<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[support for GnuPG smartcard]]></title><description><![CDATA[<p dir="auto">I'm using on my FreeBSD netbooks and laptops the USB GnuPG smartcard which helds the sec and pub keys to encrypt, decrypt files or the sec key for SSH. Access to the sec keys are protected by a 6 digit PIN, one must it enter only once as long the USB token remains attached. The software stack is a pcsd daemon controling the hardware token, a smartcard daemon having the unlocked key and the gnupg daemon allowing access for gnupg frontend commands or ssh. With a user level cmd 'pass' one can build a tree of login/password files which are stored encrypted in ~/.password/web/www.ubports.com.gpg (as an example here) and with a firefox plugin you just click an icon in FF which decrypts the file, asking for the PIN on 1st usage after attaching the token, and fills in the secrets in the fields in the webpage. Or one uses the 'pass' command to get the secrets on stdout or the clipboard. All very handy and secure, two factor security: hardware token + PIN, and if you enter 3 times a wrong PIN, the hardware is locked, one need a 8 digit master PIN to reset, and having the latter entered 3x wrong, all is gone for ever.</p>
<p dir="auto">Can we get the above pieces to work in UT, at least up to the 'pass' cmd? I could put a detailed tutorial on my web site.</p>
<p dir="auto">matthias</p>
]]></description><link>https://forums.ubports.com/topic/554/support-for-gnupg-smartcard</link><generator>RSS for Node</generator><lastBuildDate>Sat, 16 May 2026 17:53:16 GMT</lastBuildDate><atom:link href="https://forums.ubports.com/topic/554.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 17 Sep 2017 09:01:18 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to support for GnuPG smartcard on Thu, 05 Oct 2017 19:29:39 GMT]]></title><description><![CDATA[<p dir="auto">Here are some pictures and a better readable write-up:</p>
<p dir="auto"><a href="https://gnupg.org/blog/20171005-gnupg-ccid-card-daemon-UbuntuPhone.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://gnupg.org/blog/20171005-gnupg-ccid-card-daemon-UbuntuPhone.html</a></p>
<p dir="auto">HIH</p>
<p dir="auto">matthias</p>
]]></description><link>https://forums.ubports.com/post/4709</link><guid isPermaLink="true">https://forums.ubports.com/post/4709</guid><dc:creator><![CDATA[guru]]></dc:creator><pubDate>Thu, 05 Oct 2017 19:29:39 GMT</pubDate></item><item><title><![CDATA[Reply to support for GnuPG smartcard on Sun, 24 Sep 2017 09:36:31 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guru" aria-label="Profile: guru">@<bdi>guru</bdi></a> Good, good. Thanks!</p>
]]></description><link>https://forums.ubports.com/post/4366</link><guid isPermaLink="true">https://forums.ubports.com/post/4366</guid><dc:creator><![CDATA[hans1977se]]></dc:creator><pubDate>Sun, 24 Sep 2017 09:36:31 GMT</pubDate></item><item><title><![CDATA[Reply to support for GnuPG smartcard on Sun, 24 Sep 2017 09:14:37 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/hans1977se" aria-label="Profile: hans1977se">@<bdi>hans1977se</bdi></a> said in <a href="/post/4333">support for GnuPG smartcard</a>:</p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guru" aria-label="Profile: guru">@<bdi>guru</bdi></a> said in <a href="/post/4154">support for GnuPG smartcard</a>:</p>
<blockquote>
<p dir="auto">I could put a detailed tutorial on my web site.</p>
</blockquote>
<p dir="auto">I think your project to set this up on the phone seem very nice and useful. <img src="https://forums.ubports.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=bc7965752a7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> I think the tutorial, if you put it up, will be very helpful.</p>
<p dir="auto">Where did you buy the device from? Did you find any nice and slim solution for the connector to fit?</p>
</blockquote>
<p dir="auto">I will publish something in the blog of <a href="http://gnupg.org" target="_blank" rel="noopener noreferrer nofollow ugc">gnupg.org</a> and/or in my gitbook about the UbuntuPhone.</p>
<p dir="auto">Re/ your questions:</p>
<p dir="auto">The card (USB token and SIM) is from:</p>
<p dir="auto"><a href="https://www.floss-shop.de/en/hardware/" target="_blank" rel="noopener noreferrer nofollow ugc">https://www.floss-shop.de/en/hardware/</a></p>
<p dir="auto">One needs the following items:</p>
<p dir="auto">OpenPGP Smart Card V2.1 mit ID000 Ausfräsung  (Art. Number 654020)<br />
uTrust Token Standard black  (Art. number 655010)</p>
<p dir="auto">A photo of the BQ E4.5 with the token attached is here: is here:</p>
<p dir="auto"><a href="http://www.unixarea.de/UbuntuPhone-GnuPG-card.jpg" target="_blank" rel="noopener noreferrer nofollow ugc">http://www.unixarea.de/UbuntuPhone-GnuPG-card.jpg</a></p>
<p dir="auto">For the connection between the USB token and the phone, I used some OTG<br />
(USB On-The-Go) cable. I own as well a small connector receiving on one<br />
end the token and to be plugged in into the phones port, but this<br />
connection is very unstable, with the cable it's fine.</p>
<p dir="auto">matthias</p>
]]></description><link>https://forums.ubports.com/post/4364</link><guid isPermaLink="true">https://forums.ubports.com/post/4364</guid><dc:creator><![CDATA[guru]]></dc:creator><pubDate>Sun, 24 Sep 2017 09:14:37 GMT</pubDate></item><item><title><![CDATA[Reply to support for GnuPG smartcard on Sat, 23 Sep 2017 08:57:28 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/guru" aria-label="Profile: guru">@<bdi>guru</bdi></a> said in <a href="/post/4154">support for GnuPG smartcard</a>:</p>
<blockquote>
<p dir="auto">I could put a detailed tutorial on my web site.</p>
</blockquote>
<p dir="auto">I think your project to set this up on the phone seem very nice and useful. <img src="https://forums.ubports.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=bc7965752a7" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /> I think the tutorial, if you put it up, will be very helpful.</p>
<p dir="auto">Where did you buy the device from? Did you find any nice and slim solution for the connector to fit?</p>
]]></description><link>https://forums.ubports.com/post/4333</link><guid isPermaLink="true">https://forums.ubports.com/post/4333</guid><dc:creator><![CDATA[hans1977se]]></dc:creator><pubDate>Sat, 23 Sep 2017 08:57:28 GMT</pubDate></item><item><title><![CDATA[Reply to support for GnuPG smartcard on Sat, 23 Sep 2017 08:21:28 GMT]]></title><description><![CDATA[<p dir="auto">follow up: I have the GnuPG-card running with my BQ E4.5:</p>
<p dir="auto">We start in the phone the pcscd daemon as:</p>
<p dir="auto">$ sudo /home/phablet/myRoot/usr/local/sbin/pcscd<br />
$ ps ax | grep pcscd<br />
31669 pts/53   Sl     0:00 /home/phablet/myRoot/usr/local/sbin/pcscd</p>
<p dir="auto">insert the GnuPG-card into the USB port of the BQ E4.5 and do:</p>
<p dir="auto">$ ./gpg.sh --card-status<br />
gpg-agent[20254]: enabled debug flags: mpi crypto memory cache memstat hashing ipc<br />
gpg-agent: a gpg-agent is already running - not starting a new one<br />
gpg-agent: random usage: poolsize=600 mixed=0 polls=0/0 added=0/0<br />
outmix=0 getlvl1=0/0 getlvl2=0/0<br />
gpg-agent: secmem usage: 0/32768 bytes in 0 blocks<br />
Reader ...........: Identiv uTrust 3512 SAM slot Token [CCID Interface] (55511514602745) 00 00<br />
Application ID ...: D27600012401020100050000532B0000<br />
Version ..........: 2.1<br />
Manufacturer .....: ZeitControl<br />
Serial number ....: 0000532B<br />
Name of cardholder: Matthias Apitz<br />
Language prefs ...: en<br />
Sex ..............: unspecified<br />
URL of public key : <a href="http://www.unixarea.de/ccid--export-key-guru.pub" target="_blank" rel="noopener noreferrer nofollow ugc">http://www.unixarea.de/ccid--export-key-guru.pub</a><br />
Login data .......: [not set]<br />
Signature PIN ....: not forced<br />
Key attributes ...: rsa4096 rsa4096 rsa4096<br />
Max. PIN lengths .: 32 32 32<br />
PIN retry counter : 3 0 3<br />
Signature counter : 457<br />
Signature key ....: 5E69 FBAC 1618 562C B3CB  FBC1 47CC F7E4 76FE 9D11<br />
created ....: 2017-05-14 18:20:07<br />
Encryption key....: EB62 00DA 13A1 9E80 679B  1A13 61F1 ECB6 25C9 A6C3<br />
created ....: 2017-05-14 18:20:07<br />
Authentication key: E51D D2D6 C727 35D6 651D  EA4B 6AA5 C5C4 51A1 CD1C<br />
created ....: 2017-05-14 18:20:07<br />
General key info..: [none]</p>
<p dir="auto">Now I removed ~/.gnupg (saving the *.conf files) and copied over from my<br />
real netbook the ~/.password-store and the key material in ~/.gnupg<br />
for the GnuPG-card;</p>
<p dir="auto">$ ./pass.sh <a href="http://askubuntu.com/guru@unixarea.de" target="_blank" rel="noopener noreferrer nofollow ugc">askubuntu.com/guru@unixarea.de</a></p>
<pre><code>                      ┌─────────────────────────────────────────────┐
                      │ Please insert the card with serial number:  │
                      │                                             │
                      │ 0005 0000532B                               │
                      │                                             │
                      │      &lt;OK&gt;                       &lt;Cancel&gt;    │
                      └─────────────────────────────────────────────┘
</code></pre>
<p dir="auto">I inserted the card and it asks for the PIN:</p>
<pre><code>                      ┌──────────────────────────────────────────────┐
                      │ Please unlock the card                       │
                      │                                              │
                      │ Number: 0005 0000532B                        │
                      │ Holder: Matthias Apitz                       │
                      │                                              │
                      │ PIN ________________________________________ │
                      │                                              │
                      │      &lt;OK&gt;                        &lt;Cancel&gt;    │
                      └──────────────────────────────────────────────┘
</code></pre>
<p dir="auto">XXXXXXXX-XXXXXX<br />
$</p>
<p dir="auto">on the 2nd run it does not need anymore the PIN:</p>
<p dir="auto">$ ./pass.sh <a href="http://askubuntu.com/guru@unixarea.de" target="_blank" rel="noopener noreferrer nofollow ugc">askubuntu.com/guru@unixarea.de</a><br />
XXXXXXXX-XXXXXX</p>
]]></description><link>https://forums.ubports.com/post/4330</link><guid isPermaLink="true">https://forums.ubports.com/post/4330</guid><dc:creator><![CDATA[guru]]></dc:creator><pubDate>Sat, 23 Sep 2017 08:21:28 GMT</pubDate></item><item><title><![CDATA[Reply to support for GnuPG smartcard on Wed, 20 Sep 2017 07:58:23 GMT]]></title><description><![CDATA[<p dir="auto">I have in my BQ E4.5 an additional complete Linux system in a chrooted environment. The installation details are described here: <a href="https://gurucubano.gitbooks.io/bq-aquaris-e-4-5-ubuntu-phone/content/en/chapter27.html" target="_blank" rel="noopener noreferrer nofollow ugc">https://gurucubano.gitbooks.io/bq-aquaris-e-4-5-ubuntu-phone/content/en/chapter27.html</a> and is relatively simple to setup.</p>
<p dir="auto">I think, it is worth to bring the GnuPG-card and the needed software-stack running at least in such a chrooted environment. At least the installtion of the software worked out of the box:</p>
<p dir="auto">phablet@ubuntu-phablet-bq:~$<br />
phablet@ubuntu-phablet-bq:~$ sudo chroot myRoot/<br />
...<br />
root@ubuntu-phablet:/# apt-get install gnupg2<br />
root@ubuntu-phablet:/# apt-get install opensc<br />
...<br />
Unpacking opensc (0.14.0-1ubuntu1) ...<br />
Processing triggers for systemd (219-7ubuntu6) ...<br />
Processing triggers for ureadahead (0.100.0-19) ...<br />
Setting up opensc-pkcs11:armhf (0.14.0-1ubuntu1) ...<br />
Setting up libccid (1.4.18-1) ...<br />
Setting up pcscd (1.8.11-3ubuntu1) ...<br />
Error, do this: mount -t proc proc /proc<br />
invoke-rc.d: -----------------------------------------------------<br />
invoke-rc.d: WARNING: 'invoke-rc.d pcscd start' called<br />
invoke-rc.d: during shutdown sequence.<br />
invoke-rc.d: enabling safe mode: initscript policy layer disabled<br />
invoke-rc.d: -----------------------------------------------------<br />
Setting up opensc (0.14.0-1ubuntu1) ...<br />
Processing triggers for libc-bin (2.21-0ubuntu4) ...<br />
Processing triggers for systemd (219-7ubuntu6) ...<br />
Processing triggers for ureadahead (0.100.0-19) ...</p>
<p dir="auto">root@ubuntu-phablet:/# su - phablet<br />
phablet@ubuntu-phablet:~$ gpg2 --version<br />
gpg (GnuPG) 2.0.26<br />
libgcrypt 1.6.2<br />
Copyright (C) 2013 Free Software Foundation, Inc.<br />
License GPLv3+: GNU GPL version 3 or later <a href="http://gnu.org/licenses/gpl.html" target="_blank" rel="noopener noreferrer nofollow ugc">http://gnu.org/licenses/gpl.html</a><br />
This is free software: you are free to change and redistribute it.<br />
There is NO WARRANTY, to the extent permitted by law.</p>
<p dir="auto">Home: ~/.gnupg<br />
Supported algorithms:<br />
...</p>
<p dir="auto">root@ubuntu-phablet:/# mount -t proc proc /proc<br />
root@ubuntu-phablet:/# ps ax | grep pcscd<br />
16467 ?        Sl     0:00 /usr/sbin/pcscd</p>
<p dir="auto">root@ubuntu-phablet:/# /usr/sbin/pcscd --debug --foreground<br />
00000000 pcscdaemon.c:266:main() pcscd set to foreground with debug send to stdout<br />
00001967 configfile.l:286:DBGetReaderListDir() Parsing conf directory: /etc/reader.conf.d<br />
00000915 configfile.l:298:DBGetReaderListDir() Skipping non regular file: .<br />
00001002 configfile.l:298:DBGetReaderListDir() Skipping non regular file: ..<br />
00000977 configfile.l:339:DBGetReaderList() Parsing conf file: /etc/reader.conf.d/libccidtwin<br />
00001459 pcscdaemon.c:571:main() pcsc-lite 1.8.11 daemon ready.</p>
<p dir="auto">So far so good. Now I would have to attach the USB GnuPG-card to the USB-port of the BQ E4.5. This requires some kind of a gender changer to attach the USB stick (the GnuPG-card) to the USB charger cable of the phone or some other hardware to attach the USB stick directly to the BQ E4.5 device.</p>
<p dir="auto">Any hints on this?</p>
]]></description><link>https://forums.ubports.com/post/4249</link><guid isPermaLink="true">https://forums.ubports.com/post/4249</guid><dc:creator><![CDATA[guru]]></dc:creator><pubDate>Wed, 20 Sep 2017 07:58:23 GMT</pubDate></item></channel></rss>