v2.3 of gnupg for automation?

Werner Koch wk at gnupg.org
Wed Oct 27 09:33:16 CEST 2021


On Tue, 26 Oct 2021 18:21, Robert J. Hansen said:

> That's true, and is correct.  If you're passing a passphrase via the
> command line, that passphrase becomes visible to anyone with the
> privileges to get a list of processes and arguments.  At that point the
> passphrase really isn't providing much in the way of security.

I fully agree.

If, for whatever reasons, a passphrase is required the suggested
workaround is to add

  --pinentry-mode=loopback

to the gpg invocation.


Salam-Shalom,

   Werner

-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 227 bytes
Desc: not available
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20211027/505c2e7d/attachment.sig>


More information about the Gnupg-users mailing list