Re: [PATCH 0/7] Remove expired keys, 2024 edition
Uwe Kleine-König <[email protected]> Wed, 6 Aug 2025 12:16:04 +0200
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <inbgo6pg27fn5r26664ygcs23m5ok34f7aso7gghsgqm7mx327@dmttrpuq2rnn> |
Hello Joel, On Wed, Aug 06, 2025 at 11:20:34AM +0200, Joel Granados wrote: > On Tue, Aug 05, 2025 at 10:57:55PM +0200, Uwe Kleine-König wrote: > > On Tue, Aug 05, 2025 at 06:42:25PM +0200, Joel Granados wrote: > > > Thanks for this. I had update my signing key but forgot to remove the > > > expired one. I use my updated Signing key that expires in 2027, so all > > > good from my side. > > > > Maybe I state the obvious, but to maybe save you some trouble: You have > > to revoke the subkey if you want to get rid of it; not delete it. I > > The change that I was thinking was actually updating my SEA key to just > S and pushing it to the pgpkeys repo. So I had no need to revoke that > one. Commit "a23ccb8 Update 5895FAAC338C6E77 (Joel Granados)" in [1]. You currently have a master key with sign and certify capabilities, an subkey each for encrypt, sign and authentication (rsa4096, rsa3072 and rsa4096 respectively) and the expired rsa4096 signing subkey. I don't understand your plans, but you cannot drop the certify capability from the master key, and if you want others to notice that you don't use a certain subkey any more, you have to revoke that. > The expired one came in on an update from keyserver.ubuntu.com Commit > "50066c0 (HEAD) Periodic update from keyserver.ubuntu.com" in [1]. And > that one was probably an inadvertent sync from my part since I try not > to use the keyservers. I'll be sure to revoke it once I have access to > my private key. > > > didn't test, but I guess after the patch the subkey will be added back > > on the next keyserver sync. The same would happen to you. > I think you are right. But I have a question here. What key server > should we use? https://keys.openpgp.org/upload/ (as described in [2]) or > should we use keyserver.ubuntu.com? I'm using these two (keys.openpgp.org via hkps, but that doesn't matter much). the openpgp keyserver has the disadvantage (advantage? feature?) to not distribute 3rd party signatures unless you do https://datatracker.ietf.org/doc/draft-dkg-openpgp-1pa3pc/. Best regards Uwe
signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmiTK2AACgkQj4D7WH0S /k4W0wf+Ia5/UkwvjnJZHDN9zP/3LEZKBA8hN5HCJyOR4uuaCzavvkMMor7IpM0H c8TIg5ZjtqHjdcKeVFdWsNY+FbgtKSuUMiH+jYEmCfL/vT2z8WbSZ1yuxpuQibUa Fg8yPInG64Jkc6XbfUOetDRWogZhTfBpdLlRRFYdwvafxlosVsqD3E0QzYclFUwL JskuHmaI6IeaxjAjM/B9rmBr0g3eLVx7jUtpwX+X1URZDy+BIQnlDvKQESoeQ0xx 80qhoVqIC3H5CVDv+0O2XmX0bIHJKXwdXx5I3WUI8/kUYYKzEylMsH9/Ukfk7suQ ab1Ex8+aUyetoF0VKgPXzimEV1rB7Q== =C1hj -----END PGP SIGNATURE-----