Release of GnuPG 2.4.0

After five years of development, the release of the GnuPG 2.4.0 (GNU Privacy Guard) toolkit has been announced, compatible with OpenPGP (RFC-4880) and S/MIME standards, providing utilities for data encryption, electronic signature handling, key management, and access to public key repositories.

GnuPG 2.4.0 is positioned as the first release of a new stable branch, incorporating changes accumulated during the preparation of the 2.3.x releases. The 2.2 branch has been classified as an old stable branch, which will be supported until the end of 2024. The GnuPG 1.4 branch continues to be maintained as a classic series, consuming minimal resources, suitable for embedded systems and compatible with outdated encryption algorithms.

Key changes in GnuPG 2.4 compared to the previous stable branch 2.2:

  • A background process has been added, implementing a key database that uses SQLite as storage and demonstrates significantly faster key searches. To enable the new storage, the 'use-keyboxd' option should be activated in common.conf.
  • A new background process, tpm2d, has been added, allowing the use of TPM 2.0 chips to protect private keys and perform encryption or digital signature operations on the TPM module side.
  • A new utility gpg-card has been added, which can be used as a flexible interface for all supported types of smart cards.
  • A new utility gpg-auth for authentication has been added.
  • A new shared configuration file common.conf has been introduced, which is used to enable the keyboxd background process without separately adding settings in gpg.conf and gpgsm.conf.
  • Support for the fifth version of keys and digital signatures has been provided, which uses the SHA256 algorithm instead of SHA1.
  • The default algorithms for public keys are now ed25519 and cv25519.
  • Support for AEAD modes of block encryption OCB and EAX has been added.
  • Support for elliptic curves X448 (ed448, cv448) has been added.
  • The use of group names in key lists is now allowed.
  • In gpg, gpgsm, gpgconf, gpg-card, and gpg-connect-agent, the '--chuid' option has been added to change the user identifier.
  • Full Unicode support in the command line has been implemented on the Windows platform.
  • A build option '--with-tss' has been added to select the TSS library.
  • Basic support for ECC and the ability to create EdDSA certificates have been added to gpgsm. Support for decrypting data encrypted with a password has been implemented. AES-GCM decryption support has been added. New options "--ldapserver" and "--show-certs" have been introduced.
  • In the agent, the use of the value "Label:" in the key file for setting the PIN input prompt has been allowed. Support for ssh-agent extensions for environment variables has been implemented. Win32-OpenSSH emulation through gpg-agent has been added. The default algorithm for creating SSH key fingerprints is now SHA-256. New options "--pinentry-formatted-passphrase" and "--check-sym-passphrase-pattern" have been added.
  • The scd has improved support for working with multiple card readers and tokens. It is now possible to use multiple applications with a specific smart card. Support for PIV cards, Telesec Signature Cards v2.0, and Rohde&Schwarz Cybersecurity has been added. New options "--application-priority" and "--pcsc-shared" have been included.
  • The gpgconf utility has added the option "--show-configs."
  • Changes in gpg:
    • A parameter "--list-filter" has been added for selective key listing, for example, "gpg -k --list-filter 'select=revoked-f && sub/algostr=ed25519'.
    • New commands and options have been added: "--quick-update-pref," "show-pref," "show-pref-verbose," "--export-filter export-revocs," "--full-timestrings," "--min-rsa-length," "--forbid-gen-key," "--override-compliance-check," "--force-sign-key," and "--no-auto-trust-new-key."
    • Support for importing arbitrary lists of revoked certificates has been added.
    • Verification of digital signatures has been accelerated by more than ten times.
    • Verification results now depend on the option "--sender" and the signature creator's identifier.
    • The ability to export Ed448 keys for SSH has been added.
    • Only OCB mode is allowed for AEAD encryption.
    • Decryption without a public key is permitted if a smart card is inserted.
    • For the algorithms ed448 and cv448, the creation of fifth-generation keys is now forcefully enabled.
    • When importing from server LDAP, applying the self-sigs-only option is disabled by default.
  • The use of algorithms with a block size of 64 bits has been discontinued for encryption in gpg. 3DES is prohibited, and AES is declared the minimum supported algorithm. To disable this restriction, the option "--allow-old-cipher-algos" can be used.
  • The symcryptrun utility (an outdated wrapper around the external tool Chiasmus) has been removed.
  • Support for the deprecated PKA key discovery method has been discontinued, and associated options have been removed.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster