Separate OpenPGP cards for master key and sub-keys

Mustrum Mustrum at Mustrum.net
Wed Jun 5 19:37:09 CEST 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Le 05/06/2013 14:50, Peter Lebbing a écrit :
> On 05/06/13 12:55, Mustrum wrote:
>> The keytocard command displays the 3 slots, but none of them are
>> listed as a valid choice. I've to choose from an empty list.
> 
> Ah. I hadn't noticed that. I believe the problem is that the "Key
> attributes" (displayed on --card-edit) force a specific keylength
> and keytocard only works for that keylength. I think I remember the
> solution was to create a key on card of the desired length, and
> then overwrite that one with keytocard.
> 
> Peter.
> 

I moved a 4096/rsa signature key to the card, with succes, and tried
to overwrite it with my real primary key

gpg> keytocard
Really move the primary key? (y/N) y
Signature key ....: A41C 227F C1EB BA5C 3CFE  776D C011 169C 983F E396
Encryption key....: [none]
Authentication key: [none]

Please select where to store the key:
Your selection? 1
Invalid selection.
Your selection? 2
Invalid selection.
Your selection? 3
Invalid selection.
Your selection? 0
Invalid selection.
Your selection? 4
Invalid selection.
Your selection? 42
Invalid selection.
Your selection?

Same issue, no valid selection avalaible.

I'm quite sur the root cause is the "certification only" capacity of
my key:

usage: C  <-primary

usage: S  <-subkey
usage: E  <-subkey

All keys with the S or E flags are fine.
All my real and test keys with only the C flag can't be move to my card.

Regards.


-----BEGIN PGP SIGNATURE-----

iQIcBAEBCgAGBQJRr3dFAAoJEEy6/YZf1YOezg8QAItXI48uKdbEeSKxw6eALJ/p
RSxmib3rH5DlL+BN9WkufPKw3RJkNsRwEDlnojzHaQ4i3QWICw2zgv2lGUBaw1Bw
UoPx1A74hjGZjgzySBjEhoQvjK3pywhRWQebguJ0iMcnZDQHkY92iKPybdR7z3r5
0QASl+WAFsrvkclLS3xawpLf9ZnhixR+w92nobKauTo8lufIrVO4l9QDQvM6BMmi
x//Tx+k7URMJJjb5IyDxkbnsjcSdYFjtWtl0mMCbcm/zbbSEYFHWX/F6EX2yw992
cph8lhvey4/JXiGpSxjxq9/3ReifoYYVlZT15t/AFxj2Jk/Axc8L2eUfmdW9z6YW
b72EYUj531Nio5Dcij4eRQLAP5MTTuksbMSx4FAHALzJbIJDuw1ZW/rtYY3mW3/G
4O1y1uo3SGN8UBzmmxkoad3HUmLiuVYspmt6gnDH2VHUCk9/5MygtbCeiueYgiTE
G8hYpUOsa3A+PMDkbq0b60j3iaKpxtX+DYgtAQYfWbGKzbCl+Z8qAqNtlanPm9qK
HRQ6hucRNV2MY0zbc1SLHRh3sFUs2xKl9PQyEFGJZkLqfZJA4qxHK5dXrX3n2mmP
lY/ZKpQuQP91NmUrBMP9FfFvg9Do6mwz5ZyBoG0GorZIMPyPcz/oVl1prVktrC9k
H1imYGmH44cdHjXLacJy
=z8dK
-----END PGP SIGNATURE-----



More information about the Gnupg-users mailing list