Gpg4win version 5.1.0 is available since 2026-07-29.
Changes
Kleopatra
- Improvement of the first part of the decryption/verification messages. (T8273)
- Improvement of the import certificates dialog text. (T7446)
- The default appearance of S/MIME root certificates was changed. (T8275)
- Addition of "Save Secret Team Key" button to success message of "Team Key"-creation. (T8166)
- Addition of "Copy" button to context menu of details tables. (T8134)
- Removal of "Backup secret key" from the context menu. (T8153)
- Removal of the .gpgsk backup offer when moving keys to card. (T8327)
- Removal of unnecessary path info from file verification feedback. (T8332)
- We now use a shorter text for verification with same name ".sig" file. (T7795)
- Prevent starting Kleopatra as Admin on Windows. (T8210)
- Decrypting packets with hybrid cipher works again without entering a symmetric passphrase. (T7339)
- Cancellation of signing only operation now reports cancellation. (T8289)
- Fix application of certificate category styling. (T8279,T8258)
- Gpgme: Fix hanging file encryption due to invalid S/MIME certificate. (T8187)
- Use an outer folder in archive decryption if the archive was renamed. (T8154)
- Do not offer "Save Secret Team Key" for card keys. (T8146)
- Do only ask for confirmation twice when deleting a secret key. (T7538)
- Add ".pub" suffix to the file selector filter when importing certificates in Kleopatra. (T7451)
- Cancellation of team key save dialog no longer keeps a background process open. (T8150)
- Prevent creation of opaquely signed unencrypted archives (S/MIME or mixed encryption). (T8324)
- Fix application order from settings via windows registry and config files. (T5707)
- Fix protocol check of detached OpenPGP signatures. (T8337)
- Fix info in smart card usage column for auth keys. (T8316)
- Disable subkey backup action in key details for primary key. (T8321)
- Prevent startup of dirmngr if it has been disabled via config files. (T8304)
Okular/GnuPG-edition
- Fix shown trust information for "not trusted" or "not verified" S/MIME certificates. (T8294)
- Not trusted certificate are no longer offered for signing. (T8017)
- Prevent overwriting of the original file when saving the signed document. (T7705)
- Fix for resizing/moving new signature. (T8335)
- Fix link to Kleopatra in signature properties. (T8295)
- OpenPGP certificate export now creates ".asc" files. (T8293)
- Fix OpenPGP fingerprints in signature properties. (T8291)
- Give an error when trying to sign with wrong passphrase. (T8018)
- Improvement of error messages when signing. (T7285)
- Highlight / preselect "nonRepudiation" certificates for qualified signatures. (T6632)
- Disable file saving during the signing process. (T8314)
- Disable reload during signing process. (T8345)
- Hide (unhelpful) details in bad passphrase error dialog (T8341)
Outlook Classic Add-In (GgpOL)
- The Ribbon Icon and Tooltip now reflect the selected security settings of a new mail. (T7098)
- Content of HTML-only OpenPGP mails is now shown with "Read as plain" activated. (T7843)
- Fix for cases where attached mails were shown empty. (T7806,rO06e35e5)
- Fix multipart attachment type in case of no cid. (T8161)
- p7m attachments no longer break attachment parsing. (T8113)
- Fix an Outlook freeze when saving S/MIME encrypted draft. (T7837)
- Fix memory leaks. (rC5b52c25,rCc18e33a)
- Fix for a case where the overlay did stay open after sending. (rO0d36b54)
- gpg4win-tools: Fix encoding for status information. (T8362)
Outlook-New Add-In (GpgOL/Web)
Several improvements to this still EXPERIMENTAL component. Among others:
- The native client now initially acts as a straight forward first install wizard, and becomes an intuitively usable configuration dialog afterwards.
- Improved status notification in both native client and tray icon.
- When no secret key is available for the current Outlook account, the addin helps you generate one (through Kleopatra).
- Attached public keys can be imported to your keyring directly.
- You can now attach all relevant public keys to an outgoing message automatically.
- Addin windows are now opened in the foreground.
- The security level of keys used for signing a message is prominently shown.
- The addin can't be run with admin privileges any longer.
- Usability of the reencrypt feature was significantly improved.
- Binding the addin components no longer relies on the account's e-mail address.
- Improved handling of the TLS certificate generating process.
- Addition of a warning if there's a mismatch between installed version and the one registered with Outlook (manifest).
Engine (GnuPG)
For changes in the backend see the release info for GnuPG versions from 2.5.19 up to 2.5.21: (T7998,T7997,T8262)
Versions of the Components
| Component |
Version |
Remarks |
| GnuPG |
2.5.21 |
T8262 |
| Kleopatra |
gpg4win-5.1.0 |
|
| GpgOL |
2.7.3 |
|
| GpgEX |
1.1.2 |
|
| Libgcrypt |
1.12.2 |
T8114 |
| Libksba |
1.8.0 |
T8253 |