Re: How to export private ed25519 subkey to the SSH format

2017-05-02 Thread Samir Nassar
uPG has made it very easy to do: $ gpg -K ~/.gnupg/pubring.kbx sec ed25519 2017-04-16 [SC] [expires: 2019-04-16] DEADBEEFDEAFBIN5ABADB0B1337 uid [ultimate] Samir Nassar ssb cv25519 2017-04-16 [E] [expires: 2020-04-16] ssb ed25519 2017

Disambiguating GnuPG Modern, Stable, and Classic

2016-07-27 Thread Samir Nassar
Hello, The GnuPG project describes the three branches of GnuPG as Modern (2.1.x), Stable (2.0.x), and Classic (1.4.x). Should it be understood that GnuPG Modern is similar to a development branch? --  Samir Nassar web:samirnassar.com email:  sa...@samirnassar.com PGP:pgp.samirnassar.com

Re: Installing gnupg

2016-06-09 Thread Samir Nassar
se let share in more detail what you are trying to accomplish. -- Samir Nassar web:samirnassar.com email: sa...@samirnassar.com PGP:pgp.samirnassar.com signature.asc Description: OpenPGP digital signature ___ Gnupg-users mailing list Gnupg-use

Re: Curve 25519 encryption subkey - problem encrypting

2016-06-04 Thread Samir Nassar
tent permitted by law. Home: ~/.gnupg Supported algorithms: Pubkey: RSA, ELG, DSA, ECDH, ECDSA, EDDSA Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH, CAMELLIA128, CAMELLIA192, CAMELLIA256 Hash: SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224 Compression: Uncompressed,

Feedback requested: GnuPG lookup and retrieval of PGP certificates via DNS

2016-05-18 Thread Samir Nassar
ing DNSSEC. [2] Cool URIs don't change: https://www.w3.org/Provider/Style/URI.html [3] Publishing Keys in DNS: https://incenp.org/notes/2015/keys-in-dns.html [4] Knot DNS features: https://www.knot-dns.cz/docs/2.x/singlehtml/index.html#knot-dns-features -- Samir Nassar web:samirnassar.com

Re: What's the contextual definition of the term?... signature

2016-01-28 Thread Samir Nassar
On Wednesday 27 January 2016 21:08:43 Don Saklad wrote: > What's the contextual definition of the term?... signature > as this term is used for GNUpg A signature, also known as a "John Hancock": https://commons.wikimedia.org/wiki/File:JohnHancocksSignature.svg --

Re: Key selection order

2016-01-18 Thread Samir Nassar
On Monday, January 18, 2016 09:17:31 AM Robert J. Hansen wrote: > This is because in the absence of trust, signatures are meaningless. > Who on this list has verified my certificate to any real degree? Samir > Nassar, Patrick Brunschwig, maybe one or two others. Who on this list >

Re: GPGrelay does not recognize Gpg-2.1 keys; Gpg4win-3beta...

2015-12-21 Thread Samir Nassar
and not part of the keys themselves. YOu can import and export OpenPGP keys freely between Gnupg 1.4 and 2.x and 2.1. The only thing you cannot do is freely re-use the keystore. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com ___ Gnupg-u

Re: GPGrelay does not recognize Gpg-2.1 keys; Gpg4win-3beta...

2015-12-20 Thread Samir Nassar
sions of GnuPG. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: FAQ: drop mention of 1.4?

2015-09-04 Thread Samir Nassar
On Friday, September 04, 2015 09:54:58 AM Johan Wevers wrote: > On 04-09-2015 0:46, Robert J. Hansen wrote: > > Here's the question I really want people to answer: "At what point do we > > tell people, 'no, that data format has been obsolete for twenty years, > > we're not going to support it any

Re: Is Open PGP or GnuPG or GPG possible on a Mac?

2015-05-01 Thread Samir Nassar
On Thursday 30 April 2015 23:47:42 Mercury Rising wrote: I will take the answer on the list and at mercuryrisin...@gmail.com. I Up graded to Mavericks on the Mac. I am looking for a whole package of open source PGP-like programs that will let me encrypt to other keys and manage other keys and

Re: PGP/MIME (Was: One alternative to SMTP for email: Confidant Mail)

2015-03-25 Thread Samir Nassar
On Wednesday, March 25, 2015 12:41:56 PM Doug Barton wrote: On 3/25/15 11:08 AM, Bob (Robert) Cavanaugh wrote: Doug, Signature shows as an attachment signature.asc. No evidence that PGP actions were envoked. Work forces use of Synaptic PGP, so I cannot tell if it is verified or not. Most

Re: PGP/MIME (Was: One alternative to SMTP for email: Confidant Mail)

2015-03-25 Thread Samir Nassar
On Thursday, March 26, 2015 12:56:03 AM Ville Määttä wrote: It seems to me that emails sent and signed by Thunderbird + Enigmail are displayed just fine by it. No signature.asc quirks. But emails sent by others are displaying the attachment in addition to the normal Enigmail added UI signature

SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
Hello, I originally posted this on the sks-devel mailing list, but after thinking about it, I believe this might be something I am doing wrong on the GnuPG side.: I set up a keyserver at keyserver.myriapolis.net. What I have done so far: Installed sks (1.1.5) from wheezy-backports SKS is

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 06:18:53 PM Daniel Kahn Gillmor wrote: It looks to me like you're using the server's certificate as the CA certificate. I don't think that's going to work. Maybe you want to use the Addtrust root cert (attached here) Ahem. You are so very right. Somehow it

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 07:28:31 PM Kristian Fiskerstrand wrote: Likely related to the PTR issues[0, 1], its already in the roadmap[2] Thank you Kristian, So I understand this better. When using non-encrypted connections GnuPG doesn't have a problem, but when I am using a wildcard

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 10:40:57 PM Kristian Fiskerstrand wrote: try renaming /home/snassar/.gnupg/myriapolis.net.crt to /home/snassar/.gnupg/myriapolis.net.pem Done. if that doesn't help , can you increase debug verbosity in dirmngr.conf and set the logfile? $ cat dirmngr.conf

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 08:54:47 PM Kristian Fiskerstrand wrote: Hmm, I didn't notice that it was a wildcard cert, that should also support holdfast.myriapolis.net in the cert matching, however it results a redirect and404 for [0]. If you add this as a vhost I suspect it will work

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 09:21:08 PM Kristian Fiskerstrand wrote: 11371 is expected to be for HKP, so requiring this to be TLS is bad practice. Oh oops. Fixed now. gpg-connect-agent --verbose --dirmngr 'keyserver hkps://keyserver.myriapolis.net:11371' 'ks_get 1e42b367' /bye

Re: SKS Keyserver, HKPS, and GnuPG 2.1

2015-03-18 Thread Samir Nassar
On Wednesday, March 18, 2015 10:14:53 PM Kristian Fiskerstrand wrote: gpg-connect-agent --dirmngr 'KEYSERVER --help' /bye S # Known schemata: S # hkp S # hkps S # http S # finger S # kdns Same. When I set the keyserver to: hkp://keyserver.myriapolis.net everything works. When

Re: Defaults

2015-03-17 Thread Samir Nassar
On Tuesday, March 17, 2015 06:53:48 PM Daniel Kahn Gillmor wrote: Brainpool-512 is incompatible with some of the other work going on in the OpenPGP ecosystem (e.g. yahoo and google's work on the e2e webmail app, which supports P-256 and P-512). Well, the Yahoo! folks are not 100% committed to

Re: Circumvention Tech Summit in Valencia

2015-03-03 Thread Samir Nassar
On Tuesday, March 03, 2015 01:34:01 PM Kristian Fiskerstrand wrote: On 03/03/2015 12:51 PM, Robert J. Hansen wrote: Daniel Kahn Gillmor and I are both here. (And in fact, we met briefly, and much to the surprise of many people here but not to either dkg or myself, there was mutual respect,

Re: Please remove MacGPG from gnupg.org due to serious security concerns

2015-02-18 Thread Samir Nassar
On Wednesday, February 18, 2015 12:05:18 PM Jonathan Schleifer wrote: I suppose it might be a good idea to have a Qt GUI. That looks native enough on Mac so that most users won't complain, works good on X11 or Wayland based systems and also works well on Windows. Ideally, this would be a

Re: File Encryption

2014-12-22 Thread Samir Nassar
https://securityinabox.org/keepass_main Surveillance Self-Defence Guide: https://ssd.eff.org/en/module/creating-strong-passwords https://ssd.eff.org/en/module/how-use-keepassx -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90

Re: FYI: Arch linux provides GnuPG (2.1.0) package without ability to use HKPS

2014-12-13 Thread Samir Nassar
On Wednesday, 2014-12-10 21:08:05 Samir Nassar wrote: The Arch linux GnuPG package 2.1.0-6 is unable to connect to HKPS. As of the latest update to GnuPG 2.1.0-7, thanks to Gaetan Bisson, gpg should work with HKPS -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint

Re: Release scheduling

2014-12-10 Thread Samir Nassar
(such as the hkps SKS pool) and that this is only fixed in the betas for 2.1.1. If this understanding is correct and 2.1.1 fixes the hkps issues, I'd vote to release 2.1.1 -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2

Re: Release scheduling

2014-12-10 Thread Samir Nassar
with either the hkps pool or individual hkps keyservers. Arch Linux, GnuPG 2.1.0. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description: This is a digitally signed message part

Re: Release scheduling

2014-12-10 Thread Samir Nassar
maintainer is being conservative with adding requirements to Arch core repository, but I believe this is a mistake. Thank you all. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description

FYI: Arch linux provides GnuPG (2.1.0) package without ability to use HKPS

2014-12-10 Thread Samir Nassar
package breaks essential and previously working functionality and was told I could build my own package. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description: This is a digitally signed

For Your Information: Circumvention Tech Festival - March 1 - 6

2014-11-28 Thread Samir Nassar
/festival/circumvention-tech-festival.html -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description: This is a digitally signed message part. ___ Gnupg

Re: Pros and cons of PGP/MIME for outgoing e-mail?

2014-11-23 Thread Samir Nassar
an obligation to be backwards compatible. If you, and others, think the PGP/MIME RFC is incomplete or invalid, then that's a conversation I want to hear. Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2

Re: How do I show the public keys?

2014-11-15 Thread Samir Nassar
sec 4096R/0xFE679A908E997AB2 2013-02-24 [expires: 2015-02-14] Key fingerprint = EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 uidSamir Nassar samir.nas...@gmail.com uidSamir Nassar sa...@samirnassar.com uid

Re: How do I show the public keys?

2014-11-15 Thread Samir Nassar
/manual.html#AEN65 By Key ID: $gpg --export --armor 0xFE679A908E997AB2 By ID: $gpg --export --armor sa...@samirnassar.com By fingerprint: $gpg --export --armor EE76B39E07788F95F796B044FE679A908E997AB2 Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E

Re: Nearly fixed

2014-11-15 Thread Samir Nassar
the mailing list archive: Disregard this misconception. Many of us, myself included, use gpg2 on a 64bit system without a problem. Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description

Re: Why the software is crap

2014-11-14 Thread Samir Nassar
and will not move you to a resolution. You've registered your complaint, it has been discussed, and now your behavior is counter-productive. Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc

Re: Help needed to setup Passphrase with GNUPG 2.0.26

2014-11-01 Thread Samir Nassar
with the Famous Phrase “Excellence is not an Adjective but a Verb”, so that I can remember it.. -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 signature.asc Description: This is a digitally signed message part

Re: Help needed to setup Passphrase with GNUPG 2.0.26

2014-11-01 Thread Samir Nassar
from the user, and it's not clear that you have the right environment set up for pinentry. whatever package manager you have, can you install pinentry-curses and try again? --dkg PS Excellence is not an Adjective but a Verb -- it's actually a noun :) -- Samir Nassar sa

Re: Fwd: GNU hackers discover HACIENDA government surveillance and give us a way to fight back

2014-08-29 Thread Samir Nassar
It is safe to say this thread has moved way off topic from being about using gnupg. Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint: EE76 B39E 0778 8F95 F796 B044 FE67 9A90 8E99 7AB2 Public Key: https://samirnassar.com/files/key.asc signature.asc

Re: Fwd: [Enigmail] [ANN] Enigmail v1.7 available

2014-08-09 Thread Samir Nassar
twice before understanding what you are saying. If you believe you found a defect you should file a proper bug report. Given that the Enigmail page on addons.mozilla.org says Works with Thunderbird 24.0 - 34.0, it looks like your version of Thunderbird is not supported. Samir -- Samir Nassar

Re: [Announce] [security fix] Libgcrypt and GnuPG

2014-08-08 Thread Samir Nassar
several updates of GnuPG since then. I am somewhat concerned. Is there any information about when an update for Windows users might be released? The GPG4Win folks are gearing up for a new release this August. Samir -- Samir Nassar sa...@samirnassar.com https://samirnassar.com PGP Fingerprint