unofficial mirror of help-guix@gnu.org 
 help / color / mirror / Atom feed
* gpg-agent error: No pinentry
@ 2019-12-18 21:41 Marco van Hulten
  2019-12-18 21:50 ` Andreas Enge
  2019-12-18 21:52 ` Gábor Boskovits
  0 siblings, 2 replies; 8+ messages in thread
From: Marco van Hulten @ 2019-12-18 21:41 UTC (permalink / raw)
  To: help-guix

Hello—

I have installed gnupg 2.2.18 and pinentry 1.1.0 on a Guix System.
When I try to import a key, I get this issue:

$ gpg --import publiko-secret.asc 
gpg: key 9FC3734DFB84400D: "Marco van Hulten (publiko) <marco@hulten.org>" not changed
gpg: key 9FC3734DFB84400D/9FC3734DFB84400D: error sending to agent: No pinentry
gpg: error building skey array: No pinentry
gpg: error reading 'publiko-secret.asc': No pinentry
gpg: import from 'publiko-secret.asc' failed: No pinentry
gpg: Total number processed: 0
gpg:              unchanged: 1
gpg:       secret keys read: 1

It seems that the public key is imported but not the private key (I can
encrypt but not decrypt).  On an OpenBSD-current system importing this
key works properly.

Do I need to do any more actions accept for 'guix package -i gnupg
pinentry'?

Thanks,

—Marco

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-18 21:41 gpg-agent error: No pinentry Marco van Hulten
@ 2019-12-18 21:50 ` Andreas Enge
  2019-12-19  8:22   ` Marco van Hulten
  2019-12-18 21:52 ` Gábor Boskovits
  1 sibling, 1 reply; 8+ messages in thread
From: Andreas Enge @ 2019-12-18 21:50 UTC (permalink / raw)
  To: Marco van Hulten; +Cc: help-guix

Hello,

On Wed, Dec 18, 2019 at 10:41:27PM +0100, Marco van Hulten wrote:
> Do I need to do any more actions accept for 'guix package -i gnupg
> pinentry'?

I also have a file .gnupg/gpg-agent.conf in my home directory
containing the following lines:

default-cache-ttl 300
max-cache-ttl 3600
pinentry-program /home/USERNAME/.guix-profile/bin/pinentry-curses

The first two determine how long, after typing your password, the key
remains unlocked; it gets locked after 5 minutes without any usage, or
1 hour even if it is used, if I remember well.

Andreas

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-18 21:41 gpg-agent error: No pinentry Marco van Hulten
  2019-12-18 21:50 ` Andreas Enge
@ 2019-12-18 21:52 ` Gábor Boskovits
  1 sibling, 0 replies; 8+ messages in thread
From: Gábor Boskovits @ 2019-12-18 21:52 UTC (permalink / raw)
  To: Marco van Hulten; +Cc: help-guix

Hello,

Marco van Hulten <marco@hulten.org> ezt írta (időpont: 2019. dec. 18., Sze
22:41):

> Hello—
>
> I have installed gnupg 2.2.18 and pinentry 1.1.0 on a Guix System.
> When I try to import a key, I get this issue:
>
> $ gpg --import publiko-secret.asc
> gpg: key 9FC3734DFB84400D: "Marco van Hulten (publiko) <marco@hulten.org>"
> not changed
> gpg: key 9FC3734DFB84400D/9FC3734DFB84400D: error sending to agent: No
> pinentry
> gpg: error building skey array: No pinentry
> gpg: error reading 'publiko-secret.asc': No pinentry
> gpg: import from 'publiko-secret.asc' failed: No pinentry
> gpg: Total number processed: 0
> gpg:              unchanged: 1
> gpg:       secret keys read: 1
>
> It seems that the public key is imported but not the private key (I can
> encrypt but not decrypt).  On an OpenBSD-current system importing this
> key works properly.
>
> Do I need to do any more actions accept for 'guix package -i gnupg
> pinentry'?
>
Yes, unfortunately you need to set pinentry program in gpgagent conf. I am
on mobile right now, so I don't have the exact settings at hand, but this
should give you enough info to  search for the solution.

>
> Thanks,
>
> —Marco
>
Regards,
g_bor

>
>

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-18 21:50 ` Andreas Enge
@ 2019-12-19  8:22   ` Marco van Hulten
  2019-12-19  9:02     ` Marco van Hulten
  0 siblings, 1 reply; 8+ messages in thread
From: Marco van Hulten @ 2019-12-19  8:22 UTC (permalink / raw)
  To: help-guix

[-- Attachment #1: Type: text/plain, Size: 1759 bytes --]

Je 18 dec 22:50 skribis Andreas:
> On Wed, Dec 18, 2019 at 10:41:27PM +0100, Marco van Hulten wrote:
> > Do I need to do any more actions accept for 'guix package -i gnupg
> > pinentry'?  
> 
> I also have a file .gnupg/gpg-agent.conf in my home directory
> containing the following lines:
> 
> default-cache-ttl 300
> max-cache-ttl 3600
> pinentry-program /home/USERNAME/.guix-profile/bin/pinentry-curses

Thank you, Andreas and Gábor, very useful to know that pinentry-program
should be set.  I did so:

$ file $(realpath $(grep ^pinentry-program ~/.gnupg/gpg-agent.conf | awk '{print $2}'))
/gnu/store/12gagy0ql4v7qlv9px54lz5fy4d7gff9-pinentry-tty-1.1.0/bin/pinentry-tty:
ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked,
interpreter /gnu/store/ahqgl4h89xqj695lgqvsaf6zh2nhy4pj-glibc-2.29/lib/ld-linux-x86-64.so.2,
for GNU/Linux 2.6.32, not stripped

Importing a public and private key pair, following [1], worked properly
now, but it still complains when decrypting a file.

[1]: https://www.debuntu.org/how-to-importexport-gpg-key-pair/

To be sure, if I now try to remove the key, 'gpg --delete-key publiko',
it says that I need to use option "--delete-secret-keys" to delete the
private key first.  So it appears to be really there.  However,

    $ date | gpg -e > jadaja.gpg
    gpg: encrypted with 4096-bit RSA key, ID 54AE7D44B93BDBDF, created 2019-05-30
          "Marco van Hulten (publiko) <marco@hulten.org>"
    gpg: public key decryption failed: No pinentry
    gpg: decryption failed: No secret key

I tried killing gpg-agent to be sure it uses the current configuration,
but again it complains about pinentry.

Apropos, I this e-mail is signed with this very key.

—Marco

[-- Attachment #2: OpenPGP digitale handtekening --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-19  8:22   ` Marco van Hulten
@ 2019-12-19  9:02     ` Marco van Hulten
  2019-12-20  9:49       ` Marco van Hulten
  0 siblings, 1 reply; 8+ messages in thread
From: Marco van Hulten @ 2019-12-19  9:02 UTC (permalink / raw)
  To: help-guix

[-- Attachment #1: Type: text/plain, Size: 2449 bytes --]

correction follows inline—

Any help is appreciated.

Je 19 dec 09:22 skribis Marco:
> Je 18 dec 22:50 skribis Andreas:
> > On Wed, Dec 18, 2019 at 10:41:27PM +0100, Marco van Hulten wrote:  
> > > Do I need to do any more actions accept for 'guix package -i gnupg
> > > pinentry'?    
> > 
> > I also have a file .gnupg/gpg-agent.conf in my home directory
> > containing the following lines:
> > 
> > default-cache-ttl 300
> > max-cache-ttl 3600
> > pinentry-program /home/USERNAME/.guix-profile/bin/pinentry-curses  
> 
> Thank you, Andreas and Gábor, very useful to know that pinentry-program
> should be set.  I did so:
> 
> $ file $(realpath $(grep ^pinentry-program ~/.gnupg/gpg-agent.conf | awk '{print $2}'))
> /gnu/store/12gagy0ql4v7qlv9px54lz5fy4d7gff9-pinentry-tty-1.1.0/bin/pinentry-tty:
> ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked,
> interpreter /gnu/store/ahqgl4h89xqj695lgqvsaf6zh2nhy4pj-glibc-2.29/lib/ld-linux-x86-64.so.2,
> for GNU/Linux 2.6.32, not stripped
> 
> Importing a public and private key pair, following [1], worked properly
> now, but it still complains when decrypting a file.
> 
> [1]: https://www.debuntu.org/how-to-importexport-gpg-key-pair/
> 
> To be sure, if I now try to remove the key, 'gpg --delete-key publiko',
> it says that I need to use option "--delete-secret-keys" to delete the
> private key first.  So it appears to be really there.  However,
> 
>     $ date | gpg -e > jadaja.gpg
>     gpg: encrypted with 4096-bit RSA key, ID 54AE7D44B93BDBDF, created 2019-05-30
>           "Marco van Hulten (publiko) <marco@hulten.org>"
>     gpg: public key decryption failed: No pinentry
>     gpg: decryption failed: No secret key

Sorry, the lines were not copied consistently.  Now the whole
encryption/decryption process verbatimly copied from my terminal:

    $ date > test.txt
    $ gpg --output test.txt.gpg --encrypt --recipient marco@hulten.org test.txt
    $ gpg --decrypt test.txt.gpg 
    gpg: encrypted with 4096-bit RSA key, ID 54AE7D44B93BDBDF, created 2019-05-30
          "Marco van Hulten (publiko) <marco@hulten.org>"
    gpg: public key decryption failed: No pinentry
    gpg: decryption failed: No secret key

> I tried killing gpg-agent to be sure it uses the current configuration,
> but again it complains about pinentry.
> 
> Apropos, I this e-mail is signed with this very key.
> 
> —Marco

[-- Attachment #2: OpenPGP digitale handtekening --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-19  9:02     ` Marco van Hulten
@ 2019-12-20  9:49       ` Marco van Hulten
  2019-12-20 19:12         ` Gábor Boskovits
  0 siblings, 1 reply; 8+ messages in thread
From: Marco van Hulten @ 2019-12-20  9:49 UTC (permalink / raw)
  To: help-guix

Following up on my pinentry issue—

In the end I used a work-around.  I decrypted the sensitive file on an
off-line OpenBSD machine onto a mounted USB flash drive, then mounted
the drive to the Guix machine, did what I needed to do with the file,
shredded any copy of the file and finally removed the USB drive and
destroyed it with a hammer.

—Marco

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-20  9:49       ` Marco van Hulten
@ 2019-12-20 19:12         ` Gábor Boskovits
  2019-12-20 21:15           ` Marco van Hulten
  0 siblings, 1 reply; 8+ messages in thread
From: Gábor Boskovits @ 2019-12-20 19:12 UTC (permalink / raw)
  To: Marco van Hulten; +Cc: help-guix

Hello Marco,

Marco van Hulten <marco@hulten.org> ezt írta (időpont: 2019. dec. 20.,
P, 10:49):
>
> Following up on my pinentry issue—
>
> In the end I used a work-around.  I decrypted the sensitive file on an
> off-line OpenBSD machine onto a mounted USB flash drive, then mounted
> the drive to the Guix machine, did what I needed to do with the file,
> shredded any copy of the file and finally removed the USB drive and
> destroyed it with a hammer.

I am sorry that this ended up like this.

If you still have the patience to experiment a little could you try
with pinentry-tty on the console and pinentry-gtk on a gui?

It might be a valuable experience, and a feedback that our simple
pinentry is faulty in some ways.

I have extracted the inforamtions from my config, and it looks like this:

manifest: (specifications->manifest '("gnupg" "pinentry-tty"))

I also use guix home-manager on this particular machine, the related
config items look like:

(define gpg-agent.conf
(plain-file "gpg-agent.conf" "
pinentry-program /home/<username>/.guix-profile/bin/pinentry
"))

and

(home
 (data-directory "/data/<username>")
 (configurations
  (list (simple-file-home gpg-agent.conf
".home-config/.gunpg/gpg-agent.conf"))))

I am using bash, and I also have:

At the end of my .bashrc:
export GPG_TTY=$(tty)

And at the end of my .bash_profile:

gpg-agent --options /home/gabriel/.home-config/.gnupg/gpg-agent.conf --daemon

I believe that is all.

Could you have a look if it works for you with these settings? Also,
please not that these are for console only use, most probably some
other tweaks are needed to use this form a gui.
>
> —Marco
>

Best regards,
g_bor
-- 
OpenPGP Key Fingerprint: 7988:3B9F:7D6A:4DBF:3719:0367:2506:A96C:CF63:0B21

^ permalink raw reply	[flat|nested] 8+ messages in thread

* Re: gpg-agent error: No pinentry
  2019-12-20 19:12         ` Gábor Boskovits
@ 2019-12-20 21:15           ` Marco van Hulten
  0 siblings, 0 replies; 8+ messages in thread
From: Marco van Hulten @ 2019-12-20 21:15 UTC (permalink / raw)
  To: Gábor Boskovits; +Cc: help-guix

Gábor—

Thank you for the help: the issue might have been solved, at least
sometimes (sort-of explanation follows)!

Je 20 dec 20:12 skribis Gábor:
> If you still have the patience to experiment a little could you try
> with pinentry-tty on the console and pinentry-gtk on a gui?

Yes, I just had a little bit of time before the new year.  (Christmas is
a holiday, they say!)

> It might be a valuable experience, and a feedback that our simple
> pinentry is faulty in some ways.
> 
> I have extracted the inforamtions from my config, and it looks like this:
> 
> manifest: (specifications->manifest '("gnupg" "pinentry-tty"))
> 
> I also use guix home-manager [...]

A guix home-manager sounds intriguing.  I alluded to it once when
asking why we wouldn't define the state of the whole computing
environment.  But it adds a layer of complexity and so I don't think it
would be very useful to use this to analyse the problem I'm having.

> I am using bash, and I also have:
> 
> At the end of my .bashrc:
> export GPG_TTY=$(tty)
> 
> And at the end of my .bash_profile:
> 
> gpg-agent --options /home/gabriel/.home-config/.gnupg/gpg-agent.conf --daemon
> 
> I believe that is all.
> 
> Could you have a look if it works for you with these settings? Also,
> please not that these are for console only use, most probably some
> other tweaks are needed to use this form a gui.

Yes, this helps!  That is, when I set GPG_TTY and started the gpg-agent
like this, 'gpg --import' and 'gpg -d' started to work without
complaining about pinentry.  But then I tried the same as another user
and there it still complained.  So I went back to the first user again,
removed the GPG_TTY variable and killed the gpg-agent, but now it does
not complain anymore about pinentry anymore at all.

I don't understand what's going on, but for now I'll just add the export
and gpg-agent commands in my .bashrc since that seemed to do the trick
at least once.

    export GPG_TTY=$(tty)
    gpg-agent --options ${HOME}/.gnupg/gpg-agent.conf --daemon

—Marco

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2019-12-20 21:15 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-12-18 21:41 gpg-agent error: No pinentry Marco van Hulten
2019-12-18 21:50 ` Andreas Enge
2019-12-19  8:22   ` Marco van Hulten
2019-12-19  9:02     ` Marco van Hulten
2019-12-20  9:49       ` Marco van Hulten
2019-12-20 19:12         ` Gábor Boskovits
2019-12-20 21:15           ` Marco van Hulten
2019-12-18 21:52 ` Gábor Boskovits

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).