Debian Bug report logs -
#386107
debsign don't use gpg agent/pinentry
Reported by: Julien Danjou <acid@debian.org>
Date: Tue, 5 Sep 2006 11:03:01 UTC
Severity: normal
Tags: moreinfo, unreproducible
Merged with 322932
Found in version gnupg-agent/1.9.15-6
Done: Xavier Luthi <xavier@caroxav.be>
Bug is archived. No further changes may be made.
Toggle useless messages
Report forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Acknowledgement sent to Julien Danjou <acid@debian.org>:
New Bug report received and forwarded. Copy sent to Julian Gilbey <jdg@debian.org>.
(full text, mbox, link).
Message #5 received at submit@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
Package: devscripts
Version: 2.9.21
Severity: normal
Hi,
When I run debsign so sign my package, it fails because I set
use-gpg-agent in my configuration. It does not seem to launch pinentry.
-- System Information:
Debian Release: testing/unstable
APT prefers unstable
APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)
Shell: /bin/sh linked to /bin/bash
Kernel: Linux 2.6.17-2-686
Locale: LANG=C, LC_CTYPE=fr_FR.UTF-8 (charmap=UTF-8)
Versions of packages devscripts depends on:
ii debianutils 2.17 Miscellaneous utilities specific t
ii dpkg-dev 1.13.22 package building tools for Debian
ii libc6 2.3.6.ds1-4 GNU C Library: Shared libraries
ii perl 5.8.8-6.1 Larry Wall's Practical Extraction
ii sed 4.1.5-1 The GNU sed stream editor
Versions of packages devscripts recommends:
ii fakeroot 1.5.10 Gives a fake root environment
-- no debconf information
--
Julien Danjou
// Λ̊ <julien@danjou.info> http://julien.danjou.info
// 9A0D 5FD9 EB42 22F6 8974 C95C A462 B51E C2FE E5CD
// Ferns will rule the world.
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Message #8 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
also sprach Julien Danjou <acid@debian.org> [2006.09.05.1219 +0200]:
> When I run debsign so sign my package, it fails because I set
> use-gpg-agent in my configuration. It does not seem to launch pinentry.
FWIW, this works for me, but I set
use-agent
in ~/.gnupg/gpg.conf. I don't know of a use-gpg-agent option.
ii gnupg 1.4.5-1 GNU privacy guard - a free PGP replacement
ii gnupg-agent 1.9.20-2 GNU privacy guard - password agent
ii pinentry-gtk2 0.7.2-3 GTK+-2-based PIN or pass-phrase entry dialog
Does gpg-agent work for you if you just call
echo test | gpg --sign
?
--
.''`. martin f. krafft <madduck@debian.org>
: :' : proud Debian developer, author, administrator, and user
`. `'` http://people.debian.org/~madduck - http://debiansystem.info
`- Debian - when you have better things to do than fixing systems
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Acknowledgement sent to Julien Danjou <acid@debian.org>:
Extra info received and forwarded to list. Copy sent to Julian Gilbey <jdg@debian.org>.
(full text, mbox, link).
Message #13 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
On Tue, Sep 05, 2006 at 01:33:19PM +0200, martin f krafft wrote:
> FWIW, this works for me, but I set
>
> use-agent
>
> in ~/.gnupg/gpg.conf. I don't know of a use-gpg-agent option.
Sorry, I have use-agent too, not use-gpg-agent :-)
> ii gnupg 1.4.5-1 GNU privacy guard - a free PGP replacement
> ii gnupg-agent 1.9.20-2 GNU privacy guard - password agent
> ii pinentry-gtk2 0.7.2-3 GTK+-2-based PIN or pass-phrase entry dialog
ii gnupg 1.4.5-1 GNU privacy guard - a free PGP replacement
ii gnupg-agent 1.9.20-2 GNU privacy guard - password agent
ii pinentry-curses 0.7.2-3 curses-based PIN or pass-phrase entry dialog
ii pinentry-gtk2 0.7.2-3 GTK+-2-based PIN or pass-phrase entry dialog
> Does gpg-agent work for you if you just call
>
> echo test | gpg --sign
No:
You need a passphrase to unlock the secret key for
user: "Julien Danjou <julien@danjou.info>"
1024-bit DSA key, ID C2FEE5CD, created 2002-02-18
gpg: cancelled by user
gpg: no default secret key: bad passphrase
gpg: signing failed: bad passphrase
But if it works for you, it might mean it's a configure issue on my
side. :-/
Thanks for your attention.
Cheers,
--
Julien Danjou
.''`. Debian Developer
: :' : http://julien.danjou.info
`. `' http://people.debian.org/~acid
`- 9A0D 5FD9 EB42 22F6 8974 C95C A462 B51E C2FE E5CD
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Message #16 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
also sprach Julien Danjou <acid@debian.org> [2006.09.05.1413 +0200]:
> gpg: no default secret key: bad passphrase
i think this may be your problem. I have
default-key 330c4a75
encrypt-to 330c4a75
in my ~/.gnupg/gpg.conf file, and I always pass -k to debsign.
--
.''`. martin f. krafft <madduck@debian.org>
: :' : proud Debian developer, author, administrator, and user
`. `'` http://people.debian.org/~madduck - http://debiansystem.info
`- Debian - when you have better things to do than fixing systems
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Acknowledgement sent to Julien Danjou <acid@debian.org>:
Extra info received and forwarded to list. Copy sent to Julian Gilbey <jdg@debian.org>.
(full text, mbox, link).
Message #21 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
On Tue, Sep 05, 2006 at 02:40:24PM +0200, martin f krafft wrote:
> i think this may be your problem. I have
>
> default-key 330c4a75
> encrypt-to 330c4a75
>
> in my ~/.gnupg/gpg.conf file, and I always pass -k to debsign.
Still fails. By the way, I also use -k to sign. But echo test | gpg
--sign seems to try to use the good key but does not launch pinentry,
even if my passphrase was forgotten
Cheers,
--
Julien Danjou
.''`. Debian Developer
: :' : http://julien.danjou.info
`. `' http://people.debian.org/~acid
`- 9A0D 5FD9 EB42 22F6 8974 C95C A462 B51E C2FE E5CD
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Julian Gilbey <jdg@debian.org>:
Bug#386107; Package devscripts.
(full text, mbox, link).
Acknowledgement sent to Julian Gilbey <jdg@polya.uklinux.net>:
Extra info received and forwarded to list. Copy sent to Julian Gilbey <jdg@debian.org>.
(full text, mbox, link).
Message #26 received at 386107@bugs.debian.org (full text, mbox, reply):
reassign 386107 gnupg
thanks
On Tue, Sep 05, 2006 at 04:49:25PM +0200, Julien Danjou wrote:
> On Tue, Sep 05, 2006 at 02:40:24PM +0200, martin f krafft wrote:
> > i think this may be your problem. I have
> >
> > default-key 330c4a75
> > encrypt-to 330c4a75
> >
> > in my ~/.gnupg/gpg.conf file, and I always pass -k to debsign.
>
> Still fails. By the way, I also use -k to sign. But echo test | gpg
> --sign seems to try to use the good key but does not launch pinentry,
> even if my passphrase was forgotten
So I'm going to reassign this to gnupg as it's clearly not a
devscripts issue.
Julian
Bug reassigned from package `devscripts' to `gnupg'.
Request was from Julian Gilbey <jdg@polya.uklinux.net>
to control@bugs.debian.org.
(full text, mbox, link).
Information forwarded to debian-bugs-dist@lists.debian.org, James Troup <james@nocrew.org>:
Bug#386107; Package gnupg.
(full text, mbox, link).
Acknowledgement sent to Micah Anderson <micah@riseup.net>:
Extra info received and forwarded to list. Copy sent to James Troup <james@nocrew.org>.
(full text, mbox, link).
Message #33 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
I also have this problem, and I have the same configuration that
madduck has.
I have pinentry-curses and gnupg-agent installed and am unable to sign
packages with debsign when I'm using an agent.
micah
[signature.asc (application/pgp-signature, inline)]
Bug reassigned from package `gnupg' to `gnupg-agent'.
Request was from Micah Anderson <micah@debian.org>
to control@bugs.debian.org.
(Thu, 14 Feb 2008 02:21:04 GMT) (full text, mbox, link).
Merged 322932 386107.
Request was from Micah Anderson <micah@debian.org>
to control@bugs.debian.org.
(Thu, 14 Feb 2008 02:21:06 GMT) (full text, mbox, link).
Information forwarded to debian-bugs-dist@lists.debian.org, Eric Dorland <eric@debian.org>:
Bug#386107; Package gnupg-agent.
(full text, mbox, link).
Acknowledgement sent to Eric Dorland <eric@kuroneko.ca>:
Extra info received and forwarded to list. Copy sent to Eric Dorland <eric@debian.org>.
(full text, mbox, link).
Message #42 received at 386107@bugs.debian.org (full text, mbox, reply):
[Message part 1 (text/plain, inline)]
> I also have this problem, and I have the same configuration that
> madduck has.
> I have pinentry-curses and gnupg-agent installed and am unable to sign
> packages with debsign when I'm using an agent.
Have you tried setting the GPG_TTY environment as indicated in the manpage?
--
Eric Dorland <eric@kuroneko.ca>
ICQ: #61138586, Jabber: hooty@jabber.com
[signature.asc (application/pgp-signature, inline)]
Information forwarded to debian-bugs-dist@lists.debian.org, Eric Dorland <eric@debian.org>:
Bug#386107; Package gnupg-agent.
(full text, mbox, link).
Acknowledgement sent to intrigeri@boum.org:
Extra info received and forwarded to list. Copy sent to Eric Dorland <eric@debian.org>.
(full text, mbox, link).
Message #47 received at 386107@bugs.debian.org (full text, mbox, reply):
Hello,
I have this problem too.
> Have you tried setting the GPG_TTY environment as indicated in
> the manpage?
I did.
My setup:
- gpg-agent is running
- $GPG_AGENT_INFO is ok
- $GPG_TTY is ok
- $DISPLAY is unset
- running in GNU Screen, inside a VServer, and over SSH
- /usr/bin/pinentry links to /etc/alternatives/pinentry, itself
linking to /usr/bin/pinentry-curses
- ~/.gnupg/gpg-agent.conf contains:
pinentry-program /usr/bin/pinentry
default-cache-ttl 3600
- non-comment lines in ~/.gnupg/gpg.conf are:
default-key FD586E52
lock-once
keyserver x-hkp://subkeys.pgp.net
use-agent
- the relevant test output:
$ echo test | gpg -vv --sign
You need a passphrase to unlock the secret key for
user: "intrigeri <intrigeri@boum.org>"
1024-bit DSA key, ID FD586E52, created 2008-07-13
gpg: cancelled by user
gpg: no default secret key: bad passphrase
gpg: signing failed: bad passphrase
Bye,
--
<intrigeri@boum.org>
| gnupg key @ https://gaffer.ptitcanardnoir.org/intrigeri/intrigeri.asc
| Did you exchange a walk on part in the war
| for a lead role in the cage?
Information forwarded to debian-bugs-dist@lists.debian.org, Eric Dorland <eric@debian.org>:
Bug#386107; Package gnupg-agent.
(full text, mbox, link).
Acknowledgement sent to intrigeri@boum.org:
Extra info received and forwarded to list. Copy sent to Eric Dorland <eric@debian.org>.
(full text, mbox, link).
Message #52 received at 386107@bugs.debian.org (full text, mbox, reply):
> My setup:
> - gpg-agent is running
> - $GPG_AGENT_INFO is ok
> - $GPG_TTY is ok
> - $DISPLAY is unset
> - running in GNU Screen, inside a VServer, and over SSH
> - /usr/bin/pinentry links to /etc/alternatives/pinentry, itself
> linking to /usr/bin/pinentry-curses
In case there are people banging their heads against this bug...
I was able to workaround this, thanks to the following ingredients:
- enabling SSH X11 forwarding
- switching to pinentry-gtk2
Yet the bug remains.
Bye,
--
intrigeri <intrigeri@boum.org>
Information forwarded
to debian-bugs-dist@lists.debian.org, Eric Dorland <eric@debian.org>:
Bug#386107; Package gnupg-agent.
(Wed, 03 Dec 2008 13:12:08 GMT) (full text, mbox, link).
Acknowledgement sent
to Xavier Luthi <xavier@caroxav.be>:
Extra info received and forwarded to list. Copy sent to Eric Dorland <eric@debian.org>.
(Wed, 03 Dec 2008 13:12:08 GMT) (full text, mbox, link).
Message #57 received at 386107@bugs.debian.org (full text, mbox, reply):
tags 386107 + moreinfo
thanks
Hi,
For those having this bug, can you please send more information?
It would be fine to start gpg-agent with verbose and debug
options activated: "gpg-agent --daemon -vv --debug-all"
Then, it would be useful to have:
* the exact values of $GPG_TTY and $GPG_AGENT_INFO
* the output of 'ps -ef |grep gpg-agent'
* the output of 'echo test |gpg -s'
Thanks for your feedback!
Cheers,
Xavier
Tags added: moreinfo
Request was from Xavier Luthi <xavier@caroxav.be>
to control@bugs.debian.org.
(Wed, 03 Dec 2008 13:12:11 GMT) (full text, mbox, link).
Information forwarded
to debian-bugs-dist@lists.debian.org, Eric Dorland <eric@debian.org>:
Bug#386107; Package gnupg-agent.
(Fri, 02 Jan 2009 10:27:02 GMT) (full text, mbox, link).
Acknowledgement sent
to Xavier Luthi <xavier@caroxav.be>:
Extra info received and forwarded to list. Copy sent to Eric Dorland <eric@debian.org>.
(Fri, 02 Jan 2009 10:27:02 GMT) (full text, mbox, link).
Message #64 received at 386107@bugs.debian.org (full text, mbox, reply):
tags 386107 + unreproducible
Hi,
I'm tagging this bug as unreproducible as no feedback has been
received for one month.
Here is how it works on my host:
* ~/.bash_profile is sourcing my .bashrc:
if [ -f ~/.bashrc ]; then
. ~/.bashrc
fi
* ~/.bahrc has the following lines:
if test -f $HOME/.gpg-agent-info && kill -0 `cut -d: -f 2 $HOME/.gpg-agent-info` 2>/dev/null; then
export `cat $HOME/.gpg-agent-info`
else
eval `gpg-agent --daemon --quiet --write-env-file $HOME/.gpg-agent-info`
fi
export GPG_TTY=$(tty)
As a result, here is what I have in a console (with or without
screen):
$ echo $GPG_TTY
/dev/pts/1
$ echo $GPG_AGENT_INFO
/tmp/gpg-5vKQhe/S.gpg-agent:8675:1
$ ps -ef |grep gpg-agent |grep -v grep
xavier 8675 1 0 11:21 ? 00:00:00 gpg-agent --daemon --quiet --write-env-file /home/xavier/.gpg-agent-info
$ echo test |gpg -s
--> The string 'test' is signed with my private key.
If no feedback is received on this bug within one week, I'll close it.
Cheers,
Xavier
Tags added: unreproducible
Request was from Xavier Luthi <xavier@caroxav.be>
to control@bugs.debian.org.
(Fri, 02 Jan 2009 10:27:03 GMT) (full text, mbox, link).
Reply sent
to Xavier Luthi <xavier@caroxav.be>:
You have taken responsibility.
(Tue, 10 Feb 2009 14:24:06 GMT) (full text, mbox, link).
Notification sent
to Julien Danjou <acid@debian.org>:
Bug acknowledged by developer.
(Tue, 10 Feb 2009 14:24:06 GMT) (full text, mbox, link).
Message #71 received at 386107-close@bugs.debian.org (full text, mbox, reply):
Package: gnupg-agent
Hi,
As I did not received feedback for more than a month, I'm closing
this bug.
Cheers,
Xavier
Reply sent
to Xavier Luthi <xavier@caroxav.be>:
You have taken responsibility.
(Tue, 10 Feb 2009 14:24:07 GMT) (full text, mbox, link).
Notification sent
to martin f krafft <madduck@debian.org>:
Bug acknowledged by developer.
(Tue, 10 Feb 2009 14:24:07 GMT) (full text, mbox, link).
Bug archived.
Request was from Debbugs Internal Request <owner@bugs.debian.org>
to internal_control@bugs.debian.org.
(Wed, 11 Mar 2009 07:28:55 GMT) (full text, mbox, link).
Send a report that this bug log contains spam.
Debian bug tracking system administrator <owner@bugs.debian.org>.
Last modified:
Sat Jan 6 16:42:10 2018;
Machine Name:
buxtehude
Debian Bug tracking system
Debbugs is free software and licensed under the terms of the GNU
Public License version 2. The current version can be obtained
from https://bugs.debian.org/debbugs-source/.
Copyright © 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd,
1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.