GPG(1) GNU Privacy Guard 2.4 GPG(1) (NAME) gpg - OpenPGP (SYNOPSIS) gpg [--homedir dir] [--options file] [] [] (DESCRIPTION) gpg OpenPGP GNU Privacy Guard (GnuPG) . OpenPGP . gpg OpenPGP . GnuPG : GnuPG 1.x GnuPG 2.x. GnuPG 2.x GnuPG 1.x . GnuPG 1.x GnuPG 2.x GnuPG 2.x ( PGP-2) . GnuPG gpg1 . (RETURN VALUE) 0 1 . . . gpgv . (WARNINGS) . . (passphrase) . . . (detached signatures) `-' STDIN . gpg (machine-parseable interface) . API (locale) gpg . --with-colons --status-fd . --command-fd . `DETAILS' . <> GnuPG PDF GnuPG GnuPG . GPGME . (INTEROPERABILITY) GnuPG OpenPGP . GnuPG SHA-512 ZLIB BZIP2 . OpenPGP --cipher-algo --digest-algo --cert-digest-algo --compress-algo GnuPG OpenPGP . OpenPGP . PGP BLOWFISH . BLOWFISH PGP . GnuPG OpenPGP OpenPGP . . --pgp6 --pgp7 --pgp8 . OpenPGP << PGP>> . (COMMANDS) . . gpg . ( ). --verbose . --version . . --help -h . ( -h ). --warranty . --dump-options . . --sign -s . --encrypt ( ) --symmetric ( ) --encrypt --symmetric ( ) . --local-user --default-key . --clear-sign --clearsign (cleartext signature). OpenPGP . . --local-user --default-key . --detach-sign -b (detached signature). --encrypt -e . --sign ( ) --symmetric ( ) --sign --symmetric ( ) . --recipient . --symmetric -c . AES-128 --cipher-algo . --sign ( ) --encrypt ( ) --sign --encrypt ( ) . gpg . --no-symkey-cache . --store ( - literal data packet). --decrypt -d ( STDIN ) STDOUT ( --output). . . --verify . STDIN . . (detached signature) . STDIN `-' . STDIN . : --batch gpg . . : gpg . --output . . : --batch . . --proc-all-sigs . : --assert-signer . gpgv . gpgv . . --multifile STDIN . . --multifile --verify --encrypt --decrypt . --multifile --verify . --verify-files --multifile --verify . --encrypt-files --multifile --encrypt . --decrypt-files --multifile --decrypt . --list-keys -k --list-public-keys . . . . --with-colons . --list-secret-keys -K . . # sec ssb . ( --export-secret-subkeys ). > . --list-keys . --check-signatures --check-sigs --list-keys . . --list-keys --with-sig-check . "sig" ( ) . "!" "-" ( ) "%" . --list-sigs . . . 1-3 (: --ask-cert-level) "L" (: --lsign-key) "R" (: "nrsign" --edit-key) "P" (: --cert-policy-url) "N" (: --cert-notation) "X" (: --ask-cert-expire) 1-9 "T" (: "tsign" --edit-key) . --import-ownertrust (trustdb) ownertrust files ( STDIN ) . trustdb ownertrust ( `otrust.txt') trustdb : cd ~/.gnupg rm trustdb.gpg gpg --import-ownertrust < otrust.txt --rebuild-keydb-caches 1.0.6 1.0.7 (keyring) . . --print-md algo --print-mds (message digest) algo STDIN . ( "*" algo) . --gen-random 0|1|2|16|30 count count 0 1 2 . count . --armor base64 . 16 1 hex . 30 30 zBase-32 . --gen-prime mode bits :-). . --enarmor --dearmor / OpenPGP ASCII armor. GnuPG OpenPGP . --dearmor PEM (dearmor PEM armors) . --unwrap --decrypt . OpenPGP OpenPGP . . --tofu-policy {auto|good|unknown|bad|ask} keys TOFU (bindings) keys . : [trust-model- tofu]. keys (fingerprint - ) keyid . . --quick-generate-key user-id [algo [usage [expire]]] --quick-gen-key user id . --generate-key (prompt) . --yes user id (keyring) . <> . user id keyring . algo usage (primary key) . (subkey) ``default'' ``future-default'' algo ``default'' usage . --quick-add-key . usage ``cert'' (certification only) (certification and signing) . expire . ``YYYY-MM-DD'' ``YYYYMMDDThhmmss'' . N N N N N ``seconds=N'' ``Nd'' ``Nw'' ``Nm'' ``Ny'' . ``-'' . ``never'' ``none'' . --batch --pinentry-mode loopback (--passphrase --passphrase-fd --passphrase-file) agent . --passphrase '' . OpenPGP (smartcard) ``card'' algo . gpg OpenPGP . . --full-gen-key . ``default'' --default-new-key-algo . --quick-set-expire fpr expire [*|subfprs] fpr expire . 0 . expire . subfprs expire . --quick-add-key fpr [algo [usage [expire]]] fpr . . . algo (curve) . ``default'' ``-'' . ``rsa'' ``dsa'' ``elg'' ``ed25519'' ``cv25519'' ECC. ``rsa'' RSA ``rsa4096'' . ``future-default'' gpg . ECC gpg --with-colons --list-config curve . algo . usage . ``default'' ``-'' ( ) : ``sign'' ``auth'' ``encr'' ( ``encrypt'' ``encr'' ). . expire . ISO ``YYYY-MM-DD'' ``YYYYMMDDThhmmss'' . N N N N N ``seconds=N'' ``Nd'' ``Nw'' ``Nm'' ``Ny'' . ``-'' . ``never'' ``none'' . --quick-add-adsk fpr adskfpr (Additional Decryption Subkey) fpr . adskfpr . . --with-subkey-fingerprint . "default" adskfpr ADSK --default-new-key-adsk . --generate-key --gen-key . . `openpgp-revocs.d' GnuPG . --full-generate-key --full-gen-key . --generate-key . (batch mode) . ``Unattended key generation'' . --generate-revocation name --gen-revoke name . --edit . . . --import . ( --send-key) (--export) . --generate-designated-revocation name --desig-revoke name . ( ) . --edit-key . . uid n n. * 0 . key n n n. * 0 . sign name. ( -u) . -u . lsign <> . . nrsign <> . tsign . ( ) ( <>) . << >> (Trusted Introducer) . <> <> RFC-4880 . <> ( / ) <> ( ) <> ( ) <> . --only-sign-text-ids ( ) . delsig . ( keyserver) . revsig . revsig . GnuPG . check . selfsig - . adduid . addphoto . JPEG . JPEG . JPEG (GnuPG) (PGP). showphoto . deluid . ( keyserver ) . revuid . revuid . primary . . keyserver (keyserver) () . . --keyserver-options honor-keyserver-url . "none" . notation name=value () . --cert-notation . "none" (-) ( =value) . pref . . showpref . 3DES ( - cipher) SHA-1 ( - digest) Uncompressed ( - compression) . ( ) . setpref string string ( ) . setpref ( --default-preference-list ) setpref "none" . gpg --version . ( "photo ID") GnuPG GnuPG . --quick-update-pref . . 3DES . ( ) OpenPGP . . OPENPGP (INTEROPERABILITY WITH OTHER OPENPGP PROGRAMS) . addkey . addcardkey . keytocard ( ) . save (keyring) (stub) . . . - . bkuptocard file file . ( ) . . . 2 . Admin PIN . keytotpm ( ) TPM. TPM TPM ( TPM ). TPM ( TPM 2.0 rsa2048 nistp256 TPM ). TPM TPM . TPM TPM TPM . TPM rw TPM (/dev/tpmrm0) . tss . delkey ( ). ( keyserver ) . revkey . . revkey . expire . . . trust (owner trust) . trust-db . disable enable . . addrevoker (designated revoker) . : "sensitive". sensitive ( export-options ). addadsk (Additional Decryption Subkey). . . --with-subkey-fingerprint . passwd . toggle (dummy) . clean ( ) ( selfsig). . . minimize . (self- signature) . change-usage () . ( Certify Sign Authenticate Encrypt) . ( Authenticate) . . cross-certify (cross-certification) . . --require-cross-certification . . save . quit . . . : "trust" "validity" . . trust : [trust-values]. --sign-key name . "sign" --edit-key . --lsign-key name (non-exportable) . "lsign" --edit-key . --quick-sign-key fpr [names] --quick-lsign-key fpr [names] . fpr . names [names] . '*' . '=' . --quick-lsign-key (non-exportable) . --quick-sign-key . (notation data) --force-sign-key . "sign" --edit-key . . --quick-add-uid user-id new-user-id . adduid --edit-key new-user-id UTF-8 . --quick-revoke-uid user-id user-id-to-revoke . ( ) ``User ID is no longer valid''. revuid --edit-key . --quick-revoke-sig fpr signing-fpr [names] signing-fpr fpr . names ( --quick-sign-key ). . . --quick-set-primary-uid user-id primary-user-id . user-id primary- user-id . . --quick-update-pref user-id ( --default-preference-list) . "setpref" --key-edit . --list-options show-pref --list-options show-pref-verbose . . --quick-set-ownertrust user-id value (ownertrust) . "trust" "disable" "enable" --key-edit . --change-passphrase user-id --passwd user-id user-id . passwd --edit-key . --dry-run . (OPTIONS) gpg . ( "~/.gnupg/gpg.conf") . - "armor" "a" . . ('#') . gpg . -- . . --default-key name name . keyID name . . -u --local-user . . . GnuPG . --default-recipient name --recipient name . name name (fingerprint) . --default-recipient-self --recipient . (secret keyring) --default-key . --no-default-recipient --default-recipient --default-recipient-self . . -v, --verbose . . --no-verbose (verbose) 0 . . -q, --quiet . . --batch --no-batch (batch). . --no-batch . gpg STDIN ( gpg (detached signature) ). STDIN STDIN `/dev/null' . (unattended) gpg --status-fd --with-colons . . --no-tty TTY () . GnuPG --batch TTY . --yes <<>> . . --no <<>> . . --proc-all-sigs --batch . --list-filter {select=expr} . --import-filter . --list-options parameters ( --list-keys --check-signatures --list-public-keys --list-secret-keys --edit-key) . no- ( ) . : show-photos --list-keys --check-signatures --list-public-keys --list-secret-keys . no . : --photo-viewer. --with-colons : (frontends) --attribute-fd . show-usage . (E= S= C= A= ). yes . show-ownertrust ownertrust . no . show-policy-urls URL --check-signatures. no . show-notations show-std-notations show-user-notations IETF --check-signatures. no . show-keyserver-urls URL --check-signatures. no . show-uid-validity . yes . show-unusable-uids . no . show-unusable-subkeys . no . show-unusable-sigs . show-keyring . no . show-sig-expire ( ) --check-signatures. no . show-sig-subpackets . . . no . --with-colons --check-signatures . show-only-fpr-mbox (user-id) . sort-sigs --list-sigs --check-sigs keyID . (self-signature) . yes . -with-colons . --verify-options parameters . `no-' . : show-photos . no . --photo-viewer . show-policy-urls URL . yes . show-notations show-std-notations show-user-notations IETF . IETF . show-keyserver-urls URL . yes . show-uid-validity . yes . show-unusable-uids . no . show-primary-uid-only . AKA . --enable-large-rsa --disable-large-rsa RSA 8192 . : 8192 . . large-secmem . --enable-dsa2 --disable-dsa2 (hash truncation) DSA DSA 1024 . --openpgp . GnuPG DSA 1024 . --photo-viewer string . "%i" . "%I" . "%k" "%K" "%f" "%t" ( "jpg") "%T" MIME ( "image/jpeg") "%v" ( "f") "%V" ( "full") "%U" base32 "%%" . %i %I . Unix xloadimage -fork -quiet -title 'KeyID 0x%k' STDIN (fallback) display -title 'KeyID 0x%k' %i xdg-open %i. Windows !ShellExecute 400 %i (meta command) API gpg . gpg . --exec-path string . PATH . --keyring file file . file (tilde) $HOME . GnuPG ("~/.gnupg" --homedir $GNUPGHOME ). . --keyring --no-default-keyring . --no-keyring . use-keyboxd `common.conf' keyboxd . --primary-keyring file --keyring file . ( --import --recv-from) . --secret-keyring file . `private-keys-v1.d' GnuPG . --trustdb-name file file trustdb . file (tilde) $HOME . GnuPG ( --homedir $GNUPGHOME `~/.gnupg'). --homedir dir dir. `~/.gnupg' . . `GNUPGHOME' ( ) HKCU\Software\GNU\GnuPG:HomeDir . GnuPG ( ) . . --display-charset name . UTF-8 . GnuPG . (locale) . . . name : iso-8859-1 Latin 1 . iso-8859-2 Latin 2. iso-8859-15 Latin 1 . koi8-r (RFC-1489). utf-8 UTF-8 . --utf8-strings --no-utf8-strings UTF-8 . (--no-utf8-strings) --display-charset . . . (options file) . . UTF-8 . Unicode UTF-8 . Unicode CreateProcess . --options file file ( --homedir). . --no-options --options /dev/null . . `~/.gnupg' . -z n --compress-level n --bzip2-compress-level n --no-compress n ZIP ZLIB. zlib ( ). --bzip2-compress-level BZIP2 ( ). --compress-level BZIP2 . -z . 0 n . -1 . --no-compress -z0 . --store gpg . -z0 --no-compress -z-1 z ( -1 ) . z . --bzip2-decompress-lowmem BZIP2 . . --bzip2-compress-level . --mangle-dos-filenames --no-mangle-dos-filenames . --mangle-dos-filenames GnuPG ( ). . --ask-cert-level --no-ask-cert-level () . --default-cert-level . --default-cert-level . --no-ask-cert-level . no . --default-cert-level n . 0 . 1 . << >> (persona) . 2 . (user ID) . 3 . ( ) (user ID) ( ) . 2 3 . <<>> <<>> . 0 ( ). --min-cert-level . . << >> . --trusted-key long key ID or fingerprint ( ) . ( ) . LDAP . <> trusted- key ( --no-options) . --add-desig-revoker [sensitive:]fingerprint fingerprint (designated revoker) . <> . . <> . . . --default-new-key-adsk fingerprint fingerprint (ADSK) . ADSK . . <> ( ). ( ) . --trust-model {pgp|classic|tofu|tofu+pgp|direct|always|auto} GnuPG . : pgp (Web of Trust) PGP 5.x . . classic PGP 2 . tofu TOFU Trust On First Use ( ) . . . ( ) . . . TOFU . TOFU ( ). TOFU . (trusted introducers) . TOFU . TOFU ( ) . --tofu-policy . --tofu-default-policy . TOFU : auto good unknown bad ask. auto ( --tofu-default-policy ) (marginally trusted) . good unknown bad . unknown TOFU . ask . (batch mode) ( ) undefined . tofu+pgp TOFU (Web of Trust) . : unknown < undefined < marginal < fully < ultimate < expired < never. --tofu-default-policy=unknown TOFU . direct . (user IDs) . ownertrust . always . . "[uncertain]" . . auto . . tofu . --always-trust --trust-model always . --assert-signer fpr_or_file . (fingerprint) . ( ) . . fpr_or_file (#) . gpg 0 . --assert-pubkey-algo algolist algolist . . "ed25519" ">" ">=" "<=" "<" . 2048 "rsa2048" 384 "brainpoolP384r1". . ">rsa3000, >=brainpool384r1, =ed25519" RSA 3000 Brainpool 384 512 ed25519 . gpg ( gpgv) 0 . --auto-key-locate mechanisms --no-auto-key-locate GnuPG . ( "user@example.com") "user@example.com" . . . --no-auto-key-locate "clear" . "local,wkd" . cert DNS CERT RFC-4398 . dane DANE draft-ietf-dane-openpgpkey-05.txt . wkd Web Key Directory. ldap LDAP. keyserver LDAP . ntds Active Directory ( ). --locate-external-key . `ldap' "ldap:///" keyserver . keyserver keyserver. keyserver LDAP --locate-external-key . keyserver-URL URL keyserver dirmngr keyserver . URL LDAP --locate-external-key . local . . `--auto-key-locate local' --no-auto-key-locate . nodefault --auto-key-locate . . local . clear . . nodefault mechanisms clear . --auto-key-import --no-auto-key-import . . --no-auto-key-import . () --include-key-block "Key Block subpacket" . --auto-key-retrieve --no-auto-key-retrieve keyserver . --no-auto-key-retrieve . : 1. --auto-key-import . 2. keyserver honor-keyserver-url ( ) keyserver . --sig-keyserver-url keyserver . 3. UID (Signer's UID) ( --sender ) Web Key Directory (WKD) . WKD auto-key-locate --disable-signer-uid . 4. keyserver (Issuer Fingerprint) ( GnuPG 2.1.16 ) keyserver . "web bug" . keyserver Web Key Directory ( ) IP . --keyid-format {none|short|0xshort|long|0xlong} . "none" . "short" . "long" ( ) . "0x" "0x" 0x99242560. --with-colons . --keyserver name - --keyserver `dirmngr.conf' . name . --receive-keys --send-keys --search-keys . name URI : `scheme:[//]keyservername[:port]' (scheme) : "hkp"/"hkps" HTTP ( ) "ldap"/"ldaps" LDAP. GnuPG . . . hkp://keys.gnupg.net (round robin DNS) . --keyserver-options {name=value} . `no-' . import-options export-options (--recv-key) (--send-key) . : include-revoked --search-keys (revoked) . . . include-disabled --search-keys (disabled) . HKP . auto-key-retrieve auto-key-retrieve . .. honor-keyserver-url --refresh-keys URL . auto-key-retrieve URL . "web bug" ( ) : . . include-subkeys . HKP . only-pubkeys (secret keys) . timeout http-proxy=value verbose debug check-cert ca-cert-file GnuPG 2.1 . dirmngr . : "self-sigs-only, repair-keys, repair- pks-subkey-bug, export-attributes". LDAP "no- self-sigs-only" "self-sigs-only" . --completes-needed n ( ). --marginals-needed n ( ). --tofu-default-policy {auto|good|unknown|bad|ask} TOFU ( auto ). : [trust-model-tofu]. --max-cert-depth n ( ). --no-sig-cache . . . . --auto-check-trustdb --no-auto-check-trustdb GnuPG (Web of Trust) --check-trustdb . . --no-auto-check-trustdb . --use-agent --no-use-agent . gpg agent . --gpg-agent-info . gpg . --agent-program file agent . gpgconf --list-dirs . (|) . --dirmngr-program file dirmngr keyserver . `/usr/bin/dirmngr' . --disable-dirmngr Dirmngr . --no-autostart gpg-agent dirmngr . gpg-agent . dirmngr gpgconf --launch dirmngr . --lock-once . --lock-multiple . --lock-once . --lock-never . . . . --exit-on-status-write-error (status FD) . FD . --enable-progress-filter gpg . --limit-card-insert-tries n n 0 N-1 . 1 gpg . . --no-random-seed-file GnuPG . . . --no-greeting . --no-secmem-warning "using insecure memory" ( ). --no-permission-warning (--homedir). GnuPG . . --homedir gpg.conf gpg.conf . --homedir . --require-secmem --no-require-secmem GnuPG . no ( ). --require-cross-certification --no-require-cross-certification "back signature" . . gpg --require-cross-certification . --expert --no-expert . . . . --no-expert . --recipient name -r name. --hidden-recipient GnuPG --default-recipient . --hidden-recipient name -R name . . --recipient GnuPG --default-recipient . --recipient-file file -f --recipient . file . gpg . --hidden-recipient-file file -F --hidden-recipient . file . gpg . --encrypt-to name --recipient (options file) "encrypt-to- self" ( ) . (long keyID) name . --recipient . . --hidden-encrypt-to name --hidden-recipient (options file) "encrypt-to- self" ( ) . (long keyID) name . --recipient . . --no-encrypt-to --encrypt-to --hidden-encrypt-to. --group {name=value} (aliases) . (-r --recipient) . . key IDs ( ) . . --- . . --ungroup name --group. --no-groups --group. --local-user name -u name . --default-key . --sender mbox . mbox . . gpg ( "Signer's User ID" OpenPGP). . ( ) . mbox TOFU . "Signer's User ID" . GnuPG . TRUST status-fd TRUST . VALIDSIG () . --try-secret-key name GPG . --default-key . . name (long keyid) . gpg-agent pinentry . (cancel) . --try-all-secrets . ( --throw-keyids --hidden-recipient) . --skip-hidden-recipients --no-skip-hidden-recipients . encrypt- to . . . (Input and Output) --armor -a ASCII (ASCII armored) . OpenPGP . --no-armor ASCII . --output file -o file file . stdout - . --max-output n . OpenPGP (plaintext) OpenPGP . GnuPG . 0 << >> . --chunk-size n AEAD (chunks) . 2^n . n 6 (64 ) 22 4 MiB . --input-size-hint n GPG . n 10 . . GPG . ``PROGRESS'' --status-fd ``total'' . --key-origin string[,url] gpg . ( keyserver web key directory) . . "help" string . url . URL string . --import-options parameters . `no-' . : import-local-sigs "local" . (keyring) . no . keep-ownertrust ownertrust . ownertrust . ownertrust . . repair-pks-subkey-bug (keyserver) PKS ( 0.9.6) . keyserver . --import no --receive-keys yes . import-show show-only . --dry-run show-only . --show-keys . '#' "sec" "sbb" . import-export . export-dane . . merge-only . no . import-clean ( -). . (keyring) . "clean" --edit-key . no . self-sigs-only - . . keyserver-options . (Web of Trust) . import-clean clean . ignore-attributes ( ) . repair-keys . . yes . bulk-import keyboxd ( use-keyboxd `common.conf') . import-minimal . - . "minimize" --edit-key . no . restore import-restore . GnuPG . . --import-filter {name=expr} --export-filter {name=expr} / / . name expr . name . : keep-uid true . drop-subkey . --export-filter . drop-sig . - . --import-filter . select --list-filter . . "FILTER EXPRESSIONS" . . --list-filter . . "pub" "sub" "uid" "sig" . . : uid . (keep-uid) mbox addr-spec (mailbox) . (keep-uid) algostr . "rsa3072" "ed25519". key_algo . (drop-subkey) key_size . (drop-subkey) key_created key_created_d (timestamp) . ISO "2016-08-17". (drop-subkey) key_expires key_expires_d 0 . ISO "2038-01-19". fpr . (drop-subkey) primary . (keep-uid) expired (keep-uid) (drop- subkey) (drop-sig) . revoked (keep-uid) (drop-subkey) . disabled . secret . (drop- subkey) usage ``ecsa?''. ``sa'' . (drop-subkey) sig_created sig_created_d . ISO "2016-08-17". (drop-sig) sig_expires sig_expires_d 0 . ISO "2038-01-19". sig_algo . (drop-sig) sig_digest_algo (digest) . (drop-sig) origin . Web Key Directory ``wkd'' . lastupd (timestamp) (keyserver) Web Key Directory . url URL . --export-options parameters . `no-' . : export-local-sigs "local" . (keyring) . no . export-attributes ( ) . OpenPGP . yes . export-sensitive-revkeys (designated revoker) "sensitive" . no . backup export-backup . GnuPG . OpenPGP GnuPG . (override ). export-clean ( ) . . (keyring) . "clean" --edit-key . no . export-minimal . (self-signature) . "minimize" --edit-key . no . export-revocs . . export-dane OpenPGP DANE (zone files) DNS . ORIGIN . mode1003 . OpenPGP . OpenPGP . GnuPG 2.4.0 . --with-colons . --display-charset UTF-8 . GnuPG . `doc/DETAILS' GnuPG . --fixed-list-mode --with-colon 1970-01-01 . 2.0.10 GnuPG . --legacy-list-mode 2.1. ( --with-colons) . . --with-fingerprint --fingerprint . --with-subkey-fingerprint . --with-fingerprint keyid-format "none" . --with-v5-fingerprint "fp2" OpenPGP v5 . --with-icao-spelling ICAO . --with-keygrip keygrip . --with-colons . --with-key-origin . --with-colons . API . --with-wkd-hash Web Key Directory . . --with-secret --with-colons . OpenPGP --force-ocb --force-aead AEAD MDC. AEAD MDC . --force-aead . --chunk-size . --force-mdc --disable-mdc GnuPG 2.2.8 . MDC AEAD AEAD . : MDC --rfc2440 . --disable-signer-uid . local-user sender . --auto-key-retrieve . --include-key-block --no-include-key-block . . . OpenPGP --include-certs gpgsm . --no-include-key-block . --auto-key-import . --personal-cipher-preferences string string . gpg --version none . GPG . --symmetric . --personal-digest-preferences string string . gpg --version none . GPG . ( --clear-sign --sign) . --personal-compress-preferences string string . gpg --version none . GPG . ( --symmetric) . --s2k-cipher-algo name name --personal-cipher-preferences --cipher-algo . AES-128 . --s2k-digest-algo name name . SHA-1 . --s2k-mode n . n 0 ( ) 1 ( ) 3 () ( --s2k-count ). --s2k-count n . 1024 65011712 ( ) . gpg-agent . 1024-65011712 GnuPG . --s2k-mode 3 . (Compliance options) GnuPG . . . . INTEROPERABILITY WITH OTHER OPENPGP PROGRAMS . --gnupg GnuPG. LibrePGP OpenPGP . --openpgp OpenPGP ( RFC-9580). RFC-9580 GnuPG . gpg.conf . --rfc4880 RFC-4880. RFC-4880 OpenPGP . --allow-old-cipher-algos . --rfc4880bis --gnupg . --rfc2440 RFC-2440. RFC-2440 OpenPGP . MDC . . --allow-old-cipher-algos . --ignore-mdc-error . --pgp6 --pgp7 . --pgp7 PGP 7. IDEA 3DES CAST5 AES128 AES192 AES256 TWOFISH MD5 SHA1 RIPEMD160 none ZIP . --escape-from-lines --throw-keyids . --pgp8 PGP 8. PGP 8 PGP OpenPGP --throw-keyids --escape-from-lines . SHA224 SHA384 SHA512 . --compliance string . string ( ) "help" string . --min-rsa-length n "de-vs" . 3000 rsa2048 dsa2048 VS-NfD . --require-compliance gpg . . gpg . "de-vs" . -n --dry-run ( ). --list-only . --dry-run . . . -i --interactive . --compatibility-flags flags . flags OR . "none" . "help" . --debug-level level . level : none . 1 . basic . 1 2 . advanced . 3 5 . expert . 6 8 . guru . 8 . . . . --debug flags . OR flags C ( 0x0042) . "help" . . --debug-all . --debug-iolbf stdout . . --debug-set-iobuf-size n IOBUF n . 0 . : . --debug-allow-large-chunks 4 EiB (--chunk-size 62) . --debug-ignore-expiration . . --faked-system-time epoch epoch ( ) . epoch ISO ( "20070924T154812") . (!) epoch () . --full-timestrings . --with-colons . . --enable-progress-filter PROGRESS . gpg . . --status-fd n n . DETAILS . --status-file file --status-fd file . --logger-fd n () n STDERR. --log-file file --logger-file file --logger-fd file . `socket://' . --log-time . --attribute-fd n n . --status-fd . --attribute-file file --attribute-fd file . --comment string --no-comments string ( --armor ). . --comment . --no-comments . . . --emit-version --no-emit-version . . --no-emit-version () . --sig-notation {name=value} --cert-notation {name=value} -N, --set-notation {name=value} (name=value) (notation data) . name '@' keyname@domain.example.com ( ). IETF . --expert '@' . value UTF-8 --display-charset . name (!) (critical) (rfc4880:5.2.3.16). --sig-notation . --cert-notation ( certifications) . --set-notation . . "%k" (key ID) "%K" "%f" "%s" "%S" "%g" ( ) "%p" "%c" OpenPGP "%%" "%" . %k %K %f () %c OpenPGP . --known-notation name name . gpg (bad) . gpg . --sig-policy-url string --cert-policy-url string --set-policy-url string string (Policy URL) (rfc4880:5.2.3.20). (!) . --sig-policy-url . --cert-policy-url () . --set-policy-url . % . --sig-keyserver-url string string . (!) . % . --set-filename string string . . string . --for-your-eyes-only --no-for-your-eyes-only `for your eyes only' . GnuPG --output PGP " " Tempest . --set-filename . --no-for-your-eyes-only . --use-embedded-filename --no-use-embedded-filename . . no . --output . . --status-fd gpg PLAINTEXT . gpgtar gpgtar . . --cipher-algo name name . --version . . OpenPGP . --personal-cipher-preferences . --digest-algo name name . --version . OpenPGP . --personal-digest-preferences . --compress-algo name name . "zlib" RFC-1950 ZLIB . "zip" RFC-1951 ZIP PGP . "bzip2" zip zlib . "uncompressed" "none" . . ZIP . ZLIB ZIP 8k . BZIP2 . . PGP ( ) ZIP . ZIP "none" PGP . OpenPGP . --personal-compress-preferences . --cert-digest-algo name name . --version . GnuPG OpenPGP . . --disable-cipher-algo name name . . --disable-pubkey-algo name name . . --throw-keyids --no-throw-keyids . . ([ .]) . --no-throw-keyids . --hidden-recipient . --not-dash-escaped (cleartext signatures) (patch) . . . GnuPG . --escape-from-lines --no-escape-from-lines "From " ">From " (cleartext) . PGP . . --no-escape-from-lines . --passphrase-repeat n gpg . . 0 . n pinentry pinentry n+1 . --passphrase-fd n (file descriptor) n . n . 0 n STDIN . . 2.0 --batch . 2.1 --pinentry-mode loopback . --passphrase-file file file . file . . . . 2.0 --batch . 2.1 --pinentry-mode loopback . --passphrase string string . . . . 2.0 --batch . 2.1 --pinentry-mode loopback . --pinentry-mode mode pinentry mode . mode : default agent ask . ask Pinentry. cancel (cancel) Pinentry. error Pinentry (``No Pinentry''). loopback Pinentry . Pinentry . --no-symkey-cache (cache) . salt (.. --s2k-mode). --request-origin origin gpg origin . Pinentry . origin : local remote browser . --command-fd n IPC . TTY . --status-fd . doc/DETAILS . --command-file file --command-fd file . --allow-non-selfsigned-uid --no-allow-non-selfsigned-uid - . - . --no-allow-non-selfsigned-uid . --allow-freeform-uid . (de-facto) . --ignore-time-conflict GnuPG . . . --ignore-valid-from . --ignore-valid-from GnuPG . 1.0.7 . . --ignore-time-conflict . --ignore-crc-error ASCII armor OpenPGP CRC . CRC ( OpenPGP ) . GnuPG CRC . --ignore-mdc-error MDC . MDC . . MDC . --rfc2440 . --allow-old-cipher-algos 3DES IDEA CAST5 . 150 MiByte . gpg . (compliance modes) . --allow-weak-digest-algos ``invalid digest algorithm'' . . MD5 . --weak-digest . --weak-digest name . . . --allow-weak-digest-algos . MD5 . --allow-weak-key-signatures (collision attacks) SHA-1 . . --override-compliance-check . --no-default-keyring . GnuPG . --keyring GnuPG . use-keyboxd `common.conf' keyboxd . --no-keyring . . --skip-verify . . --with-key-data ( --with-colons) . --list-signatures --list-sigs --list-keys . --list-keys --with-sig-list . --check-signatures . : gpg --list-sigs --with-colons USERID | \ awk -F: '$1=="sig" && $2=="?" {if($13){print $13}else{print $5}}' --fast-list-mode . . . . . --no-literal . . --set-filesize . . --show-session-key . --override-session-key . (Key Escrow) . . --override-session-key string --override-session-key-fd fd string fd . --show-session-key . . --override-session-key . --no-keyring . --ask-sig-expire --no-ask-sig-expire . --default-sig-expire . --no-ask-sig-expire . --default-sig-expire . "0" d ( ) w ( ) m ( ) y ( ) ( "2m" "5y" ) YYYY-MM-DD. "0" . --ask-cert-expire --no-ask-cert-expire . --default-cert-expire . --no-ask-cert-expire . --default-cert-expire . "0" d ( ) w ( ) m ( ) y ( ) ( "2m" "5y" ) YYYY-MM-DD. "0" . --default-new-key-algo string . string --quick-add-key . . . (compliance mode) . --no-auto-trust-new-key ownertrust ( ) ultimate . ownertrust . --force-sign-key --quick-sign-key --quick-lsign-key "sign" --edit-key . --forbid-gen-key . Not Enabled . --allow-secret-key-import . --allow-multiple-messages --no-allow-multiple-messages GnuPG 2.2.8 . --enable-special-filenames `-&n' n n . --no-expensive-trust-checks . --preserve-permissions (secret keyring) / . . --default-preference-list string string . "setpref" --edit-key . --default-keyserver-url name URL name . URL . --list-config GnuPG . GnuPG . `doc/DETAILS' . --list-config --with-colons . --list-gcrypt-config Libgcrypt . --gpgconf-list --list-config gpgconf . --gpgconf-test . gpg . . --chuid uid uid . root gpg . uid UID PATH GNUPGHOME . --homedir . . Windows . (Deprecated options) -t, --textmode --no-textmode OpenPGP "CRLF" . . ( UNIX-like Mac Mac Windows ) . --no-textmode . . --force-v3-sigs --no-force-v3-sigs --force-v4-certs --no-force-v4-certs GnuPG 2.1 . --show-photos --no-show-photos --list-keys --list-signatures --list-public-keys --list-secret-keys (photo ID) . --photo-viewer . . --list-options [no-]show-photos / --verify-options [no-]show-photos . --show-keyring (keyring) . : --list-options [no-]show-keyring . --show-notation --no-show-notation --list-signatures --check-signatures . . --list-options [no-]show-notation / --verify-options [no-]show-notation . --show-policy-url --no-show-policy-url URL --list-signatures --check-signatures URL . . --list-options [no-]show-policy-url / --verify-options [no-]show-policy-url . --personal-aead-preferences string 2.3.9 . --aead-algo name 2.3.9 . (EXAMPLES) gpg -se -r Bob file Bob gpg --clear-sign file gpg -sb file gpg -u 0x12345678 -sb file 0x12345678 gpg --list-keys user_ID gpg --fingerprint user_ID gpg --verify pgpfile gpg --verify sigfile [datafile] . sigfile ( ASCII ) datafile (".asc" ".sig") sigfile . --output stdout - . (HOW TO SPECIFY A USER ID) GnuPG . gpg gpgsm . : (By key Id). 0x . X.509 SHA-1 . . gpg (!) . OpenPGP . --with-colons . 234567C4 0F34E556E 01347A56A 0xAB123456 234AABBCC34567C4 0F323456784E56EAB 01AB3FED1347A5612 0x234AABBCC34567C4 . 0x . gpgsm ( SHA-1 ). gpg (!) . . . 1234343434343434C434343434343434 123434343434343C3434343434343734349A3434 0E12343434343434343434EAB3484343434343434 0xE12343434343434343434EAB3484343434343434 gpgsm X.509 . gpg SHA-1 . OpenPGP. . X.509 . =Heinrich Heine . . . @ . ( ). @heinrichh DN (Subject). DN RFC-2253 . gpgsm --list-keys --with-colons RFC-2253 ( ) . /CN=Heinrich Heine,O=Poets,L=Paris,C=FR DN (Issuer). (#) DN RFC-2253 . (Root cert) . . #/CN=Root Cert,O=Poets,L=Paris,C=FR DN . DN RFC-2253 . . #4F03/CN=Root Cert,O=Poets,L=Paris,C=FR keygrip. keygrip . gpgsm --dump-cert keygrip . &D75F22C3F86E355877348498CDC92BD21010A480 . . . Heine *Heine . + . . GnuPG local-id . X.509 . RFC-2253 DN . (FILTER EXPRESSIONS) --import-filter --export-filter ( ): [lc] {[{flag}] PROPNAME op VALUE [lc]} (PROPNAME) . . . (VALUE) . () && || . -- . long int C . lc && || . . . VALUE op op . (op) : =~ . !~ . = . <> . == . != . <= (LE) . < (LT) . > (GT) . >= (GE) . -le . -lt . -gt . -ge . -n ( ). -t "PROPNAME != 0" ( ). -f "PROPNAME == 0" ( ). flag . : -- VALUE . -c . -t VALUE . op . . : --import-filter keep-uid="uid =~ Alfa" --import-filter keep-uid="&& uid !~ Test" --import-filter keep-uid="|| uid =~ Alpha" --import-filter keep-uid="uid !~ Test" : --import-filter \ keep-uid="uid =~ Alfa" && uid !~ Test" || uid =~ Alpha" && "uid !~ Test" "Alfa" "Alpha" "test" . (TRUST VALUES) . : - unknown / . e expired . q undefined, undef . n never . m marginal (). f full . u ultimate (). r revoked : . ? err . (FILES) gpg . (: [option --homedir]). gpg.conf gpg . . (: [gpg-option --options]). . common.conf gpg . GnuPG . "use-keyboxd" . `~/.gnupg' GnuPG `common.conf' "use-keyboxd" . `/etc/skel/.gnupg' . (: [addgnupghome]). gpg (: [option --homedir]). gpg . ~/.gnupg GNUPGHOME --homedir . ~/.gnupg/pubring.gpg . . gpg keybox `pubring.kbx' OpenPGP . `pubring.gpg' `pubring.kbx' OpenPGP `pubring.gpg' . : GnuPG 2.1 `pubring.gpg' keybox . GnuPG 1.4 . ~/.gnupg/pubring.gpg.lock . ~/.gnupg/pubring.kbx keybox. gpgsm . . . `pubring.gpg' keybox ownertrust `pubring.gpg' `publickeys.backup' GnuPG import ownertrust : $ cd ~/.gnupg $ gpg --export-ownertrust >otrust.lst $ mv pubring.gpg publickeys.backup $ gpg --import-options restore --import publickeys.backup $ gpg --import-ownertrust otrust.lst ~/.gnupg/pubring.kbx.lock `pubring.kbx'. ~/.gnupg/secring.gpg 2.1 GnuPG . GnuPG 2.1 . GnuPG 1.4 . ~/.gnupg/secring.gpg.lock . ~/.gnupg/.gpg-v21-migrated GnuPG 2.1 . ~/.gnupg/trustdb.gpg . ownertrust (: [ --export-ownertrust]). ~/.gnupg/trustdb.gpg.lock . ~/.gnupg/random_seed . ~/.gnupg/openpgp-revocs.d/ gpg . OpenPGP . . . . . : HOME . GNUPGHOME "~/.gnupg" . GPG_AGENT_INFO GnuPG 2.1 . PINENTRY_USER_DATA gpg-agent pinentry . pinentry . COLUMNS LINES . LANGUAGE GNU W32 Registry . (langid) gpgdir/gnupg.nls/langid.mo . gpgdir gpg . Registry (locale) Windows . GNUPG_BUILD_ROOT . GNUPG_EXEC_DEBUG_FLAGS . . Windows . gpg-agent gpg gpg-agent . : gpg-connect-agent 'getinfo std_env_names' /bye | awk '$1=="D" {print $2}' (NOTES) gpg (backend) . . --status-fd --batch . GnuPG gpg GPGME . GPGME . OpenPGP S/MIME GnuPG . GPGME C-API C++ Qt Python . . (keyring) . GnuPG . GnuPG . . GnuPG . ( ) gpg GNUPGHOME --homedir . GPGME (per-context) . . . GnuPG . key_algo . (drop-subkey) key_size . (drop-subkey) key_created key_created_d . ISO "2016-08-17" . (drop-subkey) key_expires key_expires_d 0 . ISO "2038-01-19" . fpr . (drop-subkey) primary . (keep- uid) expired (keep-uid) (drop- subkey) (drop-sig) . revoked (keep-uid) (drop- subkey) . disabled . secret . (drop-subkey) : Key-Type: algo . . . algo OpenPGP . `default' algo `Key-Usage' `Subkey-Type' `default' . Key-Length: nbits . `gpg --gpgconf-list' . ECC . Key-Curve: curve . ECC ECC . Key-Grip: hexstring CSR . Key- Length . Key-Usage: usage-list . `encrypt' `sign' `auth'. . . OpenPGP `cert' . `Key-Usage' `Key-Type' `default' `default' `sign' . Subkey-Type: algo () . . `Key-Type' . Subkey-Length: nbits () . `gpg --gpgconf-list' . Subkey-Curve: curve `Key-Curve'. Subkey-Usage: usage-list `Key-Usage'. Passphrase: string . Pinentry . Name-Real: name Name-Comment: comment Name-Email: email . UTF-8 . (user ID) . Expire-Date: iso-date|(number[d|w|m|y]) ( ) . ISO ( "20000815T145012") . "seconds=N" . . OpenPGP . . OpenPGP GnuPG 2105 . Creation-Date: iso-date . "1986-04-26" "19860426T042640" . UTC . "seconds=N" (Epoch / ) . . Preferences: string . `setpref' --edit-key . Revoker: algo:fpr [sensitive] . Algo ( RSA=1 DSA=17 ). fpr . fpr . `sensitive' . v4 v5 . Keyserver: string URL . Handle: string KEY_CREATED KEY_NOT_CREATED . string . . : $ export GNUPGHOME="$(mktemp -d)" $ cat >foo < ssb elg1024 2016-12-16 [E] : %echo Generating a default key Key-Type: default Subkey-Type: default Name-Real: Joe Tester Name-Comment: with stupid passphrase Name-Email: joe@foo.bar Expire-Date: 0 Passphrase: abc # Do a commit here, so that we can later print "done" :-) %commit %echo done (BUGS) setuid(root) . . ( ) . root . root . ( ) ``suspend to disk'' ( ``safe sleep'' ``hibernate'' ) . . . https://bugs.gnupg.org . (SEE ALSO) gpgv(1), gpgsm(1), gpg-agent(1) Texinfo . GnuPG info info gnupg . GnuPG 2.4.9 2025-02-19 GPG(1)