Nitrokey / Nitrokey/nitrokey-documentation

Add How to restore from backup / create backup Nitrokey

Open
#180 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
CSS
Stars
36
Forks
53
Avg merge
1d 16h
Merged PRs (30d)
5

Description

File: [nitrokey3/linux/openpgp-keygen-backup.rst] https://docs.nitrokey.com/nitrokey3/linux/openpgp-keygen-backup.html

I'd like to suggest to add also some documentation how to restore from backup and how to install on a second backup nitrokey.

some points worth mentioning

  • create backup nitrokey
    • how to switch between nitrokeys? how to update private-key stubs?
    • is it possible to "create" two nitrokeys one after the other, if during keytocard private-key stubs are not created (to replace the private key)?
    • is ADSK a valid strategy? Is there enough space on Nitrokey for this, according to documentation only 3 keys can be stored SC/E/A?
  • in case of loss, install backup on new nitrokey
    • find the private-key stubs with --with-keygrip and delete
    • I had to use gpg --batch --import private.key, without batch I'd get sec#

Note:
this new page could be embedded in a series of pages related to how-to-recover-from-loss-or-damage. based on the forum posts, there appears to be a need for entry level documentation how to work with security tokens and the different strategies for backup and recovery (FIDO, PIV, secrets, PGP)

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with nitrokey3/linux/openpgp-keygen-backup.rst and the linked ADSK documentation. Document creating and switching between backup Nitrokeys, restoring after loss, handling private-key stubs, and the listed import command behavior. Done means the backup and recovery workflows and the open capacity questions are clearly covered, possibly across a recovery documentation series.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.