2024年GnuPG密钥偏好设置及gpg.conf配置咨询
2024年GnuPG密钥偏好设置及gpg.conf配置咨询
Hey there! Let's tackle your GnuPG config question for 2024, since you're running Ubuntu 22.04.3 LTS with GnuPG 2.2.27 and libgcrypt 1.9.4—perfect, these versions support all the modern algorithms we'll recommend.
一、gpg --edit-key 中的 setpref 命令
First, let's update your key's algorithm preferences to align with 2024 security standards. Here's what you'll run step by step:
- Open the key edit mode for your target key (replace
[YOUR_KEY_ID]with your actual key fingerprint or short ID):gpg --edit-key [YOUR_KEY_ID] - Run this
setprefcommand to prioritize modern, secure algorithms (we'll break down the choices below):setpref AES256 AES192 AES ChaCha20 SHA512 SHA384 SHA256 ZLIB Uncompressed Ed25519 Curve25519 RSA4096 RSA2048 - Save your changes with:
save
算法选择说明:
- 对称加密:优先用
AES256(当前行业标准的强对称加密算法),后续AES192、AES作为兼容 fallback,ChaCha20适合没有AES硬件加速的环境,性能更优。 - 哈希算法:
SHA512、SHA384是抗碰撞性极强的哈希算法,SHA256作为广泛兼容的备选。 - 压缩:
ZLIB平衡了压缩效率和安全性,Uncompressed则避免了压缩数据可能带来的侧信道泄露风险。 - 公钥算法:
Ed25519(现代ECC签名算法)和Curve25519(ECC加密算法)比RSA更高效且安全,RSA4096/RSA2048作为老系统的兼容 fallback。
小贴士:如果你没使用ECC密钥,可以去掉命令中的Ed25519和Curve25519部分。
二、推荐的 gpg.conf 配置
这份配置在2024年的安全标准、现代特性和兼容性之间做了平衡。记得把[YOUR_KEY_ID]替换成你的主密钥ID,如果用GUI环境,可调整pinentry-mode为gtk或qt:
# 基础身份与默认设置 default-key [YOUR_KEY_ID] charset utf-8 no-greeting no-secmem-warning # 加密偏好(与setpref保持一致) personal-cipher-preferences AES256 AES192 AES ChaCha20 personal-digest-preferences SHA512 SHA384 SHA256 personal-compress-preferences ZLIB Uncompressed default-preference-list AES256 AES192 AES ChaCha20 SHA512 SHA384 SHA256 ZLIB Uncompressed Ed25519 Curve25519 RSA4096 RSA2048 encrypt-to [YOUR_KEY_ID] default-recipient-self # 签名与证书设置 cert-digest-algo SHA512 digest-algo SHA512 sig-min-certify-depth 1 sig-check-depth 2 # 密钥服务器与网络(使用现代安全服务器) keyserver hkps://keys.openpgp.org keyserver-options timeout=10 keyserver-options no-honor-keyserver-url auto-key-locate keyserver auto-key-verify # 安全与隐私 require-cross-certification no-emit-version no-comment lock-once use-agent # 界面设置(GUI环境可改为"gtk"或"qt") pinentry-mode curses
关键配置解释:
keyserver hkps://keys.openpgp.org:替代已停止维护的旧SKS密钥池,使用现代隐私友好的密钥服务器。require-cross-certification:只信任经过交叉验证的密钥,降低伪造密钥的风险。no-emit-version&no-comment:隐藏不必要的元数据,避免泄露系统细节。encrypt-to&default-recipient-self:自动给自己加密一份消息副本,防止丢失加密内容的访问权限。
你可以根据自身需求调整——比如如果必须兼容极老系统,可添加SHA1作为最后兜底的哈希算法(但非必要不推荐)。
备注:内容来源于stack exchange,提问作者faszikam
相关产品推荐
相关产品推荐

