Re: SSH CA and OpenPGP card

2015-03-29 Thread NIIBE Yutaka
On 03/27/2015 09:36 PM, Bolesław Tokarski wrote: > ssh-keygen *can* sign a public key with a smartcard. Using a PKCS#11 token. > However, I see that the OpenPGP card does not natively talk PKCS#11, but > there's some wrapper library. Am I really forced to use that? Would it work > correctly or woul

Re: One alternative to SMTP for email: Confidant Mail

2015-03-29 Thread Mike Ingle
> Any word on whether confidant mail will support the openpgp smart cards (or > yubikey, similar)? -Nick With GPG 2.1, the gpg-agent handles all the passphrase prompting. I don't see why it would not work with a smartcard. Which one do you think I should get to test with? I have not played w

Re: SSH CA and OpenPGP card

2015-03-29 Thread Stephan Beck
Am 27.03.2015 um 13:36 schrieb Bolesław Tokarski: > Hello, [...] > Is the PKCS#11 library for OpenPGP card usable? I guess you may install and use gnupg-pkcs11-scd for that purpose, provided that you only use RSA keys. See /usr/share/man/man1/gnupg-pkcs11-scd.1 for more info. Hope that helps

Re: gpg 2.0.27 is updating the trustdb constantly, and taking minutes to do it

2015-03-29 Thread Jesus Cea
On 28/03/15 11:48, Werner Koch wrote: > On Fri, 27 Mar 2015 17:07, j...@jcea.es said: > >> My problem is that any change to the pubring, like downloading a new >> key, refreshing, adding a new local signature with "--lsign", etc., will >> force a trustdb update (in the next execution. For instance

Instructions for converting keyring for 2.1

2015-03-29 Thread Peter Lebbing
I just followed the instructions on [1] for converting your pubring.gpg to the new keybox format. I discovered I needed --import-options import-local-sigs on the import command to also import my local signatures, which obviously is very desirable when converting your public keyring... it's a bit lo

Re: One alternative to SMTP for email: Confidant Mail

2015-03-29 Thread Nick Econopouly
Any word on whether confidant mail will support the openpgp smart cards (or yubikey, similar)? -Nick On Mar 29, 2015 7:55 AM, "MFPA" <2014-667rhzu3dc-lists-gro...@riseup.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > > > On Saturday 28 March 2015 at 6:05:05 PM, in > , Peter Le

Re: gpg 2.0.27 is updating the trustdb constantly, and taking minutes to do it

2015-03-29 Thread Werner Koch
On Sat, 28 Mar 2015 19:58, dougb@dougbarton.email said: > Just out of curiosity, do you have an ETA on a new release? Nothing really important has changed since mid February except for a fix in gpgtar - does anyone really use it on non-Windows? (it has been fixed in gpg4win). Salam-Shalom,

Re: One alternative to SMTP for email: Confidant Mail

2015-03-29 Thread MFPA
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On Saturday 28 March 2015 at 6:05:05 PM, in , Peter Lebbing wrote: > No, but nobody said the adjective was used > tautological. Maybe it doesn't imply or hint that to everybody, but it is definitely what I infer when I read "from strictly busine