Occasional invalid RSA signature under repeated signing (gpg 2.3.7 / libgcrypt 1.10.1)

NIIBE Yutaka gniibe at fsij.org
Tue Jul 14 09:26:57 CEST 2026


Hello,

Diggory Blake <diggsey at googlemail.com> wrote:
> That does seem to be the issue: my `p` and `q` are stored in the wrong order.

Our ticket for this problem is:

    https://dev.gnupg.org/T8171

(It's not limited to macOS.)

Our fixes are:

   - library side: check_secret_key validates p < q with
     ENABLE_STRONGER_CHECK.

   - application side: When importing, gpg-agent rejects such a key.

> Do you know what the implications are for historical commits I've
> signed?

Some of your signatures in historical commits are perhaps invalid.  By
observing failure rate, some information of private key would be leaked
somehow.

We considered: It would be good if there is a tool to detect such a key
with this problem of wrong p and q, and to fix the key (automatically)
so that it will work correctly.

I don't know the detail of the implication exactly.  I don't know well
about how such a key is dangerous.  Possibly, a kind tool would
(wrongly) encourage keep using dangerous keys.

So, our fixes are only those two; a possible fix of library (when
ENABLE_STRONGER_CHECK is enabled at build time) and a fix in
application.
-- 



More information about the Gnupg-devel mailing list