OpenPGP is a signature and encryption standard specified by RFC4880. This standard achieves information and file signing/encryption through the use of private keys. One of the commonly used OpenPGP tools is GNU Privacy Guard, often abbreviated as GnuPG or GPG. In Windows, you can also use Kleopatra.
Firmware versions 1.6.1 and earlier only support RSA public keys with e = 65537. Firmware versions 2.0.0 and above support RSA3072 / RSA4096 key generation.
Touch policy is only effective when using the USB interface.
OpenPGP supports up to 3 keys: signature key (SIG), encryption key (DEC), and authentication key (AUT). Depending on the firmware version, you can set the touch policy for SIG, DEC, and AUT in the CanoKey Console or via the gpg
command. The value of touch cache time ranges from 0 to 255 seconds (0 means no cache).
Please use the “Settings” application in the CanoKey Console to modify the touch policy.
Please use GnuPG to modify the touch policy.
For DEC and AUT keys, after the PIN verification is successful, verification will not be required again until CanoKey is disconnected and reinserted.
For SIG, if forcesig
is on, a PIN is required for each signature; otherwise, a PIN is only required for the first signature after power-on.
Please refer to the GNU Privacy Handbook.
GnuPG, by default, uses its own implementation (scdaemon) to access smart cards including CanoKey, which conflicts with PC/SC. For details, see: https://ludovicrousseau.blogspot.com/2019/06/gnupg-and-pcsc-conflicts.html.
To avoid conflicts, we recommend using the PC/SC interface to access CanoKey by adding the following to scdaemon.conf
:
disable-ccid
In Linux and macOS, this file is usually located at ~/.gnupg/scdaemon.conf
.
In Windows, this issue is typically not encountered. If necessary, please modify the scdaemon.conf
file under the GnuPG installation directory.
Since PC/SC access to smart cards may be exclusive (depending on the application access mode), even if configured correctly, GnuPG may still fail to access CanoKey. If you encounter this issue, simply re-plug CanoKey.
Programs commonly occupying PC/SC include: