FIPS-mode keygen fails to include preferences subpackets

Werner Koch wk at gnupg.org
Fri Oct 24 16:23:41 CEST 2025


Hi Bill,

your mail was lingering around in my folder for too long.  I now
implemented your suggestion:

> Locally we're using the simple fix, but a better solution might be to
> 1) add "S2" conditionally, similar to how AES is treated, and 2)
> refactor the second half of keygen_set_std_prefs to continue
> processing algorithms, only failing later if none were matched in a
> set. I'd be happy to craft that patch if that seems like the better

Thanks.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein
-------------- next part --------------
A non-text attachment was scrubbed...
Name: openpgp-digital-signature.asc
Type: application/pgp-signature
Size: 284 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-devel/attachments/20251024/ee8870bb/attachment.sig>


More information about the Gnupg-devel mailing list