[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: gpg passphrase and package building



I have had a look at quintuple-agent.

First the passphrase is not securely stored. I believe it's ok on my
laptop giving the fact that I will use it only in a short window timeframe
and that I don't allow other users on the laptop.

Second problem it doesn't check if the passphrase is correct and then
when you type a wrong passphrase lead to a gpg error.

I will use it as in the following script, comments are welcome.

Christophe

-- 
Christophe Barbé <christophe.barbe@ufies.org>
GnuPG FingerPrint: E0F6 FADF 2A5C F072 6AF8  F67A 8F45 2F1E D72C B41E

As every cat owner knows, nobody owns a cat.
--Ellen Perry Berkeley

Attachment: test-gpg-agent.sh
Description: Bourne shell script

Attachment: pgpe0eSv4cmDj.pgp
Description: PGP signature


Reply to: