Re: Questions regarding WKD/WKS

2022-12-02 Thread Andreas Heinlein via Gnupg-users
Am 02.12.22 um 14:59 schrieb Werner Koch: > On Thu, 1 Dec 2022 14:45, Andreas Heinlein said: > >> 1. If I follow the guidelines for creating the directory >> /var/lib/gnupg/wkd, it has ownership webkey:webkey and permissions >> 2750. So there ist no chance for the apache

Questions regarding WKD/WKS

2022-12-01 Thread Andreas Heinlein via Gnupg-users
Hello, I am trying to implement WKD/WKS and followed the tutorial here: https://wiki.gnupg.org/WKS I have a few questions: 1. If I follow the guidelines for creating the directory /var/lib/gnupg/wkd, it has ownership webkey:webkey and permissions 2750. So there ist no chance for the apache

Re: Automating and integrating GPG

2017-09-21 Thread Andreas Heinlein
Am 20.09.2017 um 09:02 schrieb Werner Koch: > On Mon, 18 Sep 2017 23:45, d...@fifthhorseman.net said: > >> I don't know how much smartcard interaction gpgme supports, though. > Everything you need. Have a look at GPA's smartcard features. I assume > it is the most advanced GUI to handle the

System-wide gnupg.conf?

2017-08-09 Thread Andreas Heinlein
Hello, after reading today's announcement of GNuPG 2.1.23, I had the idea of having a system-wide /etc/gnupg.conf, to disable the new auto-key-retrieve etc. User's gnupg.conf should still be used and override the same options in the system-wide conf. Has something like this ever been discussed?

Re: How to use a the same generated keypair on enigmail/thunderbird and iOS Mail

2017-07-26 Thread Andreas Heinlein
Am 26.07.2017 um 14:05 schrieb dekkz...@gmail.com: > On 07/26, Andreas Heinlein wrote: >> Am 26.07.2017 um 11:27 schrieb MFPA: >>> Do "most normal users" make use of an OpenPGP smartcard? Those that do >>> might be able to use the same keypair on their mobile

Re: How to use a the same generated keypair on enigmail/thunderbird and iOS Mail

2017-07-26 Thread Andreas Heinlein
Am 26.07.2017 um 11:27 schrieb MFPA: > Do "most normal users" make use of an OpenPGP smartcard? Those that do > might be able to use the same keypair on their mobile phone by means > of an NFC-enabled smartcard. Surely not. I guess most "normal users" don't even know that such a thing exists.

Re: How to use a the same generated keypair on enigmail/thunderbird and iOS Mail

2017-07-25 Thread Andreas Heinlein
Am 25.07.2017 um 20:34 schrieb Robert J. Hansen: >> I would think you could transfer the private key file to the moblle >> device by bluetooth, or by using a USB cable, or by email. So long as >> the private key is protected by a decent passphrase, anybody else >> getting a copy of the file should

Re: A Quick Supplement

2017-07-18 Thread Andreas Heinlein
Am 18.07.2017 um 15:36 schrieb Robert J. Hansen: > >> While it would be nice if it were easier to be able to back up easily >> as you're suggesting, shouldn't the focus of GnuPG be on security? > This *is* a security issue. > > Some versions of GnuPG use a file called "random_seed", for instance.

Re: Questions using GPGME

2017-07-13 Thread Andreas Heinlein
Am 13.07.2017 um 09:27 schrieb Werner Koch: > On Thu, 6 Jul 2017 14:48, aheinl...@gmx.com said: > >> decrypt with cancel'ing the pinentry, one with missing private key and >> one with a truncated input file. All three gave >> >> print str(e): Invocation of gpgme_op_decrypt_verify: GPGME:

Re: Option to select "Which topic categories would you like to subscribe to?" under Gnupg-users Subscription Options

2017-07-06 Thread Andreas Heinlein
Am 06.07.2017 um 14:50 schrieb S via Gnupg-users: > Hello, > > Apologies for having to ask this. Didn't find any options in the > relevant page. > > I would like to receive messages only for topics I'm subscribed to. > But, I don't see an option to select topics of my choice either in >

Re: Questions using GPGME

2017-07-06 Thread Andreas Heinlein
Am 06.07.2017 um 14:01 schrieb Justus Winter: >> 2.) Is there a way to safely distinguish "User clicked cancel when asked >> for the passphrase" from other errors? I think an application should >> abort silently in this case, but I'm getting another GPGMEError without >> any clue to the reason. >

Questions using GPGME

2017-07-06 Thread Andreas Heinlein
Hello, I am currently taking first steps using GPGME with the Python interface. I am facing two questions: 1.) I'm looking for a way to get the recipients of encrypted data which I can not/do not want to decrypt. I.e. a message for which I do not have the private key. Enigmail tells me "This

Re: Working with a system-shared keyring

2011-06-02 Thread Andreas Heinlein
Am 02.06.2011 00:41, schrieb Dan McGee: So my questions are: 1. Does anyone else have experience with a shared among users keyring? 2. What is best/secure practice when it comes to this? Outside of --lock-never, yum does something that seems silly, but works- make a user-owned copy of the

Re: I can't stop encryption being done with a wrong key

2011-05-27 Thread Andreas Heinlein
Am 26.05.2011 21:26, schrieb Charly Avital: In Thunderbird, key usage is set in 'Per Recipient rules', that is not the Address Book. Can someone please explain to me how this could be happening, and what I need to do to correct it? Should I remove his old key from my keyring? If I

Re: Problem with the pgp to gpg key migration

2011-05-10 Thread Andreas Heinlein
Am 09.05.2011 14:43, schrieb Pramod.R: Hi, I tried migrating the public and the private key from the pgp(6.5.8) keyring to the gpg(1.4.11) by following the below commands: 1) Tried exporting the private and the public key from pgp using the commands: pgp -kx pubkey.pgp

Re: Best practice for periodic key change?

2011-05-06 Thread Andreas Heinlein
Am 05.05.2011 22:10, schrieb Doug Barton: On 05/04/2011 23:52, Andreas Heinlein wrote: We have a OpenPGP key which we use for signing our software releases. That key should be changed yearly and carry an expiration date to enforce this change. What are you trying to accomplish by doing

Best practice for periodic key change?

2011-05-05 Thread Andreas Heinlein
Hello, I hope you can give me some advice on the following problem: We have a OpenPGP key which we use for signing our software releases. That key should be changed yearly and carry an expiration date to enforce this change. However, for the signatures to be useful, the key has to be signed by

Re: cloudy understanding of asymmetric cryptography

2009-03-26 Thread Andreas Heinlein
Felipe Alvarez schrieb: On Thu, Mar 26, 2009 at 8:17 PM, Sven Radde em...@sven-radde.de wrote: Hi! Felipe Alvarez schrieb: Someone today shook my understanding of asymmetric ciphers. _Bob performs symmetric encryption on message with_ _key K (generated randomly). He then encrypts

Re: Elementary Question

2008-11-25 Thread Andreas Heinlein
Jorge Luis schrieb: I've googled and checked the docs for an answer to this, but have come up empty-handed. Is it possible to verify public keys without actually adding them to my keyring? For example, I don't want to add keys from mailing lists under most circumstances, but I would like to

Re: appending to gpg file?

2008-11-18 Thread Andreas Heinlein
David Shaw schrieb: On Mon, Nov 17, 2008 at 02:41:50PM -0500, David Kennedy wrote: Thanks for the help! I'm using an app to pipe events (text strings) through an instance of gpg to a file. This works great for me now, in an ideal environment. Two issues: 1)The problem occurs if/when