Smartcard problem (no secret keys) when moving to new machine

mikeb at mikebanahan.com mikeb at mikebanahan.com
Wed Nov 26 18:40:59 CET 2008


Summary: secret keys not marked on secret keyring when 'fetch' is used to retrieve card public keys.

I'm using Ubuntu which as standard ships with gpg 1.4.6

When I move to a 'virgin' system, i.e one with gpg but no keyrings, I insert
card, use --card-edit to access the card and then use the 'fetch' command to retrieve
the public key from a server.

All goes well.

If I then attempt to sign using the key on the card, I get a 'no secret key available' message.

If I subsequently issue 'gpg --card-status' this resolves the problem.

It appears that after the fetch of the public keys, the private keyring is not updated.

I have subequently checked this by deleting all keyrings, then using --card-edit/fetch.
After that gpg -K lists no secret keys.
A subsequent --card-status followed by -K DOES show secret keys.

This may be nit-picking but it just cost me a couple of hours to track down.

If it's documented can someone tell me where?

Thanks,

Mike
-- 
Mike Banahan - http://www.gbdirect.co.uk - Tel 0870 200 7273, Mobile 07970 942590
gpg secure email key fingerprint: 8197 386A 206D E0B7 7307 6091 5C29 F51D B3CA 298A



More information about the Gnupg-users mailing list