{"repo":"santiago-mooser/yubikey-provisioning-scripts","free":true,"listed":false,"github":"https://github.com/santiago-mooser/yubikey-provisioning-scripts","clone":"git clone https://github.com/santiago-mooser/yubikey-provisioning-scripts.git","description":"A set of scripts to automatically set up your yubikey's openPGP applet.","language":"Shell","stars":67,"topics":["automation","gpg","linux","macos","openpgp","shell-script","yubikey","yubikeys","gnupg"],"license":"GPL-3.0","category":"workflow-automation","readme_excerpt":"YubiKey provisioning scripts Automate provisioning a YubiKey's OpenPGP applet: generate a certify-only master key plus signing / encryption / authentication subkeys on the host, move the subkeys to the card, set the card PINs and touch policy, and export the public key and a revocation certificate. It automates the workflow from drduh/YubiKey-Guide. v2 rewrite. The previous version drove gpg interactively with expect and could silently report success on failure — most seriously, it could leave the card's factory user PIN in place while printing a PIN it never applied. v2 replaces prompt-scraping with gpg batch commands and a status-driven responder, exports your recovery material before the destructive card transfer, and never uploads your key unless you ask. See What changed in v2. Table of contents - What it does - Install & requirements - Usage - What you get, and what you must keep - Important behaviours and caveats - How it works - Testing - Relationship to drduh's YubiKey-Guide - What changed in v2 - Author What it does Given a connected YubiKey, yubikey provision.sh : 1. Verifies exactly one YubiKey is attached (or targets --serial ). 2. Factory-resets the card's OpenPGP applet ( ykman openpgp reset ). 3. Generates, in an ephemeral GnuPG home on tmpfs (Linux) or a temp dir (macOS): - a certify-only master key (RSA-4096 by default, or ed25519), no expiry; - three subkeys — sign / encrypt / authenticate — with a configurable expiry (default 2 years). 4. Exports the publi","default_branch":null,"files":null,"tree":[],"storefront":"/r/santiago-mooser","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/santiago-mooser/yubikey-provisioning-scripts/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}