Re: FIPS-mode keygen fails to include preferences subpackets

Werner Koch via Gnupg-devel <[email protected]> Fri, 24 Oct 2025 16:23:41 +0200
Newsgroups gmane.comp.encryption.gpg.devel
Message-ID <[email protected]>
Hi Bill,

your mail was lingering around in my folder for too long.  I now
implemented your suggestion:

> Locally we're using the simple fix, but a better solution might be to
> 1) add "S2" conditionally, similar to how AES is treated, and 2)
> refactor the second half of keygen_set_std_prefs to continue
> processing algorithms, only failing later if none were matched in a
> set. I'd be happy to craft that patch if that seems like the better

Thanks.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

_______________________________________________
Gnupg-devel mailing list
[email protected]
https://lists.gnupg.org/mailman/listinfo/gnupg-devel
openpgp-digital-signature.asc (application/pgp-signature, 284 B)
-----BEGIN PGP SIGNATURE-----

iJ8EARYKAEcWIQSHd0YfKgdOvEgNNZQZzByeCFsQegUCaPuL7hsUgAAAAAAEAA5t
YW51MiwyLjUrMS4xMSwyLDINHHdrQGdudXBnLm9yZwAKCRAZzByeCFsQehNYAP9J
7+G9B8mwX6k0ofxNgsY+HFxJLdTaXeQjenWplC6W+gEAobgGhLjPYm+3GjhXpOQt
sL3mN0TFCAlmJ5jQd6v64g4=
=3zTv
-----END PGP SIGNATURE-----