You are not logged in.

#1 2017-11-30 04:00:41

Koopa
Member
Registered: 2012-07-20
Posts: 19

gpg-agent and offlineimap - early cached passphrase timeout

I'm using mutt and offlineimap on a server at my house to check my email, leaving mutt open in a tmux session. offlineimap is configured to read passwords from files encrypted with a gpg key. I have gpg-agent setup to cache the password for the keychain, and following a suggestion on the forums linked from the GnuPG wiki page I increased the max-cache-ttl and default-cache-ttl to a really long time (30 days), to avoid having to enter my password more than once per session. A cronjob then triggers offlineimap to fetch new emails every couple of minutes. This setup was working for a while, but then broke a few months ago, which I believe may be related to gpg-agent now running as a systemd service.

My desired behavior would be to cache the password once and have it remain cached until the next time I reboot.

The behavior I'm seeing now is that I'll enter my gpg key password and it'll cache for a seemingly random amount of time, after which I'll need to re-enter the password. I've seen this fluctuate between minutes and hours. Typically it's a couple of hours. I have, however, successfully tested short cache times, which show the expected behavior of timing out after the set time.

The gpg-agent startup and then failure looks like this in the journal:

Nov 08 03:30:03 hostname systemd[19769]: Started GnuPG cryptographic agent and passphrase cache.
Nov 08 03:30:03 hostname gpg-agent[19782]: gpg-agent (GnuPG) 2.2.1 starting in supervised mode.
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 3 for extra socket (/run/user/1000/gnupg/S.gpg-agent.extra)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 4 for browser socket (/run/user/1000/gnupg/S.gpg-agent.browser)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 5 for std socket (/run/user/1000/gnupg/S.gpg-agent)
Nov 08 03:30:03 hostname gpg-agent[19782]: using fd 6 for ssh socket (/run/user/1000/gnupg/S.gpg-agent.ssh)
Nov 08 03:30:03 hostname gpg-agent[19782]: listening on: std=5 extra=3 browser=4 ssh=6
Nov 08 03:30:03 hostname pinentry-curses[19784]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 08 03:30:03 hostname gpg-agent[19782]: failed to read the secret key
Nov 08 03:30:03 hostname gpg-agent[19782]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>
Nov 08 03:30:03 hostname pinentry-curses[19791]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:03 hostname gpg-agent[19782]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 08 03:30:04 hostname gpg-agent[19782]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 08 03:30:04 hostname gpg-agent[19782]: failed to read the secret key
Nov 08 03:30:04 hostname gpg-agent[19782]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>
Nov 08 03:31:30 hostname gpg-agent[19782]: SIGTERM received - shutting down ...
Nov 08 03:31:30 hostname systemd[19769]: Stopping GnuPG cryptographic agent and passphrase cache...
Nov 08 03:31:30 hostname gpg-agent[19782]: gpg-agent (GnuPG) 2.2.1 stopped
Nov 08 03:31:30 hostname systemd[19769]: Stopped GnuPG cryptographic agent and passphrase cache.

The gpg-agent.service journalctl then gets filled with this at each failed gpg decryption attempt from the cronjob:

Nov 29 15:15:02 hostname pinentry-curses[11877]: Remote error from secret service: org.freedesktop.DBus.Error.ServiceUnknown: The name org.freedesktop.secrets was not provided by any .service files
Nov 29 15:15:02 hostname gpg-agent[4817]: Failed to lookup password for key n/XXXXXXX with secret service: The name org.freedesktop.secrets was not provided by any .service files
Nov 29 15:15:03 hostname gpg-agent[4817]: failed to unprotect the secret key: Inappropriate ioctl for device
Nov 29 15:15:03 hostname gpg-agent[4817]: failed to read the secret key
Nov 29 15:15:03 hostname gpg-agent[4817]: command 'PKDECRYPT' failed: Inappropriate ioctl for device <Pinentry>

XXXXXX is my gpg keygrip.

In my .bashrc I export what I believe to be the correct variables:

export GPG_TTY=$(tty)
export GPG_AGENT_INFO=$HOME/.gnupg/S.gpg-agent

And it appears the gpg agent info is correctly set:

$ echo $GPG_AGENT_INFO
/home/koopman/.gnupg/S.gpg-agent

The GnuPG page on the wiki has a tip for caching your passphrase for the whole session by running:

$ /usr/lib/gnupg/gpg-preset-passphrase --preset XXXXXX

I did try this, however I just get:

gpg-preset-passphrase: caching passphrase failed: Not supported

Anyone else with a similar setup experiencing this issue? Alternatively, any suggestions for achieving something similar to my desired behavior?

Thanks,
-Koopa

Offline

#2 2017-12-02 07:47:14

boojum
Member
From: /dev/null
Registered: 2013-09-23
Posts: 44
Website

Re: gpg-agent and offlineimap - early cached passphrase timeout

It might be a daft question but have you enable passphrase caching for gpg-agent (either in gpg-agent.conf, via command line option or systemd service)?
From gpg-agent(1):

--allow-preset-passphrase                                                                            
                This  option  allows the use of gpg-preset-passphrase to seed the internal cache of gpg-agent 
                with passphrases.

Offline

#3 2017-12-02 21:58:16

Koopa
Member
Registered: 2012-07-20
Posts: 19

Re: gpg-agent and offlineimap - early cached passphrase timeout

boojum wrote:

It might be a daft question but have you enable passphrase caching for gpg-agent (either in gpg-agent.conf, via command line option or systemd service)?
From gpg-agent(1):

--allow-preset-passphrase                                                                            
                This  option  allows the use of gpg-preset-passphrase to seed the internal cache of gpg-agent 
                with passphrases.

Not daft at all. I hadn't done this. However, upon enabling it and trying to use gpg-preset-passphrase with:

/usr/lib/gnupg/gpg-preset-passphrase --preset XXXXXX

where XXXXXX is the keygrip, I get the following message in the logs:

Dec 02 14:37:49 windsor gpg-agent[851]: command 'PRESET_PASSPHRASE' failed: Not implemented

I think I figured out how to reproduce the undesired behavior that I'm seeing. I typically leave mutt running in a tmux session. If I detach this session and logout from the server (assuming no other connection is present) then gpg-agent receives a SIGTERM and stops.

Dec 02 14:52:26 windsor gpg-agent[3366]: SIGTERM received - shutting down ...
Dec 02 14:52:26 windsor gpg-agent[3366]: gpg-agent (GnuPG) 2.2.3 stopped
Dec 02 14:52:26 windsor systemd[3260]: Stopped GnuPG cryptographic agent and passphrase cache.

I could see how this could be the intended behavior, so maybe my previous setup shouldn't have ever worked like it did. It's nice to know this is the cause, however I'd still like to figure out the gpg-preset-passphrase "not implemented" error. I think if I can fix that I could achieve something like my desired behavior.

Offline

#4 2017-12-03 08:05:45

boojum
Member
From: /dev/null
Registered: 2013-09-23
Posts: 44
Website

Re: gpg-agent and offlineimap - early cached passphrase timeout

Try running gpg-agent with -vv and --debug-level 9, that should give us more info to work with.
I forgot to mention that you can put both options - verbose and debug-level 9 - in gpg-agent.conf.

Last edited by boojum (2017-12-03 08:26:50)

Offline

Board footer

Powered by FluxBB