
12.3.3. OpenPGP card
Enigmail supports the OpenPGP card, a smart cart compatible with ISO
standards 7816-4 and 7816-8; see http://g10code.com/p-card.html .
The figures below show front and back of an OpenPGP card:
OpenPGP cards are distributed by Kernel Concepts,
http://www.kernelconcepts.de . It is also possible to obtain a OpenPGP
card by becoming a Fellow of the Free Software Foundation Europe; please
read http://wiki.fsfe.org/Crypto_Card for more information.
OpenPGP v2.0 cards feature three independent RSA keys, for signing,
encryption, and authentication, of up to 3072 bits each.
The card is used to store the actual secret key. A secret key stub remains
in the secret keyring to permit standard key operations. The purpose of using a
smart card is that the secrets it contains cannot be copied from the card.
Therefore, as long as the card stays physically in your possession, you know
that your secret key is safe.
There are two methods to initialize a card.
Following the first method, the key is generated on-card, i.e. the card calculates
the key using its built-in random generator; in this way the secret key never
leaves the card.
Otherwise, a standard RSA key can be generated in a safe environment, e.g. a
103
Comentarios a estos manuales