Spilt-GPG help - 3.2

48 views
Skip to first unread message

vel...@tutamail.com

unread,
Mar 25, 2018, 7:58:42 PM3/25/18
to qubes-users
I love Qubes! Kudus to those developing and helping on this forum...I am sure others would agree that the effort is greatly appreciated.

I am hoping I can get some help with "split-GPG" setup and signing emails. Some notes and questions about my configuration:

* I plan to use Thunderbird.

* I have since created a new vault from default during installation - I have some files in this vault, documents, some passwords...I consider this non-networked VM my "vault", although I am just getting into certificates for email signing and email encryption.
- Should I use this VM for my certificates(or a dedicated certificate VM) or is it a big no?

* I found a good tutorial on creating certificates using GnuPG with QubesOS: https://apapadop.wordpress.com/2013/08/21/using-gnupg-with-qubesos/
( a little dated but did create test certificates...thanks Apapadop!)

* I followed the steps in this Qubes-OS wiki: https://www.qubes-os.org/doc/split-gpg/ , however I get lost here:

Setting up the GPG backend domain

Make sure the gpg is installed there and there are some private keys in the keyring, e.g.:

[user@work-gpg ~]$ gpg -K
/home/user/.gnupg/secring.gpg
-----------------------------
sec 4096R/3F48CB21 2012-11-15
uid Qubes OS Security Team <secu...@qubes-os.org>
ssb 4096R/30498E2A 2012-11-15
(...)

How do I create this file: /home/user/.gnupg/secring.gpg ?
Where do I keep my certificates in the "vault"? What commands or folders do I need to create?

I tried finding more basic instructions but my "Googling" had no luck...how do I put private keys in my "vault" keyring and use Thunderbird in a seperate, dedicated VM to sign and encrypt my emails utilizing split GPG?

Excuse me if this has already been answered or clarified in another post I couldn't find.

Greatfully,
V

sevas

unread,
Mar 25, 2018, 11:31:33 PM3/25/18
to qubes-users
I recommend a dedicated vm(not your vault). I also recommend installing kgpg. Thats all I have.

Chris Laprise

unread,
Mar 26, 2018, 1:27:09 AM3/26/18
to vel...@tutamail.com, qubes-users
On 03/25/2018 07:58 PM, vel...@tutamail.com wrote:
> I love Qubes! Kudus to those developing and helping on this forum...I am sure others would agree that the effort is greatly appreciated.
>
> I am hoping I can get some help with "split-GPG" setup and signing emails. Some notes and questions about my configuration:
>
> * I plan to use Thunderbird.
>
> * I have since created a new vault from default during installation - I have some files in this vault, documents, some passwords...I consider this non-networked VM my "vault", although I am just getting into certificates for email signing and email encryption.
> - Should I use this VM for my certificates(or a dedicated certificate VM) or is it a big no?

Should be no problem with using vault for both gpg keys and passwords
(keepassx) and even small lists that you create in that vm. The only
files you should import from other vms into vault are gpg keys.

>
> * I found a good tutorial on creating certificates using GnuPG with QubesOS: https://apapadop.wordpress.com/2013/08/21/using-gnupg-with-qubesos/
> ( a little dated but did create test certificates...thanks Apapadop!)
>
> * I followed the steps in this Qubes-OS wiki: https://www.qubes-os.org/doc/split-gpg/ , however I get lost here:
>
> Setting up the GPG backend domain
>
> Make sure the gpg is installed there and there are some private keys in the keyring, e.g.:
>
> [user@work-gpg ~]$ gpg -K
> /home/user/.gnupg/secring.gpg
> -----------------------------
> sec 4096R/3F48CB21 2012-11-15
> uid Qubes OS Security Team <secu...@qubes-os.org>
> ssb 4096R/30498E2A 2012-11-15
> (...)
>
> How do I create this file: /home/user/.gnupg/secring.gpg ?
> Where do I keep my certificates in the "vault"? What commands or folders do I need to create?

The gpg -K command is just a way to look at your keyring. The keyring is
created automatically whenever you generate new keys or import existing
ones.


>
> I tried finding more basic instructions but my "Googling" had no luck...how do I put private keys in my "vault" keyring and use Thunderbird in a seperate, dedicated VM to sign and encrypt my emails utilizing split GPG?
>
> Excuse me if this has already been answered or clarified in another post I couldn't find.
>
> Greatfully,
> V
>


--

Chris Laprise, tas...@posteo.net
https://github.com/tasket
https://twitter.com/ttaskett
PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886

vel...@tutamail.com

unread,
Mar 27, 2018, 9:34:38 AM3/27/18
to qubes-users
I am not sure if the "Split-GPG" is for email signing and encryption only but I am being prompted to enter a password for a VM that I use for email. Is this expected? I like the idea of a password to access this VM but is there a better way to secure this?
Reply all
Reply to author
Forward
0 new messages