summaryrefslogtreecommitdiff
path: root/localgpgcleankeyring
blob: b7fb20520ec78da71dcf9b24a9f57b2aac0f4a14 (plain)
  1. #!/bin/sh
  2. # clean_keyring.sh - clean up all the excess keys
  3. # origin: https://scruss.com/blog/2013/05/12/clean-up-your-gnupg-keyring/
  4. set -e
  5. # my keys are those with a corresponding secret key
  6. mykeys=$(gpg --batch --list-secret-keys --with-colons | grep '^sec' | cut -d: -f5)
  7. if [ -z "$mykeys" ]; then
  8. # exit if no key string
  9. echo "Can't get user's key ID"
  10. exit 1
  11. fi
  12. # all of the people who have signed my key
  13. mysigners=$(gpg --batch --list-sigs --with-colons $mykeys | grep '^sig' | cut -d: -f5 | sort -u)
  14. # keep all of the signers, plus my key (if I haven't self-signed)
  15. keepers=$(echo $mykeys $mysigners | tr ' ' '\012' | sort -u)
  16. # the keepers list in egrep syntax: ^(key|key|…)
  17. keepers_egrep=$(echo $keepers | sed 's/^/^(/; s/$/)/; s/ /|/g;')
  18. # everyone who isn't on the keepers list is deleted
  19. deleters=$(gpg --batch --list-keys --with-colons | grep '^pub' | cut -d: -f5 | egrep -v ${keepers_egrep})
  20. if [ -z "$deleters" ]; then
  21. echo "# Nothing to delete!"
  22. else
  23. gpg --batch "$@" --delete-keys $deleters
  24. fi