The GNU Privacy Handbook (1999)(gnupg.org) |
The GNU Privacy Handbook (1999)(gnupg.org) |
https://emailselfdefense.fsf.org/
Tactical Tech's Security in-a-Box has more detailed, step-by-step, multiple platform guides for the same tools:
https://securityinabox.org/en/guide/thunderbird/windows
But there were some important differences. Newer GnuPG versions have simplified how gpg-agent takes the place of ssh-agent. Nowadays, it's enough to create an SSH_AUTH_SOCK environment variable that points to ~/.gnupg/S.gpg-agent.ssh
Also, I found the air-gapped system setup described there and elsewhere to be excessively difficult. Far and away the easiest way to create an air-gapped key generating machine was to install OpenBSD to a USB key (you can boot the mini install image and overwrite the same device). Installing the gpg2 package gives you a complete gnupg environment for interacting with OpenPGP smart cards. By contrast, there were a bunch of packages to install with Ubuntu / Debian.
It was a little hairy to set up in total, but I really love my Yubikey-mediated GPG setup. I also now use password-store for passwords, complete with dmenu integration.
I'm not super happy that the Yubikey 4 isn't 100% open hardware though. If someone has a recommendation for something that is, and supports 4096 bit keys, I'd gladly hear it.
Interesting as a historic artefact, but please don't follow this guide, search for something more recent.
The DSA key recommendation is terrible, either go 4096 RSA or Ed25519/Curve25519.
Secondly, use whatever keyring manager your distro has available and that supports your keys and is nice to use. GPA is okay-ish and offers most options.