Migrating from OpenPGP card + gnupg 1.4 to 2.1

Alphazo alphazo at gmail.com
Wed Dec 21 15:35:38 CET 2011


I'm testing the latest beta 3 and tried the suggested command to my
secring.gpg to 2.1 keyring.
Before I explain what I get, here is how my key is setup:
- Primary key is a RSA4096 one that I only use to sign my own subkeys
and other people's key. The private key material of this key has been
removed from this specific machine as I only sign keys offline using a
full copy of the key that I keep away from computers.
- Subkey 1 is for encryption (RSA) using an OpenPGP card (cryptostick)
therefore only a stub is present in the keychain and no private key
material
- Subkey 2 is for signature (RSA) using an OpenPGP card (cryptostick)
therefore only a stub is present in the keychain and no private key
material

When importing this key I got the pinentry-gtk popup asking for the
passphrase for this key but this won't be of any help considering that
no private key material is there.

What do you recommend to migrate this particular key?

I could probably setup a temporary machine to use the full keychain
with passphrase then migrate to 2.1 and finally remove the private key
material of the primary key (is that possible with 2.1?).

Thanks
Alphazo



More information about the Gnupg-devel mailing list