OpenGPG Smart Card v2.1 - unable to create key - card error

Conrad Kostecki ck+gnupgusers at bl4ckb0x.de
Sat Jun 18 15:51:16 CEST 2016


Hi!
I've bought an OpenGPG Smart Card v2.1 and trying now to generate a 4096 
bit key for me.
Using it with my ThinkPad X260 and a Alcor Smart Card Reader.

$ gpg --version
gpg (GnuPG) 2.1.13
libgcrypt 1.7.1

Supported algorithms:
Pubkey: RSA, ELG, DSA, ECDH, ECDSA, EDDSA
Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH,
        CAMELLIA128, CAMELLIA192, CAMELLIA256
Hash: SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224
Compression: Uncompressed, ZIP, ZLIB, BZIP2

Before creating a key, the card is found:
$ gpg --card-edit

Reader ...........: 058F:9540:X:0
Application ID ...: DXXXXXXXXXXXXXXXXXXXXXXXXXXX
Version ..........: 2.1
Manufacturer .....: ZeitControl
Serial number ....: 0000XXXX
Name of cardholder: [not set]
Language prefs ...: de
Sex ..............: [not set]
URL of public key : [not set]
Login data .......: [not set]
Signature PIN ....: not forced
Key attributes ...: rsa4096 rsa4096 rsa4096
Max. PIN lengths .: 32 32 32
PIN retry counter : 3 0 3
Signature counter : 0
Signature key ....: [none]
Encryption key....: [none]
Authentication key: [none]
General key info..: [none]

Now, when I do start the creation of the key, it fails with a card error 
at the end:

gpg/card> generate
Make off-card backup of encryption key? (Y/n) Y
What keysize do you want for the Signature key? (4096)
What keysize do you want for the Encryption key? (4096)
What keysize do you want for the Authentication key? (4096)
Please specify how long the key should be valid.
         0 = key does not expire
      <n>  = key expires in n days
      <n>w = key expires in n weeks
      <n>m = key expires in n months
      <n>y = key expires in n years
Key is valid for? (0)
Key does not expire at all
Is this correct? (y/N) Y

GnuPG needs to construct a user ID to identify your key.

Real name: John Doe
Email address: john at doe.com
Comment: JD
You selected this USER-ID:
    "John Doe (JD) <john at doe.com>"

Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? O
gpg: key generation failed: Card error
Key generation failed: Card error

What does card error means? The card is now not anymore accassible.
I am only able to access the card again, when I do restart the laptop 
completly.

Cheers
Conrad




More information about the Gnupg-users mailing list