Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

gpg-agent unlock key at login

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
7 posts • Page 1 of 1
Author
Message
potuz
Guru
Guru
Posts: 378
Joined: Sat Jan 30, 2010 2:00 am

gpg-agent unlock key at login

  • Quote

Post by potuz » Tue Dec 16, 2014 1:13 am

Hello, I use gpg-agent as a keychain manager. I would like to unlock the keychain when I type my password at the login console. How would I go about it?

Incidentally, in my current set up I launch gpg-agent from ~/.xinitrc and pinentry-gtk prompts for my password twice. Once when it needs a key to decrypt and another time when it needs the key to sign. Is there a way to unlock all keys at once?
Top
khayyam
Watchman
Watchman
User avatar
Posts: 6227
Joined: Thu Jun 07, 2012 2:45 am
Location: Room 101

  • Quote

Post by khayyam » Tue Dec 16, 2014 1:48 am

potuz ...

by "login console" I assume you mean the console (so, not DM). You could call gpg-agent from your shell login, but its probably simpler to use net-misc/keychain. You would need to edit your shell config (probably .bash_profile), call keychain and source the ~/.keychain/${HOSTNAME}-sh.

best ... khay
Top
potuz
Guru
Guru
Posts: 378
Joined: Sat Jan 30, 2010 2:00 am

  • Quote

Post by potuz » Tue Dec 16, 2014 2:01 am

khayyam wrote:potuz ...

by "login console" I assume you mean the console (so, not DM).
Indeed, no DM, I now automatically login a user and start X from .bashrc. What I'm trying to do is to stop autologin and hopefully use the password that I type at the login prompt (the one that the login program launched by agetty will produce) to not only start my session but also unlock the keychain.
khayyam wrote: You could call gpg-agent from your shell login, but its probably simpler to use net-misc/keychain. You would need to edit your shell config (probably .bash_profile), call keychain and source the ~/.keychain/${HOSTNAME}-sh.

best ... khay
I haven't seen net-misc/keychain but it simply looks like a wrapper to gpg-agent. I don't understand how changing anything in .bash_profile will allow me to unlock my keychain (or tell gpg-agent to cache the keys in memory) from the login prompt. I thought this should be some form of a PAM module of sorts.
Top
khayyam
Watchman
Watchman
User avatar
Posts: 6227
Joined: Thu Jun 07, 2012 2:45 am
Location: Room 101

  • Quote

Post by khayyam » Tue Dec 16, 2014 12:00 pm

potuz wrote:
khayyam wrote:You could call gpg-agent from your shell login, but its probably simpler to use net-misc/keychain. You would need to edit your shell config (probably .bash_profile), call keychain and source the ~/.keychain/${HOSTNAME}-sh.
I haven't seen net-misc/keychain but it simply looks like a wrapper to gpg-agent. I don't understand how changing anything in .bash_profile will allow me to unlock my keychain (or tell gpg-agent to cache the keys in memory) from the login prompt. I thought this should be some form of a PAM module of sorts.
potuz ... that wasn't altogether clear. Indeed for a single login and *-agent authentication some pam module is required. I do this for ssh-agent with sys-auth/pam_ssh but I'm not aware of something similar for gpg-agent. In the case of pam_ssh the key is used as the login authenticator, once authenticated ssh-agent is started and SSH_AUTH_SOCK is passed as an environment variable to the shell, subsequently the key can be accessed. In the case of gnupg this probably isn't possible as it uses pinentry for input, so 'login' (and therefore pam) is out of the loop.

best ... khay
Top
potuz
Guru
Guru
Posts: 378
Joined: Sat Jan 30, 2010 2:00 am

  • Quote

Post by potuz » Tue Dec 16, 2014 1:03 pm

Thanks, it seems that a pam module does exist, but I need a wrapper over gpg-agent anyway. I think https://github.com/vodik/envoy does what I want. Specially the issue discussed in https://github.com/vodik/envoy/issues/6 I'll try this at some point, but for now pinentry works for me, just a pity having to type twice my password of 16 characters and symbols.
Top
AngelKnight
Tux's lil' helper
Tux's lil' helper
Posts: 127
Joined: Tue Jan 14, 2003 3:21 am

  • Quote

Post by AngelKnight » Tue Jan 06, 2015 9:44 am

(thread necromancy, oops)

If you're not logging in via a DM, what's wrong with Keychain? If I recall correctly there's a perfectly working .ebuild for this stable in the tree. Bonus is that it is designed to manage both ssh and GnuPG keychains and knows how to communicate to both ssh-agent and gpg-agent.
Top
khayyam
Watchman
Watchman
User avatar
Posts: 6227
Joined: Thu Jun 07, 2012 2:45 am
Location: Room 101

  • Quote

Post by khayyam » Tue Jan 06, 2015 7:58 pm

AngelKnight wrote:If you're not logging in via a DM, what's wrong with Keychain? If I recall correctly there's a perfectly working .ebuild for this stable in the tree. Bonus is that it is designed to manage both ssh and GnuPG keychains and knows how to communicate to both ssh-agent and gpg-agent.
AngelKnight ... because the OP wants a single login/authentication ... and keychain is subsequent to 'login'. I do this for ssh-agent using sys-auth/pam_ssh, my ssh-key is used as authentication, and once authenticated ssh-agent is setup for my login.

best ... khay
Top
Post Reply

7 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic