Public keys
These are my public keys, for anyone who wants to send me something only I can read, check that a file really came from me, or let me log in to a server without a password.
A public key is meant to be shared. It can lock a message or check a signature, but it cannot unlock or sign anything: that takes the matching private key, which never leaves my devices. If none of this means anything to you, nothing here needs your attention, and ordinary email is fine.
PGP key
For encrypted email and files, and for checking my signatures. It works with GnuPG, Thunderbird and other OpenPGP software.
Using it
Download the key.
curl -O https://zehao-duan.com/public-key/ pgp.asc Check it before importing. The fingerprint on the line under
pubmust match the one on this page, character for character. Newer GnuPG versions print a second fingerprint undersub; that one belongs to the encryption subkey and is not the one to compare.gpg --show-keys --with-fingerprint pgp.ascImport it.
gpg --import pgp.ascEncrypt a file so that only I can read it. GnuPG will ask you to confirm, because it has no proof yet that the key is mine; the fingerprint check below is that proof.
gpg --encrypt --armor --recipient 38203A1C91D7EED4CA658D3CF14BA896331B9793 message.txtCheck a signature I made. Look for “Good signature” and the same fingerprint. GnuPG also warns that the key “is not certified with a trusted signature”; that is the same missing proof as in step 4, not a failed check.
gpg --verify paper.pdf.sig paper.pdf
SSH key
For logging in to servers and Git hosting without a password. If you run a machine I should have access to, this is the line to add.
Using it
Download the key.
curl -O https://zehao-duan.com/public-key/ ssh.pub Check it. The fingerprint it prints must match the one on this page, character for character.
ssh-keygen -lf ssh.pubAuthorise it by appending the line to
~/.ssh/authorized_keysof the account I should use. That lets whoever holds my private key log in to that one account, so add it only where I am meant to have access. If the account has no~/.sshyet, create it first withmkdir -m 700 ~/.ssh, and keepauthorized_keysat mode 600: sshd ignores the file if anyone else can write to it.cat ssh.pub >> ~/.ssh/authorized_keys