# Password Store with OTP using SmartCard ## Installation ```bash # MacOS brew install pass brew install pass-otp # Linux sudo apt-get install pass sudo apt install pass-extension-otp # Password Store git clone git@github.com:a14m/.pass ~/.password-store ``` ### Usage ```bash pass Personal/reddit pass otp Personal/reddit ``` ## Mobile Setup [Install the pass app from the app store](https://mssun.github.io/passforios/) Configure the app settings as follow: + General + Remember PGP Key Passphrase (ON) + Remember Git Credential Passphrase (ON) + Show Folders (ON) + Hide OTP Fields (ON) + Password Repository + Git URL: `https://github.com/a14m/.pass.git` + Username: `a14m` + Authentication Method: password + Generate a token at [github tokens](https://github.com/settings/tokens) (with all `repo` permissions) + Paste the token into the mobile app ---- ## SmartCard Setup ### Install Tails + Download [tails](https://tails.net/install/index.en.html) + Format a USB + Unmount disk (on MacOS ex. `diskutil unmountDisk /dev/diskX`) + Create bootable image from iso `sudo dd if=/path/to/tails.img of=/dev/diskX bs=4M status=progress` + Boot the `tails` live image from a bootable USB ### Generate GPG Keys ```bash gpg --expert --full-generate-key Please select what kind of key you want: (1) RSA and RSA (default) ... (10) ECC (sign only) (11) ECC (set your own capabilities) (12) ECC (encrypt only) ... Your selection? 11 Possible actions: Sign Certify Authenticate Current allowed actions: Sign Certify (S) Toggle the sign capability (A) Toggle the authenticate capability (Q) Finished Your selection? Q Please select which elliptic curve you want: (1) Curve 25519 (2) Curve 448 (3) NIST P-256 ... Your selection? 1 gpg --expert --edit-key gpg> adduid gpg> addkey Please select what kind of key you want: (1) RSA and RSA (default) ... (10) ECC (sign only) (11) ECC (set your own capabilities) (12) ECC (encrypt only) ... Your selection? 11 Possible actions: Sign Authenticate Current allowed actions: Authenticate (S) Toggle the sign capability (A) Toggle the authenticate capability (Q) Finished Your selection? Q gpg> addkey Please select what kind of key you want: (1) RSA and RSA (default) ... (10) ECC (sign only) (11) ECC (set your own capabilities) (12) ECC (encrypt only) ... Your selection? 12 ``` ### Backup GPG Keys ```bash gpg --export-secret-keys --armor > private.asc gpg --export --armor > pubic.asc cat private.asc | qr > private.png cat public.asc | qr > public.png gpg --delete-secret-and-public-keys ``` ### Restore GPG Keys ```bash # Restore GPG key from camera zbarcam -1 --raw > key.asc # Restore GPG key from file zbarimg -1 --raw key.png > key.asc ``` ### Import GPG Keys to SmartCard ```bash # Import the GPG key on smartcard gpg --import private.asc gpg --edit-key --expert gpg> trust gpg> keytocard Really move the primary key? (y/N) y Please select where to store the key: (1) Signature key (2) Encryption key (3) Authentication key Your selection? 1 ... gpg> key 1 gpg> keytocard Please select where to store the key: (2) Encryption key (3) Authentication key Your selection? 2 ... gpg> key 1 gpg> key 2 gpg> keytocard Please select where to store the key: (3) Authentication key Your selection? 3 ... gpg> save gpg> quit Save changes? (y/N) y ```