summaryrefslogtreecommitdiffstats
AgeCommit message (Collapse)Author
2024-04-19guide: Add missing license.mainNeal H. Walfield
- License the guide under the CC-BY-SA-4.0. - Fixes #1101.
2024-04-17openpgp: Introduce a constructor for ComponentBundle.Justus Winter
2024-04-17openpgp: Use public accessors in tests.Justus Winter
2024-04-17openpgp: Move ComponentBundles to cert::bundles.Justus Winter
2024-04-17doc: Mention the bug bounty program.Neal H. Walfield
- Mention the bug bounty program in the security vulnerabilities guide. - Link to the security vulnerabilities guide from the main readme.
2024-04-16openpgp: Support NistP521 using the RustCrypto backend.Justus Winter
2024-04-16openpgp: Support NistP384 using the RustCrypto backend.Justus Winter
2024-04-16openpgp: Refactor imports.Justus Winter
2024-04-16openpgp: Remove debugging remnant.Justus Winter
2024-04-15openpgp: Fix adding authenticated issuer information.Justus Winter
- When we discover issuer information not yet recorded in the signature, we insert this information when we get the chance. However, previously this failed to set the authenticated flag because it was cleared in SubpacketArea::add. Fix that.
2024-04-15openpgp: Simplify intra-project link.Justus Winter
2024-04-15openpgp: Improve documentation.Justus Winter
2024-04-15openpgp: Improve documentation.Justus Winter
2024-04-12buffered-reader: Release v1.3.1.buffered-reader/v1.3.1Neal H. Walfield
2024-04-12buffered-reader: Add a test.Neal H. Walfield
- Add a test to ensure that the `impl BufferedReader<C> for &mut T` also works with cookies.
2024-04-11openpgp: Release 1.20.0.openpgp/v1.20.0Justus Winter
2024-04-11ci: Update clippy to Rust 1.70.0.Justus Winter
2024-04-11Update base64.Justus Winter
2024-04-11Update all dependencies.Justus Winter
- Except for clap (which doesn't built using our MSRV), and anyhow, because of a severe performance regression on Windows: https://github.com/dtolnay/anyhow/issues/347
2024-04-11openpgp: Move the default v3 signature cutoff to 2021.Justus Winter
- Previously, we rejected v3 signatures after 2007 by default. However, Panu Matilainen observed: GnuPG appears to have only switched to v4 by default in version 1.4.8, released on 2007-12-20. Before that was in the hands of users would've been many more months, and in case of users of enterprise distro users, years. For example, RHEL 5 (initially released in early 2007) had 1.4.5 still at it's end-of-life in 2017 (and extended life end at 2020) so users on that would've still been merrily (and probably unknowingly) producing v3 signatures at 2017. - RHEL 5 support ended 2020-11-30. Cryptographically, there is nothing wrong with them. Reject v3 signatures only after 2021-02-01. - Fixes #948.
2024-04-11Remove the hidden Makefile.Justus Winter
- Fixes #664.
2024-04-11ci: Run the tests without the hidden Makefile.Justus Winter
2024-04-11ci: Run all tests on Debian Trixie.Justus Winter
- Previously, only the supported-algorithms example was executed.
2024-04-11openpgp: Align definition of self-signature.Justus Winter
- Fixes f9e15b3974b71aed87871999014b901a5aee03a8 by also applying the change to the low-level cert parser. - Fixes #1084.
2024-04-11openpgp-policy: Update certs.Justus Winter
2024-04-10openpgp: Add S2K::Implicit.Justus Winter
- For historical reasons, if the S2K usage octet is not a known S2K mechanism, the octet denotes a symmetric algorithm used to encrypt the key material with. In this case, the symmetric key is the MD5 sum over the password. See section 5.5.3. Secret-Key Packet Formats of RFC4880.While this is obviously not a great choice, it is no worse than `S2K::Simple { hash: MD5 }`, since it is equivalent to that. - Model this by adding a new S2K variant. - Notably, this fixes handling of packets with unknown S2K mechanisms. Under the model of RFC4880, which we implement, any unknown S2K mechanism is an implicit S2K, where the usage octet denotes an unsupported symmetric algorithm. Using this will fail, but we now can parse and serialize it correctly, and with them the secret key packets they come in. - Fixes #1095.
2024-04-10openpgp: Improve tracing, trace parsing failures.Justus Winter
2024-04-08openpgp: Fix documentation.Justus Winter
- There is no `Curve::Private`.
2024-04-08openpgp: Add Signature::verify_signature.Justus Winter
- Similar to Signature::verify, but doesn't constrain to document signatures. This allows for faster verification of third-party signatures on certs, taking advantage of the fact that we computed the digest during certificate canonicalization.
2024-03-24openpgp: Remember digests during certificate canonicalization.Justus Winter
- We have done the hashing, and the cert structure provides enough context to do the verification without doing the hashing again.
2024-03-24openpgp: Stash the digest on successful signature verifications.Justus Winter
2024-03-24openpgp: Rework signature verification.Justus Winter
- Introduce a new function, Signature::verify_digest_internal, that only uses concrete types to reduce monomorphization, handles the stashed computed digest, and takes an optionally owned signature digest.
2024-03-22openpgp: Optimize RawCert::primary_key.Justus Winter
- During parsing, we parse the primary key. Keep that around for later instead of caching only the fingerprint. Simplify accessors accordingly.
2024-03-21openpgp: Fix documentation.Justus Winter
2024-03-21openpgp: Improve tracing.Justus Winter
2024-03-16openpgp: Avoid heap allocation when hashing signatures.Justus Winter
- Notably, this is done during certificate canonicalization. This is expensive as-is, let's keep the allocator out of it.
2024-03-16openpgp: Avoid heap allocation when hashing keys.Justus Winter
- Notably, this is done during certificate canonicalization. This is expensive as-is, let's keep the allocator out of it.
2024-03-13openpgp: Include the reason for why a primary key is unsupported.Justus Winter
2024-03-10ipc: Release 0.34.1.ipc/v0.34.1Neal H. Walfield
2024-03-10ci: Also test the sequoia-ipc and sequoia-net crates on Windows.Neal H. Walfield
2024-03-10ipc: Add missing import in Windows code.Neal H. Walfield
2024-03-09ipc: Release 0.34.0.ipc/v0.34.0Neal H. Walfield
2024-03-09Update dependencies.Neal H. Walfield
2024-03-09Update certificates in openpgp-policy.toml.Neal H. Walfield
2024-03-09ipc: Improve error message.Neal H. Walfield
- If we can't open the socket, include the socket's file name as context.
2024-03-06ipc: Add callbacks to simplify tracing client-server interactions.Justus Winter
- To simplify debugging client-server interactions, add tracing callbacks to `Assuan`.
2024-03-06ipc: Update Client::send_simple with the version from the chameleon.Neal H. Walfield
- The Chameleon copied and improved `Client::send_simple`. Update the copy here. See: https://gitlab.com/sequoia-pgp/sequoia-chameleon-gnupg/-/blob/70802790d7d95c0084a8fea71a0836b3efc39910/src/agent.rs#L182
2024-03-06ipc: Don't panic if the server disappears, return an error.Neal H. Walfield
- If the server exits, we set the connection's state to `WriteState::Dead`. - When sending a message, don't panic if the connection's state is `WriteState::Dead`. Instead, return an error message.
2024-03-04Retire dvzrv and wiktor.Neal H. Walfield
- dvzrv and wiktor left the project, rescind their authorizations. - See https://gitlab.com/sequoia-pgp/sequoia-web/-/merge_requests/47 .
2024-02-26ci: make msvc jobs print env varsDevan Carpenter