gpg-agent-ssh is an unnecessary dependency of gnupg

Bug #1997038 reported by Avamander
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnupg (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

Installing gnupg will also install and depend on gpg-agent(-ssh) which will replace ssh-agent.

This is bad due to the fact that gpg-agent-ssh takes an exclusive lock on all smartcards incorrectly yet does not actually support neither PIV or opensc-pkcs11 integration. Until gnupg/gpg-agent/scdaemon learns how to behave or adds support for PIV, it's not a viable replacement and should not be considered as such.

Meaning gpg-agent-ssh will be installed and break PIV-based SSH authentication. gpg-agent-ssh should NOT be installed unless specifically requested, the very least it should NOT be enabled in any way unless explicitly requested. It's a boneheaded nuisance of a dependency right now.

Revision history for this message
Avamander (avamander) wrote :

Also confirmed five years ago in this issue https://github.com/OpenSC/OpenSC/issues/953

Changed in gnupg (Ubuntu):
status: New → Confirmed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.