Gpg — Dongle Setup
brew install gnupg ykman pinentry-mac :
gpg --card-status Expected output shows:
# PC/SC driver pcsc-driver /usr/lib/libpcsclite.so # Disable CCID (for YubiKey) disable-ccid # Enable card removal notification card-timeout 5 Edit ~/.gnupg/gpg-agent.conf :
gpg --export-ssh-key YOUR_KEYID > ~/.ssh/id_rsa_gpg.pub Add to ~/.ssh/config : gpg dongle setup
gpg --card-edit Within the interactive shell:
enable-ssh-support default-cache-ttl 600 max-cache-ttl 7200 pinentry-program /usr/bin/pinentry-curses # or pinentry-mac on macOS Restart the agent:
sudo apt install gnupg gnupg-agent pcscd scdaemon (Homebrew): brew install gnupg ykman pinentry-mac : gpg --card-status
Reader ...........: Yubico YubiKey OTP+FIDO+CCID 0 Application ID ...: D276000124010200... Version ..........: 3.4 Manufacturer .....: Yubico If not detected, restart pcscd :
gpgconf --kill gpg-agent Set admin PIN, user PIN, and reset code (optional):
sudo systemctl restart pcscd Edit ~/.gnupg/scdaemon.conf : gpg dongle setup
ssh -T git@github.com # Should prompt for PIN then authenticate Sign a file gpg --sign document.txt # Prompts for PIN on the dongle Decrypt a file gpg --decrypt secret.gpg List keys on card gpg --card-status Change PIN gpg --card-edit gpg/card> admin gpg/card> passwd Step 7: Backup & Recovery Critical : Backup your revocation certificate immediately:
sudo pacman -S gnupg pcsc-tools Plug in your dongle and check if the system sees it:
export SSH_AUTH_SOCK=$(gpgconf --list-dirs agent-ssh-socket) Test SSH: