In some ways, this is a bump of a post I made some weeks back regarding Sequoia that didn’t attract any responses. Since that, my understanding of it has grown somewhat, especially with the really cool resources available at Sequoia.
However, my question list continues to grow and I’m hoping some members can guide me, especially @adrelanos and @xyhhx since they have firsthand knowledge of its setup, but saying that, I’m cool with any input.
This guide by @xyhhx looks like a good place to start, but I’ve always avoided installations in dom0, while the first step in this guide is to do just that (split-gpg2-dom0), to allow VMs to communicate on the basis of created tags. Sounds like a nice idea, but I wanted to check-in with you guys before overriding all my previous caution.
Then of course there’s the official docs to setup split-gpg2. Create template + VMs and Policy for VMs. Looks easy-peasy. Is it possible to adapt this to include sequoia-sq and sequoia-chameleon-gnupg(gpg-sq) to create symlinks that allow gpg2 commands to point to gpg-sq? What incompatibilities still exist between gpg-sq and split-gpg2? I also read that keystores are handled very differently; I’d probably need guidance on that point too.
In addition, in the Qubes Global Config the qubes.Gpg is used while in the official doc qubes.Gpg2 policy is used, and there’s no reference to Global Config in the official guide. Is this documentation up to date?
And lastly (for now
), would it be better do create one split for gpg2 and one for gpg-sq so I’m not dependent on a single tool? Especially until newer key types / messages (such as “LibrePGP/v5” paths) are more mainstream? Old habits and old tools die hard for most people.
Anyway, I’m sure there’s way, way more for me to explore and understand on this, and I’d very much appreciate any input you have. Sorry for spamming you with so many questions. My curiosity doesn’t want to let go of it all, so the sooner I get it out of my head and working the better I’ll feel 