[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-02.txt
Daniel Huigens <[email protected]>
| Newsgroups | gmane.ietf.openpgp |
|---|---|
| Message-ID | <ulkJ1A_n5kJrFx8x1nTrrFWgsxaz4gdgZLwQk18UEg4bJPC5MI83kCvjGo4GSl4XU2a-bheeigDmiXM3MaAd93Qlq795wFpRwHb58y9QauI=@protonmail.com> |
On Monday, January 27th, 2025 at 17:55, Andrew Gallagher wrote: > If you have the secret key material to A, yes that would be a better method. Unfortunately loss of secret key material is still a common occurrence. And publishing an escrowed (hard) revocation would invalidate both the forward replacement subpacket and any historical signatures, so a user may not wish to avail of that option. Right, OK. But, if you lost the key material to key A, what's the use case for key B to say that it's the replacement of A? Nobody should trust that information(without any confirmation), because otherwise anyone could claim to replace anyone else's key. So, it might be best to just publish key B (without any binding to key A), get it verified and so on, and then just tell people manually to use that one (if they're still sending you emails encrypted using key A). Best, Daniel _______________________________________________ openpgp mailing list -- [email protected] To unsubscribe send an email to [email protected]