Skip to content
Zehao Duan

Public keys

These are my public keys, for anyone who wants to send me something only I can read, check that a file really came from me, or let me log in to a server without a password.

A public key is meant to be shared. It can lock a message or check a signature, but it cannot unlock or sign anything: that takes the matching private key, which never leaves my devices. If none of this means anything to you, nothing here needs your attention, and ordinary email is fine.

PGP key

For encrypted email and files, and for checking my signatures. It works with GnuPG, Thunderbird and other OpenPGP software.

Fingerprint
3820 3A1C 91D7 EED4 CA65 8D3C F14B A896 331B 9793
User ID
Zehao Duan (Main PGP Key) <zehao.duan@gmail.com>
Type
Ed25519 (signing), with a Cv25519 subkey (encryption)
Validity
Created , expires
pgp.asc
-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEaqugRBYJKwYBBAHaRw8BAQdAuv1fwBS5K3iK5hDA7C7+SrG9fDWKXarFO6NX
GULBtzy0MFplaGFvIER1YW4gKE1haW4gUEdQIEtleSkgPHplaGFvLmR1YW5AZ21h
aWwuY29tPoi1BBMWCgBdFiEEOCA6HJHX7tTKZY088UuoljMbl5MFAmqroEQbFIAA
AAAABAAObWFudTIsMi41KzEuMTIsMCwzAhsDBQkJZgGABQsJCAcCAiICBhUKCQgL
AgQWAgMBAh4HAheAAAoJEPFLqJYzG5eT4rcA/iJ4tOACKQWsHBNp0nLONx3YgABK
HECL3S3kdXqAF+hnAP40eeA19X8pSnWt1F00VgjhBM01HsULTh5Ui/YkqVxuDbg4
BGqroEQSCisGAQQBl1UBBQEBB0CtQEIYOBbkWQJXzQWSKCTCWbkV8PckROmpdrQ3
5+4yUQMBCAeImgQYFgoAQhYhBDggOhyR1+7UymWNPPFLqJYzG5eTBQJqq6BEGxSA
AAAAAAQADm1hbnUyLDIuNSsxLjEyLDAsMwIbDAUJCWYBgAAKCRDxS6iWMxuXkwKp
AP9ZS2z6sfhrDzjCGC1G7RlNKact4UVU55xbmOG+LcixRAD+PLujxvdimcR6DP0V
5MtTIaY+YtyD71MSnaCpRCfLsQU=
=OafD
-----END PGP PUBLIC KEY BLOCK-----

Using it

  1. Download the key.

    curl -O https://zehao-duan.com/public-key/pgp.asc
  2. Check it before importing. The fingerprint on the line under pub must match the one on this page, character for character. Newer GnuPG versions print a second fingerprint under sub; that one belongs to the encryption subkey and is not the one to compare.

    gpg --show-keys --with-fingerprint pgp.asc
  3. Import it.

    gpg --import pgp.asc
  4. Encrypt a file so that only I can read it. GnuPG will ask you to confirm, because it has no proof yet that the key is mine; the fingerprint check below is that proof.

    gpg --encrypt --armor --recipient 38203A1C91D7EED4CA658D3CF14BA896331B9793 message.txt
  5. Check a signature I made. Look for “Good signature” and the same fingerprint. GnuPG also warns that the key “is not certified with a trusted signature”; that is the same missing proof as in step 4, not a failed check.

    gpg --verify paper.pdf.sig paper.pdf

SSH key

For logging in to servers and Git hosting without a password. If you run a machine I should have access to, this is the line to add.

Fingerprint
SHA256:0JAhpUGbGd5G8ceQYFQ7GsxRzSfjT3ZLuZeCwFm3pFQ
Type
Ed25519, 256 bits
ssh.pub
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEwq4pJRYWFnVm255U6ATNWKrbZIdr8+zPmz0nyAA3JU zehao.duan@gmail.com

Using it

  1. Download the key.

    curl -O https://zehao-duan.com/public-key/ssh.pub
  2. Check it. The fingerprint it prints must match the one on this page, character for character.

    ssh-keygen -lf ssh.pub
  3. Authorise it by appending the line to ~/.ssh/authorized_keys of the account I should use. That lets whoever holds my private key log in to that one account, so add it only where I am meant to have access. If the account has no ~/.ssh yet, create it first with mkdir -m 700 ~/.ssh, and keep authorized_keys at mode 600: sshd ignores the file if anyone else can write to it.

    cat ssh.pub >> ~/.ssh/authorized_keys

Before you trust these keys

  1. Check where you are. The address bar should read https://zehao-duan.com, with no certificate warning. Do not take “my” key from an email attachment, a chat message or a link that merely claims to be me.
  2. Compare the whole fingerprint. Every character, not just the first and last few. A forged key whose fingerprint matches at both ends is cheap to make.
  3. When it matters, confirm it another way. This page and the key files come from the same server, so a fingerprint shown here only proves that the two agree with each other. For anything sensitive, have me read the fingerprint to you in person, or on a call where you recognise my voice or face, using contact details you already trusted rather than ones from the message you are checking.
  4. A public key is not a secret. Anyone may have it. On its own it cannot decrypt, sign or log in anywhere. Never send anyone a private key; I will never ask for yours.
  5. Keys change. This PGP key expires on 2031-09-16 unless I extend it. If this page ever shows a different key from the one you hold, treat the new one as unverified until you have confirmed it with me.
  6. Encryption hides the content, not everything. A PGP-encrypted email still shows who sent it, who received it and when, and in many mail programs the subject line too, so keep the subject bland.

Back to home page