Release of GnuPG 2.3.0

After three and a half years since the formation of the last significant branch, a new release of the GnuPG toolkit 2.3.0 (GNU Privacy Guard) has been introduced, compatible with OpenPGP (RFC-4880) and S/MIME standards, providing utilities for data encryption, working with digital signatures, key management, and access to public key repositories.

GnuPG 2.3.0 is positioned as the first release of a new codebase that includes the latest developments. GnuPG 2.2 is regarded as the stable branch, optimal for widespread use, which will be supported for at least until 2024. GnuPG 1.4 continues to be maintained as a classic series that consumes minimal resources, suitable for embedded systems, and compatible with outdated encryption algorithms.

Key innovations in GnuPG 2.3.0:

  • An experimental background process has been proposed featuring a key database implementation that uses SQLite database management system for storage, demonstrating faster key searches. To enable the new storage, activate the 'use-keyboxd' option in gpg.conf and gpgsm.conf.
  • A new utility gpg-card has been added, which can be used as a flexible interface for all supported types of smart cards.
  • A new background process tpm2d has been added, allowing the use of TPM 2.0 chips to protect private keys and perform encryption operations or create digital signatures on the TPM module side.
  • The default algorithms for public keys are now ed25519 and cv25519.
  • The use of algorithms with a 64-bit block size for encryption has been discontinued in gpg. The use of 3DES is prohibited, and AES is stated as the minimum supported algorithm. The restriction can be turned off using the '--allow-old-cipher-algos' option.
  • Support for AEAD modes of block encryption OCB and EAX has been added.
  • Support for version 5 of keys and digital signatures has been provided.
  • Support for X448 curves (ed448, cv448) has been added.
  • The use of group names in key lists is now allowed.
  • In gpg, verification results now depend on the '--sender' option and the identifier of the signature creator.
  • In gpg, gpgsm, gpgconf, gpg-card, and gpg-connect-agent, the '--chuid' option has been added to change the user identifier.
  • Options '--full-timestrings' (for date and time output), '--force-sign-key', and '--no-auto-trust-new-key' have been added to gpg.
  • Support for the deprecated PKA key discovery method has been discontinued, and associated options have been removed.
  • The ability to export Ed448 keys for SSH has been added in gpg.
  • Basic ECC support and the ability to create EdDSA certificates have been added in gpgsm.
  • In the agent, the use of the 'Label:' value in the key file is allowed for configuring the PIN code input prompt. Support for ssh-agent extensions for environment variables has been implemented.
  • The scd now has improved support for multiple card readers and tokens. It has implemented the ability to use several applications with a specific smart card. Support for PIV cards, Telesec Signature Cards v2.0, and Rohde&Schwarz Cybersecurity has been added. New options "—application-priority" and "—pcsc-shared" have been introduced.
  • The symcryptrun utility has been removed (an outdated wrapper over the external utility Chiasmus).
  • Full Unicode support in the command line has been implemented on the Windows platform.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster