Qubes 3.1 rc3 has been released!

394 views
Skip to first unread message

Marek Marczykowski-Górecki

unread,
Feb 24, 2016, 11:44:27 AM2/24/16
to qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

https://www.qubes-os.org/news/2016/02/24/qubes-OS-3-1-rc3-has-been-released/

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzd3cAAoJENuP0xzK19cs4sYH/1M3abmQ3HI9ChzuhXHgO7CC
NKXQcE7FDLg4fDyZyUJ5+uxM73ONrMuSGwfBuO7+eRS1N8zl6IyfZLXYeTt1yipS
dUYqP3HYtSAfemC0uAs6vJexmxZptulN0fdZWV6Wv4Tqsiex0+odz7caatcoAA52
+pz/zoLz7B0wG6/BRInaXR1VuPICzwv5kFOLS5tHD1fe+q7p38mkkeubP2x0Mj1r
oGhXgkzodczn+ZGUEsDoYBFyUZtD60M0WDiW5hhmfbU5HmJXUXeSpHc0NI7neqmx
lFzqpMeq7IZ45Aod7D/91Pa1VsmXTNhKoExi6hSLSmdlfaGAlQCFoA3aK1QQ9vM=
=LelG
-----END PGP SIGNATURE-----

Manuel Amador (Rudd-O)

unread,
Feb 24, 2016, 1:42:18 PM2/24/16
to qubes...@googlegroups.com
On 02/24/2016 04:44 PM, Marek Marczykowski-Górecki wrote:
> https://www.qubes-os.org/news/2016/02/24/qubes-OS-3-1-rc3-has-been-released/
>
Bug in page. A hyperlink is mal-Markdowned.

--
Rudd-O
http://rudd-o.com/

Marek Marczykowski-Górecki

unread,
Feb 24, 2016, 3:08:25 PM2/24/16
to Manuel Amador (Rudd-O), qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, Feb 24, 2016 at 06:42:10PM +0000, Manuel Amador (Rudd-O) wrote:
> On 02/24/2016 04:44 PM, Marek Marczykowski-Górecki wrote:
> > https://www.qubes-os.org/news/2016/02/24/qubes-OS-3-1-rc3-has-been-released/
> >
> Bug in page. A hyperlink is mal-Markdowned.

Thanks, fixed.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzg2yAAoJENuP0xzK19cs6tkH/3qlbmzGQLrO52S4Ey/sToNk
uViTp5KZ7zbF3VJ43DShtUxY7cAIMBTuxVurQR6hjj3F+OTYDMBjwW94g2GZvbAb
z8FmkuAL05hQp21OBSiyOxt9BCC3/vwNTczQpmiZ65joAUOuXAfveTanUG+dhwu2
5yi4PKYPAV5jP6fKzKoJaaC4JoUQLy+MOpSNEbm3ENy1QCR3rRsFHMNxEQxgE4n2
Rul2clSgncsaTeLzP8KeW3A+KRf8fgU18ucLlmauRHy47LHd9xS6LFIhapd0DOsH
mpca6p+VPmrn1AO+d9BsaZRquBT+oLrj83bcOkEIqR+jwIxAdbYO5xkhFmBB8pc=
=BZ8/
-----END PGP SIGNATURE-----

raah...@gmail.com

unread,
Feb 24, 2016, 5:02:56 PM2/24/16
to qubes-users, rud...@rudd-o.com
I'm having trouble verifying the sig in an appvm not sure what I'm doing wrong.

I have gave temp access to the template vm and used the commands:

gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc

gpg --keyserver pool.sks-keyservers.net --recv-keys 03FA5082

then from appvm:

gpg --verify Qubes-R3.1-rc3-x86_64.iso.asc Qubes-R3.1-rc3-x86_64.iso

but it is telling me public key not found.

raah...@gmail.com

unread,
Feb 24, 2016, 5:17:35 PM2/24/16
to qubes-users, rud...@rudd-o.com, raah...@gmail.com
ok i copied the files and verified from within the templatevm. After the mint issue I hope I am doing it the right way.

robin...@gmail.com

unread,
Feb 25, 2016, 5:09:20 AM2/25/16
to qubes-users
Hi,
i think the Qubes-R3.1-rc3-x86_64.iso.DIGESTS is not complete.

When I run

gpg -v --verify Qubes-R3.1-rc3-x86_64.iso.DIGESTS.
I get the following:
gpg: no valid OpenPGP data found.
gpg: the signature could not be verified.

The DIGESTS file is missing the PGP signature.

I hadn't that issue when testing rc2.

Greetings.

Marek Marczykowski-Górecki

unread,
Feb 25, 2016, 5:15:05 AM2/25/16
to robin...@gmail.com, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Feb 25, 2016 at 02:09:20AM -0800, robin...@gmail.com wrote:
> Hi,
> i think the Qubes-R3.1-rc3-x86_64.iso.DIGESTS is not complete.
>
> When I run
>
> gpg -v --verify Qubes-R3.1-rc3-x86_64.iso.DIGESTS.
> I get the following:
> gpg: no valid OpenPGP data found.
> gpg: the signature could not be verified.
>
> The DIGESTS file is missing the PGP signature.

Download the file again - initially for first few hours indeed that file
hadn't signature, but now it has.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWztQhAAoJENuP0xzK19csQwEH/jADByyn+jxBKJisvDfMtB3S
P35XITJlnNEjI14XQbyD6+5kkzF4HDXBx5NDZgA+s40Ni+iRbgrwecigdSYBH8Bc
nb06tASxHBA2EvJTf9oJIuG+P9hVMomZbl3S9DqbbNwAZwsn58RoSYxIzL7YBJnZ
RknoYFU6jfw1NPWWISe7aNqKXfQk95yixRHuBMeoKN+lYfAB/WATV3mEcerGffTd
62INpbDKiuHSIS4WZoOEfmH/k6CaPE4paUFJe7KPZQsWXwr0pRQFSAypsKLK8Hlu
8P5kxVDGYtyUcHvWCAYNhLC38sY5TRjgVUmFufih9ucr1p/l9XD8t+55M7Pf0cU=
=oJWV
-----END PGP SIGNATURE-----

robin...@gmail.com

unread,
Feb 25, 2016, 5:48:51 AM2/25/16
to qubes-users
Hi, thanks for the quick reply.

Its working now.

The file on https://mirrors.kernel.org/qubes/iso/ is not good yet.

Regards.

Marek Marczykowski-Górecki

unread,
Feb 25, 2016, 6:31:20 AM2/25/16
to robin...@gmail.com, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Feb 25, 2016 at 02:48:50AM -0800, robin...@gmail.com wrote:
> Hi, thanks for the quick reply.
>
> Its working now.
>
> The file on https://mirrors.kernel.org/qubes/iso/ is not good yet.

Yes, it's synchronized once a day, so will be there somehow tomorrow or
so.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzuYBAAoJENuP0xzK19csn2MH/3xfEZlya2Fz6kgysjeNP2l4
is5clpc1W4MHydyM4rQ9owH/OQGfKJ0Q4SPGc7dCJD6qanqLSIr8xCPtG5FIQ8Iw
H9fscqNbDSQHHbZfIkdvBSztP3SNICCe8Mz+WhAbyyczUcGtFwdvvAeJ8uTMrEcU
8pQilISUde7O8Iy+ktweN4ud1/Q2LGQD4RB5K9fH/rT9FHSt6W4nfSbqXMqSrIrQ
x6ZEvFtsE3uxdCEVeSGlEAZ8HZmE5dD7Bl0T50ZpKPl1IdsdC9VHexZdlsvQd0HW
mcgsmKG2yrjvAubNhTs51aA7xjwu/aG+INTktkDRNPcojINVKnMKyMvleKUYeA0=
=OSvC
-----END PGP SIGNATURE-----

Cube

unread,
Feb 25, 2016, 7:49:49 AM2/25/16
to qubes-users

Do you recommend we install from scratch occasionally, or is pulling in updates enough?

I created a StandaloneVM from fedora23, and when I went to install an application found that there were a lot of updates to install. However when I try to update my fedora23 template it complains about yum being depreciated and doesn't do much after that (no updates). However I do think that it recently was updated (last week or so).

Marek Marczykowski-Górecki

unread,
Feb 25, 2016, 8:11:12 AM2/25/16
to Cube, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Feb 25, 2016 at 04:49:49AM -0800, Cube wrote:
>
> Do you recommend we install from scratch occasionally, or is pulling in
> updates enough?

If you installed 3.1 rc1 or rc2, just updating (both dom0 and templates)
is enough. In case of 3.0 - there is also upgrade procedure, but somehow
more complex (still marked as experimental, but given we've got
positive feedback, it will be probably marked stable soon).

If you have still R2, we recommend migration with
backup-reinstall-restore procedure (although there is also in-place
procedure present).

> I created a StandaloneVM from fedora23, and when I went to install an
> application found that there were a lot of updates to install. However when
> I try to update my fedora23 template it complains about yum being
> depreciated and doesn't do much after that (no updates). However I do think
> that it recently was updated (last week or so).

In case if Fedora 23, you can use dnf directly - simply call 'dnf
update'.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzv1pAAoJENuP0xzK19cshz8H/09zWVWFtNEzNwsz00bbn5gm
qpXYYz11ncNf8MHNIurazV1KVpQ2aQV4+fNbOoowKpwfKyko4WZNthZ9RIQZWUbN
NgZVY2vLez/MQVj/UWKd9/dZv4tAQdxVTeXbnPGpq0bjjLE8lwPexqc9X0MOP191
H4BxB3F2bC1x4KT/YN7daT0+6CapcosNQVhMEQQCN13NSDN5x4Ox9NVUpls8ubYK
bUsVo28kQMsr4WkeETSaPX2Vxrva5H0Ugzyh9xfW/Tm13iogoZZ/atcROVTgU6PF
J3yE/w7bWeivaSr0c55hTUGXdYPN5jgjXFgYHWrNeOEZo8q3jurAWv8wpkX1mRk=
=ZDL6
-----END PGP SIGNATURE-----

Cube

unread,
Feb 25, 2016, 8:14:32 AM2/25/16
to Marek Marczykowski-Górecki, qubes-users


On 02/25/2016 05:11 AM, Marek Marczykowski-Górecki wrote:
> On Thu, Feb 25, 2016 at 04:49:49AM -0800, Cube wrote:
>
> > Do you recommend we install from scratch occasionally, or is pulling in
> > updates enough?
>
> If you installed 3.1 rc1 or rc2, just updating (both dom0 and templates)
> is enough. In case of 3.0 - there is also upgrade procedure, but somehow
> more complex (still marked as experimental, but given we've got
> positive feedback, it will be probably marked stable soon).
>
Thanks much. I don't recall what I have, I think I fully updated to rc1
but aren't sure, is there a good way to find out?

Marek Marczykowski-Górecki

unread,
Feb 25, 2016, 8:27:25 AM2/25/16
to Cube, qubes-users
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

In Qubes Manager you have "about" option for that. It it says "Qubes
release 3.1 (R3.1)" it means you have 3.1 (one of its release
candidates). You can check the same in /etc/qubes-release.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWzwE1AAoJENuP0xzK19csMYQH/3YhggAIVdRhH9LFNWr3fLlT
lqZiB5ZABeSldu8UtnEewvVel6Qx3b62knJMcciBH/RDIJ30hwPdZl5HqMfxHJF9
SP1JYP6ii2l25aBEqFP3lHCkW2ulq6dIsIznpMwPrcF2abV8Oa+CelX1vr0lqwCt
Pw3baqYHjC58G9ldp452tCa5HDl1I8yytjeLx1QLrwtkSzexwk5JESMrAekokDRr
++ZBHjETxHi6wcl7Iow3X1VPKW4JOL1CkdAwl7KTvANZLGqTRb9H/ey5xrEBqCcI
12iQVPelT21QMg/pmTuJNfQBBMfVn9Rdy0rUu3E9cibMfzW1S0j+7SAAh2Ts5uU=
=7He2
-----END PGP SIGNATURE-----

raah...@gmail.com

unread,
Feb 25, 2016, 3:12:09 PM2/25/16
to qubes-users, cubem...@gmail.com
Only issue i noticed so far was sys-whonix didn't auto start on first boot, and it is colored black like the templates instead of purple. so didn't even realize it was created at first.

Marek Marczykowski-Górecki

unread,
Feb 25, 2016, 4:20:30 PM2/25/16
to raah...@gmail.com, qubes-users, cubem...@gmail.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Thu, Feb 25, 2016 at 12:12:09PM -0800, raah...@gmail.com wrote:
> Only issue i noticed so far was sys-whonix didn't auto start on first boot, and it is colored black like the templates instead of purple. so didn't even realize it was created at first.

This was intentional change:
https://github.com/QubesOS/qubes-issues/issues/1633

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWz3AVAAoJENuP0xzK19cseS0H+wU4L0/o5ZkvgBddmaXUSiQx
RKZ8qFA6ASarJXl9SmCog7JKoc/65IzMfr95VemIicWj6Wt+ndInS3LWyodvhls0
kRW6B7POU41atH8ezdU0oy2WTMd424lWN8nxlv0ShvkpdcownzF48oyPEAa77j5J
U8D1uvDACM84lMehC04MMh6aKAF2UltEloqbie/AJIFbjO2QEtlsudRJQYPYarQ/
ANNhn/fpzrYaU5oD7JeKaYm8H9/L0nXHrmGi+CNyR3KBaG9EcQdhsOSPAbaeZEA9
xuftHuEJEjqSiWnpSpBeVUwju0rVn3U6ZOhvFTwJrDisp5q253xLGFKrAg6xkGY=
=IcdY
-----END PGP SIGNATURE-----

Nuno Branco

unread,
Feb 25, 2016, 5:11:09 PM2/25/16
to qubes...@googlegroups.com
Not sure if I should start a different thread but for me this has broken my GPG split configuration (using enigmail and Debian 8 templates for both VMs), seems there is some kind of problem communicating between the VMs or the Gnome Keyring.

Anyone else experiencing the same issue?

I upgraded by the way and not a clean install (although everything was working fine before the latest patches).


On 02/25/2016 08:12 PM, raah...@gmail.com wrote:
Only issue i noticed so far was sys-whonix didn't auto start on first boot,  and it is colored black like the templates instead of purple. so didn't even realize it was created at first.


--


Best regards,
Nuno Branco

For secure messages please MIT PGP Database
If you are not familiar with PGP please use this link to send secure messages to me.

raah...@gmail.com

unread,
Feb 25, 2016, 10:39:26 PM2/25/16
to qubes-users, nuno....@neomailbox.ch
I like having the templates black, and the anon-whonix red, which is how I did them originally when installing whonix for the first time in qubes manually.

But I would of prefered to keep the sys-whonix purple (which is how i did it originally also) so I don't get it confused with the templates, It seems really confusing this way. Purple is also the color used by tor project so it would feel natural and easy for me to identify it as the "torvm" since I don't use purple for anything else.

Nuno Branco

unread,
Feb 26, 2016, 1:25:56 PM2/26/16
to qubes...@googlegroups.com
No one replied so I am guessing I am the only one. It turns out the problem also occurred on 3.0 latest branch so I am wondering if there were any recent changes on /etc/qubes-rpc/qubes.Gpg ? I changed the file to gpg v1 and it is working fine again.

In any case there seems to be some sort of issue with Enigmail + GPGv2 + Split GPG

--
You received this message because you are subscribed to the Google Groups "qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users...@googlegroups.com.
To post to this group, send email to qubes...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/56CF7BF7.102%40neomailbox.ch.
For more options, visit https://groups.google.com/d/optout.

Marek Marczykowski-Górecki

unread,
Feb 26, 2016, 7:33:39 PM2/26/16
to Nuno Branco, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Fri, Feb 26, 2016 at 06:25:45PM +0000, Nuno Branco wrote:
> No one replied so I am guessing I am the only one. It turns out the
> problem also occurred on 3.0 latest branch so I am wondering if there
> were any recent changes on /etc/qubes-rpc/qubes.Gpg ? I changed the file
> to gpg v1 and it is working fine again.

If you have gpg 2.1 (which is the case in Fedora 23), it needs to
migrate secret keys to the new location. It is done automatically for
example when you list the keys (apparently it isn't done before
decryption, which I guess is your problem). You can either call:
- from backend VM: gpg2 -K
- from client VM: qubes-gpg-client -K

Not sure if this is the problem you have, since you've mentioned usage
of Debian template, which have older gpg version. But maybe...

> In any case there seems to be some sort of issue with Enigmail + GPGv2 +
> Split GPG
>
>
> On 02/25/2016 10:11 PM, Nuno Branco wrote:
> > Not sure if I should start a different thread but for me this has
> > broken my GPG split configuration (using enigmail and Debian 8
> > templates for both VMs), seems there is some kind of problem
> > communicating between the VMs or the Gnome Keyring.
> >
> > Anyone else experiencing the same issue?
> >
> > I upgraded by the way and not a clean install (although everything was
> > working fine before the latest patches).
> >
> > On 02/25/2016 08:12 PM, raah...@gmail.com wrote:
> >> Only issue i noticed so far was sys-whonix didn't auto start on first boot, and it is colored black like the templates instead of purple. so didn't even realize it was created at first.
> >>
> >
> > --
> >
> >
> > Best regards,
> > Nuno Branco
> >
> > For secure messages please MIT PGP Database <use>
> > If you are not familiar with PGP please use this link to send secure
> > messages <https://encrypt.to/nuno....@neomailbox.ch> to me.
> > --
> > You received this message because you are subscribed to the Google
> > Groups "qubes-users" group.
> > To unsubscribe from this group and stop receiving emails from it, send
> > an email to qubes-users...@googlegroups.com
> > <mailto:qubes-users...@googlegroups.com>.
> > To post to this group, send email to qubes...@googlegroups.com
> > <mailto:qubes...@googlegroups.com>.
> > To view this discussion on the web visit
> > https://groups.google.com/d/msgid/qubes-users/56CF7BF7.102%40neomailbox.ch
> > <https://groups.google.com/d/msgid/qubes-users/56CF7BF7.102%40neomailbox.ch?utm_medium=email&utm_source=footer>.
> > For more options, visit https://groups.google.com/d/optout.
>

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJW0O7YAAoJENuP0xzK19csvjIH/1oHBILc+DIJMwEjhpPbviOz
PUZSXd709b0p2wH1/BGhdDN0IKnOlQ6iXwovjaEERImk/ueA4N/oqD0TDZFo4j9a
65ul9P9LVanC0L3R+vgKJ3ytaOgEgk8dZL/ttC6MyknWTVh+etHTBXY54p/v9sTQ
z0xBZzk/azk6tyTylOVZ0hPPTfIcbB5DjmC4nIQQ3gZS0pIe+skiw7hhvR8P1awN
sYcwGEYWVPAUirD+waIiGfyxuQSSYtGQZHC6BnG43cOJ3GiC7NphQ/hJVP9tItE9
KoA4n3ysTyoCn5h5EeI9x+cStfraP2yFoDQKI+7js8LfK03lwABM9qJ4qSj0Xjs=
=bUjT
-----END PGP SIGNATURE-----

Nuno Branco

unread,
Feb 27, 2016, 6:58:50 AM2/27/16
to qubes...@googlegroups.com
Well to be honest I am getting really confused. Everything was working today when I changed to GPG v1 on the template VM but today after a full power cycle Enigmail is telling me that it no longer supports GPG v1 ... and there were no updated made to Enigmail or Thunderbird that I am aware between power cycles.

So I switched back on v2 on the template VM and then ran the commands you listed below on the client and backend VMs (both Debian 8) and they both list the private keys.

The error itself (when using GPGv2) from Enigmail is complaining about gpg-agent. Going to the Enigmail log when trying to e-mail myself I get the following:

2016-02-27 11:23:55.238 [DEBUG] system.jsm: determineSystemCharset
2016-02-27 11:23:55.238 [DEBUG] system.jsm: determineSystemCharset: charset='iso-8859-1'
2016-02-27 11:23:55.238 [DEBUG] system.jsm: determineSystemCharset
2016-02-27 11:23:55.238 [DEBUG] system.jsm: determineSystemCharset: charset='iso-8859-1'
2016-02-27 11:23:55.238 [DEBUG] errorHandling.jsm: parseErrorOutputWith: statusFlags = 00400000
2016-02-27 11:23:55.238 [DEBUG] errorHandling.jsm: parseErrorOutputWith: return with c.errorMsg = gpg: WARNING: The GNOME keyring manager hijacked the GnuPG agent.
gpg: WARNING: GnuPG will not work properly - please configure that tool to not interfere with the GnuPG system!
2016-02-27 11:23:55.238 [DEBUG] execution.jsm: EnigmailExecution.fixExitCode: agentType: gpg exitCode: 0 statusFlags 4194304
2016-02-27 11:23:55.238 [DEBUG] encryption.jsm: encryptMessageEnd: command execution exit code: 1
2016-02-27 11:24:25.442 [ERROR] mimeEncrypt.js: caught exception: undefined
Message: 'undefined'
File:    undefined
Line:    undefined
Stack:   undefined
2016-02-27 11:24:26.759 [DEBUG] enigmailMsgComposeOverlay.js: ECSL.ComposeProcessDone: 2147500037
2016-02-27 11:24:26.760 [DEBUG] enigmailMsgComposeOverlay.js: Enigmail.msg.removeAttachedKey:
2016-02-27 11:24:30.180 [DEBUG] traverseTree: menu_EnigmailPopup2
[...]

The command being used according to the debug console is:
/usr/bin/qubes-gpg-client-wrapper --charset utf-8 --display-charset utf-8 --use-agent --batch --no-tty --status-fd 2 -a -t --encrypt --trust-model always -r <email> -u <email>

Now to make things even more interesting if I ran that command from a terminal in the client VM it works fine:
echo "I am an encrypted message" |  /usr/bin/qubes-gpg-client-wrapper --charset utf-8 --display-charset utf-8 --use-agent --batch --no-tty --status-fd 2 -a -t --encrypt --trust-model always -r email -u email
[GNUPG:] PROGRESS need_entropy X 8 16
[GNUPG:] PROGRESS need_entropy X 16 16
[GNUPG:] BEGIN_ENCRYPTION 2 9
-----BEGIN PGP MESSAGE-----
Version: GnuPG v2
[...]
-----END PGP MESSAGE-----
[GNUPG:] END_ENCRYPTION

Marek Marczykowski-Górecki

unread,
Feb 28, 2016, 8:34:36 PM2/28/16
to Nuno Branco, qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Fri, Feb 26, 2016 at 06:25:45PM +0000, Nuno Branco wrote:
> No one replied so I am guessing I am the only one. It turns out the
> problem also occurred on 3.0 latest branch so I am wondering if there
> were any recent changes on /etc/qubes-rpc/qubes.Gpg ? I changed the file
> to gpg v1 and it is working fine again.
>
> In any case there seems to be some sort of issue with Enigmail + GPGv2 +
> Split GPG

Indeed there is a message that Enigmail can't connect to gpg-agent.
Which isn't surprising because gpg-agent (if any) is running GPG VM, so
Enigmail can't talk directly to it. All that the message says is that
password timeout setting will be ignored. That's all, it isn't an
error.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJW06AkAAoJENuP0xzK19cs+rMH/jRMAkwt4osTNLBX/QxsS4OI
8RZ7jvIeO/nCpQJ0szpULAZUEsROc23EFRr8cNoTbXWXiB7TQLNFb5wlNgn8mgqw
EfRteV5dIuqGGifj4ORX83MGzIwB4+LwtgtZN3/u3D7oNLyf6TX47ipG7zT/cRyc
XK1aXcO0nlZR1YafKgoxYn4yPQj0Ok6cuHHHlqu2XgHU6nucekBoD4H/9LVKeZzr
4jGihOvvmbr8BmE2nVca20SkQ2L6wrE51GXeIEh+sk4T19+7sB8/M/msWML9BRko
VhsUGPyyQ2iIe9SsNcu7Xq1odAz1QgnnwW+Ui6mxpQMCbYJaUJ2cGUjfNKVBcKM=
=sDjN
-----END PGP SIGNATURE-----

Nuno Branco

unread,
Mar 5, 2016, 8:36:40 AM3/5/16
to Marek Marczykowski-Górecki, qubes...@googlegroups.com
I have been playing around with this more and although no one else complained about the same thing as me I wanted to let everyone know the solution for further reference:

1) There seems there was a bug introduced in Enigmail version 1.9 that caused this behavior
2) Manually downgrading do version 1.8 resolves the issue

If you have to do this make sure you disable auto-updates for the Enigmail add-on as otherwise the problem will occur again.

Regards,
Nuno
signature.asc
Reply all
Reply to author
Forward
0 new messages