Gentoo Archives: gentoo-user

From: Grant <emailgrant@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] {OT} GPG: pub & sec keys required to decrypt?
Date: Thu, 11 Sep 2008 14:53:07
Message-Id: 49bf44f10809110753q2264d59k7035391ea19cfe79@mail.gmail.com
In Reply to: Re: [gentoo-user] {OT} GPG: pub & sec keys required to decrypt? by Mike Edenfield
1 >>>> Can I configure this so that I don't have the two keys on the same
2 >>>> system? I'd like encrypt with my remote system and decrypt with my
3 >>>> local system. Is that possible? It seems like importing my private
4 >>>> key also imports the public key.
5 >>>
6 >>> I'm a bit confused as to what you're trying to do. If you are encrypting
7 >>> mail to other people, you should be using *their* public key, not your
8 >>> own.
9 >>> The only case where you need your public key is to encrypt mail to
10 >>> *yourself*; otherwise you don't need either of your keys on the remote
11 >>> system.
12 >
13 >> Should I delete the private key from the remote system? It sounds
14 >> like the public key can always be regenerated from the private key so
15 >> there's no use in deleting it from the local system.
16 >
17 > Yes to both statements. Having your private key on the remote system is an
18 > unnecessary risk, since you don't need it to encrypt data and it's exposed
19 > to anyone else with access to that system. And, though I haven't done it,
20 > GnuPG's docs say that the public key can easily (one gpg command) be
21 > regenerated from the private key, so you may as well keep it around for
22 > convenience.
23
24 Perfect, thanks everyone.
25
26 - Grant