Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: GnuPG: users

OpenPGP card usage

 

 

GnuPG users RSS feed   Index | Next | Previous | View Threaded


psilvaferreira at gmail

Nov 2, 2009, 3:13 AM

Post #1 of 2 (456 views)
Permalink
OpenPGP card usage

Hello,

I admit this is a bit odd, but I'm having some elementary problems
using my OpenPGP card.

I got an OpenPGP v2 card and a Gemalto usb reader. Followed the howto
on http://www.gnupg.org/howtos/card-howto/en/smartcard-howto-single.html
to initialize the card using the generate command. Everything seems
fine on my personal computer.

Now when I take the card to another computer, with an empty keyring,
shouldn't I be able to make use of my private key stored on the card?
If I run gpg --list-keys I get an empty output, gpg --card-status
correctly shows my card info and if I try to sign an email with
thunderbird/enigmail I get an error saying "Clearsign faild: No secret
key"

What am I doing wrong?

Using gpg4win 2.0.1 (GnuPG 2.0.12) on Windows 7.

Thanks

Pedro

_______________________________________________
Gnupg-users mailing list
Gnupg-users [at] gnupg
http://lists.gnupg.org/mailman/listinfo/gnupg-users


listac at nebelschwaden

Nov 2, 2009, 12:24 PM

Post #2 of 2 (416 views)
Permalink
Re: OpenPGP card usage [In reply to]

> I admit this is a bit odd,

No, it's a pretty natural question. I had the same idea

> Now when I take the card to another computer, with an empty keyring,
> shouldn't I be able to make use of my private key stored on the card?

Wishful thinking. Unfortunately it does not work that way. At least from what
I have experienced so far.
You need the corresponding public key imported before usage on that new
machine/account and run a gpg2 --card-status afterwards to make the key on
the card known to gnupg. AFAIK there is no option like --keyring=smartcard

So next to the card you also need an usb stick to transport the public key,
when using the smartcard on a different account/machine.

Not sure wether this is also true for S/MIME. But that would probably need a
different kind of smartcard and there is no up to date documentation that I
am aware of what recent PKI/X509 cards are properly supported by linux. And
maybe you are bound to gnupg anyway.

> What am I doing wrong?

You are too optimistic about the usage of a smartcart with gnupg ;) However, I
am pretty new to this topic, too, so maybe some more experienced user will
correct me.

_______________________________________________
Gnupg-users mailing list
Gnupg-users [at] gnupg
http://lists.gnupg.org/mailman/listinfo/gnupg-users

GnuPG users RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.