duplicity-talk
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Duplicity-talk] PASSPHRASE, the environment, memory, etc.


From: Charles Duffy
Subject: Re: [Duplicity-talk] PASSPHRASE, the environment, memory, etc.
Date: Fri, 13 Apr 2007 04:58:01 -0500
User-agent: Thunderbird 2.0.0.0 (Windows/20070326)

Neal Clark wrote:
so I'm not sure how I could specify the --encrypt option to say "use the public key and not the private key and don't ask me for a password." Do I do something on the gpg end, changing the public key's ID somehow or something to that effect (c/f above, only experienced with encrypting e-mails :)

GPG doesn't need the private key to encrypt; it needs the private key to *sign*. So what you lose when you get rid of the private key is the ability to detect whether your backup has been tampered with (but anyone who captures the private key could then tamper with it anyway).

Tell GPG to encrypt without signing, and you should be able to take the private key out of your private keyring. (You'll need to keep it somewhere to be able to do restores, of course).




reply via email to

[Prev in Thread] Current Thread [Next in Thread]