---
title: "SSH & GPG Keys: Practical Security Guide | codingcoffee"
description: "Learn to create and manage SSH and GPG keys with Ameya Shenoy’s practical security notes, including key storage, backups and principles for protecting access."
canonical: "https://www.codingcoffee.dev/blog/the-resolvable-paranoia"
published: "2020-08-10"
tags: "blog"
---

# The Resolvable Paranoia

By Ameya Shenoy · Published 2020-08-10

Learn to create and manage SSH and GPG keys with Ameya Shenoy’s practical security notes, including key storage, backups and principles for protecting access.

I'm the relatively paranoid type and wanted to address some security blind spots. This post uses layman's terms while citing technical sources, targeting intermediate developers seeking a comprehensive guide to secure machine setup.

## SSH and GPG Keys

**SSH Keys:** Authentication mechanism using public-private key pairs. The public key resides on servers (can be shared openly), while the private key remains confidential. Used for passwordless server access and Git repository commits.

**GPG Keys:** More complex than SSH keys, used for signing messages/commits/software to verify authenticity and encrypting messages for intended recipients only.

## Nine Logical Security Principles

1. Keys shouldn't transfer between devices - separate keys per device limit compromise scope
2. Keys require passphrases - protects against hardware theft
3. Replace keys annually - precautionary measure against undetected compromises
4. Use different GPG keys for signing vs. encrypting - mathematical security reasons
5. Never replace GPG signing keys - maintains long-term web of trust verification
6. Store main GPG keys on air-gapped devices - maximum security isolation
7. Delete keys with `shred`, not `rm` - prevents recovery
8. Use FLOSS exclusively - enables code transparency and community review
9. SSH: prefer ED25519 over RSA - shorter keys, same security, immune to side-channel attacks

## Ground Rules Summary

- Unique key per system
- Passphrases mandatory
- Annual key rotation
- Permanent signing keys
- Separate encryption/signing GPG keys
- Air-gapped master GPG storage
- Secure deletion practices
- FLOSS preference
- Dual SSH key strategy

## Storage and Backups

Apply 3-2-1 backup rule: maintain three copies across locations. Options include paper backups via `paperkey`, QR codes, USB sticks, or encrypted `tomb` containers. Avoid cloud storage.

## SSH Key Creation

**ED25519 Key:**

```bash
ssh-keygen -a 100 -t ed25519 -f ~/.ssh/id_ed25519 -C "john.doe@mail.com"
```

**RSA Key:**

```bash
ssh-keygen -a 100 -b 4096 -f ~/.ssh/id_rsa -C "john.doe@mail.com"
```

Both require strong passphrases (10+ characters with mixed case, numbers, symbols).

## GPG Key Creation

Use `gpg2 --verbose --full-gen-key`

**Signing Key:** Select option 4 (RSA sign only), 4096-bit, 0 expiration, include "Signing Key" in comment.

**Encryption Key:** Select option 1 (RSA and RSA), 4096-bit, 1-year expiration.

Strong passphrases are emphasized as critical protection against key theft.

---

Canonical page: https://www.codingcoffee.dev/blog/the-resolvable-paranoia

[Site guide](/llms.txt) · [Contact](/contact) · [Sitemap](/sitemap-index.xml)
