[pkg-gnupg-maint] Bug#1078787: gpg-agent-ssh.socket ignores enable-ssh-support, stomps on SSH_AUTH_SOCK from ssh-agent.service

Richard Hansen rhansen at rhansen.org
Fri Aug 16 06:56:16 BST 2024


Package: gpg-agent
Version: 2.4.5-2
Severity: normal
Tags: patch

The /usr/lib/systemd/user/gpg-agent-ssh.socket systemd unit file 
unconditionally sets the SSH_AUTH_SOCK environment variable, even when 
enable-ssh-support is not present in ~/.gnupg/gpg-agent.conf.  This 
causes it to override the value set by openssh-client's 
/usr/lib/systemd/user/ssh-agent.service, breaking users that need to use 
the OpenSSH agent for its security key support (ecdsa-sk or ed25519-sk).

Patch available at: 
https://salsa.debian.org/debian/gnupg2/-/merge_requests/17


-- System Information:
Debian Release: trixie/sid
   APT prefers testing-debug
   APT policy: (500, 'testing-debug'), (500, 'testing'), (250, 
'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 6.10.3-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE 
not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages gpg-agent depends on:
ii  gpgconf                     2.4.5-2
ii  init-system-helpers         1.66
ii  libassuan0                  2.5.6-1+b1
ii  libc6                       2.39-6
ii  libgcrypt20                 1.11.0-6
ii  libgpg-error0               1.50-3
ii  libnpth0t64                 1.6-3.1
ii  pinentry-curses [pinentry]  1.2.1-3+b2
ii  pinentry-gnome3 [pinentry]  1.2.1-3+b2

Versions of packages gpg-agent recommends:
ii  gnupg  2.4.5-2

Versions of packages gpg-agent suggests:
ii  dbus-user-session  1.14.10-4+b1
ii  libpam-systemd     256.4-3
ii  pinentry-gnome3    1.2.1-3+b2
ii  scdaemon           2.4.5-2

-- no debconf information
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnupg-maint/attachments/20240816/cda63de0/attachment.sig>


More information about the pkg-gnupg-maint mailing list