1
0
mirror of https://git.FreeBSD.org/ports.git synced 2024-10-18 19:49:40 +00:00

gnupg: Update to 2.2.17, with security fixes

* gpg: Ignore all key-signatures received from keyservers.  This
   change is required to mitigate a DoS due to keys flooded with
   faked key-signatures.  The old behaviour can be achieved by adding
     keyserver-options no-self-sigs-only,no-import-clean
   to your gpg.conf.  [#4607]

 * gpg: If an imported keyblocks is too large to be stored in the
   keybox (pubring.kbx) do not error out but fallback to an import
   using the options "self-sigs-only,import-clean".  [#4591]

 * gpg: New command --locate-external-key which can be used to
   refresh keys from the Web Key Directory or via other methods
   configured with --auto-key-locate.

 * gpg: New import option "self-sigs-only".

 * gpg: In --auto-key-retrieve prefer WKD over keyservers.  [#4595]

 * dirmngr: Support the "openpgpkey" subdomain feature from
   draft-koch-openpgp-webkey-service-07. [#4590].

 * dirmngr: Add an exception for the "openpgpkey" subdomain to the
   CSRF protection.  [#4603]

 * dirmngr: Fix endless loop due to http errors 503 and 504.  [#4600]

 * dirmngr: Fix TLS bug during redirection of HKP requests.  [#4566]

 * gpgconf: Fix a race condition when killing components.  [#4577]

 Release-info: https://dev.gnupg.org/T4606

MFH:		2019Q3
This commit is contained in:
Adam Weinberger 2019-07-09 15:54:43 +00:00
parent 963785ff4a
commit ec81de8e63
Notes: svn2git 2021-03-31 03:12:20 +00:00
svn path=/head/; revision=506281
2 changed files with 4 additions and 4 deletions

View File

@ -1,7 +1,7 @@
# $FreeBSD$
PORTNAME= gnupg
PORTVERSION= 2.2.16
PORTVERSION= 2.2.17
CATEGORIES= security
MASTER_SITES= GNUPG

View File

@ -1,3 +1,3 @@
TIMESTAMP = 1559097348
SHA256 (gnupg-2.2.16.tar.bz2) = 6cbe8d454bf5dc204621eed3016d721b66298fa95363395bb8eeceb1d2fd14cb
SIZE (gnupg-2.2.16.tar.bz2) = 6699113
TIMESTAMP = 1562687164
SHA256 (gnupg-2.2.17.tar.bz2) = afa262868e39b651a2db4c071fba90415154243e83a830ca00516f9a807fd514
SIZE (gnupg-2.2.17.tar.bz2) = 6717554