Encriptación con gpg

Hola compañeros de la shell,

En esta entrada vamos a recopilar una serie de ejecuciones que utilizan el programa gpg para encriptar y desencriptar mensajes. Por supuesto, antes de comenzar a utilizar esta herramienta recomendamos la lectura de la documentación oficial https://www.gnupg.org/gph/es/manual.html ya que en ella se explica al detalle el funcionamiento de la herramienta gpg así como nociones básicas sobre criptografía.

  • Encriptación simétrica (una clave para cifrar y descifrar el mensaje):

Encriptar fichero con clave simetrica (solicitará passprhase con la que encriptar el mensaje):

gpg --symmetric foo.txt

Desencriptar fichero con clave simetrica (solicitará passphase con la que el fichero fue encriptado):

gpg --decrypt foo.txt.gpg
  • Encriptación asimétrica (clave pública para encriptar el mensaje y clave privada para desencriptarlo):

A continuación el comando para generar un par de claves (pública y privada) usando gpg:

gpg --full-generate-key
gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

Please select what kind of key you want:
   (1) RSA and RSA (default)
   (2) DSA and Elgamal
   (3) DSA (sign only)
   (4) RSA (sign only)
  (14) Existing key from card
Your selection? 2
DSA keys may be between 1024 and 3072 bits long.
What keysize do you want? (2048) 
Requested keysize is 2048 bits
Please specify how long the key should be valid.
         0 = key does not expire
      <n>  = key expires in n days
      <n>w = key expires in n weeks
      <n>m = key expires in n months
      <n>y = key expires in n years
Key is valid for? (0) 1y
Key expires at dom 10 nov 2024 13:26:20 CET
Is this correct? (y/N) y

GnuPG needs to construct a user ID to identify your key.

Real name: Eduardo Marina Almazan
Email address: *****@gmail.com
Comment: Par de claves de test
You selected this USER-ID:
    "Eduardo Marina Almazan (Par de claves de test) <*****@gmail.com>"

Change (N)ame, (C)omment, (E)mail or (O)kay/(Q)uit? O
We need to generate a lot of random bytes. It is a good idea to perform
some other action (type on the keyboard, move the mouse, utilize the
disks) during the prime generation; this gives the random number
generator a better chance to gain enough entropy.
gpg: WARNING: some OpenPGP programs can't handle a DSA key with this digest size
We need to generate a lot of random bytes. It is a good idea to perform
some other action (type on the keyboard, move the mouse, utilize the
disks) during the prime generation; this gives the random number
generator a better chance to gain enough entropy.
gpg: key 179C2A84B37498BD marked as ultimately trusted
gpg: revocation certificate stored as '/home/dudumarina/.gnupg/openpgp-revocs.d/E11A6E840D61B25D528D53A3179C2A84B37498BD.rev'
public and secret key created and signed.

pub   dsa2048 2023-11-11 [SC] [expires: 2024-11-10]
      E11A6E840D61B25D528D53A3179C2A84B37498BD
uid                      Eduardo Marina Almazan (Par de claves de test) <*****@gmail.com>
sub   elg2048 2023-11-11 [E] [expires: 2024-11-10]

Ver las claves públicas dentro del anillo:

gpg --list-keys

Ver claves privadas dentro del anillo:

gpg --list-secret-keys
  • Publicar clave publica en servidor de claves pgp (Ej.: keys.openpgp.org):
gpg --send-keys --keyserver keys.openpgp.org keyID

Buscar clave pública en servidor de claves pgp:

gpg --keyserver keys.openpgp.org --search-keys keyID

Descargar una clave pública de servidor de claves pgp:

gpg --keyserver keys.openpgp.org --recv-keys keyID
  • Gestión de claves en host local:

Exportar clave pública a un fichero:

pg --armor --output public_key_file --export keyID

Exportar clave privada a un fichero:

gpg --armor --output private_key_file --export-secret-key keyID

Importar clave de un fichero:

gpg --import key_file
  • Encriptar y desencriptar ficheros con clave asimétrica:

Encriptar mensaje con clave pública asimétrica:

gpg --output encrypted_with_public_key.gpg --encrypt --recipient KeyID file_name_to_encrypt

Desencriptar mensaje con clave privada asimétrica:

gpg --output unencrypted_file --decrypt encrypted_with_your_public_key.gpg

Espero que os sirva, nos vemos al otro lado de la pantalla negra.

Esta entrada fue publicada en Sin categoría. Guarda el enlace permanente.

Deja una respuesta

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *