On Mon, 26 Sep 2022 00:30, Ángel said:

> You would need to recompile gpg with that change / convince the OpenBSD

Please don't do that.  Actually you would have to recompile Libgcrypt.
But don't do that (recompile with changes to the random code).

> My recommendation: create the /dev nodes inside the chroot

Yes.  You may also want to run gpg-agent via the agent-extra-socket (see
gpgconf -L) thing for extra security; its not an out of the box feature,
though.  gpg-agent takes care of the private keys and having it isolated
from the web server is a Good Thing.


Salam-Shalom,

   Werner

-- 
The pioneers of a warless world are the youth that
refuse military service.             - A. Einstein

Attachment: signature.asc
Description: PGP signature

_______________________________________________
Gnupg-users mailing list
Gnupg-users@gnupg.org
https://lists.gnupg.org/mailman/listinfo/gnupg-users

Reply via email to