You are not logged in.
I'm using mutt and offlineimap on a server at my house to check my email, leaving mutt open in a tmux session. offlineimap is configured to read passwords from files encrypted with a gpg key. I have gpg-agent setup to cache the password for the keychain, and following a suggestion on the forums linked from the GnuPG wiki page I increased the max-cache-ttl and default-cache-ttl to a really long time (30 days), to avoid having to enter my password more than once per session. A cronjob then triggers offlineimap to fetch new emails every couple of minutes. This setup was working for a while, but then broke a few months ago, which I believe may be related to gpg-agent now running as a systemd service.
My desired behavior would be to cache the password once and have it remain cached until the next time I reboot.
The behavior I'm seeing now is that I'll enter my gpg key password and it'll cache for a seemingly random amount of time, after which I'll need to re-enter the password. I've seen this fluctuate between minutes and hours. Typically it's a couple of hours. I have, however, successfully tested short cache times, which show the expected behavior of timing out after the set time.
The gpg-agent startup and then failure looks like this in the journal:
Nov 08 03:30:03 hostname systemd[19769]: Started GnuPG cryptographic agent and passphrase cache.
Nov 08 03:30:03 hostname gpg-agent[19782]: gpg-agent (GnuPG) 2.2.1 starting in supervised mode.
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 3 for extra socket (/run/user/1000/gnupg/S.gpg-agent.extra)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 4 for browser socket (/run/user/1000/gnupg/S.gpg-agent.browser)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 5 for std socket (/run/user/1000/gnupg/S.gpg-agent)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 6 for ssh socket (/run/user/1000/gnupg/S.gpg-agent.ssh)
Nov 08 03:30:03 hostname gpg-agent[19782]: listening on: std=5 extra=3 browser=4 ssh=6
Nov 08 03:30:03 hostname pinentry-curses[19784]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 08 03:30:03 hostname gpg-agent[19782]: failed to read the secret key
Nov 08 03:30:03 hostname gpg-agent[19782]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>
Nov 08 03:30:03 hostname pinentry-curses[19791]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:04 hostname gpg-agent[19782]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 08 03:30:04 hostname gpg-agent[19782]: failed to read the secret key
Nov 08 03:30:04 hostname gpg-agent[19782]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>
Nov 08 03:31:30 hostname gpg-agent[19782]: SIGTERM received - shutting down ...
Nov 08 03:31:30 hostname systemd[19769]: Stopping GnuPG cryptographic agent and passphrase cache...
Nov 08 03:31:30 hostname gpg-agent[19782]: gpg-agent (GnuPG) 2.2.1 stopped
Nov 08 03:31:30 hostname systemd[19769]: Stopped GnuPG cryptographic agent and passphrase cache.The gpg-agent.service journalctl then gets filled with this at each failed gpg decryption attempt from the cronjob:
Nov 29 15:15:02 hostname pinentry-curses[11877]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 29 15:15:02 hostname gpg-agent[4817]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 29 15:15:03 hostname gpg-agent[4817]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 29 15:15:03 hostname gpg-agent[4817]: failed to read the secret key
Nov 29 15:15:03 hostname gpg-agent[4817]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>XXXXXX is my gpg keygrip.
In my .bashrc I export what I believe to be the correct variables:
export GPG_TTY=$(tty)
export GPG_AGENT_INFO=$HOME/.gnupg/S.gpg-agentAnd it appears the gpg agent info is correctly set:
$ echo $GPG_AGENT_INFO
/home/koopman/.gnupg/S.gpg-agentThe GnuPG page on the wiki has a tip for caching your passphrase for the whole session by running:
$ /usr/lib/gnupg/gpg-preset-passphrase --preset XXXXXXI did try this, however I just get:
gpg-preset-passphrase: caching passphrase failed: Not supportedAnyone else with a similar setup experiencing this issue? Alternatively, any suggestions for achieving something similar to my desired behavior?
Thanks,
-Koopa
Offline
It might be a daft question but have you enable passphrase caching for gpg-agent (either in gpg-agent.conf, via command line option or systemd service)?
From gpg-agent(1):
--allow-preset-passphrase
This option allows the use of gpg-preset-passphrase to seed the internal cache of gpg-agent
with passphrases.Offline
It might be a daft question but have you enable passphrase caching for gpg-agent (either in gpg-agent.conf, via command line option or systemd service)?
From gpg-agent(1):--allow-preset-passphrase This option allows the use of gpg-preset-passphrase to seed the internal cache of gpg-agent with passphrases.
Not daft at all. I hadn't done this. However, upon enabling it and trying to use gpg-preset-passphrase with:
/usr/lib/gnupg/gpg-preset-passphrase --preset XXXXXXwhere XXXXXX is the keygrip, I get the following message in the logs:
Dec 02 14:37:49 windsor gpg-agent[851]: command 'PRESET_PASSPHRASE' failed: Not implementedI think I figured out how to reproduce the undesired behavior that I'm seeing. I typically leave mutt running in a tmux session. If I detach this session and logout from the server (assuming no other connection is present) then gpg-agent receives a SIGTERM and stops.
Dec 02 14:52:26 windsor gpg-agent[3366]: SIGTERM received - shutting down ...
Dec 02 14:52:26 windsor gpg-agent[3366]: gpg-agent (GnuPG) 2.2.3 stopped
Dec 02 14:52:26 windsor systemd[3260]: Stopped GnuPG cryptographic agent and passphrase cache.I could see how this could be the intended behavior, so maybe my previous setup shouldn't have ever worked like it did. It's nice to know this is the cause, however I'd still like to figure out the gpg-preset-passphrase "not implemented" error. I think if I can fix that I could achieve something like my desired behavior.
Offline
Try running gpg-agent with -vv and --debug-level 9, that should give us more info to work with.
I forgot to mention that you can put both options - verbose and debug-level 9 - in gpg-agent.conf.
Last edited by boojum (2017-12-03 08:26:50)
Offline