Re: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Peter Lebbing
On 04/09/18 18:31, Fiedler Roman wrote: > /usr/bin/gpgv --status-fd 2 --homedir /proc/self/fd/nonexistent --keyring > sign.pub /proc/self/fd/0 You missed my point. You are not including a slash in the keyring argument, so gpgv is looking for it in the homedir. To quote the gpgv man page again:

AW: AW: AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Fiedler Roman
> Von: Werner Koch [mailto:w...@gnupg.org] > > On Tue, 4 Sep 2018 10:08, roman.fied...@ait.ac.at said: > > > [GNUPG:] UNEXPECTED 0 > > The signature is corrupted in that it has a packet which is expected > only in a key. Or the provided key has a data signature packet etc. I hope not :-) If any

Re: Issue with pinentry GUI agent

2018-09-04 Thread Daniel Kahn Gillmor
On Mon 2018-09-03 09:58:24 +0200, Kristian Fiskerstrand wrote: > Just to have it mentioned, turned out this was an issue with missing > keep-display in gpg-agent.conf, without this the Qt4/5 pinentry fail > (although I've been told it is not an issue in KDE environment). to be clear, keep-display

Re: AW: AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Werner Koch
On Tue, 4 Sep 2018 10:08, roman.fied...@ait.ac.at said: > [GNUPG:] UNEXPECTED 0 The signature is corrupted in that it has a packet which is expected only in a key. Or the provided key has a data signature packet etc. How did you create the keyfile and the signature? > Could it be, that

Re: AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Werner Koch
On Tue, 4 Sep 2018 09:52, roman.fied...@ait.ac.at said: > Werner gave a good solution in another followup message. May I recommend > updating the online docu/man page for "--verify" with something like this? we have Note: Sometimes the use of the @command{gpgv} tool is easier than using

AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Fiedler Roman
> Von: Peter Lebbing [mailto:pe...@digitalbrains.com] > > On 04/09/18 15:22, Peter Lebbing wrote: > > I don't understand, could you give commands, expected behaviour and > > actual output? > > To clarify, I thought you were giving an example of "starting gpgv > without any keyring at all",

Re: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Peter Lebbing
On 04/09/18 15:22, Peter Lebbing wrote: > I don't understand, could you give commands, expected behaviour and > actual output? To clarify, I thought you were giving an example of "starting gpgv without any keyring at all", because you gave it a non-existing homedir. Only on re-reading your other

Re: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Peter Lebbing
On 04/09/18 10:08, Fiedler Roman wrote: > /usr/bin/gpgv --status-fd 2 --homedir /proc/self/fd/nonexistent --keyring > key.pub data.gpg This would open /proc/self/fd/nonexistent/key.pub as the keyring. From the man page of gpgv: > Add file to the list of keyrings. If file begins

Re: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Peter Lebbing
On 04/09/18 13:55, Fiedler Roman wrote: > This might be an issue, but now I tried also with the "pubring.kbx" file > from the key used to create the signature (without exporting anything) > and the error message stays completely the same. I don't understand, could you give commands, expected

AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Fiedler Roman
> Von: Peter Lebbing [mailto:pe...@digitalbrains.com] > > On 04/09/18 09:52, Fiedler Roman wrote: > > Maybe the current hammer documentation should be updated, to remove > > the "--use-as-hammer" options? Or at least declare, that they shall not > > be used that way. See: > > > >

Re: Subkeys

2018-09-04 Thread Wiktor Kwapisiewicz via Gnupg-users
Hi Roland, I don't know if you have some specific questions but the Debian wiki page about Subkeys is nice: https://wiki.debian.org/Subkeys tl;dr version is primary/subkey setup lets you have your primary key completely offline and use subkeys for daily work. If something bad happens to a subkey

Re: Gnupg-users Digest, Vol 180, Issue 3

2018-09-04 Thread Wiktor Kwapisiewicz via Gnupg-users
On 04.09.2018 10:29, Roland Siemons (P) wrote: > Remains: > How can I see what is on the smartcard? gpg --card-status > How can I copy files to the smartcard? You can't copy generic files, smartcard contains only private keys (gpg --edit-key X, keytocard) and a small amount of data objects (gpg

Re: First smartcard operation always fails

2018-09-04 Thread Peter Lebbing
On 04/09/18 10:17, Andrew Gallagher wrote: > And I have just confirmed (by sending that mail) that both the first > auth operation AND the first signing operation fail, separately. I have no idea, it's quite curious. As an added bread crumb to follow: what do the PIN retry counters say after the

Re: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Peter Lebbing
On 04/09/18 09:52, Fiedler Roman wrote: > Maybe the current hammer documentation should be updated, to remove > the "--use-as-hammer" options? Or at least declare, that they shall not > be used that way. See: > > https://www.gnupg.org/gph/en/manual/r1606.html >

Subkeys

2018-09-04 Thread Roland Siemons (P)
Dear GnuPG As a user of GPG4Win, is there any explanation in the compendium about the meaning and use of subkeys (I cannot find anything about that matter in the The Gpg4win Compendium 3.0.0) Best regards, -- Roland Siemons 0xAEEC5E2ED87628F5.asc Description: application/pgp-keys

Re: Gnupg-users Digest, Vol 180, Issue 3

2018-09-04 Thread Roland Siemons (P)
@ Dirk Gottschalk: Thanks for very effective response to my first question! Remains: How can I see what is on the smartcard? How can I copy files to the smartcard? I studied the GnuPG Smartcard How-To (www.gnupg.org/howtos/card-howto/en/smartcard-howto.html), but that is entirely linux oriented.

Re: First smartcard operation always fails

2018-09-04 Thread Andrew Gallagher
On 04/09/18 09:11, Andrew Gallagher wrote: > Hi, all. > > I've had a pgp smartcard v2.1 for years now (two, actually), and I've > noticed that no matter what operation I perform, the first attempt after > inserting the card, or waking from sleep with the card inserted, fails. And I have just

First smartcard operation always fails

2018-09-04 Thread Andrew Gallagher
Hi, all. I've had a pgp smartcard v2.1 for years now (two, actually), and I've noticed that no matter what operation I perform, the first attempt after inserting the card, or waking from sleep with the card inserted, fails. Example: ``` andrewg@fred:~$ ssh my.server sign_and_send_pubkey:

AW: AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Fiedler Roman
> Von: Werner Koch [mailto:w...@gnupg.org] > > On Mon, 3 Sep 2018 19:25, pe...@digitalbrains.com said: > > > It could be that recently an option was added to check a signature by a > > certificate in a file, but in general you need to import a certificate > > No, that is nlot the case. We only

AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Fiedler Roman
> Von: Peter Lebbing [mailto:pe...@digitalbrains.com] > > On 03/09/18 18:56, Fiedler Roman wrote: > > With gpg1 a similar command should have verified, that the signature > > is exactly from the single public key stored in "key.pub". > > This has never been a supported use of gpg, it just happened

Re: AW: How to fix "ERROR key_generate 3355453" / "GENKEY' failed: IPC call has been cancelled"

2018-09-04 Thread Werner Koch
On Mon, 3 Sep 2018 19:25, pe...@digitalbrains.com said: > It could be that recently an option was added to check a signature by a > certificate in a file, but in general you need to import a certificate No, that is nlot the case. We only added the option -f to encrypt to a key taken from a