Re: GPG4Win: running gpg-agent with SSH agent support?

2010-02-02 Thread Werner Koch
On Mon,  1 Feb 2010 21:31, d...@prime.gushi.org said:
> On Mon, 1 Feb 2010, Werner Koch wrote:
>
>> Yes, we do this on Windows because we have a well known socket name
>> there.  It may actually happen that two agents are started which does
>> not harm because the the unused agent detects this case and terminates
>> itself after some time.
>
> What's the socket location inder win32, if you don't mind me asking?

On my system this is

 C:\Dokumente und Einstellungen\werner\Anwendungsdaten\gnupg\S.gpg-agent

You can get all these values using:

  c:\Programme\GNU\GnuPG>gpgconf --list-dirs
  sysconfdir:C%3a\Dokumente und Einstellunge[...]aten\GNU\etc\gnupg
  bindir:c%3a\Programme\GNU\GnuPG
  libexecdir:c%3a\Programme\GNU\GnuPG
  libdir:c%3a\Programme\GNU\GnuPG\lib\gnupg
  datadir:c%3a\Programme\GNU\GnuPG\share\gnupg
  localedir:c%3a\Programme\GNU\GnuPG\share\locale
  dirmngr-socket:C%3a\WINDOWS\S.dirmngr
  agent-socket:C%3a\Dokumente und Eins[...]gsdaten\gnupg\S.gpg-agent
  homedir:C%3a\Dokumente und Einstellungen\werner\Anwendungsdaten\gnupg
  
This is a colon delimited and percent escaped output, thus the %3a for
the colons in the filenames.


Shalom-Salam,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.


___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: GPG4Win: running gpg-agent with SSH agent support?

2010-02-02 Thread Simon Josefsson
Werner Koch  writes:

> On Fri, 29 Jan 2010 14:03, si...@josefsson.org said:
>
>> I've installed GPG4Win and it recognizes my OpenPGP smartcards without
>> problem (via a gpg-agent process which appears to be auto-started
>> somehow?).  However, I'd like to enable SSH agent support in gpg-agent
>
> Yes, we do this on Windows because we have a well known socket name
> there.  It may actually happen that two agents are started which does
> not harm because the the unused agent detects this case and terminates
> itself after some time.
>
>> too, so that Cygwin ssh can make use of it.  Is this possible, if so
>> how?
>
> It can't work out of the box because ssh needs to implement our local
> socket emulation (see libassuan/src/assuan-socket.c).  It would be very
> useful if we could get support for this into putty.

Why can't gpg-agent implement the same protocol that ssh-agent does
under Windows?

The ssh-agent under Cygwin appears to work in the same way it does on
GNU/Linux, i.e., the ssh process looks for the environment variables
that ssh-agent prints when started.

/Simon

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


Re: Gnupg doesn't recognize card.

2010-02-02 Thread Simon Josefsson
Werner Koch  writes:

> On Fri, 29 Jan 2010 01:22, jcr...@gmail.com said:
>
>> $ killall -u  scdaemon #usually has to be entered 2-3x to
>> kill it
>
> FWIW, 
>
>   gpgconf --reload scdaemon
>
> does the same in a well defined manner.

The --reload parameter doesn't appear to be documented.  Is it really
supported for use in long-term portable scripts?

/Simon

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users


OpenPGP SmartCard v2.0 w/OmniKey 6121

2010-02-02 Thread Chris Ruff
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

Hi,

I've been researching the archives for the past week after receiving
my OpenPGP v2.0 smartcard from Kernelconcepts.  Problem seems to
revolve around the reader, but between by two systems OpenSUSE 11.2
(gnupg 2.0.13) and Mac OS X 10.5.8 (MacGPG/gnupg 2.0.14) I have
slightly different results.

First I was only able to create the 3 2048-bit keys on the linux
laptop but would fail to create a 3072/2048/2048 set on the same
system.  On the Mac I couldn't create anything (tried all 1024 and
2048 keys).

I could successfully change all my card options (did this before key
generation).  With the card now having 2048 keys, on the linux system I
could encrypt/decrypt but can not perform any signing/verify
operation.  On the Mac I can encrypt, but neither decrypt/sign/verify.
 Errors vary from "general signing error" to secret key not found
(when trying to decrypt. I was unclear how to actually setup my new
keys on the Mac so I performed an export using export/export-secret-keys
over to the Mac from the linux system.

Please let me know what types of debugs I can provide back for review
or any other test information one would like performed or provided.  I
would really like to get this reader working, but if not I'll take
recommendations for USB ID-000 readers (since I already punched mine out).

Output of '--card-status' below.  Thanks in advance.

$ gpg --card-status
Application ID ...: D2760001240102050374
Version ..: 2.0
Manufacturer .: ZeitControl
Serial number : 0374
Name of cardholder: John Ruff
Language prefs ...: en
Sex ..: male
URL of public key : [not set]
Login data ...: techniq
Signature PIN : forced
Key attributes ...: 2048R 2048R 2048R
Max. PIN lengths .: 32 32 32
PIN retry counter : 3 0 3
Signature counter : 18
Signature key : 6530 8DA8 805C 707F 3611  9851 D057 FC41 052A 4FAD
  created : 2010-01-24 02:10:16
Encryption key: 0A2B BBEE 4B0D C392 A4E6  3673 ECCF B9FB 1488 8977
  created : 2010-01-24 02:10:16
Authentication key: 735C 977A DFBA 72B2 CDF0  D5D9 F9E8 742E FC34 E962
  created : 2010-01-24 02:10:16
General key info..: pub  2048R/052A4FAD 2010-01-24 John C. Ruff
(Techniq) 
sec>  2048R/052A4FAD  created: 2010-01-24  expires: never
  card-no: 0005 0374
ssb>  2048R/FC34E962  created: 2010-01-24  expires: never
  card-no: 0005 0374
ssb>  2048R/14888977  created: 2010-01-24  expires: never
  card-no: 0005 0374

- -- 
__
Chris Ruff
email: jcr...@gmail.com
gpg key: 0x307A351B4EC4B6A1
gpg fgpr: BF2F 2497 22E7 FEB5 C805
  075C 307A 351B 4EC4 B6A1
-BEGIN PGP SIGNATURE-
Version: GnuPG/MacGPG2 v2.0.14 (Darwin)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBCgAGBQJLaMuIAAoJEDB6NRtOxLah8HAQAKVBmBPEu9/W13uMMQe29v11
b6EDMk08S+FJYtj56FmNY7jd43MWlpQ2vsrnKkJlfoOXuGyCcuRiuONRI5/uXnZM
YtSaeL31c+YINoHDptHwegkaLfUD72X/2JQRjl5Z5FgkgoYOUjSSWVAO7J/Zt4I+
KQ+uuHqm3ivjpZFmjwpIlrepfMDmQpN8PTDdWoovsecV1g0BfOh0ZZ3mlbzSr84+
FX1+1Z2GeOGi3I0ibTUl+HFym9ZOj3YATuU+r6o+cMGjsrwfO22Q+k/5GdmrnAI8
60rsp+UrlYhS/WYZatYS+dIYy1yLZLfoSplHBLbgfbI5fzaOspIAElEUL5SjfWW1
EtOQtEqmDPq08CFIiisEENCKZDtX/I6FliXt7/uuWiuvFdHrNSnI9+GGEaxw9SfF
7f9tYk/dAzRGN8GHoQegnb+CoIJxhGeOs5uqcCEfXVT8SeJNf6Zi5PFpsKDJVvDV
eKi8pV36wYnI0JJbYWWI53GwvNPc0DeQUHG4Ey71EK5VUpJVpC41NX25cDlKclIy
1eunQBH+TvIaniG7qLA2b9lvArIRSIs9YXDYk8TbEJSYt3T2wNm2TKhOJTNj4oJB
fdF9fAO9p5amb0FUj2Z2CIMdxR1b/meXXq2YR7/w5w+rrlI4lp6CYBoT+gZ/h6E2
l6yvh4VpbGuJ/eLfZgqF
=kWzY
-END PGP SIGNATURE-

___
Gnupg-users mailing list
Gnupg-users@gnupg.org
http://lists.gnupg.org/mailman/listinfo/gnupg-users