<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=26&amp;t=1324" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2014-02-25T18:18:15+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=26&amp;t=1324</id>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-25T18:18:15+01:00</updated>
<published>2014-02-25T18:18:15+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4996#p4996</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4996#p4996"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4996#p4996"><![CDATA[
It works! Again, thank you very much for your help. I am also inspired by this tutorial <!-- m --><a class="postlink" href="https://we.riseup.net/debian/using-the-openpgp-card-with-subkeys">https://we.riseup.net/debian/using-the- ... th-subkeys</a><!-- m --> . <br />Step 7 was very important for me because I never did a &quot;key 1&quot;.<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />7. move the encryption key above to the card:<br /><br />$ gpg --edit-key $KEYID<br />Command&gt; toggle [this sets you into secret key mode]<br />Command&gt; key $NUMBER [select the encryption key above, it'll be the last one if you just generated it, and this command puts a * next to it]<br />Command&gt; keytocard<br />Please select where to store the key:<br />   (2) Encryption key<br />Your selection? 2<br />Command&gt; save<br /></div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Tue Feb 25, 2014 6:18 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2014-02-25T18:03:26+01:00</updated>
<published>2014-02-25T18:03:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4994#p4994</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4994#p4994"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4994#p4994"><![CDATA[
Tools like gpg-agent cache the passphrase for some time, I think 10 minutes is default. You can force purge it by sending SIGHUP to gpg-agent, like &quot;killall -SIGHUP gpg-agent&quot;.<br /><br />The way to change the password is via &quot;gpg --card-edit&quot;, the select &quot;passwd&quot; command. The OpenPGP applet has hardcoded minimum of 6 chars for password length and 8 chars for admin password.<br /><br />(Maybe someone from staff should add some of the stuff from here into FAQ, especially the part about using the Neo Openpgp on multiple computers.)<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Tue Feb 25, 2014 6:03 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-25T15:14:03+01:00</updated>
<published>2014-02-25T15:14:03+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4990#p4990</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4990#p4990"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4990#p4990"><![CDATA[
Thank you for your help <br /><br />I could actually use keytocard with version 2.2 gpg. <br />So I then used &quot;gpg - list-secret-keys&quot; that adds me &quot;Serial No. Card = 0000 00000001&quot; <br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~$ gpg --list-secret-keys <br />/home/ja/.gnupg/secring.gpg<br />---------------------------<br />sec&gt;  2048R/6AC871C1 2014-02-25 &#91;expire : 2014-02-26&#93;<br /> Nº de série de carte = 0000 00000001<br />uid                 name &lt;m@mail&gt;<br />ssb   2048R/74F58795 2014-02-25</div><br /><br />But, the Yubikey is never asked me when I want to decrypt. I was just wondering the pass of the secret key. I have a paramettre to add to the key?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Tue Feb 25, 2014 3:14 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2014-02-25T13:20:08+01:00</updated>
<published>2014-02-25T13:20:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4986#p4986</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4986#p4986"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4986#p4986"><![CDATA[
And can you try again the keyParser.py script again with 2048 bit key? That seemed to work. Just don't delete the .gnupg dir <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":-)" title="Smile" /><br /><br />I think I used hand-compiled gnupg 2.0.22 for the &quot;keytocard&quot; part to work, but if it worked with the keyParser.py for you, then that shouldn't matter. Here's the <a href="https://github.com/Yubico/ykneo-openpgp/issues/14" class="postlink">related issue from github</a>.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Tue Feb 25, 2014 1:20 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-25T12:06:26+01:00</updated>
<published>2014-02-25T12:06:26+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4985#p4985</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4985#p4985"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4985#p4985"><![CDATA[
ja@x220:~$ gpg2 --edit-key 4E99BDD5<br />gpg (GnuPG) 2.0.19; Copyright (C) 2012 Free Software Foundation, Inc.<br />This is free software: you are free to change and redistribute it.<br />There is NO WARRANTY, to the extent permitted by law.<br /><br />La clé secrète est disponible.<br /><br />pub  2048R/4E99BDD5  créé: 2014-02-25  expire: jamais      utilisation: SC  <br />                      confiance: ultime        validité: ultime<br />sub  2048R/8775108D  créé: 2014-02-25  expire: jamais      utilisation: E   <br />[  ultime ] (1). myname &lt;m@xxxx&gt;<br /><br />gpg&gt; toggle <br /><br />sec  2048R/4E99BDD5  créé: 2014-02-25  expire: jamais    <br />ssb  2048R/8775108D  créé: 2014-02-25  expire: jamais    <br />(1)  myname &lt;m@j4.pe&gt;<br /><br />gpg&gt; keytocard <br />Enlever réellement la clé principale ? (o/N) o<br />Signature key ....: [none]<br />Encryption key....: [none]<br />Authentication key: [none]<br /><br />Sélectionnez l'endroit où stocker la clé:<br />   (1) Clé de signature<br />   (3) Clé d'authentification<br />Votre choix ? 1<br /><br />Vous avez besoin d'une phrase de passe pour déverrouiller la<br />clé secrète pour l'utilisateur: « myname &lt;m@mail&gt; »<br />clé de 2048 bits RSA, ID 4E99BDD5, créée le 2014-02-25<br /><br />gpg: error writing key to card: Non pris en charge<br /><br />gpg&gt;<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Tue Feb 25, 2014 12:06 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-25T11:57:44+01:00</updated>
<published>2014-02-25T11:57:44+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4984#p4984</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4984#p4984"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4984#p4984"><![CDATA[
Thank you for your reply. Now I better understand the principle of private key on the key. <br /><br />However, I can not use &quot;keytocard&quot;. I had compiled from the git repo. In doubt I used your &quot;.cap&quot; but I have the same error. <br />I also tried killing gpg-agent<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Tue Feb 25, 2014 11:57 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2014-02-25T11:26:08+01:00</updated>
<published>2014-02-25T11:26:08+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4983#p4983</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4983#p4983"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4983#p4983"><![CDATA[
First of all, <strong>you can't just delete ~/.gnupg, even if you moved key to smartcard</strong>. The key that you just moved to Neo is still on your keyring as secret key, but has a special &quot;S2K&quot; flag. This flag tells GnuPG that the private key is not present in the keyring as a file, but it has instead to ask the smartcard.<br /><br />If you list &quot;gpg --list-secret-keys&quot;, there will be a new line showing that the key is on the card now:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Card serial no. = 0000 00000001</div><br /><br />If you want to use the keycard on another computer, you have to export the key fully and import it on the new computer using the usual &quot;gpg --import&quot;. This is the part that might have been very counter-intuitive. On the new computer, the key will also require Neo physically inserted to be usable. The key is really moved to the card - you can check with with &quot;gpg --list-packets&quot; that will show you low-level packet format of PGP file.<br /><br />-----<br />If the above did not help, here are few things you could try:<br /><br />I am a bit worried about this part, it may indicate you have an old build of openpgpcard.cap after the &quot;keytocard&quot; command:<br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />gpg: error writing key to card: not supported<br /></div><br />Where did you get the &quot;openpgpcard.cap&quot; file? The version that's for download from Yubico site may be the old one, without key import. I had to build the openpgpcard.cap myself from code in their <a href="https://github.com/Yubico/ykneo-openpgp" class="postlink">git repo</a>.<br /><br />Does the OpenPGP applet work if you let it generate key according to the older manual (instead of importing existing key)?<br /><br />You might also try to kill gpg-agent, and retry.<br /><br /><a href="https://www.constructibleuniverse.net/ykneo/openpgpcard.cap" class="postlink">Here is an openpgpcard.cap I built from current github master</a>, you might try that one, too. It's built from revision 3c11acaf6b93402f032d8ac91ed31f79eff96d7c (just one commit after 1.0.5 that only changes version number to 1.0.6).<br /><br />SHA256 file checksum (the forum won't upload the file itself as attachment):<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">7a26fd239ac6ef8d70c70b999741bef870d80292ac130504da4e9caa1f7dc6cb  openpgpcard.cap</div><p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Tue Feb 25, 2014 11:26 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-25T09:41:35+01:00</updated>
<published>2014-02-25T09:41:35+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4982#p4982</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4982#p4982"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4982#p4982"><![CDATA[
Here's what I did to reproduce my problem.<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp$ gpshell gpinstall.txt<br />mode_211<br />enable_trace<br />establish_context<br />card_connect<br />select -AID a000000003000000<br />Command --&gt; 00A4040008A000000003000000<br />Wrapped command --&gt; 00A4040008A000000003000000<br />....<br />Response &lt;-- 009000<br />card_disconnect<br />release_context</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp$ gpg --card-status <br />gpg: detected reader `YubiKey Neo CCID 00 00'<br />Application ID ...: D2760001240102000000000000010000<br />Version ..........: 2.0<br />Manufacturer .....: test card<br />Serial number ....: 00000001<br />Name of cardholder: &#91;non positionné&#93;<br />Language prefs ...: &#91;non positionné&#93;<br />Sex ..............: non indiqué<br />URL of public key : &#91;non positionné&#93;<br />Login data .......: &#91;non positionné&#93;<br />Signature PIN ....: forcé<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 0<br />Signature key ....: &#91;none&#93;<br />Encryption key....: &#91;none&#93;<br />Authentication key: &#91;none&#93;<br />General key info..: &#91;none&#93;</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp$ gpg --gen-key <br />gpg (GnuPG) 1.4.12; Copyright (C) 2012 Free Software Foundation, Inc.<br />This is free software: you are free to change and redistribute it.<br />There is NO WARRANTY, to the extent permitted by law.<br /><br />Sélectionnez le type de clef désiré :<br />   (1) RSA et RSA (par défaut)<br />   (2) DSA et Elgamal<br />   (3) DSA (signature seule)<br />   (4) RSA (signature seule)<br />Quel est votre choix ? 1<br />les clefs RSA peuvent faire entre 1024 et 4096 bits de longueur.<br />Quelle taille de clef désirez-vous ? (2048) <br />La taille demandée est 2048 bits<br />Veuillez indiquer le temps pendant lequel cette clef devrait être valable.<br />         0 = la clef n'expire pas<br />      &lt;n&gt;  = la clef expire dans n jours<br />      &lt;n&gt;w = la clef expire dans n semaines<br />      &lt;n&gt;m = la clef expire dans n mois<br />      &lt;n&gt;y = la clef expire dans n ans<br />Pendant combien de temps la clef est-elle valable ? (0) 1<br />La clef expire le mer. 26 févr. 2014 09:22:26 CET<br />Est-ce correct ? (o/N) o<br /><br />Une identité est nécessaire à la clef ; le programme la construit à partir<br />du nom réel, d'un commentaire et d'une adresse électronique de cette façon :<br />   « Heinrich Heine (le poète) &lt;heinrichh@duesseldorf.de&gt; »<br /><br />Nom réel : My Name<br />Adresse électronique : mail@mail.com<br />Commentaire : <br />Vous avez sélectionné cette identité :<br />    « My Name &lt;mail@mail.com&gt; »<br /><br />Faut-il modifier le (N)om, le (C)ommentaire, l'(A)dresse électronique<br />ou (O)ui/(Q)uitter ? o<br />Une phrase de passe est nécessaire pour protéger votre clef secrète.<br />....<br />gpg: vérification de la base de confiance<br />gpg: 3 marginale(s) nécessaire(s), 1 complète(s) nécessaire(s),<br />     modèle de confiance PGP<br />gpg: profondeur : 0  valables :   1  signées :   0<br />     confiance : 0 i., 0 n.d., 0 j., 0 m., 0 t., 1 u.<br />gpg: la prochaine vérification de la base de confiance aura lieu le 2014-02-26<br />pub   2048R/41EF8C31 2014-02-25 &#91;expire : 2014-02-26&#93;<br /> Empreinte de la clef = D3E4 FAB7 E2CC A306 7509  2B06 2FE9 B563 41EF 8C31<br />uid                  My Name &lt;mail@mail.com&gt;<br />sub   2048R/75FB60D7 2014-02-25 &#91;expire : 2014-02-26&#93;</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp$ gpg --edit-key 41EF8C31<br />gpg (GnuPG) 1.4.12; Copyright (C) 2012 Free Software Foundation, Inc.<br />This is free software: you are free to change and redistribute it.<br />There is NO WARRANTY, to the extent permitted by law.<br /><br />Secret key is available.<br /><br />pub  2048R/41EF8C31  created: 2014-02-25  expires: 2014-02-26  usage: SC  <br />                     trust: ultimate      validity: ultimate<br />sub  2048R/75FB60D7  created: 2014-02-25  expires: 2014-02-26  usage: E   <br />&#91;ultimate&#93; (1). My Name &lt;mail@mail.com&gt;<br /><br />gpg&gt; toggle <br /><br />sec  2048R/41EF8C31  created: 2014-02-25  expires: 2014-02-26<br />ssb  2048R/75FB60D7  created: 2014-02-25  expires: never     <br />(1)  My Name &lt;mail@mail.com&gt;<br /><br />gpg&gt; keytocard <br />Really move the primary key? (y/N) y<br />gpg: detected reader `YubiKey Neo CCID 00 00'<br />Signature key ....: &#91;none&#93;<br />Encryption key....: &#91;none&#93;<br />Authentication key: &#91;none&#93;<br /><br />Please select where to store the key:<br />   (1) Signature key<br />   (3) Authentication key<br />Your selection? 1<br /><br />You need a passphrase to unlock the secret key for<br />user: &quot;My Name &lt;mail@mail.com&gt;&quot;<br />2048-bit RSA key, ID 41EF8C31, created 2014-02-25<br /><br />gpg: writing new key<br />gpg: error writing key to card: not supported</div><br /><br />Ok, i use keyParser.py script<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp/util$ ./keyParser.py a 41EF8C31 12345678<br />writing RSA key<br />pub   2048R/41EF8C31 2014-02-25 &#91;expire : 2014-02-26&#93;<br /> Empreinte de la clef = D3E4 FAB7 E2CC A306 7509  2B06 2FE9 B563 41EF 8C31<br />uid                  My Name &lt;mail@mail.com&gt;<br />sub   2048R/75FB60D7 2014-02-25 &#91;expire : 2014-02-26&#93;<br /> Empreinte de la clef = 536C 694F 5E46 B3A2 1ABD  64B7 6BB7 4D00 75FB 60D7<br /></div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">opensc-tool -s '00 A4 04 00 ....'</div><br /><br />idem with option a s and e<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:~/src/ykneo-openpgp/util$ gpg --card-status <br />gpg: detected reader `YubiKey Neo CCID 00 00'<br />Application ID ...: D2760001240102000000000000010000<br />Version ..........: 2.0<br />Manufacturer .....: test card<br />Serial number ....: 00000001<br />Name of cardholder: &#91;non positionné&#93;<br />Language prefs ...: &#91;non positionné&#93;<br />Sex ..............: non indiqué<br />URL of public key : &#91;non positionné&#93;<br />Login data .......: &#91;non positionné&#93;<br />Signature PIN ....: forcé<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 0<br />Signature key ....: D3E4 FAB7 E2CC A306 7509  2B06 2FE9 B563 41EF 8C31<br />Encryption key....: D3E4 FAB7 E2CC A306 7509  2B06 2FE9 B563 41EF 8C31<br />Authentication key: D3E4 FAB7 E2CC A306 7509  2B06 2FE9 B563 41EF 8C31<br />General key info..: pub  2048R/41EF8C31 2014-02-25 My Name &lt;mail@mail.com&gt;<br />sec   2048R/41EF8C31  créé : 2014-02-25  expire : 2014-02-26<br />ssb   2048R/75FB60D7  créé : 2014-02-25  expire : 2014-02-26</div><br /><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:/tmp$ gpg -ea msg.txt <br />Vous n'avez pas indiqué d'identité (vous pouvez utiliser « -r »).<br /><br />Destinataires actuels :<br /><br />Entrez l'identité, en terminant par une ligne vide : mail@mail.com<br /><br />Destinataires actuels :<br />2048R/75FB60D7 2014-02-25 &quot;My Name &lt;mail@mail.com&gt;&quot;</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:/tmp$ cat msg.txt.asc <br />-----BEGIN PGP MESSAGE-----<br />Version: GnuPG v1.4.12 (GNU/Linux)<br /><br />hQEMA2u3TQB1+2DXAQf/ZgHDgq/jBaMsDKUvXEsCGHnKvQyDUk8ByUnUrSOLz7CC<br />WCvcYD37YA8ZdffNUpNOKqN9rMD8MwbGmu+HIxgvuY/T+HVXPi/xlUVa4t2rTqrj<br />uqWyS2xpx3o5SXraegwg+Ekd2sxMG6BqKVI6N/nbbslYzIndvucFXzdWfGtievq4<br />DhQ0P0qlnd9hFkSpKp2EX6Xy9Qex0tvvhEGgGDLJJ5xs4OZMLYahPrXFxTUXYGBt<br />GBgwXs6ssRKhWuUXtn0Gb9ZCqQcDVxJmmaXrgKcZbSQiKgEHVPF2k5ydDly6Xaeh<br />wFvgkbPVE8hqxHiB/oufHXzy4N55aabnLQcOPC+sc9JMAWGykNqAk8QDtZchBTgX<br />4kTfn1LGrYH/qIr3qk/f9MtQQoP/aL5xOTIJEoderlsmVGKSkgv7fCXn7vm+g3Nd<br />VG2Jfc3A2T8AOyGLfw==<br />=tVGY<br />-----END PGP MESSAGE-----</div><br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:/tmp$ gpg -d msg.txt.asc <br />gpg: chiffré avec une clef RSA de 2048 bits, identifiant 75FB60D7, créée le 2014-02-25<br />      « My Name &lt;mail@mail.com&gt; »<br />hello gpg</div><br /><br /><br />ok <br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">rm -rf /home/ja/.gnupg</div>  (as if I was on a new computer)<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">ja@x220:/tmp$ gpg -d msg.txt.asc <br />gpg: directory `/home/ja/.gnupg' created<br />gpg: new configuration file `/home/ja/.gnupg/gpg.conf' created<br />gpg: WARNING: options in `/home/ja/.gnupg/gpg.conf' are not yet active during this run<br />gpg: keyring `/home/ja/.gnupg/secring.gpg' created<br />gpg: keyring `/home/ja/.gnupg/pubring.gpg' created<br />gpg: encrypted with RSA key, ID 75FB60D7<br />gpg: decryption failed: secret key not available<br />ja@x220:/tmp$ gpg -d msg.txt.asc <br />gpg: encrypted with RSA key, ID 75FB60D7<br />gpg: decryption failed: secret key not available</div><br /><br />why ? <img src="https://forum.yubico.com/images/smilies/icon_e_smile.gif" alt=":)" title="Smile" /> why I can not use the secret key that is on the key?<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Tue Feb 25, 2014 9:41 am</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-24T19:18:31+01:00</updated>
<published>2014-02-24T19:18:31+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4976#p4976</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4976#p4976"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4976#p4976"><![CDATA[
I also tried with 2048 key and i have the same error. Tommorrow i try to reinitialise Yubikey with gpshell and upload 2048 key without sub key.<br />I'm not verry confident because i think i have already tried.<br /><br />also keytocard (gpg --edit-key) dont work with me. i append log tomorow.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Mon Feb 24, 2014 7:18 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[hiviah]]></name></author>
<updated>2014-02-24T18:11:53+01:00</updated>
<published>2014-02-24T18:11:53+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4975#p4975</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4975#p4975"/>
<title type="html"><![CDATA[Re: Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4975#p4975"><![CDATA[
This seems to suggest your RSA key had 4096 bit modulus, which is AFAIK not supported for Yubikey Neo, 2048 bit RSA is max:<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />gpg : encrypted with RSA key 4096 bits<br /></div><br /><br />Later, in the gpg output it shows that the imported key is 2048 bit, according to the card (something got truncated somewhere?)<br /><br /><div class="quotetitle"><b>Quote:</b></div><div class="quotecontent"><br />Key attributes ...: <strong>2048R 2048R 2048R</strong><br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 0<br />Signature key ....: XXXXXXXXXXX<br />Encryption key....: XXXXXXXXXX <br />Authentication key: XXXXXXXXXXXX<br />General key info..: <strong>pub  4096R/XXX</strong> 2014-02-24 xxx &lt;x@x&gt;<br /></div><br /><br />I also found out that the import doesn't work correctly if you created extra subkeys for your key (I had to revoke one signing subkey).<br /><br />BTW I used different method, moving keys directly to card with &quot;keytocard&quot; command from &quot;gpg --edit-key&quot;.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2457">hiviah</a> — Mon Feb 24, 2014 6:11 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[j4pe]]></name></author>
<updated>2014-02-24T16:37:49+01:00</updated>
<published>2014-02-24T16:37:49+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4973#p4973</id>
<link href="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4973#p4973"/>
<title type="html"><![CDATA[Import my old GPG private key in Yubikey Neo]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=1324&amp;p=4973#p4973"><![CDATA[
Hello to all.<br /><br />I would like to send my old private key on my YubikeyNeo . I follow the README repository: <!-- m --><a class="postlink" href="https://github.com/Yubico/ykneo-openpgp">https://github.com/Yubico/ykneo-openpgp</a><!-- m --> . The installation went very well and I use the script &quot; keyParser.py &quot; which also works fine except a regular expression in &quot; parsingFunctions.py &quot; because I 'm french . (line 121) :<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">regexp = r &quot; ^ \ s + Footprint key = (+). ? &quot; keyid + + &quot;$&quot;</div><br />By executing this script , I have an commande line that appears to play . eg<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">./keyParser.py e 00XXXXXX 12345678<br />opensc-tool -s '00 ...........'</div><br />I execute opensc-tool result and the key is added to the yubikey in Signature, Encryption and Authentication modes.<br /><span style="text-decoration: underline">I test with a file</span>:<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg -ae test.txt </div><br />which create me well an encrypted file . It is trying to uncrypt that is more complicated :<br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">gpg -d test.txt.asc<br />gpg : parts of the secret key is not available<br />gpg : encrypted with RSA key 4096 bits , XXXX identifier created on 2014-02-24<br />      &quot; xxx x &lt;x@x&gt; &quot;<br />gpg : decryption fails public key : general error<br />gpg : decryption failed : secret key not available</div><br />Why Gpg can not find my key?<br /><br /><div class="codetitle"><b>Code:</b></div><div class="codecontent">Application ID ...: D2760001240102000000000000010000<br />Version ..........: 2.0<br />Manufacturer .....: test card<br />Serial number ....: 00000001<br />Name of cardholder: &#91;non positionné&#93;<br />Language prefs ...: &#91;non positionné&#93;<br />Sex ..............: non indiqué<br />URL of public key : &#91;non positionné&#93;<br />Login data .......: &#91;non positionné&#93;<br />Signature PIN ....: forcé<br />Key attributes ...: 2048R 2048R 2048R<br />Max. PIN lengths .: 127 127 127<br />PIN retry counter : 3 3 3<br />Signature counter : 0<br />Signature key ....: XXXXXXXXXXX<br />Encryption key....: XXXXXXXXXX  <br />Authentication key: XXXXXXXXXXXX <br />General key info..: pub  4096R/XXX 2014-02-24 xxx &lt;x@x&gt;<br />sec&gt;  4096R/XXX  créé : 2014-02-24  expire : jamais    <br />                      nº de carte : 0000 00000001<br />ssb#  4096R/XXX  créé : 2014-02-24  expire : jamais <br /></div><br />Regards<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=2822">j4pe</a> — Mon Feb 24, 2014 4:37 pm</p><hr />
]]></content>
</entry>
</feed>