DEV Community

Janak Shrestha
Janak Shrestha

Posted on

Linux GPG Encryption

We have confidential data that needs to be transferred to a remote location, so we need to encrypt that data.We also need to decrypt data we received from a remote location in order to understand its content.

On storage server in Stratos Datacenter we have private and public keys stored at /home/*_key.asc. Use these keys to perform the following actions.

  • Encrypt /home/encrypt_me.txt to /home/encrypted_me.asc.
  • Decrypt /home/decrypt_me.asc to /home/decrypted_me.txt. (Passphrase for decryption and encryption is kodekloud).
  • The user ID you can use is kodekloud@kodekloud.com.

Introduction

GPG (GNU Privacy Guard) is a powerful encryption tool used to secure data during transfer and storage. It supports both symmetric encryption (using a passphrase) and asymmetric encryption (using public and private key pairs). In enterprise environments, GPG is commonly used to protect confidential data before transferring it to remote locations.

This guide walks through a real-world GPG encryption and decryption task on the Nautilus Storage Server in the Stratos Datacenter. The task involved importing keys, encrypting a file with a recipient's public key, and decrypting a file using a passphrase.


Environment Details

Server Hostname User Password
Storage Server ststor01 natasha Bl@kW
Jump Host jump-host thor mjolnir123
File Purpose
/home/public_key.asc Public key for encryption
/home/private_key.asc Private key for decryption
/home/encrypt_me.txt File to encrypt
/home/decrypt_me.asc File to decrypt
kodekloud@kodekloud.com User ID for encryption
kodekloud Passphrase for decryption

Step 1: Connect to the Storage Server

Access the storage server using SSH.

ssh natasha@ststor01
Password: Bl@kW
Enter fullscreen mode Exit fullscreen mode

Switch to root to perform administrative tasks.

sudo su -
Password: Bl@kW
Enter fullscreen mode Exit fullscreen mode

Step 2: Verify the Available Keys

Check the key files available in the home directory.

ls -la /home/*_key.asc
Enter fullscreen mode Exit fullscreen mode

Expected output:

-rw-r--r-- 1 root root 3590 Sep 27 13:43 /home/private_key.asc
-rw-r--r-- 1 root root 1723 Sep 27 13:43 /home/public_key.asc
Enter fullscreen mode Exit fullscreen mode

The public key is used for encryption, and the private key is used for decryption.


Step 3: Import the Public Key

Import the public key so GPG can use it for encryption.

gpg --import /home/public_key.asc
Enter fullscreen mode Exit fullscreen mode

Expected output:

gpg: key 8F17F26ECCE3AF51: public key "kodekloud <kodekloud@kodekloud.com>" imported
gpg: Total number processed: 1
gpg:               imported: 1
Enter fullscreen mode Exit fullscreen mode

Verify the public key is imported.

gpg --list-keys
Enter fullscreen mode Exit fullscreen mode

Expected output:

/root/.gnupg/pubring.kbx
------------------------
pub   rsa2048 2020-01-19 [SC]
      FEA85011C456B5E9AE5A516F8F17F26ECCE3AF51
uid           [ unknown] kodekloud <kodekloud@kodekloud.com>
sub   rsa2048 2020-01-19 [E]
Enter fullscreen mode Exit fullscreen mode

Step 4: Import the Private Key

Import the private key. This key is protected with a passphrase.

gpg --import /home/private_key.asc
Enter fullscreen mode Exit fullscreen mode

When prompted, enter the passphrase.

Passphrase: kodekloud
Enter fullscreen mode Exit fullscreen mode

Expected output:

gpg: key 8F17F26ECCE3AF51: "kodekloud <kodekloud@kodekloud.com>" not changed
gpg: key 8F17F26ECCE3AF51: secret key imported
gpg: Total number processed: 1
gpg:              unchanged: 1
gpg:       secret keys read: 1
gpg:   secret keys imported: 1
Enter fullscreen mode Exit fullscreen mode

Verify the secret key is imported.

gpg --list-secret-keys
Enter fullscreen mode Exit fullscreen mode

Expected output:

/root/.gnupg/pubring.kbx
------------------------
sec   rsa2048 2020-01-19 [SC]
      FEA85011C456B5E9AE5A516F8F17F26ECCE3AF51
uid           [ unknown] kodekloud <kodekloud@kodekloud.com>
ssb   rsa2048 2020-01-19 [E]
Enter fullscreen mode Exit fullscreen mode

Step 5: Encrypt the File

Encrypt /home/encrypt_me.txt using the recipient's public key.

gpg --encrypt --armor --recipient kodekloud@kodekloud.com --output /home/encrypted_me.asc /home/encrypt_me.txt
Enter fullscreen mode Exit fullscreen mode

When prompted about the key trust, answer yes.

It is NOT certain that the key belongs to the person named
in the user ID.  If you *really* know what you are doing,
you may answer the next question with yes.

Use this key anyway? (y/N) y
Enter fullscreen mode Exit fullscreen mode

Command Breakdown

Option Description
--encrypt Encrypt the file
--armor Create ASCII armored output (.asc format)
--recipient Specify the recipient's user ID
--output Output file path
/home/encrypt_me.txt Input file to encrypt

Verify the encrypted file.

ls -la /home/encrypted_me.asc
head -5 /home/encrypted_me.asc
Enter fullscreen mode Exit fullscreen mode

Expected output:

-rw-r--r-- 1 root root 651 Sep 27 14:10 /home/encrypted_me.asc

-----BEGIN PGP MESSAGE-----

hQEMA91rhQaGXAcNAQf9FKNgOTXnf1l19NE12N8iKxweVSkBHULQNQbl6VHAB6xV
7dsOkT79xGIjMD45ktzI56eczklbZg6l6sFfwcdjFDheO8YkSiPPN526HIl4hFoW
tvP1l+H6kvi1qqFnQxb6H96zZLgaUSkxyGK/kBBV1KuPxJiNH4xGOrr6J0DhfN6g
Enter fullscreen mode Exit fullscreen mode

Step 6: Decrypt the File

Decrypt /home/decrypt_me.asc to /home/decrypted_me.txt.

gpg --output /home/decrypted_me.txt --decrypt /home/decrypt_me.asc
Enter fullscreen mode Exit fullscreen mode

When prompted, enter the passphrase.

Passphrase: kodekloud
Enter fullscreen mode Exit fullscreen mode

If successful, the decrypted file will be created.

gpg: AES.CFB encrypted data
gpg: encrypted with 1 passphrase
gpg: Signature made ...
gpg: Good signature from "kodekloud <kodekloud@kodekloud.com>"
Enter fullscreen mode Exit fullscreen mode

Verify the decrypted file.

ls -la /home/decrypted_me.txt
cat /home/decrypted_me.txt
Enter fullscreen mode Exit fullscreen mode

Expected output:

-rw-r--r-- 1 root root 80 Sep 27 14:01 /home/decrypted_me.txt
Welcome to xFusionCorp Industries. This is KodeKloud System Administration Lab
Enter fullscreen mode Exit fullscreen mode

Understanding the Process

Public Key Cryptography

GPG uses asymmetric cryptography, which involves two keys:

Key Purpose Shared With
Public key Encrypt data Anyone
Private key Decrypt data Only the owner

When you encrypt a file with someone's public key, only their private key can decrypt it. This ensures confidentiality during transfer.

Symmetric Encryption

GPG also supports symmetric encryption, which uses a single passphrase for both encryption and decryption. This is simpler but requires securely sharing the passphrase.

Key Trust

When importing a key, GPG marks it as untrusted because it cannot verify the key belongs to the stated owner. You must manually confirm trust by answering "yes" when prompted.


Troubleshooting

Bad Session Key

If decryption fails with Bad session key, the passphrase does not match. Possible causes include:

  1. The passphrase is incorrect
  2. The file was encrypted with a different passphrase
  3. The file is corrupted

Solution: Verify the passphrase from the task description. If the file was encrypted with a known passphrase, use the exact value.

Public Key Not Found

If encryption fails with public key not found:

gpg --import /home/public_key.asc
gpg --list-keys
Enter fullscreen mode Exit fullscreen mode

Ensure the key is imported before encrypting.

Secret Key Not Found

If decryption fails with No secret key:

gpg --import /home/private_key.asc
gpg --list-secret-keys
Enter fullscreen mode Exit fullscreen mode

Ensure the private key is imported before decrypting.

File Format Issues

If the file does not have the expected format, check it with:

gpg --list-packets /home/decrypt_me.asc
Enter fullscreen mode Exit fullscreen mode

This shows the packet structure and helps identify whether the file is symmetrically or asymmetrically encrypted.


Summary

Task Status
Import public key Complete
Import private key Complete
Encrypt /home/encrypt_me.txt Complete
Decrypt /home/decrypt_me.asc Complete

Final File Status

-rw-r--r-- 1 root root 651 Sep 27 14:10 /home/encrypted_me.asc
-rw-r--r-- 1 root root  80 Sep 27 14:01 /home/decrypted_me.txt
Enter fullscreen mode Exit fullscreen mode

Decrypted Content

Welcome to xFusionCorp Industries. This is KodeKloud System Administration Lab
Enter fullscreen mode Exit fullscreen mode

Key GPG Commands

Command Purpose
gpg --import key.asc Import a key
gpg --list-keys List public keys
gpg --list-secret-keys List private keys
gpg --encrypt --armor --recipient user@domain --output file.asc file.txt Encrypt a file
gpg --decrypt --output file.txt file.asc Decrypt a file
gpg --symmetric --passphrase pass --output file.asc file.txt Symmetric encryption
gpg --list-packets file.asc View file structure

Best Practices

  1. Always verify keys after import with gpg --list-keys.
  2. Use --armor to create ASCII-armored output that is safe for email and text transfer.
  3. Use the --recipient flag with the exact user ID to encrypt for a specific person.
  4. Store private keys securely and protect them with a strong passphrase.
  5. Test GPG functionality with a small file before working with critical data.
  6. When decryption fails, check the file format with gpg --list-packets.
  7. If the passphrase is wrong, verify it from a trusted source.

Conclusion

This guide covered the complete process of importing GPG keys, encrypting a file with a recipient's public key, and decrypting a file with a passphrase. The tasks were completed successfully on the Nautilus Storage Server.

The key takeaways are understanding the difference between public and private keys, knowing how to import keys, and using the correct GPG commands for encryption and decryption. When issues arise, the gpg --list-packets command is invaluable for understanding the file structure.


Quick Reference

Task Command
Import key gpg --import key.asc
List keys gpg --list-keys
List secret keys gpg --list-secret-keys
Encrypt gpg --encrypt --armor --recipient user@domain --output out.asc in.txt
Decrypt gpg --output out.txt --decrypt in.asc
Symmetric encrypt gpg --symmetric --passphrase pass --output out.asc in.txt
View packets gpg --list-packets file.asc

Top comments (0)