Go to file
Felix Bechstein 42815be83b fix gradle build 2013-08-15 18:07:54 +05:30
OpenPGP-Keychain fix gradle build 2013-08-15 18:07:54 +05:30
OpenPGP-Keychain-API-Demo Crypto Provider implementation start 2013-05-28 15:10:36 +02:00
OpenPGP-Keychain-API-Lib gradle wrapper 2013-05-25 23:13:39 +02:00
Resources new import icon 2013-01-17 14:47:44 +01:00
libraries/ActionBarSherlock move ActionBarSherlock lib, add gradle build files 2013-05-25 22:48:11 +02:00
.gitignore gradle wrapper 2013-05-25 23:13:39 +02:00
CHANGELOG changelog 2013-01-08 23:03:45 +01:00
COPYING renaming whole package to org.apg to simplifiy name 2012-03-09 16:27:29 +01:00
DESCRIPTION description and screenshots 2013-01-16 16:33:04 +01:00
README.md Add coding style to README 2013-07-23 22:15:26 +02:00
build.gradle gradle wrapper 2013-05-25 23:13:39 +02:00
settings.gradle fix gradle build 2013-08-15 18:07:54 +05:30


OpenPGP Keychain (for Android)

OpenPGP Keychain is a EXPERIMENTAL fork of Android Privacy Guard (APG)


Fork OpenPGP Keychain and do a merge request. I will merge your changes back into the main project.


Build with Gradle

  1. Have Android SDK "tools", "platform-tools", and "build-tools" directories in your PATH (http://developer.android.com/sdk/index.html)
  2. Export ANDROID_HOME pointing to your Android SDK
  3. Install gradle
  4. Execute gradle wrapper (http://www.gradle.org/docs/current/userguide/gradle_wrapper.html)
  5. Execute ./gradlew assemble

Build with Ant

  1. Have Android SDK "tools" directory in your PATH (http://developer.android.com/sdk/index.html)
  2. Execute android update project -p OpenPGP-Keychain and android update project -p libraries/ActionBarSherlock
  3. Execute cd OpenPGP-Kechain, ant debug

Build with Eclipse

  1. File -> Import -> Android -> Existing Android Code Into Workspace, choose "libraries/ActionBarSherlock"
  2. File -> Import -> Android -> Existing Android Code Into Workspace, choose "OpenPGP-Keychain"
  3. OpenPGP-Kechain can now be build


All JAR-Libraries are provided in this repository under "libs", all Android Library projects are under "libraries".

  • ActionBarSherlock to provide an ActionBar for Android < 3.0
  • forked Spongy Castle Crypto Lib (Android version of Bouncy Castle)
  • android-support-v4.jar: Compatibility Lib
  • barcodescanner-android-integration-supportv4.jar: Barcode Scanner Integration

Build Barcode Scanner Integration

  1. Checkout their SVN (see http://code.google.com/p/zxing/source/checkout)
  2. Change android-home variable in "build.properties" in the main directory to point to your Android SDK
  3. Change directory to android-integration
  4. Build using ant build
  5. We use "android-integration-supportv4.jar"

On error see: http://code.google.com/p/zxing/issues/detail?id=1207

Build Spongy Castle

Spongy Castle is the stock Bouncy Castle libraries with a couple of small changes to make it work on Android. OpenPGP-Keychain uses a forked version with some small changes to improve key import speed. These changes have been sent to Bouncy Castle, and Spongy Castle will be used again when they have filtered down.



Eclipse: "GC overhead limit exceeded"

If you have problems starting OpenPGP Kechain from Eclipse, consider increasing the memory limits in eclipse.ini. See http://docs.oseems.com/general/application/eclipse/fix-gc-overhead-limit-exceeded for more information.

Generate pressed dashboard icons

  1. Open svg file in Inkscape
  2. Extensions -> Color -> darker (2 times!)

Security Model

Basic goals

  • Intents without permissions should only work based on user interaction (e.g. click a button in a dialog)

Android primitives to exchange data: Intent, Intent with return values, Send (also an Intent), Content Provider, AIDL

Possible Permissions

  • ACCESS_API: Encrypt/Sign/Decrypt/Create keys without user interaction (intents, remote service), Read key information (not the actual keys)(content provider)
  • ACCESS_KEYS: get and import actual public and secret keys (remote service)

Without Permissions


All Intents start with org.sufficientlysecure.keychain.action.

  • android.intent.action.VIEW connected to .gpg and .asc files: Import Key and Decrypt
  • android.intent.action.SEND connected to all mime types (text/plain and every binary data like files and images): Encrypt and Decrypt

With permission ACCESS_API



Broadcast Receiver

On change of database the following broadcast is send.


Content Provider

  • The whole content provider requires a permission (only read)
  • Don't give out blobs (keys can be accessed by ACCESS_KEYS via remote service)
  • Make an internal and external content provider (or pathes with )
  • Look at android:grantUriPermissions especially for ApgServiceBlobProvider
  • Only give out android:readPermission

ApgApiService (Remote Service)

AIDL service

With permission ACCESS_KEYS

ApgKeyService (Remote Service)

AIDL service to access actual private keyring objects

Coding Style


  • Indentation: 4 spaces, no tabs
  • Maximum line width for code and comments: 100
  • Opening braces don't go on their own line
  • Field names: Non-public, non-static fields start with m.
  • Acronyms are words: Treat acronyms as words in names, yielding !XmlHttpRequest, getUrl(), etc.

See http://source.android.com/source/code-style.html

XML Eclipse Settings

  • XML Maximum line width 999
  • XML: Split multiple attributes each on a new line (Eclipse: Properties -> XML -> XML Files -> Editor)
  • XML: Indent using spaces with Indention size 4 (Eclipse: Properties -> XML -> XML Files -> Editor)

See http://www.androidpolice.com/2009/11/04/auto-formatting-android-xml-files-with-eclipse/


OpenPGP Kechain is licensed under Apache License v2.



  • icon.svg
    modified version of kgpg_key2_kopete.svgz

  • dashboard_manage_keys.svg, dashboard_my_keys.svg, key.svg
    Creative Commons Attribution Share-Alike licence 3.0

  • dashboard_decrypt.svg, dashboard_encrypt.svg, dashboard_help.svg
    Public Domain

  • dashboard_scan_qrcode.svg
    New creation for OpenPGP Kechain
    Apache License v2