Re: [PATCH] Drop expired subkey from description of CFD ED9A2FD1314F0 (Michal Koutný)
Uwe Kleine-König <[email protected]> Sat, 31 Jan 2026 00:14:03 +0100
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <6vhuotebu2oaotdnzt2xnybdks6ssyh77zmbi7hnmb3v2yf65k@gezaaxe5svoc> |
--2veaigzkztx7qnj4 Content-Type: text/plain; protected-headers=v1; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Subject: Re: [PATCH] Drop expired subkey from description of =?utf-8?Q?CFD?= =?utf-8?Q?ED9A2FD1314F0_=28Michal_Koutn=C3=BD=29?= MIME-Version: 1.0 Hello Michal, On Fri, Jan 30, 2026 at 03:35:30PM +0100, Michal Koutn=FD wrote: > I use one-year expiring S subkeys, however, I don't want to refresh it > in this repo every time :-) If you upload your key to keys.openpgp.org or keyserver.ubuntu.com it should get updated automatically by Konstantin's periodic syncs. > (Attaching current export of key.) >=20 > The entry (even w/out S subkey) could still be usable since it's the > main key that is trusted by clients and signs subkeys too. But if your correspondents don't have your subkey, they cannot verify your signatures, so updating the key in the keyring makes sense. Without importing your attached cert, your mail is displayed for me starting with: [-- Begin signature information --] Problem signature from: KeyID 42136E059FF01C4639CB8AF47E3D02E794DBF808 created: Fri 30 Jan 2026 03:35:26 PM CET [-- End signature information --] after importing it into my keyring it says: [-- Begin signature information --] Good signature from: Michal Koutn=FD <[email protected]> created: Fri 30 Jan 2026 03:35:26 PM CET WARNING: We have NO indication whether the key belongs to the person named= as shown above Fingerprint: 9F2A B6F1 F2BB EE76 21C1 B620 CFDE D9A2 FD13 14F0 *** Begin Notation (signature by: 42136E059FF01C4639CB8AF47E3D02E794DBF808= ) *** manu=3D2,2.5+1.11,2,2 *** End Notation *** [-- End signature information --] I don't know what this notation thing is, but this looks a lot nicer. > > diff --git a/keys/CFDED9A2FD1314F0.asc b/keys/CFDED9A2FD1314F0.asc > > index 1d3fbebb9f59..3c35d423ac10 100644 > > --- a/keys/CFDED9A2FD1314F0.asc > > +++ b/keys/CFDED9A2FD1314F0.asc > > @@ -3,8 +3,6 @@ pub rsa4096 2017-08-23 [SC] > > uid Michal Koutn? <[email protected]> > > sub ed25519 2023-01-13 [A] > > 47DE106A4B860621B0D6E63DD8CF730A95E2521C > > -sub ed25519 2024-06-18 [S] [expires: 2025-06-18] > > - DDEA67C5D8F6C4667A5DA0092DDD69DECBBEC149 > > =20 > > -----BEGIN PGP PUBLIC KEY BLOCK----- >=20 > This patch only drops the key metadata but doesn't refresh the armored > key content (making it slightly inconsistent). Well no, it's not inconsistent, it's how gpg prints your key since the subkey expired. (Ok, you could call gpg inconsistent and you'd have a point. :-D) > But if that's OK with you, I'd prefer this patch -- the main key remains > in the keyring and I (or anyone else) wouldn't need to refresh it here > every year. Thanks. As described above that is hardly sensible. Best regards Uwe --2veaigzkztx7qnj4 Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAml9OzkACgkQj4D7WH0S /k6wpQgAqKmfuR1vcG2JgTI6XeUYwPXIiplQDDi900dUXEJ0856blqPEdidKjC3N 2QofOkykU9I3Y+slmeNGcb77QYzmAbEfMvrZ4eY8O/vdQJULMi32XCGfbUPw4TUM Uv3ESor7C8mwM+Kd3IG5LXtWuxPQeWfzQW5AiyxvhHSZmO1e9TqHb9LqUCuEOdWp rPVBHXAliLpxLw7DjoE5kOLbBrbvRtEEAmlgJUW90R/vruf9hLAQ5sqXvtte5IU6 P+DzxhYp3cfaC/o+cexTGD6Ogzee+8gQkq6jeLaCSkQ0Pq+bFPAqJ48VxctyPVbu FaomurIhfpGbaVE1sssuUrCNAUsxCA== =Cv6U -----END PGP SIGNATURE----- --2veaigzkztx7qnj4--