Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #174186 > unrolled thread

upgraded testing and now gpg is not working

Started by"H.S." <hs.samix@gmail.com>
First post2016-11-05 04:00 +0100
Last post2016-11-07 00:10 +0100
Articles 9 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  upgraded testing and now gpg is not working "H.S." <hs.samix@gmail.com> - 2016-11-05 04:00 +0100
    Re: upgraded testing and now gpg is not working Frank <zuiderduin@gmx.com> - 2016-11-05 08:00 +0100
      Re: upgraded testing and now gpg is not working "H.S." <hs.samix@gmail.com> - 2016-11-05 21:30 +0100
        Re: upgraded testing and now gpg is not working Frank <zuiderduin@gmx.com> - 2016-11-05 23:00 +0100
          Re: upgraded testing and now gpg is not working "H.S." <hs.samix@gmail.com> - 2016-11-06 05:00 +0100
            Re: upgraded testing and now gpg is not working Frank <zuiderduin@gmx.com> - 2016-11-06 07:50 +0100
              Re: upgraded testing and now gpg is not working <tomas@tuxteam.de> - 2016-11-06 10:50 +0100
                Re: upgraded testing and now gpg is not working Jörg-Volker Peetz <jvpeetz@web.de> - 2016-11-06 13:30 +0100
                  [SOLVED] Re: upgraded testing and now gpg is not working "H.S." <hs.samix@gmail.com> - 2016-11-07 00:10 +0100

#174186 — upgraded testing and now gpg is not working

From"H.S." <hs.samix@gmail.com>
Date2016-11-05 04:00 +0100
Subjectupgraded testing and now gpg is not working
Message-ID<szZn8-1Xp-5@gated-at.bofh.it>
I upgraded my testing box last night and now my gpg decryption does not 
work anymore.

I have a file encrypted for myself which I have been using. Till 
recently I was able to decrypt it successfully for years.

After last night's upgrade, I get the following:
$> gpg -d somefile.txt.asc
gpg: encrypted with 2048-bit ELG key, ID <ID here>, created 2012-02-01
       "my name and email here"
gpg: public key decryption failed: Timeout
gpg: decryption failed: No secret key

Is something broken in the updated GPG related package in testing?

Thanks.


-- 

Please reply to this list only. I read this list on its corresponding
newsgroup on gmane.org. Replies sent to my email address are just
filtered to a folder in my mailbox and get periodically deleted without
ever having been read.

[toc] | [next] | [standalone]


#174191

FromFrank <zuiderduin@gmx.com>
Date2016-11-05 08:00 +0100
Message-ID<sA37k-4xe-1@gated-at.bofh.it>
In reply to#174186
Op 05-11-16 om 03:55 schreef H.S.:
> I upgraded my testing box last night and now my gpg decryption does not
> work anymore.

Until a couple of months ago, gpg was gpg1. It's gpg2 now and you need 
to specify gpg1 explicitely if you want to use the 'classic' version. 
You may have to install the gnupg1 package first. This provides 
/usr/bin/gpg1 and I seem to remember it didn't get pulled in 
automatically on my testing machine.

gpg2 can't find your secret keys because it stores them elsewhere. For 
gpg1 they are in the secring.gpg file and gpg2 looks at the files in the 
private-keys-v1.d directory. If this directory does not exist inside 
your gnupg directory (probably ~/.gnupg), then the automatic migration 
failed somehow.

Regards,
Frank

[toc] | [prev] | [next] | [standalone]


#174209

From"H.S." <hs.samix@gmail.com>
Date2016-11-05 21:30 +0100
Message-ID<sAfLb-47w-5@gated-at.bofh.it>
In reply to#174191
On 11/05/2016 02:53 AM, Frank wrote:
> Op 05-11-16 om 03:55 schreef H.S.:
>> I upgraded my testing box last night and now my gpg decryption does not
>> work anymore.
<SNIP>
> gpg2 can't find your secret keys because it stores them elsewhere. For
> gpg1 they are in the secring.gpg file and gpg2 looks at the files in the
> private-keys-v1.d directory. If this directory does not exist inside
> your gnupg directory (probably ~/.gnupg), then the automatic migration
> failed somehow.

Earlier reply was inadvertently sent to the user only (Frank, sorry).


Thanks for that background.

I installed gnupg1 and I can use gpg1 command to decrypt my data as 
usual (instead of using gpg as I did in the past). However, current gpg, 
which links to gpg2, still doesn't work.

I tried exporing my secret keys using gpg1 and importing them using 
gpg2, which seems to have gone fine:

$ gpg1 --export-secret-keys  | gpg2 --import
< snipped info: 2 not changed, 1 imported>
gpg: Total number processed: 3
gpg:              unchanged: 3
gpg:       secret keys read: 3
gpg:  secret keys unchanged: 3


I can list secret keys using both versions using the following command:
$ gpg1 --list-secret-keys
$ gpg --list-secret-keys

So far, so good.

Still, however, decryption my file using gpg2 does not work: it does not 
ask for my passphrase on the std in and just times out. gpg1 works though.

What am I missing?

Package I have on my testing box:
$ COLUMNS=75 dpkg -l gnupg* | grep ^i
ii  gnupg          2.1.15-4     amd64  GNU privacy guard - a free PGP re
ii  gnupg-agent    2.1.15-4     amd64  GNU privacy guard - cryptographic
ii  gnupg-l10n     2.1.15-4     all    GNU privacy guard - localization
ii  gnupg1         1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
ii  gnupg1-curl    1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
ii  gnupg2         2.1.15-4     all    GNU privacy guard - a free PGP re



-- 

Please reply to this list only. I read this list on its corresponding
newsgroup on gmane.org. Replies sent to my email address are just
filtered to a folder in my mailbox and get periodically deleted without
ever having been read.

[toc] | [prev] | [next] | [standalone]


#174214

FromFrank <zuiderduin@gmx.com>
Date2016-11-05 23:00 +0100
Message-ID<sAhah-4Ry-1@gated-at.bofh.it>
In reply to#174209
Op 05-11-16 om 21:23 schreef H.S.:
> Still, however, decryption my file using gpg2 does not work: it does not
> ask for my passphrase on the std in and just times out. gpg1 works though.
>
> What am I missing?
>
> Package I have on my testing box:
> $ COLUMNS=75 dpkg -l gnupg* | grep ^i
> ii  gnupg          2.1.15-4     amd64  GNU privacy guard - a free PGP re
> ii  gnupg-agent    2.1.15-4     amd64  GNU privacy guard - cryptographic
> ii  gnupg-l10n     2.1.15-4     all    GNU privacy guard - localization
> ii  gnupg1         1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
> ii  gnupg1-curl    1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
> ii  gnupg2         2.1.15-4     all    GNU privacy guard - a free PGP re

Nothing obviously missing there, as far as I can tell.

The passphrase input is handled by gnupg-agent, so that's what appears 
to be failing. It uses a 'pinentry' tool. On my system it usually pops 
up a small graphical window, but its dependency list suggests it can 
also use something terminal based if that isn't installed. There must be 
something wrong with that combination. I *think* it may be related to 
the second item mentioned here:

https://www.gnupg.org/documentation/manuals/gnupg-devel/Common-Problems.html

Do you have the GPG_TTY variable set up? I have mine in ~/.bashrc like this:

export GPG_TTY=$(tty)

Regards.
Frank

[toc] | [prev] | [next] | [standalone]


#174227

From"H.S." <hs.samix@gmail.com>
Date2016-11-06 05:00 +0100
Message-ID<sAmMG-c3-3@gated-at.bofh.it>
In reply to#174214
On 11/05/2016 05:50 PM, Frank wrote:
> Op 05-11-16 om 21:23 schreef H.S.:
>> Still, however, decryption my file using gpg2 does not work: it does not
>> ask for my passphrase on the std in and just times out. gpg1 works
>> though.
>>
>> What am I missing?
>>
>> Package I have on my testing box:
>> $ COLUMNS=75 dpkg -l gnupg* | grep ^i
>> ii  gnupg          2.1.15-4     amd64  GNU privacy guard - a free PGP re
>> ii  gnupg-agent    2.1.15-4     amd64  GNU privacy guard - cryptographic
>> ii  gnupg-l10n     2.1.15-4     all    GNU privacy guard - localization
>> ii  gnupg1         1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
>> ii  gnupg1-curl    1.4.21-1+b1  amd64  GNU privacy guard - a free PGP re
>> ii  gnupg2         2.1.15-4     all    GNU privacy guard - a free PGP re
>
> Nothing obviously missing there, as far as I can tell.
>
> The passphrase input is handled by gnupg-agent, so that's what appears
> to be failing. It uses a 'pinentry' tool. On my system it usually pops
> up a small graphical window, but its dependency list suggests it can
> also use something terminal based if that isn't installed. There must be
> something wrong with that combination. I *think* it may be related to
> the second item mentioned here:
>
> https://www.gnupg.org/documentation/manuals/gnupg-devel/Common-Problems.html
>
>
> Do you have the GPG_TTY variable set up? I have mine in ~/.bashrc like
> this:
>
> export GPG_TTY=$(tty)
>

That was a great hint.
I tried the following.

$ GPG_TTY=$(tty) gpg -d myfile.gpg

and it popped up a graphical window asking for my passphrase. Typed in 
the phrase, entered and it decripted the file.

So, this is good and/or bad, depending on how one looks at it. What I 
*would* prefer is that on a tty it not ask me the passphrase via a 
graphical pop up and just ask me on std in.

What happens is that when I logout from my KDE session, reboot (probably 
to 'kill' gpg agen) and then login via a *virtual tty* and try to 
decrpyt the same file using gpg, gpg errors out by complaining that 
there is no secret key (this is with the GPG_TTY exported as you 
suggested). Next, when I login to my KDE session, try the same gpg 
command from a terminal, it pops up the passphrase window, which accepts 
my passphrase and decrypt the file succesfully.

So, how do I tell gpg to work on std in when on a terminal instead of 
relying on a graphical session?

Thanks.

-- 

Please reply to this list only. I read this list on its corresponding
newsgroup on gmane.org. Replies sent to my email address are just
filtered to a folder in my mailbox and get periodically deleted without
ever having been read.

[toc] | [prev] | [next] | [standalone]


#174228

FromFrank <zuiderduin@gmx.com>
Date2016-11-06 07:50 +0100
Message-ID<sAprc-1ZO-5@gated-at.bofh.it>
In reply to#174227
Op 06-11-16 om 04:52 schreef H.S.:
> So, how do I tell gpg to work on std in when on a terminal instead of
> relying on a graphical session?

The man page for gpg-agent suggests you can set that with the 
--pinentry-program option. I haven't tried this myself, but adding 
something like

pinentry-program /usr/bin/pinentry-curses

to ~/.gnupg/gpg-agent.conf should work (provided the package 
pinentry-curses is installed, of course). You probably have to make the 
gpg-agent reload its configuration for that to take effect.

A web search for 'force gpg-agent to use terminal' came up with some 
interesting pages, but most of those refer to the previous version of 
gpg2/gpg-agent so some of the suggestions are no longer valid (like the 
one that mentions --no-use-agent - that simply won't work anymore).

Regards,
Frank

[toc] | [prev] | [next] | [standalone]


#174230

From<tomas@tuxteam.de>
Date2016-11-06 10:50 +0100
Message-ID<sAsfn-3Ir-1@gated-at.bofh.it>
In reply to#174228
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sun, Nov 06, 2016 at 07:42:40AM +0100, Frank wrote:
> Op 06-11-16 om 04:52 schreef H.S.:
> >So, how do I tell gpg to work on std in when on a terminal instead of
> >relying on a graphical session?
> 
> The man page for gpg-agent suggests you can set that with the
> --pinentry-program option. I haven't tried this myself, but adding
> something like
> 
> pinentry-program /usr/bin/pinentry-curses

There's also pinentry-tty, which sounds like the more traditional
behaviour. There are separate packages for that -- just try

  aptitude search pinentry

hth
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlge+7cACgkQBcgs9XrR2kbftQCfWKlUhov82Og1nl8ZxZK1Nnt5
XkMAn2OpvFvzOl/rBxqCedVaDymCYOLl
=m3Sg
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#174238

FromJörg-Volker Peetz <jvpeetz@web.de>
Date2016-11-06 13:30 +0100
Message-ID<sAuKe-5pU-11@gated-at.bofh.it>
In reply to#174230
I'm using pinentry-gtk2 which also works in text-mode.
KDE users may prefer pinentry-qt or pinentry-qt4 which also works in text-mode.

Regards,
jvp.

[toc] | [prev] | [next] | [standalone]


#174260 — [SOLVED] Re: upgraded testing and now gpg is not working

From"H.S." <hs.samix@gmail.com>
Date2016-11-07 00:10 +0100
Subject[SOLVED] Re: upgraded testing and now gpg is not working
Message-ID<sAEJz-3lZ-19@gated-at.bofh.it>
In reply to#174238
On 11/06/2016 07:19 AM, Jörg-Volker Peetz wrote:
> I'm using pinentry-gtk2 which also works in text-mode.
> KDE users may prefer pinentry-qt or pinentry-qt4 which also works in text-mode.
>
> Regards,
> jvp.
>
>

Frank, JVP,
Thanks for the info. This completed the solution for me. Based on your 
info and some background from 
https://wiki.archlinux.org/index.php/GnuPG, I have the following in my 
config:
$ cat ~/.gnupg/gpg-agent.conf
# Specify which pinentry program to use
pinentry-program /usr/bin/pinentry-gtk-2

I then reloaded the agent using this command:
$ gpg-connect-agent reloadagent  /bye

and was able to decrypt the file from a virtual console, as well as 
using vim to edit that gpg file. Just to be clear, in a console (withoug 
a windowing environment), there is an ncurses prompt in the terminal for 
the passphrase. In a windowing environment (KDE in my case), there is a 
GKT2 window that asks for the passphrase. In both cases, the gpg-agent 
saves the passphrase. This also works when I edit my encrypted text file 
in vim. All works great now!

Thank you, everyone!


-- 

Please reply to this list only. I read this list on its corresponding
newsgroup on gmane.org. Replies sent to my email address are just
filtered to a folder in my mailbox and get periodically deleted without
ever having been read.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web