Commit Graph

25 Commits

Author SHA1 Message Date
reinhard
64f02cb85e increment PKGNAME; thx naddy@ for pointing out 2000-12-23 16:48:06 +00:00
reinhard
5e2899097a Security update, from the original patch:
It has been pointed out that there is another bug in the signature
verification code of GnuPG.

         * This can easily lead to false positives *

All versions of GnuPG released before today are vulnerable!

To check a detached singature you normally do this:

  gpg --verify foo.sig foo.txt

The problem here is that someone may replace foo.sig with a standard
signature containing some arbitrary signed text and its signature,
and then modify foo.txt - GnuPG does not detect this - Ooops.

The solution for this problem ist not easy and needs a change in the
semantics of the --verify command: It will not any longer be
possible to do this:

  gpg --verify foo.sig <foo.txt

Instead you have to use this

  gpg --verify foo.sig - <foo.txt

The difference here is that gpg sees 2 files on the command lines
and thereby knows that it should check a detached signature.  We
really need this information and there is no way to avoid that
change, sorry.  You should make sure that you never use the first
form, because this will lead to false positives when foo.sig is not
a detached signature - gnupg does detect the other case and warns
you, but this is not sufficient.  If you use GnuPG from other
applications, please change it.

ok markus@
2000-12-23 15:20:59 +00:00
markus
07aae00303 security update, since 1.0.3 does not detect modifications of files with multiple signatures 2000-10-30 12:52:32 +00:00
espie
aff2e05260 Maintainer 2000-10-22 17:02:40 +00:00
aaron
41a5d86f80 Fix some pkg/COMMENT formatting:
- Decapitalize first letter of comment if appropriate.
- Remove trailing blank lines.
- Remove punctuation.
- Remove version numbers which are often overlooked when updating.
- espie@ ok
2000-09-22 14:55:55 +00:00
brad
1ea6743d0d upgrade to gnupg 1.0.3 2000-09-19 13:18:50 +00:00
brad
da9686bef0 remove old man page; pointed out by Fabian Kroenner <escher@spoiled.org> 2000-08-12 18:21:45 +00:00
brad
144aeba379 upgrade to gnupg 1.0.2 2000-07-13 19:39:24 +00:00
brad
1f8afbaa3d - add HOMEPAGE
- GNU_CONFIGURE -> CONFIGURE_STYLE
- remove license type
- mkdir -> ${INSTALL_DATA_DIR}
- add @comment with RCS id to PLIST
2000-06-29 06:06:31 +00:00
espie
0fd05ef2ce Move all NEED_VERSION right after CATEGORY 2000-03-24 22:11:32 +00:00
espie
6f43c05443 Fake. Leave gnu-make along for now, it suspiciously looks like an OpenBSD
make bug.
2000-03-11 02:54:18 +00:00
turan
504f314d16 espie will not shut up about this, DISTF -> DISTFILES, PKG -> PACKAGE 2000-02-15 05:03:51 +00:00
turan
1574b9aa2e gpl licenses 2000-02-12 08:02:07 +00:00
brad
2cddf37962 upgrade to gnupg 1.0.1 (minus the html documentation which does not come
with the distribution anymore it seems)
1999-12-23 02:54:24 +00:00
brad
e0d38f42fe remove unnecessary CONFIGURE_ENV tag; ok'd by markus@ 1999-11-30 23:13:52 +00:00
brad
b3f9c43fa6 - change maintainers email address to markus@openbsd.org
- cleanup Makefile
1999-11-30 02:54:31 +00:00
brad
f79860d09b upgrade to gnupg 1.0.0; maintainer 1999-09-09 02:54:30 +00:00
brad
e8ddcc28e7 upgrade to GNUpg 0.9.11 1999-09-04 21:54:06 +00:00
brad
37e77d5814 upgrade to gnupg 0.9.10 1999-08-04 22:41:02 +00:00
brad
040cb584ca upgrade to GNUPG 0.9.9; -
Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
1999-07-25 23:33:41 +00:00
brad
1f6d884e7b upgrade to GNUpg 0.9.8 1999-06-28 20:05:41 +00:00
brad
f22308a351 change SEPARATE_BUILD= yes -> concurrent 1999-06-03 13:49:50 +00:00
brad
001ae99fd7 upgrade to GnuPG 0.9.7 1999-05-24 20:55:44 +00:00
brad
8b5d32c736 upgrade to GnuPG 0.9.6 1999-05-08 17:38:40 +00:00
brad
4a7daafbb4 add gnupg port; markus.friedl@informatik.uni-erlangen.de
-
GNU privacy guard - a free PGP replacement.
1999-04-23 03:16:05 +00:00