mirror of
https://github.com/thetechprepper/emcomm-tools-os-community.git
synced 2026-09-17 15:41:44 -04:00
Merge pull request #96 from thetechprepper/feature/offline-gpg
Merge feature/offline-gpg to release/r6
This commit is contained in:
+4
-3
@@ -1,7 +1,7 @@
|
||||
# ETC Regression Tests
|
||||
|
||||
- **Build**: ETC R6 Build 9
|
||||
- **Date**: 14 March 2026
|
||||
- **Build**: ETC R6 Build 10
|
||||
- **Date**: 19 March 2026
|
||||
|
||||
## Desktop/Launcher Icons
|
||||
|
||||
@@ -127,4 +127,5 @@
|
||||
## Offline Resources
|
||||
|
||||
* [ ] `offline` folder on Desktop
|
||||
* [ ] List of public nets avaiable
|
||||
* [ ] Check `nets` folder for `amrron` and `ghostnet`
|
||||
* [ ] Test gpg signature verifcation gpg crypto doc
|
||||
|
||||
@@ -0,0 +1,264 @@
|
||||
---
|
||||
title: "GNU Privacy Guard: Crypto Cheatsheet"
|
||||
date: 2026-03-19
|
||||
updated: 2026-03-19
|
||||
author: [The Tech Prepper]
|
||||
categories: [cryptography]
|
||||
tags: [gpg, pgp]
|
||||
copyright: "(C) 2026 The Tech Prepper, LLC"
|
||||
---
|
||||
|
||||
This is an in-progress cheatsheet for performing basic cryptographic
|
||||
functions using GNU Privacy Guard (gpg), including encrypting,
|
||||
decrypting, and verifying files in an offline environment.
|
||||
|
||||
|
||||
## Add Key
|
||||
|
||||
Import a public key into your keyring.
|
||||
|
||||
1. Download the public key from the trusted individual. It can be saved
|
||||
anywhere. For ease of backup, save it under `~/keys/`. Create this
|
||||
directory if it does not exist in your home directory.
|
||||
|
||||
2. Import the key file.
|
||||
|
||||
gpg --import KEYFILE
|
||||
|
||||
3. Verify the key fingerprint. Your trusted source should provide you
|
||||
with the fingerprint. From the example above, the fingerprint is the
|
||||
value starting with `77F8`.
|
||||
|
||||
gpg --fingerprint
|
||||
|
||||
4. Optionally, edit the key and set the trust level. See the "Set Trust
|
||||
Levels" section.
|
||||
|
||||
5. For an off-grid use case, where you trust the key, you can sign it
|
||||
yourself to mark the key valid on your machine.
|
||||
|
||||
gpg --lsign-key FINGERPRINT
|
||||
|
||||
Here's an example from EmComm Tools Community R6 that imports the AmRRON
|
||||
public key.
|
||||
|
||||
```
|
||||
$ gpg --import ~/Desktop/offline/nets/amrron/AmRRON_Actual_ECC_PUBLIC.asc
|
||||
```
|
||||
|
||||
|
||||
## List Public Keys
|
||||
|
||||
List the current public keys on your system.
|
||||
|
||||
```
|
||||
gpg --list-keys
|
||||
```
|
||||
|
||||
Use the following to interpret the keys listed:
|
||||
|
||||
- `pub` - Primary key
|
||||
- Your identity
|
||||
- Used for signing and certifying other keys
|
||||
- `sub` - Subkey
|
||||
- Used for specific operations (usually encryption)
|
||||
- Can be replaced or rotated without changing identity
|
||||
- Can be revoked or rotated if compromised
|
||||
- `[SC]` - Sign + Certify
|
||||
- `[E]` - Encrypt
|
||||
- `unknown|full|ultimate` - See "Set Trust Levels"
|
||||
|
||||
Here's an example showing the AmRRON public key.
|
||||
|
||||
```
|
||||
$ gpg --list-keys
|
||||
/home/ham/.gnupg/pubring.kbx
|
||||
-------------------------------
|
||||
pub ed25519 2023-05-25 [SC]
|
||||
77F888F3524F00C75FF9F91A8D518D7A50612239
|
||||
uid [ unknown] AmRRON Actual (ECC) <amrron@actual.net>
|
||||
sub cv25519 2023-05-25 [E]
|
||||
```
|
||||
|
||||
|
||||
## Verify Signature
|
||||
|
||||
There are two common types of signed files:
|
||||
|
||||
### 1. Embedded Signature
|
||||
|
||||
A single file that contains both the message and the signature. For
|
||||
example, the AmRRON Intelligence Brief (AIB) uses an inline message.
|
||||
|
||||
gpg --verify COMBINEDFILE
|
||||
|
||||
|
||||
### 2. Detached Signature
|
||||
|
||||
A file and a separate signature file.
|
||||
|
||||
gpg --verify SIGNATUREFILE FILE
|
||||
|
||||
Here's an example from EmComm Tools Community R6 that verifies that the
|
||||
AIB distributed by AmRRON on the nationwide net on March 16, 2026 was
|
||||
created by AmRRON.
|
||||
|
||||
```
|
||||
$ gpg --verify ~/Desktop/offline/nets/amrron/NATL-RR-260316-1330Z-AIB-sig.k2s
|
||||
gpg: Signature made Mon 16 Mar 2026 06:22:46 AM MST
|
||||
gpg: using EDDSA key 77F888F3524F00C75FF9F91A8D518D7A50612239
|
||||
gpg: checking the trustdb
|
||||
gpg: marginals needed: 3 completes needed: 1 trust model: pgp
|
||||
gpg: depth: 0 valid: 1 signed: 1 trust: 0-, 0q, 0n, 0m, 0f, 1u
|
||||
gpg: depth: 1 valid: 1 signed: 0 trust: 0-, 0q, 0n, 0m, 1f, 0u
|
||||
gpg: Good signature from "AmRRON Actual (ECC) <amrron@actual.net>" [full]
|
||||
```
|
||||
|
||||
|
||||
## Create Key
|
||||
|
||||
Generate a new private/public key pair using ECC. It is a modern
|
||||
standard that provides strong security and works well for radio use
|
||||
due to smaller key sizes.
|
||||
|
||||
1. Create a primary key for signing using ECC. Replace FIRSTNAME,
|
||||
LASTNAME, and EMAIL (keep the < and > characters).
|
||||
|
||||
gpg --quick-generate-key "FIRSTNAME LASTNAME <EMAIL>" ed25519 sign 0
|
||||
|
||||
2. List your keys and identify the fingerprint of your new key.
|
||||
|
||||
gpg --list-keys
|
||||
|
||||
3. Generate an encryption subkey. Replace FINGERPRINT.
|
||||
|
||||
gpg --quick-add-key FINGERPRINT cv25519 encrypt 0
|
||||
|
||||
4. List your keys again. You should now see a subkey that is suitable
|
||||
for encryption (`[E]`).
|
||||
|
||||
gpg --list-keys
|
||||
|
||||
|
||||
## List Private Keys
|
||||
|
||||
List the current private keys on your system.
|
||||
|
||||
```
|
||||
gpg --list-secret-keys
|
||||
```
|
||||
|
||||
|
||||
## Sign File
|
||||
|
||||
Signing a file allows recipients to verify the sender is authentic
|
||||
and that the file has not been modified in transit.
|
||||
|
||||
Create a test file:
|
||||
|
||||
echo "This is a test file for gpg training." > file.txt
|
||||
|
||||
There are two common ways to sign a file.
|
||||
|
||||
|
||||
### Embedded Signature
|
||||
|
||||
Create a single text file that contains both the message and the
|
||||
signature.
|
||||
|
||||
gpg --clearsign file.txt
|
||||
|
||||
This creates:
|
||||
|
||||
file.txt.asc
|
||||
|
||||
|
||||
### Detached Signature
|
||||
|
||||
Create a separate ASCII signature file for the original file.
|
||||
|
||||
gpg --armor --detach-sign file.txt
|
||||
|
||||
|
||||
## Encrypt / Decrypt File
|
||||
|
||||
Encryption protects a file so that only the intended recipient can
|
||||
read it. Decryption restores the original file using your private key.
|
||||
|
||||
Create a test file:
|
||||
|
||||
echo "This is a test file for gpg training." > file.txt
|
||||
|
||||
|
||||
### Encrypt File
|
||||
|
||||
Encrypt a file for a specific recipient. Replace RECIPIENT with the
|
||||
recipient email or key ID. This command also signs it (`-s`) and
|
||||
encrypts the output as plain ASCII (`--armor`).
|
||||
|
||||
gpg --armor -e -s -r RECIPIENT file.txt
|
||||
|
||||
This creates:
|
||||
|
||||
file.txt.asc
|
||||
|
||||
|
||||
### Decrypt File
|
||||
|
||||
Decrypt a file that was encrypted to you.
|
||||
|
||||
gpg -d file.txt.asc > decrypted.txt
|
||||
|
||||
This creates:
|
||||
|
||||
decrypted.txt
|
||||
|
||||
|
||||
## Set Trust Levels
|
||||
|
||||
Here are common trust levels for basic use:
|
||||
|
||||
- `unknown` - No trust assigned (default)
|
||||
- `full` - You trust this person to sign other keys
|
||||
- `ultimate` - Your own key
|
||||
|
||||
Perform the following steps to change the trust level for a key.
|
||||
|
||||
1. List the keys and identify the key ID (KEYID).
|
||||
|
||||
gpg --list-keys
|
||||
|
||||
2. Replace `KEYID` with the key ID to edit.
|
||||
|
||||
gpg --edit-key KEYID
|
||||
|
||||
3. Type `trust` and press [ENTER].
|
||||
|
||||
4. Type the number for the desired trust level and press [ENTER].
|
||||
|
||||
5. Type `quit` to exit.
|
||||
|
||||
|
||||
## Export Keys
|
||||
|
||||
If you need to back up your keys, export them as follows.
|
||||
|
||||
### Export Public Key
|
||||
|
||||
To export your public key for distribution, run the command below.
|
||||
Replace EMAIL with the email address attached to the key. This file can
|
||||
be shared with your community.
|
||||
|
||||
gpg --export -a EMAIL > public.asc
|
||||
|
||||
### Export Private Key
|
||||
|
||||
WARNING: DO NOT SHARE THIS KEY WITH ANYONE.
|
||||
|
||||
gpg --export-secret-keys -a EMAIL > private.asc
|
||||
|
||||
Restrict permissions to read-only for your user:
|
||||
|
||||
chmod 400 private.asc
|
||||
|
||||
Store this file securely and be careful when moving it between systems.
|
||||
@@ -0,0 +1,21 @@
|
||||
-----BEGIN PGP SIGNED MESSAGE-----
|
||||
Hash: SHA512
|
||||
|
||||
<flmsg>4.0.24.01
|
||||
:hdr_ed:22
|
||||
KF7VII 20261603132148
|
||||
<customform>
|
||||
:mg:1714 CUSTOM_FORM,amrron_blank_Form_V5.00.html
|
||||
L01,AmRRON Nets
|
||||
L02,AmRRON Natl
|
||||
L04,AIB-260316- 1330Z
|
||||
L05,AmRRON Intelligence Brief 16 March 2026
|
||||
L06,T26-Q1 DE U5C; AUTH: ZTW(QB9J) | AmRRON_Actual PGP signature embedded in FLAMP .k2s file\n\nPREC: Routine RRR\n\nCurrent AmCON: Level 3 (THREE)\n\n::::: T-REX 2026 ANNUAL EXERCISE ::::: Fri-Sun, JULY 24th, 25th, & 26th \n\n----\nSOURCE: NationalToday (Rating: B1: New Source) | Nebraska Battles Largest-Ever Wildfire as Over 600,000 Acres Burn\nThe Morrill Fire has burned 460,000 acres and killed one person, while the Cottonwood Fire has burned over 100,000 acres. Bad weather related to a severe winter storm has hampered fire suppression efforts, and high winds are expected to keep aircraft grounded on Sunday.\nNebraska Governor declared an emergency; mobilized the National Guard to respond to the wildfires.\nNational Interagency Fire Center assumed management of the two largest fires, the Morrill Fire and the Cottonwood Fire\n\n----\nSOURCE: YahooNews (Rating: B1) | Oklahoma wildfire evacuations, power outages\nWeekend [wild]fires sparked around the state, worsened by strong winds, prompted thousands to evacuate.\nOn Sunday, emergency managers in Sayre, Oklahoma, in Beckham County ordered neighborhoods to evacuate as fires swept north of the community of about 5,200 people. The order was lifted around 2 p.m. Sunday\nAt the height of the fire activity on Sunday, there were more than 25,000 power outages reported statewide, according to the Oklahoma State Emergency Operations Center.\nAt this time, there are about 8,500 outages remaining. Counties with the highest number of damages are Canadian, Oklahoma, Tulsa, and Cleveland.\n\n\n//EOM//
|
||||
L03,R
|
||||
-----BEGIN PGP SIGNATURE-----
|
||||
|
||||
iHUEARYKAB0WIQR3+IjzUk8Ax1/5+RqNUY16UGEiOQUCabgEJgAKCRCNUY16UGEi
|
||||
Oe0kAPoCi51bp+3Fve8mVi0OSJtfKJT14kDLrwLIcqGMX9DxIAD9Gs/h0B5PpUr/
|
||||
4XVel6DMrxsizsdTZzPfVeqV3PtG9Ao=
|
||||
=v/xX
|
||||
-----END PGP SIGNATURE-----
|
||||
@@ -19,6 +19,16 @@
|
||||
"file": "AmRRON-Intelligence-Brief-White-Paper_MAR_2024.pdf",
|
||||
"dir": "nets/amrron"
|
||||
},
|
||||
{
|
||||
"url": "https://amrron.com/wp-content/uploads/2023/02/GPG-PGP_Signature_Verification_Guidance_5-25-23.pdf",
|
||||
"file": "GPG-PGP_Signature_Verification_Guidance_5-25-23.pdf",
|
||||
"dir": "nets/amrron"
|
||||
},
|
||||
{
|
||||
"url": "https://amrron.com/wp-content/uploads/2023/02/AmRRON_Actual_ECC_PUBLIC.asc",
|
||||
"file": "AmRRON_Actual_ECC_PUBLIC.asc",
|
||||
"dir": "nets/amrron"
|
||||
},
|
||||
{
|
||||
"url": "https://raw.githubusercontent.com/s2underground/GhostNet/1a2d08d579813e54967af06f1a871e7fa0ce583f/GhostNet_Version_1.5.pdf",
|
||||
"file": "GhostNet_Version_1.5.pdf",
|
||||
|
||||
Reference in New Issue
Block a user