PGP / gpg スレ

1秘密
垢版 |
NGNG

秘密を守る人のスレ
2025/02/13(木) 00:42:17.71
GnuPG 2.5.4 (テスト版)

Noteworthy changes in version 2.5.4 (2025-02-12)
================================================
[compared to version 2.5.3]

* gpg: New option --disable-pqc-encryption. [rG00c31f8b04]
* gpg: Fix --quick-add-key for Weierstrass ECC with usage given. [T7506]
* gpg: Fix handling with no CRC armor. [T7071]
* gpg: New private Kyber keys are now cross-referenced using a new Link attribute. [T6638]
* gpg: Fix an import problem with keys having another primary key as a subkey. [T7527]
* gpgsm: Allow unattended PKCS#12 export without passphrase. [rG159e801043]
* gpgsm: Allow CSR generation with an unprotected key. [rG89055f24f4]
* agent: New option --change-std-env-name. [T7522]
* agent: Fix ssh-agent's request_identities for skipped Brainpool keys. [rG2469dc5aae]
* Do not package zlib and bzip2 object files in a Speedo release build. [T7442]

Release-info: https://dev.gnupg.org/T7480
2025/03/08(土) 12:45:40.32
GnuPG 2.5.5 (テスト版)

Noteworthy changes in version 2.5.5 (2025-03-07)
================================================
[compared to version 2.5.4]

* gpg: Fix a verification DoS due to a malicious subkey in the keyring. [T7527]
* dirmngr: Fix possible hangs due to blocking connection requests. [T6606, T7434]
* w32: On socket nonce mismatch close the socket. [T7434]
* w32: Print more detailed diagnostics for IPC errors.
* GPGME is not any more distributed with the Windows installer. Please install gpg4win to get gpgme version.

Release-info: https://dev.gnupg.org/T7530
2025/03/08(土) 12:46:52.02
https://www.gpg4win.org/version5.html

Gpg4win開発版はこちらからダウンロード可能
(今リンクされてる5.0.0-beta103に含まれてるのはGnuPG 2.5.4なので注意)
2025/03/11(火) 14:55:59.81
Gpg4win 5.0.0-beta145
これにはGnuPG 2.5.5が入ってる
2025/05/09(金) 22:20:00.42
GnuPG 2.5.6 (テスト版) & Gpg4win 5.0.0-beta190

Noteworthy changes in version 2.5.6 (2025-05-08)
================================================
[compared to version 2.5.5]

* gpg: Add a flag to the filter expressions for left anchored substring match. [rGc12b7d047e]
* gpg: New list option "show-trustsig" to avoid resorting to colon mode for this info. [rG41d6ae8f41]
* gpg: New command --quick-tsign-key to create a trust signature. [rGd90b290f97]
* gpg: New keygen parameter "User-Id". [rGcfd597c603]
* gpg: New list options "show-trustsig". [rGrG41d6ae8f41]
* gpg: Fix double free of internal data in no-sig-cache mode [T7547]
* gpg: Signatures from revoked or expired keys do not anymore show up as missing keys. Fixes regression in 2.5.5. [T7583]
* gpgsm: Extend --learn-card by an optional s/n argument. [T7379]
* gpgsm: Skip expired certificates when selection a certificate by subject. [rG4cf83273e8]
* card: New command "ll" as alias for "list --cards". [rGd6ee7adebe]
* scd: Fix posssible lockup on Windows due to a lost select result. [rGa7ec3792c5]
* scd:p15: Accept P15 cards with a zero-length label. [rGdb25aa9887]
* keyboxd: Use case-insensitive search for mail addresses. [T7576]
* dirmngr: Fix a problem in libdns related to an address change from 127.0.0.1. [T4021]
* gpgconf: Fix reload and kill of keyboxd. [T7569]
* Fix logic for certain recsel conditions. [rG8968e84903]
* Add Solaris support to get_signal_name. [T7638]
* Fix build error of the test shell on AIX. [T7632]

Release-info: https://dev.gnupg.org/T7586
2025/05/27(火) 14:37:05.93
Gpg4win 4.4.1

深刻なセキュリティ脆弱性の修正のためアップデート推奨
(入ってるGnuPG 2.4.8は公式にはまだリリースアナウンスされていないバージョン)

About the vulnerability:
Embedded malicious fonts in a PDF file may lead to code execution in Okular. CVSS Base Score: 8.1 (v3.1)
Details https://euvd.enisa.europa.eu/enisa/EUVD-2025-6367 (alternative ids: CVE-2025-27363, GHSA-g8qj-jv5h-78cp)

There are other good things in Gpg4win 4.4.1, for example
* improvements in the Outlook Add-in (GpgOL)
* a better Kleopatra
* GnuPG upgraded to v2.4.8

Check out the https://www.gpg4win.org/change-history.html
2025/06/03(火) 09:22:28.77
GnuPG 2.5.7 (テスト版)

Noteworthy changes in version 2.5.7 (2025-06-02)
================================================
[compared to version 2.5.6]

* gpg: Allow updating a SHA-1 key certification w/o using the --force-sign-key option. [T7663]
* gpg: The group key flag has now been fully implemented. [rG8833a34bf0]
* gpg: Make combination of show-only-fpr-mbox and show-unusable-uid work. [rGd5a4a2dc89]
* gpg: Do not allow compressed key packets on import. [T7014]
* gpgsm: Allow an empty subject DN also during import. [T7171]
* agent: Recover the old behavior with max-cache-ttl=0. [T6681]
* agent: Fix ECC key on smartcard for composite KEM with PQC. [T7648]
* scd: Fix a harmless read buffer over-read in a function used by PKCS#15 cards. [T7662]
* gpg-mail-tube,wks: Support templates for mail content. [T7381]
* Use the KEM interface of Libgcrypt for encryption/decryption. [T7649]
* Fix a glitch in socket handling in Windows in case of a nonce mismatch. [rG645cf7d8fc]

Release-info: https://dev.gnupg.org/T7671

Gpg4win 最新ベータ版(5.0.0-beta190)に入ってるのはまだgpg 2.5.6
2025/06/03(火) 21:34:55.63
リリースアナウンスは出てないけど

https://www.gnupg.org/download/index.html
> GnuPG 2.4.8 2025-05-14

5/14付で安定版2.4.8が出てることになってる
2025/06/21(土) 01:06:13.08
GnuPG 2.5.8 (テスト版)

Noteworthy changes in version 2.5.8 (2025-06-20)
================================================
[compared to version 2.5.7]

* gpg: Show revocation reason with a standard -k listing. [T7083]
* gpg: Emit a revocation reason as comment in a "pub" record. [T7083]
* agent: Fix regression in 2.5.7 decrypting with a card based cv25519 key. [T7676]
* scd:openpgp: Fix a regression in exporting card based ed25519 ssh keys. [T7589]
* dirmngr: Do not require a keyserver for "gpg --fetch-key". [T7693]

Release-info: https://dev.gnupg.org/T7672

Gpg4win 最新ベータ版(5.0.0-beta190)に入ってるのはgpg 2.5.6
2025/07/02(水) 08:24:31.11
Gpg4win 5.0.0-beta336

https://www.gpg4win.org/version5.html

同梱のGnuPGも2.5.8になってる
2025/07/14(月) 23:15:18.50
GnuPG 2.5.9 & Gpg4win 5.0.0-beta345

Noteworthy changes in version 2.5.9 (2025-07-10)
================================================
[compared to version 2.5.8]

* gpg: Add the revocation reason to the sigclass of a "rev" line.
Regression in 2.5.7. [T7073]
* gpg: Do not show the non-standard secp256k1 curve in the menu to select the curve. It can however be specified using its name. [rG49a9171f63]
* gpg: Fix regression in using the secp256k1 curve. [T7698]
* dirmngr: New option --user-agent and send a default User-Agent of "GnuPG/2.6" for all HTTP requests. [T7715]

Release-info: https://dev.gnupg.org/T7695
2025/08/09(土) 15:39:44.49
リリースのアナウンスはないけどGnuPG 2.5.11 & Gpg4win 5.0.0-beta357 (どちらもテスト版)

https://www.gnupg.org/download/index.html
https://www.gpg4win.org/version5.html
2025/09/03(水) 08:03:32.24
GnuPG 2.5.12 (テスト版だけど "fully supported and thus ready for production use" と謳ってる)
Gpg4winの新しいベータ版はまだ出てない

Noteworthy changes in version 2.5.12 (2025-09-02)
=================================================
[compared to version 2.5.11]

* gpg: New options --[no-]auto-key-upload. [T7333]
* gpg: Keys send to an LDAP server are now first updated from that server. New keyserver option "no-update-before-send" to disable this feature. [T7730]
* gpg: Disable default compression for 7z compressed input. [rG53252628de]
* gpg: Fix a regression with composite PQC and ECC algos. [T7649]
* gpg: Fix the list of possible algos for --edit-key:addkey. [T7788]
* gpg: Allow to select the Kyber variants with --edit-key:addkey. [T7792]
* gpg: Avoid a second Pinentry pop-up for a configured ADSK during key generation. [T7491]
* gpg: Change the ADSK key binding time to use the current time. [T6882]
* gpgsm: Add option --no-qes-note and new trustlist flag "noconsent". [T7713]
* agent: Enable "relax" in the trustlist by default and add flag "norelax". [rG7b133027ae]
* agent: Fix a crash on Windows in the Putty support. [T7799]
* dirmgr: Support LDAP servers using a schema like the Windows LDS servers. [T7742]
* scd:openpgp: Support Yubikey attestation generation. [rG5ddfedf24a]
* gpgtar: Fix regression in end-of-archive detection. [T7757]

Release-info: https://dev.gnupg.org/T7756
2025/09/06(土) 12:57:53.01
Gpg4win 5.0.0-beta369

https://www.gpg4win.org/version5.html

同梱のGnuPGは2.5.12
2025/10/22(水) 23:29:33.55
GnuPG 2.5.13

Noteworthy changes in version 2.5.13 (2025-10-22)
=================================================
[compared to version 2.5.12]

* gpg: Fix de-vs compliance with OCB and additional password. [T7804]
* gpg: Detect duplicate keys with --add-recipients. [T1825]
* gpg: Take care about the prefix for cv25519 encryption. [T7649]
* gpg: Avoid potential downgrade to SHA1 in 3rd party key signatures. [rGdb9705ef59]
* gpg: Error out on unverified output for non-detached signatures. [rG8abc320f2a]
* gpgsm: Use KEM interface for en- and decryption. [T7811,T7845]
* gpgsm: Fix delete and store certificate locking glitches. [T7855]
* gpg,gpgsm: Run keybox compression only when there are no other users. [T7855]
* gpg,gpgsm: Improve keybox closing and locking order on read and write. [T7855]
* gpg,gpgsm: Always use share mode read-write for the keybox file access. [T7829]
* scd:openpgp: Fix an oddity in changing the PIN. [T7840]
* dirmngr: New LDAP keyserver flag "upload". [T7866]
* agent: Retry private key deletion in case of sharing violations for up to 400ms. [T7863]
* Take care of a possible race on daemon startup under Windows. [T7829]
* Improve file renaming on Windows in case of a sharing violation error. [T7829]

Release-info: https://dev.gnupg.org/T7801
2025/10/22(水) 23:30:37.08
Gpg4win 5.0.0-beta395

https://www.gpg4win.org/version5.html
レスを投稿する

5ちゃんねるの広告が気に入らない場合は、こちらをクリックしてください。

ニューススポーツなんでも実況