git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: Stable GnuPG interface, git should use GPGME

From
PLPeter Lebbing <peter@digitalbrains.com>
Date
Mar 22, 2017, 18:46 UTC
Message-ID
<bec6098f-3016-0a41-02b0-a4e541a66bc4@digitalbrains.com>
In-Reply-To
<87poh9p70n.fsf@wheatstone.g10code.de>
On 22/03/17 18:15, Werner Koch wrote:
> It actually does.  For the tasks git uses gpg you should not notice a
> difference in gpgme between any of these versions.

Bernhard wrote "interoperability problems between [...] key stores". I'm under the impression you are actually answering the question "can GPGME be used in the same way regardless of the GnuPG version" instead?

> Interoperability with 1.4 is a bit cumbersome if you often add new keys.
> However, "gpg --export | gpg1 --import" is not too complicated. 
This presumes that
1) Keys are only updated on the 2.1 side
2) Keys are not deleted
3) Secret keys are never changed
right?
1) is trivially solvable. 2) is trickier, but can be done.
3) is because GnuPG 1.4 cannot update a secret key at all. Adding a new
subkey fails with:

gpg: key DCDFDFA4: already in secret keyring gpg: Total number processed: 1 gpg: secret keys read: 1 gpg: secret keys unchanged: 1

You could delete before re-importing, but what if the key on the 1.4 side is actually the newer one? You'd lose all changes. Worst case: updates of a single key on both sides. But that is perhaps pushing the limit of sane use. Perhaps not, perhaps the user likes to use two different frontends which use different GnuPG versions as their backend.

Luckily, expiration extensions are picked up by just transferring the public key part of a secret key, so that does work.

Peter.
-- 
I use the GNU Privacy Guard (GnuPG) in combination with Enigmail.
You can send me encrypted mail if you want some privacy.
My key is available at <http://digitalbrains.com/2012/openpgp-key-peter>
Previous: Werner KochNext: Werner Koch
Message 8 of 19 in “Stable GnuPG interface, git should use GPGME”
  1. Bernhard E. ReiterMar 10, 2017
  2. Ævar Arnfjörð BjarmasonMar 10, 2017
  3. Michael J GruberMar 13, 2017
  4. Bernhard E. ReiterMar 13, 2017
  5. Michael J GruberMar 14, 2017
  6. Bernhard E. ReiterMar 17, 2017
  7. Werner KochMar 22, 2017
  8. Peter LebbingMar 22, 2017
  9. Werner KochMar 23, 2017
  10. Bernhard E. ReiterMar 23, 2017
  11. Werner KochMar 23, 2017
  12. Bernhard ReiterMar 13, 2017
  13. Linus TorvaldsMar 10, 2017
  14. Theodore Ts'oMar 10, 2017
  15. Bernhard E. ReiterMar 13, 2017
  16. Jeff KingMar 13, 2017
  17. brian m. carlsonMar 11, 2017
  18. Bernhard E. ReiterMar 13, 2017
  19. Christian NeukirchenMar 13, 2017

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.