GPG-CARD(1) GPG-CARD(1) (NAME) gpg-card - (Smart Cards) GnuPG (SYNOPSIS) gpg-card [ ] [ [ ... ] ] (DESCRIPTION) gpg-card OpenPGP . gpg --card-edit (Frontend) scdaemon gpg-agent . gpg-card (Interactive) . gpg-card . (--) . . . help help CMD . << (COMMANDS)>> . <<>> . (COMMANDS) gpg-card . `--' `--' . <> . (Tab Completion) . AUTHENTICATE [--setkey] [--raw] [< file]|key] AUTH . (Mutual Authentication) file key. --raw . --setkey . PIV . CAFPR [--clear] N (CA Fingerprint) N OpenPGP. N . --clear CA N ( N ) . FACTORY-RESET (Reset ) OpenPGP PIV. PIN . . FETCH URL OpenPGP . FORCESIG forcesig OpenPGP. GENERATE [--force] [--algo=algo{+algo2}] keyref . --force . <> algo . OpenPGP . OpenPGP --algo keyref . KDF-SETUP KDF ( ) OpenPGP . LANG [--clear] . . . --clear . (GnuPG) . LIST [--cards] [--apps] [--info] [--no-key-lookup] [n] [app] L . . . n n- app . app <<->> n . n . --cards . --apps . --info . --no-key-lookup OpenPGP X.509 . LOGIN [--clear] [< file] (Login) OpenPGP. file . . --clear . NAME [--clear] OpenPGP. --clear . PASSWD [--reset|--nullpin] [pinref] PIN. pinref . pinref . --reset TCOS PIN PUK --nullpin PIN . PRIVATEDO [--clear] n [< file] n OpenPGP. n . file . --clear . QUIT Q gpg-card. READCERT [--openpgp] certref > file certref file. --openpgp OpenPGP CMS ( OID=1.3.6.1.4.1.11591.2.3.1) file . OpenPGP certref <> . RESET (Reset) . SALUTATION [--clear] SALUT / . . --clear . . UIF N [on|off|permanent] (User Interaction Flag). . N . <> <> . UNBLOCK PIN PUK (Reset Code). OpenPGP PASSWD PIN . URL [--clear] URL OpenPGP. --fetch gpg . --clear . VERIFY [chvid] PIN chvid PIN . WRITECERT certref < file WRITECERT --openpgp certref [< file|fpr] WRITECERT --clear certref certref. --clear . --openpgp OpenPGP CMS file OpenPGP fpr . WRITEKEY [--force] keyref keygrip keygrip keyref. --force . CHECKKEYS [--ondisk] [--delete-clear-copy] [--delete-protected-copy] . --ondisk . --delete-clear-copy . --delete-protected-copy . (Shadow Keys) . . : Serial number . Type <> <>. Keygrip . Keyref <>. Status . <> . <> . <> . <> . YUBIKEY cmd args Yubikey cmd : LIST Yubikey. ENABLE usb|nfc|all [otp|u2f|opgp|piv|oath|fido2|all] DISABLE . (NOTES - OPENPGP) OpenPGP gpg-card . gpg --card-edit . (NOTES - PIV) PIV ( <> NIST Special Publication 800-73-4) . () Yubikey PIV ( Yubikey-5). : Authentication key : 010203040506070801020304050607080102030405060708. PIV Application PIN 123456 . PIN Unblocking Key 12345678 . . . (Authentication Key) Pinentry . . list . ( gpg/card> ). : gpg/card> list Reader ...........: 1050:0407:X:0 Card type ........: yubikey Card firmware ....: 5.1.2 Serial number ....: D2760001240102010006090746250000 Application type .: OpenPGP Version ..........: 2.1 [...] <> GnuPG OpenPGP Yubikey . GnuPG OpenPGP . PIV Yubikey : Yubikey OpenPGP Yubikey : gpg/card> yubikey disable all opgp gpg/card> yubikey list Application USB NFC ----------------------- OTP yes yes U2F yes yes OPGP no no PIV yes no OATH yes yes FIDO2 yes yes gpg/card> reset reset GnuPG . ( `help yubikey' ). Yubikey OpenPGP scdaemon . : disable-application openpgp `~/.gnupg/scdaemon.conf' scdaemon `gpgconf --kill scdaemon'. scdaemon . PIV OpenPGP : application-priority piv `~/.gnupg/scdaemon.conf' scdaemon. PIV OpenPGP OpenPGP . list gpg-card : gpg/card> list Reader ...........: 1050:0407:X:0 Card type ........: yubikey Card firmware ....: 5.1.2 Serial number ....: FF020001008A77C1 Application type .: PIV Version ..........: 1.0 Displayed s/n ....: yk-9074625 PIN usage policy .: app-pin PIN retry counter : - 3 - PIV authentication: [none] keyref .....: PIV.9A Card authenticat. : [none] keyref .....: PIV.9E Digital signature : [none] keyref .....: PIV.9C Key management ...: [none] keyref .....: PIV.9D gpg-card . (0, 1, 2, ...) list . `list --cards' . <> Pinentry PIN . . PIV authentication ( PIV.9A) . Application PIN USB . Secure Shell (SSH) . Card authentication (PIV.9E) CAK . PIN . Digital signature (PIV.9C) . Application PIN . Key management (PIV.9D) . Application PIN USB . . GnuPG Card authentication PIV . . ( ): gpg/card> auth 010203040506070801020304050607080102030405060708 . LF ( ) : gpg/card> auth < myauth.key `help auth' . . USB . `<' . : gpg/card> generate --algo=nistp384 PIV.9A PIV card no. yk-9074625 detected gpg/card> generate --algo=nistp256 PIV.9E PIV card no. yk-9074625 detected gpg/card> generate --algo=rsa2048 PIV.9C PIV card no. yk-9074625 detected `--force' . . GnuPG . gpgsm . list : gpg/card> list Reader ...........: 1050:0407:X:0 Card type ........: yubikey Card firmware ....: 5.1.2 Serial number ....: FF020001008A77C1 Application type .: PIV Version ..........: 1.0 Displayed s/n ....: yk-9074625 PIN usage policy .: app-pin PIN retry counter : - 3 - PIV authentication: 213D1825FDE0F8240CB4E4229F01AF90AC658C2E keyref .....: PIV.9A (auth) algorithm ..: nistp384 Card authenticat. : 7A53E6CFFE7220A0E646B4632EE29E5A7104499C keyref .....: PIV.9E (auth) algorithm ..: nistp256 Digital signature : 32A6C6FAFCB8421878608AAB452D5470DD3223ED keyref .....: PIV.9C (sign,cert) algorithm ..: rsa2048 Key management ...: [none] keyref .....: PIV.9D keygrip . keygrip . gpg-agent GnuPG (X.509 OpenPGP SecureShell) . keygrip . gpg . gpg . Key management generate . gpg gpgsm (Import) . (Self-signed) X.509 ( quit gpg-card ): $ gpgsm --gen-key -o encr.crt (1) RSA (2) Existing key (3) Existing key from card Your selection? 1 What keysize do you want? (3072) 2048 Requested keysize is 2048 bits Possible actions for a RSA key: (1) sign, encrypt (2) sign (3) encrypt Your selection? 3 Enter the X.509 subject name: CN=Encryption key for yk-9074625,O=example,C=DE Enter email addresses (end with an empty line): > otto@example.net > Enter DNS names (optional; end with an empty line): > Enter URIs (optional; end with an empty line): > Create self-signed certificate? (y/N) y These parameters are used: Key-Type: RSA Key-Length: 2048 Key-Usage: encrypt Serial: random Name-DN: CN=Encryption key for yk-9074625,O=example,C=DE Name-Email: otto@example.net Proceed with creation? (y/N) Now creating self-signed certificate. This may take a while ... gpgsm: about to sign the certificate for key: &34798AAFE0A7565088101CC4AE31C5C8C74461CB gpgsm: certificate created Ready. $ gpgsm --import encr.crt gpgsm: certificate imported gpgsm: total number processed: 1 gpgsm: imported: 1 . (CSR) (CA) CA . keygrip ( & ) `gpgsm --with-keygrip -k otto@example.net' . gpg-card : gpg/card> writekey PIV.9D 34798AAFE0A7565088101CC4AE31C5C8C74461CB gpg/card> writecert PIV.9D < encr.crt (Passphrase) Pinentry . list : [...] Key management ...: 34798AAFE0A7565088101CC4AE31C5C8C74461CB keyref .....: PIV.9D (encr) algorithm ..: rsa2048 used for ...: X.509 user id ..: CN=Encryption key for yk-9074625,O=example,C=DE user id ..: ( keygrip) <> . . : . `34798AAFE0A7565088101CC4AE31C5C8C74461CB.key' `~/.gnupg/private-keys-v1.d/' . . quit Control-D gpg-card gpgsm : $ gpgsm --learn $ gpgsm --gen-key -o sign.crt Please select what kind of key you want: (1) RSA (2) Existing key (3) Existing key from card Your selection? 3 Serial number of the card: FF020001008A77C1 Available keys: (1) 213D1825FDE0F8240CB4E4229F01AF90AC658C2E PIV.9A nistp384 (2) 7A53E6CFFE7220A0E646B4632EE29E5A7104499C PIV.9E nistp256 (3) 32A6C6FAFCB8421878608AAB452D5470DD3223ED PIV.9C rsa2048 (4) 34798AAFE0A7565088101CC4AE31C5C8C74461CB PIV.9D rsa2048 Your selection? 3 Possible actions for a RSA key: (1) sign, encrypt (2) sign (3) encrypt Your selection? 2 Enter the X.509 subject name: CN=Signing key for yk-9074625,O=example,C=DE Enter email addresses (end with an empty line): > otto@example.net > Enter DNS names (optional; end with an empty line): > Enter URIs (optional; end with an empty line): > Create self-signed certificate? (y/N) These parameters are used: Key-Type: card:PIV.9C Key-Length: 1024 Key-Usage: sign Serial: random Name-DN: CN=Signing key for yk-9074625,O=example,C=DE Name-Email: otto@example.net Proceed with creation? (y/N) y Now creating self-signed certificate. This may take a while ... gpgsm: about to sign the certificate for key: &32A6C6FAFCB8421878608AAB452D5470DD3223ED gpgsm: certificate created Ready. $ gpgsm --import sign.crt gpgsm: certificate imported gpgsm: total number processed: 1 gpgsm: imported: 1 `gpgsm --learn' gpg-agent . . . <> . Application PIN . gpg-card : gpg/card> writecert PIV.9C < sign.crt list : Reader ...........: 1050:0407:X:0 Card type ........: yubikey Card firmware ....: 5.1.2 Serial number ....: FF020001008A77C1 Application type .: PIV Version ..........: 1.0 Displayed s/n ....: yk-9074625 PIN usage policy .: app-pin PIN retry counter : - [verified] - PIV authentication: 213D1825FDE0F8240CB4E4229F01AF90AC658C2E keyref .....: PIV.9A (auth) algorithm ..: nistp384 Card authenticat. : 7A53E6CFFE7220A0E646B4632EE29E5A7104499C keyref .....: PIV.9E (auth) algorithm ..: nistp256 Digital signature : 32A6C6FAFCB8421878608AAB452D5470DD3223ED keyref .....: PIV.9C (sign,cert) algorithm ..: rsa2048 used for ...: X.509 user id ..: CN=Signing key for yk-9074625,O=example,C=DE user id ..: Key management ...: 34798AAFE0A7565088101CC4AE31C5C8C74461CB keyref .....: PIV.9D (encr) algorithm ..: rsa2048 used for ...: X.509 user id ..: CN=Encryption key for yk-9074625,O=example,C=DE user id ..: gpgsm <> ssh : $ ssh-add -l 384 SHA256:0qnJ0Y0ehWxKcx2frLfEljf6GCdlO55OZed5HqGHsaU cardno:yk-9074625 (ECDSA) ssh-add `-L' ssh . (Thunderbird) Scute . PIV OpenPGP ( Yubikey OpenPGP PIV) : $ gpgsm --learn $ gpg --full-gen-key Please select what kind of key you want: (1) RSA and RSA (default) (2) DSA and Elgamal (3) DSA (sign only) (4) RSA (sign only) (14) Existing key from card Your selection? 14 Serial number of the card: FF020001008A77C1 Available keys: (1) 213D1825FDE0F8240CB4E4229F01AF90AC658C2E PIV.9A nistp384 (auth) (2) 7A53E6CFFE7220A0E646B4632EE29E5A7104499C PIV.9E nistp256 (auth) (3) 32A6C6FAFCB8421878608AAB452D5470DD3223ED PIV.9C rsa2048 (cert,sign) (4) 34798AAFE0A7565088101CC4AE31C5C8C74461CB PIV.9D rsa2048 (encr) Your selection? 3 Please specify how long the key should be valid. 0 = key does not expire = key expires in n days w = key expires in n weeks m = key expires in n months y = key expires in n years Key is valid for? (0) Key does not expire at all Is this correct? (y/N) y GnuPG needs to construct a user ID to identify your key. Real name: Email address: otto@example.net Comment: You selected this USER-ID: "otto@example.net" Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? o gpg: key C3AFA9ED971BB365 marked as ultimately trusted gpg: revocation certificate stored as '[...]D971BB365.rev' public and secret key created and signed. Note that this key cannot be used for encryption. You may want to use the command "--edit-key" to generate a subkey for this purpose. pub rsa2048 2019-04-04 [SC] 7F899AE2FB73159DD68A1B20C3AFA9ED971BB365 uid otto@example.net PIN PIV . gpg --expert (Usage flags) . : $ gpg --edit-key 7F899AE2FB73159DD68A1B20C3AFA9ED971BB365 Secret key is available. sec rsa2048/C3AFA9ED971BB365 created: 2019-04-04 expires: never usage: SC card-no: FF020001008A77C1 trust: ultimate validity: ultimate [ultimate] (1). otto@example.net gpg> addkey Secret parts of primary key are stored on-card. Please select what kind of key you want: (3) DSA (sign only) (4) RSA (sign only) (5) Elgamal (encrypt only) (6) RSA (encrypt only) (14) Existing key from card Your selection? 14 Serial number of the card: FF020001008A77C1 Available keys: (1) 213D1825FDE0F8240CB4E4229F01AF90AC658C2E PIV.9A nistp384 (auth) (2) 7A53E6CFFE7220A0E646B4632EE29E5A7104499C PIV.9E nistp256 (auth) (3) 32A6C6FAFCB8421878608AAB452D5470DD3223ED PIV.9C rsa2048 (cert,sign) (4) 34798AAFE0A7565088101CC4AE31C5C8C74461CB PIV.9D rsa2048 (encr) Your selection? 4 Please specify how long the key should be valid. 0 = key does not expire = key expires in n days w = key expires in n weeks m = key expires in n months y = key expires in n years Key is valid for? (0) Key does not expire at all Is this correct? (y/N) y Really create? (y/N) y sec rsa2048/C3AFA9ED971BB365 created: 2019-04-04 expires: never usage: SC card-no: FF020001008A77C1 trust: ultimate validity: ultimate ssb rsa2048/7067860A98FCE6E1 created: 2019-04-04 expires: never usage: E card-no: FF020001008A77C1 [ultimate] (1). otto@example.net gpg> save PIV gpg . (OPTIONS) gpg-card : --with-colons . --status-fd n n. SUCCESS FAILURE (Double fork) . --verbose . --quiet . --version . --help . --no-autostart gpg-agent . gpg-agent . --no-history GnuPG . . --agent-program file . gpgconf --list-dirs . --gpg-program file gpg . --gpgsm-program file gpgsm . --chuid uid uid . (root) gpg-card . uid PATH GNUPGHOME . --homedir . . . (SEE ALSO) scdaemon(1) gnupg GPG-CARD(1)