The process is surprisingly involved, and there's a lot of opportunity for error given gpg's dreadful user interface (not saving to keep the key on both the host and the keycard? wtf?).
I think there would be a lot of value in creating tooling around the "best-practice" setup, even if it's just wrappers around gpg commands. Scripts to setup the main key & subkeys, revocation certs, smartcards and backups, all that jazz. A Raspberry Pi image to act as an "air-gapped" computer for sensitive operations might also be part of this.
The process is surprisingly involved, and there's a lot of opportunity for error given gpg's dreadful user interface (not saving to keep the key on both the host and the keycard? wtf?).
I think there would be a lot of value in creating tooling around the "best-practice" setup, even if it's just wrappers around gpg commands. Scripts to setup the main key & subkeys, revocation certs, smartcards and backups, all that jazz. A Raspberry Pi image to act as an "air-gapped" computer for sensitive operations might also be part of this.