User Tools

Site Tools


informatica:linux:claves_gpg

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
Last revisionBoth sides next revision
informatica:linux:claves_gpg [2013/05/24 09:32] javiinformatica:linux:claves_gpg [2017/02/02 14:31] – [Claves gpg] javi
Line 5: Line 5:
 Para operar con las claves, instalar gunpg: Para operar con las claves, instalar gunpg:
  
-  aptitude install gnupg+  sudo aptitude install gnupg
  
  
Line 216: Line 216:
  
  
 +==== Revocar Clave del Servidor ====
 +Si una clave vamos a dejar de usarla, hay que revocarla.
  
 +Para revocarla, tenemos que crear un certificado de revocación y luego subirlo al servidor. Para crear el certificado de revocación, necesitamos la clave privada. Es aconsejable crear siempre el certificado de revocación.
 +
 +Vamos a revocar la antigua clave de 1024DSA porque hemos generado una nueva de 4096RSA
 +
 +<code>
 +# gpg --list-keys
 +
 +-----------------------------
 +pub   4096R/F4AD9A55 2014-09-15
 +uid                  Jose Legido <jose@legido.com>
 +sub   4096R/BAB57DE6 2014-09-15
 +
 +pub   1024D/5A988F96 2008-03-20
 +uid                  Jose Legido <jose@legido.com>
 +sub   2048g/9BC56CC9 2008-03-20
 +
 +</code>
 +<code>
 +# gpg --output revoke1024.asc --gen-revoke 5A988F96
 +
 +sec  1024D/5A988F96 2008-03-20 Jose Legido <jose@legido.com>
 +Create a revocation certificate for this key? (y/N) y
 +Please select the reason for the revocation:
 +  0 = No reason specified
 +  1 = Key has been compromised
 +  2 = Key is superseded
 +  3 = Key is no longer used
 +  Q = Cancel
 +(Probably you want to select 1 here)
 +Your decision? 3
 +Enter an optional description; end it with an empty line:
 +> New Key F4AD9A55
 +>
 +Reason for revocation: Key is no longer used
 +New Key F4AD9A55
 +Is this okay? (y/N) y
 +
 +You need a passphrase to unlock the secret key for
 +user: "Jose Legido <jose@legido.com>"
 +1024-bit DSA key, ID 5A988F96, created 2008-03-20
 +
 +ASCII armored output forced.
 +Revocation certificate created.
 +
 +Please move it to a medium which you can hide away; if Mallory gets
 +access to this certificate he can use it to make your key unusable.
 +It is smart to print this certificate and store it away, just in case
 +your media become unreadable.  But have some caution:  The print system of
 +your machine might store the data and make it available to others!
 +</code>
 +
 +Ahora subimos el certificado de revocación para revocar la clave:
 +<code>
 +# gpg --import revoke1024.asc
 +gpg: key 5A988F96: "Jose Legido <jose@legido.com>" revocation certificate imported
 +gpg: Total number processed: 1
 +gpg:    new key revocations: 1
 +gpg: 3 marginal(s) needed, 1 complete(s) needed, PGP trust model
 +gpg: depth: 0  valid:    signed:    trust: 0-, 0q, 0n, 0m, 0f, 1u
 +</code>
 +
 +Al cabo de un rato, la clave aparece como revocada:
 +<code>
 +# gpg --search-keys jose@legido.com
 +gpg: searching for "jose@legido.com" from hkp server keys.gnupg.net
 +(1) Jose Legido <jose@legido.com>
 +   4096 bit RSA key F4AD9A55, created: 2014-09-15
 +(2) Jose Legido <jose@legido.com>
 +   1024 bit DSA key 5A988F96, created: 2008-03-20 (revoked)
 +
 +</code>
  
 ==== Descargar claves a servidor de claves ==== ==== Descargar claves a servidor de claves ====
informatica/linux/claves_gpg.txt · Last modified: 2023/11/30 14:04 by jose