GPG & AGE ENCRYPTION
GPG KEY GENERATION#
gpg --gen-key # Quick generation gpg --full-gen-key # Full options (recommended) # Choose: RSA+RSA, 4096 bits, expiry 2y gpg --list-keys # List public keys gpg --list-secret-keys # List private keys gpg --list-keys --keyid-format=long # Show key IDs
GPG KEY MANAGEMENT#
# Export keys gpg --export -a "user@example.com" > public.asc gpg --export-secret-keys -a "user@example.com" > private.asc # Import keys gpg --import public.asc gpg --import private.asc # Delete keys gpg --delete-key "user@example.com" gpg --delete-secret-key "user@example.com" # Trust a key gpg --edit-key "user@example.com" gpg> trust # Select trust level (5 = ultimate for your own keys) gpg> quit # Generate revocation certificate gpg --gen-revoke "user@example.com" > revoke.asc # Revoke a key gpg --import revoke.asc
GPG ENCRYPTION#
# Symmetric (password-based) gpg -c file.txt # Encrypt with passphrase gpg -c --cipher-algo AES256 file.txt # Specify cipher gpg -d file.txt.gpg # Decrypt # Asymmetric (public key) gpg -e -r "recipient@example.com" file.txt # Encrypt gpg -e -r "user1" -r "user2" file.txt # Multiple recipients gpg -d file.txt.gpg # Decrypt (auto-finds key) # Encrypt and sign gpg -se -r "recipient@example.com" file.txt # Encrypt to stdout gpg -e -r "recipient" --armor < file.txt > encrypted.asc # Decrypt from stdin cat encrypted.asc | gpg -d > decrypted.txt
GPG SIGNING#
# Sign a file (creates .sig) gpg -s file.txt # Binary signature gpg --clearsign file.txt # Cleartext signature gpg -b file.txt # Detached signature gpg --armor -b file.txt # Detached ASCII signature # Verify signature gpg --verify file.txt.sig file.txt gpg --verify file.txt.asc
GPG AGENT#
# Cache passphrase gpg-agent --daemon echo "default-cache-ttl 3600" >> ~/.gnupg/gpg-agent.conf echo "max-cache-ttl 7200" >> ~/.gnupg/gpg-agent.conf gpg-connect-agent reloadagent /bye
GPG BEST PRACTICES#
# Use Ed25519 or RSA 4096 # Set key expiration (1-2 years) # Create subkeys for signing and encryption # Keep master key offline # Use strong passphrase # Backup keys securely # Publish to keyserver gpg --keyserver hkps://keys.openpgp.org --send-keys KEY_ID ===================================
AGE - MODERN ENCRYPTION TOOL#
INSTALLATION#
# macOS brew install age # Linux apt install age # Debian/Ubuntu # Or download from https://github.com/FiloSottile/age
AGE KEY GENERATION#
# Generate X25519 key pair age-keygen -o key.txt # Output: public key to stdout, private key to file # Public key format: age1... # Private key format: AGE-SECRET-KEY-1...
AGE ENCRYPT / DECRYPT#
# Encrypt to recipient age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p -o file.age file.txt # Encrypt to multiple recipients age -r age1... -r age1... -o file.age file.txt # Encrypt with recipients file age -R recipients.txt -o file.age file.txt # Decrypt age -d -i key.txt -o file.txt file.age # Passphrase encryption (symmetric) age -p -o file.age file.txt # Encrypt (prompts for passphrase) age -d -o file.txt file.age # Decrypt (prompts for passphrase) # Pipe support cat file.txt | age -r age1... > file.age cat file.age | age -d -i key.txt > file.txt # Armor (ASCII output) age -r age1... -a -o file.age.txt file.txt
AGE WITH SSH KEYS#
# Encrypt using SSH public key age -R ~/.ssh/id_ed25519.pub -o file.age file.txt # Decrypt using SSH private key age -d -i ~/.ssh/id_ed25519 -o file.txt file.age # Encrypt using GitHub user's SSH keys curl https://github.com/username.keys | age -R - -o file.age file.txt
AGE VS GPG COMPARISON#
Feature | GPG | age -----------------|---------------|---------------- Key format | PGP keys | X25519/SSH Complexity | High | Minimal Web of trust | Yes | No Signing | Yes | No (use signify) Symmetric | Yes | Yes (passphrase) SSH key support | No | Yes Config files | Many | None Key management | Complex | Simple Streaming | Yes | Yes Audit | Complex | Easy (small codebase)
PRACTICAL WORKFLOWS#
# Encrypt backup tar czf - /important/data | age -r age1... > backup.tar.gz.age # Decrypt and extract age -d -i key.txt backup.tar.gz.age | tar xzf - # Encrypt for team (age) age -R team-keys.txt -o secrets.age secrets.env # Store encrypted secrets in git (age) age -R .age-recipients -o .env.age .env echo ".env" >> .gitignore git add .env.age .age-recipients # sops integration (age) export SOPS_AGE_KEY_FILE=~/.config/sops/age/keys.txt sops -e --age age1... secrets.yaml > secrets.enc.yaml sops -d secrets.enc.yaml > secrets.yaml
GPG & AGE ENCRYPTION CHEATSHEET ================================== Source: https://cheatsheet.johlem.net GPG KEY GENERATION ------------------ gpg --gen-key # Quick generation gpg --full-gen-key # Full options (recommended) # Choose: RSA+RSA, 4096 bits, expiry 2y gpg --list-keys # List public keys gpg --list-secret-keys # List private keys gpg --list-keys --keyid-format=long # Show key IDs GPG KEY MANAGEMENT ------------------ # Export keys gpg --export -a "user@example.com" > public.asc gpg --export-secret-keys -a "user@example.com" > private.asc # Import keys gpg --import public.asc gpg --import private.asc # Delete keys gpg --delete-key "user@example.com" gpg --delete-secret-key "user@example.com" # Trust a key gpg --edit-key "user@example.com" gpg> trust # Select trust level (5 = ultimate for your own keys) gpg> quit # Generate revocation certificate gpg --gen-revoke "user@example.com" > revoke.asc # Revoke a key gpg --import revoke.asc GPG ENCRYPTION -------------- # Symmetric (password-based) gpg -c file.txt # Encrypt with passphrase gpg -c --cipher-algo AES256 file.txt # Specify cipher gpg -d file.txt.gpg # Decrypt # Asymmetric (public key) gpg -e -r "recipient@example.com" file.txt # Encrypt gpg -e -r "user1" -r "user2" file.txt # Multiple recipients gpg -d file.txt.gpg # Decrypt (auto-finds key) # Encrypt and sign gpg -se -r "recipient@example.com" file.txt # Encrypt to stdout gpg -e -r "recipient" --armor < file.txt > encrypted.asc # Decrypt from stdin cat encrypted.asc | gpg -d > decrypted.txt GPG SIGNING ----------- # Sign a file (creates .sig) gpg -s file.txt # Binary signature gpg --clearsign file.txt # Cleartext signature gpg -b file.txt # Detached signature gpg --armor -b file.txt # Detached ASCII signature # Verify signature gpg --verify file.txt.sig file.txt gpg --verify file.txt.asc GPG AGENT --------- # Cache passphrase gpg-agent --daemon echo "default-cache-ttl 3600" >> ~/.gnupg/gpg-agent.conf echo "max-cache-ttl 7200" >> ~/.gnupg/gpg-agent.conf gpg-connect-agent reloadagent /bye GPG BEST PRACTICES ------------------- # Use Ed25519 or RSA 4096 # Set key expiration (1-2 years) # Create subkeys for signing and encryption # Keep master key offline # Use strong passphrase # Backup keys securely # Publish to keyserver gpg --keyserver hkps://keys.openpgp.org --send-keys KEY_ID =================================== AGE - MODERN ENCRYPTION TOOL =================================== INSTALLATION ------------ # macOS brew install age # Linux apt install age # Debian/Ubuntu # Or download from https://github.com/FiloSottile/age AGE KEY GENERATION ------------------ # Generate X25519 key pair age-keygen -o key.txt # Output: public key to stdout, private key to file # Public key format: age1... # Private key format: AGE-SECRET-KEY-1... AGE ENCRYPT / DECRYPT ----------------------- # Encrypt to recipient age -r age1ql3z7hjy54pw3hyww5ayyfg7zqgvc7w3j2elw8zmrj2kg5sfn9aqmcac8p -o file.age file.txt # Encrypt to multiple recipients age -r age1... -r age1... -o file.age file.txt # Encrypt with recipients file age -R recipients.txt -o file.age file.txt # Decrypt age -d -i key.txt -o file.txt file.age # Passphrase encryption (symmetric) age -p -o file.age file.txt # Encrypt (prompts for passphrase) age -d -o file.txt file.age # Decrypt (prompts for passphrase) # Pipe support cat file.txt | age -r age1... > file.age cat file.age | age -d -i key.txt > file.txt # Armor (ASCII output) age -r age1... -a -o file.age.txt file.txt AGE WITH SSH KEYS ----------------- # Encrypt using SSH public key age -R ~/.ssh/id_ed25519.pub -o file.age file.txt # Decrypt using SSH private key age -d -i ~/.ssh/id_ed25519 -o file.txt file.age # Encrypt using GitHub user's SSH keys curl https://github.com/username.keys | age -R - -o file.age file.txt AGE VS GPG COMPARISON ----------------------- Feature | GPG | age -----------------|---------------|---------------- Key format | PGP keys | X25519/SSH Complexity | High | Minimal Web of trust | Yes | No Signing | Yes | No (use signify) Symmetric | Yes | Yes (passphrase) SSH key support | No | Yes Config files | Many | None Key management | Complex | Simple Streaming | Yes | Yes Audit | Complex | Easy (small codebase) PRACTICAL WORKFLOWS -------------------- # Encrypt backup tar czf - /important/data | age -r age1... > backup.tar.gz.age # Decrypt and extract age -d -i key.txt backup.tar.gz.age | tar xzf - # Encrypt for team (age) age -R team-keys.txt -o secrets.age secrets.env # Store encrypted secrets in git (age) age -R .age-recipients -o .env.age .env echo ".env" >> .gitignore git add .env.age .age-recipients # sops integration (age) export SOPS_AGE_KEY_FILE=~/.config/sops/age/keys.txt sops -e --age age1... secrets.yaml > secrets.enc.yaml sops -d secrets.enc.yaml > secrets.yaml
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.