this post was submitted on 20 Jun 2023
7 points (88.9% liked)

Sysadmin

7713 readers
2 users here now

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
!lemmy@lemmy.ml
!lemmyworld@lemmy.world
!lemmy_support@lemmy.ml
!support@lemmy.world

founded 1 year ago
MODERATORS
 

I'm interested to know whether you have a specific process or tool you use for managing your PGP keys?

I was thinking it'd be great if Lemmy allowed you to use PGP to verify your identity across multiple users on different instances. This made me think I need a good way to make sure I never lose my keys!

top 4 comments
sorted by: hot top controversial new old
[–] bbigras@sh.itjust.works 4 points 1 year ago

Not as the only way but using paperkey might be a good idea too.

[–] benkinder@infosec.pub 3 points 1 year ago

I install my keys on 5 Yubikeys and then encrypt a copy of the private key so that it can only be decrypted with one of the Yubikeys. I store the encrypted bundle on Google drive and I’ve spread out the Yubikeys a little geographically by sending them to friends who I trust (PIN is still required to use the Yubikey so there’s still a layer of security). I also keep one of them in a safe at my house just in case.

I do feel like I may have gone a little overboard but maybe something similar could work for you!

[–] PetrichorBias@lemmy.one 2 points 1 year ago

In a password manager (keepass2)

[–] pragma@lemmy.zip 1 points 1 year ago

I have mine in a Kleopatra keychain for convenience, but I also keep backups in a KeePassXC encrypted database for security. They are essentially text files, so you can treat them the same way as you treat your passwords. I hope this helps.