Signing several files one after another, you are asked for your GnuPG passphrase only the first time. Which component caches it, and takes default-cache-ttl in ~/.gnupg/gpg-agent.conf?

LPIC-1 Exam 102-500, objective 110. Security easy

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct gpg-agent

Correct. Since GnuPG 2 every private-key operation goes through gpg-agent, which holds the unlocked key material and expires it after default-cache-ttl seconds of disuse, up to max-cache-ttl.

Not correct dirmngr

Wrong. dirmngr is the GnuPG component that handles network access, such as keyserver lookups and certificate revocation lists. It never sees a passphrase.

Not correct ssh-agent

Wrong. ssh-agent caches SSH private keys for the SSH client. gpg-agent can be configured to take over that role with enable-ssh-support, but ssh-agent itself knows nothing about GnuPG keys.

Not correct gpgconf

Wrong. gpgconf inspects and modifies the configuration of the GnuPG components, and gpgconf --kill gpg-agent is a common way to restart the agent. It stores no secrets of its own.

Why

gpg-agent is to GnuPG what ssh-agent is to SSH: the private keys stay in the agent's memory, and gpg asks it to perform each decryption or signature. The caching interval is set with default-cache-ttl and default-cache-ttl-ssh in ~/.gnupg/gpg-agent.conf, and the agent must be told to reload the file, for example with gpgconf --reload gpg-agent. Everything else under ~/.gnupg, including the keyrings and the private-keys-v1.d directory, should be mode 700 and owned by the user.

Where this comes from

Cited
manual page gpg-agent(1)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 110 and space the ones you get wrong.

Practise LPIC-1 Exam 102-500

More questions on this objective

All questions on Security

Practise LPIC-1 Exam 102-500