[openpgp] Re: I-D Action: draft-ietf-openpgp-replacementke y-02.txt

Daniel Huigens <[email protected]>
Newsgroups gmane.ietf.openpgp
Message-ID <ulkJ1A_n5kJrFx8x1nTrrFWgsxaz4gdgZLwQk18UEg4bJPC5MI83kCvjGo4GSl4XU2a-bheeigDmiXM3MaAd93Qlq795wFpRwHb58y9QauI=@protonmail.com>
On Monday, January 27th, 2025 at 17:55, Andrew Gallagher wrote:

> If you have the secret key material to A, yes that would be a better method. Unfortunately loss of secret key material is still a common occurrence. And publishing an escrowed (hard) revocation would invalidate both the forward replacement subpacket and any historical signatures, so a user may not wish to avail of that option.

Right, OK.

But, if you lost the key material to key A, what's the use case for key B to say that it's the replacement of A? Nobody should trust that information(without any confirmation), because otherwise anyone could claim to replace anyone else's key. So, it might be best to just publish key B (without any binding to key A), get it verified and so on, and then just tell people manually to use that one (if they're still sending you emails encrypted using key A).

Best,
Daniel

_______________________________________________
openpgp mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.