Gentoo Archives: gentoo-dev

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] First release of Gentoo Keys
Date: Mon, 12 Jan 2015 18:01:03
Message-Id: 54B40BD2.2080709@gentoo.org
In Reply to: Re: [gentoo-dev] First release of Gentoo Keys by Rich Freeman
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA512
3
4 On 01/12/2015 02:55 AM, Rich Freeman wrote:
5 > On Sun, Jan 11, 2015 at 8:34 PM, Brian Dolbec <dolsen@g.o>
6 > wrote:
7 >> But for the rest, yes, you don't need gkeys to create your key,
8 >> It is just most people seem to know little about using gpg, so
9 >> creating the template where you just filled out name, email,
10 >> password, makes it easy.
11 >
12 > Makes sense. I can always create a new account, create a key,
13 > export/import, and delete the account. That will avoid messing
14 > with config files and such.
15 >
16 >>
17 >> From the above, it looks like you also need to create a signing
18 >> subkey with a preferred 1 yr. expiry. But it can be 5 years max.
19 >> too. You may also want to add an encryption subkey for encrypted
20 >> email and such.
21 >
22 > From docs I was reading it sounds like a signing and encryption
23 > subkey are created by default (two keys total). Is there any
24 > difference between a "main key" and a subkey? I have to admit that
25 > I haven't kept up with gpg features over the years.
26
27 By default GnuPG only create a primary key with SC flags (sign &
28 certification) and an encryption subkey. In this case you'll want to
29 add a signing subkey using the "addkey" command of --edit-key to make
30 a compliant key.
31
32
33 - --
34 Kristian Fiskerstrand
35 Public PGP key 0xE3EDFAE3 at hkp://pool.sks-keyservers.net
36 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3
37 -----BEGIN PGP SIGNATURE-----
38
39 iQIcBAEBCgAGBQJUtAvMAAoJEPw7F94F4TagBsEQALMRpYPlAsVm/J/3cqA57BYH
40 +mcCFA9sNVd8zwGp2fAybGl7Umj0oCTU/c5R/YICPtmuzu8hxYjhvPpKc1gF3UBb
41 QzjCeqMEHNXz1hEsfbmQyqw10Jc9xxiJZmUVESB8tC1l/OTmDOHjgfU5APWzAIg/
42 4scM91Y1lbtKoeJsTpfW0Tv9ROC75PuWudHhEx/3RKJvygACeWGbeLZX9tmdKZbz
43 Zc+Iv3je0XCabC4G0vviuAddpeyNMj0ck5d9lrPLM+MxdJDSkeAT0/+aMBhiQOqt
44 jZImJ4eZq48sEdh0wUqt7EeLuKL6w5rO9N8DTHPCfDhJ9mhFmxPgozVkRmzhTrTX
45 Twac69fSklDzEcQZHr/kPynYdp1ZTN97MxcLxNMXNhWTIG51sFfNK4is+kdmBVUk
46 9wAuMQbWdeeC7oFy60h8sIak7yNeh7L34C7XrYIN7urT9W9zw0tQttRmPbY82yBU
47 K/w8OvdpcwkYNGoAkFfpCL1aqJjwfrWqyWglNGgbaWgw5hkKQ5f+Ljvou9sdfiVc
48 1e4Vu5Tiblz1Ucs5JZRoioXwsW9EAxUYg7wAxnjHyEgE4opFpvVwgq4beWMzgbG9
49 1f2YVxrrakLfpuJ5WneDZJBToaDeVDpMInERiF9xlJDb8vvZeUtKzEElAOF0Ptg4
50 6b9fY0tzc1eAd4uuYPj2
51 =v+RL
52 -----END PGP SIGNATURE-----