[Gpg4win-users-en] gpg4win: cannot enter passphrase when creating key
Alexander Kriegisch
alexander at kriegisch.name
Sun Nov 10 14:34:36 CET 2013
Hi community.
I have a fresh installation
- of gpg4win 2.2.1
- on Windows XP Pro SP3 (German).
First I tried the vanilla version (only GnuPG command line), then later the full package with Kleopatra. The result is always the same: I cannot create a new key pair because somehow the passphrase is not captured correctly. On the command line the following happens:
- Run cmd.exe
- gpg --gen-key
- The whole assistant works nicely until I get to the part where I
should enter my passphrase. Now nothing happens, I see no dots or
asterisks when entering the passphrase. I can enter it as many times
as I want to, the passphrase is not captured. I can only stop the
process via Ctrl-C. Then the passphrase is written to the console
as CLEAR TEXT(!) and treated as if I entered it as a command. This
is a security nightmare. I cannot understand how something like this
can ever pass a test unnoticed.
By the way, the same problem was reported long ago already, but nothing happened. See this thread:
http://lists.wald.intevation.org/pipermail/gpg4win-users-en/2009-August/000349.html
Regards
--
Alexander Kriegisch
More information about the Gpg4win-users-en
mailing list