From a335cc6f1bedc9f827843669b8f1865c35e4d411 Mon Sep 17 00:00:00 2001 From: TW Date: Tue, 4 Dec 2018 02:19:41 +0100 Subject: [PATCH 1/2] split-gpg + enigmail: qubes-gpg-client-wrapper is always needed the section applies to qubes 3.2 (did not check, but it said so) and to qubes 4.0 (verified, was not obvious before). --- security/split-gpg.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/security/split-gpg.md b/security/split-gpg.md index 5b3f8d51..b8e4f2f3 100644 --- a/security/split-gpg.md +++ b/security/split-gpg.md @@ -157,9 +157,7 @@ only `gpg2`). If you encounter trouble while trying to set up Split-GPG, make sure you're using `gpg2` for your configuration and testing, since keyring data may differ between the two installations. -## Qubes 3.2 Specifics ## - -### Using Thunderbird + Enigmail with Split GPG ### +### Using Thunderbird + Enigmail with Split GPG (Qubes 3.2 and 4.0) ### However, when using Thunderbird with Enigmail extension it is not enough, because Thunderbird doesn't preserve the environment @@ -176,6 +174,10 @@ the name of the GPG backend VM. This file survives the AppVM reboot, of course. [user@work ~]$ sudo bash [root@work ~]$ echo "work-gpg" > /rw/config/gpg-split-domain +## Qubes 3.2 Specifics ## + +None. + ## Qubes 4.0 Specifics ## ### Using Thunderbird + Enigmail with Split GPG ### From cd6e3e65b120912b8d9e72a152ed2c2017d02861 Mon Sep 17 00:00:00 2001 From: Andrew David Wong Date: Mon, 3 Dec 2018 20:04:38 -0600 Subject: [PATCH 2/2] Improve page organization (#751) --- security/split-gpg.md | 10 ++-------- 1 file changed, 2 insertions(+), 8 deletions(-) diff --git a/security/split-gpg.md b/security/split-gpg.md index b8e4f2f3..3cc2417f 100644 --- a/security/split-gpg.md +++ b/security/split-gpg.md @@ -157,7 +157,7 @@ only `gpg2`). If you encounter trouble while trying to set up Split-GPG, make sure you're using `gpg2` for your configuration and testing, since keyring data may differ between the two installations. -### Using Thunderbird + Enigmail with Split GPG (Qubes 3.2 and 4.0) ### +### Using Thunderbird + Enigmail with Split GPG ### However, when using Thunderbird with Enigmail extension it is not enough, because Thunderbird doesn't preserve the environment @@ -174,13 +174,7 @@ the name of the GPG backend VM. This file survives the AppVM reboot, of course. [user@work ~]$ sudo bash [root@work ~]$ echo "work-gpg" > /rw/config/gpg-split-domain -## Qubes 3.2 Specifics ## - -None. - -## Qubes 4.0 Specifics ## - -### Using Thunderbird + Enigmail with Split GPG ### +#### Qubes 4.0 Specifics #### New qrexec policies in Qubes R4.0 by default require the user to enter the name of the domain containing GPG keys each time it is accessed. To improve usability