Re: card is permanently locked!

2014-11-18 Thread tux . tsndcb
Hello, I can confirm, works fine. Best Regards - Mail original - De: "Pete Stephenson" À: "Damien Goutte-Gattat" Cc: "GnuPG Users Mailing List" Envoyé: Lundi 17 Novembre 2014 20:15:09 Objet: Re: card is permanently locked! == /hex scd serialno scd apdu 00 20 00 81 08 40 40 40 40

Cyberjack go plus new internal storage size

2014-07-10 Thread tux . tsndcb
Hello all, Just for information, it seems than ReinerSCT have change internal storage size from 2 Go to 4 Go. Best Regards ___ Gnupg-users mailing list Gnupg-users@gnupg.org http://lists.gnupg.org/mailman/listinfo/gnupg-users

Re: Smart card reader security

2014-07-07 Thread tux . tsndcb
Hello Christian >I bought a cyberJack go [1] to use it with my openPGP smart card for >authentification. Since the firmware of that device is upgradeable and >is capable of saving atleast 2 GB of data, how can I be sure it is not a >security threat by saving sensitive data? May be done an encrypt

Re: riseup.net OpenPGP Best Practices article

2014-06-27 Thread tux . tsndcb
> My understanding is that the YubiKey Neo applet supports up to 2048 bit RSA. > Thus there are some keys that will work with the V2 SmartCard but not on the > Neo. Yes limitation is physical, the ship cannot have key size more than 2048 bit RSA on Yubikey, for the V2 SmartCard GnuPG, it's d

Re: mascot_p

2014-06-17 Thread tux . tsndcb
Hi, >I think a mascot would be nice. Is there some especially secretive animal? Some >animal that hides stuff? Or just a nice animal, something cuddly like a >pufferfish. Erm. > >Peter. Yes or may be an animal with two Gnus like the old smartcard GnuPG V1 logo with the new GnuPG logo (padlock) o

Cannot reset smartcard

2014-06-12 Thread tux . tsndcb
Hello all, Sorry to disturb you but I cannot more used my smartcard and I wanted to known if someone has already have this : gpg2 --card-status gpg: selecting openpgp failed: Reset card required gpg: OpenPGP smartcard not available : Reset card required I've tried to reset it : gpg-connect-age

Re: fulldisc encryption

2014-05-30 Thread tux . tsndcb
> LUKS soltution works also for android (but not for full disk), available here > : I don't know any full disc encryption metghod for Android. However, LUKS doesn't work for windows. Yes of course because LUKS => L for linux (so not for Windows) but works also for android as virtual folders

Re: fulldisc encryption

2014-05-30 Thread tux . tsndcb
Hello Johan, - Mail original - De: "Johan Wevers" À: gnupg-users@gnupg.org Envoyé: Vendredi 30 Mai 2014 22:51:28 Objet: Re: fulldisc encryption On 30-05-2014 12:48, sys...@ioioioio.eu wrote: > as truecrypt gave up developing the software any further, the question > raised up, how to enc

Re: Reiner SCT Cyberjack go : Display languge question

2014-05-29 Thread tux . tsndcb
Hello Ingo > IMHO, the real shame is that this device (as probably most other similar > devices) doesn't have an open-sourced Free Firmware. (Or does it?) Yes I'm totaly agree with you, but unfortunally for us it's not tomorrow .. Best Regards ___

Re: Reiner SCT Cyberjack go : Display languge question

2014-05-29 Thread tux . tsndcb
(same as other cardreader), it will be a nice very small pinpad cardreader, but it's the life ... Best Regards - Mail original - De: "tux tsndcb" À: gnupg-users@gnupg.org Envoyé: Lundi 26 Mai 2014 14:26:00 Objet: Reiner SCT Cyberjack go : Display languge question Hello all

Reiner SCT Cyberjack go : Display languge question

2014-05-26 Thread tux . tsndcb
Hello all, I wanted to know, if people who use this cardreader have english language on display. Because on display I've done this configuration : Menu -> Setting -> Language -> German >English I've selected it but all display messages are in German for exemple wh

Re: what hardware entropy usb key equivalent Simtec entropy key take ?

2014-05-26 Thread tux . tsndcb
Hello Diega, Yes it will be probably only for entropy because I use my smartcards GnuPG with PINPAD smartcard card reader and actualy I don't want to use it without PINPAD. I haven't see than you can use it only for Random, I will look more and price is not so expensive. Thanks for the informa

what hardware entropy usb key equivalent Simtec entropy key take ?

2014-05-25 Thread tux . tsndcb
Hello alls, As you know it is not more possible to buy a Simtec entropy usb key since many years, so my question what hardware entropy usb key do you recommend now to replace it (not too expensive) ? PS: need to be compatible with GNU Linux / Debian Thanks in advanced for your return. Best R

Re: does gpg & gpg2 use same gpg.conf file in home directory & what are the best practices to create gpg2 signature ?

2014-05-23 Thread tux . tsndcb
Hello War, Don't worry, part 5 to 8 and are commun for without or with smartcard GunPG key. Part 9 is only for smartcard but don't forgot part 10. Creating a revocation certificate Good reading. Best Regards ___ Gnupg-users mailing list Gnupg-user

Re: does gpg & gpg2 use same gpg.conf file in home directory & what are the best practices to create gpg2 signature ?

2014-05-23 Thread tux . tsndcb
Hello war, Yes gpg and gpg2 use the same gpg.conf file, the .gnupg directory will be created on your fist usage gpg or gpg2. On debian, the first time you use it a generic gpg.conf file is also generated. Do you use a smartcard ? or do you want to use one ? You can first look at this link :

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-21 Thread tux . tsndcb
Hello Peter, Don't worry I can understand. I will look your new way, and yes pinpad usage is may be the problem, I will look for that also (but as I have see on rescue mode after boot PINPAD askpass PIN works fine to pinpad, may be and surely the problem is during boot phase). Many thanks agai

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-21 Thread tux . tsndcb
Hello Peter, Could you tel me what reader you use ? Thanks in advanced. Best Ragards - Mail original - De: "tux tsndcb" À: "Peter Lebbing" Cc: gnupg-users@gnupg.org Envoyé: Mardi 20 Mai 2014 17:28:20 Objet: Re: gnupg smartcard on boot for LUKS on sid debian

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-20 Thread tux . tsndcb
:0 same good result. If I try : gpg --card-edit admin verify PIN code is well asked on my smartcard reader and works well. So is it possible to add a "debug mod" on your script to have more informations during boot phase ? Thanks in advance for your help Best Regards - Mail o

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-20 Thread tux . tsndcb
Hello Peter, If I done : gpg --card-status --debug-ccid-driver => I have no error, so normaly it is good, isn't it ? and if I done : echo scd getinfo reader_list | gpg-connect-agent --decode | awk '/^D/ {print $2}' answer 0982:0008:00F5:0 it is well my smartcard reader with my smartcard

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-19 Thread tux . tsndcb
Hello Peter - Mail original - De: "Peter Lebbing" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Lundi 19 Mai 2014 20:01:38 Objet: Re: gnupg smartcard on boot for LUKS on sid debian howto ? > But I've always : > > gpg: pcsc_etablish_context failed:

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-19 Thread tux . tsndcb
Hello Peter, First good news, as I tell you during initramfs generation, I see no trace for /etc/key/cryptkey.gpg, but this file is obligatory OK because passphrase works on boot (with gpg.conf in /etc/keys) (may be it it's because my test is for /data/test encrypted FS and not /) But I've alw

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-18 Thread tux . tsndcb
Hi Peter, Thanks for your answer - Mail original - De: "Peter Lebbing" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Dimanche 18 Mai 2014 22:04:18 Objet: Re: gnupg smartcard on boot for LUKS on sid debian howto ? On 18/05/14 18:51, tux.tsn...@free.fr wrote:

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-18 Thread tux . tsndcb
Hi Peter, My first return on jessie, on boot ask me PIN to decrypt but failed, but it is normal, here messages : Performing GPG key decryption Enter Smartcard PIN or passphrase for key /etc/keys/cryptkey.gpg gpg pcsc_establish_context failed : no service (0x8010001d) gpgh card reader not availab

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-18 Thread tux . tsndcb
Hi Peter, - Mail original - De: "Peter Lebbing" À: "tux tsndcb" , gnupg-users@gnupg.org Envoyé: Dimanche 18 Mai 2014 12:52:52 Objet: Re: gnupg smartcard on boot for LUKS on sid debian howto ? On 16/05/14 16:06, tux.tsn...@free.fr wrote: > I answer my self, afte

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-16 Thread tux . tsndcb
Hi all, I answer my self, after, many many tests done, in fact it isn't actually possible to do it under sid debian => root cause bug on systemd : Debian Bug report logs - #618862 systemd: ignores keyscript in crypttab link here : https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=618862 Best R

REINERSCT cyberJack® go plus works fine with pinpad ? Thanks to confirm it.

2014-05-12 Thread tux . tsndcb
Hi, Thanks for your answers (Werner and Julian), so maybe the good choise should be the other : cyberJack® go plus, CCID compliance as I've can read, isn't it ? SCM SPR 532, KAAN Advanced and Cherry ST2000 are too big for a nomade usage and the last : Vasco DigiPASS 920, seems no longer be sold

cyberJack® RFID komfort works fine with pinpad ?

2014-05-11 Thread tux . tsndcb
Hi all, Before buy it, I wanted to know if someone use a cyberJack® RFID komfort or cyberJack® go plus smartcard reader and can confirm to me than pinpad works fine with gnupg-ccid driver. Thanks in advanced for your return Best Regards ___ Gnupg-us

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-05-09 Thread tux . tsndcb
Hi Thomas, I believe this blog article could be a useful reference: https://blog.kumina.nl/2010/07/two-factor-luks-using-ubuntu/ I've tested it on my sid debian with my pinpad reader, but the mean matter, it's on boot my debian failed to acces to my smartcard. Does somebody have sucessfully u

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-04-20 Thread tux . tsndcb
Hello Peter, I've read the README.gnupg file in cryptsetup, and it is indicate 3 steps to do : 1) First, you'll have to create the encrypted keyfile by: # dd if=/dev/random bs=1 count=256 | gpg --no-options --no-random-seed-file \ --no-default-keyring --keyring /dev/null --secret-keyrin

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-04-18 Thread tux . tsndcb
Hello all, Someone has an idea to do that please and how to do that ? All help is appreciated. Thanks in advanced. Best Regards. - Mail original - De: "tux tsndcb" À: "Thomas Harning Jr." Cc: gnupg-users@gnupg.org Envoyé: Mercredi 16 Avril 2014 22:19:28 Objet: Re

Re: gnupg smartcard on boot for LUKS on sid debian howto ?

2014-04-16 Thread tux . tsndcb
crypt UUID=xx none luks,discard But in the debian case, it's seems than I neeed to use /lib/cryptsetup/scripts/decrypt_gnupg, but I've not really exemple on that. Best Regards - Mail original - De: "Thomas Harning Jr." À: "tux tsndcb" Cc: "

gnupg smartcard on boot for LUKS on sid debian howto ?

2014-04-16 Thread tux . tsndcb
Hello Peter, Actually, I'm on a fresh sid Debian installed, I've use during install crypted LVM volume for all my partitions excepted for /boot. So now I've two files like these : /etc/fstab # /etc/fstab: static file system information. # # Use 'blkid' to print the universally unique identifier

G83-6744 keyboard + smart-card reader

2012-01-16 Thread tux . tsndcb
Hello, I can tell you for G83-6744 but gnupg2 work fine with G83-14601, card reader is same. Best Regards - Mail original - De: gn...@lists.grepular.com À: gnupg-users@gnupg.org Envoyé: Lundi 16 Janvier 2012 19:56:26 Objet: G83-6744 keyboard + smart-card reader I'm thinking of buying o

Re: Using pinentry-curses interactively in Linux boot process fails (SOLVED)

2010-07-28 Thread tux . tsndcb
- Mail Original - De: "Malte Gell" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Vendredi 23 Juillet 2010 21h03:53 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: Re: Using pinentry-curses interactively in Linux boot process fails (SOLVE

Re: Using pinentry-curses interactively in Linux boot process fails (SOLVED)

2010-07-23 Thread tux . tsndcb
> Yes and the boot partition is not encrypted, only /home But I solved it. It > was an init script issue. On openSUSE there is an init script "earlyxdm" and > it has overridden so to say the pinentry-ncurses program. I have now edited > earlyxdm and have added my own script to Requried-Start, th

tools to test reader's keypad with GnuPG smartcard V2 ?

2009-10-19 Thread tux . tsndcb
Hello Werner, Could you tell me if you've a debug tools to test reader's keypad with a GnuPG smartcard V2 ? Or could you explain please how you've done your tests and valided the reader's keypad with a GnuPG smartcard V2 ? Thanks in advanced for your answer. Best Regards __

Re: Smartcard GnuPG V2 and CHECKPIn with keypad (pin code conversion) ?

2009-10-19 Thread tux . tsndcb
Hi All, I answer to myself, in fact it's PIN uses an ASCII format conversion with padding Best Regards - Mail Original - De: "tux tsndcb" À: gnupg-users@gnupg.org Envoyé: Lundi 19 Octobre 2009 14h33:27 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne O

Smartcard GnuPG V2 and CHECKPIn with keypad (pin code conversion) ?

2009-10-19 Thread tux . tsndcb
Hi All, I'm testing my reader's pinpad with my GnuPG smartcard V2 for VERIFY PIN function by scardcontrol tools, but I don't know how the PIN code is read by the smartcard : - PIN uses a binary format conversion - PIN uses a shift rotation format conversion

APDU for CKECKPIN and MODIFY PIN for Smartcard GnuPG V2 ?

2009-10-16 Thread tux . tsndcb
Hi, I've done some tests to validate my reader's pinpad with my smartcard GnuPG V2 I've put this to CHECKPIN : /* PC/SC v2.02.05 Part 10 PIN verification data structure */ pin_verify -> bTimerOut = 0x00; pin_verify -> bTimerOut2 = 0x00; pin_verify -> bmFormatStrin

Re: How to enable the reader's keypad

2009-10-14 Thread tux . tsndcb
Hi Werner, Do I need to change also something in this two files : agent/divert-scd.c scd/app-dinsig.c Is there a commande line to test reader's keypad acces ? thanks in advanced for your return. Best Regard - Mail Original - De: "tux tsndcb" À: "Werner Ko

How to enable the reader's keypad

2009-10-13 Thread tux . tsndcb
Hi Werner, the Vendor tell to me than I need also this for the reader, but I dont know where to put it : bNumberMessage = 0x01 bEntryValidationCondition = 0x02 bNumberMessages = 0x03 Thanks in advanced for your return Best Regards - Mail Original - De: "tux tsndcb" À: &q

How to enable the reader's keypad

2009-10-13 Thread tux . tsndcb
ttl 1800 scdaemon.conf : verbose and gpg-agent is invoked by STARTUP="$GPGAGENT --daemon --sh --write-env-file=$PID_FILE $STARTUP" in the file /etc/X11/Xsessions.d/90gpg-agent Thank in advanced for your confirmation. Best Regards - Mail Original - De: "Werner Koch"

How to enable the reader's keypad

2009-10-08 Thread tux . tsndcb
Hi, I'm using gnupg2 2.0.13 (with libccid on my debian) and a smardcard reader with keypad, but code PIN is always ask on my desktop, not on the reader. On my scdaemon.conf I've not disable-keypad So how to do this ? Thanks in advanced for your answer. Best regards ___

Is it possible to have the same authentication key on several smartcard ?

2009-10-04 Thread tux . tsndcb
Hi Werner, I answer to my self, in fact I need to use the expert mode to do that, sorry ... Best Regards - Mail Original - De: "tux tsndcb" À: "Werner Koch" Cc: gnupg-users@gnupg.org Envoyé: Dimanche 4 Octobre 2009 17h51:18 GMT +01:00 Amsterdam / Berlin / Berne

Is it possible to have the same authentication key on several smartcard ?

2009-10-04 Thread tux . tsndcb
r. Best Regards - Mail Original ----- De: "tux tsndcb" À: "Werner Koch" Cc: gnupg-users@gnupg.org Envoyé: Jeudi 24 Septembre 2009 23h01:46 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: Is it possible to have the same authentication key on severa

Re: poldi logon screen

2009-10-02 Thread tux . tsndcb
Hi, I answer to my self, in fact it's an gdm setup. Best Regards. - Mail Original - De: "tux tsndcb" À: gnupg-users@gnupg.org Envoyé: Lundi 28 Septembre 2009 22h36:18 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: poldi logon screen Hi all, T

poldi logon screen

2009-09-28 Thread tux . tsndcb
Hi all, This is the last functionnaly than I've to setup. I'm on debian squeeze with limpam-poldi 0.4.1-2, I can logon with my smartcard, so poldi is ok, but I've the normal debian logon screen, not the poldi screen like this : http://www.g10code.com/graphics/poldi-screenshot-gdm.png So my qu

Why a full keys and sub keys backup are not proposed when keys and sub keys are done "on-card" ?

2009-09-28 Thread tux . tsndcb
Hi Werner, Thanks for these informations. Best Regards - Mail Original - De: "Werner Koch" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Lundi 28 Septembre 2009 09h34:28 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: Re: Why a fu

Why a full keys and sub keys backup are not proposed when keys and sub keys are done "on-card" ?

2009-09-27 Thread tux . tsndcb
I think it will be a big problematic. It's for that than I suggested to add the authentication key, but it's just a suggestion. Best Regards - Mail Original - De: "Werner Koch" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Dimanche 27 Septembre 200

Why a full keys and sub keys backup are not proposed when keys and sub keys are done "on-card" ?

2009-09-27 Thread tux . tsndcb
Hi, Just for information, I wanted to known why you don't propose a full backup of the three keys (Sign, encryption and authentication) when keys are generated "on-card". Because only encryption key is backupted, a good idea will be perhaps to add also authentication key in the backup. Thanks

Re: How to reset a smartcard ?

2009-09-25 Thread tux . tsndcb
Hi Werner, Your help is a pleasure, thanks you very much, it works fine. Best Regars. - Mail Original - De: "Werner Koch" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Vendredi 25 Septembre 2009 11h48:36 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockhol

How to reset a smartcard ?

2009-09-25 Thread tux . tsndcb
Hi all, No body has an idea to "reset" a smartcard as factory settings ? I think it is possible, but I don't know how to do that. Thanks in advanced for your help. Best Regard - Mail Original - De: "tux tsndcb" À: gnupg-users@gnupg.org Envoyé: Dimanche 20 Se

Is it possible to have the same authentication key on several smartcard ?

2009-09-24 Thread tux . tsndcb
Hi werner, I think I've the solution, could you confirm it please : gpg2 --edit-key commande > addkey RSA (sign only) Thanks in advanced for your answer Best Regards - Mail Original ----- De: "tux tsndcb" À: "Werner Koch" Cc: gnupg-users@gnupg.org Envoyé: J

Is it possible to have the same authentication key on several smartcard ?

2009-09-24 Thread tux . tsndcb
ns and your answer. Best Regards - Mail Original ----- De: "tux tsndcb" À: "Werner Koch" Cc: gnupg-users@gnupg.org Envoyé: Mercredi 23 Septembre 2009 14h45:37 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: Is it possible to have the same authenti

How to used a smartcard who has already be used to backup my fisrt smartcard ?

2009-09-23 Thread tux . tsndcb
Hi, Sorry, I need help again. I want to used an other smardcard to backup my first smartcard, but this other smartcard has already be used to generate keys so it isn't blank. I've successfully imported the secretkey (encription key) of my first smartcard on it by used bkuptocard command, this i

Is it possible to have the same authentication key on several smartcard ?

2009-09-23 Thread tux . tsndcb
Hi Werner, Many thanks for your answer, I will try it. Best Regard - Mail Original - De: "Werner Koch" À: "tux tsndcb" Cc: gnupg-users@gnupg.org Envoyé: Mercredi 23 Septembre 2009 13h36:49 GMT +01:00 Amsterdam / Berlin / Berne / Rome / Stockholm / Vienne Objet: R

Is it possible to have the same authentication key on several smartcard ?

2009-09-23 Thread tux . tsndcb
Hi, Is it possible to have the same authentication key on several smartcard ? Is it possible to done an authentication key backup when it has been generated directly on a smartcard ? Thanks in advanced for your answer. Best Regard. ___ Gnupg-users m

One Private Key on Two or more OpenPGP 2.0 cards?

2009-09-20 Thread tux . tsndcb
Hi, I'm also very interresting if there is a way to put the same authentication key on several smartcards. Thanks in advanced. Best Regards - Mail Original - De: "Sean Wilson" À: "David Shaw" Cc: gnupg-users@gnupg.org Envoyé: Lundi 14 Septembre 2009 12h00:35 GMT +01:00 Amsterdam / Be

How to reset a smartcard ?

2009-09-19 Thread tux . tsndcb
Hi, I wanted to hown how to "reset" a smartcard as factory settings or how to blanck all informations on the smartcard (Signature key, Encrpytion key, Authentication key ... to none) as on the first use. Thanks in advanced for your help. Best Regards __

Re: how to validate keys on smartcard (only) on an other PC or on a news OS installation

2009-08-23 Thread tux . tsndcb
Hi, Thanks for your answer. Best Regard - Mail Original - De: "Michel Messerschmidt" À: gnupg-users@gnupg.org Envoyé: Samedi 22 Août 2009 21h04:50 GMT +02:00 Harare / Pretoria Objet: Re: how to validate keys on smartcard (only) on an other PC or on a news OS installation On Fri, Aug 21

how to validate keys on smartcard (only) on an other PC or on a news OS installation

2009-08-21 Thread tux . tsndcb
Hi, I don't know how to validate keys on smartcard V2 on PC2 when the keys has been generated on PC1 or if the hard disk crash on PC1 how to validate again it after new OS installation. I ask for this, because when I put for example my smartcard on PC2 with key generate on PC1, when I done gpg

how to validate keys on smartcard (only) on an other PC or on a news OS installation

2009-08-21 Thread tux . tsndcb
Hi, I don't know how to validate keys on smartcard V2 on PC2 when the keys has been generated on PC1 or if the hard disk crash on PC1 how to validate again it after new OS installation. I ask for this, because when I put for example my smartcard on PC2 with key generate on PC1, when I done gpg