Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 617706 - app-crypt/gnupg-2.1.20: gpg-agent, OpenPGP subkey does not unlock SSH subkeys (but works the other way around)
Summary: app-crypt/gnupg-2.1.20: gpg-agent, OpenPGP subkey does not unlock SSH subkeys...
Status: RESOLVED UPSTREAM
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Kristian Fiskerstrand (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2017-05-07 09:16 UTC by Michał Górny
Modified: 2017-05-13 19:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2017-05-07 09:16:07 UTC
As discussed some time ago, I'm now using GnuPG w/ gpg-agent both for SSH and OpenPGP tasks. All encryption, signing and auth subkeys are part of the same key. Now, presuming that no keys are unlocked:

a. if I connect to SSH first, pinentry asks me for SSH password and afterwards the key is unlocked both for SSH and OpenPGP uses. For example, if I try to decrypt a file, it will be decrypted without another password query.

b. If I do something OpenPGP first, pinentry asks me for the key password but seems to only unlock the key for OpenPGP purposes. For example, if I try to decrypt a file first, then connect via SSH, then I get a second pinentry dialog asking me for the SSH key password.
Comment 1 Kristian Fiskerstrand (RETIRED) gentoo-dev 2017-05-13 19:51:48 UTC
This issue should be brought up on the gnupg-devel ML or in https://dev.gnupg.org , its not a downstream issue and given its benign nature I don't have sufficient time to provide debugging support.