Re: how to disable pinentry

2015-02-25 Thread Stephan Beck
Hi, Cathy, Am 25.02.2015 um 17:51 schrieb Smith, Cathy: > > One of my goals of this is to be able to set a passphrase on a key in batch processing. Perhaps, there is another way to accomplish that? > > I am not sure if that's the solution to your problem, but according to the *Unattended Key G

Re: Can't Encrypt in Freebsd 10.1

2015-02-26 Thread Stephan Beck
Hi, Antoine, Am 25.02.2015 um 14:07 schrieb Antoine Michard: > Hi, > > Still not working :( > Got no idea why... > > #gpg -r 6349E5E0 -e test.txt > Abort [...] > And then try to encryp a file: > # gpg -r F2E7CBA5 -e test.txt > Abort > I am not familiar with BSD but this should apply to BSD ins

Re: Can't Encrypt in Freebsd 10.1

2015-02-26 Thread Stephan Beck
real user > and not to root, who isn't a normal user. > May be it will help you. > --pit > > Von: Stephan Beck > An: gnupg-users@gnupg.org > Gesendet: 14:29 Donnerstag, 26.Februar 2015 > Betreff: Re: Can't Encrypt in Freebsd 10.1 > > H

Re: German ct magazine postulates death of pgp encryption

2015-03-02 Thread Stephan Beck
Am 28.02.2015 um 13:31 schrieb Peter Lebbing: > PS: By the way, my ISP and some of it's employees are in a perfect position to > do a man in the middle. No doubt about it. And we actually don't know how they "use" their position. Well, looking at some sort of collaboration published a few weeks

Fwd: Re: German ct magazine postulates death of pgp encryption

2015-03-03 Thread Stephan Beck
ephan Beck , gnupg-users@gnupg.org On 02/03/15 11:35, Stephan Beck wrote: > Sticking to that "perfect position argument", in what kind of position are > (would be) the people that control (packaging of) your distro? (Just > curious.) I think they basically completely control m

Re: Fwd: Re: German ct magazine postulates death of pgp encryption

2015-03-03 Thread Stephan Beck
Am 03.03.2015 um 14:00 schrieb Ville Määttä: > On 03.03.15 14:54, Stephan Beck wrote: >> as your message hasn't reached the list inspite of being addressed to it > > It did :). > Strange, I did only receive the PM, not the listmail, so I thought it might be useful to

Re: Enigmail speed geeking

2015-03-11 Thread Stephan Beck
Hi Robert, Am 11.03.2015 um 18:10 schrieb Robert J. Hansen: > "Things you're doing wrong with Enigmail" is a short (500-word) essay on > four mistakes I repeatedly see Enigmail users making. However, it's not > limited to Enigmail: most of the content is broadly applicable to any > cryptosystem.

Re: Enigmail speed geeking

2015-03-12 Thread Stephan Beck
Am 12.03.2015 um 16:51 schrieb Robert J. Hansen: >> As to your enigmail essay, point 1, would you go that far that >> keeping keys on hard disk is unsafe and using a smart card is a >> must? > > If email crypto makes it hard to read email, few people will adopt the > technology. We want technolo

Question concerning OpenLDAP PGP Keyserver setup guide (wiki.gnupg.org)

2015-03-12 Thread Stephan Beck
Hi, reproducing the OpenLDAP PGP keyserver setup guide on http://wiki.gnupg.org, published by Neal, I get the following error message: ldapmodify: wrong attributeType at line 5, entry "olcDatabase={1}hdb,cn=config" I am reproducing the guide on debian stable (main sources only), which uses "hdb"

Re: Enigmail speed geeking

2015-03-13 Thread Stephan Beck
Am 13.03.2015 um 22:33 schrieb Robert J. Hansen: > GnuPG doesn't have one RNG. It has *many* RNGs. Some of them are > really just thin wrappers over lower-level OS facilities. And if you > don't trust /dev/urandom, I'd suggest using a different operating > system, because that's a game-over com

Re: Question concerning OpenLDAP PGP Keyserver setup guide (wiki.gnupg.org)

2015-03-13 Thread Stephan Beck
Obviously, this ** has to be OpenLDAP(slapd)2.4.31 not 3, sorry! Still stuck in there, though. Am 13.03.2015 um 00:00 schrieb Stephan Beck: > Hi, > > reproducing the OpenLDAP PGP keyserver setup guide on http://wiki.gnupg.org, > published by Neal, I get the following e

Re: Enigmail speed geeking

2015-03-15 Thread Stephan Beck
Am 15.03.2015 um 13:59 schrieb Robert J. Hansen: >> Wouldn't the installation of haveged, at least for GNU/linux distros, >> extend the possibilities of traditional /dev/(u)random based RNG? > > No idea -- I haven't looked at haveged. Sorry. :( Well, I forgot to include relevant information (s

Re: Enigmail speed geeking

2015-03-15 Thread Stephan Beck
Am 15.03.2015 um 16:32 schrieb Stephan Beck: > Am 15.03.2015 um 13:59 schrieb Robert J. Hansen: >>> Wouldn't the installation of haveged, at least for GNU/linux distros, >>> extend the possibilities of traditional /dev/(u)random based RNG? >> >> No idea

Re: Enigmail speed geeking

2015-03-15 Thread Stephan Beck
Am 15.03.2015 um 20:50 schrieb Werner Koch: > On Sun, 15 Mar 2015 16:32, st...@mailbox.org said: > >> Now, I'll look for information on how RNG in GnuPG exactly works. It *seems* >> that haveged should impact on the gathering of entropy (available) at the >> moment >> of keypair generation on any

Re: Enigmail speed geeking

2015-03-16 Thread Stephan Beck
Am 16.03.2015 um 08:48 schrieb Werner Koch: > On Sun, 15 Mar 2015 23:38, st...@mailbox.org said: > >> Thanks, Werner. I read that, but I was particularly interested in how to get >> GnuPG work with haveged. > > You should feed it into /dev/random or get into the kernel proper. This > way all app

Re: Error Installing gnupg-2.0.27 on Debian Squeeze

2015-03-22 Thread Stephan Beck
Hi Angel, I cannot reproduce the error and I don't know which documentation you exactly refer to, but using Debian Squeeze (oldstable) you need the gnupg and libgcrypt oldstable versions that are adequate for you. I'd use the package manager (apt) for installing it. Here's what I found (1): gnupg

Re: Weird error during key refresh

2015-03-25 Thread Stephan Beck
Hi Doug, it's an error very similar to the one I've got using --refresh-keys with a specified -keyserver [name]. Did you try to specify the keyserver's name and enable both --use-temp-files and --keep-temp-files? The output of the temp files retain the communication data of the refreshing action a

Re: Enabling and using ECC keys (any reason not to?)

2015-03-28 Thread Stephan Beck
Am 27.03.2015 um 14:21 schrieb Martin Behrendt: > On 26.03.2015 18:40, Pete Stephenson wrote: >> >> People have raised concerns about the NIST curves, but they are part >> of the RFC 6637 standard so compliant programs must implement P-256, >> may implement P-384, and should implement P-521. >> >>

Re: SSH CA and OpenPGP card

2015-03-29 Thread Stephan Beck
Am 27.03.2015 um 13:36 schrieb Bolesław Tokarski: > Hello, [...] > Is the PKCS#11 library for OpenPGP card usable? I guess you may install and use gnupg-pkcs11-scd for that purpose, provided that you only use RSA keys. See /usr/share/man/man1/gnupg-pkcs11-scd.1 for more info. Hope that helps

Re: Teaching GnuPG to noobs

2015-06-18 Thread Stephan Beck
Hi, Am 16.06.2015 um 15:50 schrieb A.T. Leibson: > Lastly, what's your favorite noob-friendly guide, and why? I think that the guide available at (1) (1) https://emailselfdefense.fsf.org/en/ is the most suitable for noobs (as far as I know), because it's straightforward and short. I would no

Re: Teaching GnuPG to noobs

2015-06-19 Thread Stephan Beck
Am 18.06.2015 um 21:37 schrieb Chuck Peters: > Stephan Beck said: >> Am 16.06.2015 um 15:50 schrieb A.T. Leibson: >> >>> Lastly, what's your favorite noob-friendly guide, and why? >> >> I think that the guide available at (1) >> >> (1

Re: Heuristics of gpg's output

2016-02-13 Thread Stephan Beck
Ingo Klöcker: > On Saturday 13 February 2016 18:20:09 st...@mailbox.org wrote: >> Hi, >> >> a few days ago I downloaded [snip] > It doesn't tell us anything because the signature does not belong to the > iso file. The signature SHA256SUMS.sign belongs to the file SHA256SUMS > which contains th

Re: Key Discovery Made Simple

2016-09-08 Thread Stephan Beck
Hi Christopher, Christopher Beck: > Hi, > > just a (maybe) stupid question: the matching key to my recipient can be > fetched by keyservers and i determine the korrect key of all of the > (sometimes > "wrong" keys") by vaidating the signatures according to the WoT. So, what's > the benefit of th

Re: gpg-agent only works when started in terminal

2016-09-09 Thread Stephan Beck
Hi Antony, just some ideas to (possibly) track it down... Antony Prince: > I know this has got to be something simple. When invoking gpg2 normally > to decrypt, I get: > > gpg: encrypted with 4096-bit RSA key, ID 0E98CD22ADB13E99, created > 2015-05-06 > "Antony Prince " > gpg: public key d

Re: :-(( Re: smart card no longer works

2016-09-10 Thread Stephan Beck
Hi Philip, Philip Jackson: > On 10/09/16 06:27, NIIBE Yutaka wrote: > >> I don't have any experience with this error behavior. Please describe >> the situation and the interaction; Did you input passphrase and push >> [OK] button, and then gpg failed? >> >> Please try again with pinentry-curses

Re: :-(( Re: smart card no longer works

2016-09-11 Thread Stephan Beck
Philip Jackson: > On 10/09/16 20:56, Stephan Beck wrote: > It looks like I got the process of moving to a new installation wrong. > So I am in need of a precise process description to start again and do > it correctly. Which type of smartcard do you have? Which gnupg versions we

Re: :-(( smart card no longer works

2016-09-11 Thread Stephan Beck
Peter Lebbing: > On 10/09/16 20:56, Stephan Beck wrote: > [...] > It looks fine to me, I think you're getting confused by it referring to > the key in several ways. Here's part of the output for "gpg2 -v -d" for me: > >> gpg: public key is 73A33BEE

Re: :-(( Re: smart card no longer works

2016-09-16 Thread Stephan Beck
Hi, Philip Jackson: > On 11/09/16 19:49, Stephan Beck wrote: >> Which type of smartcard do you have? Which gnupg versions were installed >> on the the old system and with which of it did you generate keys? > > > The smartcard is a version2.0 made by ZeitControl and bough

Re: :-(( Re: smart card no longer works

2016-09-19 Thread Stephan Beck
Philip Jackson: > On 16/09/16 22:09, Stephan Beck wrote: >> Sorry for the delayed response. >> It's not enough to simply copy and paste all the files into the new >> ~/.gnupg directory, as you write you did in your previous mail. You have >> to run gpg2 with th

Re: :-(( Re: smart card no longer works

2016-09-21 Thread Stephan Beck
Hi, Philip Jackson: > On 19/09/16 13:02, Stephan Beck wrote: > > Yes, Stephan, that seems to have solved the issues I had with > verification. The command you suggested does not work as you wrote it - > I got words to the effect that the command was not recognised. > >

Re: Compilation problems while building GnuPG 2.1.15, no TLS no sqlite3

2016-09-24 Thread Stephan Beck
I sent this message yesterday at midnight and it hasn't made it to the list yet, so I resend it. Stephan Beck: > Hi, > > compiling the latest version of GnuPG, there were some config errors and > gnupg was compiled without TOFU and TLS, although I have installed the > pac

Fwd: Compilation problems while building GnuPG 2.1.15, no TLS no sqlite3

2016-09-26 Thread Stephan Beck
nutls components apt/synaptic cannot resolve on my specific intallation. Stephan Forwarded Message Subject: Compilation problems while building GnuPG 2.1.15, no TLS no sqlite3 Date: Sat, 24 Sep 2016 22:12:00 + From: Stephan Beck Reply-To: st...@mailbox.org To: gnupg-users@gnup

Re: Compilation problems while building GnuPG 2.1.15, no TLS no sqlite3

2016-09-26 Thread Stephan Beck
Thanks, Werner. Werner Koch: > On Sun, 25 Sep 2016 08:35, st...@mailbox.org said: >> Stephan Beck: > >>> gnupg was compiled without TOFU and TLS, although I have installed the >>> packages gnutls-bin and sqlite3 after a first compilation run had given > > Y

Re: automate pga clipboard

2016-09-30 Thread Stephan Beck
Hi, tim.dcl...@gmail.com: > i am using GPA 0.9.9 to encrypt text file data. i copy/paste my text > into the clipboard and hit encrypt. Im prompted to choose public key. > After choosing, i get the following results (less the blah blahs). > > I would like to do this from a command line so i can do

Re: recording and retrieving "secrets" into gpg files

2016-09-30 Thread Stephan Beck
Hi Arbiel, Arbiel (gmx): > Hi > > Thank you Andrew. > > In the material I've been ready lately, all examples are written in a > programming language and I only have abilities in bash scripting. > > Can somebody, please, direct me toward a url where they provide bash > scripting examples. [...]

Re: recording and retrieving "secrets" into gpg files

2016-10-04 Thread Stephan Beck
ked again but haven't found anything specific related to your question. Cheers, Stephan > Le 30/09/2016 à 17:30, Stephan Beck a écrit : >> Hi Arbiel, >> >> Arbiel (gmx): >>> Hi >>> >>> Thank you Andrew. >>> >>> In the mat

Re: Agent forwarding failure when the socketdir was autodeleted

2016-10-05 Thread Stephan Beck
Hi, Daniel Kahn Gillmor: > Hi Andre-- > > On Tue 2016-10-04 14:49:00 -0400, Andre Heinecke wrote: > >> On Tuesday 04 October 2016 11:26:59 Daniel Kahn Gillmor wrote: But if I am not logged in or there is no gnupg process running. systemd autodeletes /var/run/user//gnupg this causes the

Re: Agent forwarding failure when the socketdir was autodeleted

2016-10-05 Thread Stephan Beck
Oh, just seen Werner's answer :-) Well, I had a good time reading the mentioned docs ;-) Cheers, Stephan Stephan Beck: > Hi, > > Daniel Kahn Gillmor: >> Hi Andre-- >> >> On Tue 2016-10-04 14:49:00 -0400, Andre Heinecke wrote: >> >>> On Tuesd

Re: Agent forwarding failure when the socketdir was autodeleted

2016-10-05 Thread Stephan Beck
Oh, just seen Werner's answer :-) Well, I had a good time reading the mentioned docs ;-) Cheers, Stephan Stephan Beck: > Hi, > > Daniel Kahn Gillmor: >> Hi Andre-- >> >> On Tue 2016-10-04 14:49:00 -0400, Andre Heinecke wrote: >> >>> On Tuesd

Re: unable to decrypt a mail coming from apple mail

2016-10-14 Thread Stephan Beck
Hi, ng0: > Hi, > > I've just got an email where the X-Mailer is Apple Mail. It adds some > bits and pieces, is a 7bit Content-Transfer-Encoding and I fail to > decrypt it with gpg --decrypt (applied to the email as a file and also > when applied to the BEGIN/END PGP block). > The key is imported,

Fwd: Re: regular update of all keys from a keyserver

2016-10-17 Thread Stephan Beck
I forgot to send it to the list as well... Forwarded Message Subject: Re: regular update of all keys from a keyserver Date: Mon, 17 Oct 2016 16:20:00 + From: Stephan Beck Reply-To: st...@mailbox.org To: Martin T Hi Martin, Martin T: > Hi, > > I am aware tha

Re: reviewing wiki / shortlist PIN-pad readers

2016-10-18 Thread Stephan Beck
Hi, NIIBE Yutaka: > Sorry, I didn't have time to reply your call the other day. > > I think that Gemalto Shelltoken Card Reader, which is available > at http://shop.kernelconcepts.de/ is good one. > > Please note that OpenPGP card requires specific card readers. Its > users usually use RSA-2048,

Re: smartcard reader

2016-10-18 Thread Stephan Beck
Hi Liz, Elizabeth Ferdman: > Hello, > > I'm in the market for a smartcard reader and I live in the United > States. I found two ways to get an OpenPGP card already, either from > shop.kernelconcepts.de or from the FSFE as a sustaining member. > Does anyone know how I can get a smart card reader

Re: Why doesn't gpg-agent forwarding work?

2016-10-18 Thread Stephan Beck
Hi Kevin, Kevin Gallagher: > Hi all, > > I've tried to get this working to no avail. I've consulted past postings > to this list as well as various online references. Some people seem to > have got this to work, but most seem to have trouble. I would appreciate > any guidance or help anyone can o

Re: Why doesn't gpg-agent forwarding work?

2016-10-19 Thread Stephan Beck
Hi, (update) Stephan Beck: > Hi Kevin, > >> Setting some environment variables in the VM does not help: >> >> GPG_AGENT_INFO=/home/vagrant/.gnupg/S.gpg-agent:0:1 >> GPG_SOCK=/home/vagrant/.gnupg/S.gpg-agent >> GPG_TTY=/dev/pts/1 > > And if

Re: smartcard reader

2016-10-19 Thread Stephan Beck
Hi, NIIBE Yutaka: > On 10/19/2016 12:40 AM, Stephan Beck wrote: >>> FSIJ Gnuk Token >>> USB ID: 234b: > > Ah... This is not a card reader. It is the project of Free Software > Initiative of Japan (FSIJ) since 2010. FSIJ acquired USB vendor ID, > speci

Re: reviewing wiki / shortlist PIN-pad readers

2016-10-19 Thread Stephan Beck
Werner Koch: > On Tue, 18 Oct 2016 13:11, st...@mailbox.org said: > >> For example, The Nitrokey Storage (1,2), a usb crypto stick with >> integrated card reader) is 100% open source, free software, verifiable >> firmware. On the other hand, it has no pinpad. > > and using a proprietary card fo

Re: configure warnings and errors upon ./configure for Pinentry v0.9.7

2016-11-21 Thread Stephan Beck
Hi, David Adamson: > On Mon, Nov 21, 2016 at 4:16 AM, Werner Koch wrote: > >>> configure: error: No pinentry enabled. >> >> You need to install the appropriate development package for the GUI >> platform. > > I looked for a GUI platform but had no idea what it's called where to > find it and wh

Re: GPGSM detached signature without auth attributes

2016-11-21 Thread Stephan Beck
Hi Jerney, Jernej Kos: > Hello! > > I would like to use GPGSM to sign a Linux kernel module with a private > key stored on an OpenPGP smartcard. As to the OpenPGP card 2.1 [1] specification, you can store the private key of an X.509 certificate on card (Data Object Cardholder Certificate, TAG 7F

Re: configure warnings and errors upon ./configure for Pinentry v0.9.7

2016-11-21 Thread Stephan Beck
Hi, David Adamson: > On Mon, Nov 21, 2016 at 12:33 PM, Stephan Beck wrote: >> Hi, >> >> David Adamson: >> >> If you only want to use the command line (i.e. text mode) and do not >> need a GUI, you'll probably need the pinentry-curses package. I

Re: GPGSM detached signature without auth attributes

2016-11-21 Thread Stephan Beck
Hi, I forgot to include the links to the docs. [1] http://g10code.com/docs/openpgp-card-2.1.pdf [2] http://g10code.com/docs/openpgp-card-3.0.pdf Stephan Beck: > Hi Jerney, > > Jernej Kos: >> Hello! >> >> I would like to use GPGSM to sign a Linux kernel module with a

Re: GPGSM detached signature without auth attributes

2016-11-22 Thread Stephan Beck
Hi, Jernej Kos: > Hello! > > Not sure about what you mean with the OpenPGP card not supporting > signing? I have set gpgsm to use the signing key on the OpenPGP card (in > key slot 1) for generating X509 certificates and CMS (S/MIME) signatures > by doing: > > gpgsm --learn-card > gpgsm --ge

Re: configure warnings and errors upon ./configure for Pinentry v0.9.7

2016-11-23 Thread Stephan Beck
Hi, David Adamson: > On Mon, Nov 21, 2016 at 8:15 PM, Stephan Beck wrote: >> Ah, I forgot one thing: you have to add the following to your ~/.bashrc >> file: >> GPG_TTY=$(tty) >> export GPG_TTY >> >> Does it work now? >> >> HTH >> >

Re: Implications of a common private keys directory in 2.1

2016-11-23 Thread Stephan Beck
Peter Lebbing: > On 23/11/16 10:53, Andrew Gallagher wrote: >> If the message is being automatically decrypted at the MTA then it >> provides no more security than TLS. > > I could concur with this statement if we amend it a little: when two > MTA's are explicitly configured as TLS peers. They h

Re: configure warnings and errors upon ./configure for Pinentry v0.9.7

2016-11-23 Thread Stephan Beck
Peter Lebbing: > On 23/11/16 11:14, Stephan Beck wrote: >> [...] and properly symlink >> /usr/bin/pinentry to the pinentry-curses you actually would like to use >> if you are using text-mode only, I don't know why it should not work. > [...]So by installing the Deb

Re: Trying to figure out what's going on with a key update failure...

2016-11-23 Thread Stephan Beck
Anthony Papillion: > Hello Everyone, > > When I run > > gpg2 --keyserver --refresh-keys > > I get a list of all of the keys in my keyring with the message that they > have not been changed (this is expected). At the bottom of the output, I > see the following message: > > gpg: Total number p

Re: Is --export-ssh-key functionality possible with GnuPG 2.0?

2016-11-24 Thread Stephan Beck
Hi Teemu, Teemu Likonen: > Keys with authentication capability can be used with ssh, and GnuPG > 2.1's command --export-ssh-key will export the ssh public key. Right? Yes, --export-ssh-key has been introduced in gpg with release of version 2.1.11. To set the whole thing up, a few more steps are n

Re: Is --export-ssh-key functionality possible with GnuPG 2.0?

2016-11-25 Thread Stephan Beck
Hi, Peter Lebbing: > On 2016-11-24 16:59, Teemu Likonen wrote: >> I believe that file ~/.gnupg/sshcontrol should contain >> key's keygrip but how do I get the keygrip when there's no >> --with-keygrip option in 2.0? > > I think the following: > > $ gpg-connect-agent >> help keyinfo > # KEYINFO [

PM from David Adamson -please ask on-list

2016-11-25 Thread Stephan Beck
Hi David, I kindly invite you to post your PM on-list. It might be of interest for other people as well. Thanks and regards Stephan ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Trying to figure out what's going on with a key update failure...

2016-11-25 Thread Stephan Beck
Hi Anthony, Stephan Beck: > > > Anthony Papillion: >> Hello Everyone, >> >> When I run >> >> gpg2 --keyserver --refresh-keys >> >> Can someone tell me what this error means and how can I fix it? > > Which gpg2 version are you runnin

Re: Trying to figure out what's going on with a key update failure...

2016-11-25 Thread Stephan Beck
variations), the use-temp-files=/tmp/tempfile.txt is I used in my example below is plainly wrong. Cheers Stephan Stephan Beck: > Hi Anthony, > > Stephan Beck: >> >> >> Anthony Papillion: >>> Hello Everyone, >>> >>> When I run >>> >>&

Re: Is --export-ssh-key functionality possible with GnuPG 2.0?

2016-11-25 Thread Stephan Beck
Thanks, Peter. [no irony] Wherever you shed your light, I'm a bit more enlightened. Peter Lebbing: > Stephan, thanks for helping out! I think I can improve a bit on one part > of it, though. > > On 24/11/16 17:51, Stephan Beck wrote: >> A2) Export the secret subkey yo

Re: What are those attachments you have on your email?

2016-11-25 Thread Stephan Beck
/fetching/retrieving the signer's key gpg verifies that this message/file really was signed by the one who claims to be the signer. Cheers Stephan David Adamson: > On Fri, Nov 25, 2016 at 5:28 AM, Stephan Beck wrote: >> Hi David, >> >> I kindly invite you to post your

Re: What are those attachments you have on your email?

2016-11-26 Thread Stephan Beck
Hi, David Adamson: > On Fri, Nov 25, 2016 at 9:33 AM, Stephan Beck wrote: > Stephan so this is a result of you using a mail client that requires > the signature file and If I used a similar mail client it could > automatically verify this email message was signed by the holder of

Re: Is --export-ssh-key functionality possible with GnuPG 2.0?

2016-11-26 Thread Stephan Beck
ks! Stephan Peter Lebbing: > On 25/11/16 14:36, Stephan Beck wrote: >> Would you please describe more in detail where (or in which way, in >> which use case) the window is left open? > > Let me reuse a bit of quote from an earlier mail: > >>>> A2) Export th

Re: Is --export-ssh-key functionality possible with GnuPG 2.0?

2016-11-26 Thread Stephan Beck
Hi Teemu, Teemu Likonen: > Stephan Beck [2016-11-24 16:51:00Z] wrote: > >> A1) Install the monkeysphere package (1) that includes openpgp2ssh tool >> A2) Export the secret subkey you'd like to use for ssh authentication >> purposes and pipe it through openpgp2ssh &g

Re: Trying to figure out what's going on with a key update failure...

2016-11-26 Thread Stephan Beck
Anthony Papillion: > On 11/25/2016 4:02 AM, Stephan Beck wrote: >> Hi Anthony, >> > No problem. When I try to decrypt your message, I get the follow from GPG: > > gpg: invalid radix64 character 2D skipped > gpg: invalid radix64 character 2D skipped > gpg: invali

Re: Trying to figure out what's going on with a key update failure...

2016-11-26 Thread Stephan Beck
Stephan Beck: > > Anthony Papillion: [...] > > Thanks, Anthony. I'll have a look into libpgp-error, maybe I can find > some info. The message may have been altered (tampered). > Oops, I wrote and then I thought. To speak with the libgcrypt manual (libgcrypt uses lib

Re: Trying to figure out what's going on with a key update failure...

2016-11-26 Thread Stephan Beck
Hi Anthony, Anthony Papillion: > On 11/25/2016 4:02 AM, Stephan Beck wrote: [...] > > No problem. When I try to decrypt your message, I get the follow from GPG: > > gpg: invalid radix64 character 2D skipped > gpg: invalid radix64 character 2D skipped > gpg: invalid radix64

Re: Proof for a creation date

2016-12-02 Thread Stephan Beck
Hi Quan Zhou, Quan Zhou: > so GnuPG's timestamping isn't an option for this? > Even X509 has a timestamping feature for this kind of use. > > On Fri, Dec 2, 2016 at 11:59 AM, Schlacta, Christ > wrote: > >> The easiest way is to publish your code to a publicly controlled source >> with a signatu

Re: Still trying to troubleshoot --refresh-keys error

2016-12-04 Thread Stephan Beck
Anthony Papillion: > For the last few weeks, I've talked about how, when I try to refresh the > keys on my ring, I get an error from GnuPG. Today, I noticed a message > that I hadn't noticed before and I strongly suspect this might be the > cause of the problem I'm having. > > When I issued the >

Re: Proof for a creation date

2016-12-04 Thread Stephan Beck
MFPA: > > > On Friday 2 December 2016 at 1:46:00 PM, in > , Stephan Beck > wrote:- > > > >> gpg's signature timestamp (on a given file) would NOT >> be a real proof of >> a document being allegedly signed at that specific >> date or

Re: Implications of a common private keys directory in 2.1

2016-12-06 Thread Stephan Beck
Carola Grunwald: > Peter Lebbing wrote: >> On 25/11/16 00:03, Carola Grunwald wrote: [...] >> An option --only-try-secret would solve both (your software >> would know which to try for a given nym account), but such an option is >> not available. You could try to make the case that such an opti

Re: Implications of a common private keys directory in 2.1

2016-12-07 Thread Stephan Beck
Peter Lebbing: > On 06/12/16 15:53, Stephan Beck wrote: >> [...], and use it as in >> gpg2 --no-default-keyring --secret-keyring file --try-secret-key >> [NAME=aspecificlongKeyID | fingerprint] --decrypt >> any_signedANDencrypted_message.txt.gpg ? >> Would that

Re: Hybrid keysigning party, your opinion?

2016-12-07 Thread Stephan Beck
Peter Lebbing: > Hi all, > > In just a few weeks, the 33C3 will be held in Hamburg, the 33th Chaos > Communication Congress organized by the Chaos Computer Club. I intend to > organize a keysigning party, just because they are fun. > > I am asking for your thoughts on a variant of the organizat

Re: Hybrid keysigning party, your opinion?

2016-12-08 Thread Stephan Beck
Hi, Lachlan Gunn: > Le 2016-12-08 à 08:14, Stephan Beck a écrit : >> Doesn't your proposal imply that late attendees could >> make their way through all the keysigning without fingerprint >> verification? Or do I miss something? > > If I understand correctly, the

Re: Hybrid keysigning party, your opinion?

2016-12-08 Thread Stephan Beck
Peter Lebbing: > Stephan and Lachlan, thank you for thinking about this! I need to make a > decision soon, I really need feedback! > > On 07/12/16 22:44, Stephan Beck wrote: >> Doesn't your proposal imply that late attendees could >> make their way through all the k

Re: Hybrid keysigning party, your opinion?

2016-12-08 Thread Stephan Beck
Peter Lebbing: > On 08/12/16 14:14, Stephan Beck wrote: >> Just some meditations: >> >> So, the late attendees can see and hear that the ordinary participants >> confirm the checksum and that their fingerprints check out? > > Yes, the late attendees definitely

Re: An attempt at backporting 2.1.16 from Debian sid to Debian jessie

2016-12-08 Thread Stephan Beck
Teemu Likonen: > Peter Lebbing [2016-12-08 18:12:50+01] wrote: > >> I forked the Debian git repo for GnuPG 2.1 [1], and had a go at what >> was primarily the reversal of the changes introduced by 2.1.11-7+exp1. >> You can find the result at GitLab at [2]. > > Thanks. I'm not brave enough to try

Re: Something strange with Stephan Becks Signatures?

2016-12-09 Thread Stephan Beck
it > freezes mostly exactly during loading a signed mail from Stephan > Beck. Well, I can't say that I feel honored by so many references to my name, but have you checked that (I suspect compatibility of PGP plugin and your PM version as a probable reason) 1) the PGP-plugin you use i

Re: Something strange with Stephan Becks Signatures?

2016-12-11 Thread Stephan Beck
Stephan Beck: > Hi Matthias, > > Matthias Mansfeld: >> Hello, maybe someone has similar effects or can give me a hint where >> to look. If not, it's OK... >> >> Windows 7 pro(64), GPGRelay 9.962 (a POP3/SMTP "proxy" or better >> loc

Re: Strange behaviour

2016-12-11 Thread Stephan Beck
Matthias Mansfeld: > On 9 Dec 2016 at 14:01, Stephan Beck wrote: > >> Hi Matthias, > [..] >>> Windows 7 pro(64), GPGRelay 9.962 (a POP3/SMTP "proxy" or better >>> local relay for GnuPG), GnuPG 1.4.18, Pegasus Mail 4.72de >>> >>> Base

Re: Strange behaviour

2016-12-12 Thread Stephan Beck
Matthias Mansfeld: > On 11 Dec 2016 at 20:43, Stephan Beck wrote: > >> I'm truly interested in receiving such log files to have a look >> into it myself, but the list may be interested as well. If there was >> really something "special" about (precisel

Re: Recording keysigning attendants on phone

2016-12-12 Thread Stephan Beck
Lachlan Gunn: > Le 2016-12-08 à 22:30, Stephan Beck a écrit : >> Yes, to your first question. How you would do that via the >> hash-on-the-projector method, is not clear to me, though. Would that be >> for generating the (initial) list of the organizers as in Sassama

Re: Implications of a common private keys directory in 2.1

2016-12-12 Thread Stephan Beck
Carola Grunwald: > Peter Lebbing wrote: > >> On 11/12/16 20:58, Carola Grunwald wrote: >>> With 'problems' i referred to the GenKey bug/feature I reported a few >>> hours ago and the IPC instabilities I experienced. Sure, the >>> single-sec-keys-depository : multiple-pub-keyrings configuration i

Re: Strange behaviour

2016-12-12 Thread Stephan Beck
Peter Lebbing: > On 12/12/16 12:38, Stephan Beck wrote: >> You MIGHT consider having it expired as well, setting a decent expiry >> date (maybe, expiry within 2 or 3 years). > > No, I don't think that is good advice if given without a specific reason > to do so.

Re: An attempt at backporting 2.1.16 from Debian sid to Debian jessie

2016-12-16 Thread Stephan Beck
Peter Lebbing: > On 08/12/16 21:42, Stephan Beck wrote: >> [...], so I don't see the real need for a forced coexistence of the two >> (or three) versions on Jessie. > > I did that because all the software in jessie that depends on GnuPG 1.4 > might not work with G

Re: Implications of a common private keys directory in 2.1

2016-12-16 Thread Stephan Beck
Hi Caro, Carola Grunwald: > Stephan Beck wrote: >> Carola Grunwald: >>> Peter Lebbing wrote: > > > Removing all cached passphrases sounds great. But does that mean I have > to invoke the agent directly using the Assuan protocol? And what would > be the way to

Re: PM from David Adamson -please ask on-list

2016-12-17 Thread Stephan Beck
Doug Barton: > On 11/25/2016 02:28 AM, Stephan Beck wrote: >> Hi David, >> >> I kindly invite you to post your PM on-list. It might be of interest for >> other people as well. > > Why send this to the list, rather than to him privately? Why not? I supposed that

Re: Implications of a common private keys directory in 2.1

2016-12-19 Thread Stephan Beck
Hi, Carola Grunwald: > Stephan Beck wrote: >> Carola Grunwald: >>> Stephan Beck wrote: >>>> Carola Grunwald: >>>>> Peter Lebbing wrote: >>> [...] > > Removing all cached passphrases sounds great. But does that mean I have > to invo

Re: [Announce] GnuPG 2.1.17 released

2016-12-20 Thread Stephan Beck
Hi, Christoph Moench-Tegeder: > Hi, > > I believe there's something wrong with the signature of the latest > release. > > ## Werner Koch (w...@gnupg.org): > >> * If you already have a version of GnuPG installed, you can simply >>verify the supplied signature. For example to verify the sig

Re: Counterarguments Supporting GnuPG over Off The Record (OTR)

2017-01-19 Thread Stephan Beck
15-20 years from now, OpenPGP will have expired and be a case of study for computer historians. Christian Heinrich: > https://www.foo.be/2016/12/OpenPGP-really-works outlines a number of > counter-arguments in support of GnuPG over OTR chat app and other > alternatives. > ___

Re: Counterarguments Supporting GnuPG over Off The Record (OTR)

2017-01-24 Thread Stephan Beck
MFPA: > > > On Friday 20 January 2017 at 6:10:37 AM, in > , Miroslav Rovis wrote:- > > > >> And we all are controled, exception, to varying >> extent, > > We are all completely controlled in modern society: we are enslaved to > money and those who control it. And sometimes even organizatio

Re: moving up from 2.0.26 to 2.1.1

2015-02-12 Thread Stephan Beck
together with its dependencies ? > > And returning to my original questions, since it is written that 2.0* and 2.1 > cannot co-exist, I suppose that I shall have to remove manually everything > connected with my 2.0.26 ? If you click on "remove completely" in the m

Re: MIME or inline signature ?

2015-02-13 Thread Stephan Beck
rom xx You might have signed your message with a key different from the one I can download from the keyserver. As a security measure I have assigned your key a non-trust attribute. Best regards Stephan Beck signature.asc Description: OpenPGP digital signat

Re: MIME or inline signature ?

2015-02-14 Thread Stephan Beck
Hi Am 14.02.2015 um 15:44 schrieb MFPA: > Hi > > > On Friday 13 February 2015 at 11:28:43 AM, in > , Stephan Beck wrote: > > > >> BAD Signature from xx > > I get that as well. > > > >> As a >> security measure I have assigned your

Re: MIME or inline signature ?

2015-02-15 Thread Stephan Beck
Hi MFPA Am 15.02.2015 um 13:14 schrieb MFPA: > > > On Saturday 14 February 2015 at 10:05:24 PM, in > , Stephan Beck wrote: > > >> Well, it's rather a precautionary measure than an >> actual security measure, , reminding me of not trusting >> the

Re: MIME or inline signature ?

2015-02-15 Thread Stephan Beck
Am 15.02.2015 um 12:26 schrieb Ludwig Hügelschäfer: > On 14.02.15 23:05, Stephan Beck wrote: > >> Well, it's rather a precautionary measure than an actual security >> measure, , reminding me of not trusting the key owner's ability to >> handle and verify sign

Re: MIME or inline signature ?

2015-02-15 Thread Stephan Beck
Hi, Hauke, Am 15.02.2015 um 17:04 schrieb Hauke Laging: > Am So 15.02.2015, 16:12:01 schrieb Stephan Beck: > >> X-GPG-Key-ID: 0xBA4909B78F04DE1B >> X-GPG-Key: >> http://wwwkeys.pgp.net/pks/lookup?search=0xBA4909B78F04DE1B&op=index >> X-GPG-Fingerprint: 9983 D

Re: MIME or inline signature ?

2015-02-15 Thread Stephan Beck
Am 15.02.2015 um 17:25 schrieb Ludwig Hügelschäfer: > On 15.02.15 16:30, Stephan Beck wrote: > > The only place to get trust to the senders key (i.e. to make it > "valid" for you) is to meet the key owner in real life, verify the > identity documents, his fingerprint an

  1   2   >