more on read_s2k() for GnuTLS 2.4.1 (including "GNU dummy S2K")

Daniel Kahn Gillmor dkg-debian.org at fifthhorseman.net
Fri Aug 15 02:59:41 CEST 2008


On Thu 2008-08-14 04:19:01 -0400, Simon Josefsson wrote:

> Ouch.  

I know!  One day i'll be a better programmer, i hope :/

> FWIW, I think your goal is fine and it should be supported
> eventually.

Thanks, that's good to hear.

> I'm not sure this can go into 2.4.x, it seems like a somewhat large
> addition, although I'll let Nikos comment as well.  Maybe it could
> go in.

Hrm.  I don't think it's that big of a change (and it only affects a
people using GnuTLS for OpenPGP), but of course i'll defer to you and
Nikos.

> However, this certainly seems appropriate for 2.5.  Please create a
> patch for it, and I'll apply it.

The patch to enable parsing (but not decrypting) of locked secret keys
(including the "gnu-dummy" S2K option) against GnuTLS 2.5.3 is
attached, and seems to work for me.  Please let me know if you have
any problems or concerns with it.

> Btw, I want to get the 2.6.x release process started, I think we
> have enough new features in 2.5.x to be ready for a new stable
> release.  So maybe it isn't that important to get into 2.4.x if
> 2.6.x is release relatively soon.

I was hoping for 2.4.x because i'd love to see support for this in
debian lenny, but we likely won't be able to get a new version of
2.4.x into lenny at this point in debian's release cycle anyway.
Regardless of its status in 2.4.x, i'd certainly like to see this
behavior in 2.6.

Regards,

        --dkg

-------------- next part --------------
A non-text attachment was scrubbed...
Name: 20_functional_s2k_with_GNU_dummy_against_2.5.diff
Type: text/x-diff
Size: 3089 bytes
Desc: patch against 2.5.3, implementing read_s2k() and enabling support for gnu-dummy S2K extension
URL: </pipermail/attachments/20080814/16d9d252/attachment.diff>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 826 bytes
Desc: not available
URL: </pipermail/attachments/20080814/16d9d252/attachment.pgp>


More information about the Gnutls-devel mailing list