The GNU Privacy Handbook (1999)
gnupg.org
The GNU Privacy Handbook (1999)
1–10 of 17 posts
Re: The GNU Privacy Handbook (1999)
#2Re: The GNU Privacy Handbook (1999)
#3Re: The GNU Privacy Handbook (1999)
#4Re: The GNU Privacy Handbook (1999)
#5Interesting as a historic artefact, but please don't follow this guide, search for something more recent.
Re: The GNU Privacy Handbook (1999)
#6https://emailselfdefense.fsf.org/
Tactical Tech's Security in-a-Box has more detailed, step-by-step, multiple platform guides for the same tools:
https://securityinabox.org/en/guide/thunderbird/windows
Re: The GNU Privacy Handbook (1999)
#7The DSA key recommendation is terrible, either go 4096 RSA or Ed25519/Curve25519.
Secondly, use whatever keyring manager your distro has available and that supports your keys and is nice to use. GPA is okay-ish and offers most options.
Re: The GNU Privacy Handbook (1999)
#8But there were some important differences. Newer GnuPG versions have simplified how gpg-agent takes the place of ssh-agent. Nowadays, it's enough to create an SSH_AUTH_SOCK environment variable that points to ~/.gnupg/S.gpg-agent.ssh
Also, I found the air-gapped system setup described there and elsewhere to be excessively difficult. Far and away the easiest way to create an air-gapped key generating machine was to install OpenBSD to a USB key (you can boot the mini install image and overwrite the same device). Installing the gpg2 package gives you a complete gnupg environment for interacting with OpenPGP smart cards. By contrast, there were a bunch of packages to install with Ubuntu / Debian.
It was a little hairy to set up in total, but I really love my Yubikey-mediated GPG setup. I also now use password-store for passwords, complete with dmenu integration.
I'm not super happy that the Yubikey 4 isn't 100% open hardware though. If someone has a recommendation for something that is, and supports 4096 bit keys, I'd gladly hear it.
Re: The GNU Privacy Handbook (1999)
#9I've been meaning to write up the adventure I had setting up my Yubikey 4 together with GnuPG. Most of my work was cribbed off of this guide: https://www.jfry.me/articles/2015/gpg-smartcard/ But there were some important differences. Newer GnuPG versions have simplified how gpg-agent takes the place of ssh-agent. Nowadays, it's enough to create an SSH_AUTH_SOCK environment variable that points to ~/.gnupg/S.gpg-agent…
Re: The GNU Privacy Handbook (1999)
#10I've been meaning to write up the adventure I had setting up my Yubikey 4 together with GnuPG. Most of my work was cribbed off of this guide: https://www.jfry.me/articles/2015/gpg-smartcard/ But there were some important differences. Newer GnuPG versions have simplified how gpg-agent takes the place of ssh-agent. Nowadays, it's enough to create an SSH_AUTH_SOCK environment variable that points to ~/.gnupg/S.gpg-agent…
There is NitroKey[0], which seemed to me like a good alternative to Yubikey, but I haven't ordered either yet so I can't say I have first-hand experience. But much luck if you decide to go with it, something I'm looking more and more into, especially since I too use password-store and it would be good having an easier to use setup that is still secure. [0] https://www.nitrokey.com/