X-Git-Url: https://iankelling.org/git/?a=blobdiff_plain;f=subdir_files%2F.gnupg%2Fgpg.conf;h=9641d86ee4e059fe3ae009b561238991d0c5b15e;hb=2d3ce30754a3f24d922635647bab4990b60f5c27;hp=f9da1b58f50f80ea44ee0a55e4e2040ce7de7df4;hpb=eb9b839bb5a91c60cc4f6eb9d7e38ffbf73f0e90;p=distro-setup diff --git a/subdir_files/.gnupg/gpg.conf b/subdir_files/.gnupg/gpg.conf index f9da1b5..9641d86 100644 --- a/subdir_files/.gnupg/gpg.conf +++ b/subdir_files/.gnupg/gpg.conf @@ -6,15 +6,19 @@ keyserver-options auto-key-retrieve # start gpg agent on login use-agent + # standard short key ids are easy to collide # https://security.stackexchange.com/questions/84280/short-openpgp-key-ids-are-insecure-how-to-configure-gnupg-to-use-long-key-ids-i # https://evil32.com/ # another option is 0xshort keyid-format 0xlong -# iank@fsf.org + default-key B125F60B7B287FF6A2B7DF8F170AF0E2954295DF +# financial key +#default-key 0xFB40960C541A7D1F + # note, i did this so that gpg-agent would not hold open the .gnupg dir. # so I could unmount the filesystem which holds the .gnupg dir while # running gpg-agent. @@ -26,3 +30,15 @@ default-key B125F60B7B287FF6A2B7DF8F170AF0E2954295DF # echo -e "%Assuan%\nsocket=${HOME}/gpg-agent-socket/s" > ~/.gnupg/S.gpg-agent # # this is also in my conflink scrpt: # install -d -m700 ~/gpg-agent-socket +# and in /etc/X11/Xsession.d/01iank +# install -o iank -g iank -d -m700 /home/iank/gpg-agent-socket +# because something keeps deleting that directory + +# default keyserver +# +#keyserver hkp://pgp.mit.edu +# this one seems more reliable, but it's down now +keyserver hkp://pool.sks-keyservers.net + +# more secure, but had problems with my gpg version +#keyserver hkps://hkps.pool.sks-keyservers.net