We have confidential data that needs to be transferred to a remote location, so we need to encrypt that data.We also need to decrypt data we received from a remote location in order to understand its content.
On storage server in Stratos Datacenter we have private and public keys stored at /home/*_key.asc. Use these keys to perform the following actions.
- Encrypt
/home/encrypt_me.txtto/home/encrypted_me.asc. - Decrypt
/home/decrypt_me.ascto/home/decrypted_me.txt. (Passphrase for decryption and encryption iskodekloud). - The user ID you can use is
kodekloud@kodekloud.com.
Introduction
GPG (GNU Privacy Guard) is a powerful encryption tool used to secure data during transfer and storage. It supports both symmetric encryption (using a passphrase) and asymmetric encryption (using public and private key pairs). In enterprise environments, GPG is commonly used to protect confidential data before transferring it to remote locations.
This guide walks through a real-world GPG encryption and decryption task on the Nautilus Storage Server in the Stratos Datacenter. The task involved importing keys, encrypting a file with a recipient's public key, and decrypting a file using a passphrase.
Environment Details
| Server | Hostname | User | Password |
|---|---|---|---|
| Storage Server | ststor01 | natasha | Bl@kW |
| Jump Host | jump-host | thor | mjolnir123 |
| File | Purpose |
|---|---|
| /home/public_key.asc | Public key for encryption |
| /home/private_key.asc | Private key for decryption |
| /home/encrypt_me.txt | File to encrypt |
| /home/decrypt_me.asc | File to decrypt |
| kodekloud@kodekloud.com | User ID for encryption |
| kodekloud | Passphrase for decryption |
Step 1: Connect to the Storage Server
Access the storage server using SSH.
ssh natasha@ststor01
Password: Bl@kW
Switch to root to perform administrative tasks.
sudo su -
Password: Bl@kW
Step 2: Verify the Available Keys
Check the key files available in the home directory.
ls -la /home/*_key.asc
Expected output:
-rw-r--r-- 1 root root 3590 Sep 27 13:43 /home/private_key.asc
-rw-r--r-- 1 root root 1723 Sep 27 13:43 /home/public_key.asc
The public key is used for encryption, and the private key is used for decryption.
Step 3: Import the Public Key
Import the public key so GPG can use it for encryption.
gpg --import /home/public_key.asc
Expected output:
gpg: key 8F17F26ECCE3AF51: public key "kodekloud <kodekloud@kodekloud.com>" imported
gpg: Total number processed: 1
gpg: imported: 1
Verify the public key is imported.
gpg --list-keys
Expected output:
/root/.gnupg/pubring.kbx
------------------------
pub rsa2048 2020-01-19 [SC]
FEA85011C456B5E9AE5A516F8F17F26ECCE3AF51
uid [ unknown] kodekloud <kodekloud@kodekloud.com>
sub rsa2048 2020-01-19 [E]
Step 4: Import the Private Key
Import the private key. This key is protected with a passphrase.
gpg --import /home/private_key.asc
When prompted, enter the passphrase.
Passphrase: kodekloud
Expected output:
gpg: key 8F17F26ECCE3AF51: "kodekloud <kodekloud@kodekloud.com>" not changed
gpg: key 8F17F26ECCE3AF51: secret key imported
gpg: Total number processed: 1
gpg: unchanged: 1
gpg: secret keys read: 1
gpg: secret keys imported: 1
Verify the secret key is imported.
gpg --list-secret-keys
Expected output:
/root/.gnupg/pubring.kbx
------------------------
sec rsa2048 2020-01-19 [SC]
FEA85011C456B5E9AE5A516F8F17F26ECCE3AF51
uid [ unknown] kodekloud <kodekloud@kodekloud.com>
ssb rsa2048 2020-01-19 [E]
Step 5: Encrypt the File
Encrypt /home/encrypt_me.txt using the recipient's public key.
gpg --encrypt --armor --recipient kodekloud@kodekloud.com --output /home/encrypted_me.asc /home/encrypt_me.txt
When prompted about the key trust, answer yes.
It is NOT certain that the key belongs to the person named
in the user ID. If you *really* know what you are doing,
you may answer the next question with yes.
Use this key anyway? (y/N) y
Command Breakdown
| Option | Description |
|---|---|
| --encrypt | Encrypt the file |
| --armor | Create ASCII armored output (.asc format) |
| --recipient | Specify the recipient's user ID |
| --output | Output file path |
| /home/encrypt_me.txt | Input file to encrypt |
Verify the encrypted file.
ls -la /home/encrypted_me.asc
head -5 /home/encrypted_me.asc
Expected output:
-rw-r--r-- 1 root root 651 Sep 27 14:10 /home/encrypted_me.asc
-----BEGIN PGP MESSAGE-----
hQEMA91rhQaGXAcNAQf9FKNgOTXnf1l19NE12N8iKxweVSkBHULQNQbl6VHAB6xV
7dsOkT79xGIjMD45ktzI56eczklbZg6l6sFfwcdjFDheO8YkSiPPN526HIl4hFoW
tvP1l+H6kvi1qqFnQxb6H96zZLgaUSkxyGK/kBBV1KuPxJiNH4xGOrr6J0DhfN6g
Step 6: Decrypt the File
Decrypt /home/decrypt_me.asc to /home/decrypted_me.txt.
gpg --output /home/decrypted_me.txt --decrypt /home/decrypt_me.asc
When prompted, enter the passphrase.
Passphrase: kodekloud
If successful, the decrypted file will be created.
gpg: AES.CFB encrypted data
gpg: encrypted with 1 passphrase
gpg: Signature made ...
gpg: Good signature from "kodekloud <kodekloud@kodekloud.com>"
Verify the decrypted file.
ls -la /home/decrypted_me.txt
cat /home/decrypted_me.txt
Expected output:
-rw-r--r-- 1 root root 80 Sep 27 14:01 /home/decrypted_me.txt
Welcome to xFusionCorp Industries. This is KodeKloud System Administration Lab
Understanding the Process
Public Key Cryptography
GPG uses asymmetric cryptography, which involves two keys:
| Key | Purpose | Shared With |
|---|---|---|
| Public key | Encrypt data | Anyone |
| Private key | Decrypt data | Only the owner |
When you encrypt a file with someone's public key, only their private key can decrypt it. This ensures confidentiality during transfer.
Symmetric Encryption
GPG also supports symmetric encryption, which uses a single passphrase for both encryption and decryption. This is simpler but requires securely sharing the passphrase.
Key Trust
When importing a key, GPG marks it as untrusted because it cannot verify the key belongs to the stated owner. You must manually confirm trust by answering "yes" when prompted.
Troubleshooting
Bad Session Key
If decryption fails with Bad session key, the passphrase does not match. Possible causes include:
- The passphrase is incorrect
- The file was encrypted with a different passphrase
- The file is corrupted
Solution: Verify the passphrase from the task description. If the file was encrypted with a known passphrase, use the exact value.
Public Key Not Found
If encryption fails with public key not found:
gpg --import /home/public_key.asc
gpg --list-keys
Ensure the key is imported before encrypting.
Secret Key Not Found
If decryption fails with No secret key:
gpg --import /home/private_key.asc
gpg --list-secret-keys
Ensure the private key is imported before decrypting.
File Format Issues
If the file does not have the expected format, check it with:
gpg --list-packets /home/decrypt_me.asc
This shows the packet structure and helps identify whether the file is symmetrically or asymmetrically encrypted.
Summary
| Task | Status |
|---|---|
| Import public key | Complete |
| Import private key | Complete |
Encrypt /home/encrypt_me.txt
|
Complete |
Decrypt /home/decrypt_me.asc
|
Complete |
Final File Status
-rw-r--r-- 1 root root 651 Sep 27 14:10 /home/encrypted_me.asc
-rw-r--r-- 1 root root 80 Sep 27 14:01 /home/decrypted_me.txt
Decrypted Content
Welcome to xFusionCorp Industries. This is KodeKloud System Administration Lab
Key GPG Commands
| Command | Purpose |
|---|---|
gpg --import key.asc |
Import a key |
gpg --list-keys |
List public keys |
gpg --list-secret-keys |
List private keys |
gpg --encrypt --armor --recipient user@domain --output file.asc file.txt |
Encrypt a file |
gpg --decrypt --output file.txt file.asc |
Decrypt a file |
gpg --symmetric --passphrase pass --output file.asc file.txt |
Symmetric encryption |
gpg --list-packets file.asc |
View file structure |
Best Practices
- Always verify keys after import with
gpg --list-keys. - Use
--armorto create ASCII-armored output that is safe for email and text transfer. - Use the
--recipientflag with the exact user ID to encrypt for a specific person. - Store private keys securely and protect them with a strong passphrase.
- Test GPG functionality with a small file before working with critical data.
- When decryption fails, check the file format with
gpg --list-packets. - If the passphrase is wrong, verify it from a trusted source.
Conclusion
This guide covered the complete process of importing GPG keys, encrypting a file with a recipient's public key, and decrypting a file with a passphrase. The tasks were completed successfully on the Nautilus Storage Server.
The key takeaways are understanding the difference between public and private keys, knowing how to import keys, and using the correct GPG commands for encryption and decryption. When issues arise, the gpg --list-packets command is invaluable for understanding the file structure.
Quick Reference
| Task | Command |
|---|---|
| Import key | gpg --import key.asc |
| List keys | gpg --list-keys |
| List secret keys | gpg --list-secret-keys |
| Encrypt | gpg --encrypt --armor --recipient user@domain --output out.asc in.txt |
| Decrypt | gpg --output out.txt --decrypt in.asc |
| Symmetric encrypt | gpg --symmetric --passphrase pass --output out.asc in.txt |
| View packets | gpg --list-packets file.asc |
Top comments (0)