#!/bin/bash #---help--- # Usage: # gen-ffice-key # gen-ffice-key [-h|--help] # # Generate a GPG key pair for Hackspace Jena e.V.'s office email addresses # # Options: # # -h --help Show this message and exit # # Description: # # gen-office-key generates a GPG key pair for the three Hackspace Jena e.V. # office email addresses # # office@hackspace-jena.de , # office@krautspace.de , and # office@kraut.space # # under the user id 'Hackspace Jena e.V. Büro ($year)', for the current year # ($year). The script generates a 4096-bit RSA key pair for signing, # encryption, and authentication. The key expires on January 31st of the # following year and the a new key should be generated every Janurary. # # The scripts exports two files. 'office_key_$year.pub.asc' with the ASCII # armored public key, and 'office_key_$year.asc' with both keys in ASCII # armored form. If either file exists, the script reports and error and exists # without doing anyting. # # Notes: # # This script has no arguments or options (except for -h) so that the user # does not have to think. You run it in January once every year, upload the # key to the appropriate places, and that is it. # # If circumstances change in the future, rather than add options to this # script, adapt it. # # License: # # 2019 Philipp Matthias Schäfer # # To the extent possible under law, the author has dedicated all copyright and # related and neighboring rights to this software to the public domain # worldwide. This software is distributed without any warranty. # # You can find a copy of the CC0 Public Domain Dedication at the end of source # of this script and under . #---help--- # This script exports environment variables and changes the file mode creation # mask if [[ "${BASH_SOURCE[0]}" != "${0}" ]]; then echo "Error: ${BASH_SOURCE[0]} must not be sourced" return 1 fi set -eu if [ $# -gt 0 ]; then # Print the help message enclosed between the two lines containing # '#---help---' sed -n '/^#---help---/,/^#---help---/p;' "$0" \ | sed -E 's/^# ?//;1d;$d;' # If -h or --help was passed, the user wanted to see the help message, # otherwise, we showed it due to an erroneous invocation. case "$1" in -h | --help) exit 0;; *) exit 1;; esac fi # Determine the current year year=$(date +%Y) # The next year next_year=$((year+1)) # And from that the expiration date of new key expiration_date="$next_year-01-31" # Derive the output file names from the current year public_key_file="office_key_$year.pub.asc" secret_key_file="office_key_$year.asc" # Ensure that the files do not exist die_if_exists() { if [ -f "$1" ]; then echo "Error: File $1 already exists" exit 1 fi } die_if_exists "$public_key_file" die_if_exists "$secret_key_file" # Warn when it is not January if [ "01" -ne "$(date +%m)" ]; then echo "Warning: This script should have been run in January." fi # Create temporary directory as our working directory work_directory=$(mktemp -d) # Ensure that it gets deleted when this script exists (for whatever reason) trap "rm -rf '$work_directory'" EXIT HUP INT TERM # Make GPG use the work directory export GNUPGHOME="$work_directory" # Create key generation configuration with first uid # https://www.gnupg.org/documentation/manuals/gnupg/Unattended-GPG-key-generation.html cat > "$work_directory/configuration" << EOF %no-protection Key-Type: RSA Key-Length: 4096 Key-Usage: encrypt,sign,auth Name-Real: Hackspace Jena e.V. Büro ($year) Name-Email: office@hackspace-jena.de Expire-Date: $expiration_date %commit EOF echo -n "Generating..." # Generate key gpg --quiet --batch --no-tty --gen-key "$work_directory/configuration" \ 2>&1 >/dev/null \ | grep -v "marked as ultimately trusted" 1>&2 \ || echo -n '' # Because grep exits with 1 # Determine keyid of the new key keyid=$(gpg --quiet --no-tty --list-secret-keys --with-colons 2>/dev/null \ | awk -F: '/^sec:/ { print $5 }') # Add two additional uids gpg --quick-add-uid "$keyid" \ "Hackspace Jena e.V. Büro ($year) " gpg --quick-add-uid "$keyid" \ "Hackspace Jena e.V. Büro ($year) " # Export public key gpg --batch --yes --no-tty --armor \ --output "$public_key_file" --export "$keyid" # Store old umask old_umask=$(umask) # Ensure secret key is only readable by the current user umask 0077 # Export secret key gpg --batch --yes --no-tty --armor \ --output "$secret_key_file" --export-secret-keys "$keyid" echo -e "\rGenerated key pair:" gpg --list-keys | grep -v "$work_directory" echo "Public Key: $public_key_file" echo "Secret Key: $secret_key_file" 