GPG-AGENT(1) GNU Privacy Guard 2.4 GPG-AGENT(1) (NAME) gpg-agent - GnuPG (SYNOPSIS) gpg-agent [--homedir dir] [--options file] [options] gpg-agent [--homedir dir] [--options file] [options] --server gpg-agent [--homedir dir] [--options file] [options] --daemon [command_line] (DESCRIPTION) gpg-agent () . () gpg gpgsm . gpg gpgsm gpgconf gpg-connect-agent . . Secure Shell Agent : gpg-connect-agent /bye : gpgconf --kill gpg-agent .bashrc : GPG_TTY=$(tty) export GPG_TTY tty . W32 . pinentry ( ) pinentry-program . pinentry ( `/usr/bin/pinentry-gtk') ( `/usr/bin/pinentry') . (COMMANDS) . --version . . --help -h . . --dump-options . . --server stdin . . --daemon [command line] gpg-agent . gpg-agent : gpg-agent --daemon /bin/sh. gpg-agent . --supervised stderr . Windows . `common.conf' no-autostart . --supervised LISTEN_FDNAMES ( ssh extra) ( sd_listen_fds(3) Linux ). (OPTIONS) . --options file file . `gpg-agent.conf' `.gnupg' . . --homedir dir dir . `~/.gnupg' . . `GNUPGHOME' ( Windows) HKCU\Software\GNU\GnuPG:HomeDir . Windows GnuPG (portable) . . -v --verbose . verbose gpg-agent `-vv' ( ) . -q --quiet . --batch pinentry . --faked-system-time epoch epoch 1970 . --debug-level level . level : none . 1 . basic . 1 2 . advanced . 3 5 . expert . 6 8 . guru . 8 . . . . --debug flags . OR flags C ( 0x0042) . "help" . . --debug-all --debug=0xffffffff --debug-wait n n pid . . --debug-quick-random (GCRY_VERY_STRONG_RANDOM Libgcrypt) . . . GNU/Linux rngd . rngd rng-tools . : `sudo rngd -f -r /dev/urandom'. --debug-pinentry Pinentry . --debug 1024 . --no-detach . . --steal-socket --daemon gpg-agent gpg-agent . : gpg-agent . . -s --sh -c --csh Bourne C-shell. SHELL . --grab --no-grab pinentry (grab ). X-Server X ( X-sniffing) . --grab --no-grab . --no-grab . --log-file file file . agent . `socket://' . HKCU\Software\GNU\GnuPG:DefaultLogFile ( ) . --no-allow-mark-trusted `trustlist.txt' . Root-CA . --no-user-trustlist (`/etc/gnupg/trustlist.txt') . --no-allow-mark-trusted . --sys-trustlist-name file "trustlist.txt" file . file "~/" (`/etc/gnupg') . --allow-preset-passphrase gpg-preset-passphrase gpg-agent . --no-allow-loopback-pinentry --allow-loopback-pinentry loopback pinentry pinentry-mode . (Allow) . --force Assuan DELETE_KEY : loopback pinentry . --no-allow-external-cache Pinentry . Pinentry . Pinentry . --allow-emacs-pinentry Pinentry Emacs . Pinentry . --ignore-cache-for-signing gpg-agent . . --default-cache-ttl n n . 600 . . max-cache-ttl . . . --default-cache-ttl-ssh n SSH n . 1800 . . max-cache-ttl-ssh . --max-cache-ttl n n . gpg-preset-passphrase . 2 (7200 ) . --max-cache-ttl-ssh n SSH n . gpg-preset-passphrase . 2 (7200 ) . --enforce-passphrase-constraints ``Take it anyway'' . --min-passphrase-len n . . 8 . --min-passphrase-nonalpha n . . 1 . --check-passphrase-pattern file --check-sym-passphrase-pattern file file . . file () "~/" (`/etc/gnupg') . . . : . . . --max-passphrase-days n n . --enforce-passphrase-constraints . --enable-passphrase-history . --pinentry-invisible-char char Pinentry char . char UTF-8 . Pinentry . --pinentry-timeout n Pinentry n (timeout) . 0 pinentry Pinentry . Pinentry . --pinentry-formatted-passphrase Pinentry . (non- breaking space) . GENPIN Pinentry . . --pinentry-program filename filename PIN . . pinentry `pinentry' `pinentry-basic' . Windows : `bin\pinentry.exe', `..\Gpg4win\bin\pinentry.exe', `..\Gpg4win\pinentry.exe', `..\GNU\GnuPG\pinentry.exe', `..\GNU\bin\pinentry.exe', `bin\pinentry-basic.exe' GnuPG . --pinentry-touch-file filename gpg-agent Pinentry (touch) ( curses ). Pinentry filename . /dev/null . Pinentry . --scdaemon-program filename filename (Smartcard) . gpgconf . --disable-scdaemon scdaemon . . scdaemon (fork ) . --disable-check-own-socket gpg-agent . gpg-agent gpg-agent . . --use-standard-socket --no-use-standard-socket --use-standard-socket-p GnuPG 2.1 . . gpg-agent --use-standard-socket-p . --display string --ttyname string --ttytype string --lc-ctype string --lc-messages string --xauthority string . --keep-tty --keep-display tty DISPLAY X . pinentry tty . --listen-backlog n . 64 . --extra-socket name . ``none'' ``/dev/null'' name . gpg-agent . (Unix domain socket forwarding) . gpg gpg-agent . . --enable-extended-key-format --disable-extended-key-format . 2.1.12 . . --enable-ssh-support --enable-win32-openssh-support --enable-putty-support OpenSSH Agent gpg-agent SSH_AUTH_SOCK enable-ssh-support . ssh-agent . ssh enable-win32-openssh-support . gpg-agent Pageant PuTTY enable-putty-support . gpg-agent OpenSSH ( Named Pipes) PuTTY . gpg-agent ssh-agent . SSH ssh-add gpg-agent . ssh-add gpg-agent (passphrase) gpg-agent . gpg-agent gpg- agent . : gpg-agent . ssh-agent / ssh gpg-agent TTY X gpg-agent . : gpg-connect-agent updatestartuptty /bye GnuPG gpg-agent ssh ssh . GnuPG ssh gpg-agent . gpg-agent : gpg-connect-agent /bye --verbose . --enable-putty-support gpg-agent ssh putty . ssh-agent putty (Windows message queue) . ssh : --max-cache-ttl-ssh n SSH n . gpg-preset-passphrase . ( ) . --enforce-passphrase-constraints ``Take it anyway'' . --min-passphrase-len n . . . --min-passphrase-nonalpha n . . . --check-passphrase-pattern file --check-sym-passphrase-pattern file file . . file "~/" (`/etc/gnupg') . . . : . . . --max-passphrase-days n n . --enforce-passphrase-constraints . --enable-passphrase-history . --pinentry-invisible-char char Pinentry char . char UTF-8 . Pinentry . --pinentry-timeout n Pinentry n . 0 pinentry Pinentry . Pinentry . --pinentry-formatted-passphrase Pinentry () . (non-breaking space) . GENPIN Pinentry . . --pinentry-program filename filename PIN . . pinentry `pinentry' `pinentry-basic' . : `bin\pinentry.exe', `..\Gpg4win\bin\pinentry.exe', `..\Gpg4win\pinentry.exe', `..\GNU\GnuPG\pinentry.exe', `..\GNU\bin\pinentry.exe', `bin\pinentry-basic.exe' GnuPG . --pinentry-touch-file filename gpg-agent Pinentry touch ( curses ). Pinentry filename . /dev/null . Pinentry . --scdaemon-program filename filename Smartcard . gpgconf . --disable-scdaemon scdaemon . . scdaemon . --disable-check-own-socket gpg-agent . gpg-agent gpg-agent . . --use-standard-socket --no-use-standard-socket --use-standard-socket-p GnuPG 2.1 . . gpg-agent --use-standard-socket-p . --display string --ttyname string --ttytype string --lc-ctype string --lc-messages string --xauthority string . --keep-tty --keep-display tty DISPLAY X window system . pinentry tty (agent) . --listen-backlog n . 64 . --extra-socket name . ``none'' ``/dev/null'' name . gpg-agent . Unix domain socket . gpg gpg-agent . . --enable-extended-key-format --disable-extended-key-format . 2.1.12 . . --enable-ssh-support --enable-win32-openssh-support --enable-putty-support OpenSSH Agent gpg-agent SSH_AUTH_SOCK enable-ssh-support . ssh-agent . ssh enable-win32-openssh-support . gpg- agent Pageant PuTTY enable-putty-support . (agent) gpg-agent OpenSSH ( Named Pipes) PuTTY . gpg- agent ssh-agent . SSH ssh- add gpg-agent . ssh-add gpg- agent gpg-agent . gpg-agent gpg-agent . : gpg-agent . ssh-agent / ssh gpg-agent TTY X gpg-agent . : gpg-connect-agent updatestartuptty /bye GnuPG gpg-agent ssh ssh . GnuPG ssh gpg-agent . gpg-agent : gpg-connect-agent /bye --verbose agent . --enable-putty-support gpg-agent ssh putty . ssh- agent putty . ssh : Use-for-ssh "Use-for-ssh" ssh . -999 -999 -1 . . ( ) . sshcontrol sshcontrol . sshcontrol . Use-for-ssh "Use-for-ssh" "yes" "true" . "yes" "true" 1 99999 . "Use-for-ssh" gpg-connect-agent "KEYATTR" ( "Use-for-ssh:" ). --ssh-fingerprint-digest (digest algorithm) ssh ( pinentry) . OpenSSH MD5 SHA256 . --auto-expand-secmem n Libgcrypt . n . 32 KiB C . gpg-agent . --s2k-calibration milliseconds milliseconds . 0 . SIGHUP ( gpgconf --reload gpg-agent) S2K . --s2k-count n . . 100ms . --s2k-calibration . S2K : gpg-connect-agent 'GETINFO s2k_count' /bye gpg-connect-agent 'GETINFO s2k_time' /bye : gpg-connect-agent 'GETINFO s2k_count_cal' /bye (EXAMPLES) GPG_TTY (login shell) `~/.bashrc' : export GPG_TTY=$(tty) SSH (Ssh Agent Support) ssh : unset SSH_AGENT_PID if [ "${gnupg_SSH_AUTH_SOCK_by:-0}" -ne $$ ]; then export SSH_AUTH_SOCK="$(gpgconf --list-dirs agent-ssh-socket)" fi (FILES) . (: [ --homedir]). gpg-agent.conf gpg-agent . . SIGHUP . (: [ --options]). . trustlist.txt . . (#) . S . . ! . : # CN=Wurzel ZS 3,O=Intevation GmbH,C=DE A6935DD34EF3087973C706FC311AA2CCF733765B S # CN=PCA-1-Verwaltung-02/O=PKI-1-Verwaltung/C=DE DC:BD:69:25:48:BD:BB:7E:31:6E:BB:80:D3:00:80:35:D4:F8:A6:CD S # CN=Root-CA/O=Schlapphuete/L=Pullach/C=DE !14:56:98:D3:FE:9C:CA:5A:31:6E:BC:81:D3:11:4E:00:90:A3:44:C2 S . . (root certificate) CA CA ( CA ). [ --no-allow-mark- trusted] . . include-default ( `/etc/gnupg/trustlist.txt'). [ --no- user-trustlist] . S : relax . basicConstraints ( CA (MUST) ) CRL . cm CA . qual CA . . CA `qualified.txt' . de-vs CA PKI VS-NfD . . . sshcontrol (secure shell agent) (: [ --enable-ssh-support]). SSH . . "Use- for-ssh" . ssh-add . . keygrip TTL . TTL --default-cache-ttl-ssh . confirm . pinentry . -c ssh-add gpg-agent . keygrip ! . . OpenPGP . # Key added on: 2011-07-20 20:38:46 # Fingerprint: 5e:8d:c4:ad:e7:af:6e:27:8a:d6:13:e4:79:ad:0b:81 34B62F25E277CF13D3C6BCEBFD3F85D08F0A864B 0 confirm private-keys-v1.d/ gpg-agent . keygrip `key' . . `/etc/skel/.gnupg' . (: [addgnupghome]). (SIGNALS) gpg-agent kill . : SIGHUP . : quiet verbose debug debug-all debug-level debug-pinentry no-grab pinentry-program pinentry-invisible-char default-cache-ttl max-cache-ttl ignore-cache-for-signing s2k-count no-allow-external-cache allow-emacs-pinentry no-allow-mark-trusted disable-scdaemon disable-check-own-socket. scdaemon-program scdaemon scdaemon . SIGTERM . . SIGINT . SIGUSR1 . SIGUSR2 . (SEE ALSO) gpg(1), gpgsm(1), gpgconf(1), gpg-connect-agent(1), scdaemon(1) Texinfo . GnuPG info info gnupg . GnuPG 2.4.9 2025-02-19 GPG-AGENT(1)