Home / Alt manpages / addgnupghome(8)

  • addgnupghome(8)
  • Admin command
  • linux

Create Missing GnuPG Home Directories Safely with addgnupghome

By the end, you will have created a missing .gnupg directory for one or more existing Linux accounts, populated it from /etc/skel/.gnupg, and checked that the result belongs to the right user. The command does not merge with an existing GnuPG home: it skips any account whose .gnupg directory already exists.

Allow about five minutes for a normal account setup. You need the gnupg-utils package, a root shell or sudo, the target accounts, and a prepared /etc/skel/.gnupg directory. This guide describes the installed Ubuntu package version gnupg-utils 2.4.4-2ubuntu17.6, whose command identifies itself as GnuPG 2.4.4.

Checkpoint: understand what will change

addgnupghome is a small administrative shell script. It looks up each account, finds its home directory, creates $HOME/.gnupg only when that directory is absent, and copies the files and directories found in /etc/skel/.gnupg. It excludes files ending in ~. The new directory and copied entries are assigned to the target user and group, and the script sets a restrictive 0077 umask while it works.

The command has no option for selecting a different skeleton directory, home directory, or destination. Its syntax is a list of account names, not arbitrary paths:

addgnupghome ACCOUNT...

Run it as root. It needs to create directories in other users' home directories and change their ownership. Do not use it to repair an existing GnuPG home: an existing directory is deliberately left alone, even if its contents are incomplete.

1. Check the package and skeleton

First, confirm the command and the source directory. These checks do not change anything:

command -v addgnupghome
dpkg-query -W gnupg-utils
sudo find /etc/skel/.gnupg -maxdepth 2 -print

On this installation, the package reports gnupg-utils 2.4.4-2ubuntu17.6. The final command must list /etc/skel/.gnupg and the files or directories you intend to seed. If the directory is absent, the program stops before processing accounts with this error:

addgnupghome: skeleton directory `/etc/skel/.gnupg' does not exist

Do not create a skeleton by copying an arbitrary user's private GnuPG home. The skeleton is a system-wide template, and anything placed there may be copied into every account you name.

2. Check the target accounts

Confirm the account names and their home directories before invoking the command:

getent passwd alice bob
getent passwd alice | cut -d: -f1,6
getent passwd bob | cut -d: -f1,6

Replace alice and bob with real account names. Each account must exist, and its home directory must already be a directory. A missing account, missing home, or failed ownership operation is reported on standard error and contributes to a non-zero exit status.

Check whether an existing GnuPG home is present. This matters because the command will skip it rather than add files to it:

for account in alice bob; do
    home=$(getent passwd "$account" | cut -d: -f6)
    printf '%s: ' "$account"
    if [ -d "$home/.gnupg" ]; then
        printf 'already exists\n'
    else
        printf 'will be created at %s/.gnupg\n' "$home"
    fi
done

3. Create the missing directories

Warning

This step changes account configuration and copies GnuPG-related files. Review the account list and skeleton contents immediately before running it. The command does not ask for confirmation.

sudo addgnupghome alice bob

Successful creation writes progress messages to standard error, such as:

addgnupghome: creating home directory `/home/alice/.gnupg' for `alice'
addgnupghome: skipping user `bob': `.gnupg' already exists

A skip is success for that account, not evidence that files were copied. The command may process later accounts after an individual error, then return a non-zero status. Capture the status if this is part of a script:

if sudo addgnupghome alice bob; then
    echo "all requested accounts completed"
else
    status=$?
    printf 'addgnupghome failed with status %s\n' "$status" >&2
    exit "$status"
fi

4. Verify ownership, mode and contents

For each account that was meant to receive a new directory, inspect the result as root:

sudo stat -c '%n owner=%U group=%G mode=%a' /home/alice/.gnupg
sudo find /home/alice/.gnupg -maxdepth 2 -printf '%M %u:%g %p\n' | sort

The owner should be alice, the group should match the account's primary group, and the directory should not be readable by other users. The installed script uses a 0077 umask for files it creates, but the mode of a source file is still relevant when it is copied. Check the actual result rather than assuming a mode.

Confirm that GnuPG can use the new home without changing keys or contacting a service:

sudo -u alice gpg --homedir /home/alice/.gnupg --list-keys

An empty key listing can be normal for a freshly seeded directory. The useful checks here are that the command runs, the home is accessible to alice, and the expected template files are present.

Common traps and recovery

Existing directory: a message saying .gnupg already exists means nothing was merged. Inspect that directory separately. If it needs repair, back it up and use a deliberate migration plan; do not delete it just to make addgnupghome run.

Wrong account name: the command accepts account names resolved through the system account database. It does not accept a home path such as /home/alice. Use getent passwd to check the spelling.

Missing skeleton: populate /etc/skel/.gnupg with files approved by the system administrator, then rerun the read-only checks. A failed run caused by a missing skeleton does not create target directories.

Partial failure: inspect the output and each named home. If a new directory was created but copying or ownership failed, stop and preserve evidence before repairing it. To undo only a directory that this run created, first verify the exact path and that it contains no user-created keys or configuration, then remove that path as root:

sudo rm -rf -- /home/alice/.gnupg

This is destructive and cannot be undone from the filesystem. Restore from a backup if the directory contained data, or leave it in place and repair ownership and contents manually. Never run that command with an unreviewed variable or a broad path.

Done means

  • The skeleton existed before the run and contained only approved template data.
  • Every named account and home directory was checked.
  • New directories were created only for accounts without an existing .gnupg.
  • stat shows the expected user, group and restrictive mode.
  • The final gpg --list-keys check runs as the target user.
  • Any non-zero exit status or partial result has been investigated before the account uses GnuPG.