Re: Poldi, GPGME, and Auth Keys
Chandler Davis via Gnupg-devel <[email protected]> Wed, 19 Nov 2025 01:08:24 +0000
| Newsgroups | gmane.comp.encryption.gpg.devel |
|---|---|
| Message-ID | <DoxL7FiaFsFOeKTBDwoGYJnJIu5B0FbPYU_KRIvhxfhAUbsjZU8yZ6taL5C2XJmAewvd15OfNFtt2KhoeHKutaxTS3ihqTSBmHFFhafD-Kw=@chandlerdavis.cc> |
Apologies for the email blunder. I have included the original content of the message below. If this happens again, I'll switch to a better email client. --- Hello all, I've been thinking a lot about GPG as an authentication mechanism. Of course this isn't a new idea--I've so far been able to find it being used via gpg-agent for SSH auth, as well as in the poldi project for PAM. However, I was surprised to find that not much else leveraged it. I'm primarily interested in getting PAM working for me, but while spelunking I noticed a few potential opportunities to contribute: 1. It seems poldi has had only a few commits in the past few years, and that there's not much prose about it outside the repo. I also had some trouble getting it to build (though that may well be a skill issue). I'm considering giving it some love, but with that: 2. I wonder if poldi would benefit from using the gpgme library instead of directly going through assuan. If that seems reasonable, it follows that perhaps gpgme would benefit from being able to sign and verify challenges using the auth key on a smart card. I don't believe its currently possible to use the auth key at all via gpgme, but please correct me if I'm wrong. This would make it easier for other things outside of poldi to leverage GPG for auth (without using the signing key, which feels hacky and wrong but is probably workable?). Maybe as a start, it could be good to hack on a reasonable addition to the gpgme interface for auth? I'll probably end up fleshing this out to some extent for my own experimentation and learning, but wanted to share the ideas and discuss before I get too deep. Thanks for humoring me, and wishing everyone a happy holiday season (or otherwise, a tolerable rest of the year)! Best, Chandler Davis _______________________________________________ Gnupg-devel mailing list [email protected] https://lists.gnupg.org/mailman/listinfo/gnupg-devel
publickey - [email protected] - 0x806B3070.asc
(application/pgp-keys, 1.2 KB)
-----BEGIN PGP PUBLIC KEY BLOCK----- xjMEaQ6uERYJKwYBBAHaRw8BAQdAIPKKOe+zE0diRrVyJngquM1MotVQJyoT GuMQljs93p/NJENoYW5kbGVyIERhdmlzIDxtZUBjaGFuZGxlcmRhdmlzLmNj PsKOBBMWCgA2FiEEgGswcAPCWnIj+us0APg8u/VuvoEFAmkOrhECGwEECwkI BwQVCgkIBRYCAwEAAh4BAheAAAoJEAD4PLv1br6BnzIBAPcakqsiqNknXheC Rrr5g68n++n0UUjYiI8cs4gS9ZWtAPwOfpglhn37IkHzm1O09eEOX9Ep6ZJa +TnPMiPcPihnC84zBGkOrk0WCSsGAQQB2kcPAQEHQPtD4iX44psDccW0w/Yx mt/wdeJcHhpOEczYNgPUMUnmwsAvBBgWCgAgFiEEgGswcAPCWnIj+us0APg8 u/VuvoEFAmkOrk0CGwIAgQkQAPg8u/VuvoF2IAQZFgoAHRYhBL7QThr5oYT4 suuONWLnSS+A9vSXBQJpDq5NAAoJEGLnSS+A9vSXiRkBAIIqFGMKpOcW6IeN CkJSY3+vu9Yhy7vY24hj+ncHzrQ3AQCNn2eoTb1lXqNoIXq46Q0O4y5T5e0B I1iEk1HxBVzrD6w4AP4mG4I+7m6luPqWyjX1F8mCsmfpMVDfbMu2a3xAjfGK gAEA4T5j8I/kb8gBQMaAjq2xeTbfEk01iFk3VW+Is+ZS/wjOOARpDq5lEgor BgEEAZdVAQUBAQdAdUnZxWCe4YIrMRWlljl+9McRTxxQC9/L8tUqAu54tlUD AQgHwngEGBYKACAWIQSAazBwA8JaciP66zQA+Dy79W6+gQUCaQ6uZQIbDAAK CRAA+Dy79W6+gccDAQD4pG8+6ymbBZEavRGjon4eihk54JlJB9KpswSvuJXD ZAEAnKgowQmJ/vA4gTSlUEiWi3jQrlIlzmQZgfZ9kxmwkgPOMwRpDq59Fgkr BgEEAdpHDwEBB0CyMQwXa77CNIY+PiU0Mn+0UF9FVudW+KyBLq/2A2nkg8J4 BBgWCgAgFiEEgGswcAPCWnIj+us0APg8u/VuvoEFAmkOrn0CGyAACgkQAPg8 u/VuvoE8VQD+NWZFVZ8MQ5tyVeUkTwZjKAhN7y/Y3QffL4CdFSD0Sc8A/1Rx oqmjJmrbTECrVGzzUR9fkwTsHxglzw4oaadmo8wF =TvwI -----END PGP PUBLIC KEY BLOCK-----
signature.asc
(application/pgp-signature, 343 B)
-----BEGIN PGP SIGNATURE----- Version: ProtonMail wrsEARYKAG0FgmkdGHkJEGLnSS+A9vSXRRQAAAAAABwAIHNhbHRAbm90YXRp b25zLm9wZW5wZ3Bqcy5vcmeJmkVZRomdX9JitklA6ctJnL++ivzA6di5DKfH R18YhxYhBL7QThr5oYT4suuONWLnSS+A9vSXAADtuwEAkaeYWY66VkiFoKn2 5jfULS+cedq9+qZL4QceumxPLKYBAIkYgRefPJ7odJP/kvqgGSBvhTrlo0Kf k9+KYcD16dkI =n0dn -----END PGP SIGNATURE-----