Re: A few newbie questions, I'am doing this right?

2012-12-13 Thread Roy Sindre Norangshol
On 12/13/12 at 02:43pm, Roy Sindre Norangshol wrote: > On 12/13/12 at 02:21am, Hauke Laging wrote: > > *snip* > > This is very useful for a key policy document (--set-policy-url). > > Could you please show me an example of how you set such a key policy document? > I tried «gpg2 --edit-key 0xMyPubl

Re: A few newbie questions, I'am doing this right?

2012-12-13 Thread Roy Sindre Norangshol
On 12/13/12 at 02:21am, Hauke Laging wrote: > *snip* > This is very useful for a key policy document (--set-policy-url). Could you please show me an example of how you set such a key policy document? I tried «gpg2 --edit-key 0xMyPublicKey --set-policy-url static-www-link-to-my-gpg-policy-webpage-w

Re: A few newbie questions, I'am doing this right?

2012-12-13 Thread Hauke Laging
Am Do 13.12.2012, 11:03:07 schrieb Roy Sindre Norangshol: > > I would add signing ability at any rate and (depending on the > > circumstances > > perhaps) even encryption. This allows you to make very secure signatures. > > This is very useful for a key policy document (--set-policy-url). > > I wa

Re: A few newbie questions, I'am doing this right?

2012-12-13 Thread Roy Sindre Norangshol
On 12/13/12 at 02:21am, Hauke Laging wrote: > Am Mi 12.12.2012, 19:28:18 schrieb Roy Sindre Norangshol: > > > I'm trying to setup my gpg setup properly for the first time, and wondering > > if this setup seems fine: > > "Best practice" is often subjective. Indeed, fighting between security vs us

Re: Same key on different smart cards

2012-12-13 Thread Hauke Laging
Am Do 13.12.2012, 08:43:53 schrieb Richi Lists: > But as far as I understand, for eMail signing and decryption, it needs > to be the same key on all cards. I have not checked that but I don't think so. Wouldn't make sense. When using key A, why should gpg-agent care, where key B is stored? > I

Re: Same key on different smart cards

2012-12-13 Thread Werner Koch
On Thu, 13 Dec 2012 08:43, ricu...@gmail.com said: > (~/.gnupg/secring.gpg). Thus if I try to use the second card, I get an > error telling me to insert the correct card. You need to delete the secret key stub and then gpg should be able to re-create it using the current card. I am not sure abou

Same key on different smart cards

2012-12-13 Thread Richi Lists
Hi, I want to have a second and third smart card as fallback. For full disk encryption and ssh it would be ok to have different keys. But as far as I understand, for eMail signing and decryption, it needs to be the same key on all cards. I set up two crypto sticks to contain the same sub keys. But