|
* The generated keys are stored in:
* *nix - $HOME/.gnupg
* Windows XP - %HOME%\Application Data\gnupg
* Windows 7 - C:\ProgramData\GNU\etc\gnupg
* "gpg --version" shows the GnuPG's home location.
* Follow the latest steps and guides on the ASF website at [http://www.apache.org/dev/openpgp.html#generate-key](http://www.apache.org/dev/openpgp.html#generate-key) as you need to disable using SHA1 and new keys should be 4096 bits.
* Append the following text to gpg.conf.
personal-digest-preferences SHA512
cert-digest-algo SHA512
default-preference-list SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 \
ZLIB BZIP2 ZIP Uncompressed
* If you are using an existing gpg certificate, update your current certificate with the above preference using:
leealber@jpadev:~/.gnupg$ gpg --edit-key Albert Lee
Secret key is available.
pub 1024D/8007117F created: 2007-11-05 expires: never usage: SC
trust: ultimate validity: ultimate
sub 2048g/8D910F8A created: 2007-11-05 expires: never usage: E
[ultimate] (1). Albert Lee (CODE SIGNING KEY)
Invalid command (try "help")
Command> showpref
[ultimate] (1). Albert Lee (CODE SIGNING KEY)
Cipher: AES256, AES192, AES, CAST5, 3DES
Digest: SHA512, SHA384, SHA256, SHA224, SHA1
Compression: ZLIB, BZIP2, ZIP, Uncompressed
Features: MDC, Keyserver no-modify
Command> setpref SHA512 SHA384 SHA256 SHA224 AES256 AES192 AES CAST5 ZLIB \
BZIP2 ZIP Uncompressed
Set preference list to:
Cipher: AES256, AES192, AES, CAST5, 3DES
Digest: SHA512, SHA384, SHA256, SHA224, SHA1
Compression: ZLIB, BZIP2, ZIP, Uncompressed
Features: MDC, Keyserver no-modify
Really update the preferences? (y/N) y
pub 1024D/8007117F created: 2007-11-05 expires: never usage: SC
trust: ultimate validity: ultimate
sub 2048g/8D910F8A created: 2007-11-05 expires: never usage: E
[ultimate] (1). Albert Lee (CODE SIGNING KEY)
Command>
|