
* Gpgsm always tries to locate missing certificates from a running
|
|
|
|
Dirmngr's cache.
|
|
|
|
|
2008-02-19 11:33:35 +01:00
|
|
|
* Tweaks for Windows.
|
|
|
|
|
2008-03-26 10:20:40 +01:00
|
|
|
* The Admin PIN for OpenPGP cards may now be entered with the pinpad.
|
|
|
|
|
2008-02-19 11:33:35 +01:00
|
|
|
* Improved certificate chain construction.
|
2008-02-15 10:58:01 +01:00
|
|
|
|
2008-02-19 11:33:35 +01:00
|
|
|
* Extended the PKITS framework.
|
|
|
|
|
2008-03-20 16:31:43 +01:00
|
|
|
* Fixed a bug in the ambigious name detection.
|
|
|
|
|
2008-03-25 20:41:11 +01:00
|
|
|
* Fixed possible memory corruption while importing OpenPGP keys (bug
|
2008-03-28 10:21:59 +01:00
|
|
|
introduced with 2.0.8). [CVE-2008-1530]
|
2008-03-25 09:33:31 +01:00
|
|
|
|
2008-02-19 11:33:35 +01:00
|
|
|
* Minor bug fixes.
|
2008-02-15 10:58:01 +01:00
|
|
|
|
2008-01-26 23:12:23 +01:00
|
|
|
|
2007-12-20 09:52:40 +01:00
|
|
|
Noteworthy changes in version 2.0.8 (2007-12-20)
|
2007-09-10 18:38:04 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-10-19 16:51:39 +02:00
|
|
|
* Enhanced gpg-connect-agent with a small scripting language.
|
|
|
|
|
2007-10-23 20:13:27 +02:00
|
|
|
* New option --list-config for gpgconf.
|
|
|
|
|
2007-12-20 09:52:40 +01:00
|
|
|
* Fixed a crash in gpgconf.
|
2007-11-19 17:03:50 +01:00
|
|
|
|
2007-12-20 09:52:40 +01:00
|
|
|
* Gpg-agent now supports the passphrase quality bar of the latest
|
|
|
|
Pinentry.
|
|
|
|
|
|
|
|
* The envvars XAUTHORITY and PINENTRY_USER_DATA are now passed to the
|
|
|
|
Pinentry.
|
2007-12-12 11:28:30 +01:00
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
* Fixed the auto creation of the key stub for smartcards.
|
2007-12-12 11:28:30 +01:00
|
|
|
|
|
|
|
* Fixed a rare bug in decryption using the OpenPGP card.
|
|
|
|
|
|
|
|
* Creating DSA2 keys is now possible.
|
|
|
|
|
2007-12-13 16:45:40 +01:00
|
|
|
* New option --extra-digest-algo for gpgsm to allow verification of
|
|
|
|
broken signatures.
|
|
|
|
|
2007-12-20 09:52:40 +01:00
|
|
|
* Allow encryption with legacy Elgamal sign+encrypt keys with option
|
|
|
|
--rfc2440.
|
|
|
|
|
|
|
|
* Windows is now a supported platform.
|
|
|
|
|
|
|
|
* Made sure that under Windows the file permissions of the socket are
|
|
|
|
taken into account. This required a change of our socket emulation
|
|
|
|
code and changed the IPC protocol under Windows.
|
|
|
|
|
2007-09-10 18:38:04 +02:00
|
|
|
|
2007-09-10 17:40:29 +02:00
|
|
|
Noteworthy changes in version 2.0.7 (2007-09-10)
|
2007-08-16 12:57:35 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-08-24 11:34:39 +02:00
|
|
|
* Fixed encryption problem if duplicate certificates are in the
|
|
|
|
keybox.
|
|
|
|
|
2007-08-27 20:10:27 +02:00
|
|
|
* Made it work on Windows Vista. Note that the entire Windows port
|
|
|
|
is still considered Beta.
|
|
|
|
|
2007-08-28 19:48:13 +02:00
|
|
|
* Add new options min-passphrase-nonalpha, check-passphrase-pattern,
|
|
|
|
enforce-passphrase-constraints and max-passphrase-days to
|
|
|
|
gpg-agent.
|
2007-08-24 11:34:39 +02:00
|
|
|
|
2007-08-29 11:51:37 +02:00
|
|
|
* Add command --check-components to gpgconf. Gpgconf now uses the
|
|
|
|
installed versions of the programs and does not anymore search via
|
|
|
|
PATH for them.
|
|
|
|
|
2007-08-16 12:57:35 +02:00
|
|
|
|
2007-08-16 12:42:06 +02:00
|
|
|
Noteworthy changes in version 2.0.6 (2007-08-16)
|
2007-07-05 22:29:14 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-08-10 18:52:05 +02:00
|
|
|
* GPGSM does now grok --default-key.
|
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
* GPGCONF is now aware of --default-key and --encrypt-to.
|
2007-07-17 20:11:24 +02:00
|
|
|
|
2007-08-10 18:52:05 +02:00
|
|
|
* GPGSM does again correctly print the serial number as well the the
|
|
|
|
various keyids. This was broken since 2.0.4.
|
2007-07-05 22:29:14 +02:00
|
|
|
|
2007-08-14 18:50:27 +02:00
|
|
|
* New option --validation-model and support for the chain-model.
|
|
|
|
|
2007-08-16 12:42:06 +02:00
|
|
|
* Improved Windows support.
|
2007-08-14 18:50:27 +02:00
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
|
2007-07-05 20:59:50 +02:00
|
|
|
Noteworthy changes in version 2.0.5 (2007-07-05)
|
2007-05-15 18:10:48 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-07-04 21:49:40 +02:00
|
|
|
* Switched license to GPLv3.
|
|
|
|
|
|
|
|
* Basic support for Windows. Run "./autogen.sh --build-w32" to build
|
|
|
|
it. As usual the mingw cross compiling toolchain is required.
|
2007-05-29 22:11:17 +02:00
|
|
|
|
2007-07-04 21:49:40 +02:00
|
|
|
* Fixed bug when using the --p12-charset without --armor.
|
2007-06-14 19:05:07 +02:00
|
|
|
|
2007-06-21 20:44:48 +02:00
|
|
|
* The command --gen-key may now be used instead of the
|
|
|
|
gpgsm-gencert.sh script.
|
|
|
|
|
2007-07-05 18:58:19 +02:00
|
|
|
* Changed key generation to reveal less information about the
|
|
|
|
machine. Bug fixes for gpg2's card key generation.
|
|
|
|
|
2007-05-15 18:10:48 +02:00
|
|
|
|
2007-05-09 13:01:33 +02:00
|
|
|
Noteworthy changes in version 2.0.4 (2007-05-09)
|
2007-03-08 15:54:33 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-05-09 13:01:33 +02:00
|
|
|
* The server mode key listing commands are now also working for
|
|
|
|
systems without the funopen/fopencookie API.
|
2007-03-19 15:35:04 +01:00
|
|
|
|
2007-03-19 19:54:34 +01:00
|
|
|
* PKCS#12 import now tries several encodings in case the passphrase
|
2007-03-20 11:00:55 +01:00
|
|
|
was not utf-8 encoded. New option --p12-charset for gpgsm.
|
2007-03-19 19:54:34 +01:00
|
|
|
|
2007-04-20 18:59:37 +02:00
|
|
|
* Improved the libgcrypt logging support in all modules.
|
|
|
|
|
2007-03-08 15:54:33 +01:00
|
|
|
|
2007-03-08 15:16:15 +01:00
|
|
|
Noteworthy changes in version 2.0.3 (2007-03-08)
|
2007-02-26 21:24:29 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2007-03-05 15:56:31 +01:00
|
|
|
* By default, do not allow processing multiple plaintexts in a single
|
|
|
|
stream. Many programs that called GnuPG were assuming that GnuPG
|
|
|
|
did not permit this, and were thus not using the plaintext boundary
|
|
|
|
status tags that GnuPG provides. This change makes GnuPG reject
|
|
|
|
such messages by default which makes those programs safe again.
|
2007-03-19 15:35:04 +01:00
|
|
|
--allow-multiple-messages returns to the old behavior. [CVE-2007-1263].
|
2007-03-05 15:56:31 +01:00
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
* New --verify-option show-primary-uid-only.
|
2007-02-26 21:24:29 +01:00
|
|
|
|
2007-03-08 15:16:15 +01:00
|
|
|
* gpgconf may now reads a global configuration file to select which
|
2007-03-07 21:55:14 +01:00
|
|
|
options are changeable by a frontend. The new applygnupgdefaults
|
|
|
|
tool may be used by an admin to set default options for all users.
|
|
|
|
|
|
|
|
* The PIN pad of the Cherry XX44 keyboard is now supported. The
|
|
|
|
DINSIG and the NKS applications are now also aware of PIN pads.
|
2007-03-06 21:44:41 +01:00
|
|
|
|
2007-02-26 21:24:29 +01:00
|
|
|
|
2007-01-31 15:24:41 +01:00
|
|
|
Noteworthy changes in version 2.0.2 (2007-01-31)
|
2006-12-06 11:16:50 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
|
|
|
* Fixed a serious and exploitable bug in processing encrypted
|
|
|
|
packages. [CVE-2006-6235].
|
|
|
|
|
|
|
|
* Added --passphrase-repeat to set the number of times GPG will
|
|
|
|
prompt for a new passphrase to be repeated. This is useful to help
|
|
|
|
memorize a new passphrase. The default is 1 repetition.
|
|
|
|
|
2007-01-31 15:24:41 +01:00
|
|
|
* Using a PIN pad does now also work for the signing key.
|
2007-01-25 09:30:47 +01:00
|
|
|
|
2007-02-18 14:48:03 +01:00
|
|
|
* A warning is displayed by gpg-agent if a new passphrase is too
|
2007-01-31 15:24:41 +01:00
|
|
|
short. New option --min-passphrase-len defaults to 8.
|
2007-01-25 09:30:47 +01:00
|
|
|
|
2007-01-31 15:24:41 +01:00
|
|
|
* The status code BEGIN_SIGNING now shows the used hash algorithms.
|
2007-02-26 21:24:29 +01:00
|
|
|
|
2006-12-06 11:16:50 +01:00
|
|
|
|
2006-11-28 17:36:02 +01:00
|
|
|
Noteworthy changes in version 2.0.1 (2006-11-28)
|
|
|
|
------------------------------------------------
|
2006-11-11 15:41:22 +01:00
|
|
|
|
2006-11-20 17:49:41 +01:00
|
|
|
* Experimental support for the PIN pads of the SPR 532 and the Kaan
|
|
|
|
Advanced card readers. Add "disable-keypad" scdaemon.conf if you
|
|
|
|
don't want it. Does currently only work for the OpenPGP card and
|
2006-11-28 17:36:02 +01:00
|
|
|
its authentication and decrypt keys.
|
2006-11-20 17:49:41 +01:00
|
|
|
|
2006-11-23 10:53:17 +01:00
|
|
|
* Fixed build problems on some some platforms and crashes on amd64.
|
|
|
|
|
2006-12-06 11:16:50 +01:00
|
|
|
* Fixed a buffer overflow in gpg2. [bug#728,CVE-2006-6169]
|
2006-11-28 17:36:02 +01:00
|
|
|
|
2006-11-11 15:41:22 +01:00
|
|
|
|
2006-11-11 15:17:09 +01:00
|
|
|
Noteworthy changes in version 2.0.0 (2006-11-11)
|
2006-11-28 17:36:02 +01:00
|
|
|
------------------------------------------------
|
2006-11-06 11:26:55 +01:00
|
|
|
|
|
|
|
* First stable version of a GnuPG integrating OpenPGP and S/MIME.
|
|
|
|
|
|
|
|
|
2006-11-06 10:44:28 +01:00
|
|
|
Noteworthy changes in version 1.9.95 (2006-11-06)
|
2006-10-24 17:01:23 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-11-06 10:44:28 +01:00
|
|
|
* Minor bug fixes.
|
|
|
|
|
2006-10-24 17:01:23 +02:00
|
|
|
|
2006-10-24 16:45:34 +02:00
|
|
|
Noteworthy changes in version 1.9.94 (2006-10-24)
|
2006-10-19 16:22:06 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-10-20 13:38:48 +02:00
|
|
|
* Keys for gpgsm may now be specified using a keygrip. A keygrip is
|
|
|
|
indicated by a prefixing it with an ampersand.
|
|
|
|
|
2006-10-23 16:02:13 +02:00
|
|
|
* gpgconf now supports switching the CMS cipher algo (e.g. to AES).
|
|
|
|
|
|
|
|
* New command --gpgconf-test for all major tools. This may be used to
|
|
|
|
check whether the configuration file is sane.
|
|
|
|
|
2006-10-19 16:22:06 +02:00
|
|
|
|
2006-10-18 19:19:08 +02:00
|
|
|
Noteworthy changes in version 1.9.93 (2006-10-18)
|
2006-10-11 19:52:15 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-10-17 16:34:42 +02:00
|
|
|
* In --with-validation mode gpgsm will now also ask whether a root
|
|
|
|
certificate should be trusted.
|
|
|
|
|
|
|
|
* Link to Pth only if really necessary.
|
|
|
|
|
2006-10-18 19:19:08 +02:00
|
|
|
* Fixed a pubring corruption bug in gpg2 occurring when importing
|
|
|
|
signatures or keys with insane lengths.
|
|
|
|
|
|
|
|
* Fixed v3 keyID calculation bug in gpg2.
|
|
|
|
|
|
|
|
* More tweaks for certificates without extensions.
|
|
|
|
|
2006-10-11 19:52:15 +02:00
|
|
|
|
2006-10-11 12:05:03 +02:00
|
|
|
Noteworthy changes in version 1.9.92 (2006-10-11)
|
2006-10-05 13:06:42 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-10-11 12:05:03 +02:00
|
|
|
* Bug fixes.
|
|
|
|
|
2006-10-05 13:06:42 +02:00
|
|
|
|
2006-10-04 12:22:56 +02:00
|
|
|
Noteworthy changes in version 1.9.91 (2006-10-04)
|
2006-09-25 20:29:20 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-09-26 12:00:12 +02:00
|
|
|
* New "relax" flag for trustlist.txt to allow root CA certificates
|
|
|
|
without BasicContraints.
|
|
|
|
|
2006-10-04 12:22:56 +02:00
|
|
|
* [gpg2] Removed the -k PGP 2 compatibility hack. -k is now an
|
|
|
|
alias for --list-keys.
|
|
|
|
|
|
|
|
* [gpg2] Print a warning if "-sat" is used instead of "--clearsign".
|
|
|
|
|
2006-09-25 20:29:20 +02:00
|
|
|
|
2006-09-25 09:59:34 +02:00
|
|
|
Noteworthy changes in version 1.9.90 (2006-09-25)
|
2006-09-18 16:08:27 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-09-22 20:15:18 +02:00
|
|
|
* Made readline work for gpg.
|
|
|
|
|
|
|
|
* Cleanups und minor bug fixes.
|
2006-09-18 16:08:27 +02:00
|
|
|
|
2006-09-25 09:59:34 +02:00
|
|
|
* Included translations from gnupg 1.4.5.
|
|
|
|
|
2006-09-18 16:08:27 +02:00
|
|
|
|
2006-09-18 15:23:18 +02:00
|
|
|
Noteworthy changes in version 1.9.23 (2006-09-18)
|
2006-07-27 16:45:11 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-09-13 17:57:30 +02:00
|
|
|
* Regular man pages for most tools are now build directly from the
|
2006-09-14 18:50:33 +02:00
|
|
|
Texinfo source.
|
2006-08-18 15:05:39 +02:00
|
|
|
|
|
|
|
* The gpg code from 1.4.5 has been fully merged into this release.
|
|
|
|
The configure option --enable-gpg is still required to build this
|
|
|
|
gpg part. For production use of OpenPGP the gpg version 1.4.5 is
|
2006-09-18 15:23:18 +02:00
|
|
|
still recommended. Note, that gpg will be installed under the name
|
|
|
|
gpg2 to allow coexisting with an 1.4.x gpg.
|
2006-07-27 16:45:11 +02:00
|
|
|
|
2006-08-29 18:18:30 +02:00
|
|
|
* API change in gpg-agent's pkdecrypt command. Thus an older gpgsm
|
|
|
|
may not be used with the current gpg-agent.
|
|
|
|
|
2006-09-07 17:13:33 +02:00
|
|
|
* The scdaemon will now call a script on reader status changes.
|
|
|
|
|
2006-09-13 17:57:30 +02:00
|
|
|
* gpgsm now allows file descriptor passing for "INPUT", "OUTPUT" and
|
|
|
|
"MESSAGE".
|
|
|
|
|
|
|
|
* The gpgsm server may now output a key listing to the output file
|
|
|
|
handle. This needs to be enabled using "OPTION list-to-output=1".
|
|
|
|
|
|
|
|
* The --output option of gpgsm has now an effect on list-keys.
|
|
|
|
|
|
|
|
* New gpgsm commands --dump-chain and list-chain.
|
|
|
|
|
|
|
|
* gpg-connect-agent has new options to utilize descriptor passing.
|
|
|
|
|
2006-09-15 20:53:37 +02:00
|
|
|
* A global trustlist may now be used. See doc/examples/trustlist.txt.
|
|
|
|
|
2006-09-18 11:28:58 +02:00
|
|
|
* When creating a new pubring.kbx keybox common certificates are
|
|
|
|
imported.
|
|
|
|
|
2006-07-27 16:45:11 +02:00
|
|
|
|
2006-07-27 16:18:55 +02:00
|
|
|
Noteworthy changes in version 1.9.22 (2006-07-27)
|
2006-06-27 16:32:34 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-07-21 11:41:11 +02:00
|
|
|
* Enhanced pkcs#12 support to allow import from simple keyBags.
|
|
|
|
|
2006-07-24 13:20:33 +02:00
|
|
|
* Exporting to pkcs#12 now create bag attributes so that Mozilla is
|
|
|
|
able to import the files.
|
|
|
|
|
2006-07-27 16:18:55 +02:00
|
|
|
* Fixed uploading of certain keys to the smart card.
|
|
|
|
|
2006-06-27 16:32:34 +02:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
Noteworthy changes in version 1.9.21 (2006-06-20)
|
2005-12-20 12:12:16 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* New command APDU for scdaemon to allow using it for general card
|
|
|
|
access. Might be used through gpg-connect-agent by using the SCD
|
|
|
|
prefix command.
|
2006-04-19 13:26:11 +02:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* Support for the CardMan 4040 PCMCIA reader (Linux 2.6.15 required).
|
2005-12-20 12:12:16 +01:00
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
* Scdaemon does not anymore reset cards at the end of a connection.
|
2006-02-06 19:31:27 +01:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* Kludge to allow use of Bundesnetzagentur issued X.509 certificates.
|
2006-02-09 19:29:31 +01:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* Added --hash=xxx option to scdaemon's PKSIGN command.
|
2006-03-21 10:56:47 +01:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* Pkcs#12 files are now created with a MAC. This is for better
|
|
|
|
interoperability.
|
2006-03-21 13:48:51 +01:00
|
|
|
|
2006-06-20 20:52:43 +02:00
|
|
|
* Collected bug fixes and minor other changes.
|
2006-06-20 19:21:37 +02:00
|
|
|
|
2005-12-20 12:12:16 +01:00
|
|
|
|
2005-12-20 11:26:32 +01:00
|
|
|
Noteworthy changes in version 1.9.20 (2005-12-20)
|
2005-11-28 12:52:25 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-12-16 16:52:48 +01:00
|
|
|
* Importing pkcs#12 files created be recent versions of Mozilla works
|
|
|
|
again.
|
|
|
|
|
2005-12-20 11:26:32 +01:00
|
|
|
* Basic support for qualified signatures.
|
|
|
|
|
2011-02-03 16:31:42 +01:00
|
|
|
* New debug tool gpgparsemail.
|
2005-12-20 11:26:32 +01:00
|
|
|
|
2005-11-28 12:52:25 +01:00
|
|
|
|
2005-09-12 10:23:33 +02:00
|
|
|
Noteworthy changes in version 1.9.19 (2005-09-12)
|
2005-08-16 11:15:09 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-09-09 13:18:08 +02:00
|
|
|
* The Belgian eID card is now supported for signatures and ssh.
|
2005-09-12 10:23:33 +02:00
|
|
|
Other pkcs#15 cards should work as well.
|
2005-09-06 20:42:13 +02:00
|
|
|
|
2005-09-09 13:18:08 +02:00
|
|
|
* Fixed bug in --export-secret-key-p12 so that certificates are again
|
|
|
|
included.
|
2005-08-16 11:15:09 +02:00
|
|
|
|
2005-09-12 10:23:33 +02:00
|
|
|
|
2005-08-01 18:54:54 +02:00
|
|
|
Noteworthy changes in version 1.9.18 (2005-08-01)
|
2005-06-20 19:52:13 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-07-25 16:35:04 +02:00
|
|
|
* [gpgsm] Now allows for more than one email address as well as URIs
|
|
|
|
and dnsNames in certificate request generation. A keygrip may be
|
|
|
|
given to create a request from an existing key.
|
|
|
|
|
2005-08-01 18:54:54 +02:00
|
|
|
* A couple of minor bug fixes.
|
|
|
|
|
2005-06-20 19:52:13 +02:00
|
|
|
|
2005-06-20 19:32:44 +02:00
|
|
|
Noteworthy changes in version 1.9.17 (2005-06-20)
|
2005-04-21 16:59:18 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-05-21 20:49:00 +02:00
|
|
|
* gpg-connect-agent has now features to handle Assuan INQUIRE
|
|
|
|
commands.
|
|
|
|
|
|
|
|
* Internal changes for OpenPGP cards. New Assuan command WRITEKEY.
|
|
|
|
|
2005-05-18 12:48:06 +02:00
|
|
|
* GNU Pth is now a hard requirement.
|
|
|
|
|
2005-04-27 14:09:21 +02:00
|
|
|
* [scdaemon] Support for OpenSC has been removed. Instead a new and
|
2005-05-18 12:48:06 +02:00
|
|
|
straightforward pkcs#15 modules has been written. As of now it
|
2005-04-27 14:09:21 +02:00
|
|
|
does allows only signing using TCOS cards but we are going to
|
|
|
|
enhance it to match all the old capabilities.
|
|
|
|
|
2005-06-07 21:09:18 +02:00
|
|
|
* [gpg-agent] New option --write-env-file and Assuan command
|
2005-06-03 15:57:24 +02:00
|
|
|
UPDATESTARTUPTTY.
|
|
|
|
|
2005-06-07 21:09:18 +02:00
|
|
|
* [gpg-agent] New option --default-cache-ttl-ssh to set the TTL for
|
|
|
|
SSH passphrase caching independent from the other passphrases.
|
|
|
|
|
2005-04-21 16:59:18 +02:00
|
|
|
|
2005-04-21 16:39:00 +02:00
|
|
|
Noteworthy changes in version 1.9.16 (2005-04-21)
|
2005-01-13 20:03:37 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-04-18 12:44:46 +02:00
|
|
|
* gpg-agent does now support the ssh-agent protocol and thus allows
|
|
|
|
to use the pinentry as well as the OpenPGP smartcard with ssh.
|
|
|
|
|
2005-04-21 16:39:00 +02:00
|
|
|
* New tool gpg-connect-agent as a general client for the gpg-agent.
|
2005-04-18 12:44:46 +02:00
|
|
|
|
|
|
|
* New tool symcryptrun as a wrapper for certain encryption tools.
|
|
|
|
|
2005-04-21 16:39:00 +02:00
|
|
|
* The gpg tool is not anymore build by default because those gpg
|
|
|
|
versions available in the gnupg 1.4 series are far more matured.
|
|
|
|
|
2005-01-13 20:03:37 +01:00
|
|
|
|
2005-01-13 19:00:46 +01:00
|
|
|
Noteworthy changes in version 1.9.15 (2005-01-13)
|
2004-12-22 20:07:46 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2005-01-13 19:00:46 +01:00
|
|
|
* Fixed passphrase caching bug.
|
|
|
|
|
|
|
|
* Better support for CCID readers; the reader from Cherry RS 6700 USB
|
|
|
|
does now work.
|
|
|
|
|
2004-12-22 20:07:46 +01:00
|
|
|
|
2004-12-22 18:55:28 +01:00
|
|
|
Noteworthy changes in version 1.9.14 (2004-12-22)
|
2004-12-03 20:43:11 +01:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2004-12-20 17:17:25 +01:00
|
|
|
* [gpg-agent] New option --use-standard-socket to allow the use of a
|
|
|
|
fixed socket. gpgsm falls back to this socket if GPG_AGENT_INFO
|
|
|
|
has not been set.
|
|
|
|
|
2004-12-22 18:55:28 +01:00
|
|
|
* Ported to MS Windows with some functional limitations.
|
|
|
|
|
|
|
|
* New tool gpg-preset-passphrase.
|
2004-12-20 17:17:25 +01:00
|
|
|
|
2004-12-03 20:43:11 +01:00
|
|
|
|
2004-12-03 18:44:57 +01:00
|
|
|
Noteworthy changes in version 1.9.13 (2004-12-03)
|
2004-10-22 21:57:03 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2004-12-03 18:44:57 +01:00
|
|
|
* [gpgsm] New option --prefer-system-dirmngr.
|
|
|
|
|
2004-12-06 14:49:14 +01:00
|
|
|
* Minor cleanups and debugging aids.
|
2004-12-03 18:44:57 +01:00
|
|
|
|
2004-10-22 21:57:03 +02:00
|
|
|
|
2004-10-22 21:48:12 +02:00
|
|
|
Noteworthy changes in version 1.9.12 (2004-10-22)
|
2004-10-01 15:31:46 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2004-10-20 10:54:45 +02:00
|
|
|
* [scdaemon] Partly rewrote the PC/SC code.
|
|
|
|
|
2004-10-22 18:03:04 +02:00
|
|
|
* Removed the sc-investigate tool. It is now in a separate package
|
|
|
|
available at ftp://ftp.g10code.com/g10code/gscutils/ .
|
|
|
|
|
|
|
|
* [gpg-agent] Fixed logging problem.
|
2004-10-01 15:31:46 +02:00
|
|
|
|
2004-10-15 18:10:50 +02:00
|
|
|
|
2004-10-01 14:54:53 +02:00
|
|
|
Noteworthy changes in version 1.9.11 (2004-10-01)
|
2004-07-22 13:40:17 +02:00
|
|
|
-------------------------------------------------
|
|
|
|
|
2004-08-17 17:26:22 +02:00
|
|
|
* When using --import along with --with-validation, the imported
|
|
|
|
certificates are validated and only imported if they are fully
|
|
|
|
valid.
|
2004-07-22 13:40:17 +02:00
|
|
|
|
2004-09-09 09:27:57 +02:00
|
|
|
* [gpg-agent] New option --max-cache-ttl.
|
|
|
|
|
|
|
|
* [gpg-agent] When used without --daemon or --server, gpg-agent now
|
|
|
|
check whether a agent is already running and usable.
|
|
|
|
|
2004-09-30 23:37:11 +02:00
|
|
|
* Fixed some i18n problems.
|
|
|
|
|
2004-09-09 09:27:57 +02:00
|
|
|
|
2004-07-22 11:37:36 +02:00
|
|
|
Noteworthy changes in version 1.9.10 (2004-07-22)
|
|
|
|
-------------------------------------------------
|
|
|
|
|
|
|
|
* Fixed a serious bug in the checking of trusted root certificates.
|
|
|
|
|
|
|
|
* New configure option --enable-agent-pnly allows to build and
|
|
|
|
install just the agent.
|
|
|
|
|
|
|
|
* Fixed a problem with the log file handling.
|
2004-06-08 21:25:06 +02:00
|
|
|
|
|
|
|
|
2004-06-08 21:10:32 +02:00
|
|
|
Noteworthy changes in version 1.9.9 (2004-06-08)
|
2004-04-29 20:16:44 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-05-11 11:15:56 +02:00
|
|
|
* [gpg-agent] The new option --allow-mark-trusted is now required to
|
|
|
|
allow gpg-agent to add a key to the trustlist.txt after user
|
|
|
|
confirmation.
|
2004-04-29 20:16:44 +02:00
|
|
|
|
2004-06-06 15:00:59 +02:00
|
|
|
* Creating PKCS#10 requests does now honor the key usage.
|
|
|
|
|
2004-04-29 20:16:44 +02:00
|
|
|
|
2004-04-29 19:32:02 +02:00
|
|
|
Noteworthy changes in version 1.9.8 (2004-04-29)
|
2004-04-06 16:15:47 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-04-20 18:42:55 +02:00
|
|
|
* [scdaemon] Overhauled the internal CCID driver.
|
|
|
|
|
|
|
|
* [scdaemon] Status files named ~/.gnupg/reader_<n>.status are now
|
|
|
|
written when using the internal CCID driver.
|
|
|
|
|
2004-04-26 10:09:25 +02:00
|
|
|
* [gpgsm] New commands --dump-{,secret,external}-keys to show a very
|
|
|
|
detailed view of the certificates.
|
|
|
|
|
|
|
|
* The keybox gets now compressed after 3 hours and ephemeral
|
|
|
|
stored certificates are deleted after about a day.
|
|
|
|
|
2004-04-29 19:32:02 +02:00
|
|
|
* [gpg] Usability fixes for --card-edit. Note, that this has already
|
|
|
|
been ported back to gnupg-1.3
|
|
|
|
|
2004-04-06 16:15:47 +02:00
|
|
|
|
2004-04-06 13:40:28 +02:00
|
|
|
Noteworthy changes in version 1.9.7 (2004-04-06)
|
2004-03-06 21:42:14 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-03-16 20:00:00 +01:00
|
|
|
* Instrumented the modules for gpgconf.
|
|
|
|
|
|
|
|
* Added support for DINSIG card applications.
|
|
|
|
|
2004-04-06 09:36:25 +02:00
|
|
|
* Include the smimeCapabilities attribute with signed messages.
|
|
|
|
|
2004-04-06 12:01:04 +02:00
|
|
|
* Now uses the gettext domain "gnupg2" to avoid conflicts with gnupg
|
|
|
|
versions < 1.9.
|
|
|
|
|
2004-03-06 21:42:14 +01:00
|
|
|
|
2004-03-06 21:11:19 +01:00
|
|
|
Noteworthy changes in version 1.9.6 (2004-03-06)
|
2004-02-21 14:35:42 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-03-06 21:11:19 +01:00
|
|
|
* Code cleanups and bug fixes.
|
2004-02-21 14:35:42 +01:00
|
|
|
|
|
|
|
|
2004-02-21 14:13:35 +01:00
|
|
|
Noteworthy changes in version 1.9.5 (2004-02-21)
|
2004-01-30 11:13:51 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-02-12 10:25:30 +01:00
|
|
|
* gpg-protect-tool gets now installed into libexec as it ought to be.
|
|
|
|
Cleaned up the build system to better comply with the coding
|
|
|
|
standards.
|
2004-01-30 11:13:51 +01:00
|
|
|
|
2004-02-13 18:06:34 +01:00
|
|
|
* [gpgsm] The --import command is now able to autodetect pkcs#12
|
|
|
|
files and import secret and private keys from this file format.
|
2004-02-19 17:26:32 +01:00
|
|
|
A new command --export-secret-key-p12 is provided to allow
|
|
|
|
exporting of secret keys in PKCS\#12 format.
|
2004-02-13 18:06:34 +01:00
|
|
|
|
2004-02-18 17:57:38 +01:00
|
|
|
* [gpgsm] The pinentry will now present a description of the key for
|
2004-02-21 14:13:35 +01:00
|
|
|
whom the passphrase is requested.
|
2004-02-13 13:40:54 +01:00
|
|
|
|
2004-02-18 17:57:38 +01:00
|
|
|
* [gpgsm] New option --with-validation to check the validity of key
|
|
|
|
while listing it.
|
|
|
|
|
|
|
|
* New option --debug-level={none,basic,advanced,expert,guru} to map
|
|
|
|
the debug flags to sensitive levels on a per program base.
|
|
|
|
|
2004-02-13 13:40:54 +01:00
|
|
|
|
2004-01-30 10:12:36 +01:00
|
|
|
Noteworthy changes in version 1.9.4 (2004-01-30)
|
2003-12-23 12:27:13 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2004-01-29 21:16:59 +01:00
|
|
|
* Added support for the Telesec NKS 2.0 card application.
|
|
|
|
|
2004-01-30 10:12:36 +01:00
|
|
|
* Added simple tool addgnupghome to create .gnupg directories from
|
|
|
|
/etc/skel/.gnupg.
|
|
|
|
|
2004-01-29 21:16:59 +01:00
|
|
|
* Various minor bug fixes and cleanups; mainly gpgsm and gpg-agent
|
|
|
|
related.
|
2003-12-23 12:27:13 +01:00
|
|
|
|
2004-01-30 10:12:36 +01:00
|
|
|
|
2003-12-23 12:05:19 +01:00
|
|
|
Noteworthy changes in version 1.9.3 (2003-12-23)
|
2003-11-17 13:56:43 +01:00
|
|
|
------------------------------------------------
|
|
|
|
|
2003-12-17 18:12:14 +01:00
|
|
|
* New gpgsm options --{enable,disable}-ocsp to validate keys using
|
2003-12-23 11:23:16 +01:00
|
|
|
OCSP. This option requires a not yet released DirMngr version.
|
|
|
|
Default is disabled.
|
2003-12-16 12:30:16 +01:00
|
|
|
|
2003-12-16 17:32:02 +01:00
|
|
|
* The --log-file option may now be used to print logs to a socket.
|
|
|
|
Prefix the socket name with "socket://" to enable this. This does
|
|
|
|
not work on all systems and falls back to stderr if there is a
|
|
|
|
problem with the socket.
|
2003-12-01 11:53:40 +01:00
|
|
|
|
2003-12-17 18:12:14 +01:00
|
|
|
* The options --encrypt-to and --no-encrypt-to now work the same in
|
|
|
|
gpgsm as in gpg. Note, they are also used in server mode.
|
|
|
|
|
|
|
|
* Duplicated recipients are now silently removed in gpgsm.
|
|
|
|
|
2003-12-01 11:53:40 +01:00
|
|
|
|
2003-11-17 13:20:11 +01:00
|
|
|
Noteworthy changes in version 1.9.2 (2003-11-17)
|
2003-09-06 15:44:17 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2003-10-08 12:46:58 +02:00
|
|
|
* On card key generation is no longer done using the --gen-key
|
|
|
|
command but from the menu provided by the new --card-edit command.
|
|
|
|
|
|
|
|
* PINs are now properly cached and there are only 2 PINs visible.
|
|
|
|
The 3rd PIN (CHV2) is internally syncronized with the regular PIN.
|
2003-09-06 15:44:17 +02:00
|
|
|
|
2003-11-17 13:20:11 +01:00
|
|
|
* All kind of other internal stuff.
|
|
|
|
|
2003-09-06 15:44:17 +02:00
|
|
|
|
2003-09-06 15:23:48 +02:00
|
|
|
Noteworthy changes in version 1.9.1 (2003-09-06)
|
2003-08-05 20:55:40 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2003-09-06 15:23:48 +02:00
|
|
|
* Support for OpenSC is back. scdaemon supports a --disable-opensc to
|
2003-08-18 19:34:28 +02:00
|
|
|
disable OpenSC use at runtime, so that PC/SC or ct-API can still be
|
|
|
|
used directly.
|
|
|
|
|
2003-09-06 15:23:48 +02:00
|
|
|
* Rudimentary support for the SCR335 smartcard reader using an
|
|
|
|
internal driver. Requires current libusb from CVS.
|
|
|
|
|
|
|
|
* Bug fixes.
|
|
|
|
|
2003-08-05 20:55:40 +02:00
|
|
|
|
2003-08-05 19:20:18 +02:00
|
|
|
Noteworthy changes in version 1.9.0 (2003-08-05)
|
2002-10-18 12:41:34 +02:00
|
|
|
------------------------------------------------
|
|
|
|
|
2003-08-05 19:20:18 +02:00
|
|
|
====== PLEASE SEE README-alpha =======
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
* gpg has been renamed to gpg2 and gpgv to gpgv2. This is a
|
2003-08-05 19:20:18 +02:00
|
|
|
temporary change to allow co-existing with stable gpg versions.
|
2003-08-05 19:11:04 +02:00
|
|
|
|
2003-08-05 19:20:18 +02:00
|
|
|
* ~/.gnupg/gpg.conf-1.9.0 is fist tried as config file before the
|
|
|
|
usual gpg.conf.
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
* Removed the -k, -kv and -kvv commands. -k is now an alias to
|
|
|
|
--list-keys. New command -K as alias for --list-secret-keys.
|
|
|
|
|
|
|
|
* Removed --run-as-shm-coprocess feature.
|
|
|
|
|
2003-06-27 22:53:09 +02:00
|
|
|
* gpg does now also use libgcrypt, libgpg-error is required.
|
|
|
|
|
2003-01-09 14:15:07 +01:00
|
|
|
* New gpgsm commands --call-dirmngr and --call-protect-tool.
|
1998-01-12 11:18:17 +01:00
|
|
|
|
2003-01-09 14:15:07 +01:00
|
|
|
* Changing a passphrase is now possible using "gpgsm --passwd"
|
2002-06-29 16:15:02 +02:00
|
|
|
|
2003-01-09 14:15:07 +01:00
|
|
|
* The content-type attribute is now recognized and created.
|
|
|
|
|
|
|
|
* The agent does now reread certain options on receiving a HUP.
|
|
|
|
|
|
|
|
* The pinentry is now forked for each request so that clients with
|
|
|
|
different environments are supported. When running in daemon mode
|
|
|
|
and --keep-display is not used the DISPLAY variable is ignored.
|
|
|
|
|
|
|
|
* Merged stuff from the newpg branch and started this new
|
|
|
|
development branch.
|
|
|
|
|
|
|
|
|
2008-10-29 18:24:27 +01:00
|
|
|
Copyright 2002, 2003, 2004, 2005, 2006, 2007,
|
2011-02-03 16:31:42 +01:00
|
|
|
2008, 2009, 2010, 2011 Free Software Foundation, Inc.
|
2002-06-29 16:15:02 +02:00
|
|
|
|
2002-10-19 09:55:27 +02:00
|
|
|
This file is free software; as a special exception the author gives
|
|
|
|
unlimited permission to copy and/or distribute it, with or without
|
|
|
|
modifications, as long as this notice is preserved.
|
2002-06-29 16:15:02 +02:00
|
|
|
|
2002-10-19 09:55:27 +02:00
|
|
|
This file is distributed in the hope that it will be useful, but
|
|
|
|
WITHOUT ANY WARRANTY, to the extent permitted by law; without even the
|
|
|
|
implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
|