메뉴
HN
Hacker News 94일 전

GnuPG, 메인라인에 양자내성암호(PQC) 추가

IMP
8/10
핵심 요약

대표적인 오픈소스 암호화 도구인 GnuPG의 최신 버전(2.5.19)이 공식 릴리스 되었습니다. 이번 2.5 시리즈의 가장 큰 특징은 양자 컴퓨터의 위협에 대응하기 위한 양자내성암호(PQC) 알고리즘인 Kyber(ML-KEM, FIPS-203) 암호화를 지원한다는 점입니다. 또한 다양한 버그 수정과 64비트 윈도우 환경 개선, 보안 관련 기능들이 강화되어 기존 2.4 버전 사용자의 빠른 업데이트가 권장됩니다.

번역된 본문

[공지] GnuPG 2.5.19 릴리스 Werner Koch (wk at gnupg.org) 2026년 4월 24일 금요일 13:52:45 CEST

이전 메시지 (스레드별): [공지] [보안 수정 사항] Libgcrypt 1.12.2, 1.11.3, 1.10.x 릴리스 정렬 기준: [ 날짜 ] [ 스레드 ] [ 제목 ] [ 작성자 ]

안녕하세요! 새로운 GnuPG 버전인 2.5.19의 출시를 기쁘게 알려드립니다. 이번 릴리스에는 몇 가지 새로운 기능이 추가되고 여러 버그가 수정되었습니다.

2.5 시리즈의 주요 기능은 64비트 윈도우에 대한 개선과 PQC(Post-Quantum Cryptography, 양자내성암호) 암호화 알고리즘으로서 Kyber(일명 ML-KEM 또는 FIPS-203)의 도입입니다. PQC 지원을 제외하면 2.6 시리즈는 지원 라이브러리의 최신 기능을 활용하기 위한 내부 변경이 대부분이므로 2.4와 크게 다르지 않을 것입니다.

구버전인 2.4 시리즈는 단 두 달 뒤에 지원이 종료(End-of-life)된다는 점을 유의하시기 바랍니다. 따라서 제때 2.5.19로 업데이트하시기 바랍니다. GnuPG의 새 버전은 항상 이전 버전과 완벽하게 호환됩니다.

GnuPG란?

GNU Privacy Guard(GnuPG, GPG)는 OpenPGP 및 S/MIME 표준의 완전하고 무료인 구현체입니다. GnuPG는 데이터 및 통신을 암호화하고 서명할 수 있게 해주며, 다재다능한 키 관리 시스템과 공개 키 디렉터리에 대한 액세스 모듈을 특징으로 합니다. GnuPG 자체는 다른 애플리케이션과의 쉬운 통합을 위한 기능을 갖춘 명령줄(Command line) 도구입니다. 별도의 라이브러리인 GPGME은 일반적인 프로그래밍 언어로 작성된 소프트웨어가 GnuPG 엔진을 사용할 수 있도록 통일된 API를 제공합니다. GnuPG를 활용하는 수많은 프론트엔드 애플리케이션과 라이브러리를 사용할 수 있습니다. 범용 암호화 엔진으로서 GnuPG는 OpenPGP 외에도 S/MIME 및 Secure Shell(SSH)을 지원합니다. GnuPG는 자유 소프트웨어입니다(즉, 사용자의 자유를 존중한다는 의미). GNU General Public License의 조건에 따라 자유롭게 사용, 수정 및 배포할 수 있습니다.

버전 2.5.19(2026-04-24)의 주요 변경 사항

[버전 2.5.18과 비교]

  • 새로운 기능 및 확장된 기능:
  • gpg: 새로운 옵션 --use-ocb-sym 추가. [rGccdcdfbb37]
  • gpg: 새로운 옵션 --show-[only-]session-hash 추가. [rGecd0f7afa1]
  • gpgsm: --cipher-algo 옵션에 제공된 알고리즘의 일부로 암호화 모드(cipher mode)를 허용. [T3979]
  • gpgsm: crlDP 확인 실패 시 더 자세한 세부 정보 출력. [T8221]
  • agent: 스마트카드 컨텍스트에서 Pinentry(비밀번호 입력창) 동작 및 텍스트 개선. [T6425]
  • dirmngr: --keyserver에 대한 새로운 키워드 "clear" 추가. [rG2ab4cba36c]
  • 버그 수정:
  • gpg: --refresh-keys의 엣지 케이스(극단적인 상황) 수정. [T8197]
  • gpg: 빈 암호 구문(passphrase)으로 gcry_kdf_derive를 호출하지 않도록 수정. [T7739]
  • gpgsm: 독일 도이치 텔레콤(German Telekom)이 최근에 발급한 인증서를 가져올 수 있도록 선택적 PKCS#12 PBES2 keyLength 매개변수 건너뛰기. [rGc8c9604bba]
  • gpgsm: 다른 알고리즘을 사용하여 인증서에 서명할 수 있도록 버그 수정. [rG66fdafab3c]
  • gpgsm: de-vs 모드에서 GCM을 완벽하게 준수하도록 수정. [rG04fd775fce]
  • gpgsm: de-vs 규정 준수를 위한 인증서 체인 검사 추가. [T8188]
  • gpgsm: 목록에 rsaPSS 인증서를 de-vs 규정 준수로 표시. [T8222]
  • agent: 끝에 LF(줄바꿈 문자)가 누락된 trustlist.txt 파일을 허용하도록 신뢰 목록 읽기 코드(trustlist reading code) 재작업. [T8078]
  • ssh: 서명 처리 시 RSA 패딩 수정. [T7882, T8202]
  • gpgtar: 출력 디렉터리를 확인하도록 -C (--directory) 수정. [T8159]
  • 기타 변경 사항:
  • agent: 잘못 생성된 *PGP 키를 감지하기 위해 RSA 키의 p >= q인 경우 오류 발생. [T8171]

릴리스 정보: https://dev.gnupg.org/T7998

소프트웨어 다운로드

< https://gnupg.org/download/ >에 있는 지침을 따르거나 다음 내용을 읽어주세요. GnuPG는 GnuPG 미러 사이트 중 하나에서 다운로드하거나 기본 파일 서버에서 직접 다운로드할 수 있습니다. 미러 목록은 < https://gnupg.org/download/mirrors.html >에서 찾을 수 있습니다. GnuPG는 ftp.gnu.org에서 사용할 수 없다는 점에 유의하십시오.

BZIP2로 압축된 GnuPG 소스 코드와 해당 OpenPGP 서명은 여기에서 사용할 수 있습니다: https://gnupg.org/ftp/gcrypt/gnupg/gnupg-2.5.19.tar.bz2 (8127k) https://gnupg.org/ftp/gcrypt/gnupg/gnupg-2.5.19.tar.bz2.sig

최소한의 Pinentry 도구를 제외하고는 그래픽 프론트엔드가 없는 Windows용 설치 프로그램을 사용할 수 있습니다.

원문 보기
원문 보기 (영어)
[Announce] GnuPG 2.5.19 released Werner Koch wk at gnupg.org Fri Apr 24 13:52:45 CEST 2026 Previous message (by thread): [Announce] [Security fixes] Libgcrypt 1.12.2, 1.11.3, 1.10.x released Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] Hello! We are pleased to announce the availability of a new GnuPG release: Version 2.5.19. This release adds a few new features and fixes a couple of bugs. The main features in the 2.5 series are improvements for 64 bit Windows and the introduction of Kyber (aka ML-KEM or FIPS-203) as PQC encryption algorithm. Other than PQC support the 2.6 series will not differ a lot from 2.4 because the majority of changes are internal to make use of newer features from the supporting libraries. Note that the old 2.4 series reaches end-of-life in just two months. Thus update to 2.5.19 in time. As always with GnuPG new versions are fully compatible with previous versions. What is GnuPG ============= The GNU Privacy Guard (GnuPG, GPG) is a complete and free implementation of the OpenPGP and S/MIME standards. GnuPG allows to encrypt and sign data and communication, features a versatile key management system as well as access modules for public key directories. GnuPG itself is a command line tool with features for easy integration with other applications. The separate library GPGME provides a uniform API to use the GnuPG engine by software written in common programming languages. A wealth of frontend applications and libraries making use of GnuPG are available. As an universal crypto engine GnuPG provides support for S/MIME and Secure Shell in addition to OpenPGP. GnuPG is Free Software (meaning that it respects your freedom). It can be freely used, modified and distributed under the terms of the GNU General Public License. Noteworthy changes in version 2.5.19 (2026-04-24) ================================================= [compared to version 2.5.18] * New and extended features: - gpg: New option --use-ocb-sym. [rGccdcdfbb37] - gpg: New options --show-[only-]session-hash. [rGecd0f7afa1] - gpgsm: Allow cipher mode to be part of the algo given to the --cipher-algo option. [T3979] - gpgsm: Emit more details when failing to check a crlDP. [T8221] - agent: Improve pinentry behavior and texts in smartcard context. [T6425] - dirmngr: New keyword "clear" for --keyserver. [rG2ab4cba36c] * Bug fixes: - gpg: Fix edge case in --refresh-keys. [T8197] - gpg: Don't call gcry_kdf_derive with empty passphrase. [T7739] - gpgsm: Skip the optional PKCS#12 PBES2 keyLength parameter to allow import of recently issued certificates by the German Telekom. [rGc8c9604bba] - gpgsm: Fix a bug so that a certificate can be signed using a different algo. [rG66fdafab3c] - gpgsm: Make GCM fully compliant in de-vs mode. [rG04fd775fce] - gpgsm: Add a certificate chain check for de-vs compliance. [T8188] - gpgsm: Show rsaPSS certificates as de-vs compliant in listings. [T8222] - agent: Rework the trustlist reading code to finally allow a trustlist.txt with a missing trailing LF. [T8078] - ssh: Fix RSA padding in signature handling. [T7882,T8202] - gpgtar: Fix -C (--directory) to check the output directory. [T8159] * Other changes: - agent: Raise an error when p >= q for RSA keys to detect incorrect generated *PGP keys. [T8171] Release-info: https://dev.gnupg.org/T7998 Getting the Software ==================== Please follow the instructions found at < https://gnupg.org/download/ > or read on: GnuPG may be downloaded from one of the GnuPG mirror sites or direct from its primary file server. The list of mirrors can be found at < https://gnupg.org/download/mirrors.html >. Note that GnuPG is not available at ftp.gnu.org. The GnuPG source code compressed using BZIP2 and its OpenPGP signature are available here: https://gnupg.org/ftp/gcrypt/gnupg/gnupg-2.5.19.tar.bz2 (8127k) https://gnupg.org/ftp/gcrypt/gnupg/gnupg-2.5.19.tar.bz2.sig An installer for Windows without any graphical frontend except for a very minimal Pinentry tool is available here: https://gnupg.org/ftp/gcrypt/binary/gnupg-w32-2.5.19_20260424.exe (5627k) https://gnupg.org/ftp/gcrypt/binary/gnupg-w32-2.5.19_20260424.exe.sig The source used to build this installer for 64-bit Windows is available as https://gnupg.org/ftp/gcrypt/gnupg/gnupg-w32-2.5.19_20260424.tar.xz (15M) https://gnupg.org/ftp/gcrypt/gnupg/gnupg-w32-2.5.19_20260424.tar.xz.sig This source tarball may also be used to download all required libraries at once to build a Unix version on any modern system. See the included README. Debian Packages =============== We also provide Debian style packages for a couple of Debian variants. See https://repos.gnupg.org/deb/gnupg/trixie/ or use the menu to switch to other distros/releases. If you encounter packaging problems please report them to the gnupg-devel mailing list. Due to the holidays it may take a few days until the packages are available. Windows Installer ================= A new Version of Gpg4win is in planning. For those who are affected by one of the now fixed bugs, it is possible to install the simple Windows installer mentioned above on top of gpg4win 5.0.1. Checking the Integrity ====================== In order to check that the version of GnuPG which you are going to install is an original and unmodified one, you can do it in one of the following ways: * If you already have a version of GnuPG installed, you can simply verify the supplied signature. For example to verify the signature of the file gnupg-2.5.19.tar.bz2 you would use this command: gpg --verify gnupg-2.5.19.tar.bz2.sig gnupg-2.5.19.tar.bz2 This checks whether the signature file matches the source file. You should see a message indicating that the signature is good and made by one or more of the release signing keys. Make sure that this is a valid key, either by matching the shown fingerprint against a trustworthy list of valid release signing keys or by checking that the key has been signed by trustworthy other keys. See the end of this mail for information on the signing keys. * If you are not able to use an existing version of GnuPG, you have to verify the SHA-1 checksum. On Unix systems the command to do this is either "sha1sum" or "shasum". Assuming you downloaded the file gnupg-2.5.19.tar.bz2, you run the command like this: sha1sum gnupg-2.5.19.tar.bz2 and check that the output matches the next line: dbe9ce2aca9d553ed4367692575cee15204a95a6 gnupg-2.5.19.tar.bz2 e4de189d1310893b2f8e565781d25093944b883e gnupg-w32-2.5.19_20260424.tar.xz a2b9b2d0ad979209e1c74f28ff910ce6f97f0e41 gnupg-w32-2.5.19_20260424.exe Internationalization ==================== This version of GnuPG has support for 26 languages with Chinese, Czech, Dutch, French, Georgian, German, Italian, Japanese, Norwegian, Polish, Portuguese, Russian, Turkish, and Ukrainian being almost completely translated. Documentation and Support ========================= The file gnupg.info has the complete reference manual of the system. Separate man pages are included as well but they miss some of the details available only in the manual. The manual is also available online at https://gnupg.org/documentation/manuals/gnupg/ or can be downloaded as PDF at https://gnupg.org/documentation/manuals/gnupg.pdf You may also want to search the GnuPG mailing list archives or ask on the gnupg-users mailing list for advise on how to solve problems. Most of the new features are around for several years and thus enough public experience is available. https://wiki.gnupg.org has user contributed information around GnuPG and relate software. If you are using cleartext signatures in your application please read https://gnupg.org/blog/20251226-cleartext-signatures.html and maybe https://gnupg.com/20260122-39C3_reply_gpg_fail.html In case of build problems specific to this release please first check https://dev.gnupg.org/T7998 for updated information. We are sorry that due to ongoing DoS on this service, you may end up at a "is under maintenance page". Please consult the archive of the g