PGP Question 

In 2020, I generated new keys in a form that I previously had not done. I had made a primary key, along with a sub-signing and a sub-encyption key. These keys expire soon, but the main key is still valid. Should I change their expiration date? If I let these keys expire, and generate new keys for sign/encrypt does it break Web of Trust?
I have changed their experation date. However, another question arises. Have I accidently made two keys for encryption?
2021-03-13-154126_492x132_scrot.png
Follow

@se7en I believe you have. That's not a fatal problem. But it could be annoying if you generated those keys on hardware devices.

Re: Web-of-Trust, the web-of-trust attests to identities, via the master key. So adding new subkeys doesn't break it.

Re: expiration, you absolutely can just extend the expiration. I've done that with my key repeatedly.

· · Web · 1 · 0 · 0
@pete I know I can extend (or in this case revoke) my expiration. I was simply concerned about the fact that the subkeys were set to expire on Mar 20. This is the first time I've ever used this subkey setup. Also, for my personal PGP it was the first time I used pgp in a truly professional setting (confirming/signing correspondance with the court).
@pete I believe my keys are missetup so the master key is still set to be a signing key. How do I remove that? Also, what is "C" in the [SC]

@se7en
The "C" means certification: the ability to delegate to a subkey. It might be possible to remove that. But you definitely don't want to do that. :)

I'm not sure if you actually can remove the master key as a signing key. It wouldn't be all that relevant from a security perspective anyway, as the master key can always just delegate another subkey, so removing signing ability doesn't fundamentally remove its ability to sign things.

@se7en Looks like you can generate a cert-only master key with the --quick-gen-key option. But AFAICT you have to do that from the start - you can't change that later.

That'd be a pretty unusual setup, so I'd advice against it purely on a "will likely break things" basis.

@se7en Ah, I think I see what you mean. Yes, letting those keys expire, as well as extending the expiration, is fine. And as I said, changes to subkeys doesn't affect the WoT.

Sounds like you already know understand this fully, but note that the recipients actually need to get a copy of your updated key for any of this to take effect from their perspective. So in practice, push it to keyservers (which are kinda broken these days...) and/or send a copy directly.

I hope that helps!

@pete I already pushed it to the keyservers and uploaded it ot the reliable sites. What about my follow-up question
Sign in to participate in the conversation
Mastodon

The social network of the future: No ads, no corporate surveillance, ethical design, and decentralization! Own your data with Mastodon!