./security/gnupg2, GnuPG with OpenPGP and S/MIME capabilities

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ]


Branch: CURRENT, Version: 2.5.22, Package name: gnupg2-2.5.22, Maintainer: ada

GnuPG is GNU's tool for secure communication and data storage. It
can be used to encrypt data and to create digital signatures. It
includes an advanced key management facility and is compliant with
the proposed OpenPGP Internet standard as described in RFC4880.

This package contains the full suite of GnuPG tools for cryptographic
communications and data storage.


Required to run:
[security/libgpg-error] [security/gnutls] [security/libksba] [security/libgcrypt] [security/pinentry] [devel/readline] [security/libassuan2] [devel/libusb1] [devel/npth]

Required to build:
[pkgtools/cwrappers]

Package options: bzip2, gnutls, libusb-1, zlib

Master sites: (Expand)

Filesize: 8167.826 KB

Version history: (Expand)


CVS history: (Expand)


   2026-09-07 07:19:50 by Adam Ciarcinski | Files touched by this commit (2) | Package updated
Log message:
gnupg2: updated to 2.5.22

Noteworthy changes in version 2.5.22 (2026-08-31)

* New and extended features:

  - gpg: New option "primary" for the --card-edit "generate" \ 
command.
    This option is useful create only the primary key on the first
    slot of an OpenPGP card.  [T8344]

  - Make detection of the installation directory work for macOS.
    [rG0be940905d]

  - gpgsm: Emit issuer and serial no. when the certificate is not
    found.  [T8363]

* Bug fixes:

  - gpg: Fix trustdb recursive lock problem.  [T8317]

  - gpg: Fix using wrong fingerprint length for the intended
    recipient fingerprint.  [T8330]

  - gpg: Fix wrong assertion edge case in building packets.
    [rGe319d82d7e]

  - gpg: Fix possible double free in import_revoke_cert.  [T8328]

  - gpg: Fix long standing regression of "bkuptocard".
    [T8344,rGf103eaee63]

  - gpg: Fix TOFU trust models to actually check UTK signatures.
    [T8404]

  - gpg: Don't enable the partial file guard if already done.  Fix
    regression introduced by partial file guards.  [T8399]

  - gpgsm: Only display de-vs compliance status in de-vs compliance
    mode.  [T8333]

  - gpgsm: Return 0 if decryption of multi recipient file succeeds.
    [T8340]

  - gpgsm: Check args for special file names and dashes.  [T8347]

  - gpgsm: Fix keydb_get_flags with keyboxd.  [T8048]

  - g13: Add sanity check on the syntax of the dmsetup algo string.
    [rG386c3e63b1]

* Other changes:

  - gpg,gpgsm: Emit signing time as status output also for bad
    signatures.  [T8364]

  - gpg: Emit status line for failed write.  [T8398]

  - scd: Put a workaround for buggy CCID device.  [T8331]

  - scd: Allow switching APP when --pcsc-shared is enabled.
    [rGf783c02525]

  - gpgconf: Print a warning on Windows on insufficent global config
    directory permissions.  [rG56eb3148c7]
   2026-07-03 13:30:46 by Adam Ciarcinski | Files touched by this commit (3) | Package updated
Log message:
gnupg2: updated to 2.5.21

Noteworthy changes in version 2.5.21 (2026-07-02)

* New and extended features:

  - gpg, gpgsm: Use partial file on decryption, remove on failure.
    Disable with "--compatibility-flags=no-partial-file-guard".

  - gpg: Use the INT_RCP_FPR subpacket in revocation signatures.

  - Create a pkgversioninfo.txt file when building using the speedo
    build system.

* Bug fixes:

  - gpg: Fix potential use-after-free in batch key generation when
    handling the keyserver URL option.

  - gpgsm: Fix regression in gpgsm_verify with expired certificates.

  - gpgsm: Require a minimum tag length for GCM decryption.

  - scd: Limit the size of returned APDU objects from faulty cards.

  - scd: Fix condition to retrieve ATR.

  - scd:openpgp: Fix regression in CHV1 retry counter byte index.

  - agent: Make batch import of Kyber keys work.

  - dirmngr: Add a validation check in get_dns_cert_standard.

  - gpgconf: Raise an error on certain parse errors.

  - Fix use of usleep in file remove function on Windows.  Regression
    since 2.5.13.
   2026-06-22 22:08:57 by Thomas Klausner | Files touched by this commit (3)
Log message:
gnupg2: add upstream patch for CVE-2026-34182

Bump PKGREVISION.
   2026-05-14 18:42:34 by Ryo ONODERA | Files touched by this commit (1335)
Log message:
*: Recursive revbump from security/nettle-4.0
   2026-05-14 14:38:11 by Adam Ciarcinski | Files touched by this commit (2) | Package updated
Log message:
gnupg2: updated to 2.5.20

Noteworthy changes in version 2.5.20 (2026-05-13)

* New and extended features:

  - gpgsm: Implement GCM encryption.  Note that decryption works
    since version 2.3.2.
  - gpgsm: New option --attribute and server command SETATTR to
    include arbitrary signed or unsigned attributes into a signature.
    Enable only with libksba 1.7.0 or later.
  - gpgsm: Introduce system attribute _signingCertificateV2.

* Bug fixes:

  - gpg: Fix wrong assertion failure which could very rarely occur
    during key signature checking.
  - gpg: Consider certify-only keys for revocation signature check.
  - gpgsm: Fix possible double free in the CMS parser.
  - gpgsm: Fix possible too early removal of ephemeral keys.
  - gpgsm: Avoid emitting a final FAILURE status line if --status-fd
    is not used.
  - gpgsm: Fix a regression in 2.5.19 for password encrypted GCM
    data.
  - agent: Fix not using cache for pinentry loopback.
  - agent: Fix command PUT_SECRET by saving input line.
  - keyboxd: Mark keys searched but not imported via LDAP correctly
    as ephemeral.
  - scdaemon: Avoid buffer overflow with SC-HSM cards providing RSA
    keys > 2k.
  - dirmngr: Fix uninitialized use of the dns_any union in
    dns_rr_cmp.
   2026-04-27 12:51:14 by Adam Ciarcinski | Files touched by this commit (2) | Package updated
Log message:
gnupg2: updated to 2.5.19

Noteworthy changes in version 2.5.19 (2026-04-24)

 * New and extended features:

 - gpg: New option --use-ocb-sym.
 - gpg: New options --show-[only-]session-hash.
 - gpgsm: Allow cipher mode to be part of the algo given to the
   --cipher-algo option.
 - gpgsm: Emit more details when failing to check a crlDP.
 - agent: Improve pinentry behavior and texts in smartcard context.
 - dirmngr: New keyword "clear" for --keyserver.

 * Bug fixes:

 - gpg: Fix edge case in --refresh-keys.
 - gpg: Don't call gcry_kdf_derive with empty passphrase.
 - gpgsm: Skip the optional PKCS#12 PBES2 keyLength parameter to
   allow import of recently issued certificates by the German
   Telekom.
 - gpgsm: Fix a bug so that a certificate can be signed using a
   different algo.
 - gpgsm: Make GCM fully compliant in de-vs mode.
 - gpgsm: Add a certificate chain check for de-vs compliance.
 - gpgsm: Show rsaPSS certificates as de-vs compliant in listings.
 - agent: Rework the trustlist reading code to finally allow a
   trustlist.txt with a missing trailing LF.
 - ssh: Fix RSA padding in signature handling.
 - gpgtar: Fix -C (--directory) to check the output directory.

 * Other changes:

 - agent: Raise an error when p >= q for RSA keys to detect
   incorrect generated *PGP keys.
   2026-02-26 18:24:49 by Adam Ciarcinski | Files touched by this commit (2) | Package updated
Log message:
gnupg2: updated to 2.5.18

Noteworthy changes in version 2.5.18 (2026-02-24)

* gpg: Support deleting a composite secret key in gpg-agent.
* gpg: Fix armor parsing when no CRC is found.
* gpgsm: New option --assert-validsig.
* agent: Fix the recent regression in pkdecrypt with TPM RSA.
* scdaemon: Add support for D-Trust Card 6.1/6.4.
* dirmngr: Let KS_SEARCH print all uid records for a key.
  Fixes regression since 2015.
* gpg-authcode-sign.sh: Keep the log file even on success.
   2026-02-06 11:06:21 by Thomas Klausner | Files touched by this commit (1305)
Log message:
*: recursive bump for nettle 4.0 shlib major bump