Re: Re: GPG Agent
Maxim Britov <[email protected]> Fri, 16 Jan 2004 21:18:27 +0200
| Newsgroups | gmane.comp.security.pgp-n-gpg |
|---|---|
| Organization | Modum.by |
| Message-ID | <[email protected]> |
--Signature=_Fri__16_Jan_2004_21_18_27_+0200_We/OXbNZfwnqALZc
Content-Type: text/plain; charset=KOI8-R
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
> >> =EB=D3=D4=C1=D4=C9, =D0=D2=CF=D1=D3=CE=C9=D4=C5 =D3=C9=D4=D5=C1=C3=C9=
=C0 -- =D3=D4=C1=D7=C9=D4=D3=D1 =CC=C9 agent =CF=D4=C4=C5=CC=D8=CE=CF =C9=
=CC=C9 =CF=CE =D7=C8=CF=C4=C9=D4
> >> =D4=CF=CC=D8=CB=CF =D7 GPG 1.9?
> >>
> > pinentry 0.6.9 - =EB=C1=D6=C5=D4=D3=D1 =D7=CF=D4 =DC=D4=CF =C1=C7=C5=CE=
=D4 (=CB=CF=D4=CF=D2=D9=CA =CF=D4=C4=C5=CC=D8=CE=CF =D3=D4=C1=D7=C9=D4=D3=
=D1, =D1
> > =CE=C5 =D5=D7=C5=D2=C5=CE =CF=CE =CC=C9 =D7=C8=CF=C4=C9=D4 =D7 =D7=C5=
=D4=CB=D5 GPG 1.9, =CE=CF =D0=D2=C9 =CF=C2=D3=D5=D6=C4=C5=CE=C9=D1=C8 gpg-a=
gent -
> > =C1 =DE=C1=D3=D4=CF =D5=D0=CF=CD=C9=CE=C1=C5=D4=D3=D1 =C9=CD=C5=CE=CE=
=CF =CF=CE, =CE=CF =D1 =C9=CD =CE=C5 =D0=CF=CC=D8=DA=CF=D7=C1=CC=D3=D1, =C9=
=CE=C9=DE=C5=C7=CF
> > =D3=CB=C1=DA=C1=D4=D8 =CE=C5 =CD=CF=C7=D5)
>=20
> pinentry -- =DC=D4=CF =CE=C1=D7=C5=D2=CE=CF=C5 =C4=CC=D1 pine? =F7=D2=CF=
=C4=C5 =D6=C5 =C2=D9=CC =CB=C1=CB=CF=CA-=D4=CF =CF=D4=C4=C5=CC=D8=CE=D9=CA
> gpg-agent =CF=D4 =D2=C1=DA=D2=C1=C2=CF=D4=DE=C9=CB=CF=D7 gpg? =F7=CF=D4 =
=CB=C1=CB =D2=C1=DA =D7 GPG 1.9...
=F0=CF =D3=D3=D9=CC=CB=C5 http://www.gnupg.org/aegypten/tech.en.html :
GpgAgent
This module takes over multiple tasks:
* It takes over all cryptographic operations requiering a private key.
* It manages both the Soft-PSEs and the Token PSE.
* It saves the fingerprint of the root certificate.
* It delegates operations to a krypto token, using the standards PKCS11=
, PKCS12 and PKCS15.
* Optionally, it is capable of assuring the integrity of the system (i.=
e. it's modules and certain keys). To assure this, it uses a MAC, whose key=
is derived from a PIN.
* It offers functionality for both import and export of the private key=
s.
* It generates new key-pairs.=20
For querying the PIN, the GpgAgent uses the PIN Entry-module. Special measu=
res to protect the sensitive information are implemented here (e.g. to prot=
ect information from being swapped to the harddrive).
The design of this modules interface enables the module to be completely im=
plemented on a seperate hardware module.
--=20
MaxBritov
GnuPG KeyID 0x4580A6D66F3DB1FB Keyserver hkp://keyserver.kjsl.com
Fingerprint: 4059 B5C5 8985 5A47 8F5A 8623 4580 A6D6 6F3D B1FB
--Signature=_Fri__16_Jan_2004_21_18_27_+0200_We/OXbNZfwnqALZc
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.3.5-cvs (GNU/Linux)
iQEVAwUBQAg5C1JphUrYR8fHAQIldwgAqumQgeATIZTZ6x0pyAgCJY4SrxtFNxXa
9cjNNV5RJVwOghtaUoZ3QSzYwEB1B6TsYhtOLPThcS7tJ8i/gBLCnUsYCagraH+A
bQMocNJ/CND1KWQH2soWu4y3QDNv0rgOjL+RvZO0UCmjhwDTwXhqwvTTAdDC+s1t
qbiHsHBPmt37FMZRNFM4rMfnz/t7oRRWPYW4D9Paq2D6CggMdQWs/zw0vvOmSytm
adtBQxJqQFY6LZqUMCZf0Qg70nPfzPd7MCRkwae39Y6UdW86upj6P+8IZE3teyBF
07VEw8/IzBtLUsWdDH+tI+NQyzR2Z+GPX5JaMJx3sNFKUo7eZZSakg==
=h8Ab
-----END PGP SIGNATURE-----
--Signature=_Fri__16_Jan_2004_21_18_27_+0200_We/OXbNZfwnqALZc--