1.3 KiB
Decrypt Namespace Secret
Requirements
{{ #include ../../operator-requirements.md:requirements }}
-
High Visibility Storage: plastic container or bag that's used to keep items while not in use in a visible location like the middle of a desk.
Procedure
{{ #include template-ceremony-setup.md:content }}
-
Retrieve Ceremony SD Card from High Visibility Storage and plug it into the machine
-
Copy the Ceremony SD Card contents to machine
cp -r /media/vaults /root/
-
Start
keyfork
using the relevant Shardfile:$ keyfork recover shard --daemon /root/vaults/<namespace>/shardfile.asc
- Follow on screen prompts
-
Derive the OpenPGP root certificate:
$ keyfork derive openpgp > secret_key.asc
-
Decrypt the secret material:
sq decrypt --recipient-file secret_key.asc < encrypted.asc --output decrypted
-
Proceed to transfer the secret (
decrypted
) to desired location such as hardware wallet, power washed chromebook (via SD card) etc. -
Shut down the air gapped machine
-
Gather all the original items that were in the air-gapped bundle:
-
Air-gapped computer
-
AirgapOS SD card
-
{{ #include ../../../../component-documents/tamper-evidence-methods.md:vsbwf-procedure-sealing}}